Privacy Policy
Last updated:
1. Introduction and Scope
1.1 This Privacy Policy ("Policy") describes how the Holo Group collects, uses, discloses and otherwise
processes personal data in connection with the Holo AI-powered platform available at
https://tryholo.ai and https://app.tryholo.ai, and any related tools, features, applications and services
(together, the "Services"). The Services are made available at those domains and at any successor or
additional domain we use for that purpose, and this Policy applies to all of them.
1.2 Capitalized terms used but not defined in this Policy have the meanings given to them in the Holo
Terms of Service (the "Terms"), available at https://tryholo.ai/policies/terms. This Policy forms part
of the framework described in the Terms; in the event of any conflict between this Policy and the
Terms regarding contractual rights and obligations, the Terms prevail.
1.3 The Services are available only for business or professional use and are not offered to consumers.
This Policy therefore applies primarily to personal data relating to the representatives, employees,
contractors and Authorized Users of our business customers, to visitors of our websites, and to
individuals whose personal data is contained in Inputs or Outputs.
2. Who Is Responsible for Your Personal Data
2.1 "Holo Group" means UAB Holo LT, a Lithuanian private limited liability company with its registered
office at Perkūnkiemio g. 19, LT-12120 Vilnius, Republic of Lithuania, and Holo AI Inc., a Delaware
corporation with its registered office at 3500 South Dupont Highway, Dover, Delaware 19901, USA,
together with their Affiliates.
2.2 Where we act as controller, the entity responsible for your personal data is the entity that is your
counterparty under the Terms: Holo AI Inc. if your billing address is in the United States, and UAB
Holo LT in every other case. Where your Account has not been allocated to a market, or you interact
with us without an Account, UAB Holo LT is the controller.
2.3 Holo Group entities may share personal data with each other where necessary to operate the
Services, including to collect payments as payment collection agent for your counterparty, to retry
failed charges through another Holo Group entity, and to give effect to a transfer of the Terms to
another Holo Group entity, in each case as described in the Terms. Payment routing between Holo
Group entities does not change the entity responsible for your personal data as controller.
3. Our Role: Controller and Processor
3.1 Processor when we provide the Services to you. Where we process personal data contained in
Inputs in order to provide the Services to you, you (our business customer) are the controller and we
are the processor. We process such data on your documented instructions, which are set out in the
Terms, in the Data Processing Agreement referred to in Section 3.4 and in your use of the Services.
You are responsible for ensuring that you have all rights, permissions, consents and legal bases
required to submit personal data in Inputs, including any consents required to process or synthetically
reproduce the name, image, likeness or voice of an identifiable person.
3.2 Independent controller when we develop and improve the Services. Section 8.4 of the Terms
permits us to use Inputs, Outputs and associated usage data to develop, train, fine-tune, test,
evaluate, secure and improve the Services, AI models and related datasets. That use is for our own
purposes and is not carried out on your instructions. We therefore do not act as your processor for
that activity: to the extent it involves personal data, we act as an independent controller and are
responsible for establishing a valid legal basis for it. Section 6 describes that activity and the limits
that apply to it.
3.3 Independent controller for our own operations. Where we process personal data for our own
purposes, including account administration, billing, security, fraud prevention, analytics and
compliance, we act as an independent controller. Each party is responsible for complying with the
data protection laws applicable to its own processing.
3.4 Data Processing Agreement. Our Data Processing Agreement (the "DPA"), available at
https://tryholo.ai/policies/dpa, sets out the terms on which we process personal data as your
processor under Section 3.1. It covers the subject matter, duration, nature and purpose of the
processing, the types of personal data and categories of data subjects, and our obligations as to
confidentiality, security, sub-processing, assistance with data subject requests and data protection
impact assessments, breach notification, audit, and the return or deletion of data, together with the
transfer mechanisms that apply. The DPA is incorporated into the Terms and applies automatically
from the moment you first submit personal data in Inputs. You do not need to request it or sign it
separately. If you require a countersigned copy, or wish to propose your own form of DPA, contact
us at support@tryholo.ai.
