Live Agent Pro Privacy Policy
Effective Date: July 22, 2026 Last Updated: July 22, 2026
1. Introduction
This Privacy Policy describes how Pelton Solutions LLC, a Michigan limited liability company doing business as Live Agent Pro ("Live Agent Pro," "we," "us," or "our"), collects, uses, and discloses information when you use our website, software-as-a-service platform for live-streaming talent agencies, host portal, mobile application, messaging tools, and related services (collectively, the "Service").
This Policy is incorporated into our Terms of Service. Defined terms have the meanings given in the Terms.
The Service is offered to business customers who are at least 18 years old. Hosts must also be at least 18 years old. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the Service is not offered to you; please do not provide us with personal information.
2. Who This Policy Covers — Agencies, Staff, and Hosts
Three groups of people interact with the Service, and they stand in different relationships to us. This Policy addresses all three.
- Agencies and their staff. The talent agency that subscribes to the Service (the "Agency") is our customer, and the Agency's administrators, managers, and recruiters ("Staff") are its authorized users. For Agency account, Staff, billing, and usage information, we act as the controller (or "business" under U.S. state privacy laws) and this Policy describes our own practices.
- Hosts / talent. The live-streaming creators an Agency recruits and manages ("Hosts") are, first, data subjects of the Agency: the Agency decides what Host information to collect and how to use it, and the Agency is the controller of Host records; we process that data on the Agency's behalf as a processor / service provider under our Data Processing Addendum.
- Hosts as direct users. Hosts also log in directly to a portal and mobile app that we operate. For the data generated by that direct relationship — portal and app login credentials, sessions, device identifiers, push notification tokens, and app usage records — we determine the means of processing and act as controller. A separate, Host-oriented summary of these practices is provided in our Host Privacy Notice; where the two documents overlap, they are intended to describe the same practices.
This Policy also covers applicants — members of the public who submit an Agency's application form — and visitors to liveagentpro.com and our marketing and documentation pages.
If you are a Host or applicant and you have a question or request about your information, Section 15 explains how to raise it: in most cases your Agency is the right first contact, and we will assist it.
3. Information We Collect
3.1 Agency and Staff Information (We Are the Controller)
- Account and Staff information. Each Staff member's name, nickname, email address, email-verification timestamp, avatar, locale and timezone preferences, email signature, role and permission assignments, and a password (stored only in hashed form).
- Security credentials. As security features, Staff may enable two-factor authentication and passkeys. When enabled, we store the two-factor secret and recovery codes, and the public-key credential for each registered passkey. These are used solely to authenticate the Staff member and secure the account.
- Billing information. The Agency's billing contact and subscription details. Payment card details are collected and stored by our payment processor, Stripe; we never receive or store full card numbers — only Stripe customer, subscription, and price identifiers, card brand and last four digits, and limited billing metadata.
- Agency configuration. Subdomain, active platforms, branding, custom domain settings, messaging settings, and — where the Agency connects its own accounts — the Agency's WhatsApp Business credentials, TikTok connections, and email provider API keys (see Section 5).
- Support and feedback. Information you submit when you contact support, request features, or otherwise interact with us.
3.2 Host and Applicant Information (The Agency Is the Controller)
Agencies collect and manage a rich set of personal information about their Hosts within the Service. We store and process it on the Agency's instructions. It includes:
- Host profile data. First and last name, email address, phone number (used for WhatsApp messaging), date of birth (also used for automated birthday greetings), gender, Instagram handle, preferred contact method, language (English, Spanish, or Brazilian Portuguese) and timezone preferences, and platform usernames and statuses.
- Brazilian payment identifiers. For Agencies operating in Brazil: the Host's CPF (Brazilian taxpayer identification number), PIX key and PIX key type (which may itself be a CPF, phone number, or email address), and a free-text payout address. These are stored for the Agency's compensation record-keeping; we do not move money to Hosts (see Section 3.4).
- Custom fields. Agencies can define their own additional data fields for Host records. The Agency controls what those fields contain; our Acceptable Use Policy prohibits placing special-category data (such as health, biometric, or religious information) in them.
