CaptainX SQR
Privacy Policy
آخر تحديث · 20 August 2026
This policy explains what personal data CaptainX handles through SQR, why, on what legal basis, and what you can ask us to do about it. It is written to meet the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19) and its Implementing Regulations.
1The short version
- This website sets no cookies, runs no analytics and loads nothing from a third party. Reading it tells us nothing about you.
- If you ask for access, we keep what you type in the form so we can reply to you.
- Match footage uploaded to SQR belongs to the organisation that uploaded it. That organisation decides what happens to it; we process it on their instructions.
- We do not use anyone's footage to train our models unless the organisation that owns it has explicitly opted in.
- You can ask us what we hold about you, get a copy, correct it or have it destroyed — see section 10.
2Two different roles, and why it matters
CaptainX handles personal data in two distinct capacities, and your rights are exercised differently in each.
We are the data controller for people who visit this website, ask for access, hold an SQR account, or contact us. We decide why and how that data is processed, and you should come to us directly.
We are a data processor for the footage our customers upload and for everything derived from it — including the players and other people in that footage. The customer organisation is the controller. It decides what is uploaded, why, who can see it and how long it is kept. If you are a player, a parent or a guardian and you want to know what is held about you or have it removed, the club, academy or agency is the right place to ask; if you contact us we will pass your request to them promptly and help them act on it.
3What we collect when we are the controller
Visiting the website. Nothing. This site sets no cookies, uses no analytics or tracking pixels, and loads its fonts, images and video from our own servers rather than a third party. Our hosting provider keeps standard server logs, which may briefly include your IP address, for security and to keep the site running.
Asking for access. What you enter in the request form: your name, email, phone number if you give one, country, the type of organisation you are, your role, and what you tell us you want SQR to do. We use it to reply to you and to set you up.
Holding an account. Your name, work email, the Google account used to sign in, your role and permissions, and a record of what you did in the Service — which clips were uploaded, which reviews you confirmed or overruled, and when. That record is part of what SQR is for: it is what lets a decision be retraced later.
Billing. The contact and billing details we need to invoice your organisation and meet our tax and accounting obligations. We do not store card numbers.
Contacting us. Your message and whatever is in it.
4Footage, and the people in it
Match footage shows identifiable people, and the analysis run on it produces movement and positional data about them. Under the PDPL, location data and biometric data are sensitive personal data, which requires explicit consent.
When a customer uploads a clip, we process the video, the descriptions they attach to it, the identification SQR makes, and the analysis it derives — which can include positional traces, distance covered, speed and other measures of physical performance.
The customer organisation is responsible for holding a lawful basis for all of it, including explicit consent where the data is sensitive, and verifiable consent from a parent or legal guardian for anyone under 18. Our terms require that of them before they upload anything. We do not obtain that consent ourselves and are not in a position to — we are not at the ground.
We process footage only to provide the Service to the customer who uploaded it. We do not sell it, share it with other customers, or use it for advertising. It is not used to train our models unless that customer has separately and explicitly opted in, which is off by default.
5Why we process it, and on what basis
- To provide the Service and perform our contract with your organisation — basis: performance of a contract.
- To reply to an access request or an enquiry you sent us — basis: your consent, and steps taken at your request before entering a contract.
- To keep the Service secure, prevent abuse and investigate incidents — basis: our legitimate interest in a secure service, assessed against your rights and documented.
- To fix faults and improve the Service using aggregated, non-identifying usage statistics — basis: legitimate interest.
- To invoice and to meet tax, accounting and record-keeping obligations — basis: compliance with a legal obligation.
- To train or improve our models using customer footage — basis: explicit opt-in consent from the customer organisation, which we do not have unless it has been given in writing.
Where we rely on your consent, you can withdraw it at any time; that does not affect processing already carried out.
6Who else sees it
We keep the list of suppliers short, and every one of them is bound in writing to protect the data, to process it only on our instructions, and to meet standards at least equivalent to those we accept ourselves. We use:
- cloud hosting and storage, to run the Service and hold your data;
- AI processing, to produce the analysis itself;
- authentication — Google Sign-In, which is how SQR accounts log in;
- email delivery, for service messages and support;
- professional advisers, auditors and, where we are compelled to, a court or competent authority.
