Privacy policy
PRIVACY AND DATA PROTECTION POLICY
The electronic information resource ITERIOS (hereinafter – "ITERIOS" or "Service"), is owned and operated by Travel Technology Lab Limited Liability Company (EDRPOU code 38682976, Ukraine; hereinafter – "Owner", "We").
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use the website https://office.iterios.com/, API, and related services of ITERIOS (hereinafter – "Services").
We respect the privacy of our Users and comply with the requirements of the Law of Ukraine "On Personal Data Protection", as well as the EU General Data Protection Regulation (GDPR).
1. ROLES OF THE PARTIES AND SCOPE OF APPLICATION
1.1. ITERIOS as a Data Controller:
We act as a Data Controller regarding the personal data of the Users themselves (representatives of travel agencies, sole proprietors, legal entities) who create an account, pay for, and use the Services, as well as visitors to our Website.
1.2. ITERIOS as a Data Processor:
When Users (travel agencies) enter data of their clients (hereinafter – "Tourists") into the ITERIOS system to process bookings, applications, and documents, the User acts as the Data Controller, and ITERIOS acts as the Data Processor. In such cases, processing is governed by the Data Processing Agreement (DPA), which forms an integral part of the Public Offer.
1.3. Processing Tourist Requests:
If a Tourist contacts ITERIOS directly to exercise their rights under the GDPR or data protection legislation, we will forward such request to the respective User (travel agency), who is the Data Controller of this Tourist's data, and assist the User in processing the request within the CRM functionality.
2. WHAT DATA WE COLLECT AND SOURCES OF OBTAINING IT
2.1. Data you provide to us directly (User Data):
- Upon registration and profile setup: first name, last name, company name, position, email address, phone number, country, postal address.
- Upon payment for Services: company details, payment details (credit card processing is handled via secure payment providers).
- Upon contacting customer support: correspondence content, records of requests, contact details.
2.2. Tourist Data (entered into ITERIOS by the User):
Full name, date of birth, passport details, document series/number, visas, booking details, contact details. The User guarantees that they have proper legal grounds (consent or contract) to enter this data into ITERIOS.
2.3. Automatically collected data:
IP address, browser type and version, operating system, time zone, referring URLs, system activity logs, cookie data (detailed in Section 9).
3. LEGAL BASES AND PURPOSES OF DATA PROCESSING (Under Art. 6 GDPR)
We process personal data only when at least one of the following legal bases exists:
|
Purpose of Processing |
Category of Data |
Legal Basis (GDPR) |
|
Account registration, providing CRM access, support, and billing |
User Data, payment details |
Performance of a contract (Art. 6(1)(b) GDPR) |
|
Ensuring security, fraud and DDoS prevention, CRM performance analytics |
Automatic data, IP addresses, activity logs |
Legitimate interest of the Owner in ensuring uninterrupted and secure operation of the Service (Art. 6(1)(f) GDPR) |
|
Compliance with tax, accounting, and legal obligations |
Financial and primary documents |
Legal obligation of the Owner (Art. 6(1)(c) GDPR) |
|
Sending marketing newsletters, news, and promotional materials |
Email, phone number |
Consent of the User (Art. 6(1)(a) GDPR) with the right to withdraw at any time |
You may opt out of marketing newsletters at any time by clicking the "Unsubscribe" link in the email or by sending a request to support@iterios.com
4. DATA TRANSFER TO THIRD PARTIES AND SUB-PROCESSORS
4.1. We do not sell personal data to third parties. Data transfer is carried out strictly to the extent necessary to provide the Services:
- Hosting providers: Hetzner Online GmbH (Germany) — hosting servers and databases within the European Union.
- Communication and chat providers: email/SMS distribution and online support services (Helpcrunch) to ensure communication with the User.
- Travel service providers: tour operators, booking systems (solely based on direct instructions of the User during ticket issuance/booking).
- Law enforcement and state authorities: solely to fulfill legal requirements or court orders.
5. INTERNATIONAL DATA TRANSFERS (FOR EU CLIENTS)
5.1. Primary storage and processing of personal data are carried out on secure servers in Germany (Hetzner Online GmbH).
5.2. As the Owner of the service (Travel Technology Lab LLC) and technical support are located in Ukraine, access to data from Ukraine for administration and support purposes is considered a data transfer outside the EU.
5.3. Data transfers to Ukraine are conducted in accordance with Chapter V of the GDPR based on Standard Contractual Clauses (SCCs) approved by the European Commission, which are incorporated into our Data Processing Agreement (DPA).
