1. General Provisions and Acceptance of the Agreement
1.1.This User Agreement (the "Agreement") sets out the terms and conditions on which the Allezroma ID single sign-on service (the "Service") is provided. The Agreement is concluded between the person using the Service (the "User") and the operator of the Service (the "Operator"), whose identity and contact details are set out in Sections 3 and 13 of this Agreement. The Agreement is a legally binding agreement between the Operator and the User; to the extent that it governs the processing of the User's personal data, it also constitutes the privacy notice of the Service.
1.2.This Agreement is an open offer addressed to an unlimited number of persons. By creating an account in the Service, signing in, or otherwise commencing use of the Service, the User accepts this Agreement in full and without conditions (acceptance by conclusive conduct). Neither party is required to execute a written counterpart of the Agreement.
1.3.The User confirms that, prior to accepting this Agreement, the User has read and understood its complete text, including the provisions on the processing of personal data (Section 9). If the User does not accept any provision of this Agreement, the User must refrain from using the Service.
1.4.By using Allezroma ID to sign in to connected services, the User also accepts the user agreement of each such service; the terms of use of the connected services are set out in their own agreements.
2. Definitions and Interpretation
2.1.For the purposes of this Agreement, the following terms have the meanings set out below:
2.1.1."Applicable Law" — the mandatory laws and regulations of the jurisdiction whose rules apply to the respective relationship between the User and the Operator.
2.1.2."Connected Services" — the services of the Allezroma ecosystem that may be accessed using Allezroma ID; the up-to-date list is available on the sign-in page of each service.
2.1.3."Ecosystem Services" — the services operated by the Operator under the common designation "Allezroma", including the Service and the Connected Services.
2.1.4."SEED Code" — a one-time code issued by the Service for guest sign-in without an e-mail address; the SEED Code is a sign-in credential equivalent in function to a password.
2.1.5."Session" — an authenticated state of the User's browser or application created upon sign-in and identified by session means (including the strictly functional sso_sid cookie).
2.2.Interpretation. Headings are inserted for convenience only and do not affect the construction of this Agreement. The word "including" is to be construed as "including without limitation". References to Sections are references to sections of this Agreement.
3. The Operator and the Service
3.1.The operator of the Service is Roman Zhamaletdinov (Жамалетдинов Роман), a natural person residing in the Russian Federation (the "Operator"), who operates the Ecosystem Services under the common designation "Allezroma". The Operator does not act through a legal entity. The Operator's contact e-mail is specified in Section 13.
3.2.The Service is the unified authentication service of the Allezroma ecosystem: it allows the User to create one account and use it to sign in to all Connected Services (including the websites wt.allezroma.com, thera.allezroma.com, orga.allezroma.com, redactor.allezroma.com, poll.allezroma.com and pay.allezroma.com).
3.3.The Service is provided free of charge, without advertising or other mandatory payments, and does not constitute entrepreneurial activity requiring registration or licensing under the law of the Operator's place of residence.
4. Eligibility, Registration and Accounts
4.1.The Service is intended for persons who have reached the age of thirteen (13) years, or such higher age of digital consent as may be established by the Applicable Law of the User's country (for example, fourteen (14) to sixteen (16) years in the countries of the European Economic Area); where the age of digital consent is higher than thirteen (13) years, an account may be created and used only with the consent of a parent or legal representative.
4.2.An account is created: by e-mail address with confirmation; through Google sign-in (OAuth); or by means of a one-time SEED Code (guest sign-in without an e-mail address).
4.3.One natural person may maintain one account. Transferring an account to other persons is prohibited. The User is responsible for maintaining the confidentiality of the User's sign-in credentials (password, SEED Code) and for all activities performed under the User's account.
4.4.SEED Code warning. A SEED Code cannot be recovered. If the User loses the SEED Code, access to the guest account cannot be restored by the Operator.
4.5.The User undertakes to provide accurate and complete information where information is requested by the Service.
5. Acceptable Use
5.1.The User shall use the Service solely for lawful purposes and in accordance with this Agreement and Applicable Law. Without limiting the generality of the foregoing, the User shall not:
5.1.1.circumvent the authentication mechanisms or the limits of the Service or of Connected Services;
5.1.2.create accounts automatically (by scripts, bots or other automated means) without the prior written permission of the Operator;
5.1.3.impersonate another person or misrepresent the User's identity;
5.1.4.use the Service for unlawful purposes.
