Privacy Policy
Your photos stay yours.
This policy explains how AVSOF handles personal data when you visit this website, contact us or buy Photo JSON Rescue.
1. Data controller
The controller is AVSOF di Enrico Bisco, Via Villanova 91, 35020 Saonara (PD), Italy, VAT / P.IVA IT05793440289, tax code / C.F. BSCNRC78R02A059H (referred to below as AVSOF or we). You can contact us at info@avsof.comor +39 049 6747089.
2. The desktop app and your photo archive
Photo JSON Rescue processes selected photos, videos, JSON sidecars, timestamps, coordinates and place information locally on your Windows computer. The normal restoration workflow does not upload those files or coordinates to AVSOF and does not use an online reverse-geocoding service. AVSOF cannot see your archive unless you deliberately send files to us for support.
Please remove or obscure unnecessary personal content before sending any sample file for support. We will use a support sample only to investigate your request.
If you activate software updates, the app checks at most once every 30 days. It sends the installed version and a random update credential issued with your purchase. It does not send photos, file names or paths, coordinates, your name or email, or a device identifier. The hosting provider necessarily receives the request IP address and time in ordinary security logs. The check is not advertising telemetry.
3. Personal data we may receive
- Purchase data: name, email, preferred transactional-email language, billing address, country, buyer type, order, tax identifier and, for an Italian business where supplied, SDI recipient code or PEC. Stripe processes full payment-card details; AVSOF does not receive your complete card number.
- Protected delivery data: a hashed download token, package and entitlement status, download count, and short-lived hashed network and browser signals used to prevent automated abuse. The download is not rigidly bound to an IP address.
- Software-update data: installed product version, a server-side hash of the random update credential, entitlement status and last successful use time. The raw credential is encrypted only while the transactional email is pending and is purged after delivery; on Windows it is protected for the current user. Infrastructure security logs may include the request IP address and time.
- Messages and support: your contact details, message, diagnostic information and attachments you choose to provide.
- Online withdrawal requests: name, purchase email, public order reference, withdrawal statement, submission time, acknowledgement status and provider message reference. The request content is encrypted at rest.
- Technical website data: IP address, browser, device, time and requested pages in security or server logs generated by our hosting infrastructure.
- Consent preference: the choice saved by the cookie banner in local browser storage.
4. Why we process data and our legal bases
5. Service providers and international transfers
Data may be handled by providers that support hosting, transactional email, payment processing, accounting, electronic invoicing, fraud prevention and customer support. Stripe acts under its own privacy information for parts of the payment process. We disclose only the data reasonably necessary for each service and may also disclose data where required by law.
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, approved standard contractual clauses or another lawful safeguard. You may ask us for information about the relevant safeguard.
6. Retention
We keep personal data only as long as needed for the purpose collected. Purchase, invoice and accounting records are normally retained for the period required by Italian law. Download entitlements and the minimum security record needed to provide or support the purchase, including an update credential hash and last-use time, are kept for the licence/support period, then deleted or anonymised unless a longer legal retention rule applies. Support communications are generally kept for up to 24 months after the request closes, unless they are needed longer for a contract, security matter or legal claim. Withdrawal requests and acknowledgements are retained with the related contract records for the period required to demonstrate compliance and handle claims. Security logs are retained for a limited period set according to operational and hosting needs.
7. Your GDPR rights
Subject to the conditions in applicable law, you may ask for access, correction, deletion, restriction, portability or objection to processing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also complain to the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the competent authority where you live or work.
To exercise a right, email info@avsof.com. We may request information reasonably needed to confirm your identity.
8. Security, children and changes
We use proportionate technical and organisational measures, but no system is completely risk-free. The product and website are not directed to children. We may update this policy when the service, providers or law changes; the date at the top identifies the current version.