Skip to main content
Legal

Privacy Policy

Version 8.12 — effective 2026-09-16

Privacy Policy
Version 8.12 — effective 16 September 2026.
1. Who we are
The Liva brand and its booking websites are operated by Liva Dot Com (Asia) Co., Ltd. (“LIVA.COM”), a company registered in Thailand, which sells the Services to you and is the party you contract with when you make a Booking. Our full company details are set out in our Legal Notice. The Liva Booking Platform on which those websites run is developed and operated by Liva Core SASU, a company established in France (2 avenue du Président Pierre Angot, 64000 Pau; SIREN 908 471 303, RCS Pau), which makes the Platform available to LIVA.COM under licence. In this Privacy Policy “Liva”, “we” and “us” mean both companies, each in the role set out below; where a particular activity is determined by only one of them, we say which.

Liva Core SASU is the data controller for the Liva platform and customer-data environment. It determines the purposes and the essential means of the processing the Platform itself carries out: your Liva account and the authentication of it, the platform data model and the databases that hold your data, how long data is kept and how it is deleted or anonymised, platform and account security, the communications infrastructure through which our messages are sent, platform analytics, and the infrastructure through which you exercise your privacy rights.

Liva Dot Com (Asia) Co., Ltd. is a separate data controller — not a joint controller with Liva Core — for the processing whose purposes it determines itself as the travel agent and intermediary that sells you the Booking. That includes your commercial relationship with LIVA.COM, the sale itself, payment and refund administration, invoices, receipts and other commercial documents, and the Thai accounting, tax and regulatory records LIVA.COM is required to keep. LIVA.COM remains the party that sells you the Service and issues your commercial documents: how data-protection responsibility is allocated here does not change who you buy from.

Transport Providers are independent data controllers of the passenger and customer data we disclose to them. A Transport Provider decides for itself how it uses that data to operate the Service you booked and to meet its own legal and regulatory obligations, and processes it under its own privacy policy. It is not our processor, and its processing is not governed by this Policy.

We do not treat Liva Core and LIVA.COM as joint controllers by default. Joint controllership is applied to a specific activity only where the two companies in fact jointly determine its purposes and its essential means; where that is so, the essential terms of the arrangement are made available to you on request.

Which data-protection law applies depends on which processing is concerned. The platform processing controlled by Liva Core SASU is carried out in the context of the activities of its establishment in France, and is governed by the European Union General Data Protection Regulation (“GDPR”). The commercial and OTA processing controlled by Liva Dot Com (Asia) Co., Ltd. is governed by Thailand’s Personal Data Protection Act (“PDPA”), and by the GDPR in addition where that Regulation applies to it. Where another data-protection regime also applies to you, the rights and protections it gives you are respected in addition. Not every activity described in this Policy is governed by the same law, and section 17 says which authority you can complain to about which.

You can contact us about privacy, or reach our Data Protection Officer, at dpo [at] livacore [dot] com.
2. Scope
This Privacy Policy applies when you browse a Liva website, search for transport, make or manage a Booking, create or use a Liva account, contact Customer Service, use Liva Vouchers, account credit, rewards or referral features, submit a review, take part in our affiliate, travel-agent or partner programmes, sign in using a supported third-party account, receive communications from us, or otherwise use the Liva Booking Platform. It also applies to the people who use our professional surfaces: the Operator Portal, used by the staff of the Transport Providers we work with, and the Partner Portal, used by affiliates, travel agents and resellers.
3. Personal data we collect
We apply the principle of data minimisation and collect only what is reasonably necessary for the service concerned. Depending on how you use Liva, we may process the following.

Account and identification data — first name, last name, title, email address, telephone number, nationality, date of birth, account identifiers and authentication information.

Booking and passenger information — booking reference, the journey and service selected, departure and arrival details, passenger names and category, nationality, date of birth and contact information. Not every Booking requires all of this.

Travel-document information — where the Service, the Transport Provider or a legal requirement makes it necessary, we process information from your passport or another travel document: the document number and the name, nationality, date of birth and expiry date as they appear on it. We ask for this only where it is genuinely required for the journey you booked. It is held under tighter access controls than ordinary booking data, and how long we keep it is described in section 10.

Payment information — payment amount, method and status, transaction reference, refund information, disputes or chargebacks, and fraud or risk information relating to a transaction.

We do not store your full payment-card number or card security code. Where you choose to save a card, the payment provider stores the card details and provides Liva with a token. We retain that token together with limited card information — the card brand, the last four digits and the expiry date — so the saved card can be identified and used again without Liva holding the complete details.

