General Terms and Conditions
TourOperate SaaS Service · Version 1.0 · in force from 21 September 2026
Contents
- 1. Definitions
- 2. Subject matter
- 3. Scope: professional customers
- 4. Registration and Account
- 5. Free trial
- 6. Fees, invoicing and payments
- 7. Term, termination for convenience and withdrawal
- 8. Suspension and termination for cause
- 9. Licence of use and intellectual property
- 10. Customer Data
- 11. Permitted use of the Service
- 12. Service levels, support and maintenance
- 13. Warranties and exclusions
- 14. Limitation of liability
- 15. Indemnity
- 16. Confidentiality
- 17. Changes to the Terms
- 18. Processing of personal data
- 19. Notices
- 20. Final provisions
- 21. Governing law and jurisdiction
- 22. Clauses expressly approved
- Annex A: Data Processing Agreement (DPA)
- A.1 Roles and subject matter
- A.2 Obligations of the Supplier (processor)
- A.3 Security measures
- A.4 Sub-processors
- A.5 Data breaches and transfers outside the EU
- A.6 Fate of the data on termination
- A.7 Obligations of the Customer (controller)
- Annex B: Separation measures and trust commitments
- B.1 EnRoma.com as an ordinary tenant
- B.2 Segregation of EnRoma.com staff
- B.3 Access by Supplier staff
- B.4 Prohibition of commercial use
- B.5 Sanction for breach
- B.6 The Customer’s right of verification
These General Terms and Conditions (the “Terms”) govern the supply of the software-as-a-service product named TourOperate (the “Service”) by TU Italia S.r.l. (the “Supplier”), with registered office at Via Sommacampagna 9, 00185 Rome, Italy, VAT number IT09802381005, REA RM-1190289, email info@touroperate.com, telephone 0039 393 4578504, to any party that activates a subscription to the Service (the “Customer”).
These Terms are published and permanently accessible on this page. They govern a subscription where they have been accepted as part of the contracting process by which that subscription is taken out. Viewing this website, or merely creating an account, does not by itself constitute acceptance and does not by itself supply the separate approval required by art. 22. For subscriptions already in force at the date shown above, any change takes effect in the manner and within the periods set out in art. 17. The Supplier retains the versions of the Terms in force from time to time.
Annex A (Data Processing Agreement, DPA) and Annex B (Separation measures and trust commitments) form an integral and substantial part of these Terms.
1. Definitions
For the purposes of these Terms:
- “Service”: the software-as-a-service management platform named TourOperate, accessible on the web at the address indicated by the Supplier, intended for the operational management of tourism activities (by way of example: management of bookings, calendars, resources, guides and staff, participant manifests, operational communications and reporting), in the version and with the features of the subscription plan taken out by the Customer.
- “Account”: the Customer’s private profile on the Service, including the user accounts activated by the Customer for its own staff (“Authorised Users”).
- “Customer Data”: any data, content or information uploaded, entered or generated in the Service by the Customer or its Authorised Users, including the personal data of the Customer’s own end customers.
- “Plan”: the combination of features, usage limits and fees taken out by the Customer, as described on the Supplier’s website or in the order.
- “Billing Period”: the monthly or annual period, depending on the Plan chosen, for which the fee is due.
2. Subject matter
2.1 The Supplier grants the Customer, for the term of the contract and against payment of the fee, the non-exclusive and non-transferable right to access and use the Service for its own internal business purposes, in accordance with the Plan taken out.
2.2 The Service is a purely operational management tool. The following are expressly excluded from the subject matter of the contract, and the Supplier does not perform them for the Customer or through the Service: (a) the collection, handling or intermediation of payments between the Customer and its end customers; (b) the sale, resale or intermediation of the Customer’s tourism services; (c) travel agency or tour operating activities on the Customer’s behalf. The Supplier does carry on a tour operating business of its own through EnRoma.com, which uses the Service as an ordinary Customer and is subject to the separation commitments in Annex B. The Customer remains solely responsible for the contractual, financial and regulatory relationships with its own end customers.
2.3 The Supplier may update, improve or modify the features of the Service, provided it does not materially reduce the essential characteristics of the Plan taken out.
