Effective: 10 August 2026·Last updated: 10 August 2026·Version: 1.0
This Privacy Policy explains how Titan Software z.s. (“Titan”, “we”, “us”) processes personal data and related technical information when you use our websites, Titan Auth, Titan Security and other Titan Software services.
Titan Software z.s. · IČO 29738725
1. Who we are
Controller: Titan Software z.s., Ametystová 702/46, 153 00 Praha 16, Czech Republic. Registration No. (IČO): 29738725. Contact: [email protected].
We are a Czech registered association. We design processing around data minimization, purpose limitation, access control, limited retention and transparency.
2. Scope
This Policy covers websites operated under titansoftware.eu, Titan Auth, Titan Security and other Titan applications that link to this Policy, unless a service publishes a more specific notice.
Third-party services (for example Discord or GitHub) process data under their own policies when you interact with them directly.
3. Data we process
Account and identity data
Where you use Titan Auth or a connected service, we may process account identifiers and profile information such as a Titan subject/account ID, username or display name, email address, avatar or profile fields, and identifiers from linked identity providers when you choose to connect them. Exact fields depend on the authentication methods actually enabled.
Technical and security data
We may process IP addresses, timestamps, user agents, request identifiers, authentication and security events, rate-limit information and audit or security logs. These support authentication, security, abuse prevention, debugging, fraud prevention and infrastructure protection.
Security report data
If you submit a report, we may process descriptions, uploaded files or archives, logs, indicators, URLs, hashes, evidence, contact details and attribution preferences. Please avoid submitting unnecessary personal information about yourself or others.
Security intelligence data
We may process technical indicators such as file hashes, domains, URLs, IP addresses, resource names, repository references and detection metadata. Some intelligence may be published after review where appropriate. Raw private evidence from reports is not automatically made public.
Community data
Where community features exist, we may process contribution history and, if you opt in, public researcher profile elements such as display name, badges or linked GitHub/Discord profiles.
Website and contact data
If you use the contact form, we process the name, email, subject and message you submit in order to respond.
4. How we use data
We process data to:
- Operate and improve services you request.
- Authenticate users and manage sessions via Titan Auth.
- Handle security reports and threat intelligence workflows.
- Protect infrastructure and prevent abuse.
- Debug failures and maintain audit trails.
- Send important service or security notices.
- Publish user-approved contributions or attribution where designed.
We do not use personal data for advertising profiling.
5. Titan Auth and connected services
Titan Auth provides centralized identity for the Titan ecosystem. Applications such as Titan Security may receive identity information from Titan Auth to authenticate you and authorize access. Applications do not necessarily store all identity-provider data independently.
Conceptual model: Titan Auth holds central Titan identity → connected services maintain service-specific profiles and authorization as needed.
6. Security reports and threat intelligence
Private reports and evidence are processed for analysis, triage, detection engineering and operational security. Published threat intelligence is a separate category: after human review, technical indicators and research summaries may be shared publicly or with partners as appropriate.
Where coordination with an affected developer or vendor is necessary, we share only what is needed. Reporter identity is not shared without necessity or your permission where feasible.
9. Retention
We retain data only as long as needed for the purposes described, including:
- Account data while the account or service relationship exists and for a limited period afterward as needed.
- Security and audit logs for security and operational purposes.
- Threat intelligence and technical indicators for longer periods where historical context remains relevant to protection.
- Malicious samples where justified for detection and research.
We aim to minimize or remove unnecessary personal information. Exact retention periods may be refined as operational policies mature.
10. Security
We apply reasonable technical and organizational measures, which may include access controls, authentication, encryption in transit, restricted access to sensitive evidence, audit logging and infrastructure monitoring.
No method of transmission or storage is completely secure. We do not claim absolute security or end-to-end encryption for all data categories.
11. Your rights
Where the GDPR or other applicable law applies, you may have rights to access, rectification, erasure, restriction, objection, portability (where applicable) and withdrawal of consent where processing is based on consent.
To exercise rights, contact [email protected]. We may need to verify your request. Some data may be retained where required for security, legal obligations or legitimate interests that override the request in the specific case.
You may also lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
12. Legal bases
Depending on the context, processing may rely on:
- Performance of a contract or steps prior to a contract (providing requested services and accounts).
- Legitimate interests in operating, securing and improving systems and preventing abuse, balanced against your rights.
- Compliance with legal obligations.
- Consent where we specifically ask for it (for example optional features).
This section is structured for EU/GDPR expectations and may be refined after legal review. It is not a certification claim.
13. International processing
Infrastructure and processors may process data in the European Economic Area and, in some cases, outside it. Where required, we use appropriate safeguards for international transfers as available under applicable law.
14. Children and capacity
Users must have legal capacity to use the services, or appropriate guardian authorization where required by applicable law or service rules. We do not knowingly target children with these services. If you believe a child has provided personal data inappropriately, contact us so we can review and delete it where required.
15. Changes
We may update this Privacy Policy. The effective and last-updated dates appear at the top of this page. Material changes may be communicated through appropriate channels where practicable.
16. Contact
Privacy questions and data-subject requests: [email protected]. Security-related contact: [email protected]. You may also use the contact form on this website.