1. Who we are
charliedesk is an independent crypto media site at charliedesk.com (the "site"). We publish analyses, market data, exchange and coin overviews, regulation and tax coverage.
The site is operated by CAP-NET s.r.o., company ID 25466640, VAT ID CZ25466640, registered office at 1. máje 476/53, Liberec III-Jeřáb, 460 07 Liberec, Czech Republic, represented by its managing director Milan Litvan (referred to as "we" or "the operator"). We are the data controller.
For anything related to personal data, write to hello@charliedesk.com. We have not appointed a data protection officer, because we do not meet the conditions under which the GDPR requires one.
2. What we do not do
Without your consent, no analytics, no marketing tools and nothing that tracks you runs on the site. We do not sell or rent personal data and we do not carry out automated decision-making with legal effects. Anything beyond what the site strictly needs to work starts only after you consent in the cookie banner.
Google's analytics and marketing cookies (Google Analytics loaded through Google Tag Manager) are switched on only if you allow them in the cookie banner. Until you consent, no Google code loads on the page at all. You can withdraw your consent at any time via the "Cookie settings" link in the site footer.
If you simply read the site, do not sign in and do not allow cookies in the banner, we create no account for you and do not track you in any way. We only process the server logs described in section 3.
3. What data we process
Account and sign-in
You can create an account in four ways, and the data we hold depends on which one you pick:
- E-mail (magic link): your e-mail address. The link carries a single-use token that we store only as a hash, valid for a short time and invalidated once used.
- Wallet (Sign-In with Ethereum): the public address of your wallet. We never have access to your private key or to any funds.
- Passkey: a public key and a credential identifier. Your biometrics or PIN never leave your device and we never see them.
- Google account: your Google identifier, e-mail address, and name or profile picture if Google provides them.
For every account we also keep the creation date, the last sign-in date, the role and the membership tier. The creation date also weights your exchange ratings, so that freshly created accounts cannot easily skew the results.
Exchange ratings and comments
When you rate an exchange we store your scores, an optional comment and the link to your account. The rating is public but is shown without your e-mail address. Reports of inappropriate content are recorded for moderation.
Newsletter
If you subscribe, we store your e-mail address, chosen language and subscription status. You can unsubscribe at any time using the link in every e-mail or by writing to hello@charliedesk.com.
Paid membership
Payments are handled by the Stripe payment gateway. Card numbers never reach us. From Stripe we store only the customer and subscription identifiers, the subscription status and the end of the billing period, so that we can unlock the paid section for you.
Analytics and marketing (only with consent)
If you allow cookies in the banner, we use Google Analytics 4 to measure the pages you view, your approximate city-level location, your device and browser type, and where you arrived from. The consent also covers Google marketing features (Google Signals): aggregate demographic reports and campaign measurement. Google may link this data to your Google account under its own terms. Individual records are deleted after 14 months at the latest.
Server logs
The server and its protective layer keep ordinary technical access logs, which may contain an IP address, request time, page address and browser type. They serve only to keep the site running, to debug errors and to defend against attacks, and are deleted automatically within days to weeks.
4. Why we process it and on what legal basis
- Running your account and unlocking the paid section: performance of the contract you enter into by accepting the terms of use.
- Newsletter: your consent, which you can withdraw at any time.
- Analytics and marketing cookies: your consent given in the cookie banner, which you can withdraw at any time in the site footer.
- Exchange ratings, their moderation and abuse prevention: our legitimate interest in keeping ratings trustworthy.
- Site security, attack and abuse prevention: our legitimate interest in secure operation.
- Accounting and tax records for paid services: compliance with a legal obligation.
- Answering your questions and complaints: our legitimate interest in communicating with readers, or compliance with a legal obligation.
7. How long we keep data
- Account data: for as long as the account exists. Once deleted, we erase or irreversibly anonymise it.
- Sign-in tokens: minutes. They stop working once used or expired and are deleted continuously.
- Exchange ratings: for as long as they are published. After account deletion we detach them from your identity so that the public rating keeps its meaning.
- Newsletter: until you unsubscribe.
- Accounting and tax records: for the period required by accounting and tax law.
- Server logs: days to weeks.
- Your cookie-banner choice: 12 months.
- Analytics data: individual records for 14 months at most, aggregate statistics beyond that.
8. Your rights
In relation to your personal data you have the right:
- to access your data and receive a copy,
- to have inaccurate data corrected,
- to erasure (the "right to be forgotten"),
- to restriction of processing,
- to data portability in a machine-readable format,
- to object to processing based on legitimate interest,
- to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before it.
Just write to hello@charliedesk.com. We will handle it within one month. You can also delete your account at any time in the Account section.
If you believe we are mishandling your data, you can lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority in your country of residence. We would appreciate the chance to put it right first.
9. Security
The site is served exclusively over encrypted HTTPS. Sign-in tokens are stored only as hashes and we do not use passwords at all. Database access is limited to the necessary people and systems.
No measure is perfect. Should a security breach occur that poses a risk to your rights, we will notify the supervisory authority and you within the statutory deadlines.
10. Children
The site is not intended for children under 16 and we do not knowingly create accounts for them. If we find that we hold such an account, we delete it.
11. Changes to this policy
We may update this policy when the site or the law changes. We will always publish the new version with its effective date. For material changes we will notify registered readers by e-mail.