3. Scope: professional customers
3.1 The Service is intended exclusively for businesses and professionals (B2B) acting for purposes relating to their entrepreneurial or professional activity. By taking out a subscription, the Customer declares that it acts in that capacity and holds a VAT number or equivalent tax identification.
3.2 The provisions of Legislative Decree 206/2005 (the Italian Consumer Code) therefore do not apply, including those on the right of withdrawal.
4. Registration and Account
4.1 To use the Service the Customer must create an Account, providing true, complete and up-to-date information.
4.2 The Customer is responsible for safeguarding its own access credentials and those of its Authorised Users, and for all activity carried out through the Account. The Customer undertakes to notify the Supplier without delay of any unauthorised use of the Account.
4.3 The number of Authorised Users may be limited according to the Plan taken out.
5. Free trial
5.1 The Supplier may offer a free trial period of the Service for the duration indicated at activation (the “Trial”).
5.2 At the end of the Trial, the subscription automatically converts into the selected paid Plan and the corresponding fee becomes payable, unless the Customer cancels before the Trial expires through the channel in which the subscription was taken out. Where the subscription was taken out through the Bókun App Store, the Trial and the subsequent billing are managed by Bókun and the cancellation is made there. The date on which the Trial ends is shown in the channel that manages the subscription. Notice of termination may also be given in writing under art. 19.
6. Fees, invoicing and payments
6.1 Plan fees are set out on the Supplier’s website or in the order and are inclusive of VAT where applicable.
6.2 The fee is payable in advance for each Billing Period (monthly or annual, according to the Plan chosen) and is collected through the channel in which the subscription was taken out. Where the subscription was taken out through the Bókun App Store, billing and the payment method are managed by Bókun under its own terms, and the Supplier neither collects nor stores the Customer’s payment card details.
6.3 Automatic renewal. At the end of each Billing Period the subscription renews tacitly for a further period of the same length, unless notice of termination is given under art. 7.
6.4 The Customer undertakes to keep the payment method registered with the channel that manages the subscription valid and sufficiently funded. In the event of non-payment or late payment, the Supplier may, after notice, suspend access to the Service under art. 8 and apply the default interest provided for by Legislative Decree 231/2002.
6.5 Price changes. The Supplier may change the fees on at least 30 (thirty) days’ written notice. Changes apply from the Billing Period following the end of the notice period. If the Customer does not wish to accept the change, it may withdraw from the contract with effect from the date the change applies, by giving notice by that date; failing which, the change is deemed accepted.
6.6 Fees paid are non-refundable, save as otherwise provided by these Terms or by mandatory law.
6.7 Taxes. Fees are inclusive of VAT where applicable. Any further taxes, duties, levies or withholdings provided for by applicable law in relation to the subscription remain payable by the Customer, with the exception of taxes on the Supplier’s income. Where the Customer is required by law to apply a withholding on payments due to the Supplier, the fee shall be increased so as to allow the Supplier to receive the net amount it would have received absent the withholding, and the Customer shall promptly provide documentation evidencing payment of the withholding.
7. Term, termination for convenience and withdrawal
7.1 The contract starts on activation of the subscription (or on conversion of the Trial) and runs for the Billing Period, renewing automatically under art. 6.3.
7.2 Termination for convenience. Either party may give notice of termination at any time, with no minimum lead time, provided the notice is received before the next renewal; it then takes effect at the end of the current Billing Period. The Customer gives it through the channel in which the subscription was taken out (where that is the Bókun App Store, by cancelling the subscription there) or by written notice under art. 19. The Customer keeps access to the Service until the end of the Billing Period already paid for; where the Customer uninstalls the integration, operational access ends when the uninstall takes effect.
7.3 Termination for convenience gives no right to a refund, even partial, of fees already paid for the current Billing Period.
7.4 The rights of withdrawal and termination provided for by arts. 6.5, 8 and 17 are unaffected.
8. Suspension and termination for cause
8.1 The Supplier may suspend access to the Service, with prior notice where possible, in the event of: (a) non-payment not remedied within 15 (fifteen) days of a reminder; (b) breach of art. 11 (permitted use); (c) concrete risks to the security of the Service or of third parties; (d) legal obligations or orders of an authority.