4. Personal Data We Collect
4.1 We collect the following categories of personal data:
– Account and registration data: name, business email address, authentication data (passwords
are stored only in salted, hashed form and are not accessible to us in plain text), company
name, role, and, where requested under the Terms, company registration, VAT or tax
numbers and evidence of authority;
– Billing and payment data: billing address, invoice details, transaction history, and payment
credentials stored and used by Holo Group entities and our payment providers in accordance
with the Terms. Full card numbers are processed by our payment providers, not stored by us;
– Inputs and Outputs: prompts, instructions, briefs, files, images, video, audio, Brand Materials
and other content you or your Authorized Users submit to the Services, and the content
generated in response, in each case to the extent they contain personal data;
– Usage data: features used, generations initiated, Credit consumption, log data, IP address,
browser type and version, device identifiers, operating system, pages visited, and the dates,
times and duration of use;
– Communications data: support requests, correspondence and related metadata sent to or
from support@tryholo.ai or through the Services;
Cookie and tracking data, as described in Section 13; and
– Compliance data: information reasonably necessary for sanctions screening, fraud prevention
and the verification of business or professional use, as contemplated by the Terms.
5. Purposes and Legal Bases
5.1 Where we act as controller, we process personal data for the following purposes and on the
following legal bases:
– to provide, operate and support the Services, manage Accounts and Subscriptions, allocate
Credits and provide technical support — performance of a contract, or our legitimate interest
in serving the business you represent;
– to bill and collect Fees, issue invoices, process refunds under the Terms and manage payment
disputes and chargebacks — performance of a contract and compliance with legal obligations;
– to secure the Services, prevent fraud and abuse, enforce Credit and rate limits, investigate
suspected breaches of the Terms and act on notices of unauthorized Account access — our
legitimate interests in protecting the Services, our customers and our providers;
– to comply with legal obligations, including accounting and tax law, sanctions law and lawful
requests from authorities — compliance with legal obligations;
– to analyze usage, measure performance and develop, test, evaluate, secure and improve the
Services and the AI models used to provide them, as further described in Section 6 — our
legitimate interests, or consent where required;
– to send service communications regarding the Services, Subscriptions, renewals, price
changes and changes to the Terms — performance of a contract and compliance with legal
obligations;
– to send marketing communications about our products and services — our legitimate interest
in marketing to business contacts, or consent where required by applicable law. You may opt
out at any time; and
– to establish, exercise or defend legal claims, including under the dispute resolution provisions
of the Terms — our legitimate interests.
6. AI Development and Model Training
6.1 Under Section 8.4 of the Terms, we and our Affiliates may use Inputs, Outputs and associated
usage data to develop, train, fine-tune, test, evaluate, secure and improve the Services, AI models
and related datasets, including services made available to other customers, and may exercise this
right through our model, infrastructure and technology providers. As explained in Section 3.2, we act
as an independent controller for this activity and not as your processor.
6.2 To the extent that Inputs or Outputs contain personal data, we use them for the purposes
described in Section 6.1 only where that data has been anonymized or aggregated, or where we have
an appropriate legal basis for the processing under applicable data protection law. Where we rely on
legitimate interests, we carry out and record a balancing assessment before doing so, and you or the
individual concerned may object to that processing as described in Section 11.
6.3 The Services depend on third-party AI models, APIs and infrastructure. Inputs and Outputs may
be processed by those providers in order to generate Outputs and operate the Services. We will not
intentionally publish your Inputs or Outputs as customer-facing marketing materials in a manner that
identifies you, or identify you as a customer, without your consent.
6.4 Limits of deletion. Where personal data has already been used to train or fine-tune an AI model,
it is generally not technically possible to remove the influence of that data from the model once
trained. We will delete the underlying personal data from our systems in accordance with Section 9
and will act on valid erasure requests in respect of that data, but we cannot reverse training that has
already taken place. If you need to prevent Inputs from being used for the purposes described in
Section 6.1, contact us at support@tryholo.ai before submitting them; any restriction on the licence
granted in Section 8.4 of the Terms must be agreed by us in writing.
7. How We Share Personal Data
7.1 We share personal data with:
– Holo Group entities, for the purposes and in the circumstances described in Section 2.3;
– service providers acting on our behalf, including hosting and infrastructure providers, AI
model and API providers, payment providers, acquirers and card schemes, analytics
providers, communication and support tooling providers, and fraud prevention services, in
each case under contracts that restrict their use of the data;
– professional advisers, including lawyers, auditors and accountants, where reasonably
necessary;
– courts, arbitral tribunals, regulators, law enforcement and other public authorities, where we
are required or permitted to do so by applicable law, or where reasonably necessary to
establish, exercise or defend legal claims, protect the rights, property or safety of the Holo
Group, our customers or others, or investigate suspected wrongdoing in connection with the
Services;
– an acquirer or successor in connection with a merger, reorganization, financing or sale of all or
part of our business or assets, in accordance with the assignment provisions of the Terms;
and
– other recipients with your consent or at your direction.
7.2 We do not sell personal data, and we do not share personal data with third parties for their own
direct marketing purposes.
