Document summary
This policy explains the personal data we process, its sources and purposes, sharing, retention, and data subject rights.
Who controls the data?
Cup Code Studio manages data collected through its public services unless a contract or product notice states that Cup Code processes data on behalf of a client. The privacy request route and studio@cupcodestudio.com receive questions and requests. We do not publish a registration number or legal address before it is documented in the organization register.
Scope and precedence
This policy covers visits, accounts, Council activity, forms, tickets, and user portals. A client project, game, or app may provide a more specific notice. Applicable law, contract terms, or a product-specific notice prevails for its scope.
Data categories
We process the minimum data tied to the stated purpose. Categories vary by the feature used.
- Identity and contact data, such as name, email, phone, organization, and language.
- Account and security data, such as account ID, verification state, sessions, devices, and sign-in attempts.
- Transaction content, such as a project request, suggestion, comment, ticket, file, consent, or correspondence.
- Technical and operational data, such as request logs, browser type, network address where needed, errors, and performance signals.
- Contract and finance data for client relationships. Website forms do not store full payment card details.
Data sources
We obtain data from you, an authorized member of your organization, an integration you use, or service operation logs. We do not buy personal data lists for marketing.
Purposes and lawful basis
Each processing activity is tied to a defined purpose and suitable basis. This includes fulfilling a request or contract, explicit consent where needed, a legal obligation, or a documented legitimate interest that does not override data subject rights.
- Provide accounts, services, support, and project delivery.
- Protect accounts, prevent fraud and abuse, and respond to incidents.
- Improve performance, accessibility, and user experience using aggregated data or suitable consent.
- Send service communications, and marketing messages only under the available choice.
- Keep records needed for rights, claims, and legal obligations.
Required and optional data
Required fields are clearly marked and the form explains the effect of not providing them. Optional data is not used for an incompatible new purpose without notice or required consent.
Transfers outside the Kingdom
We identify processing location before enabling an external provider. Data is transferred outside the Kingdom only after validating purpose, minimization, applicable controls or exemption, and documenting the transfer assessment and contractual safeguards where needed.
Retention and disposal
Each category has a retention period based on purpose, contract, obligation, and dispute needs. Once no longer needed, data is securely deleted or anonymized. A legal hold pauses disposal only for its scope and is reviewed regularly.
Data subject rights
Subject to legal conditions, a data subject has rights to be informed, access and obtain a copy, correction, destruction, consent withdrawal, and other applicable rights. We verify identity and explain the outcome, including reasons for partial refusal or required retention.
Analytics and AI
Passwords and payroll data are not sent to AI models. Any feature using personal data is assessed for purpose, minimization, access, provider, and retention. The system does not make a legal decision or permanent user ban based only on an automated result.
Security and incidents
We apply role-based access, MFA for sensitive accounts, transport encryption, secret protection, audit logs, file scanning, backups, and restore tests. We assess incidents and notify the authority and affected data subjects when reporting conditions are met and within the required period.
Minors data
Business services and project requests are not directed to minors. If a game or app targets a younger audience, we publish a specific notice and apply suitable consent, minimization, and privacy settings.
Submit a request or complaint
Use the data rights form or the privacy contact route and state the right, product, and scope. The operating deadline starts when the request is received, and we target a response within 30 days. Verification occurs during this period and does not restart it. Where a permitted extension ground applies, we notify you before the deadline with the reason and new date, within the legally allowed extension.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
- Personal Data Protection LawSDAIA, National Data Governance Platformopens in a new tab
- PDPL Implementing RegulationsSDAIA, National Data Governance Platformopens in a new tab
- Personal data breach notification serviceSDAIA, National Data Governance Platformopens in a new tab
- Regulation on Personal Data Transfer Outside the KingdomSDAIA, National Data Governance Platformopens in a new tab
- E-Commerce LawBureau of Experts at the Council of Ministersopens in a new tab
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.