Personal data

Personal Data Processing Policy

This document defines how personal data is processed and protected when using UpCore.

Operator
OOO Dexmobile
Tax ID
9715334304
Document
Personal data policy
Revision date
08.06.2026

1. General provisions

This policy applies to personal data of UpCore users, customer representatives, employees and other persons whose data is processed during product operation.

Processing is performed to provide access to UpCore, support the product, calculate engineering metrics, prepare reports and ensure security.

2. Personal data operator

OperatorOOO Dexmobile
Tax ID / KPP9715334304 / 773401001
OGRN5187746013659
Address123308, Moscow, Marshal Zhukov Ave., 2, premises 21P
Emailsales@dex-it.ru

3. Categories of processed data

  • full name, position, department, work email, work phone and system role;
  • account identifiers in UpCore, Git, Jira, YouTrack and other connected systems;
  • actions in UpCore: logins, settings, report views and configuration changes;
  • engineering data: commits, merge requests, tasks, reviews, worklogs and timesheets;
  • technical data: IP address, date and time of actions, event log and session data.

4. Processing purposes

  • providing access to UpCore and account administration;
  • calculating development efficiency, code quality, grades and project risks;
  • preparing reports for managers, HR, team leads and administrators;
  • technical support, maintenance and product development;
  • information security, logging and incident investigation;
  • contract performance and legal compliance.

5. Actions with personal data

The operator may collect, record, systematize, accumulate, store, update, use, depersonalize, block, delete and destroy personal data with or without automation.

Transfer to third parties is allowed when there is a legal basis, customer agreement, operator instruction or legal requirement.

6. Storage and termination

  • Data is stored for the contract term, UpCore operation period and the time needed for reporting or protection of rights.
  • After contract termination, data is deleted, depersonalized or returned under the agreed procedure.
  • When consent is withdrawn, processing stops unless another legal basis applies.

7. Protection measures

  • role, project and scope-based access control;
  • protected data transmission channels;
  • logging of user and administrator actions;
  • backups and integrity control;
  • limited employee and contractor access by need-to-know principle;
  • control of integrations, accounts and service keys.

8. Data subject rights

The data subject may request information about processing, correction, blocking, deletion or withdrawal of consent.

Requests are sent to sales@dex-it.ru and should include name, response contact and request subject.