Skip to content

Last updated 4 September 2026

Privacy

This policy covers two very different groups of people: the customers who author training in GVR, and the trainees whose behaviour a headset records. The second group has the stronger claim on our care, so they get their own section.

Who we are

GVR provides a VR authoring tool: a web application for building training scenarios, a runtime that plays them on a headset, and the analytics that come back. Where you are a customer, we are the data controller for your account. Where your trainees use a scenario you published, you are the controller and we are your processor, acting on your instructions.

What we collect

Account data

  • Your name, email address and a bcrypt hash of your password. We use email and password only — there is no social sign-in, so we never receive a profile from a third-party identity provider.
  • Your organization, your role within it, and the organizations you have been invited to.
  • Verification and password-reset tokens, which expire and are then deleted.

Content you upload

  • Prefabs, 360° environments, images, video, audio and the presentations you assemble from them, along with their file metadata and checksums.
  • Published builds, which are immutable snapshots of a scenario, and the access codes that point at them.

Training analytics

  • Session and scene entry and exit times, gaze and grab events on objects, prefab events, actions fired, answers given, hints used, score changes, and head pose at the moment of an event.
  • The participant record a facilitator created — typically a name and an email address — and the device session created when a code is redeemed.

Technical data

  • Server logs containing IP address, user agent and request path, retained for 30 days for security and debugging.
  • A session cookie, set when you sign in. It is strictly necessary, it is the only cookie we set, and we run no advertising or third-party analytics scripts on this site.

Trainee data, specifically

A VR training session produces an unusually intimate record: where somebody looked, what they reached for, how long they hesitated. We treat it accordingly.

  • Head pose is stored as coordinates attached to discrete events. We do not record continuous video, audio, room scans or hand imagery.
  • A trainee can be enrolled without an account. Where a participant has no user record, the only identifier is the one the facilitator entered.
  • Analytics are scoped to the organization that published the scenario. Nobody outside it, including other GVR customers, can query them.
  • We do not use trainee data to train models, and we do not sell or share it with anyone for their own purposes.

How we use data

  • To run the service: authenticate you, store your content, deliver builds to headsets and return analytics.
  • To keep it secure: rate limiting, abuse detection, audit trails.
  • To bill you, where you are on a paid plan.
  • To email you about your account — verification, password resets, invitations, and material changes to the service. Marketing email is opt-in and separately unsubscribable.

Legal bases

We rely on contract for everything necessary to provide the service you signed up for, legitimate interests for security, abuse prevention and service email, legal obligation for tax and accounting records, and consent for optional marketing email, which you can withdraw at any time.

Where data lives

Application data is held in Postgres and assets in object storage, both in the EU by default. Enterprise agreements may specify a different region for asset storage. Transactional email is sent through Amazon SES.

Who we share it with

Only the subprocessors we need to run the service: our cloud provider (compute, object storage and email), our managed Postgres provider, and our payment processor for paid plans. Each is bound by a data processing agreement. We will publish an updated subprocessor list before adding a new one.

How long we keep it

  • Account data: for as long as your account exists, then 30 days.
  • Content and builds: until you delete them, or 90 days after an organization is closed.
  • Training analytics: according to your plan — 30 days on Studio, 12 months on Team, and whatever your Enterprise agreement specifies. Raw event rows are deleted at the end of the window; anonymous aggregates may be kept.
  • Server logs: 30 days.

Your rights

You can access, correct, export or delete your personal data, object to or restrict processing, and complain to your supervisory authority. Account settings cover most of this directly; anything else, email us and we will respond within 30 days. If you are a trainee, contact the organization that ran your session first — they control the record — and we will help them action your request.

Children

GVR is a workplace tool and is not directed at anyone under 16. We do not knowingly collect their data, and will delete it if we learn we have.

Changes

We will post any change here and update the date at the top. If a change materially affects how we handle personal data, we will email account owners before it takes effect.

Contact

Data protection enquiries: privacy@leprechaunvsogre.com.