Privacy Policy

Ektimal Sports Company ("Pure Gym") is committed to protecting the personal information of its members ("Information") in accordance with the applicable regulations in the Kingdom of Saudi Arabia, to the extent that enables it to provide its services while fulfilling its legal responsibilities towards its Members.

This Privacy Policy outlines the following: • The type of personal data required from Members. • How the data is used by Ektimal Sports Company team. • Member rights.

This Privacy Policy applies to personal data related to members and relevant parties that may be processed when submitting a subscription request via the website or mobile application. It also applies when participating in any marketing events with Ektimal Sports Company, or when contacting a member service representative, whether the information was provided directly by the members or collected from other sources, in accordance with the Personal Data Protection Law in the Kingdom of Saudi Arabia, relevant regulations, governing provisions, or based on authorization from the Member, their consent, or the consent of related parties.

Definitions: • Company: Ektimal Sports Company. • Member(s): Sports club members. • Law: Personal Data Protection Law. • Regulations: Implementing regulations of the Law. • Competent Authority: The authority designated by a resolution of the Council of Ministers. • Personal Data: Any information—regardless of its source or format—that leads to the identification of an individual or makes identification possible, whether directly or indirectly. This includes names, personal identification numbers, addresses, contact numbers, license numbers, records, personal properties, bank account numbers, credit cards, static or moving images of the individual, and other personally identifiable information. • Processing: Any operation carried out on personal data by any means, manual or automated, including collection, registration, saving, indexing, organizing, structuring, storing, modifying, updating, merging, retrieving, using, disclosing, transferring, publishing, sharing data, linking, blocking, erasing, and destruction. • Disclosure: Enabling any person—other than the controller—to access, use, or view personal data by any means for any purpose. • Transfer: The act of transferring personal data from one location to another for processing purposes. • Publishing: Disseminating any personal data through any readable, audible, or visible medium, or making it accessible. • Personal Data Subject: The individual to whom the personal data relates, their representative, or their legal guardian. • Public Authority: Any ministry, public department, public institution, or public agency in the Kingdom, or any independent public authority, or any affiliated bodies. • Controller: Any public authority or private entity, either natural or legal, that determines the purpose and means of processing personal data, whether it processes the data itself or assigns the processing to a processor. • Processor: Any public authority or private entity, either natural or legal, that processes personal data on behalf of the controller. • Collection: The act of the controller obtaining personal data in accordance with the provisions of the Law, either directly from the data subject, their representative, their legal guardian, or a third party. • Destruction: Any action that leads to the removal of personal data, making it impossible to access or retrieve again. • Related Parties: The guardian of a member who is under the legal age.

Method of Collecting Personal Information:

  1. Personal data is collected to provide sports club membership services to the member and to continuously improve these services.

  2. The data is used to communicate with the Member or relevant parties, understand their needs, and enhance the relationship with them.

  3. Personal data is obtained either from the Member or related parties, or in accordance with regulations or by their authorization.

  4. Personal data may be collected in paper or electronic format, or through any other means.

  5. When visiting the company’s website or using its mobile application, data about the device or browser used (such as IP address, operating system, browser version) and browsing behavior may be collected. Cookies and similar technologies are used to gather this data, and Members can disable cookies by adjusting their settings, as outlined in this policy.

  6. Technical data that does not identify an individual will not be treated as personal data. However, if such data can identify an individual on its own or when combined with other data, it will be protected as personal data.

  7. Ektimal Sports Company reserves the right to refuse membership services if the Member or related parties refuse to consent to the collection of personal data, or if the data provided is inaccurate or incorrect. The Member has the right to provide personal data themselves or allow its collection by a third party with their consent.

  8. Members may be invited to subscribe to updates and alerts, participate in marketing events or surveys. Upon acceptance, personal data such as name, residency number, phone number, and email address will be collected. Refusal to provide this data will not affect their use of the website or applications.

