Legal center & community standards
Review the current terms, privacy information, safety rules and other policies that govern IterOrbis.
Acceptable Use Policy
0.9.5 · Published
System security
Unauthorised access, bypassing access controls or Production Lock, vulnerability scanning without written authorisation, service disruption, API abuse, automated bulk extraction, and attempts to obtain secrets or other users’ data are prohibited.
Illegal and dangerous activity
Do not use the platform to organise unlawful activity, offer services without required authorisation, commit fraud, launder money, evade sanctions, trade prohibited items, or knowingly create danger for travel participants.
Automation and scraping
Automated use is permitted only through documented interfaces and within granted permissions and limits. Bots must not falsify demand, reviews, bookings, clicks or reputation signals.
Age and Account Eligibility Notice
0.9.5 · Published
Minimum age
In the current production configuration, IterOrbis is intended for people who are at least 18 years old. At registration we request only confirmation that the age threshold is met; we do not collect date of birth solely to perform this check.
Minor accounts
Minor accounts are disabled. Guardian-authorisation functions are not part of the initial production launch. If the model is expanded, separate rules, guardian mechanisms, privacy review and appropriate safeguards will be implemented before minor accounts are enabled.
Accuracy of the attestation
Do not make a false age attestation or create an account for a person below the threshold. Where there are justified doubts, the platform may restrict the account and request proportionate confirmation of eligibility to use the service.
Cancellation and Refund Policy
0.9.5 · Published
Offer-specific rules
Before booking, the user receives the cancellation rules applicable to the specific offer, including any deadlines and financial consequences. The policy version assigned to a booking is snapshotted with the transaction so a later policy change does not overwrite the history of that purchase.
Cancellation by provider
If the service provider cannot perform the booked service, the platform handles booking-state changes, communication and the relevant refund or alternative-resolution process under the applicable terms and law for that service. Specific traveller rights may depend on the legal classification of the travel product.
Cancellation by user
The user initiates cancellation through the available platform channel or support. The financial outcome depends on the policy assigned to the booking and mandatory law. The platform does not describe all travel services as subject to one universal withdrawal right.
History and evidence
The system retains the booking identifier, policy version, amounts, payment status, cancellation and refund events and relevant communications as needed to administer the transaction, complaints and legal obligations.
Consumer Complaints and Appeals
0.9.5 · Published
How to complain
A complaint about IterOrbis may be sent to [email protected]. Provide information sufficient to identify the account or transaction, describe the problem, state the requested resolution and include supporting material where needed. Do not send sensitive data that is unnecessary to resolve the matter.
Who the complaint concerns
If the issue concerns performance by an independent host or operator, the transaction record should identify the relevant party and allocation of responsibility. IterOrbis handles its own platform obligations and helps route the matter to the appropriate entity to the extent required by law and the feature design.
Out-of-court dispute resolution
Information about out-of-court dispute resolution is presented according to current law and IterOrbis’s reviewed participation decision. This document does not include the historic link to the former EU ODR platform, which has been discontinued.
Content and Account Moderation Policy
0.9.5 · Published
Moderation scope
Moderation covers public and reported content, offers, profiles, messages or behaviour as needed to enforce law, terms, safety and marketplace integrity. Review may be automated, manual or hybrid; an automated signal should not by itself determine a high-impact outcome without the designated review.
Possible measures
Measures may include no action, reduced visibility, content removal, publication or transaction hold, feature restriction, suspension or account closure. The measure should take account of the nature of the issue, risk of harm, repetition, strength of evidence and legal requirements.
Reason for decision
Where required by the DSA, a statement of reasons for a restriction identifies at least the measure and its scope or duration, the relevant facts and circumstances including the source of information about the content, whether automated means were used, the legal ground or specific terms-and-conditions ground, and available redress. The explanation should allow the recipient to understand the actual reason for the decision.
Appeal
Where the DSA internal complaint-handling system applies, an eligible person may lodge a complaint electronically, free of charge and for at least six months after the decision. Complaints are handled in a timely, diligent and non-discriminatory manner; the outcome must not be based solely on automated means, and appropriately qualified staff must be able to review the decision. Information on further redress accompanies the outcome.
Cookie and Device Storage Policy
0.9.5 · Published
Scope
This policy describes cookies, local storage and similar mechanisms used by IterOrbis, together with external-provider mechanisms that may be activated by a specific feature. The technical source of truth is the versioned Browser Storage Inventory tied to the application release.
Rules for storing and accessing information on a device
Before using a mechanism that requires consent, we provide clear and understandable information about the purpose of storing or accessing information on the device and about the possibility of defining the conditions for such storage or access through software or service settings. Optional mechanisms are activated only after the required consent. Consent is not required only where an exception provided by law applies, in particular where storage or access is necessary for transmission or to provide a telecommunications or electronically supplied service requested by the user.
Essential and security storage
Session, authentication, security and privacy-choice mechanisms may operate without consent only to the extent that they satisfy a statutory exception, in particular where they are necessary for transmission or to provide a service requested by the user. Their actual name, purpose, provider and lifetime must match the versioned Browser Storage Inventory for the deployed release.
Language preference
The gj_lang cookie remembers the language selected by the user for up to 365 days after the latest selection. It is not used for advertising or marketing profiling.
Optional analytics
The analytics choice is stored locally as gj_analytics_consent. When analytics_requires_consent is enabled, analytics events are not sent before the user chooses “allow”. Declining leaves core service functionality available.
External providers
Optional integrations, such as web push or external hosted payment checkout, may use their own mechanisms on provider-controlled surfaces. They should not be enabled in production until their behaviour is reflected in the current inventory, privacy documentation and country-appropriate CMP configuration.
