1. An Overview of This Policy
This Privacy Policy explains how information is collected, used, shared and kept safe when a person visits the website at cdsarhold.lat or enquires about the virtual production stages, augmented reality content and broadcast integration services offered by the organization behind this site. The policy is written to be plain and readable, and it reflects the way this business actually handles data rather than a set of rules copied from another industry.
The organization that runs these services is an operating company in the computer systems design and related services sector. The site is developed and maintained by CDSARHold for that organization. Where the word Company appears in this policy it refers to the legal entity described in the Scope section of this document. Where the word User appears it refers to any individual who reads the website, sends an enquiry, books a stage day or otherwise provides information through the channels described here.
A short summary appears first so a reader can understand the main ideas without reading the entire document. The full sections that follow give the detail. Nothing in the summary replaces the sections below, and the sections below govern how any information is treated.
2. Scope and Who We Are
This policy applies to the website located at https://www.cdsarhold.lat and to any related booking, support or stage enquiry channel that links to this policy. It does not apply to websites that belong to third parties, including any platform that carries content produced on a stage or any tool that a visitor uses to reach this site.
The Company
Legal name: CDS AR HOLDINGS, LLC
Registered and operating address: 2681 E 6425 S, Uintah - 84403-5451, United States (US)
Email of the dispatch desk: dispatch@cdsarhold.lat
Production telephone line: +12233871381
CDS AR HOLDINGS, LLC is a limited liability company formed under the laws of the United States and located in the state of Utah. Uintah is the community associated with the company street address given above. The stage and the offices that support it are reached through the email and telephone details shown across this website.
CDSARHold is the name used publicly as the developer and operation brand behind the site. When a User writes to the dispatch desk or books a stage day, the request is answered by the same team and is governed by this single policy, whether it is described as acting for the Company or under the CDSARHold brand. There is only one holder of any personal information described in this document.
Because the industry in which the Company works is computer systems design and related services, the information handled most often concerns business enquiries, production planning and content delivery. Consumer personal data is not the main purpose of the business and is collected only in the limited ways set out in the next section.
3. The Information We Collect
The information that the Company collects falls into a few clear groups. The first group is information a person provides directly, such as a name, an email address, a telephone number, the subject of an enquiry and the content of a message. This information arrives through the contact form on the site, through and a direct email to the dispatch desk, through a telephone call or through written correspondence sent to the address given above.
The second group is information gathered automatically when a person uses the website. This can include the browser type, the operating system, the date and time of a visit, the pages viewed, the approximate region of the device and the referring website. Log files hold basic request details for a short time so that the site can be kept stable and attacks can be recognised.
The third group is information connected to a production project. Where a client engages the Company for a stage day or an augmented reality build, the Company may receive details of the creative work, file names, tracking surveys, still frames, contact names of a client team and scheduling notes. This information is treated as confidential project material and is handled according to the same care that is applied to any other data described in this policy.
The fourth group is payment and fulfilment data. Booking an actual stage day normally requires an invoice and a payment method. Payment itself is usually collected through a separate payment provider, and the Company keeps only the record needed to issue an invoice and to prove the transaction. Finally, the Company keeps the minimum administrative data needed to comply with accounting law in the region where the Company is formed.
The Company does not seek to collect sensitive categories of personal data as that term is used in many privacy laws. If sensitive information is sent to the dispatch desk by mistake, the sender is asked to resend a version without that detail, and the early message is removed where it is reasonable to do so.
4. How We Collect Information
Information is collected in three straightforward ways. First, through direct interaction, when a User sends a message, calls the line, writes an email or posts a letter. Second, through automated means, when a browser requests pages from the web server and when small storage files known as cookies are read. Third, through the normal operation of the business, when a client places an order, signs a production agreement or sends stage and content files to the dispatch desk.
Direct interaction is always voluntary. A User is never required to identify themselves just to read the pages of this website. Providing an email address or telephone number is needed only where the User wants an answer to an enquiry or wants to reserve a stage day. The amount of information given in a first message can be small and the team will follow up to ask only for what the reply or booking genuinely requires.
The web server records requests because every web server does so to function. No attempt is made to join those short-lived logs to a named person without a clear reason, such as the investigation of a security incident. Cookies used on the site are described in the next section and are limited to the few that help the site work well rather than to build a broad profile of a visitor.