Personal Data Collection, Usage, Protection, and Reasons for Collection:

Personal data is collected to provide membership services to the sports club for the Member and continuously improve the Member experience. The purposes include using the data to communicate with the Member or related parties, understand their needs, enhance and maintain the relationship, and develop it further. This data is obtained either from the Member, their related parties, in accordance with regulations, or by their authorization. Additionally, data can be collected and verified through other sources such as partners or third parties (including credit reference agencies, service providers, or relevant entities).

Personal data of customers is collected indirectly through cookies, which are gathered when visiting the website.

Personal Data That May Be Collected:

• Personal Information: Name, gender, nationality, national ID/residency number, mobile number, email address, signature, contact details, date of birth, place of birth, require disabled access (Yes/No), permanent, and residence addresses.

• Health Information: General health status.

• Banking Information: Card number, Cardholder number, CVV, and expiry date.

• Subscription Data: Details of the sports club membership, including session schedules, sports activities, and payments.

• Other Information: o Personal data provided by the Member when submitting feedback, suggestions, or complaints, and data entered when participating in campaigns or surveys. This data is used to analyze Member experience and communicate with them to provide relevant services or products.

o Any other personal data necessary to provide sports club services. This data will be clearly identified, and consent will be obtained before collection, either electronically or through paper means.

The above list might be updated from time to time.

Use of Personal Data: When visiting or browsing the company’s website or using its applications, personal data of members may be used for the following purposes:

  1. Responding to inquiries and requests.
  2. Providing information about requested products or services, or those that may be of interest, provided prior consent is obtained.
  3. Allowing interaction with the website or applications.
  4. Notifying members of changes to the website or applications.
  5. Ensuring content is displayed effectively on the devices used.
  6. Maintaining the proper and secure operation of the website and applications, including preventing and controlling risks or detecting misuse.
  7. Complying with applicable laws and regulations.
  8. Conducting statistics and analysis of service usage, without including personal data in these statistics.

If the member is a current or potential Member, their personal data may be used for the following purposes:

  1. Providing products or services and verifying the identity of the member or relevant parties.
  2. Complying with legal or regulatory requirements.
  3. Enforcing the company's legal and regulatory obligations.
  4. Defending the company's rights or fulfilling imposed obligations.
  5. Achieving the company’s operational goals, including data analysis, research and development, and service improvements.
  6. Marketing products or services based on authorization, or conducting market research and satisfaction surveys.
  7. Obtaining necessary administrative, consulting, or technological services to operate activities.

The collection and use of data, as described in this policy, will not affect previously agreed-upon uses between the company or the club and the member. In the event that personal data is used for additional purposes beyond those specified, prior consent will be obtained.

Protection of Personal Data: The security of personal data is a top priority for Ektimal Sports Company, as the company is committed to protecting personal data from unauthorized or accidental access, processing, damage, or disclosure.

This commitment is achieved through the implementation of appropriate physical, electronic, and administrative measures to ensure the protection of personal data. In the event of unauthorized access, public disclosure, deletion, or damage of data due to an error attributable to the company, it will bear legal responsibility for any damages affecting the rights and interests of its members.

The company adheres to a strict security system to prevent unauthorized access to personal data, including the strict management of employees who may have access to such data. This includes enforcing access control policies based on contractual confidentiality obligations for relevant employees, drafting and implementing policies and procedures related to data security, and providing continuous training in this field.

Personal data will not be disclosed to any third party except in cases of legal or regulatory necessity or based on prior consent from the member. When using the services of external providers, the company imposes strict confidentiality obligations on them and requires compliance with security standards as outlined in the Personal Data Protection Law of Saudi Arabia.

Member Responsibility for Protecting Personal Data: Members also bear responsibility for protecting their personal data, including account information and identity verification details, and ensuring that this data is used in a secure environment. Members should not disclose this information to anyone else, and if they believe their data has been disclosed, lost, or stolen, they should notify the company immediately so that appropriate measures can be taken to prevent further loss.

