edenfinder

Nuitee Datenschutz & Compliance

Direktbuchungen auf edenfinder.com werden von Nuitee Travel Limited als Merchant of Record abgewickelt. Aus Transparenzgründen führt diese Seite die offiziellen Nuitee-Referenzen zu Datenschutz, dem Data Processing Agreement (DPA) für Europa und zur regulatorischen Compliance auf.

Inhalte auf Englisch, automatisch aus der offiziellen Nuitee-Dokumentation (docs.liteapi.travel) übernommen und täglich neu synchronisiert. Maßgeblich ist die von Nuitee veröffentlichte Version.

Datenschutz & Privacy

Originaldokument

Types of Data Processed

Nuitee Connect processes data strictly necessary to provide travel search, booking, and related API services. Depending on the API and use case, this may include:

  • Business contact information
    (e.g. customer account details, API credentials, technical contacts)

  • Booking-related data
    (e.g. guest names, stay dates, hotel identifiers, nationality, pricing details)

  • Technical and operational data
    (e.g. IP addresses, request metadata, logs, timestamps)

Nuitee Connect does not intentionally collect special categories of personal data as defined under GDPR (such as health, biometric, or political data).


Roles and Responsibilities

Under GDPR and similar data protection frameworks:

  • Customers act as the Data Controller, determining the purpose and lawful basis for processing personal data.
  • Nuitee Connect acts as a Data Processor, processing data solely on documented instructions from the customer and only for the purpose of providing the services.

Nuitee Connect does not use customer data for advertising, profiling, or resale.


Lawful Processing & Data Minimization

Nuitee Connect applies the principle of data minimization by:

  • Processing only data required for API functionality
  • Avoiding unnecessary storage of personal data
  • Limiting internal access to data on a need-to-know basis

Customers are responsible for ensuring that any personal data sent to Nuitee Connect is lawfully collected and shared.


Data Retention

Nuitee Connect retains data only for as long as necessary to:

  • Provide the contracted services
  • Meet legal, accounting, and regulatory obligations
  • Support operational security, fraud prevention, and dispute resolution

Retention periods vary by data type and purpose. Personal data is deleted or anonymized when it is no longer required, in accordance with internal retention policies.


Sub-Processors

Nuitee Connect may engage carefully selected third-party service providers (sub-processors) to support infrastructure, hosting, monitoring, and operational services.

All sub-processors are subject to contractual obligations regarding data protection, confidentiality, and security that are consistent with applicable data protection laws.

A list of sub-processors can be provided upon request.


Data Subject Rights

Where Nuitee Connect acts as a data processor, requests from data subjects (such as access, rectification, or deletion) should be directed to the relevant customer acting as data controller.

Nuitee Connect supports customers in fulfilling such requests where required by law and within the scope of the services.


International Data Transfers

Nuitee Connect may process data in jurisdictions outside the customer’s country of operation, including within the European Union.

Where international data transfers occur, Nuitee Connect relies on appropriate safeguards such as Standard Contractual Clauses or equivalent legal mechanisms, in accordance with applicable regulations.


Data Protection Agreements

Nuitee Connect offers a Data Processing Agreement (DPA) aligned with GDPR requirements. The DPA defines the roles, responsibilities, and security measures applicable to the processing of personal data.

Data Processing Agreement (DPA) — Europa

Originaldokument

Scope and Purpose

The Data Processing Agreement applies where Nuitee Connect processes personal data on behalf of a customer in the course of providing its services.

The DPA:

  • Defines the roles and responsibilities of each party
  • Ensures compliance with GDPR Article 28
  • Applies to all Nuitee Connect services that involve the processing of personal data

Roles Under GDPR

For the purposes of the GDPR:

  • Customer acts as the Data Controller
  • Nuitee Connect acts as the Data Processor

Nuitee Connect processes personal data solely on documented instructions from the customer and only to provide and operate the services.


Categories of Data and Data Subjects

Data Subjects

May include:

  • End users
  • Travelers or guests
  • Customer employees or agents

Categories of Personal Data

May include:

  • Identifiers (e.g. names, booking references)
  • Contact information (where applicable)
  • Booking and travel-related data
  • Technical and usage data

Nuitee Connect does not intentionally process special categories of personal data under GDPR.