5.2.The Operator may restrict or terminate the User's access to the account in the event of a violation of this Agreement, with notification by e-mail where one is provided.
6. Operation of Single Sign-On
6.1.By signing in to a Connected Service through Allezroma ID, the User authorises the transfer to that Connected Service of the User's account identifier, e-mail address (where provided) and display name. Further processing of these data by the Connected Service is governed by the user agreement of that service.
6.2.Signing out of Allezroma ID ends the Sessions in the Connected Services of that sign-in; the "sign out of all devices" functionality revokes all issued session tokens.
6.3.The Operator is not responsible for the content and operation of the Connected Services; each Connected Service has its own user agreement.
7. Suspension and Termination of Access
7.1.The Operator may block or restrict an account where required by this Agreement or Applicable Law (Section 5.2), with notification where feasible.
7.2.The User may delete the account at any time upon request (Section 9.6); deletion erases the e-mail address, the identifiers and the links to Connected Services; residual copies may persist in backups for up to fourteen (14) days.
8. Term and Amendments
8.1.This Agreement takes effect upon acceptance by the User (Section 1.2) and remains in force until termination. Upon termination, Sections 2, 9, 10, 11, 12 and 13 survive.
8.2.The Operator may amend this Agreement. Material amendments shall be announced in the sign-in interface no later than seven (7) days before they take effect. Continued use of the Service after the effective date of the amendments constitutes acceptance of the amended Agreement.
8.3.Each version of this Agreement is identified by a version number and date indicated at the top of the document. The versions previously accepted by the User may be requested from the Operator; the Operator maintains a record of accepted versions where required by Applicable Law.
9. Personal Data Processing and Privacy
9.1.Controller. The controller of the User's personal data processed in the Service is the Operator (Section 3.1). Requests regarding the processing of personal data shall be submitted to the contact e-mail specified in Section 13.
9.2.Categories of personal data. The Service processes: (a) the account identifier and display names shown in the services; (b) the e-mail address (where provided) and its confirmation status; (c) the password hash (for password sign-in); the SEED Code in an irreversible (hashed and encrypted) form; (d) the Google account identifier where sign-in is performed through Google OAuth (only the identifier, e-mail address and name as permitted by Google; the Google password is neither requested nor stored); (e) Sessions: creation and last-activity time, expiry, client type (user agent); (f) records of sign-ins to Connected Services (which service, when) — necessary for the operation of single sign-on; (g) technical events of the ecosystem observability system (for a period of thirty (30) days). IP addresses are not stored.
9.3.Purposes and legal bases. Personal data are processed for the purposes of: providing authentication and Sessions (performance of this Agreement); prevention of abuse and unauthorised access (legitimate interest of the Operator in the security of the Service); and handling of User requests (performance of this Agreement). The legal bases applied are those permitted by the Applicable Law governing the respective processing.
9.4.Recipients and transfers. Personal data are not sold, rented or otherwise transferred to third parties for their own purposes, and are not used for advertising or profiling. The following recipients process personal data: (a) Connected Services — Ecosystem Services operated by the same Operator (the data listed in Section 6.1, for the purpose of single sign-in); (b) Google — where the User signs in through Google OAuth (only the fact of the authentication request and the data returned by Google). Where personal data are transferred to recipients located in third countries, the Operator shall apply safeguards appropriate under Applicable Law, including standard contractual clauses where required; a copy of such safeguards may be requested pursuant to Section 9.6.
9.5.Retention periods. Personal data are retained for as long as the account exists; Sessions are retained until sign-out or expiry; technical logs are retained for thirty (30) days; residual copies may persist in backups for up to fourteen (14) days after deletion.
9.6.Rights of the data subject. To the maximum extent permitted by Applicable Law (including, where the GDPR applies, Articles 15–21 thereof), the User has the right: to access the User's personal data; to rectification; to erasure; to restriction of processing; to object to processing; to data portability; to withdraw consent at any time (without affecting the lawfulness of prior processing); and to lodge a complaint with the competent supervisory authority. Requests shall be submitted to the contact e-mail specified in Section 13; the Operator shall respond within one (1) month, extendable where permitted by Applicable Law. The Operator may request reasonable verification of the requester's identity.
