Privacy Notice, Consumer Health Data Notice & Regional Privacy Addenda
Effective / Last Updated: September 27, 2026
IMPORTANT: THIS POLICY APPLIES TO ALL CURRENT AND FUTURE LIVE LIFE ALL SERVICES. IT DESCRIBES GLOBAL DATA PRACTICES AND REGIONAL RIGHTS. SERVICE-SPECIFIC CONSENTS OR NOTICES MAY PROVIDE ADDITIONAL OR MORE RESTRICTIVE PROTECTIONS.
Privacy at a Glance
On smaller screens, swipe or scroll sideways to read the full table.
| Topic | Our approach |
|---|---|
| Who controls data? | Live Life All for Company platform/administration and Company-Provided Services. Independent Vendors may be separate controllers/businesses for their own Service fulfillment. |
| What do we collect? | Account/contact, order/payment-status, communications, device/security, Vendor verification, service/task information, Customer content, and limited sensitive information only when relevant to a requested Service. |
| Medical records / HIPAA | Ordinary Services do not request or intentionally maintain medical charts, clinical records, insurance records or HIPAA-regulated PHI. Limited self-reported wellness information may still be sensitive/health data under other laws. |
| Do we sell sensitive/private Service data? | No. We do not sell Private Service Data or consumer-health information for data-broker or targeted-advertising purposes. |
| Advertising | General site analytics/advertising may be used subject to local consent/opt-out law. Sensitive/private Service areas should not be used for behavioral advertising. |
| International processing | Data may be processed in the United States and other countries used by authorized providers. We use legally required transfer safeguards where applicable. |
| Your rights | Rights vary by location and may include access, correction, deletion, portability, objection, restriction, withdrawal of consent, opt-outs and complaints/appeals. |
| Requests | Use https://livelifeall.com/contact-us/ and identify the request as a Privacy Request |
1. Scope, Company, Roles & Global Application
System Solutions Group Inc. ("Company," "Live Life All," "we," "us," or "our") operates www.livelifeall.com and related current/future websites, applications, marketplace features, accounts, digital tools and Services. The Company is based in the Federation of Saint Christopher and Nevis. Contact correspondence may be sent through the Contact Us page
This Policy applies to the Company's processing of personal information worldwide unless a more specific notice applies. Privacy law may describe us as a controller, business, responsible party, organization, agency, holder or similar term. Independent Vendors may separately control information they receive to provide their own Vendor Services and are responsible for their own lawful processing.
Where we process information only on documented instructions of another controller/business, we may act as a processor/service provider/operator and the other party's privacy notice may also apply.
2. Categories of Personal Information & Notice at Collection
On smaller screens, swipe or scroll sideways to read the full table.
| Category / examples | Examples / scope | Primary purposes | Retention criteria |
|---|---|---|---|
| Identifiers/contact | Name, email, phone, address/location at city/state/country level, account ID, usernames, organization/role. | Account, orders, support, service delivery, identity/authority, security. | Account/service life plus legal, tax, fraud, dispute and security needs. |
| Transactions/payment status | Orders, products/services, prices, invoices, payment status, refunds, chargebacks, processor references. Full card credentials are normally handled by payment processors. | Checkout, accounting, tax, fraud prevention, refunds, disputes. | As required for accounting, tax, payment disputes, fraud prevention and legal claims. |
| Communications | Support messages, service instructions, emails, texts, call/video details, recordings only where authorized. | Service fulfillment, quality, safety, support, dispute/legal record. | Purpose-based; recordings generally retained only as reasonably necessary or as disclosed. |
| Private Service Data | Business records, task files, CRM/contact data, property/admin information, relationship/family information, safety concerns, limited wellness/routine information, private documents and other information voluntarily supplied for a Service. | Perform requested Service, coordinate authorized recipients/providers, quality/safety, legal compliance. | Minimized to Service/legal need; sensitive material deleted/de-identified when no longer reasonably needed unless retention is lawful/required. |
| Vendor/business verification | Business name, identity/contact, payment/payout details, registrations, licenses, tax identifiers, insurance/compliance information. | Marketplace KYC, payout, tax, fraud, DSA/marketplace compliance. | Contractual relationship plus legally required retention. |
| Device/usage/security | IP address, device/browser, timestamps, pages, cookies/identifiers, authentication, logs, approximate location inferred from IP. | Operate site, security, analytics, fraud, preferences, legally permitted advertising. | Typically shorter technical periods unless needed for security/fraud/legal purposes. |
| Sensitive data | Only when relevant/voluntarily provided: health/wellness, biometric data if a future feature specifically uses it, race/ethnicity/religion, sexual orientation, criminal allegations, precise geolocation or similar legally sensitive categories. | Only for disclosed Service, safety, legal or consented purposes and with an appropriate legal basis. | Minimum necessary; heightened controls and deletion when no longer needed, subject to law. |
We do not intentionally collect more personal information than reasonably necessary for the disclosed purpose. If information is optional, refusal may limit only the feature that reasonably needs it. Do not send passwords, PINs, full payment-card details, government ID numbers, private keys, complete medical records, or other unnecessary high-risk credentials through ordinary service channels.
3. Sources of Personal Information
- You directly, including account creation, checkout, service forms, communications, files, recordings, consent choices and privacy requests.
- Purchasers, authorized representatives, family/household participants, business contacts or other people who lawfully provide information about you for a Service.
- Independent Vendors/Fulfilling Providers and contracted processors involved in orders, support, payments, communications, security and service administration.
- Public or business sources where lawful, such as company websites, professional directories, property/business records or lead sources supplied for a legitimate task.
- Automatically from devices, browsers, cookies, logs and security systems.
- Third-party platforms/integrations you choose to connect or authorize.
When applicable law requires notice because we obtained personal information indirectly, we will provide the required notice within the legally applicable period unless an exception applies.
4. Purposes & Lawful Bases
We process personal information for the following purposes, using one or more lawful bases recognized in the relevant jurisdiction: performing a contract or requested pre-contract steps; consent; legitimate/business interests balanced against individual rights; compliance with legal obligations; protection of vital/safety interests; fraud/security; establishment/exercise/defense of legal claims; and other bases permitted by local law.
- Provide, personalize, schedule, route, administer and support Services and marketplace transactions.
- Process payments, refunds, credits, accounting, tax, Vendor payouts and fraud/chargeback controls.
- Authenticate users, verify authority/Vendors, secure accounts, detect abuse and investigate incidents.
- Communicate about orders, service status, support, safety, privacy, security and administrative matters.
- Improve Services, quality, reliability, training, analytics and product design using data appropriate for that purpose.
- Enforce Terms, protect users and platform reputation/integrity, investigate complaints and defend legal rights.
- Send marketing only where permitted, with required consent/relationship basis and opt-out mechanisms.
- Comply with lawful requests, court orders, regulators, sanctions, taxation, marketplace and consumer-protection obligations.
Where consent is the legal basis, it is voluntary and may be withdrawn prospectively. Withdrawal does not make prior lawful processing unlawful. Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact on individual rights. Where local law requires explicit consent for sensitive/special-category data, we seek it before that processing unless another lawful exception applies.
5. Marketplace Vendors, Fulfilling Providers & Authorized Recipients
We may disclose information reasonably necessary to the assigned Fulfilling Provider. An independent Vendor may be a separate controller/business/responsible party and is responsible for its own personnel and privacy compliance. Company personnel and processors may access information needed for Company-Provided Services and platform administration.
Authorized Recipient sharing. For a personal or multi-participant Service, we disclose non-public information to family, caregivers, spouses/partners, representatives, business contacts or other recipients only when the Service Recipient/authorized representative has directed or authorized the sharing, or when law otherwise permits/requires it. Participation in the same Service does not automatically grant access to another participant's private information.