- Application-form submissions. Agencies can publish public application forms. Anyone who submits one provides their name, email, phone number, date of birth, and answers to whatever custom questions the Agency configured — this is personal information collected from members of the public who have no account. Applications, including rejected applications and the rejection reason, are retained in the Agency's account.
- Staff notes, tasks, and onboarding records. Free-text notes Staff write about a Host, follow-up tasks, monthly targets, onboarding progress, and event attendance / RSVP records.
- Documents and media. Files the Agency uploads (such as CSV stat reports) and images associated with Host records.
- Generated profile photos. The Service can composite a Host's photo onto Agency-branded templates. Generated and published images are intended for sharing and are publicly accessible to anyone who has the URL. Do not use this feature for images you are not prepared to make public. Other uploaded documents and private media are stored in access-controlled storage.
3.3 Performance and Earnings Data
The Service records per-Host, per-period performance statistics from the streaming platforms the Agency works with (follower and following counts, likes, video and live counts, live views, peak viewers, and diamonds earned — the platforms' revenue currency), whether synced automatically, entered manually, or imported from CSV. From these, the Service derives monthly statements showing diamonds, live hours, valid days, the assigned compensation tier, calculated payout amount, payout method, payment date, and recruiter commission. This is, in substance, earnings and productivity data about individual Hosts, and we treat it accordingly: it is processed only on the Agency's behalf and is never used by us for our own marketing or profiling.
Leaderboards and Hall of Fame. The Service includes a leaderboard (current-month diamond ranking) and a Hall of Fame (all-time diamond ranking), each scoped to the viewing Host's own platform and sub-agency. This means a Host's performance ranking is visible to peer Hosts within the same Agency. The Agency chooses to use these features; Hosts are informed of this visibility in the Host Privacy Notice.
3.4 Points, Missions, and Rewards
Agencies may award points (labelled "Sparks" by default) to Hosts and offer a rewards store. We record the associated data: points wallets and transaction ledgers (including expiry dates), mission progress, level assignments, reward redemptions (including the Staff member who approved or rejected each one), and inactivity-rule applications. Points are an Agency-administered loyalty mechanic with no cash value; we act as record-keeper only, and the Agency is responsible for fulfilling rewards. Similarly, monthly statements record payout amounts and methods for the Agency's books, but we do not disburse funds to Hosts and are not a payment processor or money transmitter for Host payouts.
3.5 Communications Content
The Service is a messaging platform, and message content is stored in full:
- WhatsApp messages. The complete body of every WhatsApp message sent or received through the Service, in both directions, together with the phone numbers involved, delivery and read status, the template used, and the attributed sender. Inbound media attachments are downloaded and stored. Messages from unknown senders are retained as prospect conversations unless blocked.
- Email messages. The complete body (including HTML) of every email sent through the Service and — for Agencies using our managed sending domain — every inbound reply, stored in full. Because anyone can reply to or email an Agency's managed address, this means we store message content from third parties who have no account with us or with the Agency. If you email an Agency through the Service, your message content, email address, and related metadata are stored in that Agency's account.
- Conversation and deliverability records. Conversation threading and participants; blocked-number lists (with reason and who blocked); email suppression lists (bounce, complaint, or manual, with reason and source); and bounce, complaint, and delivery telemetry used to protect deliverability.
3.6 Technical, Session, and Device Information
- Sessions. For signed-in Staff and Hosts we record session identifiers, the associated user, IP address, browser user-agent string, and last-activity time.
- Policy acceptances. Each time a legal document is accepted, we record the document, its version, the timestamp, the acceptance context (for example, registration or checkout), and the IP address and user agent at the moment of acceptance. This record is kept as evidence of consent.
- Mobile app and push notifications. When a Host uses the mobile app, we store API access tokens (expiring after approximately 30 days and pruned automatically), the push notification token for each registered device and its platform (iOS or Android), and, for each push notification, its content, delivery status, and whether and when it was opened.
- Audit trail. The Service keeps an append-only change history of records in an Agency's account, retaining prior values of changed fields so Agencies can review and undo changes. This means that when a record is corrected or a field is removed, the previous value remains visible in the account's audit trail for integrity, security, and fraud-prevention purposes while the account is active. The audit trail is deleted together with the Agency's account (see Section 9).
