Privacy Policy
Last updated: September 2, 2026
1. Introduction and Scope
1.1 This Privacy Policy ("Policy") describes how the Holo Group collects, uses, discloses and
otherwise processes personal data in connection with the Holo AI-powered platform available at
https://tryholo.ai and https://app.tryholo.ai, and any related tools, features, applications and
services (together, the "Services"). The Services are made available at those domains and at any
successor or additional domain we use for that purpose, and this Policy applies to all of them.
1.2 Capitalized terms used but not defined in this Policy have the meanings given to them in the
Holo Terms of Service (the "Terms"), available at https://tryholo.ai/policies/terms. This Policy
forms part of the framework described in the Terms; in the event of any conflict between this
Policy and the Terms regarding contractual rights and obligations, the Terms prevail.
1.3 The Services are available only for business or professional use and are not offered to
consumers. This Policy therefore applies primarily to personal data relating to the representatives,
employees, contractors and Authorized Users of our business customers, to visitors of our
websites, and to individuals whose personal data is contained in Inputs or Outputs.
2. Who Is Responsible for Your Personal Data
2.1 "Holo Group" means Holo AI Inc., a Delaware corporation with its registered office at 3500
South Dupont Highway, Dover, Delaware 19901, USA, together with its Affiliates.
2.2 Where we act as controller, the entity responsible for your personal data is Holo AI Inc., which
is your counterparty under the Terms. Where you interact with us without an Account, Holo AI Inc.
is the controller.
2.3 Holo Group entities may share personal data with each other where necessary to operate the
Services, including to collect payments as payment collection agent for your counterparty, to retry
failed charges through another Holo Group entity, and to give effect to a transfer of the Terms to
another Holo Group entity, in each case as described in the Terms. Payment routing between
Holo Group entities does not change the entity responsible for your personal data as controller.
3. Our Role: Controller and Processor
3.1 Processor when we provide the Services to you. Where we process personal data
contained in Inputs in order to provide the Services to you, you (our business customer) are the
controller and we are the processor. We process such data on your documented instructions,
which are set out in the Terms, in the Data Processing Agreement referred to in Section 3.4 and
in your use of the Services. You are responsible for ensuring that you have all rights, permissions,
consents and legal bases required to submit personal data in Inputs, including any consents
required to process or synthetically reproduce the name, image, likeness or voice of an identifiable
person.
3.2 Independent controller when we develop and improve the Services. Section 8.4 of the
Terms permits us to use Inputs, Outputs and associated usage data to develop, train, fine-tune,
test, evaluate, secure and improve the Services, AI models and related datasets. That use is for
our own purposes and is not carried out on your instructions. We therefore do not act as your
processor for that activity: to the extent it involves personal data, we act as an independent
controller and are responsible for establishing a valid legal basis for it. Section 6 describes that
activity and the limits that apply to it.
3.3 Independent controller for our own operations. Where we process personal data for our
own purposes, including account administration, billing, security, fraud prevention, analytics and
compliance, we act as an independent controller. Each party is responsible for complying with the
data protection laws applicable to its own processing.
3.4 Data Processing Agreement. Our Data Processing Agreement (the "DPA"), available at
https://tryholo.ai/policies/dpa, sets out the terms on which we process personal data as your
processor under Section 3.1. It covers the subject matter, duration, nature and purpose of the
processing, the types of personal data and categories of data subjects, and our obligations as to
confidentiality, security, sub-processing, assistance with data subject requests and data
protection impact assessments, breach notification, audit, and the return or deletion of data,
together with the transfer mechanisms that apply. The DPA is incorporated into the Terms and
applies automatically from the moment you first submit personal data in Inputs. You do not need
to request it or sign it separately. If you require a countersigned copy, or wish to propose your
own form of DPA, contact us at support@tryholo.ai.
4. Personal Data We Collect
4.1 We collect the following categories of personal data:
– Account and registration data: name, business email address, authentication data
(passwords are stored only in salted, hashed form and are not accessible to us in plain
text), company name, role, and, where requested under the Terms, company registration,
VAT or tax numbers and evidence of authority;
– Billing and payment data: billing address, invoice details, transaction history, and payment
credentials stored and used by Holo Group entities and our payment providers in
accordance with the Terms. Full card numbers are processed by our payment providers,
not stored by us;
– Inputs and Outputs: prompts, instructions, briefs, files, images, video, audio, Brand
Materials and other content you or your Authorized Users submit to the Services, and the
content generated in response, in each case to the extent they contain personal data;
– Usage data: features used, generations initiated, Credit consumption, log data, IP
address, browser type and version, device identifiers, operating system, pages visited,
and the dates, times and duration of use;
– Communications data: support requests, correspondence and related metadata sent to or
from support@tryholo.ai or through the Services;
– Cookie and tracking data, as described in Section 13; and
– Compliance data: information reasonably necessary for sanctions screening, fraud
prevention and the verification of business or professional use, as contemplated by the
Terms.
5. Purposes and Legal Bases
5.1 Where we act as controller, we process personal data for the following purposes and on the
following legal bases:
to provide, operate and support the Services, manage Accounts and Subscriptions,
allocate Credits and provide technical support — performance of a contract, or our
legitimate interest in serving the business you represent;
– to bill and collect Fees, issue invoices, process refunds under the Terms and manage
payment disputes and chargebacks — performance of a contract and compliance with
legal obligations;
– to secure the Services, prevent fraud and abuse, enforce Credit and rate limits, investigate
suspected breaches of the Terms and act on notices of unauthorized Account access —
our legitimate interests in protecting the Services, our customers and our providers;
– to comply with legal obligations, including accounting and tax law, sanctions law and lawful
requests from authorities — compliance with legal obligations;
– to analyze usage, measure performance and develop, test, evaluate, secure and improve
the Services and the AI models used to provide them, as further described in Section 6 —
our legitimate interests, or consent where required;
– to send service communications regarding the Services, Subscriptions, renewals, price
changes and changes to the Terms — performance of a contract and compliance with
legal obligations;
– to send marketing communications about our products and services — our legitimate
interest in marketing to business contacts, or consent where required by applicable law.
You may opt out at any time; and
– to establish, exercise or defend legal claims, including under the dispute resolution
provisions of the Terms — our legitimate interests.
6. AI Development and Model Training
6.1 Under Section 8.4 of the Terms, we and our Affiliates may use Inputs, Outputs and associated
usage data to develop, train, fine-tune, test, evaluate, secure and improve the Services, AI models
and related datasets, including services made available to other customers, and may exercise
this right through our model, infrastructure and technology providers. As explained in Section 3.2,
we act as an independent controller for this activity and not as your processor.
6.2 To the extent that Inputs or Outputs contain personal data, we use them for the purposes
described in Section 6.1 only where that data has been anonymized or aggregated, or where we
have an appropriate legal basis for the processing under applicable data protection law. Where
we rely on legitimate interests, we carry out and record a balancing assessment before doing so,
and you or the individual concerned may object to that processing as described in Section 11.
6.3 The Services depend on third-party AI models, APIs and infrastructure. Inputs and Outputs
may be processed by those providers in order to generate Outputs and operate the Services. We
will not intentionally publish your Inputs or Outputs as customer-facing marketing materials in a
manner that identifies you, or identify you as a customer, without your consent.
6.4 Limits of deletion. Where personal data has already been used to train or fine-tune an AI
model, it is generally not technically possible to remove the influence of that data from the model
once trained. We will delete the underlying personal data from our systems in accordance with
Section 9 and will act on valid erasure requests in respect of that data, but we cannot reverse
training that has already taken place. If you need to prevent Inputs from being used for the
purposes described in Section 6.1, contact us at support@tryholo.ai before submitting them; any
restriction on the licence granted in Section 8.4 of the Terms must be agreed by us in writing.
7. How We Share Personal Data
7.1 We share personal data with:
– Holo Group entities, for the purposes and in the circumstances described in Section 2.3;
– service providers acting on our behalf, including hosting and infrastructure providers, AI
model and API providers, payment providers, acquirers and card schemes, analytics
providers, communication and support tooling providers, and fraud prevention services, in
each case under contracts that restrict their use of the data;
– professional advisers, including lawyers, auditors and accountants, where reasonably
necessary;
– courts, arbitral tribunals, regulators, law enforcement and other public authorities, where
we are required or permitted to do so by applicable law, or where reasonably necessary
to establish, exercise or defend legal claims, protect the rights, property or safety of the
Holo Group, our customers or others, or investigate suspected wrongdoing in connection
with the Services;
– an acquirer or successor in connection with a merger, reorganization, financing or sale of
all or part of our business or assets, in accordance with the assignment provisions of the
Terms; and
– other recipients with your consent or at your direction.
7.2 We do not sell personal data, and we do not share personal data with third parties for their
own direct marketing purposes.