Vendors and processors are not authorized by Live Life All to use Private Service Data for unrelated marketing, data brokerage, off-platform prospecting or independent general-purpose AI model training. Contractual restrictions apply where appropriate and legally required.
6. Sensitive Information, Consumer Health Data & Medical-Record Boundary
MEDICAL RECORDS / HIPAA: ORDINARY LIVE LIFE ALL SERVICES DO NOT REQUEST OR INTENTIONALLY CREATE OR MAINTAIN CLINICAL MEDICAL RECORDS OR HIPAA-REGULATED PHI. DO NOT SUBMIT MEDICAL CHARTS, LAB/IMAGING REPORTS, INSURANCE RECORDS OR COMPLETE PRESCRIPTION HISTORIES UNLESS A SEPARATE LAWFUL SERVICE EXPRESSLY REQUIRES THEM.
Some Services may involve limited voluntarily provided wellness/routine information, safety concerns, relationship/family information or other sensitive data. Such information may be protected even when HIPAA does not apply. We treat covered consumer-health/wellness information and other sensitive Service data as restricted data and use it only for the requested Service, authorized safety/recipient sharing, security, legal compliance or other specifically disclosed lawful purposes.
We do not sell consumer-health data or Private Service Data for data-broker purposes or use it for targeted/behavioral advertising. We do not use prohibited health-related geofencing. If a U.S. state consumer-health law requires separate collection or sharing consent, a separate consent/service form is used. If a future Service intentionally creates a personal health record or similar product within the FTC Health Breach Notification Rule, we will apply that rule to the extent it legally applies.
Biometrics. Standard Services do not use facial recognition, voiceprint recognition, fingerprints, iris/retina scans or biometric templates for identification/authentication. A future biometric feature will receive any separate notice, consent/release, retention/destruction disclosure and security treatment required by applicable law before activation.
7. Cookies, Analytics, Advertising & Tracking Choices
We may use necessary cookies and similar technologies for login, security, checkout, preferences, fraud prevention and core functionality. We may also use analytics, personalization and advertising technologies on general site pages where permitted.
Where UK/EU/EEA or other law requires consent before non-essential cookies or similar tracking, those technologies should remain off until valid consent is obtained, except for any legally recognized exemption. Users may change cookie choices through available preference controls. Browser/device privacy signals are honored where legally required, including qualifying U.S. universal opt-out signals.
Sensitive/private Service pages should not be used to send consumer-health, relationship/family, private task content or recordings to advertising networks for behavioral advertising. Marketing suppression/opt-out requests are respected under applicable law, including CASL, PECR/UK rules, EU ePrivacy/national rules, Australia's Spam Act, South Africa POPIA/CPA rules and comparable local laws.
8. AI, Automated Tools & Profiling
We or authorized providers may use automation/AI for scheduling, drafting, transcription/summarization, organization, customer support, quality, fraud/security, analytics and service assistance. Automated outputs may be inaccurate and require human review. Unless separately disclosed and lawfully authorized, Private Service Data and sensitive/consumer-health data are not knowingly provided to unrelated general-purpose AI services for the provider's independent model training.
We do not ordinarily make solely automated decisions that produce legal or similarly significant effects about consumers. If a future Service does so, we will provide the notices, lawful basis, safeguards, human-review/contest rights and opt-outs required by applicable law.
9. How We Disclose Personal Information
- Fulfilling Providers/Vendors and Company personnel for the requested transaction or Service.
- Processors/service providers for payment, forms/e-signature, hosting, storage, communications, telephony, video, support, security, analytics, fraud prevention, tax/accounting and other operations.
- Authorized Recipients selected by a Service Recipient or authorized representative.
- Professional advisers, auditors, insurers, financing counterparties and transaction counterparties under confidentiality or legal controls where appropriate.
- Authorities, courts, regulators, law enforcement, protective services or others when required or permitted by law, valid legal process, safety, fraud, sanctions, rights protection or legal claims.
