Protezione dati e conformità Nuitee
Le prenotazioni dirette su edenfinder.com sono elaborate da Nuitee Travel Limited in qualità di merchant of record. Per trasparenza riportiamo qui i riferimenti ufficiali di Nuitee su protezione dei dati, accordo di trattamento dati (DPA) per l’Europa e conformità normativa.
Contenuti in inglese, riprodotti automaticamente dalla documentazione ufficiale Nuitee (docs.liteapi.travel) e risincronizzati ogni giorno. Fa fede la versione pubblicata da Nuitee.
Protezione dei dati e privacy
Types of Data Processed
Nuitee Connect processes data strictly necessary to provide travel search, booking, and related API services. Depending on the API and use case, this may include:
-
Business contact information
(e.g. customer account details, API credentials, technical contacts) -
Booking-related data
(e.g. guest names, stay dates, hotel identifiers, nationality, pricing details) -
Technical and operational data
(e.g. IP addresses, request metadata, logs, timestamps)
Nuitee Connect does not intentionally collect special categories of personal data as defined under GDPR (such as health, biometric, or political data).
Roles and Responsibilities
Under GDPR and similar data protection frameworks:
- Customers act as the Data Controller, determining the purpose and lawful basis for processing personal data.
- Nuitee Connect acts as a Data Processor, processing data solely on documented instructions from the customer and only for the purpose of providing the services.
Nuitee Connect does not use customer data for advertising, profiling, or resale.
Lawful Processing & Data Minimization
Nuitee Connect applies the principle of data minimization by:
- Processing only data required for API functionality
- Avoiding unnecessary storage of personal data
- Limiting internal access to data on a need-to-know basis
Customers are responsible for ensuring that any personal data sent to Nuitee Connect is lawfully collected and shared.
Data Retention
Nuitee Connect retains data only for as long as necessary to:
- Provide the contracted services
- Meet legal, accounting, and regulatory obligations
- Support operational security, fraud prevention, and dispute resolution
Retention periods vary by data type and purpose. Personal data is deleted or anonymized when it is no longer required, in accordance with internal retention policies.
Sub-Processors
Nuitee Connect may engage carefully selected third-party service providers (sub-processors) to support infrastructure, hosting, monitoring, and operational services.
All sub-processors are subject to contractual obligations regarding data protection, confidentiality, and security that are consistent with applicable data protection laws.
A list of sub-processors can be provided upon request.
Data Subject Rights
Where Nuitee Connect acts as a data processor, requests from data subjects (such as access, rectification, or deletion) should be directed to the relevant customer acting as data controller.
Nuitee Connect supports customers in fulfilling such requests where required by law and within the scope of the services.
International Data Transfers
Nuitee Connect may process data in jurisdictions outside the customer’s country of operation, including within the European Union.
Where international data transfers occur, Nuitee Connect relies on appropriate safeguards such as Standard Contractual Clauses or equivalent legal mechanisms, in accordance with applicable regulations.
Data Protection Agreements
Nuitee Connect offers a Data Processing Agreement (DPA) aligned with GDPR requirements. The DPA defines the roles, responsibilities, and security measures applicable to the processing of personal data.
Accordo sul trattamento dei dati (DPA) — Europa
Scope and Purpose
The Data Processing Agreement applies where Nuitee Connect processes personal data on behalf of a customer in the course of providing its services.
The DPA:
- Defines the roles and responsibilities of each party
- Ensures compliance with GDPR Article 28
- Applies to all Nuitee Connect services that involve the processing of personal data
Roles Under GDPR
For the purposes of the GDPR:
- Customer acts as the Data Controller
- Nuitee Connect acts as the Data Processor
Nuitee Connect processes personal data solely on documented instructions from the customer and only to provide and operate the services.
Categories of Data and Data Subjects
Data Subjects
May include:
- End users
- Travelers or guests
- Customer employees or agents
Categories of Personal Data
May include:
- Identifiers (e.g. names, booking references)
- Contact information (where applicable)
- Booking and travel-related data
- Technical and usage data
Nuitee Connect does not intentionally process special categories of personal data under GDPR.
Processing Activities
Nuitee Connect processes personal data for the following purposes:
- Providing API-based travel search, booking, and related services
- Operating and maintaining the Nuitee Connect platform
- Security monitoring and incident prevention
- Customer support and troubleshooting
Data Protection Obligations
Nuitee Connect commits to:
- Process personal data lawfully, fairly, and transparently
- Implement appropriate technical and organizational security measures
- Ensure confidentiality of personnel with access to personal data
- Restrict access to personal data on a need-to-know basis
Sub-Processors
Nuitee Connect may engage sub-processors to support infrastructure and service delivery.
Nuitee Connect ensures that:
- Sub-processors are bound by data protection obligations equivalent to those in the DPA
- Customers are informed of sub-processors upon request
- Sub-processors are subject to appropriate security and confidentiality commitments
International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), Nuitee Connect relies on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Contractual and technical safeguards consistent with GDPR requirements
Data Subject Rights
Nuitee Connect supports customers in fulfilling data subject rights requests, including:
- Access
- Rectification
- Erasure
- Restriction of processing
Requests from data subjects should be directed to the customer acting as Data Controller.
Security Incident Notification
Nuitee Connect will notify customers without undue delay after becoming aware of a personal data breach affecting customer data, in accordance with GDPR requirements.
Notifications will include relevant information available at the time.
Data Retention and Deletion
Personal data is retained only for as long as necessary to provide the services and meet legal or operational obligations.
Upon termination of the services, Nuitee Connect will delete or anonymize personal data in accordance with the DPA, unless retention is required by law.
Audits and Compliance
Nuitee Connect makes available information reasonably necessary to demonstrate compliance with GDPR obligations and the DPA.
Audit requests are subject to reasonable notice, scope, and confidentiality obligations.
Availability of the DPA
The formal Data Processing Agreement (DPA) is available upon request and forms part of the contractual documentation governing Nuitee Connect services.
Customers can request the DPA through their account or support contact.
Questions
For questions related to data protection or the DPA, customers can contact us through the usual support or account channels.
Conformità normativa
General Data Protection Regulation (GDPR)
Nuitee Connect complies with the EU General Data Protection Regulation (GDPR).
Key principles applied include:
- Lawfulness, fairness, and transparency of processing
- Purpose limitation and data minimization
- Integrity and confidentiality of personal data
- Accountability and documentation of processing activities
As described in the Data Protection & Privacy section, Nuitee Connect generally acts as a Data Processor, while customers act as Data Controllers.
Jurisdiction and Supervisory Authority
Nuitee Connect operates under the jurisdiction of Ireland, a member state of the European Union.
As such:
- EU data protection laws apply by default
- Nuitee Connect is subject to oversight by the Irish Data Protection Commission (DPC)
This provides a clear and well-established regulatory framework for data protection and privacy.
PCI DSS (Payment Card Industry Data Security Standard)
Nuitee Connect does not store, process, or transmit raw payment card data.
Card payments are handled through PCI-compliant third-party payment providers using a PCI proxy or redirection model. As a result:
- Nuitee Connect’s PCI DSS scope is limited
- Nuitee Connect aligns with SAQ A requirements under PCI DSS v4.x
- Sensitive cardholder data never passes through Nuitee Connect systems
Customers remain responsible for their own PCI DSS obligations based on their integration model.
Third-Party Compliance Dependencies
Nuitee Connect relies on trusted third-party providers for infrastructure and operational services, including:
- Cloud hosting
- Monitoring and logging
- Payment processing (where applicable)
These providers maintain their own industry-standard certifications and compliance programs (such as ISO 27001, SOC 2, or PCI DSS, depending on the service).
Nuitee Connect performs due diligence when selecting and reviewing third-party vendors.
Data Protection Agreements (DPA)
Nuitee Connect offers a Data Processing Agreement (DPA) consistent with GDPR Article 28 requirements.
The DPA defines:
- Processing scope and purpose
- Security and confidentiality obligations
- Sub-processor conditions
- Data subject rights support
- Audit and compliance terms
The DPA is available upon request.
Audits and Assessments
Nuitee Connect maintains internal controls and documentation to support security and compliance reviews.
While Nuitee Connect does not publicly publish audit reports, reasonable security and compliance information may be shared with customers under appropriate confidentiality terms.
Regulatory Updates
Nuitee Connect monitors regulatory developments and adapts its policies and controls as required to remain compliant with applicable laws and industry standards.