7.3 Sub-processors. A current list of the sub-processors we engage to process personal data
on behalf of our customers, including their location and the purpose for which they are engaged,
is available at https://tryholo.ai/policies/subprocessors. We will give notice of the intended addition
or replacement of a sub-processor as provided in the DPA, and you may object on reasonable
data protection grounds in accordance with the DPA.
8. International Transfers
8.1 We and our providers may process personal data in the European Economic Area, the United
States and other countries in which they operate. Where personal data is transferred outside the
EEA (or the United Kingdom or Switzerland, where their laws apply), the transfer will be subject
to an adequacy decision, standard contractual clauses approved by the European Commission
or another lawful transfer mechanism, together with supplementary measures where required.
8.2 A copy of the relevant transfer safeguards may be requested at support@tryholo.ai, subject
to redaction of commercially sensitive terms.
8.3 Where the UK GDPR applies, transfers of personal data out of the United Kingdom are made
under the International Data Transfer Agreement or the International Data Transfer Addendum to
the EU standard contractual clauses issued by the UK Information Commissioner, or another
lawful transfer mechanism. Where Swiss data protection law applies, the EU standard contractual
clauses apply with the amendments recognized by the Swiss Federal Data Protection and
Information Commissioner.
9. Retention
9.1 We retain personal data only for as long as necessary for the purposes described in this
Policy, including to comply with legal obligations, resolve disputes and enforce our agreements.
In particular:
– Account and Subscription data is retained for the duration of the contractual relationship
and thereafter for the length of the applicable limitation periods for legal claims;
– billing, invoicing and tax records are retained for the periods required by applicable
accounting and tax law;
– Inputs and Outputs are kept available for retrieval for 30 calendar days after an Account
or Subscription ends, as provided in the Terms. Where we terminate for fraud, unlawful
activity, a breach of the prohibited content rules in the Terms, or because a law, regulator,
court or provider requires us to do so, that period may be shortened or withheld as
provided in the Terms, and we will make material available only to the extent we are legally
required to do so. After the applicable period we may permanently delete Inputs and
Outputs and are under no obligation to retain them, subject to our standard retention and
backup cycles and any legal hold;
– usage data, including log data and IP addresses, is retained for up to 24 months from
collection, except where it is retained for longer to investigate a security incident, to
strengthen the security of the Services, to establish, exercise or defend legal claims, or
where longer retention is required by law;
– backup copies are overwritten in the ordinary course of our backup cycle, and personal
data deleted from our live systems is deleted from backups within 90 days;
– data anonymized or aggregated so that it no longer relates to an identified or identifiable
individual may be retained without restriction.
10. Security
10.1 We maintain technical and organizational measures appropriate to the risks presented by
the processing. These include role-based access control on a least-privilege basis, multi-factor
authentication for administrative access, encryption of personal data in transit using TLS,
encryption of personal data at rest, logging and monitoring of access to production systems, and
organizational safeguards including written confidentiality obligations for staff and contractors. No
security measure can guarantee that every unauthorized access, loss or security incident will be
prevented.
10.2 You are responsible for keeping Account credentials secure and must notify us at
support@tryholo.ai within 24 hours after becoming aware of any actual or suspected unauthorized
access to your Account, as required by the Terms.
10.3 Personal data breaches. Where we become aware of a personal data breach affecting
personal data that we process as your processor under Section 3.1, we will notify you without
undue delay after becoming aware of it and will provide the information and reasonable assistance
you need in order to meet your own notification obligations. Where we act as controller, we will
notify the competent supervisory authority and affected individuals where and as required by
applicable law.
11. Your Rights
11.1 Depending on the law applicable to you, you may have the right to request access to,
rectification or erasure of your personal data, restriction of or objection to its processing, and
portability of the data you provided, and the right to withdraw consent at any time where
processing is based on consent, without affecting the lawfulness of processing carried out before
withdrawal.
11.2 You may exercise these rights, and update your information at any time, through your
Account settings or by contacting us at support@tryholo.ai. We may need to verify your identity
before acting on a request, and we may retain certain information where we have a legal obligation
or another lawful basis to do so.
11.3 Where we act as processor for personal data contained in Inputs (Section 3.1), requests
from individuals should be addressed to the relevant business customer as controller. We will
forward such requests to the customer and will provide reasonable assistance as required by
applicable law.
11.4 If you consider that our processing infringes applicable data protection law, you have the
right to lodge a complaint with a supervisory authority, in particular the Lithuanian State Data
Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312
Vilnius, Lithuania, vdai.lrv.lt) or the supervisory authority of your habitual residence or place of
work. Where no EU, UK or Swiss data protection law applies to the processing, the rights available
to you are described in Section 12. We would, however, appreciate the opportunity to address
your concerns first.
