2026-09-07

 Privacy Policy

Privacy and Personal Data Protection Policy

MyTable Platform — MYT Global Company

Version 1.1 — Effective Date: 27 August 2026

This Policy is addressed to users and visitors of the MyTable platform, booking guests, representatives of establishments, partners, content creators and persons who communicate with us through the platform's channels. It explains in clear language what Personal Data we collect, why we collect it, how we process and protect it, with whom we disclose it, how long we retain it, and the rights available to you under the laws applicable in the Kingdom of Saudi Arabia.

This Policy does not constitute general or open-ended consent to all processing activities. Where the law requires separate or explicit consent—such as for the processing of Sensitive Data, direct marketing, access to precise location or contacts, the operation of non-essential technologies, or a decision based solely on automated processing in cases governed by law—we request that consent separately, in a manner that can be demonstrated and withdrawn.

1. Who We Are

MYT Global Company is a Saudi limited liability company, registered in the Kingdom of Saudi Arabia under Unified National Number 7054723072, with its head office in Riyadh, Kingdom of Saudi Arabia. The company owns and operates the MyTable platform and brand. In this Policy, it is referred to as “MYT Global,” “MyTable,” “we,” “us” or “our,” as the context requires.

MYT Global is the Personal Data Controller where it determines the purposes and means of processing Personal Data to operate MyTable. This includes accounts; search, booking, ordering and payment interfaces; waitlists; any wallet, balance or rewards features when activated; social content; support; security; analytics; and marketing managed by MYT Global.

MYT Global's Data Protection Officer is the designated contact for this Policy and requests concerning Data Subject rights. The officer may be contacted at privacy@mytable.sa or on the unified number 920032786. If those channels are unavailable, you may also use the support channels within the application or the MyTable website.

2. Scope of this Policy and the Roles of Other Parties

This Policy applies to the MyTable website, applications, application programming interfaces, embedded pages within partner applications or websites, and features and services that refer to this Policy, whether accessed directly or through an integration partner.

This Policy covers features currently available and any future feature that processes your Personal Data only when that feature is activated and made available to you or when you choose to use it. Mentioning a category of data or a feature in this Policy does not mean that we collect it from every user or at all times.

We may provide a short-form notice within a particular screen or feature before collecting data, such as at a payment screen, a location permission request, contact synchronisation or a healthcare appointment. That notice supplements this Policy and explains details specific to the feature; it may not diminish any right or protection stated here.

A restaurant, hotel, event, entertainment, tourism, beauty and wellness, sport, retail or healthcare provider, or any other establishment (a “Service Provider”), may act as an independent Controller in relation to Personal Data it uses to provide its service, manage its establishment, comply with its legal obligations, or communicate with you outside MYT Global's instructions. That independent use is governed by the Service Provider's own privacy notice.

A channel partner or application through which you initiated a transaction may act as an independent Controller for your account data and use of that application. We may exchange with it the minimum data necessary to complete or support the transaction. The relevant agreements and notices determine each party's role. We do not place responsibility on users to understand the parties' internal arrangements; we identify the relevant party to the extent needed for the user to make a clear decision.

Where MYT Global processes Personal Data exclusively under another party's documented instructions, it acts as a Processor within the scope of those instructions. The party that determines the purposes and means remains responsible for notifying Data Subjects and establishing the lawful basis for processing, as required by law.

This Policy does not apply to processing MYT Global employee data in the context of current employment, or to processing by a third party that MYT Global neither controls nor acts for. Employees or other categories of persons may receive a separate privacy notice appropriate to the nature of that processing.

3. Categories of Data Subjects

Depending on the service used, we process Personal Data relating to an unregistered visitor, account holder, person making a booking, order or payment, guest added to a booking, recipient of an invitation or gift, user of social features, content creator, representative of a Service Provider or partner, applicant through a business or recruitment form, and any person who contacts support, submits a complaint or exercises a right relating to their Personal Data.

If you provide us with another person's data, you must be legally authorised to provide it, limit it to what is necessary for the purpose, and inform that person of this Policy where required. You must not enter Sensitive Data or data relating to a minor or a person lacking or having limited legal capacity without a valid lawful basis.

4. Personal Data We Collect

We collect the minimum data directly connected with the relevant purpose. The categories actually collected vary according to the feature, sector, Service Provider and access channel.