- Diagnostic and error data. When the Service encounters an error, we capture diagnostic information through our error-monitoring provider, Sentry. This may incidentally include request details associated with the error. We use it only to detect, investigate, and fix problems.
3.7 What We Do Not Collect
- The Service is not directed to minors. Staff and Hosts must be 18 or older, and Agencies must not use the Service to manage anyone under 18. See Section 14.
- We do not intentionally collect biometric or genetic identifiers, precise geolocation (beyond what an IP address incidentally implies), health data, or other special categories of data, and the Acceptable Use Policy prohibits Agencies from putting such data into the Service.
- We do not use third-party advertising cookies or cross-site tracking technologies in the Service.
4. How We Use Information
We use the information described in Section 3 to:
- Provide the Service — operate the Agency panel, host portal, and mobile app; store and display Host records, statistics, statements, and points; generate profile photos; and run the features the Agency configures;
- Send and receive messages — deliver WhatsApp messages, emails, campaigns, automated greetings and alerts, and event reminders that the Agency triggers; thread inbound replies into conversations; and maintain suppression and blocked-number lists to honor opt-outs and protect deliverability;
- Bill the Agency and process payments — charge the payment method on file via Stripe, send receipts, and manage trials, renewals, refunds, and disputes;
- Authenticate and secure accounts — verify credentials, operate two-factor authentication and passkeys, manage sessions and API tokens, and detect suspicious sign-ins;
- Communicate with you — service announcements, security and account notices, support responses, and (where permitted) marketing emails (see Section 13);
- Improve the Service — diagnose issues, analyze performance, and develop new features;
- Maintain security and integrity — detect and prevent fraud, abuse, account takeover, spam, and other harm, including through the audit trail and policy-acceptance records; and
- Comply with legal obligations and enforce our agreements — including tax record-keeping, responses to legal process, and enforcement of the Terms and Acceptable Use Policy.
Host and applicant data that we process on an Agency's behalf is used only for the purposes above as directed by the Agency — never for our own advertising, and never sold. We do not sell personal information for monetary consideration. See Sections 11 and 12 for jurisdiction-specific definitions and rights.
5. Agency-Connected Accounts and Bring-Your-Own Credentials
A distinctive feature of the Service is that Agencies connect their own third-party accounts, and data then flows to those third parties at the Agency's direction. These disclosures are directed by the Agency, and the third party's own terms and privacy policy govern its handling of the data:
- Meta / WhatsApp. The Agency connects its own Meta WhatsApp Business account (phone number ID and access token). When the Agency sends or receives WhatsApp messages through the Service, Host phone numbers and full message content flow to Meta Platforms via the WhatsApp Cloud API, in both directions. Meta's terms and privacy policy apply to Meta's processing.
- TikTok. Hosts may authorize a per-Host TikTok connection (OAuth). We receive the Host's TikTok display name, bio, avatar URL, and follower / following / likes / video counts under the basic profile and stats scopes, and we store the associated access and refresh tokens in encrypted form. TikTok's terms and privacy policy apply to TikTok's processing.
- Agency email providers. An Agency may bring its own email provider (such as Postmark, Resend, or its own SMTP server) by supplying its own API key or credentials. Mail the Agency sends then leaves through that provider under the Agency's own contract with it — these providers are Agency-directed recipients, not our sub-processors. Alternatively, the Agency may use our managed sending domain, in which case mail is delivered through Amazon SES as described in Section 6.1.
The Agency warrants that it is authorized to connect these accounts, and we act on the Agency's behalf when using them. Stored credentials for connected accounts (WhatsApp access tokens, email API keys, TikTok tokens) are held in encrypted form in our database (see Section 10).
White-label domains. Agencies on eligible plans may serve the host portal from their own custom domain, where the Live Agent Pro brand may not be visible. In that case the Agency is required to present its Hosts with the privacy notices this Policy and the Terms require — including disclosure of our role and our sub-processors — so that Hosts receive the information this Policy provides even when they never see our brand.
6. How We Share Information
We disclose information in the following situations.
