Legal

Privacy Notice

Effective date: 24 April 2026 · Complies with the Saudi Personal Data Protection Law.

1. INTRODUCTION

This Privacy Notice explains how Titan Battle ("Titan Battle", "we", "us", "our") collects, uses, discloses, and protects personal data when you use the Titan Battle online portal and related services (the "Services") and when you attend our events. We comply with the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19 of 2021, as amended, the "PDPL") and its implementing regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA).

2. DATA CONTROLLER

Titan Battle is the data controller for personal data processed through the Services. You can reach us at sponsor@titanbattle.fit or through the in-Portal support system for any privacy request, question, or complaint.

3. PERSONAL DATA WE COLLECT

We collect the following categories of personal data:

Account and profile data: name, email address, phone number, preferred language, password (stored as a salted hash only), and profile details.

Ticketing and order data: order number, product purchased, price paid, currency, billing and shipping address, and order status. Payment card data is processed by our Shopify storefront's payment processor and is not stored by Titan Battle.

Team and event data: team name, team role (captain or member), team invite code, teammate email addresses you submit for invites, event entitlements, check-in records, and performance scores.

Waiver and safety data: the text of the waiver version you signed, the name you signed with, your electronic signature record, your IP address, browser/user-agent, and the date and time of signing.

Health and emergency data (limited): conditions, injuries, pregnancy, or medications you disclose, and emergency contact details, where you choose to share this with us for your safety at events.

Media data: photographs, video, and audio recordings captured at events, which may feature you.

Communications and support data: support tickets, messages, and any information you share with us through customer service or email.

Technical data: IP address, device identifiers, browser type and version, operating system, time zone, referring URL, and interactions with the Services; and essential cookies and similar technologies required to operate the Services.

4. HOW WE USE PERSONAL DATA

We use personal data to: operate the Services and your account; fulfill ticket purchases and grant event entitlements; enable team registration, invitations, and seat assignments; manage waivers and event check-in; ensure on-site safety and respond to medical incidents; record and publish event scores and leaderboards; communicate with you about your account, tickets, events, and support requests; send service and transactional emails (for example, magic-link sign-in and team invitations); promote Titan Battle through event coverage and recap materials; analyze and improve the Services; prevent fraud, abuse, and security incidents; and comply with legal obligations, including record-keeping and responses to lawful requests from competent authorities.

Where we use personal data for direct marketing (for example, season announcements), we rely on your consent and offer a clear mechanism to opt out in every marketing message.

5. LEGAL BASES UNDER THE PDPL

We process personal data on one or more of the following legal bases recognized by the PDPL: (a) your explicit consent, for example when you sign the waiver, provide health information, or opt in to marketing; (b) performance of a contract with you, for example to deliver tickets, check you in, and operate your team; (c) compliance with a legal obligation, for example accounting, tax, and safety records; (d) protection of vital interests, for example in a medical emergency during an event; and (e) our legitimate interests where not overridden by your rights, for example preventing fraud, securing the Services, and producing event recap media.

6. HOW WE SHARE PERSONAL DATA

We do not sell personal data. We share personal data only in the following circumstances:

Service providers and processors: we use vetted third parties to host, operate, and support the Services, including (currently) Shopify for e-commerce, Vercel for application hosting, Neon for database hosting, Resend for transactional email, and Google for maps and fonts. These providers process personal data on our behalf under written agreements requiring appropriate security and confidentiality.

Event partners and officials: we share limited operational data (such as athlete name, team, and check-in status) with venue operators, event officials, judges, medical staff, and safety personnel strictly as needed to run the event.

Sponsors and media: in-event photography and video may feature participants and is shared with sponsors, media partners, and published through our social channels as part of our event coverage rights under the waiver.

Legal and regulatory: we may disclose personal data to comply with applicable law, valid legal process, or requests from competent Saudi authorities, and to protect the rights, safety, and property of Titan Battle, its participants, staff, or the public.

Business transfers: in the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.

7. INTERNATIONAL TRANSFERS

Our Services use international cloud infrastructure, which means personal data may be processed outside the Kingdom of Saudi Arabia by our service providers. We carry out these transfers in accordance with the PDPL and SDAIA guidance, including assessing the level of protection, entering into contractual safeguards with recipients, and limiting the scope of data transferred. You can contact us for more information about the transfers and safeguards that apply to your data.

8. RETENTION

We keep personal data only as long as needed for the purposes described in this notice or as required by law:

Account data is retained while your account is active and for up to five (5) years after account closure to handle post-season queries and comply with applicable law.

Order and financial data is retained for at least ten (10) years from the date of the transaction in accordance with Saudi tax and commercial record-keeping requirements.

Waiver signatures and related event safety records are retained for at least ten (10) years from the date of the event to defend against potential claims.

Check-in, team, and performance records are retained while relevant for the season and season archive.

Event photography and video are retained indefinitely as part of the Titan Battle brand archive.

Support tickets are retained for up to five (5) years.

When data is no longer needed, we delete or anonymize it in a secure manner.

9. YOUR RIGHTS UNDER THE PDPL

Subject to the conditions and limits set out in the PDPL, you have the right to: (a) be informed of the legal basis and purposes for processing your data; (b) access your data; (c) request correction of inaccurate or incomplete data; (d) request the destruction of your data where it is no longer necessary for the stated purposes and where retention is not required by law; (e) withdraw consent where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and (f) request data portability where applicable.

To exercise any of these rights, contact us at sponsor@titanbattle.fit. We will respond within the timelines required by the PDPL. If you are not satisfied with our response, you have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).

10. SECURITY

We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, and destruction. These include transport encryption, encrypted database connections, salted password hashing, access controls, audit logging of sensitive administrative actions, and least-privilege access for staff. No method of transmission over the internet or method of electronic storage is fully secure, and we cannot guarantee absolute security.

11. COOKIES

We use a small number of strictly necessary cookies and local storage items required to operate the Services (for example, your sign-in session and your preference for whether the WhatsApp support button is shown). We do not use third-party advertising cookies. If in the future we introduce analytics or marketing cookies, we will update this notice and obtain your consent where required.

12. CHILDREN

The Services are not directed to individuals under the age of eighteen (18), and you must be at least eighteen to create an account or participate in an event. If you believe a minor has provided personal data to us without parental consent, please contact us and we will take appropriate steps to delete the data.

13. CHANGES TO THIS NOTICE

We may update this Privacy Notice from time to time. When we do, we will update the "Effective date" above and, where changes are material, we will notify you through the Portal or by email.

14. CONTACT

For privacy requests, questions, or complaints, contact us at sponsor@titanbattle.fit. Our website is titanbattle.fit and our customer Instagram is @titan.battle.

Privacy requests: sponsor@titanbattle.fit.