Replay consent-basedStorage privateAudit client-ready
Security & GDPR

LiveLiz Trust Center.

LiveLiz live sessions are designed to minimize data, isolate each customer and make replay explainable: participant consent, private storage, short signed URLs, access logs and governed deletion.

Updated · June 8, 2026

01

Where are my videos stored?

The live feed is not stored continuously. A replay is created only when the showroom allows it, the operator requests recording and invited participants consent.

Raw recorder files transit through the private `session-recordings` bucket. They are not public and uploads use short-lived signed URLs. Final replay playback is served through a signed URL.

02

Replay consent

Each acceptance or refusal is timestamped with the displayed notice version, locale, participant, guest access type, available IP address and user-agent.

For multi-guest sessions, the product rule is strict: if one active participant has not consented, replay does not start.

03

Access and confidentiality

Customer accounts are tenant-isolated. Privileged roles carry MFA flags and blocking enforcement is enabled in production by environment variable after the enrollment journey is verified.

Persisted installation secrets are application-encrypted with AES-256-GCM envelopes when the production key is configured.

04

Subprocessors

Main technical subprocessors are Supabase for authentication and database, Vercel for application hosting, Cloudflare for media transport and Stream, Stripe for billing and an AI provider only when AI Replay features are enabled.

The customer DPA must list region, purposes, retention and transfer mechanisms applicable to each subprocessor.

05

Incident and audit

LiveLiz maintains an incident register with severity, status, detection date and a 72-hour due date for CNIL notification analysis when required.

Signed replay accesses, secret reveals and justified support access should feed the audit log. A customer export can be prepared for enterprise accounts.

Security & GDPR · LiveLiz Trust Center