How Titan Account handles your data
Version 2026-09-12 · Last updated 12 September 2026
This policy explains what Titan Software z.s. collects and processes when you use Titan Account, the identity service at auth.titansoftware.eu.
The controller is Titan Software z.s., zapsaný spolek (registered association), Czech Republic. Registered seat: Ametystová 702/46, 153 00 Praha, Česká republika. IČO: 29738725. For privacy questions and to exercise your rights, contact [email protected]. We have not appointed a Data Protection Officer [OWNER INPUT REQUIRED — confirm].
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address, username, profile image, locale, timezone | Creating and running your account; identifying you to applications you authorize | Performance of a contract (Art. 6(1)(b)) |
| Password hash (Argon2id), passkey credentials, TOTP secret and backup codes (encrypted) | Authenticating you and protecting the account | Contract; legitimate interest in account security (Art. 6(1)(f)) |
| Sessions: IP address, summarised browser/OS, timestamps | Keeping you signed in; showing your active devices; detecting sign-ins from new devices | Contract; legitimate interest in security |
| Security events: sign-in, password and two-factor changes, passkey changes, data export, deletion requests — with IP address and summarised browser/OS | Letting you review account activity; investigating abuse and compromise | Legitimate interest in platform security |
| Acceptance of these documents: timestamp and version | Evidencing which terms your account was created under | Legal obligation / legitimate interest in accountability |
| Onboarding interests — which kinds of work you told us you do (for example “I run a FiveM server”) | Deciding which Titan products to suggest to you, instead of showing all of them | Legitimate interest in a usable product; clear them at any time |
| Conversion source — which Titan product you came from when starting a subscription | Understanding which products lead people to subscribe. A coarse product name, not a tracking identifier | Legitimate interest in measuring our own funnel |
| Organization membership, roles and invitations | Managing team access to Titan applications | Contract |
| OAuth consents and tokens issued to applications you authorize | Single sign-on to Titan applications | Contract |
| Discord account identifier and provider tokens, if you link Discord (stored encrypted) | Signing in with Discord | Contract (you chose this sign-in method) |
| Billing: Stripe customer and subscription identifiers, plan, status, period dates, invoice amounts and payment outcomes for organizations you administer | Taking payment, granting paid features, keeping accounting records | Contract; legal obligation for accounting records |
| Record of transactional email we sent you (recipient, subject, delivery status) | Delivering verification, password-reset and security messages, and retrying failures | Contract; legitimate interest in reliable delivery |
| Administrative audit entries when Titan staff act on an account | Accountability for administrative action | Legitimate interest in accountability |
We do not use advertising, profiling for marketing, or analytics or tracking cookies on this service. We do not sell personal data. We do not knowingly collect data from children under 16.
The interests you pick during onboarding are used for one thing: choosing which products to recommend. Nothing is inferred from your behaviour, no score is built, and the selection is never shared with the individual products. Skipping onboarding, or unticking everything, removes it.
Rate limiting and abuse controls may temporarily block a sign-in attempt or a request from an IP address. Two-factor lockout may temporarily block verification after repeated failures. These are automated but time-limited and do not by themselves terminate an account; account suspension is decided by a person. We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR on this service.
Titan Account sets only what is strictly necessary to sign you in and keep the service secure: a session cookie, cookies used during OAuth sign-in, and a preference for light or dark theme stored in your browser. These are exempt from consent under the ePrivacy rules, so there is no cookie banner. We set no analytics, advertising or tracking technologies.
These providers act as our processors under a data processing agreement, except Discord, which is an independent controller for your Discord account.
Some of these providers are established outside the European Economic Area or may process data there. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with additional safeguards where required. The specific mechanism for each provider is confirmed in our processor agreements. [OWNER INPUT REQUIRED — confirm the transfer mechanism relied on for each provider]
Your account data is kept while your account exists. Other categories are deleted automatically once they reach the periods below:
| Category | Retention |
|---|---|
| Security events (sign-ins, password and MFA changes) | 180 days |
| Administrative audit entries | 730 days |
| Billing and subscription events | 730 days |
| Record of transactional email sent to you | 30 days |
| Completed change-of-address requests | 180 days |
| Expired sessions | 7 days |
| Unaccepted organization invitations | 30 days |
Expired sessions, verification links and OAuth tokens are cleared shortly after they expire. Invoices and accounting records are kept for the period Czech accounting and tax law requires. Backups are retained on a rolling schedule and overwritten in turn; data deleted from the live system disappears from backups as they roll over.
You can delete your account from Settings → Security. We email a confirmation link; once you open it we erase your profile, credentials, passkeys, two-factor secrets, sessions, linked accounts, organization memberships and invitations, application consents and issued tokens, your security event history and organizations of which you were the only member.
Two things survive, and we think you should know which: records we are legally required to keep, such as invoices and accounting data for paid subscriptions; and administrative audit entries recording actions taken on other accounts, from which your identity is removed. Deletion of your Titan Account does not automatically delete data held by connected Titan applications you used — contact that service, or us, to have it removed.
Under the GDPR you have the right to:
We answer within one month. You may also lodge a complaint with the Czech data protection authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), whose address is Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, or with the authority where you live.
Passwords are hashed with Argon2id. Two-factor secrets, backup codes and provider access tokens are encrypted at rest. OAuth client secrets and issued tokens are stored hashed. Traffic is encrypted with TLS. We apply rate limiting, log security-relevant events, and restrict administrative access. No system is perfectly secure; if a breach affects your personal data and is likely to result in a high risk to you, we will notify you.
Titan Account is provided as a beta version. That does not change any of the obligations described here or reduce your rights.
We may update this policy. The version and date at the top change when we do, and we record which version your account accepted. We will notify you of material changes.
© 2026 Titan Software z.s.