Trust

Legal center & community standards

Review the current terms, privacy information, safety rules and other policies that govern IterOrbis.

Acceptable Use Policy

Acceptable Use Policy

0.9.5 · Published

System security

Unauthorised access, bypassing access controls or Production Lock, vulnerability scanning without written authorisation, service disruption, API abuse, automated bulk extraction, and attempts to obtain secrets or other users’ data are prohibited.

Illegal and dangerous activity

Do not use the platform to organise unlawful activity, offer services without required authorisation, commit fraud, launder money, evade sanctions, trade prohibited items, or knowingly create danger for travel participants.

Automation and scraping

Automated use is permitted only through documented interfaces and within granted permissions and limits. Bots must not falsify demand, reviews, bookings, clicks or reputation signals.

Age and Account Eligibility Notice

Age and Account Eligibility Notice

0.9.5 · Published

Minimum age

In the current production configuration, IterOrbis is intended for people who are at least 18 years old. At registration we request only confirmation that the age threshold is met; we do not collect date of birth solely to perform this check.

Minor accounts

Minor accounts are disabled. Guardian-authorisation functions are not part of the initial production launch. If the model is expanded, separate rules, guardian mechanisms, privacy review and appropriate safeguards will be implemented before minor accounts are enabled.

Accuracy of the attestation

Do not make a false age attestation or create an account for a person below the threshold. Where there are justified doubts, the platform may restrict the account and request proportionate confirmation of eligibility to use the service.

Cancellation and Refund Policy

Cancellation and Refund Policy

0.9.5 · Published

Offer-specific rules

Before booking, the user receives the cancellation rules applicable to the specific offer, including any deadlines and financial consequences. The policy version assigned to a booking is snapshotted with the transaction so a later policy change does not overwrite the history of that purchase.

Cancellation by provider

If the service provider cannot perform the booked service, the platform handles booking-state changes, communication and the relevant refund or alternative-resolution process under the applicable terms and law for that service. Specific traveller rights may depend on the legal classification of the travel product.

Cancellation by user

The user initiates cancellation through the available platform channel or support. The financial outcome depends on the policy assigned to the booking and mandatory law. The platform does not describe all travel services as subject to one universal withdrawal right.

History and evidence

The system retains the booking identifier, policy version, amounts, payment status, cancellation and refund events and relevant communications as needed to administer the transaction, complaints and legal obligations.

Consumer Complaints and Appeals

Consumer Complaints and Appeals

0.9.5 · Published

How to complain

A complaint about IterOrbis may be sent to [email protected]. Provide information sufficient to identify the account or transaction, describe the problem, state the requested resolution and include supporting material where needed. Do not send sensitive data that is unnecessary to resolve the matter.

Who the complaint concerns

If the issue concerns performance by an independent host or operator, the transaction record should identify the relevant party and allocation of responsibility. IterOrbis handles its own platform obligations and helps route the matter to the appropriate entity to the extent required by law and the feature design.

Out-of-court dispute resolution

Information about out-of-court dispute resolution is presented according to current law and IterOrbis’s reviewed participation decision. This document does not include the historic link to the former EU ODR platform, which has been discontinued.

Content and Account Moderation Policy

Content and Account Moderation Policy

0.9.5 · Published

Moderation scope

Moderation covers public and reported content, offers, profiles, messages or behaviour as needed to enforce law, terms, safety and marketplace integrity. Review may be automated, manual or hybrid; an automated signal should not by itself determine a high-impact outcome without the designated review.

Possible measures

Measures may include no action, reduced visibility, content removal, publication or transaction hold, feature restriction, suspension or account closure. The measure should take account of the nature of the issue, risk of harm, repetition, strength of evidence and legal requirements.

Reason for decision

Where required by the DSA, a statement of reasons for a restriction identifies at least the measure and its scope or duration, the relevant facts and circumstances including the source of information about the content, whether automated means were used, the legal ground or specific terms-and-conditions ground, and available redress. The explanation should allow the recipient to understand the actual reason for the decision.

Appeal

Where the DSA internal complaint-handling system applies, an eligible person may lodge a complaint electronically, free of charge and for at least six months after the decision. Complaints are handled in a timely, diligent and non-discriminatory manner; the outcome must not be based solely on automated means, and appropriately qualified staff must be able to review the decision. Information on further redress accompanies the outcome.

DAC7 Tax Reporting Notice for Host

DAC7 Tax Reporting Notice for Host

0.9.5 · Published

When this notice matters

IterOrbis assesses platform-operator duties and reportable activities for the actual operating model. If an account or transactions fall within platform reporting, the business user receives information about data required for identification and reporting. This notice is not individual tax advice.

Due-diligence and reporting data

Depending on status, required data may include identity and address details, tax or registration numbers, account information, jurisdiction and the value and number of relevant transactions or other elements required by applicable rules and guidance.

Duty to keep data current

The user should provide truthful, current data and report changes. Missing information required to satisfy a legal duty may lead to restriction of settlement or publication functionality to the extent necessary for compliance.

Disclosure to authorities

Where a reporting obligation applies, required information may be disclosed to the competent tax authority under applicable rules. The basis, scope and retention of that data are documented in the privacy processing register.

DAC7 Tax Reporting Notice for Operator

DAC7 Tax Reporting Notice for Operator

0.9.5 · Published

When this notice matters

IterOrbis assesses platform-operator duties and reportable activities for the actual operating model. If an account or transactions fall within platform reporting, the business user receives information about data required for identification and reporting. This notice is not individual tax advice.

Due-diligence and reporting data

Depending on status, required data may include identity and address details, tax or registration numbers, account information, jurisdiction and the value and number of relevant transactions or other elements required by applicable rules and guidance.

Duty to keep data current

The user should provide truthful, current data and report changes. Missing information required to satisfy a legal duty may lead to restriction of settlement or publication functionality to the extent necessary for compliance.

Disclosure to authorities

Where a reporting obligation applies, required information may be disclosed to the competent tax authority under applicable rules. The basis, scope and retention of that data are documented in the privacy processing register.

Digital Service Accessibility Statement

Digital Service Accessibility Statement

0.9.5 · Published

Commitment

BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ develops IterOrbis so that digital functions can be used by as broad a range of people as possible, including people using assistive technologies. The applicable legal scope and any exemptions are confirmed for the actual entity and service model before production activation.

Assessment scope

The accessibility assessment covers discovery, registration and sign-in, Journey creation, booking and checkout, communications, help and account management. Where the Polish e-commerce accessibility requirements apply, it also covers functions, methods and procedures used for identifying the parties to the service, security and electronic payments, and the provision of accessibility information concerning the service and elements supplied by responsible economic operators.

Reporting a barrier

Accessibility issues can be reported to [email protected] with the page, function and barrier described. The report is routed to the appropriate team, and the response should state the resolution, workaround or work status where an immediate fix is not possible.

Status and updates

The final production statement will include the outcome of the actual audit, known limitations, assessment date and preparation method. This template remains a draft and must not be used to claim compliance before real-stack testing is complete.

Disclosure for Products Combining Travel Services

Disclosure for Products Combining Travel Services

0.9.5 · Published

No default legal classification

Technical combination of legs, accommodation, activities or other elements in one plan is not treated by the system as a final legal classification. Before sale, a documented scope decision is required for the actual offer and purchase flow.

Where the platform is not package organiser

Where the approved classification is marketplace-only, the user receives information about the individual providers and allocation of responsibilities applicable to that model, without suggesting protections applicable to a package organised by the platform.

Fees and Payouts for Host

Fees and Payouts for Host

0.9.5 · Published

Separation of amounts

The system records at least the amount due to the provider, the platform fee and adjustments arising from a refund, dispute or other event. The dashboard should allow a payout to be linked to the relevant bookings and ledger events.

Platform collection model

Where the selected model collects funds through the platform integration and subsequently makes a separate payout to the provider, payout status is separate from the traveller payment status. Preparing a payout record does not itself mean the external transfer has completed.

Holds and adjustments

A payout may be held or adjusted where needed for a refund, dispute, chargeback, suspected abuse, missing required verification data or a legal obligation. The reason and status should be visible to an authorised administrative operator.

Tax and records

The provider is responsible for its own tax affairs, subject to reporting duties imposed directly on the platform operator by law. Transaction history and relevant reports are made available according to production functionality and legal requirements.

Fees and Payouts for Operator

Fees and Payouts for Operator

0.9.5 · Published

Separation of amounts

The system records at least the amount due to the provider, the platform fee and adjustments arising from a refund, dispute or other event. The dashboard should allow a payout to be linked to the relevant bookings and ledger events.

Platform collection model

Where the selected model collects funds through the platform integration and subsequently makes a separate payout to the provider, payout status is separate from the traveller payment status. Preparing a payout record does not itself mean the external transfer has completed.

Holds and adjustments

A payout may be held or adjusted where needed for a refund, dispute, chargeback, suspected abuse, missing required verification data or a legal obligation. The reason and status should be visible to an authorised administrative operator.

Tax and records

The provider is responsible for its own tax affairs, subject to reporting duties imposed directly on the platform operator by law. Transaction history and relevant reports are made available according to production functionality and legal requirements.

Host Business Complaint Procedure

Host Business Complaint Procedure

0.9.5 · Published

Complaint scope

A business user may raise an issue concerning platform operation, an account or offer restriction, ranking, settlement, technical functionality or another decision affecting use of business services. The complaint channel does not replace urgent safety channels.

Submission and identification

A complaint may be submitted electronically free of charge, identifying the account or case, the problem and available evidence. Contact: [email protected]. The platform records receipt and material steps in the case and keeps the channel easily accessible to the business user.

Review

Complaints are handled within a reasonable time, transparently, with equal treatment of comparable cases and proportionately. The review considers the arguments and available evidence. The business user receives an individual outcome stated in plain and intelligible language.

Outcome and further redress

The outcome states whether the decision is upheld, changed or reversed and, where applicable, available further redress. The case record is retained for accountability and analysis of recurring issues.

Information on complaint-system performance

Where required by P2B, we publish easily accessible information on the functioning and effectiveness of the internal complaint-handling system, including the number of complaints, their main types, the average time needed to process them and aggregated information on outcomes; the information is updated as required.

Mediation

Where the P2B mediation obligation applies, our terms identify at least two mediators with whom we are willing to attempt an agreement: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation is without prejudice to the right to court proceedings and other available remedies.

Host Business Terms

Host Business Terms

0.9.5 · Published

Provider and account scope

The Host account on IterOrbis is operated by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. These terms govern use of Journey and offer publishing, messaging, booking, settlement and safety tools available to a Host. Contact: [email protected]; legal matters: [email protected]; complaints: [email protected].

Status and truthful information

The Host must provide truthful, current and complete information about identity, trader status, offered services, required authorisations and settlement details. If an offer is made in the course of business or professional activity, the Host must declare the appropriate trader status and must not present itself as a private person to avoid duties owed to travellers.

Platform role in intermediary model

Where the operating model classifies IterOrbis as an intermediary, the Host remains the offer provider identified to the user before the transaction and is responsible for the accuracy, availability and performance of the Host service. The platform provides technical infrastructure, safety controls and transaction tooling as described in the interface.

Visibility and ranking

Offer visibility may depend on route and location fit, traveller preferences, Journey parameters, availability, information quality, safety and other parameters described in the current ranking notice. No ranking position is guaranteed. Paid placement is not used unless it is explicitly enabled and labelled in the product and documentation.

Access to data in the business relationship

The business user has access to data for its account, offers, bookings, settlements and communications made available in the dashboard or supported exports. The platform accesses data needed to provide the service, maintain security, settle transactions, moderate content, handle disputes and comply with legal obligations. Access after termination depends on export functions, retention, data-subject rights and legal duties; we do not promise access to data that the platform no longer lawfully retains.

Content, restrictions and moderation

The Host must not publish unlawful, misleading, unsafe content or content infringing third-party rights. The platform may restrict content, functionality, an offer or an account under the applicable moderation policy, while providing any required information on the basis of the decision and available redress where applicable.

Internal complaint-handling system

Where the P2B obligations apply, a business user may use the internal complaint-handling system free of charge for matters covered by the applicable rules. The current Business User Complaints Policy describes the channel and handling procedure.

P2B mediators

Where the obligation to identify mediators applies, we are willing to attempt mediation with at least the following mediators: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation does not restrict either party’s right to seek judicial relief or other mandatory remedies.

Fees, settlements and payouts

Amounts due to the Host, platform fees, adjustments, refunds, disputes and payout preparation timing are shown in the relevant screens and the current payments, fees and payouts policy. The Host is responsible for accurate settlement and required tax information; a payout may be held for a safety review, dispute, refund or legal obligation.

Host Privacy Notice

Host Privacy Notice

0.9.5 · Published

Controller and contact

The controller for data relating to the business account is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy contact: [email protected].

Data categories

Depending on the functions used, we process account and contact data, business and trader-status information, offer and booking data, communications, settlement information, payment-provider identifiers, verification outcomes, safety data, moderation history and tax information required for platform reporting.

Required and optional data

Data identified as required is needed, as applicable, to create and secure the business account, verify status or authorisations, publish an offer, enter into and perform a transaction, settle amounts or comply with a legal obligation. Failure to provide required data may prevent the relevant action. Optional fields may be omitted without losing a function that does not require them.

Purposes and legal bases

Data is used to operate the account and offers, perform platform services, communicate and settle transactions, maintain safety and prevent abuse, comply with legal obligations, handle disputes and-where legally required-perform tax reporting. A legal basis is assigned to each process, and consent is used only where the specific operation genuinely requires it.

Indirect sources

Data may also come from a user making a booking, a payment provider, a verification provider, a relevant public register or another source identified for the process. Where personal data was not obtained directly from the data subject, we provide the required information about data categories and sources in accordance with Article 14 GDPR unless a statutory exception applies.

Recipients and retention

Data may be shared with the relevant traveller as needed for a transaction, infrastructure and payment providers, and public authorities where a legal basis exists. Retention follows the purpose, account lifecycle, limitation periods, tax obligations and safety needs; details are maintained in the versioned retention register.

Transfers and automation

If a provider processes data outside the EEA, an appropriate transfer mechanism and the required information on safeguards must exist before production use. If automated decision-making that produces legal effects or similarly significantly affects a person is introduced for business accounts, this notice will be supplemented with the required information on the logic involved, significance and envisaged consequences.

Rights and requests

Depending on the legal basis and circumstances, the data subject may exercise rights of access, rectification, erasure or restriction, portability, objection and withdrawal of consent for the future. Requests: [email protected]. A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.

Host Verification Notice

Host Verification Notice

0.9.5 · Published

Purpose of verification

Verification is used to confirm identity and information needed for safe offer publication, settlements and duties relating to professional providers. The scope depends on role, country, service category and risk level.

Data and evidence

Where the DSA trader-traceability obligation applies, before allowing a trader to offer products or services to consumers we collect at least: the trader’s name, address, telephone number and email address; a copy of an identification document or electronic identification to the extent required by law; payment-account details where applicable; the relevant trade-register details and registration number where the trader is registered; and the required self-certification that the offered products or services comply with applicable Union law. Data is limited where an element is not legally required in the specific case.

Outcome and updates

To the extent required by the DSA, we make best efforts to assess whether the supplied information is reliable and complete using available sources or documents. If information is inaccurate, incomplete or outdated, the trader is given an opportunity to correct it; failure to remedy the issue within the required period may result in suspension of the ability to offer until the deficiency is resolved.

Retention and access

Verification data is accessible only to authorised people and systems in accordance with data minimisation. Data collected under the DSA trader-traceability obligation is stored securely for the period required by that rule-generally six months after the relationship with the trader ends-and then deleted unless another legal obligation requires specified information to be retained longer.

