Our position on privacy
Privacy sits at the centre of how we build and operate HoloBox911. Our holographic displays, cloud services and companion application are used inside boardrooms, showrooms, training floors and live events — places where what you show and say belongs to you and to nobody else. Our commitment is simple: your business stays your business.
This Policy explains what personal data we handle, why we handle it, who we share it with, how long we keep it, and the rights available to you.
Who we are
This website and the services described here are operated by AXRverse Global Private Limited (CIN: U62099UP2024PTC205949), an Indian company trading under the brands HoloBox911 and Metaverse911.
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), AXRverse Global Private Limited acts as the Data Fiduciary for the personal data described in this Policy. You, as the individual the data relates to, are the Data Principal.
- Registered office
- IS700, Ground Floor, Tower IS7, Urbtech Trade Centre, Sector 132, Noida, Uttar Pradesh 201304, India
- Privacy contact
- privacy@holobox911.com
What this Policy covers
This Policy applies to:
- holobox911.com and any other websites, landing pages or online forms we operate under the HoloBox911 or Metaverse911 brands;
- HoloBox devices — our holographic display units, whether purchased, leased or rented, including any onboard software and device diagnostics;
- HoloBox cloud services — the streaming, content management, scheduling and remote-support services that our devices connect to;
- the HoloBox911 companion application, on mobile and desktop.
We refer to all of the above together as the "Services".
Our Services are designed, manufactured and supplied for customers in India, and this Policy is written for them. It does not apply to services operated by other companies, even where you reach them from our Services. Section 15 explains how those are treated.
Personal data we collect
You may be asked to give us information at various points — when you enquire about a HoloBox, register a device, sign in to the application, download a software or firmware update, raise a support ticket, visit one of our experience centres, or take part in a survey or event.
Depending on how you interact with us, we may collect:
| What we collect | Examples |
|---|---|
| Identity and contact details | Your name, job title, organisation name, business email address, telephone number, postal or delivery address, and how you prefer to be contacted |
| Account credentials | Login identifiers and authentication data for the HoloBox911 application and cloud console |
| Device and technical data | Device identifiers, serial numbers, firmware and software versions, IP address, browser type and language, operating system, error and diagnostic logs |
| Usage data | Pages viewed, features used, session times, referring and exit pages, in-app actions, search queries within our Services, clickstream data, date and time stamps |
| Location data | Approximate or precise location of a HoloBox device or application, subject to Section 14 |
| Content you provide | Videos, images, 3D assets, avatar inputs, presentation material and other content you upload to or stream through the Services |
| Commercial and transaction data | Products and services quoted, ordered, rented or purchased; billing, PAN and GST details; purchase and service history |
| Correspondence | Enquiries, support conversations, survey responses and feedback |
Payment information
We do not collect or store complete payment card numbers, CVV codes, net-banking credentials or UPI PINs. Payments are made by bank transfer against invoice, or through third-party payment gateways and banking partners who process card and account details under their own terms and applicable payment security standards. We receive only confirmation of payment and the transaction reference we need for invoicing and accounting.
You are never obliged to give us the information we request. However, if you choose not to, we may be unable to supply the product or service you are asking for, fulfil a contract with you, or answer your query.
Where your data comes from when it does not come from you
Most of the personal data we hold is given to us directly by you or by the organisation you represent.
We may also receive personal data from:
- Colleagues at your organisation, for example when a procurement or IT contact registers you as a device user or nominates you as a point of contact;
- Business partners, resellers and event organisers, where you have interacted with them in relation to our Services.
Why we use your data, and on what basis
Under the DPDP Act we may process your personal data with your consent, or for certain legitimate uses recognised by the Act — for example, where you have voluntarily given us your data for a specified purpose, or where processing is necessary to comply with a legal obligation or a judgment, or to respond to a medical emergency or a threat to life or public health.
We use personal data to:
- Provide and operate the Services — fulfil orders, install, configure, rent, lease and maintain HoloBox devices, deliver cloud streaming and content management, and enable the companion application.
- Support you — diagnose faults, respond to service requests, arrange site visits, and supply spares and replacements.
- Deliver software and firmware updates and confirm your devices are running supported versions.
- Keep you informed about products — new HoloBox models, feature releases, updates and events. You can withdraw consent for these messages at any time using the unsubscribe link in the message or by writing to privacy@holobox911.com.
- Send essential service notices — for example, changes to our terms, safety or security advisories, billing notices, or changes to this Policy. These are necessary to your use of the Services, so they are not marketing messages and cannot be opted out of while you hold an active account or device.
- Improve and develop the Services — analyse how features are used, test improvements, and shape our product roadmap.
- Protect accounts, devices and networks — detect and prevent fraud, misuse and unauthorised access, and screen uploaded content where necessary to identify unlawful material.
- Run our business — accounting, invoicing, auditing, internal reporting, and internal research.
- Meet legal and regulatory obligations — including income tax, GST, corporate and data-protection requirements applicable to us in India.
We give you a clear notice describing the purpose before or at the time we ask for your consent, and we only ask for the data we need for that purpose. Where required, that notice is made available in English and in the languages listed in the Eighth Schedule to the Constitution of India.
Withdrawing your consent
Where we rely on your consent, you may withdraw it at any time, as easily as you gave it, by writing to privacy@holobox911.com or using the controls provided in the Services or in our messages to you.
Withdrawing consent does not affect anything we lawfully did with your data before you withdrew it. It may, however, mean we can no longer provide part or all of a Service to you, and we will tell you where that is the case.
Data that does not identify you
We also collect and use information in a form that does not, by itself, identify a specific individual or organisation. For example:
- Aggregated interest and industry data — sector, city, PIN code, time zone and device model, so we can understand which markets and use cases our products serve and improve how we present them.
- Aggregated product and website analytics — which pages, features and content are used most, which help us prioritise development and improve documentation and support material.
- Performance and reliability data — anonymised diagnostics used to measure streaming quality, latency and uptime.
- Application usage insights, shared with developers or integration partners only where you have specifically agreed to it, to help improve the software you use.
Where such information cannot reasonably be linked back to an identifiable individual, it falls outside the definition of personal data and we may collect, use, transfer and disclose it for any lawful purpose. If we ever combine non-identifying information with personal data, we treat the combined set as personal data under this Policy.
Cookies and similar technologies
Like most online services, our website automatically records certain information in log files, including IP addresses, browser type and language, internet service provider, referring and exit pages, operating system, date and time stamps, and clickstream activity. We use this to keep the site secure and functioning, to understand how it is being used, and to improve it.
- Strictly necessary cookies are always active. These are required for the website and application to work — page delivery, session handling, load balancing, security and fraud prevention. They cannot be switched off.
- Analytics, performance, personalisation and marketing cookies are set only if you opt in. When you first visit our website you are shown a consent banner. Nothing beyond strictly necessary cookies is placed on your device until you accept it.
- You can change your mind at any time through the cookie settings link on our website, or by clearing cookies in your browser. Withdrawing cookie consent stops further collection through those cookies.
We do not use cookies or similar technologies to track you across unrelated third-party websites.
Categories of data we collect and disclose
For transparency, the table below sets out the broad categories of personal data we handle and whether we disclose them to the recipients described in Section 11.
| Category | Examples | Collected | Disclosed |
|---|---|---|---|
| Identifiers | Name, alias, organisation, postal address, email, phone number, unique account identifier, online identifier, IP address | YES | YES — Section 11 recipients |
| Financial and sensitive record data | Government identification numbers, signature, bank account details, insurance details, medical or health information | NO | NO |
| Protected characteristics | Age, caste, race, religion, gender, sexual orientation, disability, marital status, genetic information | NO | NO |
| Commercial information | Products and services quoted, ordered, rented or purchased; service history; purchasing preferences | YES | YES — Section 11 recipients |
| Biometric information | Facial images, facial geometry, voice recordings and voice models used to build or drive a digital avatar or likeness | YES — limited, see below | YES — commissioning client and its production processors only |
| Internet and network activity | Browsing and search history within our Services, interactions with our website, application and content | YES | YES — Section 11 recipients |
| Geolocation data | Physical location or movement of a device or application | YES | YES — Section 11 recipients |
| Audio and visual data | Photographs, video footage and audio recordings supplied to us, or captured at a client's request, for production of holographic or avatar content | YES — limited, see below | YES — commissioning client and its production processors only |
| Professional or employment information | Employment history, performance evaluations | NO | NO |
| Education records | Academic records, transcripts, student identifiers | NO | NO |
Job title and organisation name are collected as business contact details and are treated under Identifiers above. Company PAN, GST and billing identifiers are treated under Commercial information.