Liva Vouchers, credit and rewards — voucher identifiers, type and origin, balances, issue and expiry dates, earning and redemption activity, refunds, adjustments, reward eligibility and the related booking references.

Customer-service information — your identity and contact details, the booking concerned, the content of your request, correspondence, support tickets, attachments you provide and the records needed to investigate and resolve it. Where you contact us by telephone, this may include call records and call recordings made through our customer-service platform. Please avoid putting sensitive or unnecessary personal data into free-text fields.

Reviews and feedback — your identity, booking reference, review content and rating, related correspondence, and any reward associated with an eligible review.

Operator Portal user accounts — for the staff of a Transport Provider given access to the Operator Portal, we process their name and preferred name, job title, department, internal employee reference, work email address, office, mobile and WhatsApp numbers, profile photograph, language and time-zone preferences, the authentication data needed to sign them in (including two-factor authentication settings), and security telemetry such as sign-in times, failed-attempt counts and account lock or status changes.

Affiliate, travel-agent and partner information — name, email address, telephone number, company information, account and partner identifiers, booking and commission information, settlement records and the payment details necessary to make a payout. The same applies to the people who use the Partner Portal on behalf of an affiliate, agency or reseller.

Email delivery information — for the messages we send you we record whether the message was accepted, delivered, bounced or rejected, the time of those events, and a message reference. That is what tells us a message reached you, or why it did not. We do not track what you do with our email. We do not record whether a message was opened — our messages carry no tracking image — and we do not record whether or when you followed a link in one, because the links in our email are not rewritten to pass through us on the way to where they say they go. This applies to all the email we send you — service messages such as booking confirmations, e-tickets and payment or refund notices, and marketing alike.

Technical and security information — IP address, browser, device type, operating environment, language, connection timestamps, pages or functions accessed, referring URL, session identifiers, authentication activity, and security and application logs.

Audit records. We keep a record of actions taken on your data — what was done, when, which record it concerned, and whether it was done by you, by our staff, by an operator or automatically. Some entries include the state of a record before and after a change, and the connection details the action came from. These records are kept in a form that cannot be altered. An entry is therefore not edited or deleted when you ask us to correct or erase your data: it is the evidence of how your data was handled, which the law allows us to keep for that purpose. It is deleted or anonymised at the end of its retention period, which depends on the kind of action recorded and is never longer than 10 years (section 10).

Consent and acceptance records — which agreement you accepted, which version of it, when, from which IP address, and through which channel. Where available, we also keep the wording you were shown.

Document delivery records — when you open or download an e-ticket, booking confirmation, wallet pass, invoice or receipt from your account, we record which document it was, for which Booking, when, and whether it was provided to you. We do not record your IP address or device for this.

Dispute records. If a payment is disputed, we assemble a case file to answer it. It contains information about you, your Booking and its payment that is necessary to answer the dispute, together with the response we submit. We do not include your IP address or device information in a dispute file. Once submitted, the file is kept unaltered.

Rights-request records — when you exercise a right, we keep your request, the email address you sent it from, our note of how it was handled, and the dates it was received, was due and was closed, as proof that we answered you.
4. Special categories and sensitive information
We do not ordinarily need health information, or any other special category of personal data, to sell you a journey, and we ask you not to put such information into free-text fields where it is not needed.

Some journeys need it anyway. If you tell us that a passenger needs step-free boarding, a wheelchair space, assistance at the pier, or that a passenger has a medical condition the operator has to know about in order to carry them safely, that is information about health and we treat it as such. We process it only so far as is necessary to arrange the Service you asked for and to tell the Transport Provider what it needs to know. Where such information constitutes special-category personal data, we process it only where an applicable condition under Article 9 GDPR, the PDPA or other applicable law permits us to do so. Depending on the circumstances, this may include your explicit consent.

We pass on only what the operator needs in order to perform the journey, we do not use it for any other purpose, and we do not keep it once the journey and any related complaint, claim or legal obligation has finished. If you would rather not enter this kind of information on the website, contact Customer Service and we will arrange it with you directly.
5. Where we obtain personal data
Directly from you, when you make a Booking, create or update an account, communicate with us, request a refund or an amendment, take part in a programme, submit a review, or otherwise use the Platform.

From another person making a Booking. A person making a Booking may provide information about other passengers. If you provide personal data about someone else, you are responsible for ensuring it is accurate and that they are informed their data is processed as described here.