7.3 Sub-processors. A current list of the sub-processors we engage to process personal data on behalf
of our customers, including their location and the purpose for which they are engaged, is available at
https://tryholo.ai/policies/subprocessors. We will give notice of the intended addition or
replacement of a sub-processor as provided in the DPA, and you may object on reasonable data
protection grounds in accordance with the DPA.
8. International Transfers
8.1 We and our providers may process personal data in the European Economic Area, the United
States and other countries in which they operate. Where personal data is transferred outside the EEA
(or the United Kingdom or Switzerland, where their laws apply), the transfer will be subject to an
adequacy decision, standard contractual clauses approved by the European Commission or another
lawful transfer mechanism, together with supplementary measures where required.
8.2 A copy of the relevant transfer safeguards may be requested at support@tryholo.ai, subject to
redaction of commercially sensitive terms.
8.3 Where the UK GDPR applies, transfers of personal data out of the United Kingdom are made under
the International Data Transfer Agreement or the International Data Transfer Addendum to the EU
standard contractual clauses issued by the UK Information Commissioner, or another lawful transfer
mechanism. Where Swiss data protection law applies, the EU standard contractual clauses apply with
the amendments recognized by the Swiss Federal Data Protection and Information Commissioner.
9. Retention
9.1 We retain personal data only for as long as necessary for the purposes described in this Policy,
including to comply with legal obligations, resolve disputes and enforce our agreements. In
particular:
– Account and Subscription data is retained for the duration of the contractual relationship and
thereafter for the length of the applicable limitation periods for legal claims;
– billing, invoicing and tax records are retained for the periods required by applicable
accounting and tax law;
– Inputs and Outputs are kept available for retrieval for 30 calendar days after an Account or
Subscription ends, as provided in the Terms. Where we terminate for fraud, unlawful activity,
a breach of the prohibited content rules in the Terms, or because a law, regulator, court or
provider requires us to do so, that period may be shortened or withheld as provided in the
Terms, and we will make material available only to the extent we are legally required to do
so. After the applicable period we may permanently delete Inputs and Outputs and are under
no obligation to retain them, subject to our standard retention and backup cycles and any
legal hold;
– usage data, including log data and IP addresses, is retained for up to 24 months from
collection, except where it is retained for longer to investigate a security incident, to
strengthen the security of the Services, to establish, exercise or defend legal claims, or where
longer retention is required by law;
– backup copies are overwritten in the ordinary course of our backup cycle, and personal data
deleted from our live systems is deleted from backups within 90 days;
– data anonymized or aggregated so that it no longer relates to an identified or identifiable
individual may be retained without restriction.
10. Security
10.1 We maintain technical and organizational measures appropriate to the risks presented by the
processing. These include role-based access control on a least-privilege basis, multi-factor
authentication for administrative access, encryption of personal data in transit using TLS, encryption
of personal data at rest, logging and monitoring of access to production systems, and organizational
safeguards including written confidentiality obligations for staff and contractors. No security measure
can guarantee that every unauthorized access, loss or security incident will be prevented.
10.2 You are responsible for keeping Account credentials secure and must notify us at
support@tryholo.ai within 24 hours after becoming aware of any actual or suspected unauthorized
access to your Account, as required by the Terms.
10.3 Personal data breaches. Where we become aware of a personal data breach affecting personal
data that we process as your processor under Section 3.1, we will notify you without undue delay
after becoming aware of it and will provide the information and reasonable assistance you need in
order to meet your own notification obligations. Where we act as controller, we will notify the
competent supervisory authority and affected individuals where and as required by applicable law.
11. Your Rights
11.1 Depending on the law applicable to you, you may have the right to request access to, rectification
or erasure of your personal data, restriction of or objection to its processing, and portability of the
data you provided, and the right to withdraw consent at any time where processing is based on
consent, without affecting the lawfulness of processing carried out before withdrawal.
11.2 You may exercise these rights, and update your information at any time, through your Account
settings or by contacting us at support@tryholo.ai. We may need to verify your identity before acting
on a request, and we may retain certain information where we have a legal obligation or another
lawful basis to do so.
11.3 Where we act as processor for personal data contained in Inputs (Section 3.1), requests from
individuals should be addressed to the relevant business customer as controller. We will forward such
requests to the customer and will provide reasonable assistance as required by applicable law.
11.4 If you consider that our processing infringes applicable data protection law, you have the right
to lodge a complaint with a supervisory authority, in particular the Lithuanian State Data Protection
Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania,
vdai.lrv.lt) or the supervisory authority of your habitual residence or place of work. Where your
counterparty is Holo AI Inc. and no EU, UK or Swiss data protection law applies to the processing, the
rights available to you are described in Section 12. We would, however, appreciate the opportunity
to address your concerns first.
