Last updated: March 15, 2026 · Version 2.0
Note: This policy is a template based on common GDPR compliance patterns. It has not been reviewed by a qualified legal professional.
This Privacy Policy explains how Torchinsky Executive Consulting ("we", "us", "our", the "Controller") collects, uses, stores, and protects your personal data when you use AlgoTradingMap.com (the "Service"). We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable data protection legislation.
Torchinsky Executive Consulting
Mike Torchinsky
Email: mike@torchinsky.net
Website: torchinsky.net
We are the data controller responsible for your personal data. As a small business with limited data processing volume, we have not appointed a Data Protection Officer (DPO) but handle all privacy inquiries directly at mike@torchinsky.net.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide and maintain the Service | Account info, usage data | Contract performance (Art. 6(1)(b)) |
| Process subscription payments | Email, payment metadata | Contract performance (Art. 6(1)(b)) |
| Resume scanning and matching | Resume content | Consent (Art. 6(1)(a)) - you initiate the scan |
| Salary report generation | Firm data, compensation data | Contract performance (Art. 6(1)(b)) |
| Job alert notifications | Email, alert preferences | Consent (Art. 6(1)(a)) |
| Display recruiter/firm information | Public professional data | Legitimate interest (Art. 6(1)(f)) |
| Security and fraud prevention | IP address, usage patterns | Legitimate interest (Art. 6(1)(f)) |
| Service analytics and improvement | Aggregated usage data | Legitimate interest (Art. 6(1)(f)) |
| Respond to your inquiries | Contact info, message | Consent (Art. 6(1)(a)) |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
Where processing is based on legitimate interest, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms.
The Service uses automated processing tools for the following features:
None of these automated processes produce decisions with legal or similarly significant effects on you. All outputs are informational and advisory. You may contact us to request human review of any automated output.
Per GDPR Article 22: we do not make solely automated decisions that produce legal effects or significantly affect you.
We do not sell your personal data. We share data with the following categories of service providers who process data on our behalf under data processing agreements:
| Sub-processor | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase (PostgreSQL) | Database, authentication, edge functions | US (AWS) | Account data, usage data, all stored records |
| Stripe | Payment processing | US | Email, subscription details (Stripe stores payment cards, we never see full card numbers) |
| Anthropic (Claude API) | Resume scanning, salary reports | US | Resume content (temporary), firm data for report generation |
| xAI (Grok API) | Job search enhancement | US | Search queries only (no personal data) |
| Resend | Email delivery (job alerts, notifications) | US | Email address, notification content |
| NowPayments | Cryptocurrency payment processing | EU | Payment metadata only |
| Netlify | Website hosting and CDN | Global | Static assets only (no personal data stored) |
| logo.dev | Firm logo delivery | US | No personal data |
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) and the United Kingdom, primarily the United States.
For transfers to the US, we rely on:
We ensure that any international transfer of personal data is subject to appropriate safeguards as required by GDPR Articles 44-49.
| Data type | Retention period | Basis |
|---|---|---|
| Account data (email, auth) | Until account deletion or 24 months of inactivity | Contract |
| Salary submissions | Indefinitely (anonymized, not linked to identity) | Legitimate interest |
| Resume scans | 90 days after scan, then automatically deleted | Consent |
| Payment records | 7 years (tax/legal compliance) | Legal obligation |
| Job alert preferences | Until unsubscribed or account deletion | Consent |
| Usage logs / analytics | 12 months | Legitimate interest |
| Support correspondence | 24 months | Legitimate interest |
| Recruiter/firm data | Until removal is requested or data becomes outdated | Legitimate interest |
After the retention period, personal data is permanently deleted or anonymized so it can no longer be associated with you.
If you are in the EEA or UK, you have the following rights:
To exercise any of these rights, contact us at mike@torchinsky.net. We will respond within 30 days. If the request is complex, we may extend this by up to 60 additional days, and will inform you of any such extension.
We will not charge a fee for processing your request unless the request is manifestly unfounded or excessive.
You have the right to lodge a complaint with your local data protection supervisory authority:
If you are a California resident, you additionally have the right to:
To exercise CCPA/CPRA rights, contact mike@torchinsky.net with subject line "CCPA Request".
Categories of personal information collected in the preceding 12 months: identifiers (email), internet activity (usage data), geolocation (IP-derived, approximate). We do not sell personal information to third parties.
We use PostHog for product analytics to understand how users interact with the platform. PostHog collects anonymous usage data such as page views, feature interactions, and session duration. No advertising cookies or tracking pixels are used. We do NOT use any third-party behavioral advertising or cross-site tracking. See PostHog's privacy policy at posthog.com/privacy.
We implement the following technical and organizational measures to protect your data:
No system is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Articles 33 and 34.
The Service is intended for professionals in the financial industry and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.
The Service displays professional information about firms, recruiters, founders, and executives sourced from public company websites and career pages, public professional profiles (LinkedIn), regulatory filings and public databases, and community submissions and industry knowledge.
Legal basis: Legitimate interest in providing a comprehensive industry reference platform (GDPR Article 6(1)(f)). We have conducted a balancing test and determined that our interest in providing industry transparency does not override the rights of the data subjects, given that all displayed information is already publicly available in professional contexts.
Data subjects' rights: Individuals whose data appears on the Service may request correction, update, or removal of their information by contacting mike@torchinsky.net. We respond to valid requests within 30 days.
We do not display personal contact information (personal email addresses, phone numbers, home addresses) without consent. Only professional information is displayed.
We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the Service. The "Last updated" date at the top will always reflect the most recent revision.
Continued use of the Service after changes constitutes acceptance of the updated policy. If you do not agree with a change, you may delete your account at any time.