From Transport Providers, where necessary to operate or manage your Booking — for example a schedule change, disruption, cancellation, amendment, boarding issue, complaint or dispute.

From payment and service providers, where necessary to confirm or manage a transaction, refund or security event.

From third-party sign-in providers. If you choose to sign in using a supported Google, Facebook or LINE account, that provider may share your name, email address, profile image and other basic account information you have authorised. You can instead use the standard Liva sign-in.
6. Why we process your personal data, and on what basis
Each purpose below names its controller — the company that decides why and how that processing happens, as described in section 1. As a general rule, Liva Core SASU controls the platform itself and what it does with your data, and LIVA.COM controls the commercial relationship: what you buy, what you pay, and the records of it. Some purposes have a genuinely split answer, and where that is so both are named rather than one being chosen for tidiness. Where a purpose below relies on our legitimate interest, the legal basis is Article 6(1)(f) of the GDPR and, for processing governed by Thailand’s PDPA, section 24(5) of that Act.

Providing and managing Bookings. Controller: LIVA.COM. To search for available Services, create a Booking, issue confirmations and e-tickets, communicate with the Transport Provider, manage amendments, cancellations and refunds, process payments, provide invoices or receipts and provide related services. The legal basis is the performance of a contract with you, or steps taken at your request before entering into one. Some information is mandatory; if it is not provided we may be unable to complete the Booking.

Your Liva account. Controller: Liva Core SASU. To create and authenticate your account, store your Bookings and travel documents, save your preferences, display available vouchers or credit and manage your profile. The legal basis is the performance of the contract under which the account exists: the account is created as part of making a Booking and is what allows you to hold, retrieve and manage it. Where we use account data beyond that — to keep the account secure, to prevent abuse and to keep the Platform working correctly — the basis is our legitimate interest under Article 6(1)(f) of the GDPR.

Customer Service. Controller: LIVA.COM, for requests about your Booking, payment or refund; Liva Core SASU for the support platform itself and its security. To answer questions, manage Bookings, investigate complaints, provide assistance, process refunds or amendments and resolve disputes. The legal basis depends on what you have asked us to do. Handling a Booking, an amendment, a cancellation or a refund is the performance of our contract with you. Where a request engages an obligation we are subject to — accounting and tax records, a statutory refund right, a regulator’s enquiry — the basis is compliance with a legal obligation. For everything else, including handling a complaint and improving the quality of our service, the basis is our legitimate interest under Article 6(1)(f) of the GDPR in answering the people who contact us. Support conversations may also be summarised with the help of an AI provider, as described in section 18.

Payments, refunds and financial operations. Controller: LIVA.COM. To take and confirm payment, issue refunds, investigate failures, manage disputes and chargebacks, detect fraud, reconcile transactions and maintain accounting records. Depending on the operation this is necessary for the performance of a contract, for compliance with a legal obligation, or for our legitimate interest in protecting the Platform.

One kind of decision about you is made automatically. Where a cancellation or amendment falls squarely within the rules published in our Terms and Conditions, the refund due to you is calculated and issued without a person reviewing it, so that you are paid promptly. This is a rules-based calculation applying the published terms to your Booking — no artificial intelligence is involved, and the rules are the ones you can read in the Terms. It is necessary for the performance of our contract with you.

The automated path either issues the refund produced by the applicable rules or refers the request for human review; it does not automatically refuse a refund request. You may ask for a human to review any automatically calculated refund, express your point of view, and contest the outcome — contact Customer Service, or write to us at dpo [at] livacore [dot] com or at the postal address in our Legal Notice.

Accounting and taxation. Controller: LIVA.COM. We keep invoices, transaction records and other mandatory documents to meet accounting and tax obligations. The legal basis is compliance with a legal obligation.

Security and fraud prevention. Controller: Liva Core SASU for platform and account security; LIVA.COM for fraud and risk on a payment or a Booking. To protect accounts, prevent unauthorised access, detect suspicious activity, prevent payment fraud, maintain system security, investigate incidents and establish, exercise or defend legal claims. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in the security of the Platform and in defending our rights, and, where a specific security obligation applies to us, compliance with a legal obligation.

Communications about your Booking. Controller: LIVA.COM decides that you receive these and what they say; Liva Core SASU operates the infrastructure that sends them. Confirmations, e-tickets, payment information, schedule changes, cancellations, amendments, refunds and other operational messages. These are service communications, not marketing.

