This is an English translation provided for convenience. In case of any discrepancy, the Italian version prevails.
This agreement (Data Processing Agreement) governs, pursuant to Art. 28 GDPR, the processing of personal data that GateAway carries out on behalf of the advisor when the advisor enters their own clients’ data (the travelers) into the service. By accepting the Terms of Service at sign-up, the advisor also accepts this agreement. The agreement applies when the user processes travelers’ data as a Controller (typically in professional use); for a private user acting for purely personal purposes, that processing may fall under the household exemption (Art. 2(2)(c) GDPR) and this agreement does not apply to it.
1. Definitions and roles
Controller: the advisor/agency who uses GateAway and decides the purposes and means of processing travelers’ data. Processor: GateAway (Adelchi Brignoli, tax code BRGDCH89M13F119Y, Via Mozart 18, 20050 Liscate, MI, Italy), which processes such data on behalf of the Controller. Data subjects: the travelers and their companions. GateAway is instead an independent Controller only for the advisor’s account data (governed by the Privacy notice).
2. Subject matter, duration, nature and purpose
The subject matter, nature, purpose of the processing, categories of data subjects and types of data are described in Annex 1. The processing lasts as long as the service relationship.
3. Controller’s instructions
GateAway processes personal data only on the basis of the Controller’s documented instructions; using the service’s features constitutes an instruction. GateAway informs the Controller if, in its opinion, an instruction infringes data protection law.
4. Confidentiality
GateAway ensures that the persons authorized to process the data are bound by a duty of confidentiality.
5. Security of processing
GateAway adopts technical and organizational measures adequate under Art. 32 GDPR, described in Annex 2.
6. Sub-processors
The Controller authorizes the use of the sub-processors listed in Annex 3. GateAway imposes on them, by contract, data protection obligations equivalent to those of this agreement. In case of new sub-processors, GateAway communicates this in advance and the Controller may object on legitimate grounds.
7. Assistance to the Controller
Taking into account the nature of the processing, GateAway assists the Controller — also through the service’s features — in responding to data subjects’ requests (access, rectification, erasure, portability, restriction, objection) and in fulfilling the obligations under Arts. 32-36 GDPR (security, breach notification, impact assessments).
8. Personal data breaches
GateAway notifies the Controller without undue delay after becoming aware of a personal data breach, providing the information needed for the Controller to fulfil its obligations towards the supervisory authority and the data subjects.
9. Transfers outside the European Union
Data is normally processed within the European Union. Any transfers to third countries by sub-processors (e.g. Google, for the AI feature) take place with adequate safeguards (Standard Contractual Clauses or EU-US Data Privacy Framework adequacy, of which the Controller may request a copy). For the AI feature the Gemini API Terms apply; on the paid tier Google does not use the data sent to train or improve its models.
10. Deletion or return of data
At the end of the relationship, at the Controller’s choice, GateAway deletes or returns the personal data and deletes the copies, except for legal retention obligations. The "delete trip" and "delete account" features allow the Controller immediate deletion.
11. Audit
The Controller exercises the right of audit by first requesting from GateAway documentation, certifications or reports on the security measures. On-site inspections or direct checks on the systems are possible only if the documentation is not suitable to demonstrate compliance, must be agreed with at least 30 days’ notice, are at the Controller’s expense and take place in a manner that does not compromise the confidentiality of other clients and the security of the infrastructure.
12. Applicable law
This agreement is governed by Italian law and is interpreted in accordance with the GDPR. In case of conflict with the Terms of Service, this agreement prevails on data protection matters.
Annex 1 — Details of the processing
Subject matter: provision of the GateAway service (creation, storage, AI-assisted generation and sharing of travel itineraries and related documents).
Duration: for the entire duration of the service relationship.
Categories of data subjects: the advisor’s clients (travelers) and their companions, possibly including minors.
Types of data: identifying and contact data, trip details and, if uploaded by the Controller, documents that may contain identity documents, data relating to minors or other special categories (Art. 9). The Controller is responsible for the legal basis and adequacy of the data it enters. GateAway is not able to identify in advance or filter such special categories. The Controller warrants a valid condition under Art. 9(2) GDPR for any special-category data; GateAway treats it as potentially special and applies adequate security measures to it (Art. 32).
Annex 2 — Technical and organizational measures
Measures currently adopted:
- Encryption of data in transit (HTTPS/TLS).
- Encryption at rest of database and files (provided by the Supabase infrastructure).
- User authentication (hashed passwords, or Google sign-in) and per-user data isolation via Row-Level Security.
- Documents in a private bucket, accessible only via time-limited signed URLs or a server-validated sharing token.
- Sharing with an unguessable token, expiry and revocation; the option to exclude documents from the link.
- Managed hosting infrastructure, with security updates and patches applied by the provider.
- Consent register (date, time, IP address).
- Minimization: the advisor’s internal notes are never included in the client link.
- Access log on the opening of shared links and the download of documents (date, IP and user agent).
- Internal access control on a least-privilege basis: authorized staff access only the data needed to provide and support the service.
Annex 3 — List of sub-processors
- Vercel — application hosting and compute (request handling, page rendering, document delivery) and aggregate, cookieless traffic statistics (Web Analytics, Speed Insights). Processing in the USA with adequate safeguards (SCC / EU-US Data Privacy Framework).
- Supabase — database, authentication and file storage at rest. Servers in the European Union.
- Google — AI itinerary generation (Gemini), only if the advisor uses the AI feature, and Google Maps/Places to search a stop’s exact place in the editor. Processing in the USA with Standard Contractual Clauses; on the paid tier of the Gemini API Google does not use the data to train its models (Gemini API terms).
- Resend — sending service and lifecycle emails (welcome, password reset, onboarding and inactivity notices). EU/USA processing with adequate safeguards (SCC / EU-US Data Privacy Framework).
- Open-Meteo — daily weather from the trip’s location. Receives only the given city, not the traveler’s data. Processing within the European Union.
- Sentry — monitoring of the platform’s technical errors (stability and security). It receives only technical error data and any internal identifiers (e.g. user/trip ID), not IP addresses, cookies or itinerary content. Servers in the European Union.
Lemon Squeezy (Merchant of Record for payments) is not a sub-processor under this agreement: it does not process travelers’ data and acts as an independent Controller for billing and payments.