Version 3 · in effect from 1 September 2026
Chess Knowledge FZE
Version: 2.1 Effective date: 1 September 2026
The App is operated by Chess Knowledge FZE ("we", "us", "our"), licence/registration number RAKIA80FZ607114372, registered with the Ras Al Khaimah Economic Zone Authority (RAKEZ), registered address B17-310, RAK Port Customs Building – Al Nakheel, RAKEZ Business Zone-FZ, Ras Al Khaimah, United Arab Emirates. We are the controller of the personal data described in this policy.
Privacy contact: Alexandra Grishina, Owner and Manager, chessuae3@gmail.com.
This policy explains what personal data we collect through the App, where it comes from, why we collect it, who we share it with, how long we keep it, and the rights you have. It covers data about you (the parent/guardian) and about the Child/Children registered to your Account.
Sources of data. We obtain personal data from three sources:
We deliberately do not collect Emirates ID numbers, passport data or any government identifier, and we do not collect photographs of Children.
| Purpose | Basis under the UAE PDPL |
|---|---|
| Create and manage your Account; enrol Children; schedule and deliver lessons | Necessary for the performance of the contract with you (Art. 4(1)) |
| Process payments, issue invoices, tax and accounting records | Necessary for the performance of the contract with you (Art. 4(1)); compliance with a legal obligation (Art. 4(2)) |
| Send you service messages: reminders, schedule changes, cancellations, attendance, coach feedback, payment and refund notices | Necessary for the performance of the contract with you (Art. 4(1)) |
| Send you optional messages that are not part of the service (new terms, camps, offers) | Your consent, given separately per channel, withdrawable at any time (Art. 6) |
| Hold and act on a Child's health information in an emergency | Your explicit consent (Art. 5); and, where a life is at risk, protection of the vital interests of the data subject |
| Keep the service and your Account secure; prevent, detect and investigate misuse | Compliance with a legal obligation (Art. 4(2)); necessary to protect the public interest |
| Establish, exercise or defend legal claims; respond to lawful requests from authorities | Necessary to protect our rights and to conduct legal or judicial procedures (Art. 4) |
| Understand and improve how classes work overall | We use aggregated statistics that do not identify any individual. Once data is genuinely anonymised it is no longer personal data and this policy does not restrict its use. |
We do not sell your data. We do not use it for third-party advertising. We do not use it for automated decision-making that produces legal effects or similarly significant effects on you or your Child, and we do not profile Children for commercial purposes.
The App is designed for parents and legal guardians to manage classes for their Children. A Child does not have their own login. A Child's information is provided and managed by you through your Account, or by the Child's school as described in Section 2.
By registering a Child you confirm that you are that Child's parent or legal guardian, that you are aged 18 or over, and that you are entitled to provide their personal data and to give the consents described in this policy on their behalf.
We collect only what is needed to run a Child's classes and to keep them safe. We do not collect photographs of Children, we do not show advertising to Children, we do not profile Children for commercial purposes, and we do not use a Child's data for targeted advertising.
We share personal data only where it is needed to deliver the service:
We do not share your data for third-party advertising, and we do not sell it.
Each of the third parties above is engaged under a written agreement that requires them to process personal data only on our instructions and to apply protection for that data equivalent to the protection described in this policy.
If you choose to tell us about a Child's medical condition, allergy or medication, we treat it as sensitive personal data:
We do not collect, store or publish photographs of Children. In the App a Child is shown as a generated avatar: the App turns a short "seed" value into a cartoon-style face on the device. The seed is not a likeness of the Child and cannot be turned back into one.
The only photograph we may hold is your own profile photo as a parent/guardian. It is optional, you provide it yourself, it is visible only to you, your Children's coaches and our staff, and you can remove it at any time from your profile. The App works fully without it.
Some of the providers listed in Section 6 process personal data on servers outside the UAE — in particular the United States, where Twilio SendGrid, Google Firebase Cloud Messaging, Apple (APNs) and Meta Platforms process data, and the country in which our hosting provider's data centre is located, which is named in Section 6.
Under Articles 22 and 23 of the UAE PDPL, personal data may be transferred outside the UAE to a jurisdiction that the UAE Data Office has approved as providing an adequate level of protection, or, in the absence of such approval, on the basis of a contract imposing PDPL-equivalent obligations on the recipient, your explicit consent, or where the transfer is necessary to perform a contract with you. We rely on contractual safeguards that place obligations equivalent to those under the UAE PDPL on each recipient, together with the necessity of the transfer for the performance of our contract with you, and we require each recipient to protect your data to the standard described in this policy.
| Data | Retention |
|---|---|
| Account and Child profile, while the Account is active | Until you delete the Account |
| Your profile photo (optional) | Until you remove it, or until you delete the Account |
| Child's health information | Deleted when the Child's enrolment ends, or on withdrawal of consent |
| Attendance and coach feedback | 24 months after the Child's last enrolment |
| Push tokens and device data | Until you uninstall the App or disable notifications, then 90 days |
| Security and access logs | 12 months |
| Consent records (what you agreed to, when, and which version) | 7 years — needed to prove compliance |
| Payment, invoice, tax and accounting records | 5 years from the end of the relevant tax period, as required by UAE tax law |
When you delete your Account, we delete your and your Child's personal data — including the Child's profile, health information, attendance and feedback records. We keep only the financial and tax records we are legally required to keep, and the minimum consent records needed to show what was agreed.
Subject to applicable law, you may:
Use the tools in your profile, or contact us using Section 19. We aim to respond within 30 days of receiving a request, and in any event within the period required by law. Where a request is complex we will tell you and explain the delay. We may need to verify your identity, and your authority as parent or guardian, before acting.
The App does not use third-party analytics, advertising, attribution or tracking SDKs. We do not track you or your Child across other companies' apps or websites, we do not use advertising identifiers, and we do not share data with data brokers.
We use crash and performance diagnostics solely to keep the App working. Our admin website uses only strictly necessary cookies needed to keep you signed in and to keep the site secure.
We use your email address, device push token and registered phone number to send you the messages described in Section 4.
You choose your channels — email, push and WhatsApp — separately, and you can change them at any time. WhatsApp messages are delivered through the WhatsApp Business service and are subject to Meta's handling of message delivery. The App works fully if you decline push notifications.
We protect your information with encryption in transit and at rest, hashed credentials, role-based access controls, access logging for sensitive data, and regular review of who can see what. We maintain a written information-security programme with a named owner, periodic risk assessments and staff training.
No system is completely secure, so please keep your login details private and tell us at once if you suspect misuse of your Account.
If a personal-data breach occurs that is likely to create a risk to the privacy, confidentiality or security of your personal data, we will notify the UAE Data Office immediately upon becoming aware of it, and will notify affected users where the breach is likely to cause them harm. Our notification will describe the nature of the breach, the approximate number of records affected, its likely effects, and the steps we have taken. Our processors are contractually required to notify us immediately of any breach affecting your data.
If you are unhappy with how we handle your data, or with any part of the service, you can reach us through the complaints channel in the App, which is available at any time, or through the contacts in Section 19. We will acknowledge your complaint and tell you what we intend to do about it.
You can also complain to the UAE Data Office about our handling of personal data, and to the Ministry of Economy and Tourism or the relevant Department of Economic Development about the service itself. Nothing in this policy or in our Terms affects those rights.
We may update this policy from time to time. If a change is significant we will notify you in the App before it takes effect and, where required, ask you to accept the new version. We record which version you accepted and when. The current version and its effective date are always available in the App.
For any privacy question or request: