Public offer
PUBLIC OFFER AGREEMENT (TERMS OF SERVICE)
for providing the right to use the electronic information resource "ITERIOS"
Travel Technology Lab LLC (EDRPOU code 38682976, Ukraine), represented by Director Yury Topolnitsky, acting on the basis of the Articles of Association (hereinafter – the "Owner"), guided by the current legislation of Ukraine and the requirements of the EU General Data Protection Regulation (GDPR), offers this Public Offer to sole proprietors and legal entities (hereinafter – the "Customer") to enter into a Service Agreement on the terms set forth below.
1. DEFINITION OF TERMS
1.1. Public Offer (Agreement) — a public offer of the Owner addressed to any person to enter into an agreement for providing access to the ITERIOS Service under the SaaS (Software-as-a-Service) model.
1.2. Acceptance — full, unconditional, and unreserved acceptance of the terms of this Offer by the Customer by registering an Account in the Service and/or paying for the Services.
1.3. ITERIOS Service — a cloud-based CRM system hosted at https://office.iterios.com/, designed to automate the operations of travel agencies, manage bookings, acquire clients, and generate documents.
1.4. Products of the Service:
-
- ITERIOS Travel Agent (ITA) — module for travel agency automation;
- ITERIOS Agency Network (IAN) — module for travel agency network management;
- ITERIOS API (ITAPI) — application programming interface for integration with external systems.
1.5. Account (Personal Cabinet) — the Customer’s user account in the Service, authenticated via the secure Auth0 service using a login (email) and password.
1.6. Personal Data of Tourists — personal data of the Customer's clients entered by the Customer or its employees into the Service to issue travel products.
1.7. Data Processing Agreement (DPA) — Annex No. 1 to this Agreement, which regulates the processing of Personal Data of Tourists in accordance with Article 28 of the GDPR and the Law of Ukraine "On Personal Data Protection".
2. SUBJECT MATTER OF THE AGREEMENT
2.1. The Owner grants the Customer a non-exclusive, fee-based right to use (SaaS access) the functionality of the ITERIOS Service, and the Customer undertakes to use the Service as intended and pay for the services in a timely manner.
2.2. The Privacy Policy (available at https://office.iterios.com/page/legal-note ) and Annex No. 1 (DPA) are integral parts of this Agreement.
3. REGISTRATION, AUTHENTICATION, AND SECURITY
3.1. Account registration is performed by the Customer independently on the Service website. User authentication, session security, and credential storage are provided using the specialized Auth0 service.
3.2. The Customer is solely responsible for maintaining the confidentiality of its credentials (passwords) and for all actions taken under its Account by its employees or authorized users.
3.3. Administrative access by the Owner to the server infrastructure of the Service is carried out exclusively via the secure SSH protocol.
3.4. The Owner provides two-factor authentication (2FA) functionality for all users by default. The Customer (acting through the Account Administrator) has the right to disable the 2FA requirement in the Account settings for all Customer users. In the event 2FA is disabled, the Customer acknowledges the increased risks of unauthorized access and solely bears full responsibility for any consequences, account compromise, or personal data breaches resulting from the absence of 2FA.
4. RIGHTS AND OBLIGATIONS OF THE PARTIES
4.1. The Owner undertakes to:
-
- Provide 24/7 access to the Service, except during scheduled technical maintenance;
- Ensure the security and storage of Customer data in accordance with Section 6 of this Offer and the DPA;
- Provide technical support through official channels (Online support via Helpcrunch or email: support@iterios.com ).
4.2. The Customer undertakes to:
-
- Pay for the use of the Service fully and in a timely manner according to the selected Tariff Plan;
- Not use the Service for unauthorized bulk mailings (Spam) or unlawful actions;
- Guarantee the existence of a legal ground (consent of data subjects or performance of a contract) for submitting Personal Data of Tourists into the Service.
