Data processing agreement (DPA)
Appendix No. 1 to the public offer
Version: 2026-08-29
This English text is a convenience translation. The complete Russian DPA is legally authoritative and prevails if the texts differ.
This DPA forms an integral part of the public offer of Artem Aravi Oganyan (the “Provider”, “Processor”) and applies to clubs (the “Customer”, “Controller”) that accept the offer and use the UTeam platform.
1. Roles
For personal data of players, staff, parents/guardians and other individuals whose data the club uploads or organises through the Platform, the club acts as the data controller.
The Provider processes such data on the club’s instructions solely to deliver Platform functionality, club support, security, backup and documented club instructions. Billing and direct data of the Customer's representative are the Provider's separate controller purposes.
2. Scope and purposes
Processing on behalf of the club includes storage, organisation, access control, backup, security and deletion as required for Platform operation.
Documented instructions include acceptance of the Offer and this DPA, the selected plan, club settings, commands and requests, data uploads, role assignments and actions by club-authorised users through the Platform interfaces. Acceptance is a standing instruction within the functionality actually used. No repeated legal acknowledgement is required for each module, operation or data type.
3. Special categories and club warranties
Health, medical and wellness survey data may be processed if the club enables the relevant modules. The club warrants that it has all required legal bases, notices and consents, including written health-data consent and verification of a representative's authority, including for minors.
The Provider does not verify each individual consent or legal basis unless otherwise agreed.
The club files its required Roskomnadzor notices, defines retention periods and access roles, retains evidence, and issues timely documented instructions for correction, export, blocking and destruction. Acceptance of the Offer and this DPA does not replace these duties.
4. Processor duties and subprocessors
The Provider processes data only on documented instructions, maintains confidentiality and security, supports data-subject requests, reports a confirmed incident to the club without undue delay and no later than 12 hours, and deletes or returns club working data no later than 3 calendar days after the instruction ends, subject to mandatory retention. Backup copies are removed from active processing and rotate out no later than 14 calendar days after primary data deletion.
Infrastructure may include Yandex Cloud, Yandex Mail/SMTP and, when enabled by the club, Expo Push followed by Apple Push Notification service or Firebase Cloud Messaging. Cross-border processing is not enabled on a club instruction until the controller completes the procedure required by Article 12 of Federal Law No. 152-FZ.
Registering a push token, enabling or using notifications is a functional instruction to send the minimum technical identifier and notification content through Expo Push, Apple Push Notification service or Firebase Cloud Messaging. No separate legal checkbox is required. The club warrants completion of applicable Article 12 duties before allowing use of that channel. The Provider does not put health data or other special-category data in push text unless the club's expressly selected scenario requires it.
The Provider notifies the club if an instruction appears manifestly unlawful and does not execute it until the issue is resolved. Remote access by a Russian controller to its own infrastructure from abroad is not treated by this DPA, by itself, as disclosure to a foreign recipient.
5. Acceptance
Accepting the public offer constitutes acceptance of this DPA and a documented instruction within its scope. Technical availability of a feature does not replace the club's controller duties. See also the Privacy Policy.