Managing your choice
The user may review and change optional-storage choices at any time in privacy settings. Withdrawing consent must be as easy as giving it and takes effect for the future; it does not affect the lawfulness of operations performed before withdrawal. Browser or device settings may additionally restrict storage, although blocking a strictly necessary mechanism may prevent the function for which it is required.
DAC7 Tax Reporting Notice for Host
0.9.5 · Published
When this notice matters
IterOrbis assesses platform-operator duties and reportable activities for the actual operating model. If an account or transactions fall within platform reporting, the business user receives information about data required for identification and reporting. This notice is not individual tax advice.
Due-diligence and reporting data
Depending on status, required data may include identity and address details, tax or registration numbers, account information, jurisdiction and the value and number of relevant transactions or other elements required by applicable rules and guidance.
Duty to keep data current
The user should provide truthful, current data and report changes. Missing information required to satisfy a legal duty may lead to restriction of settlement or publication functionality to the extent necessary for compliance.
Disclosure to authorities
Where a reporting obligation applies, required information may be disclosed to the competent tax authority under applicable rules. The basis, scope and retention of that data are documented in the privacy processing register.
DAC7 Tax Reporting Notice for Operator
0.9.5 · Published
When this notice matters
IterOrbis assesses platform-operator duties and reportable activities for the actual operating model. If an account or transactions fall within platform reporting, the business user receives information about data required for identification and reporting. This notice is not individual tax advice.
Due-diligence and reporting data
Depending on status, required data may include identity and address details, tax or registration numbers, account information, jurisdiction and the value and number of relevant transactions or other elements required by applicable rules and guidance.
Duty to keep data current
The user should provide truthful, current data and report changes. Missing information required to satisfy a legal duty may lead to restriction of settlement or publication functionality to the extent necessary for compliance.
Disclosure to authorities
Where a reporting obligation applies, required information may be disclosed to the competent tax authority under applicable rules. The basis, scope and retention of that data are documented in the privacy processing register.
Digital Service Accessibility Statement
0.9.5 · Published
Commitment
BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ develops IterOrbis so that digital functions can be used by as broad a range of people as possible, including people using assistive technologies. The applicable legal scope and any exemptions are confirmed for the actual entity and service model before production activation.
Assessment scope
The accessibility assessment covers discovery, registration and sign-in, Journey creation, booking and checkout, communications, help and account management. Where the Polish e-commerce accessibility requirements apply, it also covers functions, methods and procedures used for identifying the parties to the service, security and electronic payments, and the provision of accessibility information concerning the service and elements supplied by responsible economic operators.
Reporting a barrier
Accessibility issues can be reported to [email protected] with the page, function and barrier described. The report is routed to the appropriate team, and the response should state the resolution, workaround or work status where an immediate fix is not possible.
Status and updates
The final production statement will include the outcome of the actual audit, known limitations, assessment date and preparation method. This template remains a draft and must not be used to claim compliance before real-stack testing is complete.
Disclosure for Products Combining Travel Services
0.9.5 · Published
No default legal classification
Technical combination of legs, accommodation, activities or other elements in one plan is not treated by the system as a final legal classification. Before sale, a documented scope decision is required for the actual offer and purchase flow.
Where the platform is not package organiser
Where the approved classification is marketplace-only, the user receives information about the individual providers and allocation of responsibilities applicable to that model, without suggesting protections applicable to a package organised by the platform.
Electronic Marketing Consent Notice
0.9.5 · Published
Voluntary choice
Marketing consent is voluntary and separate from account creation, bookings and messages necessary to provide the service. Refusing or withdrawing marketing consent must not block core IterOrbis functions.
Channels
If IterOrbis wishes to use email, SMS, push or another channel for direct marketing, the consent scope should clearly identify the channel and purpose. The implementation should allow channel-specific withdrawal where required or technically offered.
Withdrawal
Consent may be withdrawn in settings or through the mechanism provided in the message. Withdrawal applies prospectively and is recorded so later campaigns respect the current state.
Fees and Payouts for Host
0.9.5 · Published
Separation of amounts
The system records at least the amount due to the provider, the platform fee and adjustments arising from a refund, dispute or other event. The dashboard should allow a payout to be linked to the relevant bookings and ledger events.
Platform collection model
Where the selected model collects funds through the platform integration and subsequently makes a separate payout to the provider, payout status is separate from the traveller payment status. Preparing a payout record does not itself mean the external transfer has completed.
Holds and adjustments
A payout may be held or adjusted where needed for a refund, dispute, chargeback, suspected abuse, missing required verification data or a legal obligation. The reason and status should be visible to an authorised administrative operator.
Tax and records
The provider is responsible for its own tax affairs, subject to reporting duties imposed directly on the platform operator by law. Transaction history and relevant reports are made available according to production functionality and legal requirements.
Fees and Payouts for Operator
0.9.5 · Published
Separation of amounts
The system records at least the amount due to the provider, the platform fee and adjustments arising from a refund, dispute or other event. The dashboard should allow a payout to be linked to the relevant bookings and ledger events.
Platform collection model
Where the selected model collects funds through the platform integration and subsequently makes a separate payout to the provider, payout status is separate from the traveller payment status. Preparing a payout record does not itself mean the external transfer has completed.
Holds and adjustments
A payout may be held or adjusted where needed for a refund, dispute, chargeback, suspected abuse, missing required verification data or a legal obligation. The reason and status should be visible to an authorised administrative operator.
Tax and records
The provider is responsible for its own tax affairs, subject to reporting duties imposed directly on the platform operator by law. Transaction history and relevant reports are made available according to production functionality and legal requirements.
Host Business Complaint Procedure
0.9.5 · Published
Complaint scope
A business user may raise an issue concerning platform operation, an account or offer restriction, ranking, settlement, technical functionality or another decision affecting use of business services. The complaint channel does not replace urgent safety channels.
Submission and identification
A complaint may be submitted electronically free of charge, identifying the account or case, the problem and available evidence. Contact: [email protected]. The platform records receipt and material steps in the case and keeps the channel easily accessible to the business user.
Review
Complaints are handled within a reasonable time, transparently, with equal treatment of comparable cases and proportionately. The review considers the arguments and available evidence. The business user receives an individual outcome stated in plain and intelligible language.
Outcome and further redress
The outcome states whether the decision is upheld, changed or reversed and, where applicable, available further redress. The case record is retained for accountability and analysis of recurring issues.
Information on complaint-system performance
Where required by P2B, we publish easily accessible information on the functioning and effectiveness of the internal complaint-handling system, including the number of complaints, their main types, the average time needed to process them and aggregated information on outcomes; the information is updated as required.
Mediation
Where the P2B mediation obligation applies, our terms identify at least two mediators with whom we are willing to attempt an agreement: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation is without prejudice to the right to court proceedings and other available remedies.
Host Business Terms
0.9.5 · Published
Provider and account scope
The Host account on IterOrbis is operated by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. These terms govern use of Journey and offer publishing, messaging, booking, settlement and safety tools available to a Host. Contact: [email protected]; legal matters: [email protected]; complaints: [email protected].
Status and truthful information
The Host must provide truthful, current and complete information about identity, trader status, offered services, required authorisations and settlement details. If an offer is made in the course of business or professional activity, the Host must declare the appropriate trader status and must not present itself as a private person to avoid duties owed to travellers.
Platform role in intermediary model
Where the operating model classifies IterOrbis as an intermediary, the Host remains the offer provider identified to the user before the transaction and is responsible for the accuracy, availability and performance of the Host service. The platform provides technical infrastructure, safety controls and transaction tooling as described in the interface.
Visibility and ranking
Offer visibility may depend on route and location fit, traveller preferences, Journey parameters, availability, information quality, safety and other parameters described in the current ranking notice. No ranking position is guaranteed. Paid placement is not used unless it is explicitly enabled and labelled in the product and documentation.
Access to data in the business relationship
The business user has access to data for its account, offers, bookings, settlements and communications made available in the dashboard or supported exports. The platform accesses data needed to provide the service, maintain security, settle transactions, moderate content, handle disputes and comply with legal obligations. Access after termination depends on export functions, retention, data-subject rights and legal duties; we do not promise access to data that the platform no longer lawfully retains.
Content, restrictions and moderation
The Host must not publish unlawful, misleading, unsafe content or content infringing third-party rights. The platform may restrict content, functionality, an offer or an account under the applicable moderation policy, while providing any required information on the basis of the decision and available redress where applicable.
Internal complaint-handling system
Where the P2B obligations apply, a business user may use the internal complaint-handling system free of charge for matters covered by the applicable rules. The current Business User Complaints Policy describes the channel and handling procedure.
P2B mediators
Where the obligation to identify mediators applies, we are willing to attempt mediation with at least the following mediators: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation does not restrict either party’s right to seek judicial relief or other mandatory remedies.
Fees, settlements and payouts
Amounts due to the Host, platform fees, adjustments, refunds, disputes and payout preparation timing are shown in the relevant screens and the current payments, fees and payouts policy. The Host is responsible for accurate settlement and required tax information; a payout may be held for a safety review, dispute, refund or legal obligation.
Host Privacy Notice
0.9.5 · Published
Controller and contact
The controller for data relating to the business account is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy contact: [email protected].
Data categories
Depending on the functions used, we process account and contact data, business and trader-status information, offer and booking data, communications, settlement information, payment-provider identifiers, verification outcomes, safety data, moderation history and tax information required for platform reporting.
Required and optional data
Data identified as required is needed, as applicable, to create and secure the business account, verify status or authorisations, publish an offer, enter into and perform a transaction, settle amounts or comply with a legal obligation. Failure to provide required data may prevent the relevant action. Optional fields may be omitted without losing a function that does not require them.
Purposes and legal bases
Data is used to operate the account and offers, perform platform services, communicate and settle transactions, maintain safety and prevent abuse, comply with legal obligations, handle disputes and-where legally required-perform tax reporting. A legal basis is assigned to each process, and consent is used only where the specific operation genuinely requires it.
Indirect sources
Data may also come from a user making a booking, a payment provider, a verification provider, a relevant public register or another source identified for the process. Where personal data was not obtained directly from the data subject, we provide the required information about data categories and sources in accordance with Article 14 GDPR unless a statutory exception applies.
Recipients and retention
Data may be shared with the relevant traveller as needed for a transaction, infrastructure and payment providers, and public authorities where a legal basis exists. Retention follows the purpose, account lifecycle, limitation periods, tax obligations and safety needs; details are maintained in the versioned retention register.
Transfers and automation
If a provider processes data outside the EEA, an appropriate transfer mechanism and the required information on safeguards must exist before production use. If automated decision-making that produces legal effects or similarly significantly affects a person is introduced for business accounts, this notice will be supplemented with the required information on the logic involved, significance and envisaged consequences.