4.1 Account, Identity and Contact Data

This may include your name, display name, telephone number, email address, password in protected form, account identifier, profile photograph, language, city, date of birth or age range where eligibility must be established, communication preferences, verification methods and account status. We do not request a copy or image of an official identity document unless required by a competent public authority, to comply with law, or for a regulated service that requires verification, and only after informing you of the reason.

4.2 Booking, Order and Service Data

This may include the Service Provider, branch or location; service type; date and time; number of persons; guest names or necessary contact details; booking or waitlist status; table, room, appointment or ticket details; special requests; amendments, cancellations and no-shows; visit history; operational notes; preferences you choose to save; and confirmation that the service was used.

4.3 Transaction and Payment Data

This may include amounts, fees, taxes, deposits or advance payments, discounts, balances or rewards, payment method, payment provider name, a reference number or secure token for the payment method, card type and last digits where made available to us, and the status of authorisation, collection, settlement, refund, dispute or chargeback.

Where card processing is performed directly by a licensed payment provider, MYT Global does not receive or store full card data or the card verification value (CVV). The payment provider may retain the data it requires in accordance with its terms, applicable laws and privacy notice.

4.4 Location and Permission Data

This may include the city or region inferred from an internet address, approximate location, precise geolocation when you choose to enable it, a check-in point, the nearest branch and related device permissions. We do not collect precise location in the background unless a clearly identified feature requires it, after displaying an appropriate notice and obtaining the required consent or permission. It can be disabled through the application or device settings.

4.5 Device and Usage Data

This may include the Internet Protocol address; device, application and session identifiers; operating system; browser type; application version; language and time zone; network operator; crash and performance data; login and security logs; pages, screens and results with which you interact; referral source; usage times; and an advertising identifier where permitted by your settings.

4.6 Social Content and Interaction Data

When you use social features, we may process your display name, photograph, posts, stories, live streams, images, video and audio clips, comments, likes, follows, ratings, check-ins, messages and attachments, your selected audience, content reports and moderation actions. An image or voice recording is not Sensitive Biometric Data unless it is technically processed for the purpose of uniquely identifying a person.

4.7 Guest, Contact and Invitation Data

We may process the name, telephone number or email address of a person you add to a booking, invitation, group or gift. If an optional feature offers contact synchronisation, we request separate permission and use only the minimum data required for matching, invitations or finding people you know. Contact data may not be used for an undisclosed purpose without a new lawful basis.

4.8 Preference Data and Sensitive Data

You may choose to provide information about allergies, dietary or health restrictions, accessibility needs, or notes connected with a healthcare appointment or wellness service. Certain free-form requests, content or messages may reveal other Sensitive Data. We request such data only when necessary for a specified feature or service, process it on the basis of explicit consent where consent is the lawful basis, or rely on another lawful basis that permits the processing, and limit disclosure to the Service Provider or other party that needs it for the stated purpose.

Please do not enter health or other Sensitive Data in a public field, post or message when the service does not require it. If you choose to publish such data publicly, it may be viewed by the audience selected in your publication settings, and we cannot control copying or onward sharing by others outside the platform.

4.9 Support, Complaint and Security Data

This may include the content of communications, calls recorded after notice to you, attachments, identity-verification data necessary to protect the request, the record of complaint handling, fraud or misuse indicators, login-attempt logs, network addresses, investigation findings and account-protection measures.

4.10 Loyalty, Rewards and Content Creator Data

If these programmes are activated, we may process a referral or campaign identifier, points or balances, rewards accrued or redeemed, attributed bookings, eligibility status, remittance or invoice data where needed for payment, indicators of manipulation or fictitious bookings, and commercial disclosures associated with paid content.

4.11 Inferred Data

We may infer from your use categories or preferences such as preferred sectors, locations or visit times, the likelihood that an offer may interest you, or an unusual usage pattern for security purposes. We do not use inferences to establish a sensitive fact about you, nor do we use them to make a decision based solely on automated processing that produces a legal or similarly significant effect, except in accordance with the safeguards described in this Policy.

5. Mandatory and Optional Data

Data identified as required in the service interface, or necessary to create and verify an account, complete a booking, order, payment or refund, or comply with law, is mandatory for the specified purpose. We may be unable to provide the feature or complete the transaction if you do not provide it.

A profile photograph, social content, precise location, contact synchronisation, saved preferences, marketing communications, non-essential cookies and most special requests are generally optional data or choices. Refusing them does not disable the core service, but may prevent the specific feature that directly depends on them.