5. PAYMENT TERMS AND METHODS
5.1. Free Trial Period: The Owner grants the Customer a free trial period of 14 (fourteen) calendar days from the date of initial Account registration. No fees are charged during the trial period.
5.2. Service Fees: The cost of using the Service is determined according to the Tariff Plan selected by the Customer and published on the Service website.
5.3. Payment Methods: Payment for Services is made on a 100% prepayment basis using one of the following methods:
-
- 5.3.1. Online credit/debit card payment (Visa, Mastercard) via the integrated LiqPay payment gateway directly in the Personal Cabinet;
- 5.3.2. Bank wire transfer to the Owner’s bank account based on an invoice that is:
- a) generated by the Customer independently in the Personal Cabinet;
- b) generated and sent to the Customer by the Support Team upon request.
5.4. Execution of Payment Obligation:
-
- For LiqPay payments — upon receipt by the Service of a successful transaction confirmation (webhook/notification) from the payment gateway;
- For bank wire transfers — upon full crediting of funds to the Owner's bank account.
5.5. Currency: Payments are made in Ukrainian Hryvnia (UAH). Non-resident Customers may pay in foreign currency (EUR/USD) based on the issued invoice or equivalent in the payment system.
5.6. Tariff Adjustments: The Owner reserves the right to unilaterally adjust Tariff Plans by notifying the Customer via email or publishing updates on the website at least 14 (fourteen) days prior to the effective date. New tariffs do not apply to periods already paid for by the Customer.
6. GRACE PERIOD, BLOCKING, AND DATA DELETION PROCEDURES
6.1. Grace Period: Upon expiration of a paid billing period without renewal, the Service grants the Customer an additional 5 (five) calendar days Grace Period, during which full access to the Service is maintained.
6.2. Access Blocking: If payment is not received after the 5-day Grace Period, the Customer's access to the Account and Service functionality is automatically blocked until the outstanding balance is settled / the next period is paid.
6.3. Data Retention During Blocking: Account blocking due to non-payment does not result in automatic deletion of Customer data. To allow the Customer to resume operations in the future (e.g., returning after several months or a year), the Owner ensures secure and confidential storage of all Customer data (including Tourist data) throughout the blocking period. Automatic data deletion is not performed.
6.4. Data Deletion Upon Request: Complete and irreversible deletion of the Account, as well as all associated Customer data and Tourist Personal Data from databases and backup copies, is executed exclusively upon a written request (application) from the Customer sent to official support email: support@iterios.com.
6.5. The Owner executes such deletion within 30 (thirty) calendar days from the receipt and verification of the written request from the Customer.
7. LIMITATION OF LIABILITY (SLA)
7.1. The Service is provided on an "As Is" basis. The Owner takes all reasonable measures to ensure uninterrupted operation but does not guarantee the absence of system errors in third-party communication channels or payment systems.
7.2. Service infrastructure is hosted on secure servers operated by Hetzner Online GmbH (Germany).
7.3. The Owner's total aggregate liability for any claims or lawsuits under this Agreement is limited to the amount actually paid by the Customer for using the Service over the 3 (three) months preceding the event giving rise to the claim.
8. INTELLECTUAL PROPERTY RIGHTS
8.1. All rights to the ITERIOS Service, including source code, design, logos, databases, trademarks, and modules (ITA, IAN, ITAPI), belong exclusively to the Owner. Granting access under this Offer does not constitute a transfer of any intellectual property rights to the Customer.
9. TERM AND TERMINATION
9.1. This Agreement enters into force upon Acceptance (Account registration or payment) and remains valid for 1 (one) year, with automatic renewal for each subsequent year.
9.2. Either Party may terminate this Agreement unilaterally by providing written notice to the other Party 30 (thirty) calendar days in advance.