Reviews and follow-up. Controller: LIVA.COM for the invitation, which follows your Booking; Liva Core SASU for the review feature itself. After travel we may invite you to review your trip, and where permitted send one limited reminder. You may opt out of non-essential communications using the unsubscribe link provided.

Email delivery. Controller: Liva Core SASU for deliverability of the platform’s mail; LIVA.COM for marketing. We process delivery information for service messages — booking confirmations, e-tickets, payment and refund notices — to establish that a message you are entitled to receive actually reached you, to retry or re-issue it if it did not, and to stop sending to addresses that reject mail. For those messages the basis is the performance of our contract with you, and our legitimate interest under Article 6(1)(f) of the GDPR in the deliverability of our own mail.

We do not measure what you do with our email. Neither we nor our email provider records whether a message was opened, or whether a link in it was followed — not for marketing, and not for service messages. We know only what the delivery record above tells us: that a message was accepted, delivered, bounced or rejected, and when. We do not treat consent to marketing as consent to anything else, and service messages are never sent on the strength of it.

Marketing. Controller: LIVA.COM. We send marketing only where we have an appropriate legal basis, including consent where required. You can withdraw consent or unsubscribe at any time; this does not affect service messages needed for your Bookings or account.

The Liva assistant. Controller: Liva Core SASU. Some of our websites offer an assistant that answers questions about routes, schedules and travel in your own words. What you type is sent to an AI provider to generate the reply. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in helping visitors find the right service, and, where you are asking in order to make a Booking, steps taken at your request before entering into a contract. Section 18 explains this in full.

Keeping a record of what was done with your data, and of what you agreed to. Controller: Liva Core SASU. We keep an audit record of actions taken on your data, and a record of the agreements and consents you gave — the version, the date, and the address you gave it from. The legal basis is compliance with a legal obligation, read with our duty to be able to demonstrate that we handle personal data correctly, and, for consent records, our obligation to be able to show that a consent was validly given. These records are deliberately kept when other data about you is deleted — see section 10.

Disputes and legal claims. Controller: LIVA.COM. Where a payment is disputed with the card scheme or the payment provider, we assemble a case file to answer it, and we keep records needed to establish, exercise or defend a legal claim, including the record that a document you were entitled to — an e-ticket, invoice or receipt — was provided to you. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in establishing, exercising and defending our rights. Where the card scheme or the payment provider sets rules for how and when a dispute must be answered, we follow those rules. Section 3 describes what a dispute file contains.

Rewards, Liva Vouchers and referrals. Controller: LIVA.COM — these are commercial programmes of the selling entity. To calculate eligibility, issue rewards or vouchers, manage balances, record redemption, prevent duplicate or abusive rewards, manage expiry and keep an auditable history. The legal basis is the performance of our contract with you in the programme you take part in, together with our legitimate interest under Article 6(1)(f) of the GDPR in preventing abuse of it.

Operator and Partner Portal accounts. Controller: Liva Core SASU. To create and administer accounts on our professional surfaces, authenticate the people who use them, apply the permissions their role requires, and keep the security records needed to protect those accounts. The legal basis is the performance of the contract between Liva Core and the operator, agency or partner the person acts for, together with our legitimate interest under Article 6(1)(f) of the GDPR in keeping those accounts secure. Where a person uses these surfaces because their employer or principal requires it, we do not rely on their consent — consent given in that situation would not be freely given, and the contract with their organisation is the honest basis.

Affiliate and partner programmes. Controller: LIVA.COM for commission, attribution and payout; Liva Core SASU for the Partner Portal accounts themselves. To administer partner accounts, attribute Bookings, calculate commissions, approve and process payouts, reconcile transactions, prevent fraud and meet accounting and tax obligations. The legal basis is the performance of the contract with the partner, our legitimate interest under Article 6(1)(f) of the GDPR in preventing fraud, and compliance with a legal obligation for the accounting and tax records.
7. Payments, invoices and accounting records
Payment transactions are processed through the payment providers made available on the Platform. Our payment providers are Omise and PayPal, depending on the method and service concerned. The provider processes the card or payment credentials needed to authorise the transaction. We transmit only the information necessary for authorisation, refunds, fraud prevention, disputes, chargebacks and reconciliation. Each provider processes that information under its own privacy policy and under its contract with us.

Invoices, receipts and accounting records. We are required to issue and keep invoices, receipts, credit notes and related accounting records, and to retain them for the period tax and accounting law requires. Those records are kept in Xero, the accounting platform we use. The controller for this processing is Liva Dot Com (Asia) Co., Ltd., which issues your commercial documents and holds the Thai accounting and tax obligations; the legal basis is compliance with a legal obligation.

