Privacy Policy

For the privacy policy of immerGallery, immerGallery Business and immerGallery Demo in the Meta Horizon Store, please click here.

Privacy Policy – immerVR GmbH

Last updated: 22 August 2026

1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

immerVR GmbH
Im Zollstock 12
91093 Heßdorf
Germany
Managing Director: Daniel Pohl
Email: support@immervr.com

If you have any questions about data protection or wish to exercise your data protection rights, you can contact us using the email or postal address above.

2. Scope of this Privacy PolicyThis Privacy Policy applies to the processing of personal data in connection with our websites, apps, online services and online presences, including in particular:
https://www.immerVR.com
https://www.imrVR.com
https://www.immerVR.de
immerGallery
immerGallery Demo
immerGallery Business
immerGallery Web
our community and social media presences

Our apps may be distributed through platforms including the Meta Horizon Store, Steam, PICO Store and Google Play.Where this Privacy Policy refers to an external platform or service, that provider may additionally process personal data under its own responsibility and according to its own privacy policy.

3. General Principles of Data ProcessingWe process personal data only where necessary for the purposes described in this Privacy Policy and where there is a legal basis for the processing.Depending on the processing activity, the relevant legal bases are in particular:Art. 6(1)(a) GDPR – consent, for example for subscribing to our newsletter;
Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures, for example when providing app functionality, purchases, licenses, support or requested online features;
Art. 6(1)(c) GDPR – compliance with a legal obligation, for example where data must be retained for tax or accounting purposes;
Art. 6(1)(f) GDPR – legitimate interests, for example for the secure and reliable operation of our services, prevention of misuse, troubleshooting, community operation and communication.

Where we rely on legitimate interests, our interests are balanced against the rights and interests of the affected persons.We do not sell personal data.

A. PRIVACY INFORMATION FOR OUR WEBSITE

4. Website Hosting and Server Log FilesOur main website and email services are hosted by:

STRATO AG, Germany

When you visit our website, the web server technically processes information required to deliver the website and maintain the security and stability of the service.This may include:IP address;
date and time of the request;
requested page or file;
HTTP status code;
amount of data transferred;
referrer information;
browser type and version;
operating system and related technical information.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and reliable operation of our website.STRATO provides us with access logs in which client IP addresses are anonymized. These access logs are generally available to us for up to six weeks.We do not use these server logs for advertising or user profiling.

5. Cookies, Tracking and External Website ResourcesOur website currently does not use analytics or advertising tracking.

In particular, we do not use:
Google Analytics;
advertising or conversion pixels;
Meta/Facebook tracking;
Google Ads tracking;
Reddit advertising tracking;
X/Twitter advertising tracking;
cookies for advertising or behavioral analytics;
browser localStorage for tracking purposes;
externally loaded Google Fonts;
external content-delivery networks for tracking purposes;
CAPTCHA or reCAPTCHA;
embedded YouTube videos.

We do not currently use non-essential cookies or comparable technologies on our website that require consent under § 25 TDDDG.If our technical setup changes in the future, we will update this Privacy Policy and implement a consent mechanism where required by law.Links to external websites or social networks do not by themselves cause those providers to process data through our website. When you follow such a link, however, your browser connects to the respective external service and that provider's privacy rules apply.

6. Contact Form and Email ContactOur website provides a contact form operated by us.When you submit the contact form, the information you enter, such as your name, email address and message, is processed in order to respond to your enquiry.The contact form is handled by our own website/backend. The submitted message is sent directly to our email account hosted by STRATO. We do not store contact-form submissions in a separate website database.The legal basis is:Art. 6(1)(b) GDPR where your enquiry concerns a contract, purchase, support request or pre-contractual matter; or
Art. 6(1)(f) GDPR for other enquiries, based on our legitimate interest in communicating with users and responding to enquiries.
The same principles apply when you contact us directly by email.Correspondence is retained only for as long as necessary to deal with the respective matter. Where communications form part of a contractual or business relationship, statutory commercial or tax-related retention obligations may require longer storage.

