Privacy Policy

RELIC — Privacy Policy and Privacy Notice

We explain what data we process, why, and what rights you have.

Platform: RELIC

Controller of your data: Camilo Solares Valle, an individual engaged in business activity, operating under the “RELIC” brand

Address: Avenida Enrique Díaz de León 2277, interior 103, C.P. 44210, Guadalajara, Jalisco, Mexico

Privacy contact: support@relic-vr.com

Effective date: June 24, 2026

1. Who we are (Controller)

1.1. Platform: RELIC.

1.2. The controller of your personal data is Camilo Solares Valle, an individual engaged in business activity, operating under the “RELIC” brand. Until the company that will operate RELIC is incorporated, that company will assume the role of controller.

1.3. Address: Avenida Enrique Díaz de León 2277, interior 103, C.P. 44210, Guadalajara, Jalisco, Mexico.

1.4. Privacy contact: support@relic-vr.com.

1.5. Territorial scope and representative. For now, RELIC directs the Service to users in Mexico and in other countries outside the European Union and the United Kingdom, and does not admit users from the European Union or the United Kingdom. Before offering the Service in those territories, we will designate a representative in accordance with Article 27 of the GDPR and of the UK GDPR and will identify them in this Notice.

1.6. Effective date: June 24, 2026.

1.7. Data Protection Officer. Where applicable law requires it due to large-scale processing of biometric or special-category data, we will designate a Data Protection Officer (DPO) and publish their contact details. Until that designation is made, you may direct any data protection matter to support@relic-vr.com.

2. Scope

This notice applies to all users of the Service and is supplemented by additional rights according to your place of residence (see section 11).

3. Personal data we process

Category

Examples

Sensitive?

Account and registration

Name or pseudonym, email, password (encrypted), country, language, profile photo

No

Content

User Content (volumetric captures, Gaussian Splatting files, video, audio, 3D), metadata (date, format, device), descriptions, comments

Depends on the content

Biometric / image data

Reconstruction of the physical appearance of individuals captured in volumetric scenes

Yes (see section 4)

Usage and device

IP address, device identifiers, browser, operating system, playback history, interactions, logs

No

Communications

Support messages, surveys, reports

No

Cookies and similar

See section 12

No

Transactions and payments

Plan, purchase history; for creators who receive payment: billing, tax, and identity (KYC) data

No (except as applicable)

We do not request special categories of data except as described. If your content reveals additional sensitive data, you do so under your responsibility and with the consent of the affected individuals.

4. Biometric data and volumetric captures

4.1. Volumetric capture and Gaussian Splatting technology can reconstruct the physical appearance of individuals in detail. Depending on the jurisdiction (for example, the GDPR, the Illinois BIPA, the Texas CUBI, or the Washington statute), these reconstructions may constitute biometric or sensitive data subject to heightened protection.

4.2. Consent. Where the processing of biometric data requires it, the express consent of the affected individual will be obtained before capturing or storing it. Creators who upload content with identifiable individuals are responsible for obtaining that consent (see Terms, clause 8) and confirm it upon uploading.

4.3. Purpose and minimization. We process this data only to host, process, and transmit the content within the Service. We do not use it to identify individuals, we do not apply facial recognition, and we do not sell it.

4.4. Retention and destruction. We retain biometric data only while the related content is hosted. We delete or anonymize it no later than 90 days after the content is deleted or the account is closed, or earlier if the individual exercises their rights or the law requires it. This retention and destruction schedule meets the BIPA requirement to maintain a written policy.

4.5. Impact assessment. Before initiating processing that may involve a high risk to individuals’ rights (for example, the large-scale processing of biometric data), we will carry out a data protection impact assessment (DPIA) in accordance with Article 35 of the GDPR and applicable regulations, and will adopt the measures resulting from it.

5. What we use your data for (purposes)

We process your data to: create and manage your account and authenticate you; host, process, transcode/convert to volumetric format, transmit, and display content; distribute your content within the Platform; operate, maintain, personalize, and improve the Service; process payments and, where applicable, payments to Creators; ensure security and prevent fraud, abuse, and unlawful activity; moderate content and address legal notices; communicate with you; and comply with legal obligations and requirements of authorities.

5.1. Secondary purposes. We may use your data for promotional communications or surveys. If you do not wish this, say so at support@relic-vr.com; your refusal will not be a condition for providing the Service to you.

6. Legal bases for processing (GDPR / UK GDPR)

Legal basis (GDPR art. 6/9)

When we use it

Performance of the contract

To provide the Service you request

Consent

Non-essential cookies, marketing communications, and biometric data; revocable

Legitimate interest

Security, fraud prevention, and Service improvement, balanced against your rights

Legal obligation

Record retention and the handling of legal requirements

7. With whom we share your data

We do not sell your personal data. We only share it with:

7.1. Providers and processors: cloud infrastructure, hosting and streaming, technology provider (Solares Films, which processes content in accordance with our instructions), transcoding, analytics, support, and communications, under agreements (including those of Article 28 of the GDPR) that require them to protect your data and process it only following our instructions.

