Privacy Notice
TourOperate website and Service · Version 1.0 · in force from 21 September 2026
Contents
- 1. Controller
- 2. Who this notice is for, and the controller’s two roles
- 3. Categories of data processed
- 4. Purposes, legal bases and retention
- 5. Whether providing data is required
- 6. Who inside the controller can access the data
- 7. Recipients and processors
- 8. Automated decision-making and profiling
- 9. Security
- 10. Data subject rights
- 11. Cookies and measurement tools
- 12. Changes
We do not sell personal data, and we do not use it for any activity that competes with our customers’ own.
References to articles in this document are to Regulation (EU) 2016/679 (the “Regulation” or “GDPR”) unless stated otherwise. References to the “Terms” are to the General Terms and Conditions of the Service and to Annexes A and B thereto.
1. Controller
The controller is TU Italia S.r.l., with registered office at Via Sommacampagna 9, 00185 Rome, Italy, VAT number IT09802381005, REA RM-1190289, email info@touroperate.com, telephone 0039 393 4578504.
Questions and requests about data protection, security and the exercise of rights, including those under art. B.6.1(c) of the Terms, are handled at info@touroperate.com.
2. Who this notice is for, and the controller’s two roles
This notice describes the processing of personal data carried out through the TourOperate.com website and through the TourOperate Service. It is addressed to visitors who browse the site and use its contact form or demo booking, to the tour operators who subscribe to the Service (the “Operators”), to the staff who access it at an Operator’s invitation (the “Authorised Users”), and to the guides, tour leaders and other suppliers who receive a secure link from an Operator in order to consult the programme for a departure, without holding an account.
Two different situations must be distinguished.
- When the controller processes the data needed to manage its direct relationship with the user (a visit to the site, a message sent through the contact form, a demo booking, registration, the account, access, support, invoicing and the security of the Service), it acts as the CONTROLLER, as described in this notice.
- When the controller processes the data an Operator enters into the Service as part of its own business (details of the guides and suppliers it works with, assigned services, participant lists, operational notes), it acts as a PROCESSOR on behalf of the Operator, who remains the controller. In that case, providing the privacy notice to data subjects and determining the purposes are the Operator’s responsibility, and the relationship is governed by Annex A (DPA) to the Terms.
Guides and suppliers who receive a secure link fall within the second situation: their data was entered by the Operator, who is its controller, and any request concerning that data is handled in accordance with section 10.
3. Categories of data processed
Depending on the relationship, the controller may process:
- data sent through the site’s contact form: name, email address, organisation and the content of the message;
- demo booking data: whatever the user enters on the page of the external scheduling provider named in section 7;
- identification and contact data: first name, last name, email address, telephone number, role, language;
- Operator data: company name, registered office, VAT number, billing details;
- account and access data: credentials and authentication are managed by the authentication provider named in section 7; the controller does not hold users’ passwords. The controller sees the status of authentication factors, the registration date and preferences;
- data generated by use of the Service: planned departures and services, assigned resources, documents attached to a departure, operational communications sent and their outcome, access and activity logs;
- technical data: IP address, device and browser type, session identifiers, date and time of access, hosting provider logs. These are generated by the request itself and therefore exist whenever a page is loaded;
- billing data: where the subscription is taken out through the Bókun App Store, the payment method and the charge are handled by Bókun; the controller does not collect or store card details, and the Service neither collects nor stores the payment data of the Operator’s end customers (art. A.1.3 of the Terms).
The service is not intended for the processing of special categories of data under article 9. Users are asked not to enter health information or other special categories of data into free-text fields, including the contact form message.
The controller carries out no profiling and no behavioural advertising, and the site integrates no advertising-tracking or application error-reporting tooling. When analytics is active, the site uses Google Analytics 4 for statistical measurement of visits only, on the conditions described in section 11: without analytics cookies before any consent, and with them only after consent. The absence of the banner does not mean measurement is off: the banner is also hidden once a choice has been stored.
4. Purposes, legal bases and retention
Data is processed for the purposes set out below. One note governs every row that cites art. 6(1)(b): that basis covers the individual who is party to the contract, or who personally asked for the pre-contractual step. Where the person is an employee, officer or other contact of an Operator rather than a party in their own right, the basis for administering that professional relationship is our legitimate interest (art. 6(1)(f)). Where the data was entered into the Service by an Operator, the Operator determines the basis as controller, and the row says so.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Answering a message sent through the contact form | Name, email, organisation, message | Pre-contractual steps at the data subject’s request (art. 6(1)(b)) | 12 months from closure of the request, unless the correspondence is needed for an ongoing contract, a dispute or a statutory obligation |
| Handling a demo booking | Data entered into the external scheduling provider’s form | Pre-contractual steps at the data subject’s request (art. 6(1)(b)) | The provider named in section 7 retains it under its own policy; our own copy of the appointment for 12 months from closure of the request, unless it is needed for an ongoing contract, a dispute or a statutory obligation |
| Providing the Service and managing the account | Identification, account, usage data | Performance of the contract with the Operator (art. 6(1)(b)) | Term of the relationship, plus 30 days for export (arts. 10.4 and A.6 of the Terms) |
| Support and assistance | Contact details, content of the request | Performance of the contract with the Operator (art. 6(1)(b)) | 12 months from closure of the request, unless needed for an ongoing contract, a dispute or a statutory obligation |
| Invoicing and accounting compliance | Operator and billing data | Legal obligation (art. 6(1)(c)) | 10 years, as required by tax law (art. 10.5 of the Terms). Where the subscription is billed through Bókun, the corresponding billing records are held by Bókun under its own terms |
| Security of the site and the Service, prevention of abuse, access logs | Technical data and logs | Legitimate interest in the security of the service (art. 6(1)(f)) | For as long as needed to keep access traceable and reviewable and to investigate and resolve a security event, and for the duration of any legal hold |
| Statistical measurement of visits before any consent, without cookies | Technical and browsing data described in section 11, collected without analytics cookies | Legitimate interest in understanding how the site is used (art. 6(1)(f)), limited to statistical measurement carried out without analytics cookies. Objection may be exercised at any time by declining | At Google: event data 2 months, user data 14 months, reset on new activity (section 11) |
| Statistical measurement of visits after consent, with cookies | The above, plus the analytics cookies named in section 11 | Consent (art. 6(1)(a)) for the storage of and access to information on the device under art. 122 of Legislative Decree 196/2003, withdrawable at any time | At Google: event data 2 months, user data 14 months, reset on new activity (section 11) |
| Sending operational communications to assigned resources | Resource contact details, departure documents, delivery outcome | Processing on the Operator’s documented instructions, in performance of the contract with the Operator (art. 6(1)(b)); towards the recipient, the Operator determines the basis as controller | For as long as needed to evidence delivery and reconcile it, and for the term of the Operator’s account; access through a secure link ends at the end of its configured validity or on earlier revocation, which is separate from how long the underlying records are kept |
| Retaining a departure’s documents and operational answers | Departure attachments, answers to participant questions | Processing on the Operator’s documented instructions; the Operator determines the basis as controller | For the operational purpose of the departure and the period set by the Operator’s instructions, within the term of the Operator’s account and the 30-day export window |
| Service communications (alerts, deadlines, changes to the Terms) | Contact details | Performance of the contract with the Operator (art. 6(1)(b)) | Term of the relationship |
| Citation among commercial references | Operator’s name and logo | Legitimate interest (art. 6(1)(f)), objectable at any time (art. 9.4 of the Terms) | Until objection |
| Defence of legal claims | Data necessary for the purpose | Legitimate interest (art. 6(1)(f)) | Duration of the dispute and applicable limitation periods |
When the criteria above are met, data is deleted or irreversibly anonymised, subject to statutory retention obligations. Backups are kept isolated and are overwritten according to ordinary cycles, including after the active data has been deleted (art. A.6 of the Terms). The twelve-month period for enquiry, demo and support correspondence is an operating policy applied by the controller from publication of this notice.
One limit must be stated plainly: an email that has already been delivered cannot be recalled or erased. Erasure reaches the copies we hold; retention at the mail provider follows that provider’s policies, and the copy in the recipient’s mailbox is permanently outside our control. No feature of the site or of the Service promises otherwise.
We send no unsolicited marketing. Should any be introduced in future, the processing would be based on consent under art. 6(1)(a), withdrawable at any time.
5. Whether providing data is required
Providing the data marked as necessary is essential in order to send a message through the contact form and to register for and use the Service: without it we cannot reply and the Service cannot be provided. Providing the other data is optional and its absence affects neither the reply nor use of the Service.
The public pages can be read without submitting a form and without creating an account. Loading a page is nonetheless a request to a server, so technical data (IP address, browser and device type, date and time) is necessarily involved and is logged by the hosting provider, as described in section 4.
