Privacy Policy
Effective Date: January 12, 2026
Data Controller Information
Company Name: Skyfall Technology OÜ
Registered Office: Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 139b, 11317
Registration Number: 16943755
Represented by: Bálint Zsolt Kuhár, Member of the Management Board
Email Address: [email protected] (hereinafter referred to as: Data Controller)
Purpose of the Privacy Policy
This Privacy Policy contains information regarding data processing related to visitors of the website iocharts.io and users of the website's content (hereinafter referred to as: Data Subject).
In this Privacy Policy, the Data Controller informs the Data Subject about which data processing activities it performs, in what manner, and on what legal basis, as well as the technical conditions applied, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – hereinafter GDPR).
Definitions
- Personal data: Any information relating to an identified or identifiable natural person.
- Identifiable natural person: A natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- Data processing: Performing technical tasks connected to data processing operations (irrespective of the method and means used for executing the operations, as well as the place of execution).
- Processor: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Data Subject: Any natural person identified or otherwise – directly or indirectly – identifiable on the basis of specific personal data. A person is considered identifiable in particular if they can be identified, directly or indirectly, by reference to a name, an identification number, or to one or more factors specific to their physical, physiological, mental, economic, cultural or social identity.
Rights of the Data Subject
During the period of data processing, the Data Controller continuously ensures the rights recorded in the GDPR, which are as follows:
- Right to information [GDPR Recital (60)]: The principle of fair and transparent processing requires that the Data Subject be informed of the existence of the processing operation and its purposes.
- Right of access by the Data Subject (GDPR Article 15): The Data Subject has the right to obtain from the Data Controller confirmation as to whether or not personal data concerning them are being processed, and, where that is the case, access to the personal data and the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients to whom the personal data have been disclosed;
- the envisaged period for which the personal data will be stored.
- Right to rectification (GDPR Article 16): The Data Subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
- Right to erasure (‘right to be forgotten’) (GDPR Article 17): The Data Subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay and the Data Controller has the obligation to erase personal data without undue delay where one of the following grounds applies:
- the personal data are no longer necessary in relation to the purposes for which they were collected;
- the Data Subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
- the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed;
- the personal data have to be erased for compliance with a legal obligation in Union or Member State law.
- Right to restriction of processing (GDPR Article 18): The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:
- the accuracy of the personal data is contested by the Data Subject;
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead.
- Right to data portability (GDPR Article 20): The Data Subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller.
- Right to object (GDPR Article 21): The Data Subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them.
- Automated individual decision-making (GDPR Article 22): The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
Principles Relating to Processing of Personal Data
Based on Article 5, Chapter II of the GDPR, the principles relating to processing of personal data are:
Personal data shall be:- processed lawfully, fairly and in a transparent manner in relation to the Data Subject (lawfulness, fairness and transparency);
- collected for specified, explicit and legitimate purposes (purpose limitation);
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimization);
- accurate and, where necessary, kept up to date (accuracy);
- kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation);
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (integrity and confidentiality).
- The Data Controller shall be responsible for, and be able to demonstrate compliance with, these principles (accountability).
Data Processing Activities at the Data Controller
The Data Controller performs the following data processing activities affecting personal data.
Contact via Email:
Purpose of data processing: Contacting the Data Controller, inquiries, requesting information.
Types of personal data: Name, email address, phone number, other personal data provided by the Data Subject in the message.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, but no later than the end of the 1st year following the Data Controller's response to the message or the last contact.
Data Processing Related to Registration and Use of User Account:
Purpose of data processing: Portfolio management within a closed user account.
Types of personal data: Email address; in case of registration with a Google account: name, email address.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, but no later than the deletion of the user account.
Sending Newsletters:
Purpose of data processing: Sending newsletters to inform about news and fresh articles.
Types of personal data: Email address.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, i.e., unsubscribing from the newsletter.
