Data Processing Agreement

Last updated September 1, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Maksym Chernysh, an individual established in Italy ("TourMan", "we", "us"), of 15A Via dei Licheni, Roma, Lazio 00172, Italy, and the organization that has registered an account with TourMan ("Customer", "you"), and applies whenever TourMan processes Personal Data on Customer's behalf in the course of providing the TourMan service.

1. Definitions

Unless defined here, terms have the meaning given in the GDPR.

  • "GDPR" means Regulation (EU) 2016/679, and, where applicable, the UK GDPR and Data Protection Act 2018.
  • "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR.
  • "Customer Data" means the Personal Data TourMan Processes on Customer's behalf as a Processor — principally, Customer's guests' booking and contact information (see Annex 1).
  • "Sub-processor" means any third party TourMan engages to Process Customer Data on TourMan's behalf (see Annex 2).

2. Roles of the parties

For Customer Data (Annex 1) — guest names, contact details, booking details, and related communications — Customer is the Controller and TourMan is the Processor. TourMan Processes Customer Data only on Customer's documented instructions, given via Customer's use of the Service and this DPA.

For account data about Customer's own users (organization admins, managers, and guides who log into TourMan) TourMan is an independent Controller — this data is covered by TourMan's Privacy Policy, not this DPA.

3. TourMan's obligations as Processor

TourMan shall:

  • Process Customer Data only on Customer's documented instructions, including regarding international transfers, unless required to do otherwise by EU or Member State law.
  • Ensure persons authorized to Process Customer Data (TourMan's own personnel, currently: the sole operator) are subject to a duty of confidentiality.
  • Implement appropriate technical and organizational security measures (Annex 3).
  • Not engage a Sub-processor without Customer's authorization — see §4.
  • Assist Customer, by appropriate technical and organizational measures, in responding to requests from Data Subjects exercising their GDPR rights.
  • Assist Customer in ensuring compliance with its obligations under GDPR Articles 32–36 (security, breach notification, impact assessments).
  • At Customer's choice, delete or return all Customer Data at the end of the provision of Services, except where EU or Member State law requires retention (§8).
  • Make available to Customer all information reasonably necessary to demonstrate compliance with this Article, and allow for and contribute to audits, including inspections — see §9.
  • Immediately inform Customer if, in TourMan's opinion, an instruction infringes GDPR or other applicable data protection law.

4. Sub-processors

Customer authorizes TourMan to engage the Sub-processors listed in Annex 2 as of the date of this DPA. TourMan will give Customer notice (e.g., by updating the public sub-processor page and, for a material change, by email) before engaging a new Sub-processor, giving Customer a reasonable opportunity to object on reasonable data-protection grounds.

Where TourMan engages a Sub-processor, TourMan imposes data protection obligations on that Sub-processor that are no less protective than those in this DPA, and remains liable to Customer for that Sub-processor's performance of its obligations.

WhatsApp messaging is addressed separately. TourMan does not select, contract with, or maintain its own account with Meta for WhatsApp messaging on Customer's behalf. Each Customer independently creates and controls its own WhatsApp Business Account, phone number, and Meta Business Manager, and separately accepts Meta's own Business Terms directly with Meta — including attaching its own payment method. Customer then authorizes TourMan's single shared Meta application (via Meta's "Embedded Signup" flow) to send messages and manage message templates on Customer's WhatsApp Business Account. Because Customer — not TourMan — is Meta's counterparty and payer, Meta is not listed as a TourMan Sub-processor in Annex 2.

Under the EDPB's Guidelines 07/2020 on the concepts of controller and processor, a party becomes a processor of a given controller when that controller decides to delegate processing to it — processor status turns on who did the delegating, not on who happens to make the technical API call. Where Customer holds its own direct contract with the third party, as here, that third party is Customer's own separate processor, not a sub-processor of the platform that technically calls its API (further reading).

5. International transfers

Where TourMan or a Sub-processor Processes Customer Data outside the EEA/UK, TourMan ensures the transfer is protected by an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism under GDPR Chapter V:

  • Google Workspace — for a customer billing from an EEA/adequate country (Italy qualifies), Google's Data Processing Amendment applies the necessary EU Processor-to-Processor SCCs automatically.
  • Stripe — the DPA is part of the Stripe Services Agreement automatically. EEA→US transfers rely primarily on the EU-U.S. Data Privacy Framework, with SCCs as a fallback via Stripe's Data Transfers Addendum.
  • Resend — its Data Processing Addendum is automatically binding. EEA→US transfers are covered by EU SCCs (Module Two) plus EU-U.S. DPF/UK Extension certification.
  • Hetzner — Falkenstein, Germany. No international transfer at all; data doesn't leave the EU.
  • Meta / WhatsApp is addressed in §4, not here — since Meta is each Customer's own vendor rather than TourMan's, its transfer mechanism (WhatsApp Ireland relies on the EU-U.S. Data Privacy Framework for transfers to WhatsApp LLC in the US, with Processor-to-Processor SCCs as fallback) is between Customer and Meta under Customer's own Business Terms.

