Immersed.Design
Features Highlights Contact Launch App
🔒 GDPR & CCPA Compliant

Privacy Policy

Your privacy is fundamental to our mission

Effective Date: January 1, 2025 | Last Updated: January 1, 2025

🛡️ Our Privacy Commitment

We will NEVER sell or share your personal information with third parties for their marketing purposes without your explicit consent. Your data is yours, and we're committed to protecting it with industry-leading security measures.

Table of Contents

  • 1. Introduction
  • 2. Information We Collect
  • 3. How We Use Your Information
  • 4. How We Share Your Information
  • 5. Data Security
  • 6. Data Retention
  • 7. Your Rights and Choices
  • 8. Cookies and Tracking
  • 9. International Data Transfers
  • 10. Children's Privacy
  • 11. California Privacy Rights
  • 12. European Privacy Rights
  • 13. Changes to This Policy
  • 14. Contact Information

1. Introduction

Welcome to Immersed.Design ("we," "our," or "us"), operated by The Astra Group. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service").

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

By using our Service, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Name, email address, password, company name, phone number
  • Profile Information: Avatar, bio, professional title, location
  • Payment Information: Credit card details (processed securely through third-party payment processors)
  • Content: 3D models, files, annotations, comments, and other content you upload
  • Communications: Messages, feedback, support requests

2.2 Information Collected Automatically

  • Usage Data: Features used, actions taken, time spent, frequency of use
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Access times, pages viewed, errors encountered
  • Location Data: Approximate location based on IP address (if permitted)
  • Cookie Data: Preferences, session information, analytics data

2.3 Information from Third Parties

  • OAuth Providers: Basic profile information when you sign in with Google, Microsoft, etc.
  • Integration Partners: Data from connected tools and services you authorize
  • Analytics Providers: Aggregated usage and demographic data

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Provision

  • Create and manage your account
  • Provide access to our 3D visualization and collaboration features
  • Process transactions and send related information
  • Respond to your requests and support needs

3.2 Service Improvement

  • Analyze usage patterns to improve features and user experience
  • Develop new features and services
  • Conduct research and analysis
  • Test and troubleshoot functionality

3.3 Communication

  • Send service-related announcements and updates
  • Provide customer support
  • Send marketing communications (with your consent)
  • Notify you about changes to our terms or policies

3.4 Legal and Security

  • Comply with legal obligations
  • Protect against fraudulent or illegal activity
  • Enforce our terms and policies
  • Protect the rights, property, and safety of our users

4. How We Share Your Information

⚠️ Important: We do NOT sell, rent, or trade your personal information to third parties for their marketing purposes.

We may share your information in the following circumstances:

4.1 With Your Consent

We share information when you explicitly authorize us to do so, such as when you connect third-party services.

4.2 Service Providers

We work with trusted third-party service providers who assist us in operating our Service:

  • Cloud hosting providers (AWS, Google Cloud)
  • Payment processors (Stripe, PayPal)
  • Analytics services (with anonymized data)
  • Customer support tools
  • Email service providers

These providers are contractually bound to protect your information and use it only for the purposes we specify.

4.3 Team Collaboration

When you use collaborative features, your information may be visible to other team members as part of the intended functionality.

4.4 Legal Requirements

We may disclose information if required by law, court order, or governmental request, or when we believe disclosure is necessary to protect our rights or prevent harm.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.

5. Data Security

We implement comprehensive security measures to protect your information:

5.1 Technical Safeguards

  • Encryption: SSL/TLS encryption for data in transit, AES-256 encryption for data at rest
  • Access Controls: Role-based access controls and multi-factor authentication
  • Infrastructure: Secure data centers with 24/7 monitoring
  • Regular Audits: Security assessments and penetration testing
  • Incident Response: Dedicated security team and incident response procedures

5.2 Organizational Measures

  • Employee training on data protection and security
  • Limited access to personal information on a need-to-know basis
  • Confidentiality agreements with employees and contractors
  • Regular security reviews and updates

5.3 Compliance Certifications

  • SOC 2 Type II compliance
  • ISO 27001 certification (in progress)
  • GDPR compliance framework
  • CCPA compliance framework

🔐 Security Incident Notification: In the unlikely event of a data breach that affects your personal information, we will notify you within 72 hours in accordance with applicable laws.

6. Data Retention

We retain your information only for as long as necessary to fulfill the purposes outlined in this policy:

6.1 Active Accounts

We retain your account information and content for as long as your account is active or as needed to provide services.