7. Newsletter and Brevo
You may voluntarily subscribe to our newsletter.For newsletter delivery we use Brevo.Our newsletter subscription field is implemented as an HTML form on our website. Your browser does not need to connect to Brevo merely to display this form. When you submit the form, however, the information entered in the form is transmitted directly to Brevo.We process your email address for the purpose of sending the newsletter on the basis of your consent pursuant to Art. 6(1)(a) GDPR.We use a double opt-in procedure. After registration, you receive a confirmation request. Your newsletter subscription becomes active after confirmation. Information relating to registration and confirmation, including relevant timestamps and technical information such as the IP address where applicable, may be processed in order to document the consent.Brevo acts as our email marketing service provider.Privacy information from Brevo is available at:https://www.brevo.com/legal/privacypolicy/

Anonymous newsletter statistics
Brevo's Anonymous Email Tracking feature is enabled for our newsletter campaigns.Brevo may technically measure email openings and link clicks in order to create overall campaign statistics. With anonymous tracking enabled, opening and clicking information is not associated with identifiable individual newsletter contacts in the reports available to us.We therefore receive aggregate statistics such as overall opening and click rates, but we cannot determine from these statistics which particular subscriber opened an email or clicked a particular link.We do not use Brevo for transactional emails.

Withdrawal of newsletter consent

You may withdraw your newsletter consent at any time, for example by using the unsubscribe link contained in each newsletter.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.After unsubscribing, your address will no longer be used for newsletter delivery. Limited information may be retained where necessary to document the previous consent, comply with legal obligations or ensure that an unsubscribed address is not inadvertently added to the mailing list again.

B. PRIVACY INFORMATION FOR OUR APPS

8. App Distribution Through Third-Party StoresOur apps are or may be distributed through third-party stores, including:
Meta Horizon Store;
Steam;
PICO Store;
Google Play.

The respective store provider is responsible for the operation of its store, user accounts, downloads and the payment processes it provides.Depending on the platform, the store provider may process information such as:account and platform identifiers;
purchase and transaction information;
payment information;
device information;
app downloads and installations;
refund information;
usage or crash statistics;
country or region information.
We do not control the data processing performed independently by these platform operators.Please refer to the respective provider's privacy information:

Meta: https://www.meta.com/legal/privacy-policy/
Steam / Valve: https://store.steampowered.com/privacy_agreement/
PICO: https://www.picoxr.com/global/legal/privacy-policy
Google: https://policies.google.com/privacy

We do not receive complete payment-card or bank-account details from these app stores.

9. Platform User IDs and Pseudonymous User Accounts

Certain app functionality requires us to identify the same platform user across app sessions, reinstallations or devices.Depending on the platform, our app may receive a platform-specific user identifier, for example a Meta User ID, Steam User ID, PICO User ID or corresponding Google Play identifier.For storage in our own systems, we immediately transform the platform identifier into a one-way hash.

We do not store the original plain platform User ID in our backend database. The resulting hashed identifier is pseudonymous data. It may still constitute personal data because it can be associated with the same user over time.We use the hashed identifier in particular to:
identify the same app user across sessions;
manage the user's StereoGold balance;
record purchased or unlocked reward galleries;
restore rewards and entitlements after reinstalling the app;
enforce limits for certain online functions;
associate technical account information with the correct app user.

The legal basis is Art. 6(1)(b) GDPR, as this processing is necessary to provide the relevant app functionality.The backend containing this information is operated by us on servers hosted by Hetzner in Germany.
We retain this information for as long as the respective user account or app functionality requires it. If you request deletion, we will delete or anonymize the corresponding records where possible, unless statutory obligations or overriding legal reasons require further retention.
Because we do not store your original platform ID, we may need appropriate information from you to identify the correct pseudonymous record when processing a data access or deletion request.

10. Meta Platform Features

On Meta Quest devices, our apps use Meta platform features including:
Meta User ID;
Meta username/user profile;
Meta profile picture;
Meta Avatars;
Meta entitlement checks;
displaying usernames and/or avatars in multiplayer functionality.