Facial, voice and likeness data — our limits
Some of our work involves creating AI avatars, digital likenesses and holographic presentations of real people on behalf of our clients. Where that happens:
- We process facial images, voice recordings and derived models only for the specific production a client has engaged us for, and only under a written agreement with that client.
- The client is responsible for obtaining the consent of the individual whose likeness or voice is being used, and we require confirmation of that consent before production begins.
- We do not use facial or voice data for identification, verification, authentication, surveillance, profiling or advertising, and we do not use it to train general-purpose models for unrelated purposes.
- We do not collect biometric data from visitors to our website, from purchasers of HoloBox devices, or from users of the HoloBox911 application in the ordinary course of use.
- Facial, voice and likeness material is deleted or returned at the end of the engagement in line with the agreement and with Section 18.
If you believe your likeness or voice has been used in our work without your consent, contact our Grievance Officer using the details in Section 19 and we will investigate.
When we share your data
We do not sell your personal data. We share it only in the circumstances below:
- Within our group. With our affiliated entities, offices and experience centres, so that we can supply, support and invoice for the Services. They use it consistently with this Policy.
- With service providers and processors. Cloud hosting and storage, content delivery, streaming infrastructure, logistics and installation partners, payment gateways and banking partners, CRM and communication tools, and support platforms. These providers act on our instructions under contract, may use the data only to perform the service for us, and may not use it for their own purposes.
- With partners you engage. Resellers, channel partners or event organisers, where you have asked us to work with them or where they introduced you to us.
- Where the law requires it. In response to a lawful requirement, legal process, court order, litigation, or a valid request from a court, regulator, or public or government authority in India.
- To protect people and rights. Where we reasonably believe disclosure is necessary for public safety or law enforcement, to enforce our terms, to investigate suspected fraud or misuse, or to protect the rights, property or safety of our users, our staff or the public. We do this only where there is a lawful basis.
- In a corporate transaction. If we are involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred to the relevant party, which will remain bound by protections consistent with this Policy.
Where we engage a processor, we do so under a valid contract as required by the DPDP Act.
Where your data is stored
Personal data collected through the Services is stored and processed on infrastructure located in India.
We remain accountable to you as Data Fiduciary for that data at all times, and we require our hosting and storage providers to maintain the protections described in this Policy. If we ever need to change this arrangement, we will update this Policy and, where the DPDP Act requires it, obtain your consent first.
How we protect your data
We treat the security of your data as a core operating requirement.
- Data in transit between your devices, our applications and our cloud services is protected using encryption.
- Data at rest in our cloud environment is stored in encrypted form, including where we use third-party storage providers.
- Access to systems holding personal data is limited to personnel who need it for their role, and is controlled through authentication and access management.
- Our offices, experience centres and fabrication facilities are protected by physical and organisational security measures.
- Our staff are trained on our privacy and security standards, and those standards are enforced internally.
No system can be guaranteed to be completely secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act and the rules made under it.
Location-based features
Some HoloBox features rely on knowing where a device or application is. Depending on the feature, location may be estimated using GPS, Bluetooth, IP address, nearby Wi-Fi access points and mobile network information, or determined from the installation address you give us.
Unless you have specifically consented to something more, location data is collected in a form that does not identify you individually, and is used by us and our mapping or infrastructure partners to deliver and improve location-dependent features. Where an application asks to share your location with a third-party provider, that sharing happens only if you opt in, and the third party's own privacy terms then apply.
Third-party websites, apps and services
Our website, devices and application may link to, or make use of, products and services supplied by other companies — for example an embedded map, a third-party integration, or an app you choose to install.
Anything those third parties collect, including contact details or location data, is governed by their own privacy practices, not ours. We encourage you to read them before you use those services. If you buy a subscription through a third-party application store or platform, that platform may share limited details of your purchase with us, and we may generate an identifier unique to you and that platform so the subscription can be serviced.