We do not sell personal data, and we do not share it for anyone else's marketing.
7Where it is processed
We aim to keep personal data within the Kingdom of Saudi Arabia. Where a supplier processes it outside the Kingdom, we transfer it only in accordance with the PDPL and its Data Transfer Regulations: limited to the minimum data needed, under appropriate safeguards such as standard contractual clauses or binding common rules, and never where it would prejudice the national security or vital interests of the Kingdom.
Before any continuous or large-scale transfer, and before any transfer of sensitive data, we carry out and document a transfer risk assessment. If a safeguard we rely on stops being effective, we stop the transfer.
We keep a current list of our sub-processors naming each company, what it does for us and the country it processes data in. Write to info@captainx.ai and we will send it to you. We would rather answer that question properly than print a list here that goes out of date the week a supplier changes.
8How long we keep it
- Access requests: 24 months from your last contact with us, then deleted.
- Account and usage records: for as long as the account is active, then 12 months after it closes.
- Customer footage and analysis: for as long as the customer keeps it, and deleted within 30 days of their account ending, or sooner on their instruction.
- Billing and tax records: for the period required by the tax and commercial laws of the Kingdom.
- Records of processing activities: while processing continues, and for five years afterwards, as the Implementing Regulations require.
- Server logs: 90 days.
When a retention period ends we delete the data or irreversibly anonymise it.
9How we protect it
Data is encrypted in transit and at rest. Access is limited to the people who need it for their job, under individual accounts, and is logged. Workspaces are separated so one customer cannot see another's data. We review access regularly, keep our systems patched, and require our suppliers to do the same.
No system is perfectly secure, and we will not claim otherwise. What we can promise is that we design for the assumption that something will go wrong one day, and that we will tell you when it does — see section 11.
10Your rights
Under the Personal Data Protection Law you have the right to:
- be informed — to know why we are collecting your data, what we do with it and who else sees it, which is what this policy is for;
- access — to ask whether we hold data about you and to see it;
- obtain a copy — in a readable, clear and commonly used electronic format;
- correction — to have data that is inaccurate, incomplete or out of date put right;
- destruction — to have your data deleted when it is no longer needed for the purpose it was collected for, or where the processing breaches the law.
Write to info@captainx.ai and we will respond within 30 days. There is no charge. We may need to verify who you are before we act, and we will only ask for what we need to do that.
If your request concerns footage held by a club, academy or agency, see section 2 — they are the controller, and we will pass your request to them and support them in answering it.
If you are not satisfied with how we have handled your data, you may complain to the Saudi Data and Artificial Intelligence Authority (SDAIA), the competent supervisory authority in the Kingdom.
11If there is a breach
If personal data we hold is breached in a way that poses a risk to the people it belongs to, we will notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of it, and notify the affected individuals — or, for customer footage, the customer organisation — without undue delay. We will tell you what happened, what data was involved, what we have done and what you should do.
12Children
SQR accounts are for adults. Nobody under 18 may register.
Footage of players under 18 may lawfully be processed in SQR, and in academy work it usually will be — but only where the customer organisation holds verifiable consent from a parent or legal guardian, obtained before the footage is uploaded. Our terms require it and we may ask a customer to demonstrate it.
A parent or guardian who wants to know what is held about their child, or wants it removed, should contact the club or academy first; if you contact us we will pass it on immediately and help them act.
13Changes to this policy
We will update this policy as SQR changes. For a change that materially affects how we handle your data we will give you notice before it takes effect — by email where we have your address, and by notice in the Service — and where the law requires fresh consent we will ask for it rather than assume it. The date at the top always shows when it last changed.
14Contact
Data controller: CaptainX Company, Kingdom of Saudi Arabia.
Privacy, data protection and any request under section 10: info@captainx.ai. That address reaches the person at CaptainX responsible for data protection, and we will tell you who has taken your request.
Our commercial registration details are provided on request, and on any contract or invoice we issue.
Supervisory authority: Saudi Data and Artificial Intelligence Authority (SDAIA), Kingdom of Saudi Arabia.