Identity Verification Data Notice for Host

Identity Verification Data Notice for Host

0.9.5 · Published

Purpose of processing

Identity data is processed to verify the account, reduce abuse, protect transactions, perform required checks on a professional provider and-depending on configuration-satisfy payment or tax duties. Each active use case must have a documented legal basis.

Verification provider

If an external verification provider is used, its identity, role, data scope, transfers and retention must be recorded in the production processor register and current privacy information before the integration is enabled.

Data minimisation

The platform should not retain a full identity-document copy where a verification outcome or limited fields are sufficient for the purpose. Data scope must follow the inventory and actual provider configuration, not the integration’s maximum capabilities.

Rights and contact

Information on access, rectification, restriction, objection, erasure and other rights depending on the legal basis and legal duty is provided in the current privacy notice. Questions may be sent to [email protected].

Identity Verification Data Notice for Operator

Identity Verification Data Notice for Operator

0.9.5 · Published

Purpose of processing

Identity data is processed to verify the account, reduce abuse, protect transactions, perform required checks on a professional provider and-depending on configuration-satisfy payment or tax duties. Each active use case must have a documented legal basis.

Verification provider

If an external verification provider is used, its identity, role, data scope, transfers and retention must be recorded in the production processor register and current privacy information before the integration is enabled.

Data minimisation

The platform should not retain a full identity-document copy where a verification outcome or limited fields are sufficient for the purpose. Data scope must follow the inventory and actual provider configuration, not the integration’s maximum capabilities.

Rights and contact

Information on access, rectification, restriction, objection, erasure and other rights depending on the legal basis and legal duty is provided in the current privacy notice. Questions may be sent to [email protected].

IterOrbis Community Standards

IterOrbis Community Standards

0.9.5 · Published

Respect and safety

Do not post threats, harassment, persistent unwanted contact, incitement to violence, degrading or intimidating content, or material that creates real-world risk for Journey participants. Disagreement or a negative review does not justify attacking another person.

Honesty

Do not impersonate others or falsify verification, qualifications, experience, availability, price, service scope or Journey history. Information that may affect safety or a purchasing decision must be presented accurately.

Other people’s privacy

Do not publish another person’s contact details, documents, exact location, medical data or other private information without a proper basis. Material from a shared journey does not automatically become public.

Enforcement

A breach may result in content or feature restrictions, a warning, a correction request, temporary suspension or termination depending on nature, context, recurrence and risk. Where law requires a statement of reasons or appeal, the platform applies the relevant procedure.

IterOrbis Privacy Notice

IterOrbis Privacy Notice

0.9.5 · Published

Controller and contact

The controller of personal data processed through IterOrbis is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy enquiries may be sent to [email protected]; legal enquiries to [email protected].

Categories of data we process

Depending on the features used, we process account and contact data, profile and travel preferences, Journey and booking information, messages, safety and verification data, payment and settlement references, technical and security data, privacy choices, and-where voluntarily enabled-location, analytics or user-generated media data.

Whether providing data is required

Fields required for registration, security, entering into or performing a contract, payment, settlement or compliance with a legal obligation are identified in the relevant interface. Failure to provide required data may prevent account creation, conclusion or performance of a specific contract, payout, verification or access to the relevant function. Optional data may be omitted without losing a function that does not require it.

Purposes and legal bases

Data is used to create and operate accounts, provide marketplace and booking functions, enable communications, process payments and settlements, protect safety and prevent abuse, handle complaints, comply with legal obligations and improve the service. The applicable basis is, as relevant, contract performance or pre-contract steps, legal obligation, legitimate interests after the required assessment, or consent where a feature genuinely requires it.

Recipients and service providers

Data may be shared with the other party to a Journey where needed for the selected function, and with providers of infrastructure, hosting, email, SMS/push, maps and routing, payments, verification, support and security. A provider is activated only according to production configuration; the existence of an integration in code does not by itself cause data to be shared.

Data received from other sources

Some data may be received from the other party to a booking, a host or operator, a payment provider, an identity or safety provider, or a public register or source where legally permitted. Where personal data was not obtained directly from the data subject, we provide the information required by Article 14 GDPR, including the categories and source of the data, within the time applicable to the process unless a statutory exception applies.

Transfers outside the EEA

If an active provider processes data outside the European Economic Area, IterOrbis uses the transfer mechanism required by the GDPR and makes information about the applicable safeguards available. The final transfer list follows the providers actually enabled in production and the processor register.

Retention

Data is retained for the period needed for the stated purpose, the life of the account or contract, transaction settlement and potential claims, and for periods required by law. Analytics and technical data use separate retention limits in configuration. When the purpose ends, data is deleted, anonymised or restricted unless further retention is legally required or needed to establish, exercise or defend claims.

Your rights

Depending on the legal basis and circumstances, the data subject may request access, rectification, erasure or restriction, exercise data portability, object to processing and withdraw consent for the future where consent is the basis. Requests may be sent to [email protected]. The data subject may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.

Analytics and personalisation

Optional first-party analytics is activated only after the consent state required by configuration. Declining analytics does not block core account functionality. The privacy choice is remembered so it can be respected on later visits.

Live location

Exact or approximate location in Live Journey is processed only after the user knowingly enables sharing. Sharing can be stopped and records use a limited lifetime. The feature is not an emergency-response guarantee or a substitute for emergency services.

Marketing

Transactional messages about the account, safety or order performance are separated from marketing. Electronic marketing is sent only after the applicable conditions are met and may be withdrawn independently for the relevant channels.

Seller reporting obligations

If platform-operator reporting duties apply to activities carried out through the platform, IterOrbis may be required to collect, verify, retain and report specified seller data and information about reportable activity to the competent authorities. This processing is activated only after a formal decision that the requirement is in scope.

Automation

The system may use automated matching, quality scoring or recommendations to organise information and assist users. The production design should not base decisions producing legal effects, or similarly significant effects on a user, solely on such automated processing without a separate lawful basis, notice and required safeguards.

Security and incidents

We use technical and organisational measures appropriate to risk, including access controls, logging of material events, server-side secret handling, webhook protection, and backup and recovery procedures. Personal-data breaches are handled under an incident procedure and applicable legal obligations.

Changes and versioning

This Notice has a version and effective date. A material change to purposes, legal bases, data categories, recipients or the business model requires a new version and appropriate notice to users; a previously delivered version is not silently rewritten.

IterOrbis Safety Standard

IterOrbis Safety Standard

0.9.5 · Published

Nature of safety tools

Profiles, verification, check-in, emergency sharing, Live Journey and safety notices help reduce risk but do not guarantee the safety of a person, vehicle, vessel, route, weather conditions or other participants’ behaviour.

Current information

The user and relevant host/operator should independently verify current entry rules, documents, qualifications, technical condition, weather, warnings and instructions from local authorities or operators. Planning data on the platform does not replace a current official source.

Emergencies

In an immediate emergency, contact the appropriate emergency services. IterOrbis features are not an emergency-dispatch system and may depend on internet access, device availability, power, GPS or an external provider.

Reporting safety concerns

A serious safety concern, abuse or incident related to the platform should be reported through the appropriate safety tool or support channel. Information is shared only with people and entities that need it to handle the incident or where disclosure is legally required.

IterOrbis Terms of Service

IterOrbis Terms of Service

0.9.5 · Published

Service provider

The IterOrbis platform is provided by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its address at Długa 2B, 56-416 Twardogóra, dolnośląskie, PL, registered in Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, IX Wydział Gospodarczy Krajowego Rejestru Sądowego (KRS) under number 0000841054, tax ID 9112034523, REGON 386056613, share capital PLN 20,000. General support: [email protected], legal contact: [email protected], complaints: [email protected].

Scope of services

IterOrbis provides accounts, profiles, Journey search and publication, participation requests, communications, booking, payment, safety and planning tools, and other functions described in the interface. Availability of a specific function may depend on country, user role, verification, Journey type and production configuration.

Age and account eligibility

In the current production version, an account may be created only by a person who is at least 18 years old. Do not create an account for a person who does not meet this requirement. The platform may require eligibility to be confirmed again where needed for safety, compliance or a specific feature.

Account and security

You must provide accurate and current information, protect your credentials and are responsible for activity performed through your account unless it results from a security breach outside your control. Impersonation, bypassing verification and creating accounts to evade restrictions are prohibited.

Platform intermediary role

For functions classified as intermediation, IterOrbis provides technical infrastructure and tools enabling contact or transactions between users, or between a user and an operator. The travel service is supplied by the identified offeror, and IterOrbis’s allocation of responsibilities is shown before the user becomes bound by a contract.

Offers and offeror status

For marketplace offers, the interface should identify the offeror, state whether the offeror declares trader status, explain the resulting consumer-law implications, and show how responsibilities are allocated between the offeror and the platform. Transaction-specific information takes precedence over a general feature description.

Price, fees and payment

Before placing a paid order, the user receives a summary of the price, fees, currency, service and rules applicable to the transaction. The final paid-checkout action must clearly communicate an obligation to pay. A quote, seat hold or expression of interest is not a paid booking unless the interface clearly states otherwise.

Reviews and authenticity

Reviews should reflect genuine experience or a genuine relationship with an offer where the relevant surface represents them that way. Fake reviews, purchased reviews, coordinated rating manipulation and undisclosed material conflicts of interest are prohibited. Details are set out in the Review Authenticity Policy.

Content, restrictions and appeals

The platform may restrict content visibility, account functionality or service access where content is illegal, breaches these Terms, or a restriction is necessary for safety or compliance. Where the relevant DSA obligations apply, decisions and appeals are handled under the applicable notice-and-action, statement-of-reasons and complaint procedures.

Complaints and disputes

Complaints about platform operation may be submitted to [email protected]. The complaint should describe the issue and allow the relevant service or transaction to be identified. Information about available out-of-court dispute-resolution methods is provided in accordance with applicable law and the platform’s current reviewed operating decision.

Changes to this document

Each published version of these Terms has its own version number, effective date and immutable content snapshot. If a change requires renewed acceptance, the user will receive an appropriate notice before continuing to use the affected functions. Acceptance history is recorded against the document version.

Live Location Consent and Notice

Live Location Consent and Notice

0.9.5 · Published

Optional feature

Live location sharing is optional and requires a deliberate user action. Refusing does not block the core account or an ordinary booking unless a specific, clearly described safety feature technically cannot function without location.

