Personal data
Personal Data Processing Policy
This document defines how personal data is processed and protected when using UpCore.
- Operator
- OOO Dexmobile
- Tax ID
- 9715334304
- Document
- Personal data policy
- Revision date
- 08.06.2026
1. General provisions
This policy applies to personal data of UpCore users, customer representatives, employees and other persons whose data is processed during product operation.
Processing is performed to provide access to UpCore, support the product, calculate engineering metrics, prepare reports and ensure security.
2. Personal data operator
| Operator | OOO Dexmobile |
|---|---|
| Tax ID / KPP | 9715334304 / 773401001 |
| OGRN | 5187746013659 |
| Address | 123308, Moscow, Marshal Zhukov Ave., 2, premises 21P |
| sales@dex-it.ru |
3. Categories of processed data
- full name, position, department, work email, work phone and system role;
- account identifiers in UpCore, Git, Jira, YouTrack and other connected systems;
- actions in UpCore: logins, settings, report views and configuration changes;
- engineering data: commits, merge requests, tasks, reviews, worklogs and timesheets;
- technical data: IP address, date and time of actions, event log and session data.
4. Processing purposes
- providing access to UpCore and account administration;
- calculating development efficiency, code quality, grades and project risks;
- preparing reports for managers, HR, team leads and administrators;
- technical support, maintenance and product development;
- information security, logging and incident investigation;
- contract performance and legal compliance.
5. Actions with personal data
The operator may collect, record, systematize, accumulate, store, update, use, depersonalize, block, delete and destroy personal data with or without automation.
Transfer to third parties is allowed when there is a legal basis, customer agreement, operator instruction or legal requirement.
6. Storage and termination
- Data is stored for the contract term, UpCore operation period and the time needed for reporting or protection of rights.
- After contract termination, data is deleted, depersonalized or returned under the agreed procedure.
- When consent is withdrawn, processing stops unless another legal basis applies.
7. Protection measures
- role, project and scope-based access control;
- protected data transmission channels;
- logging of user and administrator actions;
- backups and integrity control;
- limited employee and contractor access by need-to-know principle;
- control of integrations, accounts and service keys.
8. Data subject rights
The data subject may request information about processing, correction, blocking, deletion or withdrawal of consent.
Requests are sent to sales@dex-it.ru and should include name, response contact and request subject.