8.2 The Supplier may terminate the contract under art. 1456 of the Italian Civil Code, by written notice, in the event of breach of arts. 3.1 (declaration of professional capacity), 6.4 (payments, where suspension continues beyond 30 days), 9 (licence and intellectual property), 11 (permitted use) and 16 (confidentiality).
8.3 On termination of the contract for any reason: (a) the Customer loses access to the Service; (b) Customer Data is handled in accordance with art. 10.4 and Annex A; (c) accrued fees remain payable.
9. Licence of use and intellectual property
9.1 The software, the platform, the documentation, the trade marks and all other material relating to the Service are and remain the exclusive property of the Supplier or its licensors. The Customer is granted only the right of use set out in art. 2.1.
9.2 Save as permitted by mandatory law, the Customer may not: copy, modify, decompile or disassemble the software; sub-license, rent or otherwise make it available to third parties; use it to provide service-bureau services or to develop competing products.
9.3 Any suggestions or feedback provided by the Customer may be freely used by the Supplier to improve the Service, with no obligation towards the Customer.
9.4 References. Unless the Customer gives written notice to the contrary, the Supplier may cite the Customer’s name and logo among its commercial references (for example on the website, in marketing materials and in customer lists), in compliance with any trade mark usage guidelines provided by the Customer. The Customer may revoke this authorisation at any time by written notice.
10. Customer Data
10.1 Customer Data is and remains the property of the Customer. The Customer grants the Supplier a limited licence to host, process and handle Customer Data for the sole purpose of providing the Service and performing these Terms.
10.2 The Customer warrants that it holds every right, legal basis and authorisation necessary for uploading and processing Customer Data in the Service, including the personal data of its own end customers, and indemnifies the Supplier against any third-party claim in that regard.
10.3 The Supplier adopts appropriate technical and organisational measures for the security of Customer Data, as described in Annex A. The Customer may request an export of Customer Data at any time; the Supplier provides it with its assistance, in a standard machine-readable format, within a reasonable time.
10.4 Return of data. For 30 (thirty) days following termination of the contract, the Customer may request the export of Customer Data in a standard machine-readable format. After that period, the Supplier will delete Customer Data as provided for in Annex A, subject to statutory retention obligations.
10.5 Retention for legal obligations. The Supplier may retain a copy of Customer Data and of contractual data for as long as, and within the limits, necessary to comply with legal, accounting or tax obligations, or to establish, exercise or defend a legal claim, including after termination of the contract, processing it for those purposes only.
11. Permitted use of the Service
11.1 The Customer undertakes not to use the Service to: (a) pursue unlawful purposes or infringe third-party rights; (b) upload unlawful, defamatory or harmful content; (c) transmit malware or carry out cyber attacks; (d) send unsolicited communications (spam) in breach of applicable law; (e) carry out scraping, unauthorised automated access or stress testing without the Supplier’s written consent; (f) circumvent technical or Plan limits.
11.2 The Customer is responsible for the use of the Service by its Authorised Users.
11.3 The Supplier may remove or make inaccessible Customer Data that is manifestly unlawful or in breach of this article, or at the request of an authority, notifying the Customer where possible and permitted. The Supplier is under no obligation to carry out any prior or general monitoring of the content uploaded by the Customer.
12. Service levels, support and maintenance
12.1 The Supplier undertakes to provide the Service with the professional diligence required by art. 1176(2) of the Italian Civil Code. The Service is provided on a best-efforts basis, with no guaranteed minimum availability levels.
12.2 The following do not count towards availability: (a) scheduled maintenance, announced where possible at least 48 hours in advance and preferably carried out at times of lower usage; (b) urgent security maintenance; (c) malfunctions attributable to the Customer, to third parties or to force majeure; (d) network or third-party supplier outages outside the Supplier’s control.
12.3 Support is provided through the channels and during the hours indicated on the Supplier’s website, according to the Plan taken out.
