Skip to content

    Template content. This document is provided as a working draft and should be reviewed by qualified counsel before being relied upon for any legal purpose.

    Legal

    Privacy Policy

    How Nexa Hologram collects, uses, shares, and protects your information — written in plain language so you can actually read it.

    Last updated: May 1, 2026··

    Section 01

    Introduction

    Nexa Hologram, Inc. ("Nexa," "we," "us," or "our") designs, manufactures, and operates holographic display systems and the software services that power them. We respect your privacy and are committed to handling your personal information with care, transparency, and the security it deserves.

    This Privacy Policy explains what information we collect, how we use it, with whom we share it, the choices you have, and the rights available to you under applicable law. It applies to our website at nexahologram.com, our hardware products, our cloud content management system, our mobile and desktop applications, and any other service that links to this policy (together, the "Services").

    This policy does not cover information practices of third parties whose products or websites we do not own or control, even where we link to them.

    Effective date: May 1, 2026.

    Section 02

    Information we collect

    Information you provide

    We collect the information you give us directly when you use the Services, including:

    • Account information — name, business email, company, country, role, and the password you set.
    • Demo and sales requests — contact details, the use case you describe, the products you're considering, and any context you share with our solutions team.
    • Support tickets — the description of your issue, attached files, and any device identifiers needed to diagnose it.
    • Newsletter signups — the email address you submit and your stated communication preferences.
    • Event registrations — name, employer, and any answers to screening questions for webinars, workshops, and on-site briefings.

    Information collected automatically

    When you visit our website or use our applications, we automatically collect certain information about your device and your interactions:

    • Device and browser data — operating system, browser type and version, screen resolution, language, and approximate location derived from IP address.
    • Usage data — pages visited, referring URL, click events, session duration, and search terms entered into our site.
    • Hardware telemetry — for deployed Nexa devices, basic health and performance metrics (uptime, content playback statistics, firmware version, error logs). This telemetry does not include image or audio captured by the device.
    • Cookies and similar technologies — see our Cookie Policy for full detail.

    Information from third parties

    We may receive information about you from selected third parties, including event platforms (when you register through them), business partners and channel resellers (when they refer an opportunity), and identity providers (when you sign in using a federated login).

    Holographic content and captures

    Some Services involve volumetric capture — recording a person's body, face, and voice to reconstruct them as a hologram. This data is biometric in nature and we treat it accordingly:

    • We capture only with explicit, written consent from each subject, recorded before the session begins.
    • We retain raw captures only for the duration needed to deliver the engaged project, and never longer than the contract specifies.
    • We do not use captured likenesses to train general-purpose AI models or to generate content involving the subject in any context they have not authorized.

    Section 03

    How we use your information

    We use personal information for the following purposes:

    • Service delivery — to provide, operate, and maintain the Services, including provisioning hardware, hosting your content, and responding to your support requests.
    • Account management — to authenticate you, manage roles and permissions, and provide billing information.
    • Communications — to send transactional notices (order updates, security alerts, billing receipts) and, where permitted, marketing communications you can unsubscribe from at any time.
    • Product improvement — to understand which features are used, diagnose bugs, and inform our roadmap. Wherever possible we use aggregated or de-identified data for this purpose.
    • Security and fraud prevention — to detect, investigate, and prevent unauthorized access, abuse, and other harmful activity.
    • Legal compliance — to meet our obligations under applicable law, respond to lawful requests from authorities, and enforce our agreements.
    • Marketing — to share content we believe is relevant to your role and interests, subject to your consent where required.

    Section 05

    How we share information

    We share personal information only in the limited circumstances below:

    • Service providers — vetted vendors that help us operate the Services (cloud hosting, email delivery, analytics, payment processing, customer support tooling). They may access information only to perform the services we engage them for and are bound by contractual obligations to protect it.
    • Business partners — with your permission, we may share information with channel partners or solution integrators who deliver Nexa services to you.
    • Legal requirements — when we believe in good faith that disclosure is necessary to comply with law, valid legal process, or to protect the rights, safety, or property of Nexa, our customers, or the public.
    • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, with notice to affected users where practicable.

    We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising as those terms are defined under California, Virginia, Colorado, Connecticut, and Utah law.

    Section 06

    International data transfers

    Nexa is headquartered in the United States and operates infrastructure in the United States, the European Union, and Singapore. When we transfer personal information across borders, we rely on appropriate safeguards including:

    • European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, where applicable;
    • Adequacy decisions where the destination country is recognized as providing an adequate level of protection; and
    • Supplementary technical and organizational measures, such as encryption in transit and at rest.

    You may request a copy of the safeguards in place for your data by contacting privacy@nexahologram.com.

    Section 07

    Data retention

    We retain personal information only for as long as necessary to fulfill the purposes described in this policy, or for longer if required by law.

    • Account data — for the duration of your account plus 24 months after closure, for billing and legal records.
    • Marketing data — until you unsubscribe or 36 months of inactivity, whichever comes first.
    • Support tickets — 36 months from resolution.
    • Hardware telemetry — 18 months in raw form; aggregated indefinitely for product analytics.
    • Volumetric captures — only for the duration of the engaged project, then deleted within 30 days unless contracted otherwise.

    When data is no longer needed it is securely deleted or fully de-identified.

    Section 08

    Your rights

    Subject to applicable law, you have the right to:

    • access the personal information we hold about you;
    • correct information that is inaccurate or incomplete;
    • request deletion of your information;
    • restrict or object to certain processing;
    • port your information to another service in a structured format;
    • withdraw consent where processing is based on consent.

    To exercise any of these rights, email privacy@nexahologram.com or use our request form. We respond to verifiable requests within 30 days. We may need to verify your identity before fulfilling a request to protect your information from unauthorized access.

    Section 09

    Regional rights

    European Union and United Kingdom

    If you are in the EU or UK, you have the rights described above under the General Data Protection Regulation and the UK GDPR. You also have the right to lodge a complaint with your local supervisory authority.

    California (CCPA / CPRA)

    California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of sharing for cross-context behavioral advertising (we do not engage in this), and to limit use of sensitive personal information. We do not use or disclose sensitive personal information beyond the purposes permitted under California law without consent. We do not discriminate against consumers who exercise their privacy rights.

    Other US states

    Residents of Virginia, Colorado, Connecticut, Utah, and Texas have rights to access, correct, delete, port, and (where applicable) opt out of targeted advertising and profiling that produces legal or similarly significant effects. Submit requests through the same channels described above.

    Brazil (LGPD) and Canada (PIPEDA)

    Residents of Brazil and Canada have substantively similar rights to access, correct, and delete their information, and to obtain information about how it is processed. Our DPO serves as the contact point for Brazilian data subjects.

    Section 10

    Cookies and tracking technologies

    We use cookies and similar technologies to operate the Services, remember your preferences, measure performance, and (with consent) market our products. Categories include:

    • Strictly necessary — required for the site to function (e.g., session, security, load balancing).
    • Performance — help us understand how visitors interact with the site, in aggregate.
    • Functional — remember preferences such as language and theme.
    • Marketing — used only with your consent to measure campaign effectiveness.

    You can manage your preferences at any time through our cookie settings panel or by configuring your browser. See our full Cookie Policy for the names, providers, and durations of the cookies we use.

    Section 11

    Children's privacy

    The Services are designed for businesses and are not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact privacy@nexahologram.com and we will delete it promptly.

    Section 12

    Security

    We protect personal information with technical and organizational measures aligned with industry best practice and our SOC 2 Type II controls, including:

    • encryption in transit (TLS 1.2+) and at rest (AES-256);
    • least-privilege access controls and quarterly access reviews;
    • multi-factor authentication for all internal systems;
    • continuous vulnerability scanning and annual penetration testing;
    • vendor security review for every subprocessor.

    No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you without undue delay and in line with applicable law.

    Section 13

    Changes to this policy

    We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes we will notify you by email (where we have it) and by posting a prominent notice on the Services before the change takes effect. The "Last updated" date at the top reflects the most recent revision.

    Section 14

    Contact us

    For questions about this policy or our privacy practices, contact our Data Protection Officer:

    • Email: privacy@nexahologram.com
    • Postal: Nexa Hologram, Inc., 2424 N San Fernando Rd, Los Angeles, CA 90065, USA
    • EU representative: Nexa Hologram EU B.V., Herengracht 282, 1016 BX Amsterdam, Netherlands
    • UK representative: Nexa Hologram UK Ltd., 86–90 Paul Street, London EC2A 4NE, United Kingdom

    You also have the right to lodge a complaint with the data protection supervisory authority in your country.

    We use a small number of cookies to keep the site running and understand how it's used. Read the Cookie Policy.