12. Additional Information for United States Residents
12.1 This Section applies to individuals who are residents of a US state with a comprehensive privacy
law, including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana and Utah, and
supplements the rest of this Policy. Terms used in this Section have the meanings given to them in
the applicable state law. Where a term in this Section conflicts with the rest of this Policy, this Section
prevails for residents of those states.
12.2 Categories we collect. In the twelve months preceding the date of this Policy we have collected
the categories of personal information described in Section 4, namely identifiers, commercial
information, internet and other electronic network activity information, professional or employment-
related information, audio, electronic and visual information contained in Inputs and Outputs, and
inferences drawn from that information. We collect it from you, from your Authorized Users, from
your use of the Services and from our service providers. The purposes for which we use it are
described in Sections 5 and 6, and the categories of recipients to which we disclose it are described
in Section 7. We retain each category for the periods described in Section 9.
12.3 Sensitive personal information. We do not seek to collect sensitive personal information and we
do not use or disclose it for any purpose other than those for which a right to limit use does not apply
under applicable law. Inputs and Outputs may contain sensitive personal information only where you
choose to submit it, and you are responsible for the lawfulness of doing so.
12.4 No sale and no sharing. We do not sell personal information, and we do not share personal
information for cross-context behavioral advertising or targeted advertising. We have not done so in
the twelve months preceding the date of this Policy. We do not knowingly sell or share the personal
information of individuals under 16 years of age.
12.5 Your rights. Subject to the applicable state law, you may request to know what personal
information we hold about you and to access it, to receive a portable copy of it, to correct inaccurate
personal information, and to delete personal information. We will not discriminate against you for
exercising any of these rights.
12.6 How to exercise your rights. Submit a request by emailing support@tryholo.ai with "Privacy
Request" in the subject line. We verify a request using information already associated with your
Account or, where you do not hold an Account, information reasonably necessary to confirm your
identity, and we use that information only for verification. An authorized agent may submit a request
on your behalf with written authorization, which we may confirm with you directly. We respond
within the period required by the applicable state law. If we decline a request, you may appeal by
replying to our response with "Appeal" in the subject line; we will inform you of the outcome and,
where your appeal is denied, of how to contact your state attorney general.
12.7 Where we process personal information on behalf of a business customer under Section 3.1, we
act as that customer’s service provider or processor and we do not retain, use or disclose that
information for any purpose other than performing the Services, except as permitted by applicable
law. Requests from individuals in that case should be addressed to the business customer, as
described in Section 11.3.
12.8 California "Shine the Light". California residents may request information about our disclosures
of personal information to third parties for those third parties’ own direct marketing purposes. As
stated in Section 7.2, we do not make such disclosures.
13. Cookies and Similar Technologies
13.1 We use cookies, web beacons, tags, scripts and similar technologies on our websites and in the
Services. These include:
– strictly necessary cookies, which enable core functionality such as authentication, session
management, security and fraud prevention, and which cannot be switched off in our
systems;
functionality cookies, which remember your choices, such as login details and language
preferences; and
– analytics and performance cookies, which help us understand how the Services are used and
improve them.
13.2 Where required by applicable law, we deploy non-essential cookies only with your consent,
which you may withdraw or adjust at any time through the cookie settings on our websites or your
browser settings. Refusing cookies may limit your ability to use some parts of the Services.
14. Children
14.1 The Services are intended for business and professional use only and are not directed at anyone
under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe
that a person under 18 has provided us with personal data, contact us at support@tryholo.ai and we
will take steps to delete it.
15. Third-Party Websites
15.1 The Services may contain links to websites or services that we do not operate. This Policy does
not apply to those websites or services, and we are not responsible for their content or privacy
practices. We recommend that you review the privacy policy of every site you visit.
16. Changes to this Policy
16.1 We may update this Policy from time to time. We will post the updated Policy on this page and
revise the "Last updated" date above. Where a change materially affects how we process personal
data as controller, we will provide notice through your Account or by email before the change takes
effect, except where an immediate change is required by applicable law. Where processing is based
on your consent, we will not treat continued use as agreement to a change and will ask for consent
again where required. Otherwise, your continued use of the Services after a change takes effect
means that the updated Policy applies.
17. Contact
Email: support@tryholo.ai Website: https://tryholo.ai
Company: UAB Holo LT (Perkūnkiemio g. 19, LT-12120 Vilnius, Republic of Lithuania) and Holo AI Inc.
(3500 South Dupont Highway, Dover, Delaware 19901, USA). The entity responsible for your personal
data is determined in accordance with Section 2 of this Policy.