International Data Processing Agreement
Version and effective date: 2026-09-08
This DPA applies when an order, proposal or service agreement for UTEAM Club incorporates it.
1. Parties and roles
The customer club or academy is the Controller of personal data it uploads, collects or otherwise manages for its own purposes through UTEAM Club. The UTEAM supplier identified in the applicable order or agreement is the Processor for that data.
The supplier is ARTEM OGANISIAN, sole proprietor registered in Armenia, TIN 20393333. The applicable order or agreement identifies the services and processing instructions covered by this DPA.
UTEAM acts as an independent controller for its own account, contracting, security, support and billing records. Paddle, if shown at checkout, processes buyer and payment data under its own terms as merchant of record; it does not receive club health, sporting or workspace content through this DPA.
2. Instructions and purpose
The Processor handles personal data only on documented instructions to provide the Platform, role-based access, storage, backup, support, security, export and deletion. Documented instructions include this DPA, the order, selected settings, customer requests and actions by customer-authorised users in the Platform.
The Processor will notify the Controller if an instruction appears to violate applicable data-protection law and may suspend that instruction until the issue is resolved.
3. People and data
Data subjects may include players, minors, parents and guardians, coaches, employees, contractors, medical or recovery staff and other people added by the Controller.
Data may include identity and contact details, team and role data, attendance, schedules, sporting results, tests, GPS and workload information, documents, account and device identifiers, and other content entered by the Controller.
If the Controller enables relevant modules, the data may include health, injury, pain, recovery, restriction, treatment-history and wellness information entered by its authorised specialists. UTEAM does not diagnose or generate medical advice. The Controller decides why these data are processed and must establish the required legal basis, notices, permissions and safeguards, especially for health data and minors.
4. Processor obligations
- process data only within documented instructions;
- ensure confidentiality and role-based, least-privilege access;
- maintain reasonable technical and organisational safeguards;
- assist with data-subject requests and compliance information;
- notify the Controller of a confirmed personal-data incident without undue delay;
- keep records needed to demonstrate compliance;
- delete or return data at the end of the service, subject to mandatory retention and backup rotation.
5. Controller obligations
- give lawful, accurate and documented instructions;
- provide notices and obtain any required consent or other legal basis;
- verify authority for children and represented individuals;
- configure access roles and remove access promptly when no longer required;
- avoid uploading data that are excessive for the stated purpose;
- respond to individuals and regulators as required by applicable law.
6. Subprocessors and location
The current core application, database, object storage and backups use Yandex Cloud infrastructure in the Russian Federation. Service email may use Yandex Mail/SMTP. If the customer enables mobile push, technical routing data may pass through Expo Push and Apple Push Notification service or Firebase Cloud Messaging.
The Processor will use subprocessors only where needed for the Service, bind them to appropriate confidentiality and security terms, and remain responsible for their processing within this DPA. Material changes will be communicated through the Site, account or email where reasonably practicable.
7. International transfers
Each party is responsible for the transfer mechanisms, notices, assessments or approvals required of it under applicable law. The Controller must not instruct an unlawful transfer. The Processor will minimise transferred data and provide reasonably available information about infrastructure and subprocessors.
8. Security incidents
After confirming an incident affecting customer data, the Processor will notify the Controller without undue delay and provide available information about its nature, affected data, likely consequences and mitigation. The Controller remains responsible for notices it must make to individuals or authorities.
9. Return and deletion
The Controller should request an available export before service termination. Unless an order states otherwise, active customer data are deleted no later than three calendar days after the processing instruction ends, except data that must be retained by law. Backup copies are removed from active use and rotate out within fourteen calendar days after primary deletion.
10. Payment-data boundary
Payment providers handle payment credentials in their hosted or provider-controlled environments. UTEAM may receive customer, transaction, subscription, amount, currency, status and limited payment-method metadata needed for fulfilment and support. UTEAM does not store full payment-card numbers or CVV/CVC security codes.
11. Term and precedence
This DPA lasts while the Processor handles customer data. If it conflicts with general product terms on processing customer data, this DPA prevails. Mandatory law and a signed agreement or approved transfer addendum prevail where required.
Questions: info@uteam.club. See the Privacy Policy.