Privacy Policy
Effective Date: January 12, 2026
Data Controller Information
Company Name: Skyfall Technology OÜ
Registered Office: Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 139b, 11317
Registration Number: 16943755
Represented by: Bálint Zsolt Kuhár, Member of the Management Board
Email Address: [email protected] (hereinafter referred to as: Data Controller)
Purpose of the Privacy Policy
This Privacy Policy contains information regarding data processing related to visitors of the website iocharts.io and users of the website's content (hereinafter referred to as: Data Subject).

In this Privacy Policy, the Data Controller informs the Data Subject about which data processing activities it performs, in what manner, and on what legal basis, as well as the technical conditions applied, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – hereinafter GDPR).
Definitions
  • Personal data: Any information relating to an identified or identifiable natural person.
  • Identifiable natural person: A natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
  • Data processing: Performing technical tasks connected to data processing operations (irrespective of the method and means used for executing the operations, as well as the place of execution).
  • Processor: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • Data Subject: Any natural person identified or otherwise – directly or indirectly – identifiable on the basis of specific personal data. A person is considered identifiable in particular if they can be identified, directly or indirectly, by reference to a name, an identification number, or to one or more factors specific to their physical, physiological, mental, economic, cultural or social identity.

Rights of the Data Subject
During the period of data processing, the Data Controller continuously ensures the rights recorded in the GDPR, which are as follows:
  • Right to information [GDPR Recital (60)]: The principle of fair and transparent processing requires that the Data Subject be informed of the existence of the processing operation and its purposes.
  • Right of access by the Data Subject (GDPR Article 15): The Data Subject has the right to obtain from the Data Controller confirmation as to whether or not personal data concerning them are being processed, and, where that is the case, access to the personal data and the following information:
    • the purposes of the processing;
    • the categories of personal data concerned;
    • the recipients to whom the personal data have been disclosed;
    • the envisaged period for which the personal data will be stored.
  • Right to rectification (GDPR Article 16): The Data Subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
  • Right to erasure (‘right to be forgotten’) (GDPR Article 17): The Data Subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay and the Data Controller has the obligation to erase personal data without undue delay where one of the following grounds applies:
    • the personal data are no longer necessary in relation to the purposes for which they were collected;
    • the Data Subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
    • the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
    • the personal data have been unlawfully processed;
    • the personal data have to be erased for compliance with a legal obligation in Union or Member State law.
  • Right to restriction of processing (GDPR Article 18): The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:
    • the accuracy of the personal data is contested by the Data Subject;
    • the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead.
  • Right to data portability (GDPR Article 20): The Data Subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller.
  • Right to object (GDPR Article 21): The Data Subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them.
  • Automated individual decision-making (GDPR Article 22): The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Principles Relating to Processing of Personal Data
Based on Article 5, Chapter II of the GDPR, the principles relating to processing of personal data are:
Personal data shall be:
  • processed lawfully, fairly and in a transparent manner in relation to the Data Subject (lawfulness, fairness and transparency);
  • collected for specified, explicit and legitimate purposes (purpose limitation);
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimization);
  • accurate and, where necessary, kept up to date (accuracy);
  • kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation);
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (integrity and confidentiality).
  • The Data Controller shall be responsible for, and be able to demonstrate compliance with, these principles (accountability).

Data Processing Activities at the Data Controller
The Data Controller performs the following data processing activities affecting personal data.

Contact via Email:
Purpose of data processing: Contacting the Data Controller, inquiries, requesting information.
Types of personal data: Name, email address, phone number, other personal data provided by the Data Subject in the message.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, but no later than the end of the 1st year following the Data Controller's response to the message or the last contact.
Data Processing Related to Registration and Use of User Account:
Purpose of data processing: Portfolio management within a closed user account.
Types of personal data: Email address; in case of registration with a Google account: name, email address.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, but no later than the deletion of the user account.
Sending Newsletters:
Purpose of data processing: Sending newsletters to inform about news and fresh articles.
Types of personal data: Email address.
Legal basis for data processing: The Data Subject's consent [GDPR Article 6(1)(a)].
Duration of data processing: Until the withdrawal of consent, i.e., unsubscribing from the newsletter.
Data Controller's Presence on Social Media Platforms
The operators of social media platforms qualify as independent data controllers, therefore the data processing principles of the respective service providers apply to activities on social media platforms.The Data Controller is available on the following social media platforms:
Social Media SiteName and Address of ControllerAvailability of Privacy Policy
FacebookMeta Platforms, Inc. (1 Meta Way, Menlo Park, CA 94025)Link
XX Corp. (865 FM 1209, Building 2, Bastrop, TX 78602)Link
LinkedInLinkedIn Ireland Unlimited Company (Wilton Plaza, Wilton Place, Dublin 2)Link
RedditReddit, Inc. (548 Market St. #16093, San Francisco, CA 94104)Link
DiscordDiscord, Inc. (444 De Haro Street, Suite 200, San Francisco, CA 94107)Link
Data Processors
The Data Controller engages the following data processors for data processing activities:
Name of ProcessorAddress of ProcessorProcessor Task
DigitalOcean, LLC.105 Edgeview Drive, Ste. 425, Broomfield, CO 80021Hosting service (Physical location of servers: Frankfurt, Germany)
Google Ireland Ltd.Gordon House, Barrow Street, Dublin 4Email system service (Google)
Sendinblue SAS17 rue Salneuve, 75017, ParisOperation of newsletter sending system (Brevo)
Information on Cookies
The website uses cookies which ensure the optimal functioning of the website. Cookies are small data files that are placed on the computer of the website visitor (the Data Subject) through the website usage, saved and stored by the Data Subject's internet browser. Most commonly used internet browsers accept and allow the download and use of cookies by default. However, it depends on the Data Subject whether they refuse or disable these by modifying the browser settings. Furthermore, the Data Subject can delete cookies already stored on the computer. The "Help" menu item of individual browsers provides more detailed information on the use of cookies. The Data Subject has the option to delete cookies in the Tools/Settings menu of the browser, generally under the Privacy menu item settings. You can view and set the cookies currently used on the website in the cookie manager pop-up window upon entering the website. We draw the Data Subject's attention to the fact that essential (necessary) cookies always remain in use to ensure the basic functioning of the website; however, these do not contain personal data. The use of all other types of cookies requires the Data Subject's consent. Further information on cookie settings for the most commonly used browsers can be found at the following links:

Google Chrome
Firefox
Brave
Microsoft Edge
Safari
Legal Remedy
Right to lodge a complaint with a supervisory authority (GDPR Article 77):
Without prejudice to any other administrative or judicial remedy, every Data Subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the processing of personal data relating to him or her infringes the GDPR Regulation.

Contact Details of Data Protection Supervisory Authorities:

European Union:

CountryAuthority NameAddressWebsite
AustriaÖsterreichische DatenschutzbehördeBarichgasse 40-42, 1030 Wienwww.dsb.gv.at
BelgiumAutorité de la protection des donnéesRue de la Presse 35, 1000 Brusselswww.autoriteprotectiondonnees.be
BulgariaCommission for Personal Data Protection2 Prof. Tsvetan Lazarov Blvd., 1592 Sofiawww.cpdp.bg
CroatiaAgencija za zaštitu osobnih podatakaUlica Metela Ožegovića 16, 10000 Zagrebwww.azop.hr
CyprusCommissioner for Personal Data Protection15 Kypranoros Street, 1061 Nicosiawww.dataprotection.gov.cy
Czech RepublicOffice for Personal Data ProtectionPplk. Sochora 27, 170 00 Prague 7uoou.gov.cz
DenmarkDatatilsynetCarl Jacobsens Vej 35, 2500 Valbywww.datatilsynet.dk
EstoniaEstonian Data Protection InspectorateTatari 39, 10134 Tallinnwww.aki.ee
FinlandOffice of the Data Protection OmbudsmanP.O. Box 800, FI-00531 Helsinkiwww.tietosuoja.fi
FranceCNIL3 Place de Fontenoy, TSA 80715 – 75334 Paris Cedex 07www.cnil.fr
GermanyDie Bundesbeauftragte für den Datenschutz...Graurheindorfer Straße 153, 53117 Bonnwww.bfdi.bund.de
GreeceHellenic Data Protection AuthorityKifisias Av. 1-3, 11523 Athenswww.dpa.gr
HungaryNAIHFalk Miksa u. 9-11, H-1055 Budapestwww.naih.hu
IrelandData Protection Commission6 Pembroke Row, D02 X963 Dublin 2www.dataprotection.ie
ItalyGarante per la protezione dei dati personaliPiazza Venezia, 11, 00187 Romawww.garanteprivacy.it
LatviaData State InspectorateElijas Street 17, LV-1050 Rigawww.dvi.gov.lv
LithuaniaState Data Protection InspectorateL. Sapiegos str. 17, LT-10312 Vilniusvdai.lrv.lt
MaltaOffice of the Information and Data Protection CommissionerHigh Street, SLM 1549 Sliemawww.idpc.org.mt
NetherlandsAutoriteit PersoonsgegevensP.O. Box 93374, 2509 AJ Den Haagautoriteitpersoonsgegevens.nl
PolandUrząd Ochrony Danych Osobowychul. Stawki 2, 00-193 Warsawuodo.gov.pl
PortugalCNPDAv. D. Carlos I, 134, 1º, 1200-651 Lisboawww.cnpd.pt
RomaniaThe National Supervisory Authority...B-dul Magheru 28-30, Sector 1, Bucureştiwww.dataprotection.ro
SlovakiaOffice for Personal Data ProtectionNámestie 1. mája 18, 811 06 Bratislavawww.dataprotection.gov.sk
SloveniaInformation CommissionerDunajska 22, 1000 Ljubljanawww.ip-rs.si
SpainAgencia Española de Protección de DatosC/Jorge Juan, 6, 28001 Madridwww.aepd.es
SwedenIntegritetsskyddsmyndighetenFleminggatan 14, Box 8114, 104 20 Stockholmwww.imy.se


European Economic Area:

CountryAuthority NameAddressContact Details
IcelandPersónuverndLaugavegur 166, 4. hæð
105 Reykjavík, Ísland
Website: island.is/s/personuvernd
Email: [email protected]
Phone: 510 9600
LiechtensteinData Protection AuthorityKirchstrasse 8
9490 Vaduz, Liechtenstein
Website: www.datenschutzstelle.li
Email: [email protected]
Phone: +423 236 6090
NorwayDatatilsynetP.O. Box 458 Sentrum
0150 Oslo, Norway
Website: www.datatilsynet.no
Email: [email protected]
Phone: +47 22 39 69 00


Right to an effective judicial remedy against a controller or processor (GDPR Article 79):
Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77 of the GDPR, each Data Subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under the GDPR Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with the Regulation. Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Such proceedings may also be brought before the courts of the Member State where the Data Subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.