1. PERSONAL DATA CONTROLLER
1.1. The Personal Data Controller is a citizen of the Russian Federation, Bogdan Sergeevich Movchan, a taxpayer of the professional income tax (self-employed) (hereinafter referred to as the "Controller", "Administration", "we", "us").
1.2. This Privacy Policy (hereinafter referred to as the "Policy") defines the procedure for processing and protecting the personal data of Users of the EyesOnAssets Service.
1.3. IMPORTANT: This Policy describes the procedure for processing personal data. Consent to the processing of personal data is given by the User through an affirmative action (checking a box during registration or when using functionality that requires the processing of personal data). Mere use of the Service without active consent does not constitute consent to the processing of personal data, except for technical data (IP, user-agent, cookies), which may be processed on legal grounds provided by Federal Law No. 152-FZ (Article 6, Part 1, Clause 5 — processing is necessary for the functioning of the service). If the User does not agree with the terms of the Policy, they must immediately stop using the Service and not provide their personal data.
2. BASIC TERMS AND DEFINITIONS
2.1. Personal data — any information relating directly or indirectly to a specific or identifiable natural person (data subject).
2.2. Controller — the person who organizes and/or carries out the processing of personal data.
2.3. Processing of personal data — any action (operation) or set of actions (operations) performed using automation means or without such means with personal data.
2.4. User — any legally capable natural person over 18 years of age using the Service.
2.5. Service — "EyesOnAssets" information and analytical screener, available on the Internet at eyesonassets.online (including the web version, PWA application, and other client interfaces).
3. LIST OF PERSONAL DATA COLLECTED
3.1. The Controller collects the following personal data of Users:
3.1.1. Data provided during registration:
- Email address;
- Password (encrypted);
- Username (if provided).
3.1.2. Technical data collected automatically:
- IP address;
- User-agent (browser and device information);
- Device type (desktop, mobile, tablet);
- Screen resolution;
- Pixel ratio;
- Interface language.
3.1.3. User activity data within the Service:
- Financial instruments (symbols, e.g., BTC/USDT) that the User views or adds to favorites. This data is collected solely for functionality (synchronization of favorites and alerts) and is not analyzed to create a financial profile of the user.
- Alerts: price alerts created by the User (symbol, price, condition, type, notification settings).
- Drawings: horizontal lines created by the User on the chart.
- Favorites: list of favorite symbols, notes attached to them, set Take Profit and Stop Loss levels, color labels, group membership.
- Interface settings: selected theme (light/dark), candle color settings, screenshot watermark settings, alert sound and vibration settings.
- Trigger history: record of price alert triggers (time, price).
3.1.4. Data received via the feedback form:
- Email address (if provided by the User);
- Message text;
- Technical context: symbol, timeframe, market, exchange, PWA version, screen size, pixel ratio, device type, language, theme, authorization status, notification permission, sound and vibration settings, number of active alerts and drawings, etc.
3.1.5. Cookies: The Service may use cookies to operate (session persistence, settings). More details in Section 11.
3.1.6. The Service does NOT collect or process special categories of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, health, intimate life).
3.1.7. Payment data for paid services (the "Analytics" module, Public API): order identifier and payment status, chosen payment method (cryptocurrency / bank card / SBP) and subscription period, the email address an invoice is issued to. IMPORTANT: bank card details and cryptocurrency wallet private data are never transmitted to or stored by the Controller — payment is accepted directly by the payment processors Robokassa and NOWPayments, which operate under their own licenses and security rules (see 5.2.1).
3.1.8. For legal entities and sole proprietors registering for Public API access: organization name, contact email, chosen tariff plan. This data is processed solely to perform the contract (the Public Offer) and is not used for other purposes.
4. PURPOSES OF PERSONAL DATA PROCESSING
4.1. The Controller processes the User's personal data for the following purposes:
- 4.1.1. Provision of Service functionality:
Registration and authentication of the User. Creation, storage, and synchronization of alerts, drawings, favorites, and settings across devices. Display and real-time updating of exchange data (prices, volumes, order books, etc.).
- 4.1.2. Improvement and development of the Service:
Analysis of Service usage to identify errors, improve user experience, and develop new features. Collection of technical information (via the feedback form) for diagnostics and troubleshooting.
- 4.1.3. Communication with the User:
Responses to inquiries sent via the feedback form or email. Notifications about changes in the Service's operation, including the introduction of paid services. Sending informational messages (only with the User's consent).
- 4.1.4. Compliance with legislation:
Fulfillment of requirements of Federal Law No. 152-FZ "On Personal Data". Prevention of fraud, illegal actions, and violations of the Terms of Use.
- 4.1.5. Providing paid services:
Processing payments for the "Analytics" subscription and Public API plans via the payment processors Robokassa and NOWPayments, issuing invoices, granting and renewing access, and keeping payment records to the extent required by Russian tax and accounting legislation.
- 4.1.6. The legal basis for processing personal data is the User's consent expressed through an affirmative action (checking a box during registration), as well as the performance of a contract (Terms of Use and, for paid services, the Public Offer).
5. CONDITIONS OF PERSONAL DATA PROCESSING. CROSS-BORDER TRANSFER
5.1. The User's personal data is processed using automation means and without such means.
5.2. The Controller does NOT transfer the User's personal data to third parties, except in the following cases:
- 5.2.1. Technical providers: The Controller is entitled to engage third parties to ensure the operation of the Service (hosting, data storage, sending emails). Such parties undertake to maintain confidentiality and process personal data solely for the purposes determined by the Controller.
- 5.2.1a. Payment processors: to process payments for the "Analytics" subscription and Public API plans, the Controller shares the minimum necessary data (email, amount, order identifier) with the payment processors Robokassa (bank card and SBP payments) and NOWPayments (cryptocurrency payments). Both processors independently handle the payment-method data (card details, crypto wallet) and are separately responsible for its protection under the laws and payment-system rules applicable to them.
