DO XR Privacy Policy

Effective Date: April 3, 2026

1. Introduction

This DO XR Privacy Policy ("XR Privacy Policy") describes how Digital Original ("Digital Original", "we", "us", or "our") collects, uses, and processes information in connection with DO XR.

This XR Privacy Policy applies exclusively to data processing activities that occur within DO XR. It does not apply to any other Digital Original products, services, platforms, or websites, unless explicitly stated.

Your use of DO XR is also governed by our DO XR Terms of Use.

If you access or use any other Digital Original products or services, including our website or non-XR offerings, such use is subject to separate terms and privacy practices. In the event of any inconsistency or conflict between this XR Privacy Policy and any other Digital Original privacy policy, this XR Privacy Policy shall prevail with respect to your use of DO XR.

By accessing or using DO XR, you acknowledge that you have read and understood this XR Privacy Policy and agree to the collection and use of information as described herein. If you do not agree with this XR Privacy Policy, you must immediately cease use of DO XR.

For the purposes of this XR Privacy Policy, the "Personal Information" means information that relates to an identified or identifiable natural person.

Digital Original acts as the data controller for the Personal Information processed in connection with DO XR, except where otherwise specified by us or where a different role arises based on the nature of the processing and applicable law. Certain data may also be collected and processed by third-party platforms (such as Meta), which may act as independent data controllers in accordance with their own privacy policies.

Capitalized terms used but not defined in this XR Privacy Policy have the meaning given to them in the DO XR Terms of Use. The original language of this XR Privacy Policy is English. Digital Original may make available translations of this XR Privacy Policy in other languages for convenience. In case of conflicts between the original English version and any translation, the English version shall prevail.

2. Information We Collect

2.1 XR Interaction and Usage Data. We collect information about how DO XR is used in order to understand and improve the functionality of the application. This includes aggregated and de-identified interaction data, such as:

  1. Visits to virtual rooms;
  2. Views of digital artworks;
  3. Feature usage patterns, including:
    • use of public and private rooms;
    • access via private codes;
    • QR-based interactions (e.g., adding or viewing content);
  4. General in-application interaction events.

However, you acknowledge that, due to the nature of digital systems, absolute anonymization cannot always be guaranteed.

2.2 Automatically Collected Technical Data. We may process technical information that is strictly necessary to ensure the proper operation, security, and compatibility of DO XR, including session-level technical diagnostics, non-identifiable device compatibility data and basic system performance metrics.

Such data is:

  1. used solely for functionality, debugging, and service improvement;
  2. not used to identify individual users;
  3. not retained longer than necessary for its purpose.

2.3 Communications and Support. If you choose to contact us outside of DO XR, including via email, social media, or other communication channels, we may receive and process the information you voluntarily provide, such as your name, contact details (including your email address), and the content of your message or request. We process such information solely for the purpose of responding to your inquiries, providing customer support, and improving the XR application based on user feedback.

2.4 Information and Content You Upload. We may collect information about the content you upload, including metadata such as the time, date, and place the content was taken or uploaded, as well as information about how you use such content, who views it, and with whom it is shared.

2.5 Information Received from Third Parties. We may receive information from third-party providers strictly where necessary to operate DO XR.

In particular, we may receive certain account-related and technical information from platform providers through which DO XR is made available.

We may also receive aggregated, non-personal analytics data from third-party analytics providers (such as PostHog and Google Analytics) regarding the use of XR features and interactions within the application.

Any data collected or processed directly by third-party platforms, including Meta, is governed by their respective privacy policies. Digital Original does not control and is not responsible for such third-party data practices.

2.6 Information Received from Meta (Meta Quest Platform). DO XR is made available through a third-party platform provided by Meta Platforms, Inc. ("Meta"). Your interaction with Meta Quest devices and services may result in the independent collection and processing of data by Meta in accordance with its own terms and privacy policies. Digital Original does not control and is not responsible for such third-party data practices.

When you access DO XR through Meta Quest devices, we may receive account-related information from Meta, which may include:

  1. User ID;
  2. Username (display name);
  3. Profile photo;
  4. Meta Avatar / Meta Avatars (persistent identity within the Meta ecosystem).

We may also receive other information from Meta where necessary for the operation and functionality of DO XR. Such information is provided to us by Meta in accordance with Meta's own terms and privacy policies. We do not control the scope, accuracy, or processing of such data by Meta.

We use this information solely to:

  1. enable access to the XR experience;
  2. display user identity within the XR environment;
  3. ensure proper functionality of social and interactive XR features.