These features are used in order to provide app functionality requested by the user.For example, they may be used to:verify that you are entitled to use the app;
identify you within the app;
display your Meta username, profile picture or Avatar;
allow you to recognize yourself and other users during multiplayer sessions;
associate your rewards and StereoGold with your pseudonymous account;
restore your progress and unlocked content.

The persistent identifier stored in our own backend is the hashed identifier described above rather than the plain Meta User ID.Meta may independently process additional account or platform information when providing these features. We do not control Meta's independent platform processing.The legal basis for our processing is Art. 6(1)(b) GDPR.We do not use Meta User IDs or their hashes for advertising or cross-service advertising profiles.

11. App Backend and Hosting

Our APIs, databases and app backend services are hosted on servers operated by:Hetzner Online GmbH, GermanyThe servers used by us for these services are located in Germany.Depending on the feature being used, our backend may process technical data necessary to provide the service, such as:
IP address;
timestamps;
technical request information;
app version;
session or request identifiers;
pseudonymous hashed platform User ID;
error information;
information necessary to provide requested app functionality.

The legal basis is Art. 6(1)(b) GDPR where the processing is required to provide a requested service or app feature, and Art. 6(1)(f) GDPR for security, troubleshooting and abuse prevention.Hetzner acts as a hosting provider and processor where it processes personal data on our behalf.

12. Voluntary Developer Log Submissions
Our apps allow users to voluntarily submit a developer log if they encounter a problem and want to provide diagnostic information to us.A developer log is sent to us only when the user explicitly chooses to submit it.Depending on the circumstances, a submitted developer log may contain technical information such as:
a partially anonymized IP address;
submission date, time and time zone;
app version;
VR headset and controller information;
Android permission status and relevant environment settings;
information about buttons, interactions and events occurring before an error;
HMD-related events such as headset mounting, focus and tracking events;
recentering events;
entitlement-check results;
app settings;
technical memory and performance statistics;
frame rate and frame timing;
CPU and GPU levels;
rendering information such as draw calls or triangle counts;
local file paths or filenames that may appear in log output;
usage statistics relevant to diagnosing the problem;
purchased add-ons and/or unlocked rewards;
recognized voice-control commands stored as text.
Voice-control audio itself is not included in these logs.Developer logs are stored on our Hetzner server. A notification containing a link to the submitted log is sent to us so that we can investigate the reported problem.The legal basis is Art. 6(1)(b) GDPR where the log is submitted in connection with support or the provision of the app, and Art. 6(1)(f) GDPR based on our legitimate interest in diagnosing errors, maintaining app stability and improving the service.Developer logs are normally deleted no later than 12 months after submission, unless the log remains necessary for an ongoing support, security or technical investigation.

13. Local Voice Control

Voice-control recognition inside our app is performed locally on the user's device.We do not send voice-control audio to our servers or to a cloud speech-recognition service.Recognized commands may appear as text in a developer log. Such text is transmitted to us only if the user voluntarily submits that developer log as described above.

14. Multiplayer – Photon Fusion and Photon Voice

Our apps use Photon Fusion and Photon Voice to provide multiplayer and real-time voice communication.The provider is:
Exit Games GmbH / Photon
Privacy information:https://www.photonengine.com/en-US/PrivacyPolicy

When you use multiplayer functionality, your device connects to Photon infrastructure.Depending on the multiplayer session, information processed may include:
IP address and network information;
session identifiers;
technical device information;
app version;
multiplayer events required to synchronize the session;
your selected player name;
administrative status within a multiplayer session;
information needed to determine which galleries are available to the participants;
gallery names;
number of available content files or galleries;
where technically necessary for synchronization, information relating to local file paths.

Your plain Meta, Steam, PICO or Google platform User ID is not shared with other multiplayer participants.

Voice communication
Photon Voice is used to transmit voice communication between multiplayer participants in real time.immerVR does not record or store voice-chat audio.Voice audio is transmitted through the Photon service for the purpose of enabling live voice communication. For information about processing carried out within Photon's infrastructure, please refer to Photon's privacy information.The legal basis for multiplayer and voice processing is Art. 6(1)(b) GDPR because the processing is necessary to provide the multiplayer functionality requested by the user.We use Photon under the applicable data-processing arrangements.Photon operates globally distributed infrastructure. As a result, network and multiplayer data may be processed outside the European Economic Area. Where required, appropriate safeguards for international data transfers apply.