13. Warranties and exclusions
13.1 The Supplier warrants that the Service is produced to professional standards and substantially conforms to the documentation. Save as stated above, the Service is provided “as is” and “as available”, without further warranties, express or implied, of fitness for a particular purpose or of the complete absence of errors.
13.2 The Customer acknowledges that the Service is an operational support tool: the accuracy of the data entered, management and commercial decisions, and compliance with the regulatory obligations of the tourism sector remain the exclusive responsibility of the Customer.
14. Limitation of liability
14.1 Except in cases of wilful misconduct or gross negligence, the Supplier’s aggregate liability arising out of or in connection with the contract is limited to the amount of the fees paid by the Customer in the 12 (twelve) months preceding the event giving rise to the damage.
14.2 Except in cases of wilful misconduct or gross negligence, the Supplier is not liable for indirect or consequential damages, such as loss of profits, goodwill, business opportunities or data (without prejudice to Annex A as regards personal data).
14.3 Nothing in these Terms excludes or limits liability that cannot be excluded or limited by law (art. 1229 of the Italian Civil Code).
15. Indemnity
15.1 The Customer indemnifies and holds the Supplier harmless against any third-party claim (including from the Customer’s end customers and from authorities) arising from: (a) breach of these Terms by the Customer or its Authorised Users; (b) Customer Data and its processing upstream of upload to the Service; (c) breach of the law applicable to the Customer’s activity.
16. Confidentiality
16.1 Each party undertakes to keep confidential the other party’s confidential information that comes to its knowledge in performing the contract, not to disclose it to third parties (save for advisers and staff bound by confidentiality) and to use it only for the purposes of the contract, for the term of the contract and for the 3 (three) years thereafter.
16.2 Information that is public, already known to the recipient, independently developed, or whose disclosure is required by law or by an authority is not treated as confidential.
17. Changes to the Terms
17.1 The Supplier may amend these Terms, including for regulatory, technical or organisational reasons, on at least 30 (thirty) days’ written notice by email or by notice within the Service.
17.2 If the amendment is substantially detrimental, the Customer may withdraw from the contract with effect from the date the amendment takes effect, by giving notice by that date. Use of the Service after that date constitutes acceptance.
18. Processing of personal data
18.1 In relation to the personal data contained in Customer Data, the Customer acts as controller and the Supplier as processor within the meaning of art. 28 of Regulation (EU) 2016/679 (“GDPR”), as governed by Annex A (DPA). The notice covering the data the Supplier processes as a controller is published in the privacy notice.
19. Notices
19.1 Notices relating to the contract are validly given: to the Supplier, by email to info@touroperate.com, which is the Supplier’s address for written notices under these Terms; to the Customer, at the email address associated with the Account or at the address given at registration. Operational communications may also be made through notices within the Service or through the channel that manages the subscription. The telephone number published by the Supplier is a contact channel and is not an address for notices under this article.
20. Final provisions
20.1 Assignment. The Customer may not assign the contract without the Supplier’s written consent. The Supplier may assign the contract in the context of extraordinary corporate transactions, giving notice to the Customer.
20.2 Force majeure. Neither party is liable for failures caused by events beyond its reasonable control.
20.3 Partial invalidity. The invalidity of individual clauses does not affect the remaining provisions.
20.4 Entire agreement. These Terms, together with their annexes and the order, constitute the entire agreement between the parties in relation to the Service and supersede any prior understanding.
20.5 Waiver. A party’s tolerance of the other party’s conduct in breach of the Terms does not constitute a waiver of the rights arising from the provisions breached.
21. Governing law and jurisdiction
21.1 The contract is governed by Italian law.
21.2 The courts of Rome have exclusive jurisdiction over any dispute arising out of or connected with the contract, save for any mandatory jurisdiction provided by law.