Precision and audience

The interface should distinguish approximate and exact location and state who can see it. Location is not made public merely because it is part of Live Journey; access should be limited to authorised participants and safety functions.

Stopping and retention

You can stop sharing. Location records use a limited TTL set in platform configuration and should not be retained indefinitely as a tracking history.

No emergency-response guarantee

Live Journey and location sharing are coordination tools, not an emergency-response service. In an emergency, use the appropriate local emergency numbers and safety procedures.

Marketplace and Seller Transparency Notice

Marketplace and Seller Transparency Notice

0.9.5 · Published

Marketplace role

IterOrbis enables users to search, compare and book offers made available by hosts or operators. Before a transaction is concluded, the interface is intended to identify the provider, its status and whether, and to what extent, BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ is a contracting party for the underlying service.

Trader status

Where the provider acts as a trader, that status should be shown to the user. If the operating model permits a private provider, the interface should clearly distinguish that status and explain that certain consumer rights may depend on the identity of the contracting party.

Trader information shown with an offer

Where the DSA trader-traceability obligation applies, the offer interface makes the required trader information available in a clear, easily accessible and comprehensible manner, including the trader’s name and contact details required by law, relevant trade-register information and registration number, and the required self-certification. Identification documents and payment-account details are not made public on this basis.

Allocation of responsibilities

The allocation of responsibilities between the platform and provider is presented in the context of the relevant offer and checkout. The provider is at least responsible for information it supplies and duties assigned to it in the interface and terms; the platform is responsible for its own services and duties arising from the selected operating model.

Notice-and-Action Procedure for Potentially Illegal Content

Notice-and-Action Procedure for Potentially Illegal Content

0.9.5 · Published

How to submit a notice

A notice of potentially illegal content should allow a sufficiently substantiated explanation of why the information is considered illegal, the exact electronic location-such as a specific URL or equivalent identifier-and, where required by law, the notifier’s name and email address. The form also includes a bona fide statement that the information and allegations are accurate and complete. Identity details are not required where the applicable rule permits a notice without them.

Acknowledgement of receipt

Where the notifier provided electronic contact details, the platform acknowledges receipt without undue delay and retains a case identifier needed for further communication.

Assessment

Valid notices are processed in a timely, diligent, objective and non-arbitrary manner. The process does not automatically presume that the reported content is illegal. Where automated means were used to process the notice or make a decision, this is disclosed to the extent required by the DSA.

Outcome

After a decision, we inform the notifier of the outcome to the extent required by the DSA and identify available challenge or redress routes. Where a restriction concerns a recipient of the service or that recipient’s content, a separate statement of reasons to that person contains the elements required by the DSA.

Abuse of the procedure

Repeated manifestly unfounded notices or deliberate use of the procedure to harass other users may lead to restrictions under the terms, taking account of context and required procedural safeguards.

Notice on Main Ranking Parameters

Notice on Main Ranking Parameters

0.9.5 · Published

Search and discovery results

The baseline discovery ranking starts from a common score and may reduce position for greater origin or destination mismatch and increase it for matching travel mode or Journey vibe. Exact weights and signals may evolve, but any production change to the mechanism should be reflected in this notice.

Recommendations

Recommendations may additionally consider followed hosts, travel objectives and preferences, Travel DNA, remaining capacity, near-term departure and cost. These are matching signals and do not amount to a guarantee of the quality or safety of a particular offer.

Paid ranking influence

No mechanism for paid influence over offer ranking has been identified in the current model. If paid prominence or another commercial influence on visibility is added in the future, it must be clearly labelled to users and included in the description of main ranking parameters before production use.

No position guarantee

Ranking is dynamic and depends on query context, user data available to the function, offer parameters and current configuration. Neither a user nor a provider is entitled to a fixed position in results.

Operator Privacy Notice

Operator Privacy Notice

0.9.5 · Published

Controller and contact

The controller for data relating to the business account is BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. Privacy contact: [email protected].

Data categories

Depending on the functions used, we process account and contact data, business and trader-status information, offer and booking data, communications, settlement information, payment-provider identifiers, verification outcomes, safety data, moderation history and tax information required for platform reporting.

Required and optional data

Data identified as required is needed, as applicable, to create and secure the business account, verify status or authorisations, publish an offer, enter into and perform a transaction, settle amounts or comply with a legal obligation. Failure to provide required data may prevent the relevant action. Optional fields may be omitted without losing a function that does not require them.

Purposes and legal bases

Data is used to operate the account and offers, perform platform services, communicate and settle transactions, maintain safety and prevent abuse, comply with legal obligations, handle disputes and-where legally required-perform tax reporting. A legal basis is assigned to each process, and consent is used only where the specific operation genuinely requires it.

Indirect sources

Data may also come from a user making a booking, a payment provider, a verification provider, a relevant public register or another source identified for the process. Where personal data was not obtained directly from the data subject, we provide the required information about data categories and sources in accordance with Article 14 GDPR unless a statutory exception applies.

Recipients and retention

Data may be shared with the relevant traveller as needed for a transaction, infrastructure and payment providers, and public authorities where a legal basis exists. Retention follows the purpose, account lifecycle, limitation periods, tax obligations and safety needs; details are maintained in the versioned retention register.

Transfers and automation

If a provider processes data outside the EEA, an appropriate transfer mechanism and the required information on safeguards must exist before production use. If automated decision-making that produces legal effects or similarly significantly affects a person is introduced for business accounts, this notice will be supplemented with the required information on the logic involved, significance and envisaged consequences.