Data Controller's Presence on Social Media Platforms
The operators of social media platforms qualify as independent data controllers, therefore the data processing principles of the respective service providers apply to activities on social media platforms.The Data Controller is available on the following social media platforms:
| Social Media Site | Name and Address of Controller | Availability of Privacy Policy |
|---|
| Facebook | Meta Platforms, Inc. (1 Meta Way, Menlo Park, CA 94025) | Link |
| X | X Corp. (865 FM 1209, Building 2, Bastrop, TX 78602) | Link |
| LinkedIn | LinkedIn Ireland Unlimited Company (Wilton Plaza, Wilton Place, Dublin 2) | Link |
| Reddit | Reddit, Inc. (548 Market St. #16093, San Francisco, CA 94104) | Link |
| Discord | Discord, Inc. (444 De Haro Street, Suite 200, San Francisco, CA 94107) | Link |
Data Processors
The Data Controller engages the following data processors for data processing activities:
| Name of Processor | Address of Processor | Processor Task |
|---|
| DigitalOcean, LLC. | 105 Edgeview Drive, Ste. 425, Broomfield, CO 80021 | Hosting service (Physical location of servers: Frankfurt, Germany) |
| Google Ireland Ltd. | Gordon House, Barrow Street, Dublin 4 | Email system service (Google) |
| Sendinblue SAS | 17 rue Salneuve, 75017, Paris | Operation of newsletter sending system (Brevo) |
Information on Cookies
The website uses cookies which ensure the optimal functioning of the website. Cookies are small data files that are placed on the computer of the website visitor (the Data Subject) through the website usage, saved and stored by the Data Subject's internet browser. Most commonly used internet browsers accept and allow the download and use of cookies by default. However, it depends on the Data Subject whether they refuse or disable these by modifying the browser settings. Furthermore, the Data Subject can delete cookies already stored on the computer. The "Help" menu item of individual browsers provides more detailed information on the use of cookies. The Data Subject has the option to delete cookies in the Tools/Settings menu of the browser, generally under the Privacy menu item settings. You can view and set the cookies currently used on the website in the cookie manager pop-up window upon entering the website. We draw the Data Subject's attention to the fact that essential (necessary) cookies always remain in use to ensure the basic functioning of the website; however, these do not contain personal data. The use of all other types of cookies requires the Data Subject's consent. Further information on cookie settings for the most commonly used browsers can be found at the following links:
Google ChromeFirefoxBraveMicrosoft EdgeSafariLegal Remedy
Right to lodge a complaint with a supervisory authority (GDPR Article 77):Without prejudice to any other administrative or judicial remedy, every Data Subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the processing of personal data relating to him or her infringes the GDPR Regulation.
Contact Details of Data Protection Supervisory Authorities:European Union:| Country | Authority Name | Address | Website |
|---|
| Austria | Österreichische Datenschutzbehörde | Barichgasse 40-42, 1030 Wien | www.dsb.gv.at |
| Belgium | Autorité de la protection des données | Rue de la Presse 35, 1000 Brussels | www.autoriteprotectiondonnees.be |
| Bulgaria | Commission for Personal Data Protection | 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia | www.cpdp.bg |
| Croatia | Agencija za zaštitu osobnih podataka | Ulica Metela Ožegovića 16, 10000 Zagreb | www.azop.hr |
| Cyprus | Commissioner for Personal Data Protection | 15 Kypranoros Street, 1061 Nicosia | www.dataprotection.gov.cy |
| Czech Republic | Office for Personal Data Protection | Pplk. Sochora 27, 170 00 Prague 7 | uoou.gov.cz |
| Denmark | Datatilsynet | Carl Jacobsens Vej 35, 2500 Valby | www.datatilsynet.dk |
| Estonia | Estonian Data Protection Inspectorate | Tatari 39, 10134 Tallinn | www.aki.ee |
| Finland | Office of the Data Protection Ombudsman | P.O. Box 800, FI-00531 Helsinki | www.tietosuoja.fi |
| France | CNIL | 3 Place de Fontenoy, TSA 80715 – 75334 Paris Cedex 07 | www.cnil.fr |
| Germany | Die Bundesbeauftragte für den Datenschutz... | Graurheindorfer Straße 153, 53117 Bonn | www.bfdi.bund.de |
| Greece | Hellenic Data Protection Authority | Kifisias Av. 1-3, 11523 Athens | www.dpa.gr |
| Hungary | NAIH | Falk Miksa u. 9-11, H-1055 Budapest | www.naih.hu |
| Ireland | Data Protection Commission | 6 Pembroke Row, D02 X963 Dublin 2 | www.dataprotection.ie |
| Italy | Garante per la protezione dei dati personali | Piazza Venezia, 11, 00187 Roma | www.garanteprivacy.it |
| Latvia | Data State Inspectorate | Elijas Street 17, LV-1050 Riga | www.dvi.gov.lv |
| Lithuania | State Data Protection Inspectorate | L. Sapiegos str. 17, LT-10312 Vilnius | vdai.lrv.lt |
| Malta | Office of the Information and Data Protection Commissioner | High Street, SLM 1549 Sliema | www.idpc.org.mt |
| Netherlands | Autoriteit Persoonsgegevens | P.O. Box 93374, 2509 AJ Den Haag | autoriteitpersoonsgegevens.nl |
| Poland | Urząd Ochrony Danych Osobowych | ul. Stawki 2, 00-193 Warsaw | uodo.gov.pl |
| Portugal | CNPD | Av. D. Carlos I, 134, 1º, 1200-651 Lisboa | www.cnpd.pt |
| Romania | The National Supervisory Authority... | B-dul Magheru 28-30, Sector 1, Bucureşti | www.dataprotection.ro |
| Slovakia | Office for Personal Data Protection | Námestie 1. mája 18, 811 06 Bratislava | www.dataprotection.gov.sk |
| Slovenia | Information Commissioner | Dunajska 22, 1000 Ljubljana | www.ip-rs.si |
| Spain | Agencia Española de Protección de Datos | C/Jorge Juan, 6, 28001 Madrid | www.aepd.es |
| Sweden | Integritetsskyddsmyndigheten | Fleminggatan 14, Box 8114, 104 20 Stockholm | www.imy.se |
European Economic Area:Right to an effective judicial remedy against a controller or processor (GDPR Article 79):Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77 of the GDPR, each Data Subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under the GDPR Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with the Regulation. Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Such proceedings may also be brought before the courts of the Member State where the Data Subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.