6. Who inside the controller can access the data
Access is named, authenticated and limited to what is strictly necessary to provide the Service or to handle a request; it is recorded in dedicated logs and reviewed periodically (art. B.3.1 of the Terms). We do not claim the complete absence of all access: we state that every access is traceable, limited to what is necessary, and reviewable (art. B.3.2).
Staff carrying out the tourism operations of EnRoma.com are not authorised to access other Operators’ data, and no feature of the Service would allow them to: the separation is architectural in nature and not merely organisational (arts. B.1 and B.2 of the Terms).
7. Recipients and processors
Data is processed by the controller’s authorised staff and disclosed to the recipients listed below. Where a recipient processes the data only on the controller’s instructions it acts as a processor and the relationship is governed by article 28; where a recipient determines its own purposes for part of the processing, that is stated in its entry. The recipients currently engaged are:
- providers of cloud infrastructure and hosting, which host the site and the Service and log their requests: Vercel Inc.;
- providers of database and file storage services for the Service: Supabase Inc.;
- providers of authentication and identity management for the Service: Clerk Inc.;
- providers of the site’s contact form, which receive and forward the message sent by the visitor: Web3Forms;
- providers of transactional email services, for operational communications addressed to resources and Operators: Resend (Plus Five Five, Inc.);
- providers of asynchronous processing orchestration for the Service: Inngest Inc.;
- mailbox, accounting, tax and legal services, within the limits of the respective engagements; the identity of the suppliers currently engaged for these can be requested at info@touroperate.com;
- external scheduling, for demo bookings: the Demo page links out to Calendly LLC, and the appointment is made on Calendly’s own page under Calendly’s own notice. Calendly processes the appointment data both in order to provide the scheduling we have asked for and, for the administration and security of its own platform, on its own account; the division of roles is the one set out in Calendly’s own terms and data-processing documentation;
- the booking-platform integration and the subscription billing channel: Tripadvisor LLC, doing business as Bókun. Where the subscription is taken out through the Bókun App Store, Bókun manages the trial, the billing and the install/uninstall state under its own App Store partner terms and determines its own purposes for that relationship;
- statistical visit measurement, when analytics is active: Google Ireland Limited (Google Analytics 4), on the conditions in section 11.
Neither the site nor the Service uses profiling or application error-reporting providers, and statistical measurement is limited to what section 11 describes. The up-to-date list of processors is available on request at info@touroperate.com, including under art. B.6.1(b) of the Terms; changes are notified to the Operator at least 15 days in advance and the Operator may object on legitimate grounds (art. A.4.1).
Data is not disseminated and is not transferred to third parties for their own commercial purposes. Each Operator’s data is not accessible to other Operators and is not used for activities that compete with that Operator’s own: the prohibition is governed by art. B.4 of the Terms, applies equally to data in aggregated or statistical form, and expressly covers the tour operating business carried on by the controller through EnRoma.com.
Under art. A.5.2 of the Terms, the primary database of the Service is hosted in the European Union, in the Frankfurt region. Several of the recipients listed above are established in the United States, and backup, support and ancillary services may involve processing outside the European Economic Area. For those transfers the controller’s policy is to rely on an adequacy decision where one applies and otherwise on standard contractual clauses with the supplementary measures appropriate to the case; art. A.5.2 states this as an obligation the Supplier owes the Customer. The safeguards applicable to a given recipient, and a copy of them, can be requested at info@touroperate.com.
8. Automated decision-making and profiling
The controller takes no automated decisions and carries out no profiling that produces legal effects concerning data subjects or similarly significantly affects them, within the meaning of art. 22.
9. Security
The controller adopts technical and organisational measures appropriate to protect data against unauthorised access, loss or disclosure, including encryption of data in transit and encryption at rest as provided by the infrastructure suppliers used, logical separation of data between Operators, role-based access control following the principle of least privilege, periodic backups with restore procedures, separation of environments, and logging of significant activity. Account credentials and authentication are managed by the authentication provider named in section 7; the controller does not hold users’ passwords.
10. Data subject rights
Data subjects may exercise the rights set out in articles 15 to 22 of the Regulation: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where the processing is based on it, without affecting the lawfulness of processing carried out beforehand.
Requests should be addressed to info@touroperate.com. The controller responds without undue delay and in any event within one month, extendable by two months in particularly complex cases under art. 12(3).
If the request concerns data uploaded by an Operator (for example a participant’s details or a guide’s contact details), the controller is that Operator, not us. In that case we forward the request to the Operator without delay and provide our assistance under art. A.2(e) of the Terms.
Data subjects also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of their country of residence.