6.1 Service Providers and Sub-Processors
We use third-party vendors to operate the Service. These vendors process information only on our instructions and under contractual obligations to protect it. Our principal sub-processors are:
- Amazon Web Services (AWS) — cloud infrastructure in the United States: application hosting, databases, cache, file and media storage, secrets management, DNS, and email delivery (Amazon SES). Our primary deployment is in one U.S. region; inbound email receiving runs in a second U.S. region, where raw inbound messages are received and stored before processing;
- Stripe — payment processing and subscription billing;
- Meta Platforms — WhatsApp Cloud API message transmission (using the Agency's own WhatsApp Business account, as described in Section 5);
- TikTok — Open API statistics retrieval under per-Host authorization (Section 5);
- Google — reCAPTCHA on our registration page (Section 8);
- Sentry — application error and performance monitoring; and
- Expo and/or Firebase Cloud Messaging (Google) — delivery of mobile push notifications (device push tokens and notification payloads).
A current, detailed list is maintained in our Sub-Processor List, which we update as our vendors change. Email providers the Agency brings itself (Section 5) are Agency-directed and are noted, rather than listed as sub-processors, on that list. We also use Slack internally for operational alerts to our own team; it is not used to process Agency or Host records.
6.2 At the Agency's Direction
Because we process Host and applicant data on the Agency's behalf, we disclose it as the Agency instructs — for example, by sending the messages the Agency composes, exporting the Agency's contacts, or transmitting data through the accounts the Agency has connected under Section 5.
6.3 Legal Process and Safety
We may disclose information when we believe in good faith that disclosure is required or appropriate to (a) comply with applicable law or legal process; (b) protect the rights, property, or safety of Live Agent Pro, our customers, Hosts, or the public; (c) detect, prevent, or investigate fraud, security, or technical issues; or (d) enforce our Terms or other agreements. Where we receive legal process directed at Host data we process for an Agency, we will notify the Agency unless legally prohibited.
6.4 Business Transfers
If Pelton Solutions LLC is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
6.5 Aggregated and De-Identified Information
We may share aggregated or de-identified information that cannot reasonably be used to identify you for any purpose.
7. Our Role for Host and Applicant Data; the DPA
For Host records, applicant submissions, message content, statistics, statements, points, and everything else an Agency puts into or generates within its account, the Agency is the controller and we are the processor / service provider. In practical terms:
- The Agency determines what Host and applicant data is collected (including through custom fields and application-form questions), how long it is kept within the account, who on its Staff can see it, and which messaging and gamification features to use.
- The Agency is responsible for having a lawful basis for that processing, for providing Hosts and applicants with its own privacy notice, for obtaining and maintaining any required messaging consents (WhatsApp, SMS, email) and honoring opt-outs, and for complying with the privacy laws that apply to it — including the LGPD for Brazilian Hosts.
- We process this data only to provide the Service as described in this Policy and the Data Processing Addendum, which incorporates our Sub-Processor List. We do not use Host or applicant personal information for our own marketing, profiling, or other independent purposes.
- If a Host or applicant contacts us directly with a request about data an Agency controls, we will generally redirect the request to the Agency as the responsible party and assist the Agency in fulfilling it. Section 15 explains this in more detail; the exception is data for which we are ourselves the controller (Section 2), which we handle directly.
8. Cookies and Similar Technologies
Live Agent Pro uses a minimal set of technologies and does not use advertising or cross-site tracking cookies anywhere in the Service.
- Strictly necessary (first-party). A session/authentication cookie, a CSRF-protection token, and an optional "remember me" cookie keep you securely signed in. These cannot be turned off without breaking the Service.
- Google reCAPTCHA (third-party). Our Agency registration page uses Google reCAPTCHA to prevent automated abuse. reCAPTCHA is a Google service that sets its own cookies and collects the visitor's IP address and interaction signals, which are sent to Google and processed under Google's privacy policy. It runs only on the registration page, not throughout the Service.
- Mobile app. The mobile app does not use cookies; it authenticates with an API token stored in the device's secure keychain and uses the push notification token described in Section 3.6.
Because we do not engage in cross-context behavioral advertising and do not "sell" or "share" personal information in the advertising sense, a consent banner is generally not required for our own technologies, and there is no sale or sharing for a browser opt-out signal such as Global Privacy Control (GPC) to opt out of. You can manage cookies through your browser settings, though disabling strictly necessary cookies will prevent the Service from working.
