Legal

Privacy Policy

Last updated June 24, 2026

This policy explains what data Itero Desk collects, how we use it, and the choices you have. It applies to the Itero Desk web application, marketing website, and related services. Itero Desk is a trading name registered in Portugal. Contact: hello@iterodesk.com. In this policy "Itero Desk", "we" and "us" refer to that operator, and "you" or "Customer" refers to the organisation or person using the Service.

1. Controller & processor · who is responsible for what

This is a B2B service, and roles under the GDPR depend on the type of data:

  • End-client personal data you upload. For all personal data about your end clients and other individuals that you enter or upload into your workspace · including traveller names, passport details, dates of birth, contact details, health or dietary information, and payment details · you are the sole data controller and Itero Desk acts solely as your data processor, processing that data only on your documented instructions to provide the Service.
  • Your own account data. For the personal data of your account users (names, emails, login data) and our marketing-site visitors, Itero Desk acts as the controller for the limited purposes of operating, securing and supporting the Service.

As controller of end-client data, you warrant that you have a valid lawful basis and any required consents for all data you upload, and that you are solely responsible for the legality of its collection and use, for handling data-subject requests, and for your overall GDPR compliance. Responsibility for breaches of those obligations rests with you, as set out in our Terms of Service.

2. Data we collect

Account & workspace data

  • Your name, email and, optionally, your avatar and phone number.
  • Your company name, branding (logo, accent colour) and team members you invite.
  • Authentication information (hashed password, session tokens).

Operational data you enter (processed on your instructions)

  • Lead contact details, itineraries, pricing, destinations, accommodations, vehicles, guides, and similar library content · including end-client personal data for which you are the controller.
  • Email threads you sync from your configured mailbox to track lead communication.
  • Files and images you upload (cover photos, PDFs, supporting attachments).

Usage & technical data

  • Log data: IP address, browser and device type, pages visited, timestamps.
  • Minimal product analytics to understand which features are used and to detect errors.

3. How we use data

  • To provide the service: run your workspace, generate proposals, calculate pricing, send emails.
  • To communicate with you about account activity, billing and important product changes.
  • To secure the service: detect abuse, rate-limit, investigate incidents.
  • To improve the product in aggregate. We do not sell your data or use it to train third-party AI models.

4. AI features

Some features (for example draft itineraries and welcome letters) use large language models provided by third parties (such as Anthropic). When you use those features, the relevant prompt text is sent to the model provider to generate a response. We do not use your inputs to train foundation models, and we ask providers to retain request data only for the shortest period permitted by their policies.

5. Multi-tenant isolation

Each company gets its own workspace. Data is scoped per tenant: other customers cannot read or write your records. Administrative access by our team is limited to what is necessary to operate or debug the service, and is logged.

6. Sub-processors

We use a small set of infrastructure and tooling providers to run the service, including:

  • Cloud hosting and database infrastructure.
  • Email delivery (transactional email).
  • Stripe · payment processing for subscriptions.
  • AI model providers (for AI-assisted features, when you use them).
  • Error monitoring and product analytics.

We require sub-processors to provide appropriate safeguards for the data they handle. Contact us for the current list of sub-processors.

7. Our commitments as your processor

When we act as your data processor for end-client data, we will:

  • process that data only on your documented instructions, including for international transfers, unless required otherwise by law;
  • ensure that people authorised to process the data are bound by appropriate confidentiality obligations;
  • apply reasonable technical and organisational security measures appropriate to the risk (see §9);
  • engage sub-processors only with general authorisation (the categories listed in §6, including hosting and Stripe), and impose comparable data-protection obligations on them;
  • taking into account the nature of the processing, assist you, where reasonable, in responding to data-subject requests and in meeting your security, breach-notification and impact-assessment obligations;
  • notify you without undue delay after becoming aware of a personal-data breach affecting your data;
  • on termination, delete or return your workspace data in line with §8, save where retention is required by law.

8. Retention

We keep your workspace data as long as your account is active. After cancellation we retain data for a limited period to allow account recovery and to meet legal obligations, and then delete or anonymise it. You can request earlier deletion at any time.

9. Security

We use encryption in transit (HTTPS), encryption at rest for the database, hashed passwords and role-based access controls. We apply reasonable technical and organisational measures, but no system is completely secure and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately.

10. Your rights

Depending on where you are based, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. For data where Itero Desk is the controller, you can exercise these rights by emailing us. For end-client data where you are the controller, those individuals should contact you, and we will assist you as your processor as described in §7.

11. Children

Itero Desk is not intended for children under 16. We do not knowingly collect data from them.

12. Changes

If we change this policy materially we will notify account admins by email and, where the change is significant, in the app. Continued use after an update means you accept the revised policy.

13. Contact

Questions or requests about this policy, or to reach the data controller: email hello@iterodesk.com or use our contact form.