Data relating to children
Our Services are designed and sold for business and professional use. We do not offer them to children, and we do not knowingly collect personal data from anyone under the age of eighteen (18).
Where any part of our Services is used in a setting that involves individuals under eighteen, we require verifiable consent from the parent or lawful guardian before their personal data is processed, in line with the DPDP Act. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
If you believe a child's personal data has been provided to us, contact our Grievance Officer using the details in Section 19 and we will delete it.
Do we sell or trade your data?
No. We do not sell personal data, and we do not share it with third parties for cross-site targeted advertising. We do not track your activity across unrelated third-party websites.
Because we do not engage in these practices, we do not operate a separate opt-out mechanism for the sale of data. Any use of cookies or similar technologies on our own website is governed by Section 9 and by your consent choices.
How long we keep your data
We keep personal data only for as long as it is needed for the purposes set out in this Policy, or for as long as we are required to keep it by law.
| Type of record | Retention period |
|---|---|
| Accounting, invoicing, tax and contractual records | Eight (8) years from the end of the financial year to which they relate, as required under the Companies Act, 2013 and related tax legislation |
| Account, device registration and support records | The duration of your relationship with us, plus three (3) years, so we can honour warranties, service history and any subsequent claim |
| Marketing contact data | Until you withdraw consent or ask us to remove you, whichever is earlier |
| Facial, voice, likeness and production material | The duration of the engagement it was supplied for; deleted or returned at the end of that engagement unless the client's agreement provides otherwise |
| Website and application logs and analytics data | Twelve (12) months |
Where you ask us to delete your personal data and we are not legally required to keep it, we delete it — and instruct our processors to delete it — within thirty (30) days of verifying your request.
Where consent is withdrawn and no other lawful ground applies, we erase the personal data and require our processors to do the same, unless retention is required by law.
Your rights, and how to exercise them
As a Data Principal under the DPDP Act you have the right to:
- Access — obtain a summary of the personal data we hold about you, how we process it, and the identities of other Data Fiduciaries and processors with whom it has been shared.
- Correction, completion and updating — have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.
- Erasure — ask us to delete your personal data where we are not required to keep it for a legal purpose or for the purpose it was collected.
- Grievance redressal — raise a complaint with us about how we handle your data, and receive a response.
- Nomination — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
You also have duties under the DPDP Act, including providing accurate information and not raising false or frivolous complaints.
- Grievance Officer
- Mr Pankaj Kumar
- privacy@holobox911.com
- Post
- AXRverse Global Private Limited, IS700, Ground Floor, Tower IS7, Urbtech Trade Centre, Sector 132, Noida, Uttar Pradesh 201304, India
We may ask you for information to verify your identity before acting on a request.
Complaints and response times
Privacy contacts are routed to our Grievance Officer, who assesses each one and directs it to the right person. Where a matter is substantive, we may come back to you for more detail so we can investigate properly.
- We acknowledge every privacy request or complaint within seven (7) working days of receiving it.
- We aim to resolve it within thirty (30) days, either providing our response, requesting the further information we need, or explaining why more time is required and when you can expect an answer.
Where your complaint shows we could improve how we handle privacy, we make that change at the next reasonable opportunity. Where a privacy issue has had a negative effect on you or your organisation, we will work with you to address it.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India in accordance with the DPDP Act.
Our internal commitment
Privacy is not only a policy document for us. We communicate our privacy and security standards to everyone at AXRverse Global Private Limited, we enforce them internally, and we hold ourselves accountable for the protection, availability and confidentiality of client data across our devices, our cloud platform and our application.
Governing law
This Policy, and any dispute or claim arising out of or in connection with it, is governed by the laws of India. The courts at Gautam Buddha Nagar, Uttar Pradesh shall have exclusive jurisdiction, subject to the statutory powers of the Data Protection Board of India under the DPDP Act.
Changes to this Policy
We may update this Policy from time to time. Where a change is material, we will post a notice alongside the updated Policy on our website and, where we hold your contact details, tell you directly by email, in-app notification or another equivalent method. Where a change requires fresh consent under the DPDP Act, we will ask for it before relying on it.
The date at the top of this Policy shows when it was last revised.