22. Clauses expressly approved
Pursuant to and for the purposes of arts. 1341 and 1342 of the Italian Civil Code, the following clauses require the Customer’s separate and specific approval, to be given in the contracting process by which the subscription is taken out, where those articles require it: art. 5.2 (automatic conversion of the free trial); art. 6.3 (automatic renewal); art. 6.5 (price changes); art. 6.6 (non-refundability); art. 6.7 (taxes and withholdings); art. 7 (term, termination for convenience and withdrawal); art. 8 (suspension and express termination clause); art. 11.3 (removal of content); art. 13 (warranty exclusions); art. 14 (limitation of liability); art. 15 (indemnity); art. 17 (unilateral changes to the Terms); art. 21.2 (exclusive jurisdiction). Publication of these Terms on this website, viewing this page, or merely creating an account does not itself supply that approval.
Annex A: Data Processing Agreement (DPA)
pursuant to art. 28 of Regulation (EU) 2016/679 (“GDPR”)
This Agreement (the “DPA”) forms an integral part of the General Terms and Conditions of the TourOperate Service and governs the processing of the personal data contained in Customer Data carried out by the Supplier on behalf of the Customer.
A.1 Roles and subject matter
A.1.1 The Customer acts as controller and the Supplier as processor within the meaning of art. 28 GDPR, in relation to the personal data contained in Customer Data.
A.1.2 The processing covers the data necessary to provide the Service, for the term of the contract plus the periods set out in art. A.6. Nature and purposes: operations carried out by electronic means (collection, recording, storage, consultation, retrieval, disclosure to the Customer, erasure) for the sole purpose of providing the management features of the Service.
A.1.3 Categories of data subjects: end customers/participants, the Customer’s contacts and staff, and the Customer’s guides and suppliers. Categories of data: identification and contact details, booking data and operational notes entered by the Customer. The Service is not intended for the systematic processing of special categories of data (art. 9 GDPR) and does not collect or store end customers’ payment data.
A.2 Obligations of the Supplier (processor)
The Supplier undertakes to:
- a) process the data only on documented instructions from the Customer, as set out in the contract, in this DPA and through use of the Service, save for legal obligations;
- b) ensure that persons authorised to process the data are bound by confidentiality;
- c) adopt security measures appropriate under art. 32 GDPR (see art. A.3);
- d) comply with the conditions for engaging sub-processors (art. A.4);
- e) assist the Customer, by appropriate measures, in responding to data subject requests (arts. 15-22 GDPR) and with the obligations under arts. 32-36 GDPR (security, breach notification, DPIA), taking into account the nature of the processing and the information available to it;
- f) inform the Customer without delay if an instruction infringes data protection law;
- g) make available to the Customer the information necessary to demonstrate compliance with art. 28 GDPR and allow audits and inspections carried out by the Customer or by an auditor it mandates, on reasonable notice; ordinarily once a year, without prejudice to any further audit required by law or by a supervisory authority, or following a personal data breach.
A.3 Security measures
The Supplier adopts technical and organisational measures appropriate to the risk, including: role-based access control and the principle of least privilege; encryption of data in transit (TLS) and at rest; periodic backups and restore procedures; separation of environments and security updates; instructions and training for authorised staff; an internal breach management procedure. The Supplier may update these measures provided it does not reduce the overall level of protection.
A.4 Sub-processors
A.4.1 The Customer gives general authorisation for the engagement of sub-processors for the provision of the Service (e.g. hosting/cloud, system email delivery). The Supplier informs the Customer of intended changes (addition or replacement) at least 15 days in advance; the Customer may object on legitimate grounds and, failing an alternative solution, withdraw without penalty. The up-to-date list is published in the privacy notice.
A.4.2 The Supplier imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains liable to the Customer for their performance.
A.5 Data breaches and transfers outside the EU
A.5.1 The Supplier notifies the Customer of any personal data breach without undue delay after becoming aware of it, providing the available information needed for the Customer to comply with arts. 33-34 GDPR.
A.5.2 The primary database of the Service is hosted in the European Union, in the Frankfurt region. Some of the sub-processors referred to in art. A.4 are established outside the European Economic Area, in particular in the United States, and backup, support and ancillary services may involve processing outside the EEA. The Supplier undertakes that each such transfer is covered by a transfer mechanism under Chapter V GDPR (an adequacy decision where one applies, or standard contractual clauses together with the supplementary measures necessary in the specific case), to keep the safeguards applicable to each sub-processor documented, and to provide the Customer, on request at info@touroperate.com, with their details and a copy of them.
