Privacy

Data Privacy and Management Policy

Seede Group Company Limited (trading as Seede XR) Registered in the United Republic of Tanzania BRELA Business Registration Licence No. 101372650

Field Detail
Document title Data Privacy and Management Policy
Version 1.0
Status Final and adopted
Effective date 7 July 2026
Owner Data Protection Officer, Seede XR
Approved by Seede XR Board
Next review date 7 July 2027

1. Purpose and commitment

Seede XR is a boutique immersive design and storytelling studio. Our work in Augmented Reality (AR), Virtual Reality (VR), Extended Reality (XR), 3D modelling and animation, projection mapping, interactive media, and Artificial Intelligence (AI) often involves capturing, generating, and analysing information about real people. This can include images, voices, faces, body movement, spatial data, and behavioural data collected inside immersive experiences.

Because our craft depends on trust, both from the clients who commission us and from the audiences and communities whose stories and likenesses we work with, we treat privacy as a core creative and commercial responsibility rather than a formality.

This policy sets out how Seede XR collects, uses, stores, shares, protects, and disposes of personal data. It is designed to:

  1. Comply with the Personal Data Protection Act, No. 11 of 2022 of the United Republic of Tanzania (the "PDPA") and its subsidiary regulations.
  2. Comply with the requirements of the Personal Data Protection Commission (the "PDPC"), including registration, reporting, and cross-border transfer obligations.
  3. Meet the standards of the European Union General Data Protection Regulation (GDPR) and equivalent frameworks where Seede XR offers services to, or monitors the behaviour of, individuals located in the European Economic Area (EEA) or the United Kingdom.
  4. Protect Seede Group Company Limited from legal, financial, and reputational harm arising from mishandling of personal data.
  5. Give customers, collaborators, participants, and communities clear rights and a clear point of contact.

2. Scope

This policy applies to:

  • All directors, employees, interns, contractors, freelance artists, technologists, and volunteers of Seede XR (together, "Personnel").
  • All personal data processed by Seede XR, whether held digitally (files, cloud storage, project archives, AI training sets, headset and sensor logs) or physically (signed release forms, printed notes, physical media).
  • All processing activities across the full project lifecycle: pitching, research, production, installation, exhibition, distribution, and archiving.

This policy covers personal data relating to:

  • Clients and prospective clients, and their staff.
  • Audience members and participants in immersive experiences, exhibitions, and installations.
  • Individuals whose likeness, voice, movement, or performance is captured or recreated (for example actors, models, cultural knowledge holders, community members, and members of the public appearing in captured footage).
  • Suppliers, partners, collaborators, and cultural or academic research contributors.
  • Personnel of Seede XR.
  • Website visitors and users of any Seede XR digital product or platform.

3. Definitions

The following terms carry the meanings given in the PDPA and are used consistently throughout this policy.

  • Personal data: any information relating to an identified or identifiable natural person, including a name, identification number, location data, an online identifier, or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural, or social identity.
  • Sensitive personal data: a special category of personal data requiring enhanced protection. Under the PDPA this includes genetic data, biometric data, data concerning health, data of children (persons under 18 years), criminal records, financial transaction data, and data revealing race, ethnicity, political opinion, religious or philosophical belief, trade union membership, gender, or sexual orientation.
  • Data subject: the natural person to whom the personal data relates.
  • Data controller: the person or body that, alone or jointly with others, determines the purposes and means of processing personal data.
  • Data processor: the person or body that processes personal data on behalf of, and under the instructions of, a data controller.
  • Processing: any operation performed on personal data, whether or not by automated means, including collecting, recording, organising, storing, adapting, altering, retrieving, using, disclosing, combining, restricting, erasing, or destroying.
  • Consent: any freely given, specific, informed, and unambiguous indication by which a data subject signifies agreement to the processing of their personal data.
  • The Commission or PDPC: the Personal Data Protection Commission established under the PDPA.
  • Data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Biometric data: personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a person, such as facial geometry, iris or eye-tracking data, voiceprints, gait, and body-motion capture.
  • Immersive data: for the purpose of this policy, data captured or generated inside AR, VR, XR, projection-mapped, or interactive experiences, including head and hand tracking, gaze and eye-tracking, movement paths, spatial mapping of a person or a room, interaction logs, and physiological responses.

4. Our role and legal position

For most of its activities, Seede Group Company Limited acts as a data controller, because it decides why and how personal data is processed.