Rights and requests
Depending on the legal basis and circumstances, the data subject may exercise rights of access, rectification, erasure or restriction, portability, objection and withdrawal of consent for the future. Requests: [email protected]. A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
Host Verification Notice
0.9.5 · Published
Purpose of verification
Verification is used to confirm identity and information needed for safe offer publication, settlements and duties relating to professional providers. The scope depends on role, country, service category and risk level.
Data and evidence
Where the DSA trader-traceability obligation applies, before allowing a trader to offer products or services to consumers we collect at least: the trader’s name, address, telephone number and email address; a copy of an identification document or electronic identification to the extent required by law; payment-account details where applicable; the relevant trade-register details and registration number where the trader is registered; and the required self-certification that the offered products or services comply with applicable Union law. Data is limited where an element is not legally required in the specific case.
Outcome and updates
To the extent required by the DSA, we make best efforts to assess whether the supplied information is reliable and complete using available sources or documents. If information is inaccurate, incomplete or outdated, the trader is given an opportunity to correct it; failure to remedy the issue within the required period may result in suspension of the ability to offer until the deficiency is resolved.
Retention and access
Verification data is accessible only to authorised people and systems in accordance with data minimisation. Data collected under the DSA trader-traceability obligation is stored securely for the period required by that rule-generally six months after the relationship with the trader ends-and then deleted unless another legal obligation requires specified information to be retained longer.
Identity Verification Data Notice for Host
0.9.5 · Published
Purpose of processing
Identity data is processed to verify the account, reduce abuse, protect transactions, perform required checks on a professional provider and-depending on configuration-satisfy payment or tax duties. Each active use case must have a documented legal basis.
Verification provider
If an external verification provider is used, its identity, role, data scope, transfers and retention must be recorded in the production processor register and current privacy information before the integration is enabled.
Data minimisation
The platform should not retain a full identity-document copy where a verification outcome or limited fields are sufficient for the purpose. Data scope must follow the inventory and actual provider configuration, not the integration’s maximum capabilities.
Rights and contact
Information on access, rectification, restriction, objection, erasure and other rights depending on the legal basis and legal duty is provided in the current privacy notice. Questions may be sent to [email protected].
Identity Verification Data Notice for Operator
0.9.5 · Published
Purpose of processing
Identity data is processed to verify the account, reduce abuse, protect transactions, perform required checks on a professional provider and-depending on configuration-satisfy payment or tax duties. Each active use case must have a documented legal basis.
Verification provider
If an external verification provider is used, its identity, role, data scope, transfers and retention must be recorded in the production processor register and current privacy information before the integration is enabled.
Data minimisation
The platform should not retain a full identity-document copy where a verification outcome or limited fields are sufficient for the purpose. Data scope must follow the inventory and actual provider configuration, not the integration’s maximum capabilities.
Rights and contact
Information on access, rectification, restriction, objection, erasure and other rights depending on the legal basis and legal duty is provided in the current privacy notice. Questions may be sent to [email protected].
IterOrbis Community Standards
0.9.5 · Published
Respect and safety
Do not post threats, harassment, persistent unwanted contact, incitement to violence, degrading or intimidating content, or material that creates real-world risk for Journey participants. Disagreement or a negative review does not justify attacking another person.
Honesty
Do not impersonate others or falsify verification, qualifications, experience, availability, price, service scope or Journey history. Information that may affect safety or a purchasing decision must be presented accurately.
Other people’s privacy
Do not publish another person’s contact details, documents, exact location, medical data or other private information without a proper basis. Material from a shared journey does not automatically become public.
Enforcement
A breach may result in content or feature restrictions, a warning, a correction request, temporary suspension or termination depending on nature, context, recurrence and risk. Where law requires a statement of reasons or appeal, the platform applies the relevant procedure.
IterOrbis Privacy Notice
0.9.5 · Published
Controller and contact
The controller of personal data processed through IterOrbis is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy enquiries may be sent to [email protected]; legal enquiries to [email protected].
Categories of data we process
Depending on the features used, we process account and contact data, profile and travel preferences, Journey and booking information, messages, safety and verification data, payment and settlement references, technical and security data, privacy choices, and-where voluntarily enabled-location, analytics or user-generated media data.
Whether providing data is required
Fields required for registration, security, entering into or performing a contract, payment, settlement or compliance with a legal obligation are identified in the relevant interface. Failure to provide required data may prevent account creation, conclusion or performance of a specific contract, payout, verification or access to the relevant function. Optional data may be omitted without losing a function that does not require it.
Purposes and legal bases
Data is used to create and operate accounts, provide marketplace and booking functions, enable communications, process payments and settlements, protect safety and prevent abuse, handle complaints, comply with legal obligations and improve the service. The applicable basis is, as relevant, contract performance or pre-contract steps, legal obligation, legitimate interests after the required assessment, or consent where a feature genuinely requires it.
Recipients and service providers
Data may be shared with the other party to a Journey where needed for the selected function, and with providers of infrastructure, hosting, email, SMS/push, maps and routing, payments, verification, support and security. A provider is activated only according to production configuration; the existence of an integration in code does not by itself cause data to be shared.
Data received from other sources
Some data may be received from the other party to a booking, a host or operator, a payment provider, an identity or safety provider, or a public register or source where legally permitted. Where personal data was not obtained directly from the data subject, we provide the information required by Article 14 GDPR, including the categories and source of the data, within the time applicable to the process unless a statutory exception applies.
Transfers outside the EEA
If an active provider processes data outside the European Economic Area, IterOrbis uses the transfer mechanism required by the GDPR and makes information about the applicable safeguards available. The final transfer list follows the providers actually enabled in production and the processor register.