2.7 Consent Records. We may maintain documentation of any consent you have provided, including the date, time, method of consent, and any related details. Such records will be collected and processed solely for the purpose of demonstrating compliance with applicable legal obligations and will be handled in accordance with the principles set out in this XR Privacy Policy.

2.8 Additional Information. We may collect additional information only in limited circumstances where you voluntarily provide such information, or where we clearly inform you at the time of collection. Any such information will be collected and processed in accordance with the principles set out in this XR Privacy Policy, including data minimization and purpose limitation.

3. How We Use Personal Information

We process Personal Information for various purposes related to the provision and operation of DO XR, in accordance with applicable law and based on appropriate legal grounds.

Performance of contract:

  1. To provide, operate, monitor, maintain, and secure DO XR;
  2. To provide customer support;
  3. To communicate with you (such as through email) about your use of DO XR, changes to this XR Privacy Policy, our DO XR Terms of Use, and to other applicable legal agreements, policies or other important notifications.

Legitimate interests:

  1. To improve and analyze DO XR;
  2. To improve and analyze the effectiveness of DO XR;
  3. To develop, test and improve new products or services, by conducting surveys and research, and testing and troubleshooting new products and features;
  4. To send you newsletters and promotional materials;
  5. To share the research findings with you;
  6. To ask you to participate in surveys, or to solicit feedback;
  7. To monitor and analyze trends, usage, and activities for more effective marketing or other advertising purposes;
  8. To improve the quality of experience of your interaction with DO XR and others;
  9. To prevent misuses of DO XR, and to protect the security of DO XR.

Compliance with legal or regulatory obligations:

  1. To comply with applicable laws, cooperate with investigations by law enforcement or other authorities of suspected violations of law;
  2. To protect our and our affiliates' legal rights and interests;
  3. To audit our compliance with legal and contractual requirements and internal policies;
  4. To detect, prevent fraud, violations of our DO XR Terms of Use, or other applicable legal agreements, policies, and/or otherwise harmful or illegal activities.

Consent: When you give us consent to do so for a specific purpose.

We may aggregate or de-identify Personal Information so that it may no longer be used to identify you. We may use this anonymous, aggregated or de-identified information and/or disclose it for the purpose of improving and analyzing the effectiveness of DO XR, developing new features to DO XR, conduct research, and for other similar purposes. We will maintain and use de-identified information in anonymous or de-identified form and we will not attempt to reidentify the information, unless required by law.

Where we rely on legitimate interests to process the Personal Information, you can object to that processing as described below under "YOUR RIGHTS". In response to your objection, we will stop processing your information for the relevant purposes unless we have compelling grounds in the circumstances or the processing is necessary in the context of legal claims. Digital Original may also process other information that constitutes the Personal Information for direct marketing purposes and you have a right to object to Digital Original's use of the Personal Information for this purpose at any time.

4. To Whom We Disclose the Personal Information

We may disclose information to third parties if you consent to us doing so, as well as in the following circumstances:

  1. Third Party Service Providers. We may share the Personal Information with third party service providers to: provide technical infrastructure services; conduct quality assurance testing; analyze how DO XR is used; prevent, detect, and respond to unauthorized activities or potential violations of our DO XR Terms of Use or policies; provide technical and customer support; and/or to provide other support to you, us, and/or to DO XR. We limit the Personal Information provided to these third party service providers to that which is reasonably necessary for them to perform their functions, and our contracts with them require them to maintain the confidentiality of such Personal Information.
  2. Affiliates. We may share the Personal Information with any subsidiaries, joint ventures, or other companies or products under our common control (the "Affiliates"), in which case we will require our Affiliates to honor this XR Privacy Policy.
  3. Information Related to Your Public Activity. We may display or share information relating to your public activity on DO XR.
  4. Professional Advisors. We may share the Personal Information with professional advisors (for example, lawyers, accountants or others), where necessary in the course of the professional services that they render to us. We limit the Personal Information provided to the professional advisors to that which is reasonably necessary for them to perform their functions, and our contracts with them require them to maintain the confidentiality of such Personal Information.
  5. Corporate Restructuring. We may share the Personal Information when negotiating, or taking part in a merger, acquisition, sale, transfer, divestiture, financing, or disclosure of all or a portion of Digital Original's business or assets. If Digital Original suffers from insolvency, bankruptcy, receivership, Personal Information may form part of the assets of Digital Original. Nonetheless, Digital Original will attempt to convince any recipient of Personal Information to honour this XR Privacy Policy in its spirit and form.
  6. Law Enforcement. Under certain circumstances, we may be required to disclose the Personal Information if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
  7. Other Legal Requirements. We may disclose the Personal Information in the good faith belief that such action is necessary to comply with legal obligations, to protect and defend our rights or property, to detect or prevent fraud or other illegal activity, to prevent or investigate possible wrongdoing in connection with DO XR, to protect the security or integrity of DO XR and any facilities or equipment used to make DO XR available, to protect your personal safety or the public, to enforce our legal agreements and policies, or to protect against legal liability.
  8. Notice of Intellectual Property Infringement. As set forth in the DO XR Terms of Use, we may forward copies of your notice of intellectual property infringement, including your contact information, to the alleged infringer.