9. Data Retention
We retain personal information for as long as we need it to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific practices include:
- Agency accounts and everything in them. Retained for the life of the Agency's account. On cancellation or termination, access to the Service ends and the Agency has an approximately 30-day grace period to export its data (a contacts CSV export remains available even to lapsed accounts, and a fuller export is available on request). After that period we permanently delete the Agency's account and its contents — including Host records, applications, messages, statements, points ledgers, and the audit trail — from active systems. Residual copies in the encrypted database backups described in Section 10 age out on their retention cycle (approximately 30 days).
- Audit trail. While an account is active, prior values of changed or deleted fields remain in the account's audit trail for integrity, security, and fraud prevention. Correcting or deleting a record does not scrub its history. The audit trail is deleted along with the account as described above.
- Verified deletion requests. Honored within 45 days of verification (with one 45-day extension where the law allows), subject to the exceptions described in Sections 11 and 12 and to records we are legally required to keep.
- Financial records survive an individual deletion. When an individual Host's data is erased at their request while the Agency's account remains open, we anonymize the Host: identity and contact fields (name, email, phone, date of birth, gender, social handles, CPF, PIX key, payout address, notes, custom fields, message content, and photos) are removed or irreversibly redacted, while the financial and transaction records the Agency needs for its own tax, accounting, and audit obligations are retained in de-identified form — monthly statements, payout amounts, methods and dates, commission calculations, and points-ledger entries, linked to a non-identifying reference rather than to the person. This is a legal-obligation exception permitted by U.S. state privacy laws and LGPD Article 16, and it is limited to what those record-keeping duties require. Full erasure of these records happens when the Agency's account is deleted.
- Billing and tax records. Retained for the period required by applicable tax and financial regulations (typically about seven years in the U.S.), even after account closure.
- Policy acceptances. Consent records are retained as evidence of acceptance for as long as reasonably necessary to demonstrate compliance.
- Sessions and tokens. Web sessions expire after a period of inactivity; mobile API tokens expire after approximately 30 days and are pruned automatically.
- Email deliverability events. Bounce, complaint, and suppression-list records are retained to protect ongoing deliverability and to keep honoring opt-outs.
- Points. Unspent points may expire on the schedule the Agency configures.
- Diagnostic/error data, infrastructure logs, and support communications. Retained for a limited period reasonably needed to investigate issues, handle disputes, and improve the Service.
When we no longer need information, we delete or de-identify it, except where law or contractual obligation requires continued retention.
10. Security
We use reasonable administrative, technical, and physical safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include:
- TLS encryption in transit for the web application, host portal, mobile API, and connected third-party APIs, and DKIM / SPF / DMARC authentication on outbound managed email;
- multi-factor authentication (TOTP with recovery codes) and passkeys (WebAuthn) available to all Staff accounts;
- encrypted storage of connected-account credentials — Agency WhatsApp access tokens, email provider API keys, and per-Host TikTok tokens are encrypted at the application layer before being written to the database;
- logical tenant isolation — each Agency's data is logically separated per tenant within shared infrastructure, enforced at the application layer on every query, with cross-tenant access limited to authorized Pelton Solutions personnel for support and maintenance, on a least-access basis. Every request such personnel make is recorded — who, when, which Agency, and what was requested — in an append-only support-access log, so we can answer after the fact who looked at a given Agency's records;
- encryption at rest — the database is encrypted at rest, and uploaded files and media are stored in encrypted object storage (the exception is the assets you publish deliberately, such as generated profile photos, which are served publicly by design — see Section 3.2);
- network segregation — application servers, cache, and database run in private subnets that are not directly reachable from the internet, with traffic entering only through a managed load balancer;
- managed secrets — database credentials and application secrets are held in a managed secrets store, not in configuration files;
- backups and resilience — the database is continuously backed up with point-in-time restore and an approximately 30-day retention window (recovery point objective on the order of minutes), runs as a clustered database with an automatic-failover standby in a second availability zone (recovery time on the order of a minute for an instance or zone failure), and keeps its backups encrypted at rest. This is our internal disaster-recovery posture, not a service-level guarantee; see the "as is / as available" and availability terms in the Terms of Service; and
- access controls, logging (including the audit trail), and regular security review.