Additionally, regular training sessions are organized for employees to respond to data-related emergencies. In the event of a personal data security incident, an emergency response plan will be executed, and necessary steps will be taken to minimize potential damage. The company will also notify the relevant regulatory authorities with details of the incident, its impact, and the actions taken to mitigate future risks.

Reasons for Collecting Personal Data: The aforementioned data is collected to provide sports club services and fulfill contractual obligations with the Member, as well as to ensure compliance with legal and regulatory requirements.

Processing and Transferring Personal Data: For the purposes outlined in the privacy policy of Ektimal Sports Company, all or part of the members' personal data may be provided or disclosed to the entities listed below, with appropriate protective measures in place. These entities may have the right to use, process, or disclose the personal data they receive, provided that similar protection measures are adopted in accordance with applicable laws or company requirements:

• Employees of Ektimal Sports Company. • Any regulatory body specific to Ektimal Sports Company. • Governmental bodies or any authority affiliated with them, or any organization appointed by governmental authorities. • Any professional advisor, business partner, product or service provider from a third party (including their employees, directors, and officers).

In accordance with applicable laws and regulations, the company will seek the members' consent and inform them of the sharing or transfer of their data, including the identity of the data recipient, contact details, the purpose of processing, the method of processing, and the type of personal data.

(a) Affiliates: The company may share personal data about members with affiliates for legal and regulatory purposes, to manage business risks, and to ensure that personal data is accurate and up to date, such as addresses and birthdates. Member data may also be shared to improve relationship management and enable affiliates to offer appropriate products and services. The company will share personal data with affiliates for these purposes unless prohibited by law or otherwise notified to members.

(b) Business Partners: In cases where the company collaborates with other companies to offer products or services to members, it may disclose personal and/or non-personal or anonymized data collected about members to these third-party partners to provide those services.

(c) Sharing Personal Data Where Ownership or Responsibility is Shared with Third Parties: In the case of a product or service where ownership or responsibility is shared with third parties, the company may share members’ personal data related to that service or product. Additionally, after obtaining the members’ consent, personal data may be shared with their legal representatives, accountants, or designated third parties.

(d) Government Authorities and Law Enforcement: For other purposes permitted by law, the company reserves the right to disclose personal data to third parties as deemed appropriate to comply with legal processes and/or respond to government or regulatory requests or for any other purpose allowed by applicable law.

Transferring Personal Data: No personal data will be transferred to any company, organization, or individual without the members’ prior consent.

Disclosure of Personal Data: Ektimal Sports Company will not disclose members’ personal data publicly without obtaining prior written consent from the members.

Special Circumstances for Processing Personal Data: The company will process members' personal data (including collection, storage, usage, analysis, transfer, and disclosure) based on their consent (to the extent permitted by laws and regulations). However, personal data may be processed without members' consent in the following cases: • When necessary to protect members' vital interests in emergencies or to respond to public health emergencies. • When processing serves the actual interest of the data subject, and it is impossible or difficult to contact them. • Other circumstances as stipulated by laws and regulations.

Under no circumstances will Ektimal Sports Company bear any responsibility for any loss or damage, including, but not limited to, indirect or consequential loss or damage, or any loss or damage arising from data loss or profits resulting from the use of this website.

Members may connect to other websites through this website, which are not under the control of Ektimal Sports Company. The company cannot control the nature, content, or availability of those sites. Therefore, the inclusion of any links does not necessarily imply endorsement of those sites, or the opinions expressed therein.

However, Ektimal Sports Company assumes no responsibility or liability for the temporary unavailability of the website due to technical issues beyond its control.

Legal Basis for Data Processing:

Ektimal Sports Company will process personal data only if there is a legal basis for doing so. This includes, but is not limited to, the necessity of contract performance, compliance with legal obligations, protection of legitimate interests, obtaining necessary consents, or pursuing its legitimate interests or those of third parties, in accordance with applicable laws and regulations.

