Your operation stays yours.
TourOperate and EnRoma.com are the same company, TU Italia S.r.l. - EnRoma.com is our own tour operation in Rome, not an independent customer. So a fair question from any operator is: can our tour business see yours? Inside one company there is no corporate wall - so we keep them apart by architecture and by contract. Here is exactly how.
EnRoma.com is an ordinary tenant.
It has no privileged access and no reserved path to any data - the same isolation as every other account. This separation is enforced by the product's tenant architecture, not by giving EnRoma.com special treatment.
Our tour-operations people cannot see other customers' data.
Access is granted by name - named authorisations under GDPR article 29 - with written instructions and a separation of roles.
Support and security access is named, logged and reviewed.
Access by TourOperate's support and security staff is named, authenticated, kept to the minimum needed, recorded and reviewed. We do not claim that no one ever accesses anything - that would not be true. Specific people, for a specific reason, under audit.
We do not use your data commercially.
Your data, and anything derived from it, is never used for EnRoma.com's pricing, marketing, sales or positioning.
Breaking this has a price.
A breach gives you the right to terminate immediately, export all of your data, and a defined contractual penalty.
Prefer email? Join.