Retention
Data is retained for the period needed for the stated purpose, the life of the account or contract, transaction settlement and potential claims, and for periods required by law. Analytics and technical data use separate retention limits in configuration. When the purpose ends, data is deleted, anonymised or restricted unless further retention is legally required or needed to establish, exercise or defend claims.
Your rights
Depending on the legal basis and circumstances, the data subject may request access, rectification, erasure or restriction, exercise data portability, object to processing and withdraw consent for the future where consent is the basis. Requests may be sent to [email protected]. The data subject may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
Analytics and personalisation
Optional first-party analytics is activated only after the consent state required by configuration. Declining analytics does not block core account functionality. The privacy choice is remembered so it can be respected on later visits.
Live location
Exact or approximate location in Live Journey is processed only after the user knowingly enables sharing. Sharing can be stopped and records use a limited lifetime. The feature is not an emergency-response guarantee or a substitute for emergency services.
Marketing
Transactional messages about the account, safety or order performance are separated from marketing. Electronic marketing is sent only after the applicable conditions are met and may be withdrawn independently for the relevant channels.
Seller reporting obligations
If platform-operator reporting duties apply to activities carried out through the platform, IterOrbis may be required to collect, verify, retain and report specified seller data and information about reportable activity to the competent authorities. This processing is activated only after a formal decision that the requirement is in scope.
Automation
The system may use automated matching, quality scoring or recommendations to organise information and assist users. The production design should not base decisions producing legal effects, or similarly significant effects on a user, solely on such automated processing without a separate lawful basis, notice and required safeguards.
Security and incidents
We use technical and organisational measures appropriate to risk, including access controls, logging of material events, server-side secret handling, webhook protection, and backup and recovery procedures. Personal-data breaches are handled under an incident procedure and applicable legal obligations.
Changes and versioning
This Notice has a version and effective date. A material change to purposes, legal bases, data categories, recipients or the business model requires a new version and appropriate notice to users; a previously delivered version is not silently rewritten.
IterOrbis Safety Standard
0.9.5 · Published
Nature of safety tools
Profiles, verification, check-in, emergency sharing, Live Journey and safety notices help reduce risk but do not guarantee the safety of a person, vehicle, vessel, route, weather conditions or other participants’ behaviour.
Current information
The user and relevant host/operator should independently verify current entry rules, documents, qualifications, technical condition, weather, warnings and instructions from local authorities or operators. Planning data on the platform does not replace a current official source.
Emergencies
In an immediate emergency, contact the appropriate emergency services. IterOrbis features are not an emergency-dispatch system and may depend on internet access, device availability, power, GPS or an external provider.
Reporting safety concerns
A serious safety concern, abuse or incident related to the platform should be reported through the appropriate safety tool or support channel. Information is shared only with people and entities that need it to handle the incident or where disclosure is legally required.
IterOrbis Terms of Service
0.9.5 · Published
Service provider
The IterOrbis platform is provided by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its address at Długa 2B, 56-416 Twardogóra, dolnośląskie, PL, registered in Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, IX Wydział Gospodarczy Krajowego Rejestru Sądowego (KRS) under number 0000841054, tax ID 9112034523, REGON 386056613, share capital PLN 20,000. General support: [email protected], legal contact: [email protected], complaints: [email protected].
Scope of services
IterOrbis provides accounts, profiles, Journey search and publication, participation requests, communications, booking, payment, safety and planning tools, and other functions described in the interface. Availability of a specific function may depend on country, user role, verification, Journey type and production configuration.
Age and account eligibility
In the current production version, an account may be created only by a person who is at least 18 years old. Do not create an account for a person who does not meet this requirement. The platform may require eligibility to be confirmed again where needed for safety, compliance or a specific feature.
Account and security
You must provide accurate and current information, protect your credentials and are responsible for activity performed through your account unless it results from a security breach outside your control. Impersonation, bypassing verification and creating accounts to evade restrictions are prohibited.
Platform intermediary role
For functions classified as intermediation, IterOrbis provides technical infrastructure and tools enabling contact or transactions between users, or between a user and an operator. The travel service is supplied by the identified offeror, and IterOrbis’s allocation of responsibilities is shown before the user becomes bound by a contract.
Offers and offeror status
For marketplace offers, the interface should identify the offeror, state whether the offeror declares trader status, explain the resulting consumer-law implications, and show how responsibilities are allocated between the offeror and the platform. Transaction-specific information takes precedence over a general feature description.
Price, fees and payment
Before placing a paid order, the user receives a summary of the price, fees, currency, service and rules applicable to the transaction. The final paid-checkout action must clearly communicate an obligation to pay. A quote, seat hold or expression of interest is not a paid booking unless the interface clearly states otherwise.
Reviews and authenticity
Reviews should reflect genuine experience or a genuine relationship with an offer where the relevant surface represents them that way. Fake reviews, purchased reviews, coordinated rating manipulation and undisclosed material conflicts of interest are prohibited. Details are set out in the Review Authenticity Policy.
Content, restrictions and appeals
The platform may restrict content visibility, account functionality or service access where content is illegal, breaches these Terms, or a restriction is necessary for safety or compliance. Where the relevant DSA obligations apply, decisions and appeals are handled under the applicable notice-and-action, statement-of-reasons and complaint procedures.
Complaints and disputes
Complaints about platform operation may be submitted to [email protected]. The complaint should describe the issue and allow the relevant service or transaction to be identified. Information about available out-of-court dispute-resolution methods is provided in accordance with applicable law and the platform’s current reviewed operating decision.
Changes to this document
Each published version of these Terms has its own version number, effective date and immutable content snapshot. If a change requires renewed acceptance, the user will receive an appropriate notice before continuing to use the affected functions. Acceptance history is recorded against the document version.