12. Additional Information for United States Residents
12.1 This Section applies to individuals who are residents of a US state with a comprehensive
privacy law, including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana and
Utah, and supplements the rest of this Policy. Terms used in this Section have the meanings
given to them in the applicable state law. Where a term in this Section conflicts with the rest of
this Policy, this Section prevails for residents of those states.
12.2 Categories we collect. In the twelve months preceding the date of this Policy we have
collected the categories of personal information described in Section 4, namely identifiers,
commercial information, internet and other electronic network activity information, professional or
employment-related information, audio, electronic and visual information contained in Inputs and
Outputs, and inferences drawn from that information. We collect it from you, from your Authorized
Users, from your use of the Services and from our service providers. The purposes for which we
use it are described in Sections 5 and 6, and the categories of recipients to which we disclose it
are described in Section 7. We retain each category for the periods described in Section 9.
12.3 Sensitive personal information. We do not seek to collect sensitive personal information
and we do not use or disclose it for any purpose other than those for which a right to limit use
does not apply under applicable law. Inputs and Outputs may contain sensitive personal
information only where you choose to submit it, and you are responsible for the lawfulness of
doing so.
12.4 No sale and no sharing. We do not sell personal information, and we do not share personal
information for cross-context behavioral advertising or targeted advertising. We have not done so
in the twelve months preceding the date of this Policy. We do not knowingly sell or share the
personal information of individuals under 16 years of age.
12.5 Your rights. Subject to the applicable state law, you may request to know what personal
information we hold about you and to access it, to receive a portable copy of it, to correct
inaccurate personal information, and to delete personal information. We will not discriminate
against you for exercising any of these rights.
12.6 How to exercise your rights. Submit a request by emailing support@tryholo.ai with "Privacy
Request" in the subject line. We verify a request using information already associated with your
Account or, where you do not hold an Account, information reasonably necessary to confirm your
identity, and we use that information only for verification. An authorized agent may submit a
request on your behalf with written authorization, which we may confirm with you directly. We
respond within the period required by the applicable state law. If we decline a request, you may
appeal by replying to our response with "Appeal" in the subject line; we will inform you of the
outcome and, where your appeal is denied, of how to contact your state attorney general.
12.7 Where we process personal information on behalf of a business customer under Section 3.1,
we act as that customer’s service provider or processor and we do not retain, use or disclose that
information for any purpose other than performing the Services, except as permitted by applicable
law. Requests from individuals in that case should be addressed to the business customer, as
described in Section 11.3.
12.8 California "Shine the Light". California residents may request information about our
disclosures of personal information to third parties for those third parties’ own direct marketing
purposes. As stated in Section 7.2, we do not make such disclosures.
13. Cookies and Similar Technologies
13.1 We use cookies, web beacons, tags, scripts and similar technologies on our websites and in
the Services. These include:
– strictly necessary cookies, which enable core functionality such as authentication, session
management, security and fraud prevention, and which cannot be switched off in our
systems;
– functionality cookies, which remember your choices, such as login details and language
preferences; and
– analytics and performance cookies, which help us understand how the Services are used
and improve them.
13.2 Where required by applicable law, we deploy non-essential cookies only with your consent,
which you may withdraw or adjust at any time through the cookie settings on our websites or your
browser settings. Refusing cookies may limit your ability to use some parts of the Services.
14. Children
14.1 The Services are intended for business and professional use only and are not directed at
anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If
you believe that a person under 18 has provided us with personal data, contact us at
support@tryholo.ai and we will take steps to delete it.
15. Third-Party Websites
15.1 The Services may contain links to websites or services that we do not operate. This Policy
does not apply to those websites or services, and we are not responsible for their content or
privacy practices. We recommend that you review the privacy policy of every site you visit.
16. Changes to this Policy
16.1 We may update this Policy from time to time. We will post the updated Policy on this page
and revise the "Last updated" date above. Where a change materially affects how we process
personal data as controller, we will provide notice through your Account or by email before the
change takes effect, except where an immediate change is required by applicable law. Where
processing is based on your consent, we will not treat continued use as agreement to a change
and will ask for consent again where required. Otherwise, your continued use of the Services after
a change takes effect means that the updated Policy applies.
17. Contact
Email: support@tryholo.ai Website: https://tryholo.ai
Company: Holo AI Inc. (3500 South Dupont Highway, Dover, Delaware 19901, USA)