We do not make consent to an optional purpose a condition of a service that is not closely connected with that purpose. Before or at the time of collection, the interface indicates whether a field is mandatory or optional and the practical effect of not providing it where that effect is not clear from context.

6. How We Collect Data and Its Sources

We collect data directly from you when you create an account, complete a form, conduct a search, make a booking, order or payment, join a waitlist, publish content, send a message, select a permission, join a programme or contact support.

We collect certain data automatically from your device and use through system logs, cookies, software development kits and measurement and security technologies, in accordance with your choices, settings and any required consent.

We may obtain data from a Service Provider, integration or channel partner, payment provider or bank, verification or security provider, a user who added you to a booking or invitation, or a lawfully available public source. If we obtain your data other than directly from you, we will—where legally required—inform you of its categories, source and the required information within no more than thirty days after receipt, subject to applicable legal exceptions.

7. Purposes of Processing and Lawful Bases

We do not process data merely because it may be useful in the future. We identify a clear purpose and lawful basis for each activity. Different lawful bases may apply to different operations within the same service.

7.1 Performance of a Contract or Steps Requested by You

We process account, contact, booking, order, payment and support data to register you and verify your account, display options, create and amend a transaction, send confirmations and updates, enable the Service Provider to perform, process payments and refunds, manage balances or rewards when activated, and enable content and messaging features you choose to use. The lawful basis is the performance of an agreement to which you are party or taking steps at your request before entering into it.

7.2 Compliance with Legal Obligations

We process the minimum data necessary to issue invoices and retain financial and tax records, respond to orders from competent authorities and judicial requirements, administer Data Subject rights, report Personal Data breaches where the reporting threshold is met, and comply with any obligation imposed by laws applicable to the activity or Service Provider.

7.3 Legitimate Interests

We may process data necessary to protect accounts and the platform; prevent fraud and misuse; secure networks; measure service performance and correct faults; manage relationships with Service Providers and vendors; establish transactions or claims; and improve result ranking and the core user experience. We rely on legitimate interests only after identifying the need, balancing it against your rights and reasonable expectations, and applying measures to reduce the impact. We do not use this basis to process Sensitive Data where prohibited by law.

7.4 Consent

We rely on your separate consent where a purpose requires a free choice, including direct marketing; sharing data with an independent party for its own marketing; precise or background location; contact synchronisation; Sensitive Data where consent is the lawful basis; non-essential cookies, analytics or advertising; or a decision based solely on automated processing in cases requiring explicit consent.

We document the time, method and specified purpose of consent, and provide a means of withdrawal that is as easy as, or easier than, the method used to give it. Withdrawal does not affect the lawfulness of prior processing or processing based on another lawful basis.

7.5 Clear or Vital Interests

In limited circumstances, we may process the minimum data necessary to achieve a clear interest for you where contacting you is impossible or difficult, or to protect a person's life or safety in an emergency. We do so in accordance with applicable legal safeguards and do not extend the use beyond the necessary purpose.

7.6 Analytics, Research and Statistics

We use aggregated or anonymised data wherever possible to understand performance and demand, improve the service and prepare statistics. Where a person can no longer reasonably be identified after anonymisation in accordance with applicable controls, the resulting information is not Personal Data. Pseudonymised data that can be re-linked remains Personal Data and receives the same protection.

8. Processing Sensitive Data

Health or other Sensitive Data may arise in wellness, healthcare, hospitality and special-request services. We request it only where necessary to deliver a clearly identified service, on the basis of explicit consent or another lawful basis permitting the processing, and state whether providing it is mandatory or optional.

Where consent is the lawful basis, we request separate, explicit consent and do not incorporate it into general acceptance of terms. Access within MYT Global and the Service Provider is restricted to persons who need it. The data is not used for marketing, advertising-audience building or unauthorised health inferences.

MYT Global does not copy an official identity document unless requested by a competent public authority or required to comply with law. If a regulated service requires document verification, we identify the party collecting the document, the purpose and the retention period before collection.

9. Personalisation, Ranking and Automated Processing

MyTable may use automated rules or models to rank search results, suggest Service Providers or offers, personalise content according to city, preferences and interaction, detect unusual behaviour or fraud, and determine temporary technical eligibility for a feature or transaction.

We do not make a decision based solely on automated processing that produces a legal or similarly significant effect on you—such as final denial of an essential service or a binding financial arrangement—unless permitted by law, after providing the required information and obtaining explicit consent where required. We provide human review or a means to object where required by law.