Live Location Consent and Notice
0.9.5 · Published
Optional feature
Live location sharing is optional and requires a deliberate user action. Refusing does not block the core account or an ordinary booking unless a specific, clearly described safety feature technically cannot function without location.
Precision and audience
The interface should distinguish approximate and exact location and state who can see it. Location is not made public merely because it is part of Live Journey; access should be limited to authorised participants and safety functions.
Stopping and retention
You can stop sharing. Location records use a limited TTL set in platform configuration and should not be retained indefinitely as a tracking history.
No emergency-response guarantee
Live Journey and location sharing are coordination tools, not an emergency-response service. In an emergency, use the appropriate local emergency numbers and safety procedures.
Marketplace and Seller Transparency Notice
0.9.5 · Published
Marketplace role
IterOrbis enables users to search, compare and book offers made available by hosts or operators. Before a transaction is concluded, the interface is intended to identify the provider, its status and whether, and to what extent, BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ is a contracting party for the underlying service.
Trader status
Where the provider acts as a trader, that status should be shown to the user. If the operating model permits a private provider, the interface should clearly distinguish that status and explain that certain consumer rights may depend on the identity of the contracting party.
Trader information shown with an offer
Where the DSA trader-traceability obligation applies, the offer interface makes the required trader information available in a clear, easily accessible and comprehensible manner, including the trader’s name and contact details required by law, relevant trade-register information and registration number, and the required self-certification. Identification documents and payment-account details are not made public on this basis.
Allocation of responsibilities
The allocation of responsibilities between the platform and provider is presented in the context of the relevant offer and checkout. The provider is at least responsible for information it supplies and duties assigned to it in the interface and terms; the platform is responsible for its own services and duties arising from the selected operating model.
Notice-and-Action Procedure for Potentially Illegal Content
0.9.5 · Published
How to submit a notice
A notice of potentially illegal content should allow a sufficiently substantiated explanation of why the information is considered illegal, the exact electronic location-such as a specific URL or equivalent identifier-and, where required by law, the notifier’s name and email address. The form also includes a bona fide statement that the information and allegations are accurate and complete. Identity details are not required where the applicable rule permits a notice without them.
Acknowledgement of receipt
Where the notifier provided electronic contact details, the platform acknowledges receipt without undue delay and retains a case identifier needed for further communication.
Assessment
Valid notices are processed in a timely, diligent, objective and non-arbitrary manner. The process does not automatically presume that the reported content is illegal. Where automated means were used to process the notice or make a decision, this is disclosed to the extent required by the DSA.
Outcome
After a decision, we inform the notifier of the outcome to the extent required by the DSA and identify available challenge or redress routes. Where a restriction concerns a recipient of the service or that recipient’s content, a separate statement of reasons to that person contains the elements required by the DSA.
Abuse of the procedure
Repeated manifestly unfounded notices or deliberate use of the procedure to harass other users may lead to restrictions under the terms, taking account of context and required procedural safeguards.
Notice on Main Ranking Parameters
0.9.5 · Published
Search and discovery results
The baseline discovery ranking starts from a common score and may reduce position for greater origin or destination mismatch and increase it for matching travel mode or Journey vibe. Exact weights and signals may evolve, but any production change to the mechanism should be reflected in this notice.
Recommendations
Recommendations may additionally consider followed hosts, travel objectives and preferences, Travel DNA, remaining capacity, near-term departure and cost. These are matching signals and do not amount to a guarantee of the quality or safety of a particular offer.
Paid ranking influence
No mechanism for paid influence over offer ranking has been identified in the current model. If paid prominence or another commercial influence on visibility is added in the future, it must be clearly labelled to users and included in the description of main ranking parameters before production use.
No position guarantee
Ranking is dynamic and depends on query context, user data available to the function, offer parameters and current configuration. Neither a user nor a provider is entitled to a fixed position in results.
Operator Privacy Notice
0.9.5 · Published
Controller and contact
The controller for data relating to the business account is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy contact: [email protected].
Data categories
Depending on the functions used, we process account and contact data, business and trader-status information, offer and booking data, communications, settlement information, payment-provider identifiers, verification outcomes, safety data, moderation history and tax information required for platform reporting.
Required and optional data
Data identified as required is needed, as applicable, to create and secure the business account, verify status or authorisations, publish an offer, enter into and perform a transaction, settle amounts or comply with a legal obligation. Failure to provide required data may prevent the relevant action. Optional fields may be omitted without losing a function that does not require them.
Purposes and legal bases
Data is used to operate the account and offers, perform platform services, communicate and settle transactions, maintain safety and prevent abuse, comply with legal obligations, handle disputes and-where legally required-perform tax reporting. A legal basis is assigned to each process, and consent is used only where the specific operation genuinely requires it.
Indirect sources
Data may also come from a user making a booking, a payment provider, a verification provider, a relevant public register or another source identified for the process. Where personal data was not obtained directly from the data subject, we provide the required information about data categories and sources in accordance with Article 14 GDPR unless a statutory exception applies.
Recipients and retention
Data may be shared with the relevant traveller as needed for a transaction, infrastructure and payment providers, and public authorities where a legal basis exists. Retention follows the purpose, account lifecycle, limitation periods, tax obligations and safety needs; details are maintained in the versioned retention register.
Transfers and automation
If a provider processes data outside the EEA, an appropriate transfer mechanism and the required information on safeguards must exist before production use. If automated decision-making that produces legal effects or similarly significantly affects a person is introduced for business accounts, this notice will be supplemented with the required information on the logic involved, significance and envisaged consequences.