A.6 Fate of the data on termination
On termination of the contract, at the Customer’s choice, the Supplier returns the data in a standard machine-readable format, with its assistance on request, and/or deletes it along with the existing copies, subject to statutory retention obligations. Absent a different request within 30 days of termination, the Supplier proceeds with deletion, save for backups, which are kept isolated and are overwritten according to ordinary cycles.
One limit must be stated plainly: an email that has already been delivered cannot be recalled or erased. Erasure reaches the copies the Supplier holds; retention at the mail provider follows that provider’s policies, and the copy in the recipient’s mailbox is permanently outside the Supplier’s control.
A.7 Obligations of the Customer (controller)
The Customer warrants that it has an appropriate legal basis for the data uploaded to the Service, that it has provided data subjects with the required privacy notices, and that the instructions given to the Supplier comply with applicable law. Each party is liable for damages within the limits of art. 82 GDPR, without prejudice to art. 14 of the Terms save for mandatory law.
Annex B: Separation measures and trust commitments
Recitals. The Supplier, TU Italia S.r.l., owns and operates the TourOperate Service and is at the same time the owner of the tour operating business carried on through EnRoma.com. The parties acknowledge that some Customers of the Service may operate, in whole or in part, in competition with EnRoma.com. This Annex B governs the organisational, technical and contractual measures by which the Supplier ensures separation between the tourism business of EnRoma.com and Customer Data, and forms an integral and substantial part of the Terms. As regards the matters governed here, this Annex prevails in the event of conflict with the Terms.
B.1 EnRoma.com as an ordinary tenant
B.1.1 EnRoma.com uses the Service exclusively as any other Customer would, through an ordinary Account, without privileged access, extended views, reserved paths or technical channels of access to other Customers’ Data beyond those available to any Customer on the same Plan.
B.1.2 No feature of the Service allows EnRoma.com to view, query, export or otherwise process other Customers’ Data. That characteristic is architectural in nature and not merely organisational.
B.2 Segregation of EnRoma.com staff
B.2.1 Staff carrying out the tourism operations of EnRoma.com are not authorised to access other Customers’ Data.
B.2.2 Access is governed by named authorisations under art. 29 GDPR and by written instructions, with segregation of roles between those working for the tourism business of EnRoma.com and those providing or maintaining the Service.
B.3 Access by Supplier staff
B.3.1 Access to Customer Data by the Supplier’s support, system administration and security staff is named, authenticated, limited to what is strictly necessary to provide the Service or to handle a Customer request, recorded in dedicated logs and reviewed periodically.
B.3.2 The Supplier does not claim the complete absence of all access; it guarantees that such access is traceable, limited to what is necessary, and reviewable.
B.4 Prohibition of commercial use
B.4.1 The Supplier does not use, and does not permit EnRoma.com or any other business attributable to TU Italia S.r.l. to use, Customer Data or any information derived from it for pricing decisions, marketing, sales, commercial positioning or any other purpose of a competitive nature.
B.4.2 The prohibition in this article also applies to Data processed in aggregated, statistical or otherwise derived form. The parties acknowledge that the aggregated nature of data does not make it anonymous.
B.5 Sanction for breach
B.5.1 Breach of any of the commitments in articles B.1-B.4 constitutes a serious default. In that event the Customer is entitled, cumulatively, to: (a) terminate the contract with immediate effect under art. 1456 of the Italian Civil Code, by written notice; (b) obtain, at no cost, a complete export of its Data in a standard machine-readable format; (c) compensation for the loss it proves to have suffered as a result of the breach.
B.5.2 The limitations and exclusions of liability in art. 14 of the Terms do not apply to breaches of the commitments in this Annex B.
B.6 The Customer’s right of verification
B.6.1 At the Customer’s reasonable request, the Supplier makes available: (a) the access logs relating to the Customer’s tenant; (b) the up-to-date list of sub-processors; (c) the contact point designated by the Supplier for security and data protection matters, which is info@touroperate.com.
B.6.2 This right is in addition to, and does not replace, the audit right under art. A.2(g) of Annex A.