6.2 After Account Deletion

  • Personal Data: Deleted within 30 days of account closure
  • Backup Data: Removed from backups within 90 days
  • Legal Obligations: Some data may be retained longer if required by law
  • Anonymized Data: May be retained indefinitely for analytics

6.3 Content Deletion

When you delete content from your account, it is immediately removed from active systems and from backups within 90 days.

7. Your Rights and Choices

You have important rights regarding your personal information:

Right Description How to Exercise
Access Request a copy of your personal data Account settings or email privacy@theastralabs.com
Rectification Correct inaccurate or incomplete data Update in account settings
Erasure Request deletion of your data Account settings or contact support
Portability Receive your data in a portable format Export feature in account settings
Restriction Limit processing of your data Contact privacy@theastralabs.com
Objection Object to certain data processing Manage preferences or contact us
Withdraw Consent Withdraw previously given consent Update preferences in account settings

7.1 Communication Preferences

You can manage your communication preferences:

  • Marketing Emails: Unsubscribe link in every email or account settings
  • Service Notifications: Manage in account notification settings
  • Browser Notifications: Control through browser settings

8. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience:

8.1 Types of Cookies We Use

  • Essential Cookies: Required for basic site functionality and security
  • Performance Cookies: Help us understand how you use our Service
  • Functionality Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver relevant advertisements (with consent)

8.2 Cookie Management

You can control cookies through:

  • Our cookie consent banner when you first visit
  • Cookie preferences in your account settings
  • Your browser settings to block or delete cookies

8.3 Do Not Track

We respect Do Not Track signals and do not track users who have enabled this browser setting.

8.4 Third-Party Analytics

We use privacy-focused analytics that respect user privacy:

  • Data is anonymized and aggregated
  • No personal information is shared with analytics providers
  • You can opt-out through cookie preferences

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own:

9.1 Transfer Safeguards

  • Standard Contractual Clauses: EU-approved contracts for data transfers
  • Adequacy Decisions: Transfers to countries with adequate data protection
  • Privacy Shield: Certified frameworks where applicable

9.2 Data Localization

Where required by law, we store data within specific geographic regions. EU user data is primarily stored in EU data centers.

10. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@theastralabs.com.

If we discover we have collected personal information from a child under 16 without parental consent, we will delete that information promptly.

11. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

11.1 Your CCPA Rights

  • Right to Know: Request disclosure of personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (Note: We do not sell personal information)
  • Right to Non-Discrimination: Equal service regardless of exercising privacy rights

11.2 Categories of Information Collected

  • Identifiers (name, email, IP address)
  • Commercial information (transaction history)
  • Internet activity (usage data)
  • Professional information (job title, company)

11.3 Shine the Light

California Civil Code Section 1798.83 permits users to request information about disclosure of personal information to third parties for direct marketing. We do not share personal information with third parties for their direct marketing purposes.

To Exercise Your CCPA Rights: Call 1-800-XXX-XXXX or email ccpa@theastralabs.com with "CCPA Request" in the subject line.

12. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under GDPR:

12.1 Legal Basis for Processing

We process your personal data based on:

  • Consent: When you've given clear consent
  • Contract: To fulfill our contract with you
  • Legitimate Interests: For business purposes that don't override your rights
  • Legal Obligations: To comply with laws

12.2 Your GDPR Rights

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time
  • Lodge a complaint with supervisory authorities

12.3 Data Protection Officer

You can contact our Data Protection Officer at: dpo@theastralabs.com

12.4 EU Representative

Our EU representative for GDPR matters:
[EU Representative Name]
[EU Address]
eu-privacy@theastralabs.com

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

When we make material changes:

  • We will update the "Last Updated" date at the top
  • We will notify you via email or prominent notice on our Service
  • We will provide at least 30 days' notice before significant changes take effect
  • Your continued use after changes constitutes acceptance

We encourage you to review this policy periodically to stay informed about how we protect your information.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

The Astra Group - Privacy Team

Email: privacy@theastralabs.com

Data Protection Officer: dpo@theastralabs.com

CCPA Requests: ccpa@theastralabs.com

Phone: 1-800-XXX-XXXX

Address:
[Your Business Address]
[City, State ZIP]
United States

For EU/EEA residents, you also have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.

Immersed.Design

Advanced visualization and collaboration platform for 3D content. Create, share, and experience together.

Product

  • Features
  • Pricing
  • Documentation
  • API

Legal

  • Privacy Policy
  • Terms of Service
Astra Group

Part of the Astra Group

© 2025 Immersed.Design. All rights reserved.