When Seede XR produces work on behalf of a client and processes personal data strictly under that client's documented instructions (for example, building an interactive installation using data supplied and directed by the client), Seede XR may act as a data processor. In those cases, a written data processing agreement will define the roles, responsibilities, security measures, and instructions, as required by the PDPA.

Seede XR determines its status for each engagement at the outset and records it, because the two roles carry different obligations.


5. Legal and regulatory framework

Seede XR aligns this policy with the following instruments.

Primary Tanzanian law and regulations

  • The Personal Data Protection Act, No. 11 of 2022 (in force from 1 May 2023).
  • The Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023.
  • The Personal Data Protection (Complaints Settlement Procedures) Regulations, 2023, as amended.
  • The Constitution of the United Republic of Tanzania, 1977 (Article 16, right to privacy and personal security).

Related Tanzanian legislation that may apply to our work

  • The Electronic and Postal Communications Act, 2010 (EPOCA) and its online content regulations, where we distribute digital or online experiences.
  • The Cybercrimes Act, 2015, in relation to offences involving computer systems and privacy.

European and international standards we voluntarily meet where relevant

  • The EU General Data Protection Regulation (GDPR), which applies where we offer goods or services to, or monitor the behaviour of, individuals in the EEA. GDPR obligations attach regardless of where Seede XR is established.
  • We track ongoing EU reform, in particular the European Commission's Digital Omnibus Package published on 19 November 2025, which proposes amendments to the GDPR, the ePrivacy rules, and the EU AI Act. These are proposals moving through the EU legislative process and are not yet law, with adoption expected around mid to late 2026 or later. Notable proposed changes we are monitoring include recalibrated data breach notification thresholds and timelines, revised handling of data subject access requests, single-click consent and browser-level preference signals for tracking, and clarified rules on using personal data to develop and operate AI systems. Seede XR will update this policy once the final position is confirmed.

Where Tanzanian law and a foreign standard both apply to a given activity, Seede XR applies the stricter requirement.


6. Data protection principles

Seede XR processes all personal data in line with the principles set out in section 5 of the PDPA, which closely mirror the GDPR. Personal data must be:

  1. Lawful, fair, and transparent: processed on a valid legal basis and in a way people would reasonably expect.
  2. Purpose limited: collected for explicit, specified, and legitimate purposes and not used in ways incompatible with those purposes.
  3. Minimised: adequate, relevant, and limited to what is necessary for the purpose. We do not capture data simply because our tools are capable of capturing it.
  4. Accurate: kept correct and up to date, with reasonable steps taken to erase or correct inaccurate data without delay.
  5. Storage limited: kept in a form that identifies people for no longer than is necessary.
  6. Secure: protected by appropriate technical and organisational measures against unauthorised access, loss, destruction, alteration, or disclosure.
  7. Accountable: Seede XR takes responsibility for compliance and is able to demonstrate it through records, assessments, and documentation.

Accountability is the principle that binds the others. Seede XR keeps records that show not only that it complies, but how.


7. Categories of personal data we process

Because immersive production is data-intensive, Seede XR maintains awareness of the specific categories it handles.

Standard personal data

  • Client and partner contact details, job titles, and correspondence.
  • Contract, billing, and payment information.
  • Personnel records for staff, contractors, and freelancers.
  • Website and platform analytics, cookies, device identifiers, and online identifiers.
  • Names and contact details of research contributors and community collaborators.

Content-based personal data

  • Photographs, film, and audio recordings of identifiable people captured during production or at exhibitions.
  • 3D scans and photogrammetry of individuals used for modelling, animation, or digital recreation.
  • Performances, voices, and likenesses used to build characters or avatars.

Sensitive and immersive data (enhanced protection)

  • Biometric data such as facial geometry, voiceprints, and eye-tracking or gaze data collected by AR and VR hardware.
  • Body and motion-capture data and spatial mapping of people or their environments.
  • Interaction and behavioural logs generated inside immersive experiences.
  • Data of children (persons under 18) who participate in or appear in our experiences.
  • Any data revealing race, ethnicity, religious or cultural belief, or other special categories, which can arise naturally in Afro-centred cultural and heritage projects.
  • Data used to train, fine-tune, or prompt AI systems, where that data contains or can be linked to real people.

Seede XR recognises that much of the data generated by immersive and AI tools is sensitive by default. This category is treated with the highest level of care described in Section 10.