For customers, we deliberately keep this to the minimum that an accounting record needs, and your email address is not part of it. An accounting record carries your name and, where you are invoiced as a business, its address and tax identification number, together with the booking reference and an internal reference. Your email address, telephone number and home address are not sent to the accounting platform. Where you are an affiliate, agency or partner being paid by us, your email address is part of the accounting record, because it is how a payment to you is identified and confirmed.

Xero acts as our processor for these records — it holds and serves them on our instructions — and as an independent controller for its own operation and security of the service and for records it is itself required to keep. Your accounting records are processed in the United States. Keeping them there is an international transfer, and Xero’s own subprocessors, support teams and backup facilities may operate from other countries as well, so we do not present this as processing in one country only. The safeguards that apply are described in section 9, and you can ask our Data Protection Officer which one applies to a particular transfer.
8. Who we share personal data with
Transport Providers. We give the Transport Provider what it needs to perform the Service you booked — which, depending on the Service, may include passenger identity, booking reference, telephone number, email address, travel details and, where required, travel-document information. A Transport Provider is an independent controller of the data it receives, not our processor: it delivers the transport itself and determines how it uses that data to run the Service and to satisfy its own legal and regulatory obligations, under its own privacy policy.

Between the two Liva companies — Liva Core SASU and Liva Dot Com (Asia) Co., Ltd., and no others — where necessary to operate the Platform, manage Bookings, provide support, maintain security or provide accounting and administrative services. Access is limited by role and business need.

Who acts on our instructions, and who does not. The third parties we work with do not all have the same role, and it matters to you which is which. Some act only on our instructions — they are our processors, and what they may do with your data is limited to what we ask. Others decide for themselves what to do with the data they receive: they are independent controllers, their own privacy policy governs that processing, and this Policy does not.

Acting on our instructions (processors):

  • OVH (2 rue Kellermann, 59100 Roubaix, France) — hosting of the core Liva Platform, websites and primary Platform databases in the European Union.
  • Amazon Web Services EMEA SARL (Luxembourg) — Amazon CloudFront, the content-delivery network through which our websites may be delivered. It carries requests between your browser and our servers and holds temporary copies of website content on servers close to you, including servers outside the European Union.
  • SendGrid (Twilio Inc., United States) — delivery of our email.
  • Zendesk (United States) — the customer-service platform through which we handle your requests, including telephone contact and call recordings where they are made. Your support records are processed in the United States.
  • Xero (United States) — the accounting and invoicing platform holding the mandatory records described above, for those records. Xero also processes data for its own service-operation, security and statutory purposes, and is an independent controller for that.
  • OpenAI (United States) — artificial-intelligence services used by our staff, described in section 18.
  • Anthropic PBC (United States) — artificial-intelligence services — the Liva assistant and the document-reading and internal support tools described in section 18.
  • Cookiebot (Usercentrics A/S, European Union) — cookie-consent collection, proof of consent and cookie classification.


Deciding for themselves (independent controllers):

  • Omise and PayPal — payment providers. They collect your payment credentials directly from you, on their own pages, and carry out their own identity, anti-fraud, anti-money-laundering and card-scheme obligations, which we cannot instruct. For a PayPal payment we deliberately receive no payer identity at all.
  • Google (Google Ireland Ltd / Google LLC) — tag management, audience measurement, advertising, and the maps shown on some pages. Where we send Google information about a completed booking so that it can measure and bid on advertising, Google uses that for its own purposes as well as ours. These technologies are in the statistics and marketing categories and run only after you consent to them. Separately, where you choose to sign in with a Google account, Google provides that sign-in.
  • YouTube (Google) — where a page embeds a video. Loaded only after you consent to the marketing category.
  • Meta Platforms (Facebook, WhatsApp, Messenger) and LY Corporation (LINE) — where you choose to contact us on one of those services, or to sign in with a Facebook or LINE account. The conversation takes place on their platform, under their terms.

Professional advisers — lawyers, accountants, auditors and consultants bound by confidentiality obligations, where necessary.

We do not sell your personal data. We do not make your personal data available to any third party for that party’s own commercial purposes in exchange for money or other valuable consideration, and we do not treat your personal data as a product. The disclosures described in this section are made to deliver the Service you booked, to run the Platform, to obtain professional advice, to meet a legal obligation, to establish, exercise or defend legal claims, or in the event of a corporate transaction, as described below.