10. DETAILS OF THE OWNER
Travel Technology Lab LLC
Legal Address: Office 3-1, Bldg. 2, 7 Holosiivska St., Kyiv, 03039, Ukraine
EDRPOU Code: 38682976
Director: Yury Topolnitsky
Support Email: support@iterios.com
Official Website: https://office.iterios.com/
ANNEX NO. 1 to the Public Offer
DATA PROCESSING AGREEMENT (DPA)
This Annex No. 1 is an integral part of the Public Offer Agreement (hereinafter – the "Agreement") entered into between the Customer (Travel Agency) and the Owner (Travel Technology Lab LLC).
1. SCOPE AND ROLES OF THE PARTIES
1.1. The Customer acts as the Data Controller regarding the personal data of its clients (Tourists) submitted into the ITERIOS Service.
1.2. The Owner (ITERIOS) acts as the Data Processor, processing this data solely on behalf of, under the instructions of, and based on the mandate of the Customer to ensure CRM functionality.
2. SUBJECT MATTER AND CATEGORIES OF PROCESSING
2.1. Data Subjects: Customer’s clients (Tourists), accompanying persons, passengers.
2.2. Categories of Data: Full name, date of birth, passport data, document series/number, visa details, phone numbers, email addresses, travel booking details, and vouchers.
2.3. Purpose of Processing: Performance of the Agreement — providing CRM functionality for selecting tours, processing bookings, issuing documents, and record-keeping.
3. OBLIGATIONS OF THE PROCESSOR (ITERIOS)
3.1. Instructions: Process data strictly according to the documented instructions of the Customer (terms of the Agreement and Customer actions within the CRM interface).
3.2. Confidentiality: Ensure that personnel authorized to process personal data have committed themselves to confidentiality.
3.3. Technical and Organizational Measures (Art. 32 GDPR):
-
- Data encryption in transit (SSL/TLS, HTTPS) and at rest (Encryption at Rest);
- Administrative access to server infrastructure restricted via SSH protocol;
- User authentication handled via the specialized Auth0 platform;
- Regular automated backups and 24/7 incident monitoring.
3.4. Incident Notification: In the event of a personal data breach, notify the Customer via email within 48 hours of becoming aware of the incident.
4. OBLIGATIONS OF THE DATA CONTROLLER (CUSTOMER)
4.1. The Customer guarantees that it has obtained valid consent from Tourists or relies on another legal basis (e.g., performance of a travel service contract) to transfer their data to the ITERIOS Service.
4.2. The Customer is independently responsible for handling requests from Tourists regarding the exercise of their rights under the GDPR and the Law of Ukraine "On Personal Data Protection".
5. SUB-PROCESSORS
5.1. The Customer grants general authorization for the engagement of the following Sub-processors:
-
- Hetzner Online GmbH (Germany) — server and database hosting within the EU;
- Auth0 Inc. (US/EU) — authentication and account security management;
- HelpCrunch Corporation (US) — support chat and communication services.
5.2. The Owner shall inform the Customer of any changes regarding Sub-processors by updating the Privacy Policy.
6. INTERNATIONAL DATA TRANSFERS AND STANDARD CONTRACTUAL CLAUSES (SCCs)
6.1. Primary Service databases are hosted in Germany (EU).
6.2. Where administration and technical support are conducted from Ukraine (a country outside the EU/EEA), such access/transfer is governed by the Standard Contractual Clauses (SCCs) approved by European Commission Decision 2021/914 (Module 2: Controller-to-Processor).
6.3. The SCC text is incorporated into this DPA by reference. Upon request, the Owner will provide a signed PDF copy of the SCCs to the Customer.
7. DATA RETENTION AND DESTRUCTION
7.1. Pursuant to Article 28(3)(g) of the GDPR, following the termination of Service use or Account blocking, the Owner retains Tourist Personal Data in a blocked, secure state for the benefit of the Customer to enable future account restoration.
7.2. Destruction or return of Tourist Personal Data is executed exclusively upon written instruction (request) from the Customer sent to support@iterios.com. In the absence of such a request, data remains securely stored in a blocked state.
7.3. Upon receipt of a written deletion request, the Owner undertakes to erase all personal data from primary databases and backup copies within 30 (thirty) calendar days.