Members' Rights Regarding Their Personal Data:

Ektimal Sports Company strives to provide high-quality services to all users while ensuring their rights in accordance with the Personal Data Protection Law and other relevant regulations. This includes the following rights:

• Right to be Informed: Users have the right to be informed about the collection and use of their data, including the reasons for data collection, how the data is collected, purposes of processing, retention periods, parties with whom the data will be shared, and the security measures taken to protect this personal data and their associated rights.

• Right of Access: Users have the right to access their personal data held by Ektimal Sports Company and to obtain a copy or transfer it to another party. Exceptions to this right include: o If the restriction is necessary to protect the data subjects. o If the restriction is necessary for security purposes, enforcement of another law, or to meet judicial requirements. o If access could lead to:

  1. A threat to national security, harm to the reputation of Saudi Arabia, or conflict with its interests.
  2. Impacting Saudi Arabia's relations with other countries.
  3. Preventing the disclosure of a crime or affecting the rights of the accused or the integrity of ongoing criminal proceedings.
  4. Endangering the safety of individuals.
  5. Violating the privacy of another individual who is not the owner.
  6. Conflict with the interests of a person who is entirely or partially lacking legal capacity.

• Right to Rectification: Users have the right to request correction, completion, or updating of their personal data.

• Right to Erasure: Users have the right to request the deletion of their personal data in the following circumstances: o When the company deems that it no longer needs the data for the purposes for which it was collected. o If the user has legitimately objected to the use of their personal data. o If the company is processing the user's personal data in violation of the law or other legal obligations. o If the user has withdrawn their consent for the collection and processing of their personal data.

• Right to Object: Users have the right to object to the processing of their personal data at any time, but this right applies only under specific circumstances, such as when their personal data is processed for direct marketing purposes.

• Right to Withdraw Consent: Users have the right to withdraw their consent to the collection and processing of their personal data, unless legal or judicial requirements dictate otherwise.

Cookie Usage and Other Technologies: Ektimal Sports Company may access data stored in cookies. When visiting, browsing, or using any of its websites or mobile applications, such activities may be recorded to analyze visitor numbers, routine usage patterns, and personalized usage patterns aimed at improving the user experience. Some of this data is collected using cookies.

The data collected through cookies is aggregated and anonymized and does not contain any personal information.

Users can manage or disable cookies according to their preferences. If they wish to disable cookies, they can change the settings on their local devices. However, changing settings may result in the loss of some features provided by cookies, but the normal use of other functions on devices will not be affected.

Review of the Privacy Policy: Ektimal Sports Company complies with applicable laws and regulations regarding data storage. When collecting or processing personal data, the company is committed to storing that data in accordance with the law, applicable regulations, and regulatory requirements, as well as for the purposes outlined in this notice, and for archiving, accounting, auditing, or reporting purposes. Personal data will be stored for the minimum period necessary to achieve the purposes for which it was collected.

The personal data collected via the website or mobile applications is stored on the company’s servers within Saudi Arabia, protected by appropriate security technologies to ensure data integrity. After the retention period has ended, the company will erase, delete, or anonymize the relevant personal data. If this is not feasible, the data will be securely stored and separated from other processing operations.

These procedures do not apply to data that must be retained in accordance with applicable laws and regulations or regulatory requirements, or for archiving, accounting, auditing, or reporting purposes, or any specific agreement between the company and the concerned parties.

The company may need to retain personal data after the purpose of its collection has ended in the following cases: • If there is a legal justification requiring retention for a specified period according to the law or regulations, or for security reasons. • If the data is related to an ongoing legal case that requires retention for that purpose. • If all personal elements of the data have been anonymized.

The privacy policy of Ektimal Sports Company may be amended from time to time. Therefore, it is advisable to regularly review the privacy notice to ensure you are aware of the latest version. Continued submission of personal data or use of services by members after any changes to this notice constitutes acceptance of these changes.

Contact with the Ektimal Sports Company Team: For any inquiries, members can contact the Ektimal Sports Company team at:

• Email: [email protected] • WhatsApp: +966 59 954 8737