Skip to content

Privacy Policy

Last updated: 8 September 2026

This Privacy Policy explains how the personal data of the people who use the Evitalya service ("the Service"), provided through evitalya.com, is processed under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 on the protection of personal data. The data controller is established in Italy and your data is processed in the European Union.

1. Data Controller

FlipHouse di Rozzi Francesco
Via Friuli 11, 60123 Ancona (AN) — Italy
VAT no. (Partita IVA): 02935230421
Email: info@evitalya.com

We are not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. Any request concerning data protection can be sent to the email address above.

2. Data Processed, Purposes and Legal Bases

DataPurposeLegal basis
Email address, password (stored only as a bcrypt hash), account status Account creation and authentication Performance of the contract (Art. 6(1)(b) GDPR)
Google account identifier and email (when "Sign in with Google" is used) Authentication Performance of the contract (Art. 6(1)(b) GDPR)
Address analysed, reports generated, credit movements Providing the Service and giving you access to your report history Performance of the contract (Art. 6(1)(b) GDPR)
Payment data (card details never reach us; they are processed by Stripe) Collecting payment Performance of the contract (Art. 6(1)(b) GDPR)
Invoicing data: name, billing address and country, tax identification number where applicable Issuing the invoice and determining the correct tax Legal obligation (Art. 6(1)(c) GDPR)
Withdrawal/consent record: time of consent, IP address, version of the terms accepted Proof of prior information and of explicit consent Legal obligation (Art. 6(1)(c) GDPR)
IP address, browser information, request logs Security, prevention of abuse and fraud, rate limiting; choosing the page language (country only, not stored) Legitimate interest (Art. 6(1)(f) GDPR)
Anonymised usage statistics (page views, number of searches) Improving the Service Explicit consent — your cookie preference (Art. 6(1)(a) GDPR)
Contact form: name, email, message content Replying to your request Pre-contractual request / legitimate interest (Art. 6(1)(b), 6(1)(f) GDPR)

We do not carry out profiling, we do not apply automated decision-making, and we do not send commercial communications without your explicit consent. We do not sell personal data to third parties. The livability score is an indicator about addresses, not about people.

2-bis. Payment Reminder

If you open the payment page and leave without completing the transaction, we may send you a one-off reminder email using your email address and the contents of your basket (the credit package).

This does not cover the transactional emails sent to perform the contract (payment confirmation, invoice, sign-in link); those are not affected by the opt-out. See Terms of Service, section 18.

3. Cookies and Similar Technologies

The Service uses cookies in three categories. You can change your preferences at any time:

CategoryUseConsent
Necessary Session management, security, remembering your cookie preference, theme choice, language choice Not required (cannot be disabled)
Analytics Anonymised usage statistics. Loaded only if you give consent. Explicit consent — default: off
Marketing Not used at present. If the category is used in future, it will be enabled only with your consent. Explicit consent — default: off

Third-party components. Some pages embed third-party services which may use their own cookies or similar technologies:

You can change or withdraw your cookie preferences at any time from the "Cookie Settings" link at the bottom of the page. You can also delete or block cookies from your browser settings; in that case some parts of the Service may not work properly.

4. Processors and Recipients

We rely on the following providers to deliver the Service:

These providers act as data processors under Art. 28 GDPR and on our instructions. Personal data may also be shared with the competent public authorities where a legal obligation applies.

5. Transfers Outside the EU

Our servers are located in the European Union. Stripe and Google may also process data in the United States. Those transfers take place under the Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework. Apart from these, your data is not transferred outside the European Union.

6. Retention Periods

The periods applied under Art. 5(1)(e) GDPR (storage limitation) are set out in the table below only:

Data categoryRetention periodNotes
Account data (email, password hash, credit balance) For as long as the account remains open Deleted within 30 days of the account being closed.
Report history and addresses analysed For as long as the account remains open Access to purchased reports is permanent; they are deleted when the account is closed.
Analytics data (session, page views, searches) 90 days The IP address is stored anonymised and hashed; it is deleted automatically after 90 days.
Security and rate-limiting logs 90 days For the prevention of abuse.
Incomplete payment sessions 90 days Failed or abandoned payment attempts are deleted automatically.
Webhook processing records 90 days Technical idempotency records.
Payment, invoice and consent records 10 years Required by Italian tax and accounting law (Art. 2220 Italian Civil Code; Art. 39 of Presidential Decree 633/1972).
Contact form messages 24 months After the request has been closed.

Automatic deletion runs daily. Data not subject to a legal retention obligation is deleted within 30 days of your deletion request; mandatory data such as invoice and payment records continues to be kept until the relevant legal period expires.

7. Your Rights

Under Articles 15-22 GDPR you have the following rights:

To exercise your rights, write to info@evitalya.com; we reply within 30 days at the latest.

Right to lodge a complaint. You may lodge a complaint with the Italian data protection authority:
Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome, Italy — www.gpdp.it

8. Security

We take appropriate technical and organisational measures to protect personal data: TLS/SSL encryption for all traffic, passwords stored only as a bcrypt hash, access limited to authorised people, encrypted backups, intrusion monitoring and access logs. In the event of a personal data breach we notify the supervisory authority and, where required, you, under Articles 33-34 GDPR.

9. Changes to this Policy

We may update this Privacy Policy. Material changes are announced by email or on the site. The date of the last update appears at the top of this page.

This text is provided in six languages. In the event of any discrepancy between the versions, the Turkish version prevails.