Data Processing Agreement
(Article 28 of Regulation (EU) 2016/679 — GDPR)
Annex to the General Terms of Use — itinovo CRM, version 2.2 of 31 August 2026
Document version 1.1
This Agreement supplements and forms part of the General Terms of Use of the itinovo CRM service. By accepting the General Terms of Use, the Customer also accepts this Agreement, which is concluded in writing within the meaning of Article 28(9) GDPR ("including in electronic form"). On request, itinovo provides a PDF copy already signed on its side, which the Customer may countersign and retain.
1. The parties
Controller: the Customer, that is, the legal entity subscribing to itinovo CRM.
Processor: Itinovo S.r.l., via Lelli 3/13, 40065 Pianoro (BO), Italy — VAT no. IT04383971209 — certified email (PEC) itinovo@namirialpec.it — privacy contact: privacy@itinovo.com.
The Customer determines the purposes and means of the processing of personal data entered into the platform. itinovo processes such data solely on behalf of the Customer and on its documented instructions.
2. Subject matter, nature and purpose of the processing
itinovo provides the Customer with a SaaS software platform for managing the business of travel agencies and tour operators. The processing consists of the collection, recording, organisation, storage, retrieval, alteration, disclosure to recipients designated by the Customer, and erasure of the personal data entered by the Customer or by its end clients through the functions of the platform.
The sole purpose is the provision of the service requested by the Customer. itinovo does not use Customer data for its own purposes, does not disclose it to third parties other than as set out in this Agreement, and does not use it to train artificial intelligence models.
3. Duration
Processing begins when the service is activated and ends upon termination of the contract, subject to Clause 11 on return and erasure.
4. Categories of data subjects and types of personal data
Categories of data subjects: the Customer's users (agency staff); the Customer's clients and prospective clients; participants in trips organised by the Customer; contact persons at the Customer's suppliers and partners.
Ordinary categories of data:
- identification and contact data: first name, surname, email address, telephone number, address, city, nationality, date of birth;
- travel document data: document type (identity card, passport, driving licence), document number and expiry date;
- contractual and financial data: quotations, bookings, amounts, invoices, payments, commissions;
- travel data: destinations, dates, booked services, room allocation, sub-group membership, generated travel documents;
- professional data of participants, where entered by the Customer: company and job title;
- documents uploaded by the Customer and free-text notes;
- access data, activity records and technical logs.
Special categories of data (Article 9 GDPR). The platform provides the Customer with fields which, depending on how they are used, may contain special categories of personal data:
- dietary requirements of participants (including the halal and kosher options, from which religious beliefs may be inferred);
- accessibility requirements of participants, from which health data may be inferred.
Entering such data is at the Customer's discretion. As controller, the Customer is responsible for identifying an appropriate legal basis under Article 9(2) GDPR — as a rule, the data subject's explicit consent — and for providing the required information notice. itinovo processes such data solely on behalf of the Customer, applying the same security measures as to all other data and carrying out no further processing.
Automated extraction from documents. At the Customer's request, the platform can automatically extract data from an uploaded identity document in order to pre-fill the participant's fields. Processing is carried out using artificial intelligence models operated by Amazon Web Services in regions located within the European Union, as set out in Annex A. The result of the extraction always remains editable by the operator and produces no automated decision within the meaning of Article 22 GDPR.
5. Instructions of the Controller
itinovo processes personal data solely on the Customer's documented instructions. The General Terms of Use, this Agreement and the Customer's use of the platform's functions constitute such instructions.
Where itinovo is required to process data by Union or Member State law to which it is subject, it shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
itinovo shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
6. Confidentiality
itinovo ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The register of authorised persons is kept up to date and limited to the necessary minimum.
7. Security of processing
itinovo implements appropriate technical and organisational measures pursuant to Article 32 GDPR, described in Annex B — Technical and Organisational Measures, which forms an integral part of this Agreement.
itinovo reserves the right to update those measures in line with technological developments, provided that the level of security is not reduced below that described.
8. Sub-processors
The Customer grants itinovo general authorisation to engage sub-processors. The current list is published at https://crm.itinovo.com/{language}/subprocessors and reproduced in Annex A.
itinovo shall inform the Customer of any intended addition or replacement of sub-processors with at least 30 days' notice, by notification to the account administrator's email address and by updating the public page. Within that period the Customer may object on reasonable and documented data protection grounds. In the event of an objection, the parties shall seek an alternative solution in good faith; if none can be found, the Customer may terminate the contract without penalty with effect from the date the new sub-processor is engaged.
itinovo imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this Agreement, and remains liable to the Customer for their performance.
9. Transfers to third countries
Customer data is stored within the European Union, in the AWS region eu-central-1 (Frankfurt am Main, Germany). Artificial intelligence models are executed in AWS regions within the European Union, with eu-central-1 as the primary region, as set out in Annex A. In no case is data processed outside the territory of the European Union.
Transfers to third countries occur solely in the cases identified in Annex A and on the basis of the safeguards provided for in Chapter V GDPR, in particular the Standard Contractual Clauses adopted by the European Commission.
10. Assistance to the Controller
Taking into account the nature of the processing and the information available to it, itinovo assists the Customer:
- in responding to requests from data subjects exercising their rights (Articles 15–22 GDPR). Where such a request is received directly by itinovo, it shall forward it to the Customer without undue delay and shall not act on it independently;
- in ensuring compliance with the obligations relating to security, breach notification, communication to data subjects, data protection impact assessment and prior consultation (Articles 32–36 GDPR);
- by making available all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
11. Personal data breaches
itinovo shall notify the Customer of any personal data breach without undue delay and in any event within 48 hours of becoming aware of it, providing: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information.
Where it is not possible to provide all the information at the same time, it shall be provided in phases without further undue delay.
12. Return and erasure of data
The Customer may export its data at any time using the platform's export functions.
Upon termination of the contract, the Customer has 30 days to complete the export. After that period, itinovo permanently erases the personal data processed on the Customer's behalf. Any copies present in backups are removed in line with the backup rotation cycle, in any event within 35 days.
This is without prejudice to the 10-year retention required by Italian law of the accounting and tax records of the contractual relationship between itinovo and the Customer alone (invoices, accounting books and related documentation). That retention concerns itinovo as an independent controller for the purpose of complying with legal obligations and does not extend to the personal data entered by the Customer into the platform.
13. Audits and inspections
Upon written request, and no more than once a year, itinovo makes available to the Customer the documentation necessary to demonstrate compliance with this Agreement, including the certifications and compliance reports of its infrastructure provider.
Where that documentation is not sufficient, the Customer may request an inspection, to be agreed with at least 30 days' notice, held during business hours, without prejudice to the operation of the service and respecting the confidentiality of other customers. The costs of the inspection are borne by the Customer, unless the inspection reveals material breaches on the part of itinovo.
14. Governing law
This Agreement is governed by Italian law and by Regulation (EU) 2016/679. In the event of conflict between this Agreement and the General Terms of Use, this Agreement prevails in so far as the processing of personal data is concerned.