SovraiVerified · Secure · Premium

GDPR

Privacy policy

1. Controller

Stefano Moretti, Sonnenallee 23, 12047 Berlin, Germany. Contact: info@sovrai.de

2. Data minimisation by default

We collect only the data technically required to operate the directory. There is no registration requirement and we build no user profiles.

3. Session data & cookies

Strictly necessary storage: the age assurance token (session) and the consent status (local). Optional, IP-anonymised audience measurement only after explicit consent, Art. 6(1)(a) GDPR.

4. Age verification

Age assurance is carried out by an external certified AVS provider. ID and biometric data are never transmitted to us and never stored by us; we receive only an anonymous yes/no result.

5. Server log files

IP addresses are processed in truncated form and deleted after 7 days at the latest. Legal basis: Art. 6(1)(f) GDPR (operational security).

6. Contact via number masking (Twilio)

Calls and messages between users and providers are routed exclusively through masked numbers operated by an external telephony provider (Twilio). Each side sees only the temporary number, never the other party's real number. Every connection is limited to a fixed 3 hours and is then released automatically. Providers can request new masked numbers themselves at any time (limited per session). Only connection metadata is processed (time, duration, masked numbers). No calls are recorded and no message content is stored. Legal basis: Art. 6(1)(a) GDPR.

7. Processors and recipients

Twilio Inc. / Twilio Ireland Ltd. as processor for number masking (Art. 28 GDPR data processing agreement, EU standard contractual clauses), a certified AVS provider for age assurance, and a payment service provider for advertising subscriptions. No transfer to further third parties, in particular for advertising purposes, takes place. All processing activities are documented in the record of processing activities (Art. 30 GDPR).

8. Provider verification documents

ID cards, passports and the ProstSchG registration certificate are checked exclusively at the external verification partner and deleted there within one hour of the check at the latest. Our system retains only a boolean status (“verified: yes/no”) plus the check date.

9. Your rights

Access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR. Consent is logged with a timestamp and version and can be withdrawn at any time with future effect under “My Safe Account”.

10. Right to lodge a complaint

Competent supervisory authority: Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin.