AVRAH

Avrah® — Privacy Policy

Important. Please read carefully.

This Privacy Policy explains how Home SeTV® S.r.l. (“Data Controller”) collects, uses, stores, and protects your personal data when you use the A.V.R.A.H.® software and related services. This policy is issued in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Data Controller

1. Identity and Contact Information

The Data Controller is Home SeTV® S.r.l. For any questions or requests regarding this Privacy Policy or your personal data, you may contact us at: info@homesetv.com.

Personal Data We Collect

2. Categories of Personal Data

We collect the following categories of personal data: Account data (full name, email address, password stored in hashed form); Technical data (IP address, browser type, device information); Payment data (processed securely by Stripe — we do not store your full credit card number, only a Stripe customer identifier and transaction references); Communication data (content of emails or support requests you send us); Usage data (pages visited on our website, buttons clicked, language preference, and similar interaction signals — collected via our first-party product analytics, with IP addresses stripped at ingestion).

Purpose and Legal Basis for Processing

3. Why We Process Your Data

We process your personal data for the following purposes and legal bases under Article 6 GDPR:

Contract Performance (Art. 6(1)(b))

To create and manage your account, to provide the A.V.R.A.H.® service, to process payments for subscriptions, and to provide customer support related to your account or subscription.

Legitimate Interest (Art. 6(1)(f))

To maintain the security of our systems and prevent fraud, to improve and optimize the service, and to enforce our Terms of Service.

Consent (Art. 6(1)(a))

To send you optional marketing or newsletter communications. You may withdraw consent at any time by using the unsubscribe link or contacting info@homesetv.com.

Legal Obligation (Art. 6(1)(c))

To comply with Italian tax and accounting obligations, and to respond to lawful requests from public authorities.

Third-Party Processors

4. Who Processes Your Data

We share your personal data with the following third-party processors, each bound by data processing agreements:

Stripe, Inc.

Purpose: payment processing. Stripe processes your payment card data to execute subscription transactions. Stripe’s privacy policy is available at https://stripe.com/privacy. Stripe may process data in the United States under the EU–US Data Privacy Framework adequacy decision.

Amazon Web Services (AWS)

Purpose: hosting and infrastructure. Our application, database, and files are hosted on AWS within the EU (region eu-central-1, Frankfurt). AWS processes data as a sub-processor on our behalf.

Amazon Simple Email Service (AWS SES)

Purpose: transactional and service emails. AWS SES is used to send account verification emails, password resets, and optional newsletter communications.

PostHog (EU)

Purpose: first-party product analytics. PostHog is used to understand how visitors and users interact with our website (pages visited, buttons clicked, signup and subscription events). Data is processed and stored exclusively within the European Union (Frankfurt, eu-central-1) by PostHog Inc. under a Data Processing Agreement. IP addresses are stripped at ingestion, and we do not share this data with advertisers or third-party ad networks. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). You may opt out at any time using the toggle at the bottom of this page.

International Data Transfers

5. Where Your Data Is Processed

Your personal data is primarily processed and stored within the European Union (AWS eu-central-1, Frankfurt). Stripe, Inc. may process payment data in the United States. Such transfers are protected by the European Commission’s adequacy decision for the EU–US Data Privacy Framework. We do not transfer your data to any other countries outside the EU/EEA without appropriate safeguards in place.

Data Retention

6. How Long We Keep Your Data

Account data: retained for the duration of your account and deleted upon account deletion, subject to legal retention obligations. Financial and transaction records: retained for 10 years from the transaction date as required by Italian tax law (Art. 2220 Italian Civil Code and Italian tax regulations). Security logs (IP addresses, access logs): retained for 6 months, then permanently deleted. Backups: retained for 30 days on a rolling basis, then permanently deleted. Newsletter preferences: retained until you unsubscribe or delete your account.

Your Rights Under GDPR

7. Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

You may request a copy of the personal data we hold about you.

Right to Rectification (Art. 16)

You may request correction of inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

You may request deletion of your personal data, subject to legal retention requirements.

Right to Data Portability (Art. 20)

You may request your data in a structured, commonly used, machine-readable format.

Right to Restriction of Processing (Art. 18)

You may request that we limit the processing of your data in certain circumstances.

Right to Object (Art. 21)

You may object to processing based on legitimate interest.

How to Exercise Your Rights

To exercise any of these rights, send an email to info@homesetv.com from the email address associated with your account, specifying your request. You may be asked to provide your username or registration date for identity verification. We will respond within 30 days of receiving your request. If the request is complex, we may extend this period by an additional 60 days, and we will notify you of the extension.

Right to Lodge a Complaint

8. Supervisory Authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), Piazza Venezia 11, 00187 Roma, Italy — www.garanteprivacy.it.

Data Breach Notification

9. Breach Procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 GDPR.

Children’s Privacy

10. Age Restriction

A.V.R.A.H.® is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16 without appropriate parental consent, we will take steps to delete that data promptly.

Changes to This Policy

11. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. When we make material changes, we will notify you via email at the address associated with your account. The updated policy will indicate the date of the latest revision. Continued use of A.V.R.A.H.® after notification constitutes acceptance of the updated policy.

Analytics Preferences

We rely on first-party product analytics (PostHog, EU-hosted) on the basis of legitimate interest. If you would rather not be measured, you can opt out below. Your choice is stored on this device.

Analytics is currently active.

© 2026 Home SeTV® S.r.l. – All Rights Reserved. A.V.R.A.H.® is a registered trademark of Home SeTV®.