Rights and requests
Depending on the legal basis and circumstances, the data subject may exercise rights of access, rectification, erasure or restriction, portability, objection and withdrawal of consent for the future. Requests: [email protected]. A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
Privacy Choices and Optional Device Storage Notice
0.9.5 · Published
Your choice
Optional mechanisms remain disabled until the user makes a choice. The interface provides a way to accept or reject optional categories without concealing the refusal option; inactivity is not treated as consent.
Analytics
After consent, IterOrbis may record and send first-party usage events to measure product performance and improve the experience. The choice can later be changed without losing core account functionality.
Evidence of choice
The system records technical evidence of the choice together with the applicable notice version and decision time. For a signed-out visitor, evidence should use a pseudonymous CMP identifier rather than requiring an account.
Changing or withdrawing a choice
Privacy settings can be reopened at any time to withdraw or change consent for the future. The platform records the changed choice together with the notice version so that the current preference can be demonstrated.
Promotion and Voucher Terms
0.9.5 · Published
Promotion activation
This document family is published only when the production promotion or voucher module is actually enabled. Each campaign must identify the organiser, period, eligible users, benefit and how it is applied.
Conditions and restrictions
Campaign rules state any minimum spend, eligible offers, use limits, ability to combine with other benefits and expiry date. Material restrictions should not be hidden until after checkout has started.
Refunds where a benefit was used
For a cancellation or refund, campaign rules explain whether and to what extent a voucher or discount is restored and how it affects the refund amount. The user should not be told that promotional value will be paid out in cash where that is not provided for.
Abuse
The platform may reject or reverse a benefit obtained through account manipulation, a technical error or breach of clearly stated campaign rules, subject to the user’s rights under mandatory law.
PRO Operator Business Complaint Procedure
0.9.5 · Published
Complaint scope
A business user may raise an issue concerning platform operation, an account or offer restriction, ranking, settlement, technical functionality or another decision affecting use of business services. The complaint channel does not replace urgent safety channels.
Submission and identification
A complaint may be submitted electronically free of charge, identifying the account or case, the problem and available evidence. Contact: [email protected]. The platform records receipt and material steps in the case and keeps the channel easily accessible to the business user.
Review
Complaints are handled within a reasonable time, transparently, with equal treatment of comparable cases and proportionately. The review considers the arguments and available evidence. The business user receives an individual outcome stated in plain and intelligible language.
Outcome and further redress
The outcome states whether the decision is upheld, changed or reversed and, where applicable, available further redress. The case record is retained for accountability and analysis of recurring issues.
Information on complaint-system performance
Where required by P2B, we publish easily accessible information on the functioning and effectiveness of the internal complaint-handling system, including the number of complaints, their main types, the average time needed to process them and aggregated information on outcomes; the information is updated as required.
Mediation
Where the P2B mediation obligation applies, our terms identify at least two mediators with whom we are willing to attempt an agreement: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation is without prejudice to the right to court proceedings and other available remedies.
PRO Operator Business Terms
0.9.5 · Published
Provider and account scope
The PRO Operator account on IterOrbis is operated by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. These terms cover professional offer publication, availability management, messaging, bookings, settlements and safety tools. Contact: [email protected], legal matters: [email protected], complaints: [email protected].
Professional status and required authorisations
The Operator represents that trader information is truthful and current and that it holds licences, permits, insurance and other authorisations required for the service actually offered. Account admission or a “verified” label does not replace duties imposed by law applicable to transport, travel or another regulated activity.
Intermediation
Where IterOrbis acts as an intermediary for a category, the Operator remains the professional service provider to the user and is responsible for compliance, description, availability and performance. The pre-transaction interface identifies the parties and allocation of responsibilities.
Professional offer ranking
Ranking may consider origin and destination fit, preferences, journey type and parameters, availability, offer-data quality and safety signals described in the ranking notice. No position is guaranteed. Any future paid prominence requires separate labelling and an update to the ranking rules.
Access to data in the business relationship
The business user has access to data for its account, offers, bookings, settlements and communications made available in the dashboard or supported exports. The platform accesses data needed to provide the service, maintain security, settle transactions, moderate content, handle disputes and comply with legal obligations. Access after termination depends on export functions, retention, data-subject rights and legal duties; we do not promise access to data that the platform no longer lawfully retains.
Service restrictions and redress
For a breach of law, terms, safety rules or verification requirements, the platform may restrict an offer, function or account. Where business-user duties apply, the decision notice states the basis, scope and available complaint or appeal channel.
Internal complaint-handling system
Where the P2B obligations apply, a business user may use the internal complaint-handling system free of charge for matters covered by the applicable rules. The current Business User Complaints Policy describes the channel and handling procedure.
P2B mediators
Where the obligation to identify mediators applies, we are willing to attempt mediation with at least the following mediators: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation does not restrict either party’s right to seek judicial relief or other mandatory remedies.
Settlements and payouts
The Operator receives information on price, fees, adjustments, refunds and payout status in the relevant screens. Payout depends on accurate settlement data, required verification and absence of a hold arising from a dispute, refund, safety review or legal requirement.
PRO Operator Verification Notice
0.9.5 · Published
Purpose of verification
Verification is used to confirm identity and information needed for safe offer publication, settlements and duties relating to professional providers. The scope depends on role, country, service category and risk level.
Data and evidence
Where the DSA trader-traceability obligation applies, before allowing a trader to offer products or services to consumers we collect at least: the trader’s name, address, telephone number and email address; a copy of an identification document or electronic identification to the extent required by law; payment-account details where applicable; the relevant trade-register details and registration number where the trader is registered; and the required self-certification that the offered products or services comply with applicable Union law. Data is limited where an element is not legally required in the specific case.
