1. Introduction and scope
iXRLabs ("we", "us", "our") builds virtual reality learning software for higher education. This Privacy Policy explains what personal data we collect, how and why we use it, how long we keep it, and how you can ask us to delete it.
This policy applies to:
- our website at ixrlabs.com;
- the iXRLabs learning platform, including modules delivered in WebXR on headsets and in a browser, and the 7thi AI tutor built into them;
- the standalone virtual reality applications we publish and distribute through the Meta Horizon Store for Meta Quest devices — currently iXRLabs Engineering Demo, Industrial Journey – Thermal Power Plant, and Engineering Marvels, together with any other application published under our Meta developer account.
It applies to you whether you reach us as a website visitor, as a student or member of faculty at an institution that licenses our platform, or as an individual who downloads one of our applications from the Meta Horizon Store without any institutional relationship with us.
2. Who we are
iXRLabs operates through two entities:
- IXRLABS Learning Solutions Pvt Ltd, 401–403, 4th Floor, Mall of Jaipur, Gandhi Path, Vaishali Nagar, Jaipur 302021, India.
- IXRLABS Learning Inc, 16192 Coastal Highway, Lewes, Delaware 19958, USA.
The applications we distribute through the Meta Horizon Store are published by [CONFIRM — Legal: name the entity that holds the Meta developer account. Meta requires the policy to be owned by the organisation that publishes the apps.], which is the data controller for personal data collected through those applications.
We are the data controller for personal data collected through our website and in our dealings with prospective customers. We act as a data processor for the student and faculty data that our institutional customers entrust to us through the learning platform; in that case the institution is the controller and decides what is collected and why.
For any privacy question, and to exercise any of the rights in section 12, contact privacy@ixrlabs.com.
3. Information we collect
3.1 Information you give us
- Contact details you submit through forms on our website: name, work email address, phone number, institution, and role.
- The content of demo requests, quote requests, brochure downloads, and partnership enquiries.
- Correspondence with our sales and support teams, including support tickets and any files you attach to them.
3.2 Information collected automatically on our website
- Device and connection information: IP address, browser type and version, operating system, device type, and screen size.
- Usage information: the pages you view, the links you click, the date and time of your visit, the referring page, and how long you spend on a page.
- Cookie identifiers, as described in section 13 and in our Cookie Policy.
[CONFIRM — Engineering: the site runs Google Analytics (G-KLNRH5G3W2) and the Tawk.to live-chat widget. List any other analytics or tag-management tools so this section and section 10 both match reality.]
3.3 Information collected in the learning platform
When a student or member of faculty uses the platform under an institutional licence, we process:
- Account and identity data provided by the institution or created at sign-up: name, institutional email address, student or staff identifier, cohort or class, and role.
- Learning activity data: which modules were opened, session start and end times, interactions within a module, progress, attempts, and assessment results.
- 7thi interaction data: the questions a student asks the AI tutor, the module and scene the question was asked in, and the tutor’s responses.
- Technical data: device and headset type, browser or application version, IP address, and error and diagnostic logs.
The institution configures what is collected, retained, and made visible to faculty. [CONFIRM — Engineering: whether 7thi accepts spoken input in-headset. If it does, voice recordings and/or transcripts must be listed above, along with whether audio is retained or discarded after transcription.]
4. Applications distributed through the Meta Horizon Store
Some iXRLabs modules are available as standalone virtual reality applications on the Meta Horizon Store for Meta Quest devices. This section applies to anyone who installs one of those applications, whether or not they are associated with an institution that licenses our platform.
What we collect
[CONFIRM — Engineering: verify every line below against the shipped Unity builds and delete anything we do not in fact collect. Do not leave a category in defensively — an inaccurate list is a compliance problem in its own right.]
- Meta account identifiers: your app-scoped Meta user ID, and your Meta username and profile picture where you sign in through the Meta Platform SDK.
- Device and connection information: headset model, operating system and build version, application version, language and region settings, and IP address.
- Usage information: when you open and close the application, session length, which modules and scenes you open, in-module interactions, progress, and assessment results.
- Diagnostic information: crash reports, error logs, frame-rate and performance data.