- A purchaser/successor in a merger, financing, reorganization or sale, subject to applicable notice, consent and data-protection requirements.
We do not disclose personal information merely because someone claims to be a spouse, partner, family member, manager, purchaser or colleague. We may verify identity and authority before disclosure.
10. International Transfers & Cross-Border Processing
Information may be processed in the Federation of Saint Christopher and Nevis, the United States and other countries where authorized Vendors/processors operate. Privacy laws may differ from the law in your country. We use safeguards required for the particular transfer, which may include adequacy decisions, controller-processor terms, EU Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, Brazil ANPD-recognized transfer mechanisms, New Zealand model clauses/comparable safeguards, contractual accountability measures, or another legally recognized basis.
EEA/UK. Where a restricted transfer lacks an adequacy route, we use an appropriate Article 46 safeguard and any legally required transfer-risk assessment/supplementary measures. Canada. We remain accountable for personal information transferred to processors where PIPEDA or applicable provincial law requires comparable protection. Australia. Where APP 8 applies, we take reasonable steps regarding overseas recipients unless a lawful exception applies. New Zealand. Where Privacy Principle 12 applies, we use comparable safeguards or another lawful basis. South Africa and Latin America. We apply any adequacy, contractual, consent, registration, localization or transfer-notice requirements that apply in the relevant jurisdiction.
You may request information about applicable transfer safeguards through the Contact Us process. We may redact confidential commercial/security information where law permits.
11. Data Retention, Deletion & Record Preservation
We retain personal information only as long as reasonably necessary for the disclosed purpose, Service/account relationship, tax/accounting, payments/chargebacks, legal claims, fraud/security, regulatory obligations, consent records and legitimate business recordkeeping. Retention varies by data category, jurisdiction and dispute/legal hold. We delete, de-identify or securely dispose of information when no longer reasonably needed, subject to backups and legal exceptions.
A deletion request does not require deletion of information we are legally required or permitted to retain for tax, accounting, fraud, security, legal claims, regulatory obligations, suppression lists, evidence of consent/withdrawal, or protection of another person's rights. Access to retained data is limited according to purpose and role.
12. Security & Incident/Breach Response
We use reasonable administrative, technical and organizational safeguards appropriate to the sensitivity, amount and context of the data, which may include access controls, role restrictions, authentication, encryption in transit or at rest where appropriate, vendor controls, logging, backups, staff confidentiality and incident-response procedures. No internet, cloud, email, SMS, device or storage system can be guaranteed completely secure.
If a security incident occurs, we assess scope, containment, risk, legal obligations and remediation. We notify affected individuals, regulators, law enforcement or others when required by applicable law and within the legally required time. We may maintain legally required incident registers, including under jurisdictions such as Quebec or South Africa.
13. Global Privacy Rights & Request Process
Depending on location and law, you may have rights to know/confirm processing, access, correct, delete/erase, restrict, object, withdraw consent, data portability, opt out of sale/sharing/targeted advertising/profiling, request information about recipients or data sources, use an authorized agent, appeal a denial, or complain to a regulator. Rights and exceptions vary by jurisdiction and lawful basis.
Submit requests through https://livelifeall.com/contact-us/ and identify the request as a "Privacy Request,". Include enough information to verify identity and identify the relevant account/interaction, plus country/state/province of residence. Do not send passwords, full card numbers or unnecessary government/medical records. We may request proportionate verification and authority documentation. We respond within applicable legal deadlines and explain any lawful denial/appeal route.
We will not unlawfully discriminate or retaliate because you exercise a privacy right. A Service may become unavailable if the data you ask us not to process is objectively necessary to perform that Service and no lawful alternative exists.
14. United States Addendum
14.1 State privacy rights
Where a U.S. state privacy law applies, residents receive the rights required by that law, potentially including access/know, correction, deletion, portability, opt-out of sale/sharing/targeted advertising or qualifying profiling, sensitive-data limits/consent, authorized-agent rights, appeals and recognition of legally required universal opt-out signals. Definitions, thresholds, exemptions and response periods vary by state.