8. Lawful basis for processing

Seede XR processes personal data only where at least one lawful basis under the PDPA applies. Before any new processing activity begins, the responsible producer or lead records which basis applies. The bases we rely on are:

  • Consent: the data subject has given specific, informed, freely given, and unambiguous consent (see Section 9). This is our default basis for capturing likeness, biometric, and immersive data from participants and members of the public.
  • Performance of a contract: processing is necessary to deliver a commissioned project or to take steps at a person's request before entering a contract.
  • Legal obligation: processing is required to comply with Tanzanian law, for example tax and employment record-keeping.
  • Legitimate interests: processing is necessary for a legitimate interest of Seede XR or a third party, provided this does not override the rights and freedoms of the data subject. Where we rely on this basis, we carry out and record a balancing assessment.
  • Public interest or the exercise of official authority, and protection of the vital interests of a person, in the limited situations recognised by the PDPA.

The burden of demonstrating a lawful basis rests with Seede XR as controller. We do not proceed on assumption.


9. Consent

Where consent is our lawful basis, Seede XR ensures it is:

  • Specific: tied to a clearly described purpose. Consent to appear in a live exhibition is not consent to be used in AI training or in future unrelated projects.
  • Informed: the person is told who is collecting the data, what is being collected, why, how long it is kept, who it may be shared with, and how to withdraw.
  • Freely given: not bundled into unrelated terms and not a condition of a service where the data is not needed for that service.
  • Documented: recorded and retrievable, so we can show when and how consent was obtained.
  • Withdrawable: as easy to withdraw as it was to give. Withdrawal stops future processing but does not affect processing already carried out lawfully.

Release forms and immersive capture. For any project that films, records, scans, motion-captures, or otherwise captures identifiable people, Seede XR uses a written consent and release form that separately addresses:

  1. Capture and use of likeness, voice, and performance.
  2. Capture of biometric and immersive data (for example face scans, eye-tracking, motion capture).
  3. Any use of the captured material to train or generate outputs from AI systems.
  4. Any intended public exhibition, distribution, or archiving, including duration.

Each use is presented as a separate, optional choice so that a person can agree to some uses and decline others.

Children. Where a participant is under 18, consent is obtained from a parent or legal guardian, and, where appropriate to the child's age and understanding, the child's own agreement is also sought. Data of children is always treated as sensitive personal data.


10. Sensitive, biometric, immersive, and AI data

Given the nature of our work, Seede XR applies the following additional safeguards to sensitive personal data, biometric data, immersive data, and personal data used with AI.

  1. Explicit consent or a specific lawful ground. Sensitive data is not processed without explicit consent or another specific ground permitted by the PDPA for special categories.
  2. Necessity test. Before capturing biometric or immersive data, the project lead confirms in writing that the creative or technical goal genuinely requires it and cannot be met with less intrusive data.
  3. Data minimisation by design. Hardware and software are configured to capture the least data needed. Optional sensor streams (for example gaze tracking or physiological signals) are switched off unless required and consented to.
  4. Separation and access control. Biometric and immersive datasets are stored separately from ordinary records, encrypted, and accessible only to named team members who need them.
  5. AI-specific controls. Where personal data is used to train, fine-tune, or prompt an AI system:
    • We record the source of the data and the consent or lawful basis for its use.
    • We avoid using sensitive personal data in AI training unless a specific lawful ground applies and safeguards are in place.
    • We assess, before deployment, the risk that an AI system could reproduce a real person's likeness, voice, or identity without authorisation, and we put controls in place to prevent this.
    • We keep a record of the datasets, models, and third-party AI services used on each project.
  6. Cultural and community data. In Afro-centred and heritage work, we recognise that cultural knowledge, imagery, and narratives may carry collective as well as individual sensitivity. We seek consent from relevant knowledge holders and communities, credit sources appropriately, and avoid uses that would misrepresent or exploit the community from which the material originates.

11. Data subject rights

Seede XR respects the rights granted to data subjects under the PDPA and, where applicable, the GDPR. Every person whose data we hold has the right to:

  • Be informed about how their data is collected and used, through clear notices and this policy.
  • Access the personal data we hold about them and receive a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure of their personal data where there is no lawful reason to keep it.
  • Restriction or suspension of processing in defined circumstances.
  • Object to certain processing, including direct marketing.
  • Withdraw consent at any time where consent is the basis for processing.
  • Lodge a complaint with Seede XR and, if unsatisfied, with the Personal Data Protection Commission.