15. OpenStreetMap

Our apps can display maps based on geographic information associated with images or settings used in an .immerVR file.For this functionality we use map material provided through OpenStreetMap.The app connects directly from the user's device to OpenStreetMap infrastructure. We do not proxy this connection through our own servers.As a result, OpenStreetMap may receive technical connection information such as:the user's IP address;
time of the request;
technical request information;
requested map tiles or similar map information.
The requested map area can indirectly reveal the geographic area being displayed.The map location may originate from GPS metadata contained in an image or from location information selected or configured by the user.The legal basis for our use of this functionality is Art. 6(1)(b) GDPR because the external request is necessary to provide the map feature requested by the user.Information about OpenStreetMap's processing is available at:https://wiki.osmfoundation.org/wiki/Privacy_Policy

16. Pastebin Access

Our apps include an optional function that allows a user to retrieve text from Pastebin.The app contains a predefined pastebin.com address. The user can enter a Pastebin identifier and explicitly press a button to retrieve the corresponding content.Only when the user activates this function does the app make a direct web request to Pastebin.This operates similarly to opening a limited external web resource. Pastebin may therefore receive the user's IP address and technical information associated with the request.We do not control the content the user chooses to retrieve from Pastebin.The legal basis for initiating the connection is Art. 6(1)(b) GDPR because it is performed only in response to the user's explicit request to use this feature.Pastebin's privacy information is available at:
https://pastebin.com/doc_privacy_statement

Users should be aware that Pastebin is an external service and that information published publicly on Pastebin may be accessible to third parties.

17. Spatial Conversion Service

Our apps provide optional server-based spatial conversion functionality.When you explicitly request a spatial conversion, the relevant files are uploaded to our servers hosted by Hetzner in Germany.

Processing of uploaded files
Files are encrypted on the device before upload.For conversion, the files are temporarily processed on our server. They are decrypted only as required to perform the requested conversion and the result is encrypted again for retrieval by the app.Original filenames are anonymized before upload and restored locally by the app where applicable.The download information for a completed conversion is provided to the requesting immerGallery app.

Uploaded source files and generated result files are stored only temporarily and are deleted:
after successful processing/retrieval where appropriate; or
no later than 24 hours after upload.

We do not acquire ownership or other rights to the user's uploaded content as a result of the conversion process.

The legal basis is Art. 6(1)(b) GDPR because this processing is necessary to perform the conversion explicitly requested by the user.

Conversion logs
For operation, troubleshooting, capacity planning, enforcement of usage limits and protection against misuse, we may log information such as:
start time of a conversion;
processing duration;
time of successful retrieval;
technical error messages;
number of images processed;
image dimensions;
pseudonymous hashed user ID;
hashed IP address.

Hashing an identifier does not necessarily make it anonymous. We therefore treat such identifiers as pseudonymous data where they can still be associated with a user.The legal basis for these logs is Art. 6(1)(f) GDPR. Our legitimate interests are secure service operation, error diagnosis, capacity planning, prevention of abuse and enforcement of technical usage limits.Identifiable or pseudonymous conversion log data is normally deleted after 90 days.Genuinely aggregated or anonymized statistical information that no longer permits identification of an individual user may be retained for longer periods for service statistics and capacity planning.

18. Unity and Unity In-App Purchasing
Our apps are developed using the Unity engine.We do not use:
Unity Analytics;
Unity Ads;
Unity Diagnostics / Cloud Diagnostics;
other Unity Gaming Services for analytics or advertising.