7.2. Payment processors: under their own policies and the PCI-DSS standard. We do not store the full details of your payment method.

7.3. Rights Holders / collaborators: only the data strictly necessary to enable features (for example, aggregate metrics), without exposing identifiable data except as necessary and permitted.

7.4. Authorities and legal third parties: when required by law, by a valid order, or to protect rights, security, or prevent fraud.

7.5. Corporate operations: in a merger, acquisition, or reorganization, informing you of the change of controller.

8. International transfers

The Service operates internationally, so your data may be transferred to and stored in countries other than yours. When we transfer data from the EU/EEA, the United Kingdom, or other jurisdictions, we apply appropriate safeguards: adequacy decisions, Standard Contractual Clauses (SCC, 2021 version) with the corresponding module, and the United Kingdom International Data Transfer Addendum (IDTA), with supplementary measures and a transfer impact assessment where appropriate.

9. Data retention

Category

Indicative period

Account data

While the account is active + 90 days after closure

User Content

Until its deletion or the closure of the account (except legal or backup copies)

Biometric data

Only as necessary; deletion/anonymization no later than 90 days after deleting the content or closing the account (see section 4.4)

Transaction data

The applicable tax and accounting retention period

Security logs

12 months

After your account is closed, we will delete or anonymize your data within a reasonable period, except for what we must retain by law or to resolve disputes.

10. Security

We apply reasonable technical and organizational measures (encryption in transit and, where applicable, at rest; access controls; activity logging; minimization; confidentiality controls for all persons involved in the processing; and staff training). No system is completely secure; in the event of a security breach that affects you, we will notify you and the competent authority in accordance with Applicable law (including the GDPR’s 72-hour deadline).

11. Your rights

To exercise them, write to us at support@relic-vr.com; we may verify your identity in a proportionate manner. We will not discriminate against you for exercising your rights.

Region

Rights

Authority / deadline

EU / EEA (GDPR)

Access, rectification, erasure, restriction, portability, objection, not to be subject to automated decisions with significant effects, withdrawal of consent

Your supervisory authority (e.g., AEPD, CNIL); 30 days (+60)

United Kingdom (UK GDPR)

Equivalent to the GDPR

ICO; 30 days (+60)

Mexico (LFPDPPP 2025)

ARCO rights, withdrawal of consent, limitation of use or disclosure

Secretariat for Anti-Corruption and Good Governance (replaced INAI); remedy: amparo

California (CCPA/CPRA)

Know, access, correct, delete; opt out of the sale or “sharing” (we do not sell); limit the use of sensitive data; non-discrimination

California AG / CPPA; acknowledgment 10 business days, response 45 (+45)

Brazil (LGPD)

Access, correction, deletion, portability, information, objection

ANPD; 15 days

Mexico — ARCO rights: your request must contain your name and contact details, the documents that prove your identity, and a clear description of the data and of the right you are exercising. Send it to support@relic-vr.com.

12. Cookies and tracking technologies

Type

Purpose

Consent

Essential

Operation, security, and session

Not required

Functional

Preferences and language

As required by law

Analytics

Usage and performance measurement

Required where the law requires it

Personalization

Recommendations

Required where the law requires it

You can manage non-essential cookies from our panel or your browser. We respect Global Privacy Control (GPC) signals where the law requires it.

13. Children’s privacy

The Service is general-audience (family-friendly), is not directed to children under 13, and we do not knowingly collect their data. Where the law requires a higher minimum age, we will apply that threshold. For those below the age of majority, we may require the consent of the person who exercises guardianship. We comply, as applicable, with COPPA (United States) and the GDPR provisions on minors. If a minor appears captured in a volumetric scene without their guardian’s consent, we will remove the content through our notice and moderation mechanisms.

14. Automated decisions and AI processing

Gaussian Splatting and transcoding technology may involve automated processing for technical purposes (conversion, optimization, or assisted moderation). We do not make decisions based solely on automated processing with legal or significant effects on you without a legal basis and, where applicable, without offering you human intervention, in accordance with the GDPR and applicable AI regulation.

15. Changes to this Notice

We may update this Notice. When the changes are material, we will notify you a reasonable time in advance. The “effective date” indicates the last update.

16. How to contact us and file a complaint

Camilo Solares Valle · Address (privacy): Avenida Enrique Díaz de León 2277, interior 103, C.P. 44210, Guadalajara, Jalisco, Mexico · Email: support@relic-vr.com