Rights and requests

Depending on the legal basis and circumstances, the data subject may exercise rights of access, rectification, erasure or restriction, portability, objection and withdrawal of consent for the future. Requests: [email protected]. A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.

Promotion and Voucher Terms

Promotion and Voucher Terms

0.9.5 · Published

Promotion activation

This document family is published only when the production promotion or voucher module is actually enabled. Each campaign must identify the organiser, period, eligible users, benefit and how it is applied.

Conditions and restrictions

Campaign rules state any minimum spend, eligible offers, use limits, ability to combine with other benefits and expiry date. Material restrictions should not be hidden until after checkout has started.

Refunds where a benefit was used

For a cancellation or refund, campaign rules explain whether and to what extent a voucher or discount is restored and how it affects the refund amount. The user should not be told that promotional value will be paid out in cash where that is not provided for.

Abuse

The platform may reject or reverse a benefit obtained through account manipulation, a technical error or breach of clearly stated campaign rules, subject to the user’s rights under mandatory law.

PRO Operator Business Complaint Procedure

PRO Operator Business Complaint Procedure

0.9.5 · Published

Complaint scope

A business user may raise an issue concerning platform operation, an account or offer restriction, ranking, settlement, technical functionality or another decision affecting use of business services. The complaint channel does not replace urgent safety channels.

Submission and identification

A complaint may be submitted electronically free of charge, identifying the account or case, the problem and available evidence. Contact: [email protected]. The platform records receipt and material steps in the case and keeps the channel easily accessible to the business user.

Review

Complaints are handled within a reasonable time, transparently, with equal treatment of comparable cases and proportionately. The review considers the arguments and available evidence. The business user receives an individual outcome stated in plain and intelligible language.

Outcome and further redress

The outcome states whether the decision is upheld, changed or reversed and, where applicable, available further redress. The case record is retained for accountability and analysis of recurring issues.

Information on complaint-system performance

Where required by P2B, we publish easily accessible information on the functioning and effectiveness of the internal complaint-handling system, including the number of complaints, their main types, the average time needed to process them and aggregated information on outcomes; the information is updated as required.

Mediation

Where the P2B mediation obligation applies, our terms identify at least two mediators with whom we are willing to attempt an agreement: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation is without prejudice to the right to court proceedings and other available remedies.

PRO Operator Business Terms

PRO Operator Business Terms

0.9.5 · Published

Provider and account scope

The PRO Operator account on IterOrbis is operated by BOMEGA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Długa 2B, 56-416 Twardogóra, dolnośląskie, PL. These terms cover professional offer publication, availability management, messaging, bookings, settlements and safety tools. Contact: [email protected], legal matters: [email protected], complaints: [email protected].

Professional status and required authorisations

The Operator represents that trader information is truthful and current and that it holds licences, permits, insurance and other authorisations required for the service actually offered. Account admission or a “verified” label does not replace duties imposed by law applicable to transport, travel or another regulated activity.

Intermediation

Where IterOrbis acts as an intermediary for a category, the Operator remains the professional service provider to the user and is responsible for compliance, description, availability and performance. The pre-transaction interface identifies the parties and allocation of responsibilities.

Professional offer ranking

Ranking may consider origin and destination fit, preferences, journey type and parameters, availability, offer-data quality and safety signals described in the ranking notice. No position is guaranteed. Any future paid prominence requires separate labelling and an update to the ranking rules.

Access to data in the business relationship

The business user has access to data for its account, offers, bookings, settlements and communications made available in the dashboard or supported exports. The platform accesses data needed to provide the service, maintain security, settle transactions, moderate content, handle disputes and comply with legal obligations. Access after termination depends on export functions, retention, data-subject rights and legal duties; we do not promise access to data that the platform no longer lawfully retains.

Service restrictions and redress

For a breach of law, terms, safety rules or verification requirements, the platform may restrict an offer, function or account. Where business-user duties apply, the decision notice states the basis, scope and available complaint or appeal channel.

Internal complaint-handling system

Where the P2B obligations apply, a business user may use the internal complaint-handling system free of charge for matters covered by the applicable rules. The current Business User Complaints Policy describes the channel and handling procedure.

P2B mediators

Where the obligation to identify mediators applies, we are willing to attempt mediation with at least the following mediators: Centrum Mediacji Lewiatan (https://lewiatan.org/centrum-mediacji-lewiatan/) and Centrum Mediacji przy Krajowej Izbie Gospodarczej (https://kig.pl/uslugi/centrum-mediacji/). Mediation does not restrict either party’s right to seek judicial relief or other mandatory remedies.

Settlements and payouts

The Operator receives information on price, fees, adjustments, refunds and payout status in the relevant screens. Payout depends on accurate settlement data, required verification and absence of a hold arising from a dispute, refund, safety review or legal requirement.

PRO Operator Verification Notice

PRO Operator Verification Notice

0.9.5 · Published

Purpose of verification

Verification is used to confirm identity and information needed for safe offer publication, settlements and duties relating to professional providers. The scope depends on role, country, service category and risk level.

