Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how the personal data of the people who use the Evitalya service ("the Service"), provided through evitalya.com, is processed under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 on the protection of personal data. The data controller is established in Italy and your data is processed in the European Union.
1. Data Controller
Via Friuli 11, 60123 Ancona (AN) — Italy
VAT no. (Partita IVA): 02935230421
Email: info@evitalya.com
We are not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. Any request concerning data protection can be sent to the email address above.
2. Data Processed, Purposes and Legal Bases
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, password (stored only as a bcrypt hash), account status | Account creation and authentication | Performance of the contract (Art. 6(1)(b) GDPR) |
| Google account identifier and email (when "Sign in with Google" is used) | Authentication | Performance of the contract (Art. 6(1)(b) GDPR) |
| Address analysed, reports generated, credit movements | Providing the Service and giving you access to your report history | Performance of the contract (Art. 6(1)(b) GDPR) |
| Payment data (card details never reach us; they are processed by Stripe) | Collecting payment | Performance of the contract (Art. 6(1)(b) GDPR) |
| Invoicing data: name, billing address and country, tax identification number where applicable | Issuing the invoice and determining the correct tax | Legal obligation (Art. 6(1)(c) GDPR) |
| Withdrawal/consent record: time of consent, IP address, version of the terms accepted | Proof of prior information and of explicit consent | Legal obligation (Art. 6(1)(c) GDPR) |
| IP address, browser information, request logs | Security, prevention of abuse and fraud, rate limiting; choosing the page language (country only, not stored) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Anonymised usage statistics (page views, number of searches) | Improving the Service | Explicit consent — your cookie preference (Art. 6(1)(a) GDPR) |
| Contact form: name, email, message content | Replying to your request | Pre-contractual request / legitimate interest (Art. 6(1)(b), 6(1)(f) GDPR) |
We do not carry out profiling, we do not apply automated decision-making, and we do not send commercial communications without your explicit consent. We do not sell personal data to third parties. The livability score is an indicator about addresses, not about people.
2-bis. Payment Reminder
If you open the payment page and leave without completing the transaction, we may send you a one-off reminder email using your email address and the contents of your basket (the credit package).
- Legal basis: Art. 6(1)(a) of Regulation 2016/679 (the consent you give at the time of purchase, recorded together with the date, IP address and version of the text accepted) and Art. 130 of Italian Legislative Decree 196/2003.
- Frequency: at most one message every seven days to the same address.
- Opting out: every message contains a one-click unsubscribe link. The unsubscribe record is not deleted — if it were, we would start writing to you again.
- Retention: the send record and the unsubscribe record are kept in order to prove that the opt-out was honoured.
This does not cover the transactional emails sent to perform the contract (payment confirmation, invoice, sign-in link); those are not affected by the opt-out. See Terms of Service, section 18.
3. Cookies and Similar Technologies
The Service uses cookies in three categories. You can change your preferences at any time:
| Category | Use | Consent |
|---|---|---|
| Necessary | Session management, security, remembering your cookie preference, theme choice, language choice | Not required (cannot be disabled) |
| Analytics | Anonymised usage statistics. Loaded only if you give consent. | Explicit consent — default: off |
| Marketing | Not used at present. If the category is used in future, it will be enabled only with your consent. | Explicit consent — default: off |
Third-party components. Some pages embed third-party services which may use their own cookies or similar technologies:
- Stripe — payment page and fraud prevention.
- Google Maps / Street View — the map and street view components on the report page.
- Google Fonts — serving the typefaces.
- OpenFreeMap / MapLibre — open map layers.
You can change or withdraw your cookie preferences at any time from the "Cookie Settings" link at the bottom of the page. You can also delete or block cookies from your browser settings; in that case some parts of the Service may not work properly.
4. Processors and Recipients
We rely on the following providers to deliver the Service:
- Stripe Payments Europe, Ltd. / Stripe, Inc. — payment processing. stripe.com/privacy
- Google Ireland Ltd. / Google LLC — "Sign in with Google" authentication, Google Maps and Street View, Google Fonts. policies.google.com/privacy
- Hostinger International Ltd. — server hosting (data centre within the European Union).
- Our email server provider — delivery of transactional emails (account verification, report notification, invoice).
- FatturaElettronicaAPI.it — issuing electronic invoices and transmitting them to the SDI. Privacy policy
- Tek01 S.r.l. — electronic invoice receiving intermediary (SDI code N92GLON), Trieste, Italy.
These providers act as data processors under Art. 28 GDPR and on our instructions. Personal data may also be shared with the competent public authorities where a legal obligation applies.
5. Transfers Outside the EU
Our servers are located in the European Union. Stripe and Google may also process data in the United States. Those transfers take place under the Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework. Apart from these, your data is not transferred outside the European Union.
6. Retention Periods
The periods applied under Art. 5(1)(e) GDPR (storage limitation) are set out in the table below only:
| Data category | Retention period | Notes |
|---|---|---|
| Account data (email, password hash, credit balance) | For as long as the account remains open | Deleted within 30 days of the account being closed. |
| Report history and addresses analysed | For as long as the account remains open | Access to purchased reports is permanent; they are deleted when the account is closed. |
| Analytics data (session, page views, searches) | 90 days | The IP address is stored anonymised and hashed; it is deleted automatically after 90 days. |
| Security and rate-limiting logs | 90 days | For the prevention of abuse. |
| Incomplete payment sessions | 90 days | Failed or abandoned payment attempts are deleted automatically. |
| Webhook processing records | 90 days | Technical idempotency records. |
| Payment, invoice and consent records | 10 years | Required by Italian tax and accounting law (Art. 2220 Italian Civil Code; Art. 39 of Presidential Decree 633/1972). |
| Contact form messages | 24 months | After the request has been closed. |
Automatic deletion runs daily. Data not subject to a legal retention obligation is deleted within 30 days of your deletion request; mandatory data such as invoice and payment records continues to be kept until the relevant legal period expires.
7. Your Rights
Under Articles 15-22 GDPR you have the following rights:
- Access: to know whether your data is being processed and to obtain a copy of it.
- Rectification: to ask for incorrect or incomplete data to be corrected.
- Erasure: to ask for deletion, subject to legal obligations.
- Restriction: to ask for processing to be restricted in certain cases.
- Portability: to receive the data in a structured, machine-readable format.
- Objection: to object to processing based on legitimate interest.
- Withdrawal of consent: to stop consent-based processing (e.g. analytics cookies) at any time; withdrawal does not affect the lawfulness of processing carried out beforehand.
To exercise your rights, write to info@evitalya.com; we reply within 30 days at the latest.
Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome, Italy — www.gpdp.it
8. Security
We take appropriate technical and organisational measures to protect personal data: TLS/SSL encryption for all traffic, passwords stored only as a bcrypt hash, access limited to authorised people, encrypted backups, intrusion monitoring and access logs. In the event of a personal data breach we notify the supervisory authority and, where required, you, under Articles 33-34 GDPR.
9. Changes to this Policy
We may update this Privacy Policy. Material changes are announced by email or on the site. The date of the last update appears at the top of this page.
This text is provided in six languages. In the event of any discrepancy between the versions, the Turkish version prevails.