9.7.No sale, no advertising, no automated decisions. Personal data are not sold, are not transferred to advertising networks and are not used for profiling. The Service does not make decisions based solely on automated processing that produce legal effects concerning the User.
9.8.Security and breach notification. The Operator maintains technical and organisational measures appropriate to the risk. In the event of a personal data breach affecting the User's data, the Operator shall comply with the notification obligations of Applicable Law and shall inform the Users by e-mail (where provided) or by publication on allezroma.com.
9.9.Cookies. The Service uses only strictly functional technical means of storing information on the User's device — the session identifier sso_sid, necessary for sign-in. No consent-requiring tracking technologies are used.
10. Disclaimers and Limitation of Liability
10.1.The Service is provided free of charge, on an "as is" and "as available" basis. To the maximum extent permitted by Applicable Law, the Operator disclaims all warranties, express or implied, including warranties of uninterrupted or error-free operation, availability, merchantability and fitness for a particular purpose.
10.2.The Operator is not liable for the content and operation of Connected Services (Section 6.3). To the maximum extent permitted by Applicable Law: (a) the Operator shall not be liable for indirect, incidental or consequential damages, loss of profit, or loss of data; and (b) the Operator's aggregate liability arising out of or in connection with this Agreement shall not exceed the total amount of fees paid by the User to the Operator for the Service in the twelve (12) months preceding the event giving rise to the liability, which, given the gratuitous nature of the Service, amounts to zero.
10.3.Nothing in this Agreement excludes or limits: (a) liability for intent or gross negligence; (b) liability for death or personal injury caused by negligence; or (c) any other liability or consumer right that cannot be excluded or limited under the Applicable Law mandatory for the respective relationship.
11. Governing Law and Dispute Resolution
11.1.This Agreement and the relationship between the Operator and the User shall be governed by and construed in accordance with the laws of the Russian Federation, without regard to its conflict-of-laws rules.
11.2.Nothing in this Agreement limits the application of the mandatory rules of the law of the User's country of residence, including mandatory consumer protection rules, which shall apply to the extent they mandatorily apply under such law.
11.3.Prior to initiating court proceedings, the parties shall attempt to resolve the dispute through correspondence: a written claim shall be submitted to the Operator's contact e-mail (Section 13), and the parties shall endeavour to resolve the dispute within thirty (30) days of its receipt. Failing amicable resolution, the dispute shall be referred to the competent court determined in accordance with Applicable Law.
12. Final Provisions
12.1.Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the parties shall replace the invalid provision with a valid provision that most closely reflects its original intent and purpose.
12.2.Entire agreement. This Agreement constitutes the entire agreement between the parties concerning the Service and supersedes all prior versions of the User Agreement of the Service.
12.3.No waiver. A failure or delay by either party in exercising any right under this Agreement does not constitute a waiver of that right.
12.4.Assignment. Neither party may assign this Agreement without the prior written consent of the other party.
12.5.Independent parties. Nothing in this Agreement creates an agency, partnership, employment or joint venture between the Operator and the User.
12.6.Notices. Notices to the User shall be given by means of the sign-in interface, by e-mail (where provided) or by publication on allezroma.com. Notices to the Operator shall be given by e-mail (Section 13).
12.7.Force majeure. Neither party shall be liable for a failure to perform obligations caused by events beyond its reasonable control, to the extent permitted by Applicable Law.
12.8.Language. This Agreement is executed in English, which is the prevailing version. For the convenience of users, the Agreement is also provided in Russian, Spanish, Hindi and Chinese; in case of any discrepancy between versions, the English version prevails. For users in the Russian Federation, the Russian version is provided alongside the English one, as required by consumer information rules (Article 10 of the Russian Consumer Protection Law).
13. Contact Information
13.1.Operator: Roman Zhamaletdinov (Жамалетдинов Роман), natural person, residing in the Russian Federation; trade designation of the services: "Allezroma".
13.2.Contact e-mail for all requests, including personal data requests and claims: romzham@gmail.com.
13.3.Website of the Service: sso.allezroma.com.