6. Personal Data Breaches

TourMan will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Data, and will provide the information reasonably available to it to allow Customer to meet its own Art. 33/34 obligations, and will take reasonable steps to mitigate the breach's effects.

7. Assistance with Data Subject requests

If TourMan directly receives a request from one of Customer's guests to exercise their GDPR rights, TourMan will, without undue delay, inform Customer and will not itself respond to that request unless legally required to, or Customer instructs otherwise.

8. Deletion and retention

On termination of Customer's subscription, TourMan schedules Customer Data for deletion; deletion actually occurs 30 days later, unless TourMan cancels the scheduled deletion in that window. Deletion, once it occurs, cascades to delete Customer's Users, Tours, Bookings, and related records. During the 30-day window, the organization is blocked from active use rather than continuing to operate as normal.

No independent legal retention requirement applies to Customer Data as defined in this DPA — unlike TourMan's own billing records with Customer itself, which are retained for the period required by Italian law (10 years for accounting records and invoices, under Art. 2220 of the Codice Civile) — that retention duty is disclosed in TourMan's Privacy Policy, not here.

9. Audits

On at least 30 days' prior written notice, and no more than once in any 12-month period, Customer may request that TourMan provide written information (e.g., a completed security questionnaire, or the description of measures in Annex 3) demonstrating TourMan's compliance with this DPA.

If that information isn't reasonably sufficient to address a specific, documented compliance concern, Customer — or an independent third-party auditor bound by confidentiality — may conduct an audit (including an on-site or remote inspection), on at least 30 days' notice and during business hours. The 12-month frequency limit doesn't apply to an audit following a Personal Data Breach or required by a supervisory authority. Customer bears its own costs of an audit; if it identifies a material breach of this DPA, TourMan bears its own reasonable costs of participating in it.

10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

11. Term

This DPA remains in effect for as long as TourMan Processes Customer Data on Customer's behalf.

12. Governing law

This DPA is governed by the laws of Italy, without regard to its conflict-of-laws principles. The parties submit to the exclusive jurisdiction of the courts of Rome, Italy, for any dispute arising out of or in connection with this DPA.

Annex 1 — Details of Processing

Subject matterTourMan's provision of a tour-operator management platform (booking management, scheduling, guest communication) to Customer.
DurationFor the term of Customer's subscription, plus any post-termination retention described in §8.
Nature and purposeAutomated parsing of booking confirmation emails; guest communication via WhatsApp; storage and display of booking/schedule data within Customer's TourMan account.
Categories of Data SubjectsCustomer's guests (the people who book tours through Customer).
Categories of Personal DataGuest name, email address, phone number, headcount (adults/children — no separate name or other identifying data is collected about individual children), booking date/time/tour selected, WhatsApp message content related to a booking, payment-confirmation status.
Special categories of dataNone intentionally collected. TourMan does not ask for or design for health, biometric, or similarly sensitive data about guests.

Annex 2 — Sub-processors

See the Sub-processors page for the current list — kept there as the single source of truth rather than duplicated here.

Annex 3 — Technical and Organizational Security Measures

  • Passwords: hashed with bcrypt (cost factor 12), never stored or logged in plaintext.
  • Access control: role-based access (Admin / Manager / Guide) scoped per organization; a user cannot see another organization's data.
  • Privileged action logging: administrative actions with real-world consequence (impersonating a user, resetting a password, deleting a user or organization, granting elevated cross-organization access) are recorded in an audit log with actor, target, and timestamp.
  • Impersonation controls: administrative "log in as" sessions are time-limited (1 hour), clearly flagged to the impersonated session, and self-service password changes are blocked while impersonating.
  • Encryption in transit: the Service is served over HTTPS (TLS certificates provisioned automatically via Coolify, the deployment platform).
  • Network protection: a firewall and DDoS protection are in place at the infrastructure level.
  • Backups: database backups are automated via Coolify.
  • Hosting: self-managed infrastructure on Hetzner, physically located in Falkenstein, Germany (EU). Infrastructure access is restricted to TourMan's own personnel (currently, the sole operator).
  • Encryption at rest: not currently configured on the Hetzner servers.
Data Processing Agreement — TourMan