The ranking or suggestion of a result does not mean that MYT Global certifies the Service Provider's quality or has made a sensitive decision about you. Results may be affected by availability, location, relevance, preferences, performance and paid content that is clearly identified.

10. How We Disclose and Share Data

We do not sell your Personal Data. We disclose only the minimum necessary for a specified purpose, on a lawful basis and subject to appropriate safeguards.

10.1 Service Providers and Establishments

We disclose to the Service Provider the data necessary to fulfil a booking, order or appointment, such as name, contact method, date, time, number of guests, special requests and relevant payment status. A Service Provider may need additional data that it requests directly under its own notice and responsibility.

10.2 Channel and Integration Partners

If you initiate a transaction through a partner application or website, we exchange with it transaction identifiers, status, amounts and data needed for integration, support, refunds and preventing duplication or fraud. The integration does not give the partner a right to use MyTable data for an undisclosed independent purpose.

10.3 Payment Providers and Financial Institutions

We disclose the minimum necessary to banks, payment service providers, wallet or instalment providers, and fraud-prevention providers to process authorisation, collection, settlement, refunds and disputes, and to meet their legal requirements. Each independent institution's processing is governed by its own terms and notice.

10.4 Processors and Vendors

We may use hosting and cloud-infrastructure providers, messaging and email services, support, analytics, mapping, content-management, security, verification, development and maintenance vendors. A party that processes data on our behalf is bound by documented instructions, confidentiality, access limitation, security measures, incident reporting, return or destruction at the end of the service, and controls over the use of sub-processors.

10.5 Affiliates and Advisers

We may disclose the minimum necessary to an MYT Global affiliate, legal or financial adviser, or auditor where needed to manage the business, a claim or compliance obligation, subject to a legitimate purpose and appropriate confidentiality and protection obligations. Membership in a corporate group does not automatically make data available to every group company.

10.6 Competent Authorities and Legal Protection

We may disclose data to a government, regulatory or judicial authority in response to a valid request or legal obligation, to protect health, safety or life, or to establish or defend a legal right. Where permitted, we document the disclosure and limit it to what is required.

10.7 Corporate Transactions

A prospective acquirer, investor, financier or adviser may access the minimum necessary information as part of lawful due diligence for a financing, merger, acquisition or asset transfer, after applying confidentiality and data-minimisation measures. If a completed transaction changes the Controller, we notify you in accordance with law before your data is used for an incompatible purpose.

10.8 Users and the Public

Content, profiles, ratings and check-ins are displayed according to your selected audience settings and the nature of the feature. Messages reach their recipients and the systems needed to transmit and protect them. We do not treat public content as private, and we do not display private content publicly except at your direction or on a lawful basis.

11. Payments and Financial Data

MyTable uses banks or licensed payment service providers according to the available payment method. A financial institution may host the payment page or collect card data directly. MYT Global typically receives a reference token, transaction status, amount and data necessary for reconciliation, and does not use payment data for marketing.

MYT Global does not provide a regulated financial service in its own name unless it expressly announces the relevant entity and licence. Balances or rewards are not electronic money or a payment account unless the product is expressly described as such and satisfies applicable regulatory requirements.

12. Social Content and Messages

Feature settings control the audience for a post, story, live stream or check-in. We may process content to test it technically, display it to recipients, apply your settings, rank it, detect spam, fraud or prohibited content, and respond to reports and legal requirements.

We do not use a private photograph or private message in paid advertising outside the purpose for which it was sent without separate consent. An authorised employee or support provider may review specific content when it is reported, where there is a security indicator, to fulfil your request, or where required by law. We do not claim that messages are end-to-end encrypted unless that is expressly shown within the feature.

If you delete content, we remove it from active display within the periods set out below. A limited copy may nevertheless remain temporarily in backups, security logs or an open report, or with a user who previously received or copied it outside the platform.

13. Location, Contacts and Device Permissions

MyTable requests each permission when the associated feature requires it. You may refuse location, camera, microphone, photograph, notification or contact permission through your device settings. The dependent feature may stop working, but the account or core booking functionality will remain available.

Approximate location is used to display suitable options and protect the session. Precise location—with your consent—is used for nearby search, maps, check-in or another location-dependent service. We do not use precise location history to create targeted advertising without separate and clear consent.