Passwords are stored only in hashed form, and card numbers never touch our systems (Section 3.1). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects personal information in a way that triggers a notification obligation under applicable law, we will notify the affected Agency (and, where required, affected individuals and regulators, including Brazil's ANPD) in accordance with that law and the DPA. You are responsible for the security of your own credentials and for promptly notifying us of any suspected compromise.
11. U.S. State Privacy Rights
Several U.S. states grant residents specific rights with respect to their personal information. The rights below apply where you are a resident of the applicable state. To exercise these rights, see Section 15. Note that for Host and applicant data controlled by an Agency, these requests are generally fulfilled by the Agency with our assistance (Section 7).
11.1 California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; access a copy of it; correct inaccuracies; delete it (subject to exceptions); limit the use of sensitive personal information; opt out of any "sale" or "sharing" for cross-context behavioral advertising; and not be discriminated against for exercising these rights.
Sale and sharing. We do not sell personal information for monetary consideration and do not "share" personal information for cross-context behavioral advertising. We engage our vendors as service providers under contracts that restrict their use of personal information to providing services to us.
Categories collected. See Section 3. Categories include: identifiers (name, email, phone, government identifiers such as CPF where the Agency collects them, IP address); commercial information (subscription and billing records, statements and payout records); internet or network activity (sessions, app usage, push notification interactions); professional or employment-related information (performance statistics, earnings data, staff notes); communications content (WhatsApp and email messages); visual information (photos); and inferences drawn for compensation tiers and rankings — most of which we hold as a service provider to the Agency rather than for our own purposes.
Authorized agents. California residents may use an authorized agent to submit a request; we may require verification of the agent's authority.
11.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Similar States
Residents of these states (and other states with comparable privacy laws) generally have the right to access their personal information, correct inaccuracies, delete it, obtain a portable copy, opt out of targeted advertising / sale / certain profiling, and appeal a denied request. The exact scope depends on your state of residence. To submit a request, see Section 15.
11.3 General
We will verify your identity before fulfilling a request and may decline requests that are unverifiable, manifestly unfounded, excessive, or that conflict with our legal obligations (including record-keeping described in Section 9). We will not retaliate against you for exercising a privacy right.
12. Brazil — Lei Geral de Proteção de Dados (LGPD)
The Service is offered to Agencies and Hosts in Brazil, ships in Brazilian Portuguese, and handles Brazilian identifiers such as CPF and PIX keys. Where the LGPD (Lei nº 13.709/2018) applies to processing we perform, this Section applies.
12.1 Roles
Consistent with Section 2: the Agency is the controller (controladora) of Host and applicant data it collects and manages in the Service, and Pelton Solutions LLC is the operator (operadora) processing that data on the Agency's documented instructions. For Agency, Staff, and billing data — and for Host portal and mobile-app credentials, sessions, device data, and push tokens — Pelton Solutions LLC is the controller.
12.2 Legal Bases
Where we act as controller, we rely on the following legal bases under LGPD Article 7:
- Performance of a contract (Art. 7, V) — providing the Service to the Agency and operating portal and app access for Hosts, including authentication, sessions, and account administration;
- Compliance with legal or regulatory obligations (Art. 7, II) — tax, accounting, and record-keeping duties;
- Legitimate interest (Art. 7, IX) — securing the Service, preventing fraud and abuse, maintaining the audit trail and consent records, diagnosing errors, and improving the Service, in each case balanced against data subjects' fundamental rights; and
- Consent (Art. 7, I) — where required, such as for marketing communications and optional features; consent may be withdrawn at any time without affecting the lawfulness of prior processing.
The Agency is responsible for establishing its own legal bases for the Host and applicant data it controls.
12.3 Your Rights (LGPD Article 18)
If you are a data subject under the LGPD, you may request, with respect to data we process: confirmation that processing occurs; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of the LGPD; portability to another provider; deletion of data processed on the basis of consent; information about the entities with which we have shared your data; information about the option of refusing consent and the consequences of refusal; withdrawal of consent; and review of decisions made solely on the basis of automated processing that affect your interests. You may also petition the Autoridade Nacional de Proteção de Dados (ANPD).