During a production project, files move to and from the Company by a range of tools chosen by the client, such as project portals, secure transfer links and email. The Company does not scan the creative content beyond what is needed to do the work agreed with the client. Any survey or tracking data taken in a stage belongs under the terms of the production agreement that governs that project.
The Company does not buy personal information from data brokers and does not harvest contact details from public directories for marketing. The only people on the mailing list, if a list is ever used, are those who asked to be contacted or those who are clearly part of an active client project.
6. How We Use the Information
Personal information is used for a short list of purposes that a sensible reader would expect. The information a User sends in an enquiry is used to answer that enquiry. The information on a booking call sheet is used to prepare, price and run a stage day. Project files are used to do the agreed work. Payment details are used to bill and to keep the accounting legal. Log data is used to keep the site running and secure.
The dispatch desk may keep a record of an enquiry so that the same person is not asked twice for the same detail, and so that a follow up call can be made to a client whose stage window is about to pass. These records are kept as short as the project needs and are not sold or rented to anyone.
Where a client was contacted by the Company after an enquiry, the Company may occasionally send a note about a relevant stage opening or a new service line that directly matches an earlier request. Every such note includes a clear way to stop further notes. No general consumer marketing database is built from stage enquiries, and the Company sends no bulk messages to people who have no connection to a project or an active request.
Aggregated and de-identified information may be used for planning, for example to decide which stage weeks are busiest or which service line needs more crew. Once data is de-identified so that it can no longer be linked to an identifiable person, it falls outside the personal data rules of this policy and may be kept for analysis for as long as the Company finds it useful.
7. Legal Bases for Processing
Different privacy laws ask a controller to name the reason, or legal basis, behind each act of processing personal data. The main bases that the Company relies on are these. The first is contract, where processing is needed to prepare for or to perform a booking or a service agreement that a client has asked for. The second is legitimate interest, where the processing serves the reasonable running of the business without overriding the rights of the individual.
Legitimate interest is used for the smaller pieces of administrative work: keeping the site secure, recording an enquiry so it can be answered well, keeping basic accounting and arranging insurance cover required for a stage. The Company believes these interests are fair because they concern the ordinary running of a production services business and use only the data that a reasonable customer would expect to provide.
The third basis is consent, which is used where a rule clearly requires a free choice, such as signing up for a note about future stage openings. Where consent is the basis, a User may withdraw that consent at any time by writing to the dispatch desk address shown in the contact section, and the effect of the withdrawal is explained in the reply.
The fourth basis is a legal obligation, for example keeping the records that tax law in Utah requires for a limited liability company. Where processing relies on a legal obligation, the Company keeps only what the law needs and for no longer than the law needs it. Where a foundation matters to a specific request, the Company will name the basis that applies to that request in the ordinary course of answering it.
9. Service Providers and Processors
The processors that serve the Company fall into a small number of roles. A web hosting company stores the public pages and the log files that keep them running. An email provider carries the mail to and from the dispatch desk. A payment processor holds the bank and card details needed to settle a stage bill, acting under its own strict rules. An accounting package keeps the invoices and expense records that tax law expects.
Each of these processors is assessed before it is chosen as far as a business of this size can reasonably assess them, with attention to where the data will be held, how it is protected and what the contract says about the use of the data. The Company does not hand data to a processor that has a reputation or a record of using customer data for its own marketing.
The practice of the Company is to keep personal data inside the United States wherever the chosen tools make that possible, and to note this policy where data moves across a border as explained in the cross border section below. Where a processor uses sub-processors of its own, the Company expects the top processor to answer for the whole chain, because the client is dealing with the Company and not with a web of hidden contractors.
Staff of the Company are also processors in the practical sense. Only the people who need access to answer an enquiry or to run a stage day are given that access, and a shared mailbox is used so that cover is possible without every employee reading every message. Access to project files is reviewed when a project ends and a person leaves the team.
10. Virtual Production and Stage Data
The heart of the business is a greenscreen stage and augmented reality work, and that work produces its own kind of information. Camera surveys describe the floor grid of the stage. Tracking files record how a virtual camera moves against the physical one. Frame stores hold the takes that cleared at the village. These files are not personal data in the ordinary sense, but they are confidential to the client and are handled with the same discipline.