For the Google Play version of our app, we use Unity In-App Purchasing (Unity IAP) as the technical interface to Google Play Billing.Google Play remains responsible for the Google Play account and payment process. We do not receive your complete credit-card, debit-card or bank-account information.Depending on the Unity IAP version used in a particular app build, Unity IAP may process technical and purchase-related information necessary to provide its purchasing functionality. This can include categories such as:
installation or player identifiers;
device information;
session identifiers;
country information;
purchase-history information;
technical information necessary to process or validate in-app purchases.
We use Unity IAP solely to provide the platform purchase functionality and do not use it for advertising.The legal basis for our processing in connection with an in-app purchase is Art. 6(1)(b) GDPR.The specific processing independently performed by Google and Unity is additionally governed by their respective privacy information.

C. immergallery WEB

19. immerGallery Web

immerGallery Web provides browser-based viewing of stereoscopic side-by-side images.
The actual image display and rendering are performed locally in the user's browser/device.

CORS proxy for ZIP downloads
When a ZIP file is loaded from a source that does not permit the browser to retrieve it directly because of Cross-Origin Resource Sharing (CORS) restrictions, immerGallery Web may use a proxy server operated by us.
The proxy is hosted on a Hetzner server in Germany.

The proxy:
receives the requested data;
forwards the bytes between the source and the user's browser;
does not save the complete ZIP file;
does not intentionally inspect the contents of the transferred ZIP file;
does not log the requested URL.

For technical and security logging, the proxy may store a truncated IP address.
For IPv4 addresses, the last octet is removed before the address is retained in the log.These proxy logs are used only for security, technical troubleshooting and reliable operation of the service.The legal basis is Art. 6(1)(b) GDPR for providing the requested proxy functionality and Art. 6(1)(f) GDPR for technical security and troubleshooting.Proxy logs are deleted after 30 days.Genuinely aggregated or anonymized statistics may be retained for longer periods where they can no longer be associated with an identifiable individual.

D. PURCHASES AND LICENSING

20. App-Store PurchasesPurchases made through Meta Horizon Store, Steam, PICO Store or Google Play are processed through the respective platform's purchasing system.We may receive limited information required to provide the purchased product or feature, such as:
confirmation of purchase or entitlement;
product or app identifier;
transaction or purchase identifier;
refund or cancellation status;
information required to restore an entitlement.

We do not receive complete payment-card details from these store operators.The legal basis for the processing performed by us is Art. 6(1)(b) GDPR.The respective store operator independently determines its processing of payment, account and store data.

21. Direct Licensing of immerGallery Business – Lemon Squeezy

For licenses of immerGallery Business sold outside an app store, we use Lemon Squeezy, operated by Sold through Link, LLC (formerly Lemon Squeezy LLC).Lemon Squeezy acts as merchant of record for purchases made through its checkout and handles functions including payment processing, invoicing, applicable tax handling, refunds and related transaction administration.We do not receive complete credit-card or bank-account details.We may receive information necessary to fulfil the purchase, manage the license and provide support, such as:
name;
email address;
company information where provided;
invoice information where relevant;
purchased product/license;
transaction identifier;
purchase or refund status.
Our legal bases are:Art. 6(1)(b) GDPR for fulfilment of the purchase and provision of the license;
Art. 6(1)(c) GDPR for applicable accounting and tax obligations;
Art. 6(1)(f) GDPR for legitimate interests such as fraud prevention and customer support where applicable.
Privacy information:https://www.lemonsqueezy.com/privacy

E. MERCHANDISE SHOP

22. Merchandise Shop – Fourthwall

We use Fourthwall to provide a separate online merchandise shop for physical merchandise.The shop is hosted on Fourthwall infrastructure. It may be reached through a Fourthwall address or through a shop.immervr.com address that directs users to the Fourthwall-hosted shop.Visiting the merchandise shop therefore establishes a connection to Fourthwall rather than to the normal immerVR website infrastructure described above.Fourthwall provides the shop infrastructure and handles functions required for orders, including checkout, production and/or fulfilment and shipping.In connection with an order, Fourthwall may process customer information such as:
name;
email address;
billing or shipping address;
products ordered;
order and transaction information;
payment-related information;
technical device and connection information.