How to exercise rights. Requests can be sent to the Data Protection Officer at the contact details in Section 20. Seede XR will:

  1. Acknowledge the request promptly and verify the requester's identity.
  2. Respond within the timeframe required by the PDPA and its regulations, and in any event without undue delay.
  3. Provide the response free of charge in ordinary cases, reserving the right to charge a reasonable fee or decline where a request is manifestly unfounded, excessive, or repetitive, and recording the reasons for any such decision.

Where a person asks us to erase, rectify, or suspend processing of data that also sits inside a finished immersive work or an AI model, we assess what is technically possible, act on it to the extent we reasonably can, and explain any limitation clearly and honestly.


12. Data security

Seede XR implements appropriate technical and organisational measures to protect personal data, proportionate to the sensitivity of the data and the risk to individuals. These include:

Technical measures

  • Encryption of sensitive, biometric, and immersive datasets at rest and in transit.
  • Role-based access control, so Personnel access only the data they need.
  • Strong authentication, including multi-factor authentication for cloud storage and production systems.
  • Secure, access-controlled storage for project archives, capture rigs, headsets, and removable media.
  • Regular backups, patching, and endpoint protection.
  • Secure configuration of AR and VR hardware and third-party capture tools.

Organisational measures

  • Confidentiality obligations in all employment, freelance, and contractor agreements.
  • A clear-desk and secure-device expectation for Personnel handling personal data.
  • Vetting and written agreements with any third party that handles personal data on our behalf.
  • Periodic internal reviews of who can access what, and removal of access when a project ends or a person leaves.
  • This policy, supported by staff training (see Section 18).

13. Data retention and disposal

Seede XR keeps personal data only for as long as necessary for the purpose it was collected for, or as required by law.

  • Each project records a retention period for the personal data it generates, agreed at the outset with the client where relevant.
  • Contact and contract records are kept for the period required by Tanzanian tax, company, and employment law, then reviewed.
  • Raw capture data (footage, scans, motion and biometric data) that is not needed for the delivered work is deleted once the project is complete and any warranty or revision period has passed, unless the data subject has consented to longer retention for archiving.
  • When retention ends, data is securely and irreversibly deleted or anonymised, and physical media is securely destroyed.

A retention schedule is maintained by the Data Protection Officer and reviewed annually.


14. Sharing and third parties

Seede XR does not sell personal data. We share personal data only where necessary and lawful, for example with:

  • Clients, for delivery of the work they commissioned.
  • Trusted suppliers and processors, such as cloud hosting, AI service providers, rendering services, and exhibition partners.
  • Professional advisers, such as lawyers and accountants.
  • Public authorities, where required by law or valid legal process.

Before engaging any processor or sub-processor, Seede XR:

  1. Assesses whether the third party can provide adequate protection.
  2. Enters a written agreement requiring the third party to process data only on our instructions, keep it secure and confidential, assist with data subject rights and breaches, and delete or return data at the end of the engagement.
  3. Keeps a record of the third parties used and the data they handle.

15. Cross-border data transfers

The PDPA restricts transferring personal data outside the United Republic of Tanzania. Because Seede XR uses international cloud services, AI tools, and collaborators, we treat cross-border transfers as a controlled activity.

Personal data is transferred outside Tanzania only where one or more of the following applies, consistent with the PDPA and its regulations:

  • The recipient country has a legal framework providing an adequate, essentially equivalent, level of data protection.
  • Appropriate safeguards are in place, such as standard contractual clauses or binding commitments between the parties.
  • The data subject has given explicit, informed consent to the transfer, having been told of the risks.
  • The transfer is necessary for the performance of a contract, the establishment or defence of a legal claim, protection of the data subject's vital interests, or an important public interest.

Transfer permit. Where the regulations require it, Seede XR applies to the PDPC for a permit before a transfer is effected, providing the particulars of the applicant, the recipient, the data subjects, and the purpose. The PDPC reviews such applications within the period set by the regulations and may attach conditions, including that the data is used only by the authorised recipient, only for the stated purpose, and not onward-transferred without approval.

Before any transfer, the responsible producer records the destination, the safeguard relied on, and whether a permit is required.


16. Data protection impact assessments

Seede XR carries out a Data Protection Impact Assessment (DPIA) before starting any processing likely to result in a high risk to people's rights and freedoms. Given our work, this is likely whenever a project involves:

  • Large-scale capture of biometric or immersive data.
  • Systematic monitoring of participants inside an experience.
  • Processing sensitive data or data of children.
  • Use of AI to create or recreate identifiable people.
  • New technologies or novel uses of existing technologies.