When a person appears on a stage, a frame of that person may be included in footage, a behind the scenes still or a survey shot. If the Company is asked to use such a frame publicly, it asks the talent and the client first, in keeping with the practice of the film and television industry. A stage day call sheet lists the people expected and a safe contact for each, and that sheet is destroyed or returned to the client at the end of an agreed window.
Augmented reality content and real time composites can carry names and images of people, but the Company holds that content under the production agreement and has no independent agenda for it. Talent likeness rights are owned by the client under the relevant shoot agreement and are not used by the Company beyond demonstrating the work with the client agreement.
Live broadcast work may generate statistics and operator logs. Those logs are normal technical records and are kept only long enough to prove a clean build and to defend a technical decision if a client asks. They are not joined to any wider marketing database and are not sold.
11. Notice Regarding Children
The services offered through this website are directed at adults, studios, brand teams and production companies. The greenscreen stage and the augmented reality pipelines are not designed as an activity for children, and the Company does not knowingly collect personal information from children under the age of thirteen.
Where an estate or a shoot involves a young performer, the responsible adult provides the needed details, and the Company asks the adult to confirm that the consent rules of the applicable law are satisfied before personal data of a minor is sent. The Company does not set out to store data of children and reviews its records for any that arrives by mistake.
If a parent or a legal guardian believes that the Company has received personal information about a child without that proper involvement, the guardian should contact the dispatch desk without delay using the details in the contact section. The Company will review the record and remove it where the law and the project allow.
12. Data Retention Practices
Data is kept only as long as a reason exists to keep it. An enquiry is held until it is answered and then for a short follow up window, so that a question does not go cold mid-conversation. Once a lead has clearly closed, the message and its detail are removed and only a note of the contact remains if the person asked to be reminded about future stage openings.
A production project runs on a defined timeline. Survey files, tracking data and delivery frames are retained for the window agreed in the production terms, then deleted or returned to the client at the chosen destination as that agreement permits. Tax and accounting records are held for the number of years that the law of Utah and the United States requires a limited liability company to keep them.
Web server logs are rotated and overwritten on a short schedule, normally measured in days, unless a fault or an attack needs a longer look. Security records related to a confirmed incident may be held longer if a regulator or a legal matter requires it, and a note of that holding is made so the reason is not lost.
When retention ends, data is deleted or made anonymous in a way that cannot be reversed. Paper schedules that list a production crew are shredded. A short written register shows what was removed, when and on what instruction, so an answering later subject request does not depend on memory.
13. Security of Your Data
Protecting the data the Company holds is treated as part of doing the work well. The website is served over an encrypted connection so that a form submission travels in a way that cannot be read easily on the way. Passwords are stored in a hashed form that is hard to use even if a store is taken. Access to the dispatch mailbox and to project folders is limited to the people who need it for that day.
The physical stage carries its own discipline: call sheets sit on a clipboard by the door, project files go to the client at wrap, and a lock exists for any equipment or media holding client data. On the digital side the same care is taken with the machine that runs the real time engine and with the drive that stores frames.
No method over the internet is ever completely safe, and the Company cannot promise an absolute guarantee. What the Company can promise is a real set of controls, regular updates to the systems that hold this data, and a prompt, plain answer if a security matter ever touches the data in a way a client should know about. Where the law requires a notice of a data breach, the Company will give that notice without delay and describe what is being done.
14. Your Choices and Rights
Privacy laws around the world give individuals a set of related rights over their own information. The Company honours these wherever they apply, and the practical way to use them is simple. A person may ask to see the personal data the Company holds about them, may ask for a correction where something is wrong, may ask for a copy in a common format, and may ask the Company to stop processing or to delete the data where the law allows.
To make such a request, the easiest route is to email the dispatch desk. To be sure the Company is talking to the right person, a simple verification is done, such as calling back on the recorded telephone number or asking for a small piece of matching detail. This step exists to keep the data out of the wrong hands and is not a way of slowing a fair request down.
The Company will respond to a verified request within the window that the applicable law allows, which is commonly around thirty days, and will extend that only where the law sets out a clear reason and the request is explained. Where a request cannot be met, the reply will say why and will point to the right to complain to a regulator where that applies.