Fourthwall states that it processes end-customer personal information on behalf of creators using its shop services, while also carrying out certain processing for its own service purposes.At present, we do not independently collect customer payment information through immervr.com, and we do not use Fourthwall customer data for our newsletter or advertising.We do not add our own advertising or conversion tracking pixels to the Fourthwall shop.Fourthwall itself may use cookies and other technical tools on the Fourthwall-hosted shop according to its own privacy and cookie policies.The legal basis for processing necessary to process and fulfil merchandise orders is Art. 6(1)(b) GDPR. Processing required by applicable accounting or tax law is based on Art. 6(1)(c) GDPR. Where necessary for fraud prevention, security or support, Art. 6(1)(f) GDPR may apply.Please refer to Fourthwall's current Privacy Policy for additional information regarding processing carried out through the Fourthwall platform.

F. SOCIAL MEDIA AND COMMUNITY SERVICES

23. Social Media PresencesWe maintain presences on services including:
LinkedIn;
X;
YouTube;
Facebook;
Instagram;
TikTok;
Reddit.

We use these services to communicate with users, provide information about our products, receive feedback and engage with our community.When you visit one of our pages on these platforms, the respective provider processes personal data according to its own privacy policy. This may include account information, IP addresses, device information, usage information, interactions and other information associated with the relevant platform account.We do not control the general processing performed by these platform providers.If you communicate directly with us through a social-media platform, we may process information made available to us, such as:
username/profile name;
public profile information;
the content of messages or comments;
uploaded content;
information necessary to respond to your enquiry.

Our legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in communication, community engagement and customer support, or Art. 6(1)(b) GDPR where the communication relates to a contract or purchase.For certain platform statistics, such as Meta Page Insights, the platform provider and page operator may have responsibilities under the applicable joint-controller arrangements.

24. Discord Community Server

We operate a Discord server for community exchange and support.Our normal website does not embed Discord or establish a connection to Discord merely because you visit immervr.com.If you choose to join or use our Discord server, Discord processes personal data under its own responsibility.We may receive and process information you voluntarily make available through the server, such as:
Discord username;
profile information;
messages;
uploaded content;
support enquiries;
moderation-related information.

We process this information to operate and moderate the community, respond to support requests and maintain a safe community environment.The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests include community communication, support, moderation, prevention of abuse and maintaining a safe community.Where Discord provides aggregated Community Server or Server Insights statistics, we may use such statistics to understand and improve the community. We do not use these statistics for individualized advertising.Provider privacy information:
https://discord.com/privacy

G. SERVICE PROVIDERS AND INTERNATIONAL DATA TRANSFERS

25. Hosting and Processors
We use service providers where necessary to operate our services.The most important infrastructure providers include:

STRATO
STRATO hosts our main website and our email service.

Hetzner
Hetzner hosts our APIs, databases, app backend, CORS proxy, spatial conversion infrastructure and developer-log infrastructure.The Hetzner servers used by us for these services are located in Germany.
Where these providers process personal data on our behalf, they act as processors in accordance with Art. 28 GDPR.

26. Other Recipients

Depending on the particular feature you use, personal data may also be processed by or transmitted to providers described in this Privacy Policy, including:
Brevo for newsletter delivery;
Exit Games / Photon for multiplayer and voice communication;
Meta for Meta platform functions and Meta Horizon Store services;
Valve for Steam;
PICO for PICO platform/store services;
Google for Google Play services;
Unity in connection with Unity IAP;
Lemon Squeezy for direct Business licensing;
Fourthwall for the merchandise shop;
OpenStreetMap for requested map functionality;
Pastebin where you explicitly use the Pastebin retrieval feature;
social-media and community providers when you use the corresponding services.
Some of these providers act as processors on our behalf, while others independently determine some or all of their processing as separate controllers.

27. Transfers Outside the European Economic Area

Some external providers operate globally or are established outside the European Economic Area.As a result, personal data may in some circumstances be processed outside the EEA.Where we are responsible for such a transfer, we use a legally recognized transfer mechanism where required, such as:
an adequacy decision pursuant to Art. 45 GDPR;
the EU-U.S. Data Privacy Framework where applicable to a participating recipient;
Standard Contractual Clauses pursuant to Art. 46 GDPR;
another applicable mechanism permitted by Chapter V GDPR.

