A practical guide to what Livetech does, what our clients are responsible for, and where to get help
Data protection, cyber security and website compliance can become complicated very quickly.
For most organisations, however, the starting point is straightforward.
Even a simple website will normally process some information about its visitors. Web servers routinely handle information such as IP addresses, access logs, browser information and security data simply to deliver and protect a website.
More complex websites may also process information through contact forms, databases, analytics, mailing lists, ecommerce systems, payment providers, customer accounts and other integrations.
At Livetech, our approach is to keep responsibilities clear and proportionate.
We take responsibility for the technology and services we provide, help our clients understand how their websites handle information, and make clear where responsibility remains with the client or where specialist advice may be needed.
What Livetech does
Depending on the services you purchase from us, Livetech may provide and manage:
- website hosting;
- website files and databases;
- hosting infrastructure;
- server and website security measures;
- security monitoring and logging;
- backups and restoration;
- website maintenance and software updates;
- SSL/TLS and secure website connections;
- contact forms and other website functionality;
- analytics and third-party integrations;
- ecommerce and payment-service integrations;
- domain and DNS administration;
- technical support; and
- assistance following a technical or security incident.
Where we process personal information on your behalf in providing these services, Livetech will normally act as a Data Processor and you will normally act as the Data Controller.
Our responsibilities in those circumstances are set out in our Data Processing Addendum.
Read our Data Processing Addendum
What we help clients with as part of our normal service
We do not want ordinary compliance questions to become unnecessarily complicated.
As part of our normal client relationship, we are happy to provide reasonable information about the technology and services we manage.
For example, we can normally explain:
- what information your website collects;
- where website information is hosted;
- whether your website uses a database;
- how an enquiry form works;
- what cookies or analytics tools are installed;
- which third-party services are connected;
- how payments are technically integrated;
- what hosting arrangements apply;
- what backup arrangements apply;
- which infrastructure providers are involved; and
- what security measures apply to systems that we manage.
Where we identify an obvious technical or compliance-related issue, we will normally draw it to your attention.
This sort of reasonable signposting and explanation forms part of the way we support our clients.
What remains your responsibility
Using Livetech does not automatically make an organisation GDPR compliant, PCI DSS compliant or compliant with another legal or regulatory regime.
As the organisation operating the website or service, you remain responsible for decisions such as:
- what personal information you collect;
- why you collect it;
- the lawful basis on which you use it;
- what information you provide to customers and website visitors;
- how long information should be retained;
- who within your organisation can access it;
- how your employees and contractors use personal information;
- your marketing and mailing-list practices;
- whether consent is required;
- your organisation’s wider records and systems;
- whether sector-specific regulation applies to you;
- whether a Data Protection Impact Assessment is required;
- whether you are required to appoint a Data Protection Officer;
- your PCI DSS responsibilities where you accept card payments; and
- obtaining specialist legal or regulatory advice where appropriate.
Good data protection and security are therefore a shared responsibility.
Livetech looks after the parts of the technology we have agreed to manage. You remain responsible for how your organisation uses that technology and the information flowing through it.
What Livetech does not do
Livetech is a technology and digital services company.
Unless expressly agreed as part of a specific service, we do not act as:
- your solicitor or legal adviser;
- your statutory Data Protection Officer;
- your regulatory compliance officer;
- your PCI Qualified Security Assessor;
- your accountant or financial adviser;
- your cyber insurer; or
- a regulatory certification body.
We do not certify that an organisation is “GDPR compliant”, “PCI compliant” or otherwise legally compliant simply because we design, manage or host its website.
There will be occasions where the appropriate advice from us is:
“We can explain the technology and help you implement the technical solution, but you should obtain specialist advice on the underlying legal or regulatory question.”
We regard knowing where that boundary sits as part of providing a professional service.
When you need a little more help
Sometimes a client needs more than a quick technical answer but does not yet need a solicitor or specialist compliance consultant.
For those clients we offer a light-touch Website Data & Compliance Review.
The review can look at matters such as:
- information collected through the website;
- enquiry and contact forms;
- cookies;
- analytics and tracking;
- privacy and cookie information;
- website administrator access;
- mailing-list integrations;
- third-party services;
- payment integrations;
- data retention settings;
- backups;
- website security arrangements; and
- obvious technical compliance risks.
We provide a practical action list and can help implement technical changes where appropriate.
Find out about our Website Data & Compliance Review
When we recommend specialist advice
Some issues go beyond the appropriate scope of a website and technology company.
Examples may include:
- complex use of health or other special-category information;
- children’s personal data;
- significant personal data breaches;
- regulatory investigations;
- complex Data Protection Impact Assessments;
- disputed data subject requests;
- significant international data-transfer questions;
- questions about the legality of a particular business practice;
- significant PCI DSS compliance questions; or
- situations requiring formal legal advice or regulatory certification.
Where this happens, we will tell you.
Where appropriate, we can also help identify the type of specialist you need and provide the technical information that adviser requires.
The documents behind our approach
Our framework is supported by four principal documents.
Terms of Business
Our Terms of Business form the main contractual framework governing the services Livetech provides.
Data Processing Addendum
Where Livetech processes personal information on behalf of a client, our Data Processing Addendum sets out our obligations as Data Processor.
Read our Data Processing Addendum
Privacy Policy
Our Privacy Policy explains how Livetech processes personal information when Livetech itself determines how and why that information is used.
Sub-processor List
Like most technology providers, we use specialist infrastructure and technology companies to deliver some of our services.
Our Sub-processor List explains who the principal providers are and what they do.
Our approach in one sentence
We take responsibility for the technology we provide, help our clients understand their responsibilities, fix the technical issues we are qualified to fix, and say clearly when specialist legal, regulatory or compliance advice is required.
Summary of these documents
- https://www.livetech.co.uk/data-protection This document
- https://www.livetech.co.uk/terms
- https://www.livetech.co.uk/data-processing-addendum
- https://www.livetech.co.uk/privacy-policy
- https://www.livetech.co.uk/sub-processors-list
- https://www.livetech.co.uk/website-compliance-review
Archived / previous versions:
- https://www.livetech.co.uk/terms-pre-sept-2026
- https://www.livetech.co.uk/privacy-policy-pre-sept-2026