Processing Activities

Nuitee Connect processes personal data for the following purposes:

  • Providing API-based travel search, booking, and related services
  • Operating and maintaining the Nuitee Connect platform
  • Security monitoring and incident prevention
  • Customer support and troubleshooting

Data Protection Obligations

Nuitee Connect commits to:

  • Process personal data lawfully, fairly, and transparently
  • Implement appropriate technical and organizational security measures
  • Ensure confidentiality of personnel with access to personal data
  • Restrict access to personal data on a need-to-know basis

Sub-Processors

Nuitee Connect may engage sub-processors to support infrastructure and service delivery.

Nuitee Connect ensures that:

  • Sub-processors are bound by data protection obligations equivalent to those in the DPA
  • Customers are informed of sub-processors upon request
  • Sub-processors are subject to appropriate security and confidentiality commitments

International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), Nuitee Connect relies on appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Contractual and technical safeguards consistent with GDPR requirements

Data Subject Rights

Nuitee Connect supports customers in fulfilling data subject rights requests, including:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing

Requests from data subjects should be directed to the customer acting as Data Controller.


Security Incident Notification

Nuitee Connect will notify customers without undue delay after becoming aware of a personal data breach affecting customer data, in accordance with GDPR requirements.

Notifications will include relevant information available at the time.


Data Retention and Deletion

Personal data is retained only for as long as necessary to provide the services and meet legal or operational obligations.

Upon termination of the services, Nuitee Connect will delete or anonymize personal data in accordance with the DPA, unless retention is required by law.


Audits and Compliance

Nuitee Connect makes available information reasonably necessary to demonstrate compliance with GDPR obligations and the DPA.

Audit requests are subject to reasonable notice, scope, and confidentiality obligations.


Availability of the DPA

The formal Data Processing Agreement (DPA) is available upon request and forms part of the contractual documentation governing Nuitee Connect services.

Customers can request the DPA through their account or support contact.


Questions

For questions related to data protection or the DPA, customers can contact us through the usual support or account channels.

Regulatorische Compliance

Originaldokument

General Data Protection Regulation (GDPR)

Nuitee Connect complies with the EU General Data Protection Regulation (GDPR).

Key principles applied include:

  • Lawfulness, fairness, and transparency of processing
  • Purpose limitation and data minimization
  • Integrity and confidentiality of personal data
  • Accountability and documentation of processing activities

As described in the Data Protection & Privacy section, Nuitee Connect generally acts as a Data Processor, while customers act as Data Controllers.


Jurisdiction and Supervisory Authority

Nuitee Connect operates under the jurisdiction of Ireland, a member state of the European Union.

As such:

  • EU data protection laws apply by default
  • Nuitee Connect is subject to oversight by the Irish Data Protection Commission (DPC)

This provides a clear and well-established regulatory framework for data protection and privacy.


PCI DSS (Payment Card Industry Data Security Standard)

Nuitee Connect does not store, process, or transmit raw payment card data.

Card payments are handled through PCI-compliant third-party payment providers using a PCI proxy or redirection model. As a result:

  • Nuitee Connect’s PCI DSS scope is limited
  • Nuitee Connect aligns with SAQ A requirements under PCI DSS v4.x
  • Sensitive cardholder data never passes through Nuitee Connect systems

Customers remain responsible for their own PCI DSS obligations based on their integration model.


Third-Party Compliance Dependencies

Nuitee Connect relies on trusted third-party providers for infrastructure and operational services, including:

  • Cloud hosting
  • Monitoring and logging
  • Payment processing (where applicable)

These providers maintain their own industry-standard certifications and compliance programs (such as ISO 27001, SOC 2, or PCI DSS, depending on the service).

Nuitee Connect performs due diligence when selecting and reviewing third-party vendors.


Data Protection Agreements (DPA)

Nuitee Connect offers a Data Processing Agreement (DPA) consistent with GDPR Article 28 requirements.

The DPA defines:

  • Processing scope and purpose
  • Security and confidentiality obligations
  • Sub-processor conditions
  • Data subject rights support
  • Audit and compliance terms

The DPA is available upon request.


Audits and Assessments

Nuitee Connect maintains internal controls and documentation to support security and compliance reviews.

While Nuitee Connect does not publicly publish audit reports, reasonable security and compliance information may be shared with customers under appropriate confidentiality terms.


Regulatory Updates

Nuitee Connect monitors regulatory developments and adapts its policies and controls as required to remain compliant with applicable laws and industry standards.