In a corporate transaction. If we are involved in a merger, acquisition, restructuring, financing, or a sale or transfer of all or part of our business or assets, personal data relevant to that business may be disclosed to the other party and its advisers, and may transfer with the business. Any such disclosure or transfer is made subject to applicable data-protection law, and we would tell you if it changed who controls your personal data or how it is used.

Authorities — courts, law-enforcement agencies, regulators and tax authorities, where required by law or necessary to establish, exercise or defend legal rights.
9. International transfers
Liva operates internationally. Our primary Platform infrastructure and databases are hosted in the European Union, with OVH, which contractually undertakes that data in an EU service is not transferred outside the member countries of the European Union or countries recognised by the European Commission as offering an adequate level of protection.

Our websites may be delivered through Amazon CloudFront, a global content-delivery network. When they are, your request — including your IP address, the page or function you ask for and your browser information — is handled by the CloudFront server nearest to you, which may be outside the European Union, for example in Thailand when you visit from there.

The Liva Platform is operated by Liva Core SASU in the European Union, while LIVA.COM, which sells you your Booking, is established in Thailand. The personal data needed for your Booking, payments, refunds, invoices and Customer Service is therefore made available to LIVA.COM in Thailand. The European Commission has not recognised Thailand as offering an adequate level of protection, so this transfer relies on the safeguards required by Article 46 of the GDPR, such as the European Commission’s Standard Contractual Clauses. You may ask our Data Protection Officer for a copy of the safeguard that applies.

Your accounting records, held in Xero, your customer-service records, held in Zendesk, and the email we send you, delivered through SendGrid, are processed in the United States. Text you send to the Liva assistant, and the information processed for the purposes described in section 18, are also sent to artificial-intelligence providers in the United States. For each of these, the provider’s own subprocessors, support teams and backup facilities may operate from other countries, so these are the principal places of processing rather than the only ones.

Certain other recipients are located outside the European Union or Thailand. Where the recipient is in a country the European Commission has recognised as offering an adequate level of protection — which includes Japan, and so covers LINE — the transfer rests on that adequacy decision. Otherwise we rely on the European Commission’s Standard Contractual Clauses or another transfer mechanism permitted by applicable law. You may contact our Data Protection Officer for information about the safeguards applying to a particular transfer.
10. How long we keep personal data
We keep personal data only as long as necessary for the purpose concerned, subject to legal, accounting, tax, security and dispute-resolution requirements.

User account Until you close the account. An account that has not been used for 5 years is closed and anonymised. The 5 years run from the most recent of: the date the account was opened, the date its latest Booking was made (cancelled Bookings included), the last time you signed in, and the last time you asked us to keep the account.
Booking records 5 years after the date the Booking was made. After that, your name and the passengers’ details are removed from the Booking, and its amounts, dates and status are kept. The separate accounting records described in section 7 are kept for the period shown for accounting and tax documents.
Travel-document information Deleted 90 days after the last departure booked on your account. A travel document saved to your account, or saved against a traveller in your address book, is kept while journeys continue to be booked on your account, so that it does not have to be entered again. It is removed 90 days after the latest departure date of any journey booked on your account, cancelled journeys included, whichever traveller the document belongs to. If no journey has been booked on your account, it is removed 90 days after it was saved or last changed. An erasure request removes it at once.
Call recordings Kept only as long as the purpose the call was recorded for requires, and separately from the written record of your Customer Service case. A recording is kept longer only where a complaint, a fraud investigation, a dispute or a legal claim is still open.
Customer Service 3 years after your last request for assistance, whether or not your account is still active. Where a request engages an accounting, tax or other legal obligation, the records that obligation covers are kept for the period it requires.
Accounting and tax documents 10 years from the end of the financial year to which the document relates.
Vouchers, rewards and credit For as long as needed to operate the programme and to satisfy accounting, audit and legal requirements.
Partner and affiliate records For the duration of the relationship, then the applicable accounting and legal retention period.
Security and technical records For the period necessary for security, investigation and legal requirements.
Email delivery records 2 years from when the email was sent. After that, the record that we sent it and the address it was sent to are deleted, unless the record forms part of evidence we must keep.
Search activity The searches made on our websites are kept as anonymous statistics. Any link to your browsing session or to your account is removed after 6 months.
Audit records Kept for the period during which we may be required to demonstrate how your personal data was handled, or to establish, exercise or defend a legal claim about it — and in any event no longer than 10 years from the action recorded, after which the record is deleted or anonymised. Because these records are protected against alteration, they are kept unchanged until the end of that period, even after other data about you has been deleted.
Consent and acceptance records Kept after you withdraw a consent or close your account, because we must still be able to show that the consent was validly given at the time. Withdrawing a consent stops the processing from then on; it does not erase the record that you gave it. The IP address is removed where the record no longer needs it, and the agreement, its version and the date are kept. Evidence of consent to a Booking amendment is kept for 3 years, after which the IP address is removed.
Dispute records For as long as a payment dispute can still be raised, answered or challenged, and afterwards for any period a legal claim may require.
Document delivery records 24 months from the date the document was provided, which covers the longest period in which a card payment can be disputed. If your account is erased, the link to your account is removed and the record that the document was provided is kept for the rest of that period.
Rights-request records Kept as proof that we received and answered your request, for the period we may be required to demonstrate that.