11. Cookies and measurement tools
The site sets no cookies of its own for profiling or advertising purposes, and builds no behavioural profiles. Advertising storage stays disabled at all times.
The site keeps a small number of technical items in the visitor’s browser. In local storage: the interface language chosen, the fact that the automatic redirect to that language has already happened once, and, once a choice has been made, the analytics choice, recorded as its version, the choice itself and the date. In session storage, when measurement has been declined, a marker that keeps the rest of that session out of measurement. The two language items are technical means necessary to provide the service the visitor asked for under art. 122 of Legislative Decree 196/2003, for which no consent is required; the consent items exist in order to record and honour the choice. All of them stay in the browser until they are cleared or overwritten, and the session marker until the session ends; we set no lifetime of our own on them.
Statistical measurement. When analytics is active, measurement uses Google Analytics 4 through Google’s Consent Mode, in its advanced form. On a first visit, before any choice has been made, Google’s tag loads with analytics storage and advertising storage set to denied: in that state no Google Analytics cookie is written or read, and the events the site itself sends are sent without cookies. We rely on our legitimate interest in understanding how the site is used (art. 6(1)(f)) for that limited statistical measurement, and it can be objected to at any time by declining. Denied analytics storage governs cookies: it prevents Google Analytics cookies from being read or written, and it does not prevent information about the browser, the device and the network from reaching Google. Allowing cookies switches analytics storage to granted, which sets the analytics cookies and lets returning visits be recognised; storing and reading those cookies is based on consent under art. 122 of Legislative Decree 196/2003 and art. 6(1)(a), and is withdrawable at any time.
Declining. Declining stops the events the site itself sends, expires this domain’s analytics cookies (named _ga and _ga_<container-id>, set as host-only cookies) and keeps the remainder of that session out of measurement. Two limits apply. A Google tag already loaded in the page may still emit consent-state signals of its own, so we do not state that no further request reaches Google within that page view. On a later visit the stored refusal is read before the tag loads, so the tag does not load at all. Closing the banner without choosing is not consent: it leaves the cookieless state in place and measurement continues on that basis. The absence of the banner does not mean measurement is off: the banner is also hidden once a choice has been stored. The choice can be changed at any time from the “Cookies” control in the footer.
What reaches Google. Two different flows do, and only the first is shaped by this site. The events the site itself sends carry an allowlisted payload, which excludes the query string and fragment of the address, names, email addresses, message and form contents, and booking or appointment details. Separately, Enhanced Measurement is enabled on the Google Analytics data stream, so Google’s own tag generates events of its own: page views, scrolls, outbound clicks, site searches, video interaction, file downloads and form interactions. Which of them actually fire depends on what a page contains and on what a visitor does. They are generated by Google’s tag rather than by this site, they are not limited by our allowlist, and they can carry the interaction metadata Google’s documentation describes for them, for example the destination of an outbound link, identifiers of a link or of a form, and a search term where one is detected in the address. In addition, and inherently in calling Google’s service, Google receives browser, device and network information, including the IP address in transit and an approximate geography derived from it. For those reasons we do not describe the measurement as anonymous, and we do not state that no address query, form metadata or personal data ever reaches Google.
How long. Two different periods are easily confused, so both are set out. The analytics cookies: this site sets no override for their lifetime, so Google’s default applies: two years for _ga and for _ga_<container-id>, counted from the most recent visit, because Google refreshes them on each visit. A browser may impose a shorter limit of its own, and withdrawing consent removes them earlier, as described above. The property’s data retention: in the TourOperate Google Analytics property, event data retention is set to 2 months and user data retention to 14 months, with reset on new activity enabled. Those settings govern how long event-level and user-level data stays queryable in Google Analytics. They are not cookie lifetimes, and they do not limit the standard aggregated reports, which Google retains independently of them.
The Demo page does not embed a calendar. It links out to the external scheduling provider named in section 7; any cookie that provider sets is set on that provider’s own page, under that provider’s own notice, once the visitor follows the link. On this site the only third-party component is the measurement described above: when analytics is active it is present on every page, including this one, on the conditions set out here.
The Service, which is an application reserved to Operators and their Authorised Users, additionally uses the session cookies set by the authentication provider named in section 7, which are necessary to keep the user signed in.
12. Changes
This notice may be updated for regulatory, technical or organisational reasons. The updated version is published on this page, and material changes are notified to the Operator by email or by notice within the Service, in the manner and within the periods set out in art. 17.1 of the Terms. The effective date of the current version is shown at the top of this page.