Effective: October 2026
Liza GmbH, Oppenhoffallee 143, 52066 Aachen, Germany
Email: privacy@liza.app
Company name, name, email address, and billing address provided during registration and ordering.
IP address, browser type, access timestamps, and interactions with the platform. These are collected for service operation and security.
For website usage analysis, we use Plausible Analytics (Plausible Insights OÜ, Estonia). Plausible does not use cookies, does not store any personal data, and does not create individual user profiles. All analysis is based exclusively on anonymous, aggregated data. No consent is therefore required. The legal basis is our legitimate interest in improving our website (Art. 6(1)(f) GDPR). More information at plausible.io/data-policy.
Referral source at registration: When you register, we store with your account where you came from. Where available, this is the domain of the referring website (e.g. “google.com”, not the full address), campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the landing page on our website, as well as whether you came via an invitation or the waiting list, and the type of device (web, desktop app, iOS, Android). We take the referral, campaign parameters and landing page from the link address without cookies, and the type of device from the identifier of your browser or app (user agent). We use this information only to evaluate our website and marketing. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Messages, projects, files, and other content you create or upload on the platform are processed solely on your behalf (see Data Processing Agreement). All content created or uploaded by the Customer remains the exclusive property of the Customer. The Provider claims no rights whatsoever to such content. For information on the use of AI interactions for training AI models, see Section 2.5.
When the Customer uses AI features of the platform, the content provided by the Customer is transmitted as context to third-party AI model providers. Processing is carried out solely to deliver the requested AI function. The AI providers used are listed in the sub-processor list. The Customer may disable AI features entirely at any time in the platform settings; in this case, no data is transmitted to AI providers. The legal basis for providing AI features is contract performance (Art. 6(1)(b) GDPR).
AI Training: On paid plans (Pro, Max), Customer data is not used to train AI models. On the free plan (Free), content submitted to AI features (inputs and context) may be used to improve our AI models and services; other platform content (e.g., projects, messages, files) is not affected. The legal basis is our legitimate interest in improving our services (Art. 6(1)(f) GDPR). The Customer may object to the use of their data for AI training at any time in the platform settings (Art. 21 GDPR). Upgrading to a paid plan also excludes AI training.
We send a regular newsletter with product updates, new features, and tips for using the platform. We use Brevo (Brevo GmbH, Berlin) to send our newsletters. Brevo processes your data on our behalf on servers within the EU. A data processing agreement pursuant to Art. 28 GDPR has been concluded. Brevo is listed in our sub-processor list.
a) Newsletter sign-up via the website: When you subscribe to our newsletter through our sign-up form, we process your email address and any voluntarily provided data (first name, last name, company name). The legal basis is your consent (Art. 6(1)(a) GDPR), which you provide through a double opt-in process.
b) Newsletter for registered customers: As a registered customer of our platform, you receive our newsletter on product-related topics. The legal basis is our legitimate interest in keeping our customers informed about product developments and relevant usage tips (Art. 6(1)(f) GDPR) in conjunction with Section 7(3) of the German Unfair Competition Act (UWG) (existing customer exception). Your email address was collected in the context of the contractual relationship and is used exclusively for information about our own similar services.
Unsubscribe: You may stop receiving the newsletter at any time by using the unsubscribe link in any newsletter email or by contacting us at privacy@liza.app. For website sign-ups, this constitutes a withdrawal of consent with future effect; for customer accounts, your unsubscription is treated as an objection pursuant to Art. 21 GDPR. Upon unsubscription, your email address will be removed from the mailing list; records of consent or objections are retained for documentation purposes.
Billing data is processed through our payment service provider. We do not store complete credit card or bank details.
To trace errors and improve usability, we record how the platform is used in the web application and in the desktop app. The iOS and Android apps are not recorded. We use the open-source software OpenReplay, which we operate ourselves on our servers at UpCloud in Frankfurt; data is transmitted via our content delivery network BunnyWay. Both are listed in the sub-processor list. We do not share recordings with the maker of OpenReplay or any other third party.
What is recorded: the structure of the pages displayed, mouse movements, clicks, scrolling and page changes, as well as technical errors and loading times. In addition: browser, operating system, device type and screen size, the approximate country and city derived from the IP address, the internal ID of your user account and a random ID that only lasts as long as the browser tab is open.
What is not transmitted: No text, input or images are transmitted. They are replaced with placeholders in your browser before any data leaves your device. The only exception are fixed navigation labels that are the same for all users, such as “Projects” or “Calendar”. Content such as messages, tasks, documents, files or contacts is not contained in the recordings, nor are your name or email address. We do not record public pages or pages whose address may contain access credentials or search terms, such as invitation and sign-in links.
Scope and retention: We may record only a randomly selected share of sessions. A recording ends after five minutes of inactivity. Recordings and the related session data are deleted automatically after 30 days, or earlier on request. Only our own team has access, and only to analyze errors and develop the platform. If an error occurs, the error report contains a link to the related recording.
Legal basis and objection: Session replay is switched on by default and only switched off at your request. The legal basis is our legitimate interest in an error-free and easy-to-use platform (Art. 6(1)(f) GDPR). You can object to recording at any time (Art. 21 GDPR): in the settings under “Account” → “Privacy” or by email to privacy@liza.app. Recording then stops immediately. We delete existing recordings immediately on request, otherwise after 30 days. The entries created in your browser's storage are listed in the Cookie Policy.
We process your data on the following bases: contract performance (Art. 6(1)(b) GDPR) for account and usage data necessary to provide the Service; legitimate interest (Art. 6(1)(f) GDPR) for security, fraud prevention, and service improvement; legal obligation (Art. 6(1)(c) GDPR) for tax and commercial retention requirements; and consent (Art. 6(1)(a) GDPR) for optional analytics and marketing communications.
We share personal data with third parties only as necessary to provide the Service. A current list of our sub-processors is available at Subprocessor List. All sub-processors are contractually bound to comply with the GDPR.
Data is processed and stored exclusively in the region selected by the Customer when creating their organization on the platform (EU, USA, or Singapore). A change of region occurs only at the Customer's explicit request. When the Customer sends messages or files to external participants located in a different region, this data is also processed and stored in the recipient's region. Where the selected region is outside the EU/EEA, we ensure appropriate safeguards under Art. 46 GDPR (e.g., Standard Contractual Clauses or an adequacy decision of the European Commission).
We retain data only as long as necessary for the respective purpose: account data for the duration of the contractual relationship, usage data for up to 90 days, session recordings (Section 2.8) for 30 days, and billing data as required by law (up to 10 years). Customer content is deleted within 30 days after contract termination, unless legal retention obligations apply.
We do not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
You have the following rights: access to your stored data (Art. 15 GDPR), rectification of inaccurate data (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection to processing (Art. 21 GDPR). You may withdraw any consent at any time with future effect.
To exercise your rights, contact: privacy@liza.app
In the event of a data breach likely to pose a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform you without undue delay where a high risk exists.
You have the right to lodge a complaint with a data protection authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
We update this Policy as needed and will notify you of material changes by email or through the platform.