If contact synchronisation is available, we do not send invitations automatically in your name without a clear action from you, and we limit data to the stated matching or invitation purpose. You may stop synchronisation and request deletion of uploaded data through the account settings or the Data Protection Officer.

14. Cookies and Similar Technologies

We use cookies, local storage, application identifiers or software development kits for specified purposes.

Strictly necessary technologies are used to sign you in, protect a session, save language and essential preferences, prevent fraud and complete a transaction. They may operate without consent when necessary for the service you request and are not used for independent advertising.

Optional functionality technologies help save additional choices or operate maps, media or integrations selected by the user. Analytics technologies measure performance, use and faults. Advertising or marketing-measurement technologies are used to personalise or measure campaigns and, where consent is required, are not activated until you choose them.

Depending on the channel, the website or application provides a preference centre or notice that allows you to accept, reject or change non-essential categories. You may also use browser or device settings, although deleting or disabling necessary technologies may prevent some functions.

15. Storage and Transfers Outside the Kingdom

The geographical scope of processing MyTable data includes the Kingdom of Saudi Arabia and may extend to other countries in which cloud infrastructure, messaging, support, security or analytics providers, or technical teams necessary to deliver the service, are located. You may request an up-to-date statement of the material categories of recipients and geographical scope from the Data Protection Officer.

We do not transfer Personal Data outside the Kingdom, or make it accessible from outside the Kingdom, merely because you generally accept this Policy. A transfer occurs only for a legitimate purpose, is limited to the minimum necessary, and follows satisfaction of the requirements of the Saudi Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom. These requirements include assessing the level of protection and risks where required, confirming necessity, and applying appropriate safeguards such as Standard Contractual Clauses, Binding Common Rules or a certification, as applicable.

If transfer requirements cannot be met, we stop the transfer or change the Service Provider or means of processing. We do not rely on a transfer exception repeatedly or broadly beyond its conditions.

16. Retention and Destruction

We set retention periods according to the category of data, purpose and legal requirements, and periodically review the continuing need. The shorter standard applies once the purpose has been achieved, unless retention is required for an ongoing procedure, claim, dispute, preservation order or legal obligation.

16.1 Account and Profile

We retain account data while the account is active and for no more than two years after closure or the last material activity, for closure, security, complaints and recovery of necessary records. During that period, data that must be retained for transactions or legal obligations is separated from unnecessary profile data.

16.2 Bookings, Orders, Payments and Invoices

We retain necessary transaction, fee, payment, refund, invoice and accounting records for six years from completion of the transaction or the end of the relevant tax period, as applicable, or for a longer period required by a specific law or ongoing dispute. This does not include full card data, which MYT Global does not receive where it is processed directly by the payment provider.

16.3 Support, Complaints and Claims

We retain the record of a support request or complaint and related correspondence for three years after it is closed. We may retain the necessary portion for longer until a claim is finally resolved or a legal obligation has been fulfilled.

16.4 Consents and Rights Requests

We retain a record of consent or withdrawal, rights requests, verification and responses for five years after withdrawal, closure of the request or the end of the related processing, to demonstrate compliance and prevent reactivation of a purpose you rejected.

16.5 Security and Fraud Prevention

We retain ordinary technical and security logs for no more than twenty-four months. If a log relates to an incident, attempted fraud or an account under investigation, the necessary portion may be retained for up to five years, or until the investigation or claim ends if later, within the limits permitted by law.

16.6 Precise Location and Contacts

We process precise location during the relevant session or feature and do not retain its raw history for more than thirty days unless it becomes part of a booking, a check-in selected by the user, or a security incident. Contact data uploaded for matching or invitations is deleted within thirty days after the purpose ends, while guest data that becomes part of a booking remains within the transaction record.

16.7 Social Content

We retain content until you delete it or close the account, and then remove it from active systems within thirty days unless it is connected with a report, obligation or dispute. Removal from periodic backups may take up to ninety days. A moderation-action or content-report record may be retained for three years to protect the platform and demonstrate the action taken.

16.8 Health or Other Sensitive Data

A sensitive note connected with a booking or appointment is deleted within ninety days after the service is completed, unless you asked us to save it as a preference in your profile or a specific law requires retention. If saved as a preference, it remains until you delete it or close the account, subject to the stated backup cycle. A Service Provider may retain its own copy for a different period under an independent obligation that it must explain to you.