The DPIA describes the processing, assesses necessity and proportionality, identifies risks to individuals, and sets out the measures to reduce those risks. Where a DPIA shows a high residual risk that cannot be mitigated, Seede XR consults the PDPC before proceeding. DPIAs are recorded and retained.


17. Data breach management

Seede XR treats any suspected data breach seriously and acts quickly.

  1. Report internally. Any person who becomes aware of a suspected breach must report it to the Data Protection Officer immediately.
  2. Contain and assess. The Data Protection Officer coordinates containment, investigates what happened, what data and how many people are affected, and the likely consequences.
  3. Notify the Commission. Where the PDPA and its regulations require it, Seede XR notifies the PDPC without undue delay, providing the required details.
  4. Notify affected individuals. Where a breach is likely to result in a high risk to affected individuals, Seede XR informs them in clear language and explains what they can do to protect themselves.
  5. Processor duty. Where Seede XR acts as a processor and becomes aware of a breach, it notifies the relevant controller without undue delay.
  6. Record and learn. All breaches, including those not notified, are logged with the facts, effects, and remedial action taken, and are reviewed to prevent recurrence.

A breach response record and register is maintained by the Data Protection Officer.


18. Roles, responsibilities, and training

Data Protection Officer (DPO). Seede XR appoints a Data Protection Officer, as required for organisations whose core activities involve regular and systematic monitoring or large-scale processing of sensitive data, which describes our immersive and AI work. The DPO:

  • Oversees compliance with this policy and the PDPA.
  • Serves as the contact point for data subjects and for the PDPC.
  • Maintains records of processing, DPIAs, transfers, breaches, and consents.
  • Prepares and submits any compliance reports required by the PDPC, including periodic reports where the regulations require them.
  • Advises project teams and delivers staff training.

Directors and management are accountable for resourcing and supporting data protection and for setting the tone that privacy is part of good creative practice.

All Personnel must follow this policy, complete data protection training, handle personal data only as authorised, and report concerns and suspected breaches promptly.

Training. Seede XR provides data protection training to all Personnel at induction and at regular intervals, with additional guidance for teams working directly with biometric, immersive, or AI data.


19. Registration and regulatory compliance

The PDPA requires data controllers and data processors to register with the Personal Data Protection Commission before collecting or processing personal data. A registration certificate, once issued, is valid for a period of five years and is renewable, with renewal applications made in advance of expiry.

Seede Group Company Limited is committed to completing its registration with the PDPC and, in the meantime, applies the standards set out in this policy to all personal data it processes. Once registration is granted, the studio will keep its registered particulars accurate and up to date and will record its registration details for reference.

Entity detail Value
Registered entity Seede Group Company Limited
Trading name Seede XR
BRELA licence number 101372650

Seede XR cooperates fully with any lawful inquiry, audit, or enforcement action by the PDPC.


20. Complaints and contact

Any person can raise a question or complaint about how Seede XR handles their personal data.

Data Protection Officer, Seede XR
Seede Group Company Limited
Email: a.mkwizu@seedexr.com
Telephone: +255753648150
Address: Tembomgwaza, MajiChumvi - Tabata Kimanga

Seede XR aims to resolve complaints directly and promptly. If a person is not satisfied with our response, they have the right to complain to the regulator.

Personal Data Protection Commission (PDPC), United Republic of Tanzania
Website: www.pdpc.go.tz

Individuals in the EEA or United Kingdom may also have the right to complain to their local data protection authority.


21. Non-compliance and consequences

Compliance with this policy is a condition of employment and of engagement for all Personnel. Breach of this policy may result in disciplinary action, and, for contractors and partners, termination of the engagement.

Personnel and the company should be aware that the PDPA provides for significant consequences for non-compliance, which may include administrative fines, criminal penalties including imprisonment for serious offences, and orders to compensate data subjects who suffer damage. These consequences are a further reason why every member of the team shares responsibility for getting this right.


22. Review of this policy

Seede XR reviews this policy at least once a year and additionally whenever there is a significant change in the law, in our services or technologies, or following a material incident. Because both Tanzanian regulations and the European framework are evolving, including the EU Digital Omnibus reforms proposed in November 2025, the Data Protection Officer monitors developments and updates this policy as needed.

Changes are approved by management, version-controlled, and communicated to all Personnel.


23. Document control

Version Date Author Summary of change
1.0 7 July 2026 Data Protection Officer Final adopted policy