5.4. Users and data subjects may request a copy or extract of the Standard Contractual Clauses (SCCs) by sending a request to support@iterios.com.
6. DATA SUBJECT RIGHTS AND PROCEDURE FOR THEIR EXERCISE
Users and Tourists (when we act as the Data Controller of their data) have the following rights under the GDPR and Ukrainian legislation:
- Right of access: to obtain confirmation as to whether data is being processed and a copy of their personal data.
- Right to rectification: to request the correction of inaccurate or outdated data.
- Right to erasure ("Right to be forgotten"): to request the deletion of data if it is no longer necessary or if consent has been withdrawn.
- Right to restriction of processing: to request temporary suspension of data processing in cases specified by law.
- Right to data portability: to receive their data in a structured, commonly used format (CSV/JSON).
- Right to object: to object to data processing based on legitimate interest or for direct marketing.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
Procedure and Timelines for Exercising Rights:
- To exercise your rights, please contact: support@iterios.com.
- We respond to requests regarding the exercise of rights within 1 (one) month of receiving the request. This period may be extended by an additional 2 months in cases of complexity or a high number of requests.
- To protect privacy, we reserve the right to request additional information to verify your identity before executing a request.
Right to Lodge a Complaint:
- With the Parliamentary Commissioner for Human Rights of Ukraine (for residents of Ukraine);
- With a local Supervisory Authority (Data Protection Authority) in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
7. DATA RETENTION AND DELETION
7.1. We retain personal data for the duration of the active User account.
7.2. Upon termination of the Agreement and a request for account deletion, all User personal data and associated Tourist data are permanently deleted from our primary systems and backups within 30 (thirty) days.
7.3. Specific categories of data are retained for statutory periods:
- System logs and IP addresses: retained for 180 days for security purposes.
- Financial and primary accounting documents: retained for periods required by the tax and accounting legislation of Ukraine (at least 1095 days / 3 years).
- Marketing data: retained until consent is withdrawn by the User.
8. DATA SECURITY AND INCIDENT NOTIFICATION
8.1. We employ appropriate technical and organizational measures to protect data against unauthorized access, loss, or destruction:
- Data Encryption: use of encryption protocols during transmission (SSL/TLS, HTTPS) and at rest (Encryption at Rest);
- Access Control and Authentication:
- Restricted and secured administrative access to server infrastructure via the SSH protocol;
- Utilization of the specialized Auth0 service for secure User authentication, session management, and account protection;
- Implementation of two-factor authentication (2FA) based on the Time-based One-Time Password (TOTP / Google Authenticator) algorithm by default for all Users as a mandatory additional layer of account security;
- Backups and Monitoring: regular data backups and 24/7 monitoring of security incidents.
8.2. In the event of a security incident (data breach) posing a high risk to the rights and freedoms of data subjects, we will notify Users and the relevant Supervisory Authorities without undue delay (within 72 hours of becoming aware of it).
9. COOKIES AND TRACKING TECHNOLOGIES
9.1. The Service uses cookies and similar technologies to ensure CRM functionality, session security, and (subject to your consent) to gather aggregate analytics and power customer support chat.
9.2. Cookie consent management is handled via the integrated Cookiebot (Usercentrics) platform. Upon first visiting the Service, a Cookie Banner is displayed allowing users to accept or decline non-essential cookie categories (Statistics, Preferences, Marketing).
9.3. Strictly necessary (technical and session) cookies are set automatically based on contract performance and security maintenance (Art. 6(1)(b), (f) GDPR).
9.4. You may change or withdraw your consent at any time by clicking the "Cookie Settings" link in the footer of the Service or in your profile settings.
10. AUTOMATED DECISION-MAKING AND PROFILING
10.1. We do not use your personal data for automated decision-making or profiling (within the meaning of Art. 22 GDPR) that produces legal effects concerning you or similarly significantly affects you.
11. CONTACTS AND INTERACTION WITH EU DATA SUBJECTS
For questions regarding personal data processing, exercising your rights, and interacting with Supervisory Authorities, please contact:
Owner: Travel Technology Lab Limited Liability Company
EDRPOU Code: 38682976
Address: Office 3-1, Building 2, 7 Holosiivska St., Kyiv, 03039, Ukraine
Privacy Contact Email: support@iterios.com
Interaction with EU Data Subjects and Supervisory Authorities:
Since the Owner is registered outside the European Union (in Ukraine), all requests from EU data subjects and EU Data Protection Authorities are received and processed directly by the Owner's authorized team at support@iterios.com within the timeframes established by the GDPR.