Section 01
Introduction
Nexa Hologram, Inc. ("Nexa," "we," "us," or "our") designs, manufactures, and operates holographic display systems and the software services that power them. We respect your privacy and are committed to handling your personal information with care, transparency, and the security it deserves.
This Privacy Policy explains what information we collect, how we use it, with whom we share it, the choices you have, and the rights available to you under applicable law. It applies to our website at nexahologram.com, our hardware products, our cloud content management system, our mobile and desktop applications, and any other service that links to this policy (together, the "Services").
This policy does not cover information practices of third parties whose products or websites we do not own or control, even where we link to them.
Effective date: May 1, 2026.
Section 02
Information we collect
Information you provide
We collect the information you give us directly when you use the Services, including:
- Account information — name, business email, company, country, role, and the password you set.
- Demo and sales requests — contact details, the use case you describe, the products you're considering, and any context you share with our solutions team.
- Support tickets — the description of your issue, attached files, and any device identifiers needed to diagnose it.
- Newsletter signups — the email address you submit and your stated communication preferences.
- Event registrations — name, employer, and any answers to screening questions for webinars, workshops, and on-site briefings.
Information collected automatically
When you visit our website or use our applications, we automatically collect certain information about your device and your interactions:
- Device and browser data — operating system, browser type and version, screen resolution, language, and approximate location derived from IP address.
- Usage data — pages visited, referring URL, click events, session duration, and search terms entered into our site.
- Hardware telemetry — for deployed Nexa devices, basic health and performance metrics (uptime, content playback statistics, firmware version, error logs). This telemetry does not include image or audio captured by the device.
- Cookies and similar technologies — see our Cookie Policy for full detail.
Information from third parties
We may receive information about you from selected third parties, including event platforms (when you register through them), business partners and channel resellers (when they refer an opportunity), and identity providers (when you sign in using a federated login).
Holographic content and captures
Some Services involve volumetric capture — recording a person's body, face, and voice to reconstruct them as a hologram. This data is biometric in nature and we treat it accordingly:
- We capture only with explicit, written consent from each subject, recorded before the session begins.
- We retain raw captures only for the duration needed to deliver the engaged project, and never longer than the contract specifies.
- We do not use captured likenesses to train general-purpose AI models or to generate content involving the subject in any context they have not authorized.
Section 03
How we use your information
We use personal information for the following purposes:
- Service delivery — to provide, operate, and maintain the Services, including provisioning hardware, hosting your content, and responding to your support requests.
- Account management — to authenticate you, manage roles and permissions, and provide billing information.
- Communications — to send transactional notices (order updates, security alerts, billing receipts) and, where permitted, marketing communications you can unsubscribe from at any time.
- Product improvement — to understand which features are used, diagnose bugs, and inform our roadmap. Wherever possible we use aggregated or de-identified data for this purpose.
- Security and fraud prevention — to detect, investigate, and prevent unauthorized access, abuse, and other harmful activity.
- Legal compliance — to meet our obligations under applicable law, respond to lawful requests from authorities, and enforce our agreements.
- Marketing — to share content we believe is relevant to your role and interests, subject to your consent where required.
Section 04
Legal bases for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with comparable rules, we rely on the following legal bases:
- Performance of a contract — to provide Services you have ordered or signed up for.
- Legitimate interests — to operate, secure, and improve our business, provided those interests are not overridden by your rights.
- Consent — for marketing emails, optional cookies, volumetric captures, and any other processing where consent is the appropriate basis. You can withdraw consent at any time.
- Legal obligation — to comply with applicable laws, including tax, accounting, and law-enforcement obligations.
Section 06
International data transfers
Nexa is headquartered in the United States and operates infrastructure in the United States, the European Union, and Singapore. When we transfer personal information across borders, we rely on appropriate safeguards including:
- European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, where applicable;
- Adequacy decisions where the destination country is recognized as providing an adequate level of protection; and
- Supplementary technical and organizational measures, such as encryption in transit and at rest.
You may request a copy of the safeguards in place for your data by contacting privacy@nexahologram.com.
Section 07
Data retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, or for longer if required by law.
- Account data — for the duration of your account plus 24 months after closure, for billing and legal records.
- Marketing data — until you unsubscribe or 36 months of inactivity, whichever comes first.
- Support tickets — 36 months from resolution.
- Hardware telemetry — 18 months in raw form; aggregated indefinitely for product analytics.
- Volumetric captures — only for the duration of the engaged project, then deleted within 30 days unless contracted otherwise.
When data is no longer needed it is securely deleted or fully de-identified.
Section 08
Your rights
Subject to applicable law, you have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- request deletion of your information;
- restrict or object to certain processing;
- port your information to another service in a structured format;
- withdraw consent where processing is based on consent.
To exercise any of these rights, email privacy@nexahologram.com or use our request form. We respond to verifiable requests within 30 days. We may need to verify your identity before fulfilling a request to protect your information from unauthorized access.
Section 09
Regional rights
European Union and United Kingdom
If you are in the EU or UK, you have the rights described above under the General Data Protection Regulation and the UK GDPR. You also have the right to lodge a complaint with your local supervisory authority.
California (CCPA / CPRA)
California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of sharing for cross-context behavioral advertising (we do not engage in this), and to limit use of sensitive personal information. We do not use or disclose sensitive personal information beyond the purposes permitted under California law without consent. We do not discriminate against consumers who exercise their privacy rights.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, and Texas have rights to access, correct, delete, port, and (where applicable) opt out of targeted advertising and profiling that produces legal or similarly significant effects. Submit requests through the same channels described above.
Brazil (LGPD) and Canada (PIPEDA)
Residents of Brazil and Canada have substantively similar rights to access, correct, and delete their information, and to obtain information about how it is processed. Our DPO serves as the contact point for Brazilian data subjects.
Section 11
Children's privacy
The Services are designed for businesses and are not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact privacy@nexahologram.com and we will delete it promptly.
Section 12
Security
We protect personal information with technical and organizational measures aligned with industry best practice and our SOC 2 Type II controls, including:
- encryption in transit (TLS 1.2+) and at rest (AES-256);
- least-privilege access controls and quarterly access reviews;
- multi-factor authentication for all internal systems;
- continuous vulnerability scanning and annual penetration testing;
- vendor security review for every subprocessor.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you without undue delay and in line with applicable law.
Section 13
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes we will notify you by email (where we have it) and by posting a prominent notice on the Services before the change takes effect. The "Last updated" date at the top reflects the most recent revision.
Section 14
Contact us
For questions about this policy or our privacy practices, contact our Data Protection Officer:
- Email: privacy@nexahologram.com
- Postal: Nexa Hologram, Inc., 2424 N San Fernando Rd, Los Angeles, CA 90065, USA
- EU representative: Nexa Hologram EU B.V., Herengracht 282, 1016 BX Amsterdam, Netherlands
- UK representative: Nexa Hologram UK Ltd., 86–90 Paul Street, London EC2A 4NE, United Kingdom
You also have the right to lodge a complaint with the data protection supervisory authority in your country.
Last updated: May 1, 2026