Automated decisions are not made about an enquiry or a booking. No computer decides who gets a stage day or who receives a callback. Where the wording of a request suggests otherwise, the reply will set the record straight in plain terms.
15. State and Regional Rights
The Company is located in the state of Utah in the United States, and clients may be located in many places. Where a person lives in a state or a region that grants extra rights, the Company respects those rights where the person qualifies for them. Rights such as the right to opt out of a sale, the right to correct data and the right to a reasonable limit on the retention of sensitive data are acknowledged in principle.
Because the Company does not sell personal information, the need for a sale opt out rarely arises. Where state law requires notice of a sale or of sharing for a cross context advert, the Company confirms in writing that neither occurs through this site. Some states grant a right against discrimination for using these rights; the Company does not treat a person differently because they asked for their data to be respected.
Overseas rules, such as the roles of controller and processor found in Europe, are understood by the team that runs the dispatch desk. Where European law applies to a particular request, the contact section points the reader at the correct way to reach the Company and explains the basis for any cross border handling in the section that follows this one.
16. Cross Border Transfers
Most of the data the Company handles stays in the United States because the stage, the office and the main tools that support them are there. Where a tool stores data in another country, or where a client sends data from outside the United States, a transfer may occur across a border. That is expected in international production work and is handled in a deliberate way.
The principle is that a transfer is only made where the data protection of the receiving location is adequate in practice, or where a recognised safeguard such as a standard contractual clause is used, or where the move is clearly needed to perform the contract with the client. The dispatch desk can say which standard applies to a given project when a client asks.
The Company keeps the number of cross border locations small and reviews them when a tool is changed. A client who wants their data kept inside one country can state that on the call sheet, and the stage will work within the practical limit of that instruction for the tools it can control. Where the tools make a strict single country promise impossible, the client is told before the work begins rather than after.
17. Links to Other Websites
Pages on this website may point to tools that sit outside the control of the Company, such as a payment page, a file portal chosen by a client, or a public profile of a show. When a visitor follows such a link they leave the pages covered by this policy, and the privacy practices of the destination belong to the owner of that destination.
The Company does not control and cannot answer for the cookies, the logging or the marketing of an outside site. A reader who cares about those choices is encouraged to review the policy of the destination before sharing any detail with it. The presence of a link on this site is advice to a useful resource, not an agreement to be responsible for everything that resource does.
Where the Company sends a file by a third party portal, the portal is chosen because it is a professional transfer tool, and the Company sends the portal only the file needed for that transfer. The standing of that specific portal is still governed by the portal own policy, and delivery confirmation is sought from the client on the production side rather than assumed.
18. Changes to This Policy
The practices described here can change as the site and the business change. When this policy is updated, the date at the top of the document is revised to show the month and year of the latest issue, and the most recent version is the one that applies to any new data or to any continued use after that date.
For changes that change how personal data is treated in a meaningful way, such as a new kind of sharing or a new type of collection, the Company will give a clear heads up rather than slipping the change in quietly. That notice may take the form of a line on the website or a short note to active contacts, depending on how the matter affects them.
Older versions of the policy are not published as separate pages, but a record of the revision date is kept so that a question about what applied on a given day can be answered accurately. The duty under this section is to be honest about timing and effect, not to bury a change in fine print far from the eyes of a reader.
19. How to Contact Us
The quickest route to the Company is the dispatch desk, which answers the site and the stage enquiries. A person can ask a question about this policy, make a data request or raise a concern by using any of the contact points below. The Company aims to reply to a personal data question within the window set by the law that applies to the request.
Contact Details
Company name: CDS AR HOLDINGS, LLC
Address: 2681 E 6425 S, Uintah - 84403-5451, United States (US)
Email: dispatch@cdsarhold.lat
Telephone: +12233871381
If a request is about how this website works or about a booking, the same desk is the right place and no separate data office exists. If a dispute about data cannot be settled to the satisfaction of the person raising it, that person may also complain to the data protection authority in the place where they live, and the Company will cooperate with any lawful review that a proper authority begins. The developer CDSARHold and the Company act as one operation for the purposes of answering any enquiry raised under this policy.
This policy forms part of the wider terms that govern a visit to this website and the use of the services offered here. The legal documents of the Company work together, and a fuller description of the responsibilities of a User is given in the separate Terms of Service that are linked from the footer of every page.