- 7thi interaction data: questions you ask the AI tutor inside a module and the responses it returns.
What we do not collect
- We do not collect payment card details through the applications. Purchases, where applicable, are handled by Meta under Meta’s own terms.
- We do not collect raw camera, passthrough, or room-scan data from your headset.
- We do not use the data collected through these applications for advertising, and we do not sell it.
[CONFIRM — Engineering: confirm each of the three statements above holds for the shipped builds, in particular whether any hand-, eye-, or body-tracking data leaves the device.]
Why we collect it
To run the application and save your progress between sessions; to provide support when you contact us; to diagnose crashes and improve stability and performance; to understand which modules are used so we can improve them; and to meet our legal obligations.
How long we keep it
See section 8. In summary: account and progress data is kept while your account is active and deleted within 30 days of a deletion request; crash and diagnostic logs are kept for [CONFIRM — proposed: 90 days].
How to request deletion
Email privacy@ixrlabs.com with the subject line "Data deletion request". Include either the email address associated with your account or your Meta account username, and tell us which application you used. We will acknowledge your request within 5 working days and complete it within 30 days. There is no charge.
You do not need to go through an institution, a school, or a university to make this request. If you would prefer a different channel, you can also write to us at either address in section 2.
5. How we use your information
| Purpose | Categories used | Legal basis (where the UK/EU GDPR applies) |
|---|---|---|
| Providing, maintaining, and improving the platform, the applications, and the modules | Account, usage, technical | Performance of a contract; legitimate interests |
| Saving and restoring your progress | Account, learning activity | Performance of a contract |
| Delivering faculty analytics to institutional customers | Learning activity | Performance of a contract with the institution (we act as processor) |
| Responding to enquiries and providing support | Contact, correspondence, technical | Performance of a contract; legitimate interests |
| Diagnosing crashes and improving stability | Diagnostic, technical | Legitimate interests |
| Sending service communications | Contact | Performance of a contract; legal obligation |
| Sending marketing about our products | Contact | Consent, or legitimate interests where permitted |
| Meeting legal, tax, and regulatory obligations | As required | Legal obligation |
We do not sell personal data. We do not use student data, or data collected through our Meta Horizon Store applications, to train external AI models.
[CONFIRM — Engineering and Legal: whether 7thi sends prompts to a third-party model provider. If it does, that provider must be named in section 10, and the sentence above must distinguish between "not used for training" and "not transmitted at all" — those are different promises.]
6. Student data and institutional customers
7thi is the AI tutor built into iXRLabs modules. It answers a student’s questions in natural language, in the context of the module and scene the student is working in, and adapts as the student progresses. To do this it processes the student’s questions, the module context, and the student’s progress within that module. It is subject-scoped and does not retain student personal data beyond what the institution configures.
Student and faculty data is processed on behalf of, and under the documented instructions of, the institution. The institution decides what is collected, how long it is retained, who at the institution can see it, and how 7thi behaves, including its retention and audit settings. Our specific commitments are set out in the data processing agreement signed with each institution.
Option A — we act as a school official. For institutions in the United States, we act as a "school official" with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA), 34 CFR § 99.31(a)(1). We are under the direct control of the institution with respect to the use and maintenance of education records, we use those records only for the purposes authorised by the institution, and we do not re-disclose them except as FERPA permits and the institution directs.
Option B — the institution retains responsibility. Education records under the Family Educational Rights and Privacy Act (FERPA) remain under the control of the institution. Our processing obligations, including the restrictions on our use and disclosure of student data, are set out in the data processing agreement signed with each institution.
If you are a student or a member of faculty and you have a question about how your institution has configured the platform, contact your institution in the first instance. You can still contact us directly at any time using section 12.
7. Children and young people
Which applications and modules are genuinely intended for users under 13? Engineering Marvels is currently self-certified in the Meta dashboard as a mixed-ages app covering 10–12 as well as 13+. If that is accurate, the section below stays. If no application is actually intended for under-13 use, correct the certification in the dashboard and replace this whole section with one sentence: "Our applications are intended for users aged 13 and over, and for supervised use in institutional settings."
