Last updated September 1, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Maksym Chernysh, an individual established in Italy ("TourMan", "we", "us"), of 15A Via dei Licheni, Roma, Lazio 00172, Italy, and the organization that has registered an account with TourMan ("Customer", "you"), and applies whenever TourMan processes Personal Data on Customer's behalf in the course of providing the TourMan service.
Unless defined here, terms have the meaning given in the GDPR.
For Customer Data (Annex 1) — guest names, contact details, booking details, and related communications — Customer is the Controller and TourMan is the Processor. TourMan Processes Customer Data only on Customer's documented instructions, given via Customer's use of the Service and this DPA.
For account data about Customer's own users (organization admins, managers, and guides who log into TourMan) TourMan is an independent Controller — this data is covered by TourMan's Privacy Policy, not this DPA.
TourMan shall:
Customer authorizes TourMan to engage the Sub-processors listed in Annex 2 as of the date of this DPA. TourMan will give Customer notice (e.g., by updating the public sub-processor page and, for a material change, by email) before engaging a new Sub-processor, giving Customer a reasonable opportunity to object on reasonable data-protection grounds.
Where TourMan engages a Sub-processor, TourMan imposes data protection obligations on that Sub-processor that are no less protective than those in this DPA, and remains liable to Customer for that Sub-processor's performance of its obligations.
WhatsApp messaging is addressed separately. TourMan does not select, contract with, or maintain its own account with Meta for WhatsApp messaging on Customer's behalf. Each Customer independently creates and controls its own WhatsApp Business Account, phone number, and Meta Business Manager, and separately accepts Meta's own Business Terms directly with Meta — including attaching its own payment method. Customer then authorizes TourMan's single shared Meta application (via Meta's "Embedded Signup" flow) to send messages and manage message templates on Customer's WhatsApp Business Account. Because Customer — not TourMan — is Meta's counterparty and payer, Meta is not listed as a TourMan Sub-processor in Annex 2.
Under the EDPB's Guidelines 07/2020 on the concepts of controller and processor, a party becomes a processor of a given controller when that controller decides to delegate processing to it — processor status turns on who did the delegating, not on who happens to make the technical API call. Where Customer holds its own direct contract with the third party, as here, that third party is Customer's own separate processor, not a sub-processor of the platform that technically calls its API (further reading).
Where TourMan or a Sub-processor Processes Customer Data outside the EEA/UK, TourMan ensures the transfer is protected by an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism under GDPR Chapter V:
TourMan will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Data, and will provide the information reasonably available to it to allow Customer to meet its own Art. 33/34 obligations, and will take reasonable steps to mitigate the breach's effects.
If TourMan directly receives a request from one of Customer's guests to exercise their GDPR rights, TourMan will, without undue delay, inform Customer and will not itself respond to that request unless legally required to, or Customer instructs otherwise.
On termination of Customer's subscription, TourMan schedules Customer Data for deletion; deletion actually occurs 30 days later, unless TourMan cancels the scheduled deletion in that window. Deletion, once it occurs, cascades to delete Customer's Users, Tours, Bookings, and related records. During the 30-day window, the organization is blocked from active use rather than continuing to operate as normal.
No independent legal retention requirement applies to Customer Data as defined in this DPA — unlike TourMan's own billing records with Customer itself, which are retained for the period required by Italian law (10 years for accounting records and invoices, under Art. 2220 of the Codice Civile) — that retention duty is disclosed in TourMan's Privacy Policy, not here.
On at least 30 days' prior written notice, and no more than once in any 12-month period, Customer may request that TourMan provide written information (e.g., a completed security questionnaire, or the description of measures in Annex 3) demonstrating TourMan's compliance with this DPA.
If that information isn't reasonably sufficient to address a specific, documented compliance concern, Customer — or an independent third-party auditor bound by confidentiality — may conduct an audit (including an on-site or remote inspection), on at least 30 days' notice and during business hours. The 12-month frequency limit doesn't apply to an audit following a Personal Data Breach or required by a supervisory authority. Customer bears its own costs of an audit; if it identifies a material breach of this DPA, TourMan bears its own reasonable costs of participating in it.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
This DPA remains in effect for as long as TourMan Processes Customer Data on Customer's behalf.
This DPA is governed by the laws of Italy, without regard to its conflict-of-laws principles. The parties submit to the exclusive jurisdiction of the courts of Rome, Italy, for any dispute arising out of or in connection with this DPA.
| Subject matter | TourMan's provision of a tour-operator management platform (booking management, scheduling, guest communication) to Customer. |
| Duration | For the term of Customer's subscription, plus any post-termination retention described in §8. |
| Nature and purpose | Automated parsing of booking confirmation emails; guest communication via WhatsApp; storage and display of booking/schedule data within Customer's TourMan account. |
| Categories of Data Subjects | Customer's guests (the people who book tours through Customer). |
| Categories of Personal Data | Guest name, email address, phone number, headcount (adults/children — no separate name or other identifying data is collected about individual children), booking date/time/tour selected, WhatsApp message content related to a booking, payment-confirmation status. |
| Special categories of data | None intentionally collected. TourMan does not ask for or design for health, biometric, or similarly sensitive data about guests. |
See the Sub-processors page for the current list — kept there as the single source of truth rather than duplicated here.