14.2 California
If the California Consumer Privacy Act/CPRA applies, California residents receive applicable rights to know/access, correct, delete, opt out of sale/sharing, limit qualifying sensitive-personal-information uses, and non-discriminatory treatment. We do not sell Private Service Data or consumer-health data and do not share such data for cross-context behavioral advertising. If other site data is sold/shared as legally defined, we provide the legally required opt-out mechanism and honor qualifying Global Privacy Control signals.
14.3 Consumer health data
Where Washington My Health My Data, Nevada consumer-health-data law or a similar law applies, covered consumers may have rights to confirm, access, delete, withdraw consent and obtain recipient information, plus separate collection/sharing consent where required. We do not authorize sale of consumer-health data without any separate statutory authorization the law requires and do not use prohibited health-related geofencing.
15. Canada Addendum
Where PIPEDA applies, we follow accountability, identifying purposes, meaningful consent where required, limiting collection/use/disclosure/retention, accuracy, safeguards, openness, individual access/correction and complaint-handling principles. Personal information transferred to processors remains subject to accountability and contractual or other comparable protections.
Provincial laws, including private-sector privacy laws in British Columbia, Alberta and Quebec, may apply instead of or alongside PIPEDA. Where Quebec law applies, we provide required transparency, consent/withdrawal information, privacy-impact assessments for applicable transfers/projects, incident handling, access/correction and other Law 25 protections. Commercial electronic marketing follows CASL consent, identification and unsubscribe requirements where applicable.
16. United Kingdom & EEA/EU Addendum (including Spain and Ireland)
If UK GDPR or EU GDPR applies because we offer Services to or monitor people in the relevant territory, we process personal data on one or more lawful bases such as contract, consent, legal obligation, legitimate interests, vital interests or another legally available basis. For special-category data, we also identify a valid additional condition where required.
Applicable rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, safeguards regarding qualifying automated decisions, and complaint to the relevant supervisory authority. The right to object to direct marketing is absolute under applicable GDPR rules. Non-essential cookies/trackers are subject to PECR/ePrivacy/national cookie law and consent requirements except recognized exemptions.
International transfers outside the UK/EEA use adequacy or appropriate safeguards such as EU SCCs or the UK IDTA/Addendum as applicable. Where Article 27 requires an EU or UK representative because of our targeted activity, representative contact details will be published in this Policy or a linked regional notice before or when the obligation applies.
Spain. Spanish users also receive protections under Spanish data/e-commerce law, including applicable LSSI requirements for electronic commerce, cookies and commercial electronic communications. Where local law requires Spanish-language disclosures, a Spanish version or regional notice will be provided.
17. Australia Addendum
Where the Privacy Act 1988 and Australian Privacy Principles apply, we handle personal information under the APPs, including collection notice, use/disclosure limits, quality, security, access/correction, direct-marketing opt-outs and cross-border disclosure obligations. Sensitive information is collected/used only with consent or another lawful exception. Where APP 8 applies, we take reasonable steps to ensure overseas recipients do not breach the APPs unless an exception applies.
Commercial electronic messages and calls are handled under the Spam Act, Do Not Call rules and other applicable Australian law. Australian Consumer Law rights are addressed in the Terms and are not limited by this Privacy Policy.
18. New Zealand Addendum
Where the Privacy Act 2020 applies, we follow the Information Privacy Principles, including purpose/minimization, notice, security, access/correction, retention limits and lawful disclosure. If personal information is collected indirectly, we provide the notice required by Information Privacy Principle 3A where applicable. For overseas disclosures covered by Principle 12, we use comparable safeguards or another lawful basis and provide any required express warning if relying on individual authorization.