Some iXRLabs modules are designed for younger learners and are used in supervised classroom settings. Where an application or module is intended for children under 13, or where we otherwise become aware that a user is a child:
- Consent. We collect personal data from a child only with the verifiable consent of a parent, guardian, or the school or institution acting under its own lawful authority. Where the child uses the application through an institution, the institution is responsible for obtaining and recording that consent, and our agreement with the institution requires it to do so.
- Minimisation. We collect only what the module needs in order to run and to record the child’s progress. We do not require a child to provide more personal data than is reasonably necessary to take part.
- What we do not do. We do not use children’s data for advertising or marketing of any kind, we do not build behavioural profiles of children, we do not track children across other services, and we do not make children’s data available to other users of the application.
- Age signals. Our Meta Horizon Store applications rely on the age category associated with the Meta account, as provided to us by Meta, to determine whether an account belongs to a child. [CONFIRM — Engineering: whether the builds call Meta’s User Age Group API, and how the returned age group changes the app’s behaviour. This is the subject of a separate live enforcement and the answer must be accurate.]
- Deletion. A parent or guardian can ask us to delete their child’s data by emailing privacy@ixrlabs.com with the subject line "Data deletion request". We will confirm the request with the parent or guardian, or with the institution where the account was created by a school, and complete it within 30 days.
[CONFIRM — Legal: which frameworks we actually operate under — COPPA (US), the DPDP Act 2023 (India, which treats anyone under 18 as a child and requires verifiable parental consent), the UK Age Appropriate Design Code, GDPR Article 8. Name the ones we can evidence and no others.]
8. How long we keep data
We keep personal data only for as long as we need it for the purposes in section 5, or for as long as the law requires. The periods below are proposals for confirmation.
| Data | Retention |
|---|---|
| Website enquiry and contact form submissions | [proposed: 24 months] from the last contact with you |
| Marketing contact records | Until you unsubscribe, then [proposed: 24 months] to honour the opt-out |
| Student and faculty data in the learning platform | As configured by the institution; deleted or returned within [proposed: 60 days] of the end of the institution’s contract |
| Meta Horizon Store account and progress data | While the account is in use; deleted within 30 days of a deletion request, and after [proposed: 24 months] of inactivity |
| 7thi interaction data | As configured by the institution; for Horizon Store applications, [proposed: 12 months] |
| Crash and diagnostic logs | [proposed: 90 days] |
| Server and access logs, including IP addresses | [proposed: 30 days] |
| Contracts, invoices, and other records we must keep by law | For the period required by applicable tax and company law |
Data in encrypted backups is removed on our standard backup rotation, within [proposed: 35 days] of deletion from live systems.
9. Where your data is stored
Institutions choose where their data is stored — currently the United States, the European Union, or India. Data for that institution remains in the chosen region. The region is selected at contract time and can be changed at renewal.
Data collected through our website and through our Meta Horizon Store applications is stored in [CONFIRM — Engineering: region(s)].
Because we operate from India and the United States, personal data may be transferred between those countries and, where relevant, from the European Economic Area or the United Kingdom. Where we transfer personal data out of the EEA or the UK, we do so under [CONFIRM — Legal: Standard Contractual Clauses, the UK International Data Transfer Addendum, or another named mechanism].
10. Sharing and disclosure
We share personal data only where it is needed to run our service, and only with recipients that are bound by contract and confidentiality obligations.
Categories of recipients:
- Cloud hosting and storage providers, who host the platform and store its data.
- Content delivery and networking providers, who serve module assets to your device.
- Crash reporting and diagnostics providers, who receive error and performance data from our applications and platform.
- Analytics providers. Our website uses Google Analytics.
- Live chat providers. Our website uses Tawk.to, which receives the messages you send through the chat widget and basic technical data about your visit.
- AI model providers, where 7thi relies on a third-party model to generate responses. [CONFIRM — Engineering: whether this applies and to whom.]
- Email, CRM, and customer support providers, who process contact details and correspondence.
- Your institution, where you are a student or member of faculty using an institutional licence.
- Meta Platforms, in respect of applications distributed through the Meta Horizon Store — Meta processes your Meta account information under Meta’s own privacy policy, which we do not control.
- Professional advisers, auditors, and authorities, where required by law or to establish, exercise, or defend legal claims, or to protect the rights and safety of any person.
Software development kits in our applications. Our Meta Quest applications include third-party software development kits that may transmit data off the device: [CONFIRM — Engineering: produce the actual list from the shipped builds — for example the Meta Platform SDK / Meta XR SDK, the Unity engine and any Unity services such as Cloud Diagnostics or Analytics, and any crash reporting SDK. Name each one and what it sends.]
A current list of our named sub-processors is available at [CREATE PAGE: ixrlabs.com/subprocessors, then link it here] and is kept up to date. Institutional customers are notified of changes as set out in their data processing agreement.
We do not sell personal data and we do not share it with third parties for their own marketing purposes.
11. Security
We protect personal data with technical and organisational measures appropriate to the risk. These include encryption of personal data in transit and at rest, access controls and role-based permissions, logging and monitoring, staff training, and regular review of our providers.
The current wording, "ISO-certified", names no standard and no certifying body, so a reviewer or a procurement team cannot verify it. If the certificate exists, cite it. If it does not, use Option B here — and take the "ISO Certified" claim off the homepage and the About page in the same release, or the policy and the marketing site will contradict each other in front of the same reviewer.
Option A — certified. We hold ISO/IEC 27001:2022 certification, issued by [certification body] under certificate number [number], valid until [date]. A copy of the certificate is available to institutional customers on request.
Option B — aligned, not certified. We maintain an information-security programme aligned to ISO/IEC 27001. A full description of our technical and organisational measures is available to institutional customers on request.
No system is perfectly secure, but we work continuously to protect the data entrusted to us. If you believe you have found a security vulnerability, please report it to [CONFIRM: security@ixrlabs.com, or an existing monitored address].
12. Your rights and how to exercise them
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where our use is based on consent. Where the Digital Personal Data Protection Act, 2023 applies, you may also nominate another person to exercise your rights on your behalf.
To exercise any of these rights, including deletion, email privacy@ixrlabs.com.
- For a deletion request, use the subject line "Data deletion request" and include the email address associated with your account or your Meta account username, and tell us which application or service you used.
- We will acknowledge your request within 5 working days and complete it within 30 days. If a request is complex and we need longer, we will tell you why and when to expect a response.
- We will not charge you, and we will not ask you for more information than we need to confirm who you are.
- You do not need to go through an institution to make a request. This route is open to everyone: website visitors, students, faculty, and anyone who has installed one of our applications from the Meta Horizon Store.
If you are a student or a member of faculty, your institution holds its own copy of your records and sets the platform’s configuration, so a request made to your institution is often the fastest route for records it controls. That is an option, not a requirement — you can always come to us directly, and where we act as a processor we will support your institution in fulfilling your request.
If you are not satisfied with how we have handled your request, you can complain to your local data protection authority — in the UK the Information Commissioner’s Office, in India the Data Protection Board, or the supervisory authority in your EU member state.
13. Cookies
Our website uses cookies and similar technologies for essential functionality, for remembering your preferences, and for analytics. You can control cookies through your browser settings, and non-essential cookies are set only where you have agreed to them. Our Cookie Policy sets out the specific cookies we use and what each one does.
Our Meta Horizon Store applications do not use cookies.
14. Changes to this policy
We may update this policy from time to time. When we do, we will post the updated version on this page and change the "last updated" date at the top in the same release. Where a change materially affects how we handle personal data, we will notify institutional customers directly and, where appropriate, give notice in the application or on the platform.
15. Contact us
For any privacy question, or to exercise any of the rights in section 12:
Email: privacy@ixrlabs.com — this is the fastest route and the one we monitor for rights and deletion requests.
By post:
- India — IXRLABS Learning Solutions Pvt Ltd, 401–403, 4th Floor, Mall of Jaipur, Gandhi Path, Vaishali Nagar, Jaipur 302021, India.
- United States — IXRLABS Learning Inc, 16192 Coastal Highway, Lewes, Delaware 19958, USA.
[CONFIRM — Legal: whether we have appointed, or are required to appoint, a Data Protection Officer or an EU/UK representative. If so, name them and their contact details here.]
Our Terms of Service, Cookie Policy, and Accessibility Statement are published separately.