5. Sessions and Tracking Technologies

DO XR is designed to operate without the use of traditional web-based tracking technologies such as cookies. XR sessions within DO XR are designed to be session-based.

However, limited technical or session-related data may be temporarily processed during an active session to ensure the proper functioning, performance, and security of the XR experience. Such data is not retained beyond what is necessary for operational purposes.

To the extent that device-level identifiers, system-level tracking mechanisms, or similar technologies are used by the underlying platform (including Meta Quest), such processing is controlled by the respective platform provider and is governed by their privacy policies. Digital Original does not access or control such technologies.

6. Third-Party Websites

Through DO XR, you may encounter links, content, or references by third parties leading to third-party services. You are advised to be mindful that when you click and access any of these third-party services, any other entity might collect your Personal Information. Please be aware that we have absolutely no authority over any of these third-party services and cannot be accountable or responsible for what these third-party services might do with the Personal Information that they collect from you. The links to third party services are provided for your convenience and do not signify in any manner our endorsement of such third parties, their services or content.

7. Third-Party Application Platforms

DO XR is distributed and made available through third-party application platforms, including but not limited to the Meta Quest Store operated by Meta. Your download, installation, and use of DO XR through such platforms are also subject to the respective terms of service, privacy policies, and data practices of those third parties. When you access or use DO XR through a third-party platform, certain information may be collected and processed directly by that platform in accordance with its own privacy policy. Digital Original does not control, and is not responsible for, how such third parties collect, use, disclose, store, or otherwise process your information outside of the DO XR. We encourage you to review the privacy policies and terms of any third-party platforms through which DO XR is distributed before using the application.

8. Data Retention

We will retain the Personal Information for a period of time that is consistent with the original purpose of the data collection, or as necessary to comply with our legal obligations, resolve disputes, prevent fraud and abuse, enforce our DO XR Terms of Use or other agreements, and/or protect our and our Affiliates' legal rights and other interests. When we no longer have a legitimate need to process your information, we will delete or anonymize your information from our active databases.

9. Data Security

At Digital Original, we take data security very seriously. We have taken steps to implement appropriate administrative, technical and physical safeguards to prevent unauthorized access, use, modification, disclosure or destruction of the information you entrust to us. However, no security system is perfect, and due to the inherent nature of the Internet, we cannot guarantee that data, including the Personal Information, is absolutely safe from intrusion or other unauthorized access by others. If you believe the Personal Information has been compromised, please contact us as set forth in the "CONTACT" Section. If we learn of a security systems breach, we will inform you and the authorities of the occurrence of the breach in accordance with applicable law.

10. International Data Transfers

Digital Original may transfer the Personal Information to countries other than the one in which you live. To the extent that the Personal Information is transferred abroad, Digital Original will ensure compliance with the requirements of the applicable laws in the respective jurisdiction in line with Digital Original's obligations. Digital Original uses Standard Contractual Clauses approved by the European Commission (and the equivalent standard contractual clauses for the UK where appropriate) for transfers to countries not subject to an adequacy decision by the European Commission or your local legislature and/or regulator.

11. Children's Privacy

Protecting the privacy of children and young users is especially important.

Access to and use of DO XR is limited to individuals who are at least eighteen (18) years of age. Individuals who do not meet this requirement are not permitted to access or use DO XR. If a higher minimum age is required under applicable law in your jurisdiction, you must meet such a requirement.

We do not knowingly collect or process Personal Information of individuals who are under eighteen (18) years of age. If we become aware that we have collected or processed Personal Information from such individuals, we will take appropriate steps to delete such information without undue delay.