Outcome and updates
To the extent required by the DSA, we make best efforts to assess whether the supplied information is reliable and complete using available sources or documents. If information is inaccurate, incomplete or outdated, the trader is given an opportunity to correct it; failure to remedy the issue within the required period may result in suspension of the ability to offer until the deficiency is resolved.
Retention and access
Verification data is accessible only to authorised people and systems in accordance with data minimisation. Data collected under the DSA trader-traceability obligation is stored securely for the period required by that rule-generally six months after the relationship with the trader ends-and then deleted unless another legal obligation requires specified information to be retained longer.
Public Media Use Consent Notice
0.9.5 · Published
Separate publication consent
Adding a photo or video to a private Trip Room does not constitute consent to publish it in a public Journey Story, promotional material or another public surface. Public use requires a separate decision by the media owner within the scope shown in the interface.
Scope of consent
The interface should identify the specific media, intended use, publication surface and account giving the consent. Consent is not automatically extended to different campaigns or different media.
Prospective withdrawal
Where consent is the applicable basis, it may be withdrawn prospectively. The platform should stop new publication and, where possible and required, remove or restrict its own active publications, recognising that lawful copies may have been made outside the platform’s control.
Referral and Loyalty Programme Terms
0.9.5 · Published
Eligibility
Where the programme is active, the programme screen states who may refer, who may receive a benefit and which event earns it. Accounts created to manufacture benefits, self-referrals or coordinated abuse may be excluded from the programme.
Benefit
The value, currency or other form of benefit, timing, expiry and use restrictions are shown before participation. A benefit has no cash-out value unless the specific programme rules expressly state otherwise.
Fair communication
A referrer should not misrepresent the benefit or platform, impersonate official advertising or send unsolicited communications contrary to law. A referral link does not authorise bypassing the recipient’s privacy choices.
Programme changes
New campaigns and future programme periods may be changed or ended with appropriate notice. Properly earned benefits are handled under the rules in force when earned, subject to correction for abuse or an obvious error.
Review Authenticity Policy
0.9.5 · Published
Who may review
A review may be labelled “verified”, “after travel”, “after booking” or equivalent only where the platform has a reasonable and proportionate mechanism linking it to an actual travel, booking or transaction record. A review without such confirmation must not be presented in a way suggesting that the author actually used the reviewed service.
Whether and how reviews are checked
At the interface presenting reviews, we make available information on whether review origin is checked and how the check works, including the meaning of labels such as “verified”. Where a group of reviews is not verified against a transaction or another reliable signal, the information must not suggest that all reviews come from actual customers.
No manipulation
Buying or selling reviews, using multiple accounts to manipulate scores, coordinating reciprocal ratings for manipulation, and applying pressure in exchange for an undisclosed benefit are prohibited.
Review moderation
A review may be restricted if it violates law, privacy or community standards; critical content should not be removed merely because it is negative. The relevant interface should explain how reviews are verified and moderated.
Subscription and Premium Terms
0.9.5 · Published
Subscription scope
Where subscriptions are enabled, the purchase screen identifies the plan, features, price, currency, billing period, renewal method and when charging starts. One-off features are not presented as a subscription without clear labelling.
Renewal
If a plan renews automatically, the recurring nature of the payment is shown before purchase. The user has access to the next billing date and a method for disabling future renewal.
Cancellation of future periods
Cancelling a subscription stops future renewals as communicated to the user; effects on an already started period, refunds and consumer rights depend on the purchase terms and mandatory law.
Plan or price changes
A material change to features, price or renewal model must not be applied to a future billing cycle without the required notice and basis. Where law or the contract requires renewed agreement or a termination option, the release process must support it before charging the user.
Traveller Payments and Fees Notice
0.9.5 · Published
Price before payment
Before a paid order is placed, checkout presents the service amount, platform service fee, total amount and currency, together with the relevant offer identity. The user should review the summary before starting payment.
Explicit obligation to pay
The final action in a paid checkout must clearly communicate that completing it creates an obligation to pay. Absence of that communication is treated as a deployment-blocking error for the payment surface.
Payment provider
Payment may be processed by an external provider configured for production. IterOrbis stores only information and identifiers needed to link the transaction and settlement; the data shared with the provider follows the integration actually used and the current privacy notice.
Refunds and disputes
A refund, partial refund, cancellation or payment dispute is handled under the booking terms, applicable law and transaction status. The interface should show the process state; a technical “refund pending” record does not mean the payment provider has already completed the refund.
Travel Service Role Disclosure
0.9.5 · Published
Classification before transaction
Before sales are enabled, each flow combining travel services must have an approved legal classification for the relevant market. The checkout interface presents the role of IterOrbis, the identity of the relevant provider and information required for the operating model actually selected.
Marketplace model
In a marketplace-only model the platform facilitates discovery and transactions, while the provider identified before purchase remains the travel-service provider. The platform does not present such a product as a package organised by it unless the specific flow has been separately classified.
User Content Policy
0.9.5 · Published
Rights in content
You should publish only content you have rights or another valid basis to publish. You retain rights in your content while granting the platform the permissions needed to store, technically process and display it according to the selected feature and visibility settings.
Other people in media
When publishing media depicting other people, you must respect their rights, privacy and any required consent or other lawful basis. Travelling together does not automatically mean everyone consents to public publication of a photo or video.
Removal and restrictions
The platform may restrict or remove content where necessary because of law, other people’s rights, safety or platform rules. Where required by law, the user will receive a statement of reasons and access to the applicable appeal procedure.