Some records are kept precisely because they are evidence — of what you agreed to, of what was done with your personal data, and of how we handled a dispute or a request. Those records are deliberately not erased when the rest of your data is. Instead, wherever we can do it without destroying what makes them evidence, we remove the parts that identify you and keep the proof. Audit records are the exception: because their value as evidence depends on their being unaltered, they are kept unchanged until the end of their retention period.

Legal holds. We may keep personal data beyond the periods above where we have to in order to comply with the law, or to establish, exercise or defend a legal claim. Information kept on that basis is used only for the purpose that required it, and access to it is restricted.

Where a legal obligation requires us to keep information after an account is closed, that information is held in restricted archives and used only for the purpose requiring it. At the end of the applicable period the data is deleted or anonymised.

We may also anonymise or aggregate personal data — for analytics and statistics, to monitor and improve the security of the Platform, to improve our products and services, and for other legitimate business purposes. Where an account is erased, our method is to anonymise and retain: the information that identifies you is overwritten, while records we are required to keep — such as booking and accounting records — remain in anonymised form for the period the law requires. Once data has been anonymised so that you are no longer identifiable from it, and we cannot restore that link, it is no longer personal data and this Policy no longer applies to it.
11. Closing your account
You may request closure of your Liva account from within your account. Closing an account does not necessarily delete every record immediately: we may keep what is necessary for existing Bookings, accounting and tax, payment records, fraud prevention, legal claims or regulatory compliance. Where information no longer needs to identify you, it is anonymised.
12. Cookies
We use cookies and similar technologies for essential website operation, authentication, security, preferences, measurement and the other purposes described in our Cookie Policy. Only cookies classified as strictly necessary are used without consent where applicable law permits; other categories are activated only after the required consent. You can change or withdraw your cookie choices at any time using the Manage cookies control on the website. Cookie consent is managed separately for each of our websites and surfaces, so the categories in use and the controls offered may differ between a booking website and a professional portal. The cookies actually in use on each Website are detected by a monthly automated scan, and the resulting list — naming every cookie, the party that sets it, its purpose and its lifetime — is published in the cookie declaration available from the consent banner. That list, rather than this Policy, is the current record of the cookies in use.
13. Security
We use organisational and technical measures intended to protect personal data against unauthorised access, disclosure, alteration, loss, misuse and destruction. These include access and permission controls, monitoring, backups, encryption or pseudonymisation, and security requirements for our staff and service providers. Access to our internal systems requires additional authentication. For your Liva account, and for accounts on the Operator Portal and Partner Portal, two-factor authentication is available and we encourage you to enable it — you can turn it on at any time from the Security page of your account, using an authenticator app or a code sent to your email address. No internet service can guarantee absolute security, but we maintain and improve measures appropriate to the risks.

We maintain documented procedures for handling personal-data breaches, covering detection, assessment, containment and record-keeping. Where a breach meets the threshold set by the law that applies to it, we notify the competent supervisory authority and, where that law requires it, the individuals affected. Not every security incident is a personal-data breach, and not every personal-data breach meets a notification threshold — we assess each one against the applicable test rather than notifying by default.
14. Children and young people
A person making a Booking must be at least 20 years old and meet the legal-capacity requirements set out in our Terms and Conditions. A Booking may nevertheless include passengers who are minors — for the purposes of this Privacy Policy, anyone under 20 years of age.

Where personal data relating to a passenger who is a minor is required for a Booking, it must be provided by, or with the authority of, the parent, legal guardian or other person entitled to make the Booking on their behalf. We process that data only as far as necessary for the Booking, the Service or a legal requirement.
15. Your rights
Depending on the law applying to your personal data, you may have the right to be informed how your data is processed, to access it, to have inaccurate or incomplete data corrected, to have data erased, to restrict processing, to object to certain processing, to receive certain data in a portable format, to withdraw consent where processing is based on consent, and to lodge a complaint with a supervisory authority.