Where an external platform or provider processes personal data independently, further information about its international data transfers is available in that provider's privacy policy.

H. RETENTION, SECURITY AND YOUR RIGHTS

28. Storage Periods

We retain personal data only for as long as required for the purpose for which it was collected.Important retention periods described in this Privacy Policy include:CORS proxy logs: 30 days;
spatial-conversion source/result files: maximum 24 hours;
spatial-conversion technical logs: normally 90 days;
voluntarily submitted developer logs: normally maximum 12 months, unless required for an ongoing investigation;
newsletter subscriber information: until consent is withdrawn, subject to limited retention where necessary for proof of consent or suppression of further mailings;
hashed user IDs, StereoGold balances and reward/entitlement information: for as long as necessary to provide and restore the corresponding app functionality, subject to valid deletion requests.
Genuinely aggregated or anonymized statistical information that can no longer be associated with an identifiable individual may be retained for longer periods.Other personal data is deleted when it is no longer required for the relevant purpose unless statutory requirements require continued retention.In particular, commercial and tax laws may require certain contractual, transaction, invoice or accounting records to be retained for statutory periods.Data may also be retained where necessary for the establishment, exercise or defense of legal claims.

29. Data Security

We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, loss, disclosure or destruction.These measures are reviewed and adapted where appropriate in view of the nature of the processing, the available technology and the relevant risks.No electronic transmission or storage system can provide an absolute guarantee of security.

30. Provision of Personal Data

You are generally not required to provide personal data to us merely to visit our website.Certain information may, however, be required in order to provide a service or feature that you explicitly request.For example:an email address is required to receive our newsletter;
contact information may be required if you ask us to respond to an enquiry;
a platform identifier may be required for entitlement and account-related app features;
technical network information is required to establish online connections;
purchase information is required to provide purchased licenses or content;
uploaded content is required if you request a server-based spatial conversion.

If information necessary for a requested service is not provided, we may be unable to provide that particular service or functionality.

31. Your GDPR Rights

Subject to the respective legal requirements, you have the following rights concerning personal data relating to you:

Right of access – Art. 15 GDPR
You may request information about whether we process personal data concerning you and, where applicable, obtain access to that data.

Right to rectification – Art. 16 GDPR
You may request correction of inaccurate personal data and completion of incomplete data.

Right to erasure – Art. 17 GDPR
You may request deletion of your personal data where the legal requirements for deletion are met.

Right to restriction of processing – Art. 18 GDPR
You may request restriction of processing in the circumstances provided by law.

Right to data portability – Art. 20 GDPR
Where the statutory requirements apply, you may receive personal data you have provided to us in a structured, commonly used and machine-readable format and may have the right to transmit that data to another controller.

Right to object – Art. 21 GDPR
Where we process personal data on the basis of Art. 6(1)(e) or Art. 6(1)(f) GDPR, you have the right to object to such processing for reasons arising from your particular situation.

Where a valid objection is made, we will cease the processing unless there are compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defense of legal claims.

Withdrawal of consent – Art. 7(3) GDPR

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

32. Exercising Your RightsTo exercise your rights concerning personal data processed by immerVR GmbH, contact us at:
support@immervr.com
or by post:
immerVR GmbH
Im Zollstock 12
91093 Heßdorf
Germany

We may need to request appropriate information to verify your identity or to identify the relevant data.This can be particularly important for our app backend because we do not store original platform User IDs and instead use one-way hashed identifiers.Where personal data is processed independently by an external platform such as Meta, Steam, PICO, Google, Discord or another social-media provider, requests concerning that provider's independent processing should generally be directed to the respective provider.

33. Right to Lodge a Complaint
You have the right under Art. 77 GDPR to lodge a complaint with a competent data protection supervisory authority.The supervisory authority responsible for private-sector companies at our place of establishment is:Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany

You may also contact another competent supervisory authority where permitted by the GDPR.

34. Changes to this Privacy Policy
We may update this Privacy Policy where our services, technical infrastructure, third-party providers or applicable legal requirements change.The version published on our website at the relevant time applies.