Legal
Privacy Policy
Last updated: August 13, 2026 · Version 2026.08.13-draft.1 · Controller / operator: LIVARTH
Contractual jurisdiction: US (edge_country) · Review status: COUNSEL_APPROVED · locale: en
Controller and contact
LIVARTH (“Platform”) is operated by the legal entity identified in the corporate profile interpolated into this notice (LIVARTH, S.A.P.I. de C.V., trade name LIVARTH). Privacy contact: privacidad@livarth.com. Support: soporte@livarth.com. Domicile: Domicilio legal pendiente de confirmar, México (dato provisional editable).
This notice describes how personal data is processed when you visit or use the Platform. It is a draft for counsel review and must not be treated as counsel-approved localization.
## Scope and roles
LIVARTH operates a B2B marketplace for medical equipment, parts, and related services. Buyers, vendors, and visitors may provide account, organization, listing, messaging, RFQ, tender, order, compliance, and support data.
Where a vendor or buyer acts as an independent controller of their own customer or patient data, LIVARTH is not automatically that party’s controller. Role allocation for specific processing activities requires counsel review and, where needed, a separate data processing arrangement.
## Categories of data
Depending on use of the Platform, we may process: identity and contact data; organization and role data; credentials; commercial and transactional data; listing and catalog metadata; messages and UGC you choose to upload; technical logs; device/browser data; compliance documentation metadata; and support communications.
User-generated content (UGC) is stored and displayed in its original language and is not auto-translated by LIVARTH’s technical i18n program.
## Purposes
Purposes include: providing marketplace functionality; enabling RFQs, tenders, quotes, and orders; account administration; security and fraud prevention; customer support; product improvement; communications about the service; and compliance with applicable law where required.
Secondary marketing purposes, if any, must be presented with clear choice mechanisms appropriate to the applicable privacy framework (jurisdiction override / counsel review).
## Legal bases (framework-dependent)
Legal bases depend on the privacy framework that applies to the data subject and the operator (for example LFPDPPP in Mexico, GDPR/UK GDPR in the EEA/UK, LGPD in Brazil, PIPEDA in Canada, and U.S. state laws such as CCPA/CPRA where applicable).
This Global Core does not assert a single universal legal basis. See the jurisdiction addendum for the user’s resolved jurisdiction.
## Rights and requests
You may contact privacidad@livarth.com to request access, correction, deletion/cancellation, opposition/opt-out, or other rights available under the law that applies to you. Response timelines and required identity verification vary by jurisdiction.
No statement in this draft guarantees a specific statutory outcome beyond what counsel confirms for each market.
## Processors and international transfers
We use service providers (hosting, email, analytics, payments, security, support tooling) that may process data in countries other than your country of residence or the operator’s country. Transfer mechanisms (contractual clauses, adequacy, or other lawful tools) are jurisdiction-specific and require counsel confirmation before production claims.
## Security, retention, children
We implement reasonable technical and organizational measures appropriate to a marketplace platform. No method of transmission or storage is perfectly secure.
Retention periods follow operational need, legal obligations, and dispute-preservation needs; exact schedules are a business + counsel decision.
The Platform is intended for business and professional users. If you are below the minimum age of digital consent or contractual capacity in your jurisdiction, do not use the Platform.
## Cookies and similar technologies
The Platform may use cookies or similar technologies for session management, security, preferences (including UI locale), and analytics. Whether a standalone Cookie Notice and consent banner is required depends on market and tooling (business decision + counsel). Locale preference cookies are not used to determine governing law.