These rights are subject to the conditions and exceptions of applicable law — for example, we may be required to keep certain accounting or booking records despite a deletion request.
16. Exercising your rights
To exercise a right or ask about the processing of your personal data, contact us at dpo [at] livacore [dot] com, or write to us at the postal address in our Legal Notice. You may also use the privacy-request form on the /privacy-policy.html page of the website you are using.

We may ask for information reasonably necessary to confirm your identity before acting on a request, and we will not ask for more than is necessary for that purpose.
17. Complaints
If you are not satisfied with how we have handled your personal data, you may lodge a complaint with the data-protection authority competent for you. Which authority that is depends on the processing concerned.

For the platform processing controlled by Liva Core SASU, the supervisory authority is the French Commission nationale de l’informatique et des libertés (CNIL); if you are in the European Union or the EEA you may also complain to your own national supervisory authority.

For the commercial and OTA processing controlled by Liva Dot Com (Asia) Co., Ltd., that is ordinarily the Personal Data Protection Committee (PDPC) of Thailand.

Where another regime applies to you, you may instead or additionally complain to the authority competent under it. You are welcome to contact us at dpo [at] livacore [dot] com first if you would prefer us to look into a concern directly.
18. Artificial intelligence
We use artificial-intelligence services in a small number of places. These services are provided to us by third parties, which process what we send them in order to return a result. The providers we currently use are named in section 8; if we change provider, that list changes and this section does not.

The Liva assistant. Where a Liva website offers an assistant, the words you type are sent to an AI provider so it can answer. You do not need an account to use it and we do not attach your identity to what you type; we keep a record that a conversation happened, and with which brand, but we do not store the messages themselves. The assistant can look up public travel information such as routes and schedules. It cannot see your account, your Bookings, your payments or your personal data, and it cannot make, change or cancel anything.

Please do not enter payment-card details, passport or identity-document numbers, health information or other sensitive personal data into the assistant. Contact Customer Service if you need to provide this information.

Internal operational uses. AI providers may assist our staff with customer support, drafting communications, document processing and technical or operational tasks. In customer support, this includes summarising your conversations with Customer Service and the history of your Bookings, so that the member of staff handling your request can understand it quickly. Document processing here means reading information out of a business document — an operator’s invoice or a supplier’s statement, for example — so that it does not have to be re-typed. We do not use an artificial-intelligence service to read passports or other identity documents. Information processed for those purposes may contain personal data — relating to you, and in the case of business documents to suppliers, Transport Providers, partners or their personnel. AI outputs assist our staff and do not independently determine decisions affecting customers.

Artificial intelligence does not decide anything about you. No AI result decides whether you get a Booking, a refund, a price, or any other outcome that affects you. Where AI produces a summary or a suggestion, a member of our staff decides what to do with it and remains responsible for that decision. We do not use artificial intelligence to profile you or to build a picture of you for marketing. Section 6 describes the one place where a decision about you is made automatically, and it does not involve artificial intelligence.
19. Third-party websites and services
Our websites may link to third-party websites, Transport Providers, payment providers and other external services. Their processing of personal data is governed by their own privacy policies, and we encourage you to read those before providing personal data to them.
20. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Platform, new functionality, changes to our service providers or processing activities, or changes in legal requirements. The current version and its effective date are always shown on the website. Where a change materially affects how we process personal data we will give additional notice where applicable law requires it.
21. Language
This Privacy Policy may be made available in several languages. Translations are provided to make it easier to understand. The English version is the original and prevails if a translated version differs from it in meaning, subject to any mandatory requirement of applicable law.

Send a request to our Data Protection Officer

All data collected by this form will be sent only to our Data Protection Officer. The response will be by default by email unless otherwise requested.

Loading...
Dear {firstname},

We're sorry, but it seems there was an issue with your form submission.

Your privacy is important to us, and we want to ensure your request is handled promptly. Please try submitting the form again. If the problem persists, email our Data Protection Officer directly so we can assist you.

Thank you for your understanding and patience.

Best Regards,
Phuket Ferry Team
Dear {firstname},

Your privacy is important to us. Rest assured that your information will be handled in accordance with our privacy policy.

We have received your form successfully, and your request is being processed by our Data Protection Officer to take the necessary actions.

Best Regards,
Phuket Ferry Team