19. South Africa Addendum
Where POPIA applies, we process personal information lawfully and reasonably, for specific purposes, with appropriate notice, minimization, security, data-subject access/correction/deletion/objection rights and cross-border safeguards. Special personal information receives heightened protection. Direct marketing by unsolicited electronic communication is conducted only with consent or an applicable existing-customer basis and includes legally required opt-out mechanisms. Security compromises are handled under applicable Information Regulator requirements.
20. Latin America Addendum
Latin American data-protection and consumer laws differ by country. Where applicable, we honor local transparency, consent, ARCO/data-subject rights, security, marketing, breach, registration and international-transfer requirements. This includes, as applicable, Brazil LGPD/ANPD rules, Mexico LFPDPPP, Argentina Law 25.326, Colombia Law 1581, Peru Law 29733 and its regulations, Chilean privacy law (including Law 21,719 from its effective date), and other national laws.
20.1 Brazil
Brazilian data subjects may have rights to confirmation/access, correction, anonymization/blocking/deletion, portability, information about sharing, consent withdrawal and review/other rights under the LGPD. International transfers use a lawful LGPD mechanism, including ANPD-recognized standard clauses or another permitted basis where applicable. Brazilian transfer disclosures and required information will be made available in Portuguese when Brazil is targeted and the rules require it.
20.2 Mexico, Argentina, Colombia, Peru & Chile
Mexico: applicable holders receive ARCO and other rights under the current private-sector data law and the privacy notice/transfer rules that apply. Argentina: access, rectification, update/suppression and international-transfer safeguards apply where required. Colombia: authorization, access/update/correction/deletion and complaint rights apply where required. Peru: ARCO rights and informed transfer/cross-border safeguards apply where required. Chile: existing law applies until replaced/amended; Law 21,719 is scheduled to take effect December 1, 2026 and adds rights including access, rectification, suppression, objection, portability and blocking.
21. Children & Minors
General Services are intended for adults and are not directed to children unless a specific Service expressly states otherwise and is designed with the required parental/guardian consent, age-appropriate notices and protections. We do not knowingly use children's sensitive/private Service data for targeted advertising. If we learn that data was collected from a child contrary to applicable law, we take reasonable steps to delete or regularize it as required.
22. Language, Accessibility & Changes
This English Policy is the global master. We may publish translations for convenience or to meet local law. Where local law requires a translated/local-language privacy notice, that version controls to the legally required extent. We aim to provide notices in clear, understandable language and in accessible formats as reasonably required.
We may update this Policy prospectively. The posted date identifies the current version. Material changes receive any additional notice/consent required by law. A policy update does not retroactively authorize materially broader sensitive-data processing when fresh consent is legally required.
23. Contact, Complaints & Regulators
System Solutions Group Inc. / Live Life All
Online: https://livelifeall.com/contact-us/
Website: www.livelifeall.com
Address unmonitored is: 25 First Ave SW, STE A, Watertown, SD 57201, USA. Do not send correspondence to the physical address, all correspondence and communications to be handled via the online method specified above.
You may submit privacy complaints through the same channel. We will acknowledge and handle complaints as required by applicable law. You may also complain to the privacy/data-protection authority in your jurisdiction, including the U.S. state authority where applicable, Office of the Privacy Commissioner of Canada/provincial regulator, UK ICO, relevant EEA supervisory authority, OAIC (Australia), New Zealand Privacy Commissioner, South Africa Information Regulator, or applicable Latin American authority.
Where local law requires a Data Protection Officer, EU/UK representative, Information Officer, privacy officer or other designated contact, we will publish the relevant contact details in this Policy or a linked regional notice before or when the obligation applies.
24. Relationship to Other Notices & Consents
This Policy is a general privacy notice, not a blanket consent to sensitive processing. Service-specific consent/authorization forms, cookie banners, marketing consents, Vendor notices, biometric notices, consumer-health notices, data-processing agreements and checkout disclosures may supplement this Policy. Where a service-specific notice gives narrower permissions, the narrower permission controls for that processing. Mandatory law controls over all documents.