If you are a Host or applicant, your Agency is the controller of most of your data, so please direct requests to your Agency first; we will assist it in responding, and we will handle directly any request concerning data for which we are the controller. See Section 15.
12.4 International Transfer
The Service is hosted in the United States, so personal data of Brazilian data subjects is transferred to and processed in the United States (see Section 16). For these transfers, Pelton Solutions relies on contractual safeguards — including the data protection commitments in the Data Processing Addendum and our contracts with sub-processors — and, where required, the standard contractual clauses approved by the ANPD under LGPD Article 33 and ANPD Resolution CD/ANPD nº 19/2024, incorporated into the DPA on request.
12.5 Data Protection Contact (Encarregado)
Our data protection contact (encarregado) for LGPD matters can be reached at legal@peltonsolutions.com. Communications may be submitted in Portuguese or English.
13. Marketing Communications
We may send marketing emails (about new features, tips, or promotions) to Agency Staff who have opted in or where applicable law permits contact based on the existing customer relationship. You can unsubscribe at any time using the link in any marketing email or by emailing hello@liveagentpro.com. We do not send our own marketing to Hosts or applicants; messages Hosts receive through the Service are sent by their Agency, which is responsible for having the required consents and honoring opt-outs. We will still send operational messages (about your account, billing, and security), which are not marketing.
14. Children's Privacy
The Service is intended for business use by adults and is not directed to minors. Staff must be at least 18 years old, Hosts must be at least 18 years old, and Agencies are prohibited from using the Service to manage or collect data about anyone under 18 — the Agency warrants the age of every Host it onboards, and application forms collect date of birth in support of this rule. We do not knowingly collect personal information from anyone under 18. If you believe personal information about a minor has been submitted to the Service, please contact us at legal@peltonsolutions.com and we will take appropriate steps to delete it.
15. How to Exercise Your Rights
If you are a Host or applicant: for most of your data, your Agency is the controller, and it holds the relationship, context, and tools needed to respond. Please direct your request (access, correction, deletion, portability, or objection) to your Agency first. We contractually assist Agencies in fulfilling these requests, and if you cannot reach your Agency or your request concerns data we control directly (portal or app credentials, sessions, device data, or push tokens), contact us using the details below and we will either fulfill the request or forward it to your Agency and let you know.
If you are Agency Staff, an Agency, or a website visitor: contact us directly.
- Email: legal@peltonsolutions.com with the subject line "Privacy Request — [your state or country]";
- Include enough information to identify the relevant account or record and the right you wish to exercise; and
- We will respond within the timeframe required by applicable law (generally within 45 days, with one possible 45-day extension; LGPD requests are handled within the periods the LGPD and ANPD regulations prescribe).
We will verify your identity before acting on a request. If we deny your request, we will explain why and how to appeal.
16. International Users and Data Location
All information is processed and stored in the United States on AWS infrastructure: our primary deployment runs in one U.S. region, and inbound email receiving runs in a second U.S. region, where raw inbound messages are received and stored before being processed by the application. By using the Service from outside the United States — including from Brazil — you understand that your information will be transferred to and processed in the United States, which may have data-protection laws that differ from those of your country. For Brazilian data subjects, Section 12.4 describes the safeguards we apply to this transfer.
We do not offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and we do not provide GDPR data subject rights or EU Standard Contractual Clauses. If you are located in the EEA, the UK, or Switzerland, please do not create an account.
17. Language
This Privacy Policy is drafted in English. We may provide Spanish and Brazilian Portuguese translations for convenience, but the English version governs in the event of any conflict or ambiguity.
18. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will give reasonable advance notice (by email and/or in-product notice), and Agencies may be asked to re-accept the updated version. The "Last Updated" date at the top reflects the most recent revision.
19. Contact
Pelton Solutions LLC Attn: Live Agent Pro — Privacy 101 Rainbow Drive PMB 1624 Livingston, TX 77399
Privacy questions and requests (and LGPD encarregado contact): legal@peltonsolutions.com General support: hello@liveagentpro.com