16.9 Analytics, Cookies and Marketing

Identifiers used for analytics and non-essential cookies are retained for no more than thirteen months unless the preference centre displays a shorter lifetime. We retain your marketing preference until consent is withdrawn or there has been no interaction for twenty-four months. We then stop marketing and retain a limited suppression record for five years to ensure that the withdrawal continues to be respected.

16.10 Partnership and Recruitment Applications

We retain an incomplete or unsuccessful Service Provider or partner application for twenty-four months after the last communication, unless the applicant requests earlier deletion. We retain a job application for twelve months after the relevant vacancy closes and do not retain it for future opportunities without consent or another appropriate lawful basis.

16.11 Backups and Destruction

Backups are managed through protected cycles. Expired data is deleted or overwritten within no more than ninety days unless a legal preservation order or documented technical incident prevents this. Depending on the system and data, destruction is carried out through secure deletion, media overwriting, cryptographic-key destruction or anonymisation that prevents re-identification.

17. Data Security

We apply technical, organisational and administrative measures proportionate to the nature, volume and risks of the data. These may include need-based access control, authentication, encryption in transit and at rest where appropriate, environment segregation, logging and monitoring, vulnerability and update management, backups, restoration testing, vendor management, training and confidentiality, and incident-response plans.

No method of transmission or storage can guarantee absolute security. We therefore review and update our controls, and ask you to protect your login credentials, never share a verification code, and notify us immediately if you suspect unauthorised use.

18. Personal Data Breaches

If an incident occurs, we work to contain and investigate it, assess its impact, restore service and prevent recurrence. We notify the Saudi Data and Artificial Intelligence Authority within no more than seventy-two hours after becoming aware of the incident where it may cause harm to the Personal Data or Data Subject, or conflict with the Data Subject's rights or interests. Information not then available is supplied as soon as possible, with the reason for any delay.

We notify the affected Data Subject without undue delay where the incident may cause harm to their Personal Data or conflict with their rights or interests. To the extent that doing so does not prejudice the investigation, security or the rights of others, we explain the nature of the incident, the risks, the measures taken, recommendations and a contact channel.

19. Your Rights in Relation to Your Personal Data

These rights are subject to applicable legal controls and exceptions. Exercising them is free of charge unless the law permits otherwise.

19.1 Right to Be Informed

You have the right to know the lawful bases and purposes for collection and processing; the categories and sources of data; how it is used, retained and destroyed; the parties to whom it is disclosed; and how to exercise your rights. This Policy provides general information, and you may request an explanation specific to your circumstances.

19.2 Right of Access

You have the right to request access to your Personal Data available to us, subject to protection of the rights of others, intellectual property, trade secrets and applicable legal restrictions.

19.3 Right to Obtain a Copy

You have the right to request a readable and clear copy of your data in a commonly used electronic format where technically possible, or a printed copy where possible, without disclosure of another person's data.

19.4 Right to Correction

You have the right to request correction of inaccurate data, completion of incomplete data or updating of outdated data. We may request a document necessary for verification and destroy it once the need ends. We notify you when the correction is complete and notify parties to whom the data was disclosed where required.

19.5 Right to Request Destruction

You have the right to request destruction of your data in circumstances provided by law, including when the purpose has ended, consent is withdrawn where it was the sole lawful basis, or the processing is established to be unlawful. Immediate destruction may not be possible for a portion that must be retained under law, for a dispute, or to protect the rights of others. In that case, we restrict its use to the mandatory purpose and explain the reason.

19.6 Right to Withdraw Consent

You may withdraw any optional consent at any time through the relevant feature settings, the preference centre, or by contacting us. Withdrawal stops processing based on that consent without undue delay. It does not affect prior processing or processing based on another lawful basis.

19.7 Complaint and Objection

You may object to processing that you consider inaccurate or unlawful, submit a complaint to us, or complain to the competent authority as described in Section 26. You may request human review of an impactful automated decision where that right is established by law.

20. How to Exercise Your Rights and Delete Your Account

You may update certain data or delete your account through the application settings where the relevant tool is available. You may also submit a request to the Data Protection Officer at privacy@mytable.sa or on the unified number 920032786, stating the right you wish to exercise and a suitable contact method.

We may verify your identity to the minimum extent necessary before fulfilling the request, and do not request unnecessary additional data. If a request is submitted by a guardian or agent, we verify their status and authority to represent you.

We fulfil a complete request without delay and within no more than thirty days. We may extend that period by no more than a further thirty days where fulfilment requires unexpected or unusual effort or where multiple requests have been received, provided that we notify you in advance of the extension and its reason.