Data and evidence

Where the DSA trader-traceability obligation applies, before allowing a trader to offer products or services to consumers we collect at least: the trader’s name, address, telephone number and email address; a copy of an identification document or electronic identification to the extent required by law; payment-account details where applicable; the relevant trade-register details and registration number where the trader is registered; and the required self-certification that the offered products or services comply with applicable Union law. Data is limited where an element is not legally required in the specific case.

Outcome and updates

To the extent required by the DSA, we make best efforts to assess whether the supplied information is reliable and complete using available sources or documents. If information is inaccurate, incomplete or outdated, the trader is given an opportunity to correct it; failure to remedy the issue within the required period may result in suspension of the ability to offer until the deficiency is resolved.

Retention and access

Verification data is accessible only to authorised people and systems in accordance with data minimisation. Data collected under the DSA trader-traceability obligation is stored securely for the period required by that rule-generally six months after the relationship with the trader ends-and then deleted unless another legal obligation requires specified information to be retained longer.

Referral and Loyalty Programme Terms

Referral and Loyalty Programme Terms

0.9.5 · Published

Eligibility

Where the programme is active, the programme screen states who may refer, who may receive a benefit and which event earns it. Accounts created to manufacture benefits, self-referrals or coordinated abuse may be excluded from the programme.

Benefit

The value, currency or other form of benefit, timing, expiry and use restrictions are shown before participation. A benefit has no cash-out value unless the specific programme rules expressly state otherwise.

Fair communication

A referrer should not misrepresent the benefit or platform, impersonate official advertising or send unsolicited communications contrary to law. A referral link does not authorise bypassing the recipient’s privacy choices.

Programme changes

New campaigns and future programme periods may be changed or ended with appropriate notice. Properly earned benefits are handled under the rules in force when earned, subject to correction for abuse or an obvious error.

Review Authenticity Policy

Review Authenticity Policy

0.9.5 · Published

Who may review

A review may be labelled “verified”, “after travel”, “after booking” or equivalent only where the platform has a reasonable and proportionate mechanism linking it to an actual travel, booking or transaction record. A review without such confirmation must not be presented in a way suggesting that the author actually used the reviewed service.

Whether and how reviews are checked

At the interface presenting reviews, we make available information on whether review origin is checked and how the check works, including the meaning of labels such as “verified”. Where a group of reviews is not verified against a transaction or another reliable signal, the information must not suggest that all reviews come from actual customers.

No manipulation

Buying or selling reviews, using multiple accounts to manipulate scores, coordinating reciprocal ratings for manipulation, and applying pressure in exchange for an undisclosed benefit are prohibited.

Review moderation

A review may be restricted if it violates law, privacy or community standards; critical content should not be removed merely because it is negative. The relevant interface should explain how reviews are verified and moderated.

Subscription and Premium Terms

Subscription and Premium Terms

0.9.5 · Published

Subscription scope

Where subscriptions are enabled, the purchase screen identifies the plan, features, price, currency, billing period, renewal method and when charging starts. One-off features are not presented as a subscription without clear labelling.

Renewal

If a plan renews automatically, the recurring nature of the payment is shown before purchase. The user has access to the next billing date and a method for disabling future renewal.

Cancellation of future periods

Cancelling a subscription stops future renewals as communicated to the user; effects on an already started period, refunds and consumer rights depend on the purchase terms and mandatory law.

Plan or price changes

A material change to features, price or renewal model must not be applied to a future billing cycle without the required notice and basis. Where law or the contract requires renewed agreement or a termination option, the release process must support it before charging the user.

Traveller Payments and Fees Notice

Traveller Payments and Fees Notice

0.9.5 · Published

Price before payment

Before a paid order is placed, checkout presents the service amount, platform service fee, total amount and currency, together with the relevant offer identity. The user should review the summary before starting payment.

Explicit obligation to pay

The final action in a paid checkout must clearly communicate that completing it creates an obligation to pay. Absence of that communication is treated as a deployment-blocking error for the payment surface.

Payment provider

Payment may be processed by an external provider configured for production. IterOrbis stores only information and identifiers needed to link the transaction and settlement; the data shared with the provider follows the integration actually used and the current privacy notice.

Refunds and disputes

A refund, partial refund, cancellation or payment dispute is handled under the booking terms, applicable law and transaction status. The interface should show the process state; a technical “refund pending” record does not mean the payment provider has already completed the refund.

Travel Service Role Disclosure

Travel Service Role Disclosure

0.9.5 · Published

Classification before transaction

Before sales are enabled, each flow combining travel services must have an approved legal classification for the relevant market. The checkout interface presents the role of IterOrbis, the identity of the relevant provider and information required for the operating model actually selected.

Marketplace model

In a marketplace-only model the platform facilitates discovery and transactions, while the provider identified before purchase remains the travel-service provider. The platform does not present such a product as a package organised by it unless the specific flow has been separately classified.

User Content Policy

User Content Policy

0.9.5 · Published

Rights in content

You should publish only content you have rights or another valid basis to publish. You retain rights in your content while granting the platform the permissions needed to store, technically process and display it according to the selected feature and visibility settings.

Other people in media

When publishing media depicting other people, you must respect their rights, privacy and any required consent or other lawful basis. Travelling together does not automatically mean everyone consents to public publication of a photo or video.

Removal and restrictions

The platform may restrict or remove content where necessary because of law, other people’s rights, safety or platform rules. Where required by law, the user will receive a statement of reasons and access to the applicable appeal procedure.