- 5.2.2. Analytics services: The Controller may use statistics collection systems such as Yandex.Metrica, Google Analytics, and others. These services collect anonymized data about User behavior on the Site. IP address anonymization will be enabled in the settings of these services. The use of such services requires separate User consent for cookie processing.
- 5.2.3. By legal requirement: The Controller is obliged to provide personal data upon request from authorized state bodies (e.g., Roskomnadzor, court) in accordance with the procedure established by the legislation of the Russian Federation.
- 5.2.4. Protection of the Controller's rights: In case of need to protect the rights and legitimate interests of the Controller or third parties (e.g., in case of violation of the Terms of Use).
5.3. Cross-border transfer of personal data:
- The servers used to store and process personal data are located on the territory of the Federal Republic of Germany (European Union).
- Germany is included in the list of countries providing adequate protection for the rights of personal data subjects (European Commission's adequacy decision, as well as Article 13 of the German Federal Data Protection Act).
- Thus, the Controller performs a cross-border transfer of personal data to Germany. Such transfer is carried out in compliance with the requirements of Federal Law No. 152-FZ (in particular, notification to Roskomnadzor if the volume of data exceeds established thresholds). The Controller does not transfer data to other countries.
6. PERSONAL DATA RETENTION PERIODS
6.1. The User may delete their account at any time through the Service interface or by sending a request to contact@eyesonassets.online. In this case, all personal data associated with the account will be deleted without the possibility of recovery within 30 (thirty) days.
6.2. If the User does not delete their account, data is stored until consent is withdrawn or the account is deleted. Automatic deletion due to inactivity does not apply.
6.3. Data sent via the feedback form is stored for no more than 12 months from the date of submission, after which it is deleted.
6.4. Anonymized statistical information collected using analytics services may be stored indefinitely.
6.5. Payment records for the "Analytics" subscription and Public API (order identifier, amount, status, date) are retained for the period required by Russian tax and accounting legislation applicable to self-employed NPD taxpayers, regardless of whether the User's account has been deleted.
7. USER RIGHTS (PERSONAL DATA SUBJECTS)
7.1. In accordance with Federal Law No. 152-FZ "On Personal Data", the User has the right to:
- Receive information about the processing of their personal data.
- Request rectification, blocking, or destruction of their personal data if it is incomplete, outdated, inaccurate, or obtained unlawfully.
- Withdraw consent to the processing of personal data.
- Appeal the Controller's actions or inaction to the competent authority (Roskomnadzor) or in court.
7.2. Additional rights for Users from the European Union (GDPR):
- Right of access (Article 15): to obtain confirmation of whether your data is being processed and to obtain a copy of that data.
- Right to rectification (Article 16): to request the correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") (Article 17): to request the deletion of your personal data when there is no legal basis for its processing.
- Right to restriction of processing (Article 18): to request restriction of processing of your data in certain cases.
- Right to data portability (Article 20): to receive your data in a machine-readable format and transfer it to another controller.
- Right to object (Article 21): to object to the processing of your data, including processing for marketing purposes.
7.3. The User may exercise all the above rights by sending a request to contact@eyesonassets.online.
8. PERSONAL DATA PROTECTION MEASURES
8.1. The Controller takes necessary organizational and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, distribution, as well as from other unlawful actions of third parties.
8.2. Such measures include:
- Use of the secure HTTPS protocol for data transmission.
- Encryption (hashing) of User passwords.
- Regular software updates.
- Restricting access to personal data to any third parties except authorized technical providers.
9. CONTROLLER'S LIABILITY
9.1. The Controller is liable for non-fulfillment or improper fulfillment of obligations regarding the processing of personal data in accordance with the legislation of the Russian Federation, including:
- Fines under Article 13.11 of the Code of Administrative Offenses of the Russian Federation (violation of personal data processing procedures).
- Fines under Article 19.7 of the Code of Administrative Offenses of the Russian Federation (failure to provide information to Roskomnadzor).
- Criminal liability under Article 137 of the Criminal Code of the Russian Federation (violation of privacy).
9.2. IMPORTANT: The Controller is not liable for losses resulting from disclosure of the User's personal data if such disclosure occurred due to the User's own fault (e.g., sharing credentials with third parties) or due to force majeure circumstances.
10. CHANGES TO THE PRIVACY POLICY
10.1. The Controller has the right to make changes to this Policy. The current version is always available in the Service.
10.2. The Controller notifies the User of changes to the Policy at least 15 calendar days in advance through the Service interface and/or by email. If the changes significantly expand the purposes or scope of processed data, the Controller will request new consent from the User. Continued use of the Service after the changes take effect constitutes acceptance of the new version.
11. COOKIES
11.1. The Service uses cookies to ensure operation (authentication session persistence, storing interface settings). A cookie is a small piece of data sent by a web server and stored on the User's computer.
11.2. The use of analytics services (e.g., Yandex.Metrica, Google Analytics) requires separate User consent for cookie processing. A corresponding notice (cookie banner) will appear upon first visit to the Service.
11.3. The User can disable cookies in their browser settings, but this may affect the functionality of some features of the Service.
12. ADDITIONAL TERMS
12.1. The Privacy Policy is an integral part of the Terms of Use.
12.2. This Policy is governed by the laws of the Russian Federation.
13. CONTACT INFORMATION
Citizen of the Russian Federation: Bogdan Sergeevich Movchan
Status: taxpayer of the professional income tax (self-employed)
Address: Nizhny Novgorod
Contact email: contact@eyesonassets.online
Service domain: eyesonassets.online