If a request is unreasonably repetitive, requires unusual effort, conflicts with another person's rights or with a legal obligation, we may restrict or refuse it to the extent permitted by law, and will explain the reason and the complaint channel. Deleting the account stops active features, but does not erase records that must be retained for the periods stated in this Policy.

21. Marketing and Notifications

We send booking confirmations, receipts, security and support alerts, and notifications necessary to perform the service without treating them as marketing. It may not be possible to disable such messages while the related transaction or account remains active.

We do not process your Personal Data for direct marketing, or send marketing material through a personal communication channel, without obtaining and documenting the required consent. MYT Global or MyTable is clearly identified in the message, and a free and easy means to unsubscribe is provided that is as easy as, or easier than, subscribing.

You may opt out of marketing through the unsubscribe link, account or notification settings, or by contacting privacy@mytable.sa. We stop it without undue delay while retaining a limited suppression record so that you are not mistakenly added again.

We do not share your data with a Service Provider or partner for its independent marketing without separate consent where required. Completing a single booking is not sufficient to treat you as having consented to continuing marketing from the Service Provider.

22. Minors and Persons Lacking or Having Limited Legal Capacity

Services that create a financial or contractual obligation are intended for persons with the required legal capacity or for use under the supervision and consent of a guardian or legal representative. We do not target large-scale collection of data relating to a minor or a person lacking or having limited legal capacity without appropriate safeguards.

Where such data is needed for a family booking, ticket, appointment or suitable feature, it must be provided by a guardian or authorised person. We use appropriate language, limit the data to what is necessary, and verify guardian consent where required by law. Precise location or Sensitive Data is not displayed publicly by default.

If we learn that data was collected without a valid lawful basis or proper guardianship authority, we stop processing it and take steps to destroy it unless the law requires retention of a specified portion. A guardian may exercise rights on the person's behalf through the privacy channel.

23. External Links and Services

MyTable may include maps, content, payment, sign-in or links to an external service. This Policy applies only to processing by MYT Global. When a user moves to an independent third party or provides data directly to it, that party's privacy policy applies and should be reviewed before use.

This Section does not release MYT Global from responsibility for selecting a Processor that acts on its behalf or for data it discloses. In contracting and notices, we distinguish between a vendor that processes under our instructions and an independent party that determines its own purposes.

24. Changes to this Policy

We review this Policy when the product, data, vendors or laws change. The date of the last update and version number are displayed. If a change is material, we notify you prominently for an appropriate period before it takes effect, according to its impact, through the application, website or registered contact method.

We do not apply a new, incompatible purpose to data previously collected merely by updating the text. We provide any required notice and obtain fresh consent where required. An amendment does not retroactively affect rights that arose before its effective date.

From its effective date, this Policy replaces the previous privacy policy addressed to MyTable users. We retain a record of prior versions and their effective dates to the extent necessary to demonstrate notices, consents and obligations then in effect.

25. Language and Governing Law

This Policy has been prepared in accordance with the Saudi Personal Data Protection Law and its implementing regulations, without prejudice to any other applicable law. An English translation is provided for convenience. In the event of a conflict within the Kingdom of Saudi Arabia, the Arabic version prevails unless a mandatory law provides otherwise.

26. Contact and Complaints

To ask about this Policy, exercise a right or report a privacy concern, contact:

Data Protection Officer — MYT Global Company

Email: privacy@mytable.sa

Unified Number: 920032786

Website: MyTable

Address: Riyadh, Kingdom of Saudi Arabia

Unified National Number: 7054723072

We handle internal privacy requests and complaints within the periods and procedures set out in Section 20 of this Policy.

If you are not satisfied with our handling of your request or complaint, or believe that the Personal Data Protection Law has been infringed, you may submit a complaint to the Saudi Data and Artificial Intelligence Authority (“SDAIA”) through the National Data Governance Platform or its official channels within no more than ninety (90) days after the incident that is the subject of the complaint or the date on which you became aware of it. The competent authority may, at its discretion, accept a complaint after that period where factual reasons prevented its submission in time. You are not required to contact us first where the law permits you to approach the competent authority directly.

Without prejudice to any penalty or other right, a person who suffers harm as a result of an infringement of the Personal Data Protection Law or its implementing regulations has the right to claim before the competent court compensation for material or moral harm proportionate to the harm suffered.

This Policy was last updated on 27 August 2026.