12. Your Rights

You may have the following rights with regard to the Personal Information:

  1. Right to access — is commonly known as a "data subject access request". This enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it.
  2. Right to the Personal Information correction — this enables you to have any incomplete or inaccurate Personal Information we hold about you corrected, though we may need to verify the accuracy of the new Personal Information you provide to us.
  3. Right to be informed — this enables you to ask the Company to provide information about what Personal Information concerning you is being processed and the basis for such processing.
  4. Right to the Personal Information erasure — this enables you to ask us to delete or remove the Personal Information in certain circumstances such as where there is no good reason for us continuing to process it, where we may have processed your information unlawfully or where we are required to erase the Personal Information to comply with law. We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  5. Right to restriction of processing — this enables you to ask us to suspend the processing of the Personal Information in the following circumstances: (i) if you want us to establish the Personal Information's accuracy; (ii) if our use of the Personal Information is unlawful, but you do not want us to erase it; (iii) if you need us to hold the Personal Information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (iv) if you have objected to our use of the Personal Information, but we need to verify whether we have overriding legitimate grounds to use it.
  6. Right to withdraw consent at any time — applicable only where we are relying on your consent to process the Personal Information. Any withdrawal will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide some features or functionalities of DO XR to you. We will advise you if this is the case at the time you withdraw your consent.
  7. Right to the Personal Information portability — you have the right under certain circumstances to receive the Personal Information in a "structured, commonly used, and machine-readable format" and to transmit the Personal Information to another controller without hindrance.
  8. Right to object — you have the right to object to the use of the Personal Information in certain circumstances, such as the use of the Personal Information for direct marketing.
  9. Right to object to automated processing — you have the right to object to a decision based on automated processing.
  10. Right to complain — you have the right to lodge a complaint with a supervisory authority if you believe our processing of the Personal Information violates applicable law. This right may not be available to you if there is no supervisory authority dealing with data protection in your country.

If you are a resident of the United States of America, your rights concerning the collection and processing of your Personal Information may vary based on local data protection laws in your state or territory, but in general, you may have the following rights:

  1. The right to know the specific pieces of Personal Information we have collected about you;
  2. The right to know the categories of:
    • Personal Information the Company has collected about you;
    • Personal Information the Company has disclosed to third parties for a business purpose;
    • Personal Information that has been sold, if applicable;
    • Third parties to whom Personal Information has been sold, if applicable;
    • Recipients to whom Personal Information was disclosed;
    • Sources of Personal Information;
  3. The right to know the business or commercial purposes for collecting or selling Personal Information;
  4. The right to request deletion of Personal Information we have collected from you, subject to certain exceptions;
  5. The right to opt-out of Personal Information sales to third parties;
  6. The right to be free of discrimination for exercising these rights;
  7. The right to receive a notice of any actual or potential privacy breach with respect to your Personal Information.

California's Shine the Light law provides California residents with the right to request information concerning:

  1. the Personal Information disclosed to third parties for the third parties' direct marketing purposes during the immediately preceding calendar year;
  2. the names and addresses of any third parties that, in the preceding calendar year, obtained your Personal Information for direct marketing purposes. Samples of the goods or services offered by such third parties may be provided where it is not reasonably possible to determine the nature of their business from their name.

If you wish to exercise any of the rights set out above, please contact us as set forth in the "CONTACT" Section.

You may decline to share certain Personal Information with us, in which case we may not be able to provide to you some of the features and functionality of DO XR.

If you believe your right to privacy granted by applicable data protection laws has been infringed upon, please contact us by email specified in the "CONTACT" Section.

13. Email Communications

If you contact us directly (for example, via email or other communication channels), we may use your contact details to respond to your inquiry or provide support-related information.

Where necessary, we may send limited service-related communications, such as responses to your requests or important information regarding the XR application.

You may stop receiving such communications at any time by discontinuing contact with us or by requesting that we no longer use your contact details for communication purposes, subject to any legal obligations requiring retention.

14. Changes to This XR Privacy Policy

Please revisit this page periodically to stay aware of any changes to this XR Privacy Policy, which we may update from time to time. If we modify the XR Privacy Policy, we will make it available through the Platform and DO XR, and indicate the date of the latest revision, and will comply with applicable law. If we make changes that materially alter your privacy rights, we will provide additional notice via email. Your continued use of DO XR after the revised XR Privacy Policy has become effective indicates that you have read, understood and agreed to the current version of the XR Privacy Policy.

15. Contact

Please contact us with any questions or comments about this XR Privacy Policy, the Personal Information, our use and disclosure practices by email at: [email protected].