1. Roles of the parties
This Data Processing Addendum ("DPA") is entered into between Suite Profit Sp. z o.o., with its registered office at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska, entered in the register of entrepreneurs kept by Sąd Rejonowy dla m.st. Warszawy, XII Wydział Gospodarczy Krajowego Rejestru Sądowego under KRS number 0001102845, NIP 523-456-78-90, REGON 528 145 906, share capital PLN 10 000 fully paid up ("Suite Profit", "Processor"), and the Customer who subscribes to the Service ("Customer", "Controller"). This DPA forms an integral part of the Terms of Service and applies to any processing of Personal Data carried out by Suite Profit on behalf of the Customer in connection with the Service. In respect of Customer account data (billing details, administrator credentials, and support correspondence) Suite Profit acts as an independent controller and applies the Privacy Policy at /legal/privacy. In respect of guest data flowing from the Customer's Profitroom Suite tenant, Suite Profit acts strictly as a processor within the meaning of Article 4(8) GDPR.
2. Scope of processing
The subject-matter, duration, nature and purpose of the processing, the type of Personal Data processed, and the categories of data subjects are set out below in accordance with Article 28(3) GDPR.
- Subject-matter — the provision of independent third-party software modules that integrate with Profitroom Suite via the official Profitroom API.
- Duration — the duration of the Subscription Term plus a thirty (30) day grace period for data export.
- Nature and purpose — reading reservation and rate data from Profitroom Suite, computing pricing suggestions, sending Customer-authored messages over the WhatsApp Business Cloud API, synchronising inventory between properties in a hotel group, and displaying dashboards to Customer users.
- Types of Personal Data — Customer user contact and authentication data; guest name, contact channel, arrival and departure dates, room type, rate code, stay value, and reservation identifier; message content and delivery metadata.
- Categories of data subjects — Customer employees and contractors authorised to use the Service; guests and prospective guests of the Customer's properties.
3. Processor obligations
Suite Profit undertakes:
- To process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law; in such a case Suite Profit will inform the Customer of that legal requirement before processing, unless that law prohibits the disclosure on important grounds of public interest.
- To ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- To take all measures required pursuant to Article 32 GDPR concerning the security of processing, as described in Annex II of the Standard Contractual Clauses and summarised in Section 6 below.
- To respect the conditions for engaging sub-processors set out in Sections 4 and 5 below.
- Taking into account the nature of the processing, to assist the Customer by appropriate technical and organisational measures for the fulfilment of the Customer's obligation to respond to requests for exercising data subjects' rights.
- To assist the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data-protection impact assessment, prior consultation) taking into account the nature of processing and the information available to Suite Profit.
- At the choice of the Customer, to delete or return all the Personal Data to the Customer after the end of the provision of services relating to processing, and to delete existing copies unless Union or Member State law requires storage of the Personal Data.
- To make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and to allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, subject to Section 10 below.
4. Sub-processors
The Customer authorises Suite Profit to engage the following sub-processors at the effective date of this DPA. The list may be updated in accordance with the notice procedure in Section 5.
- Amazon Web Services EMEA SARL — Luxembourg, with hosting in eu-central-1 (Frankfurt, Germany) and secondary backup in eu-west-1 (Dublin, Ireland). Role: cloud infrastructure — compute, storage, and networking.
- Stripe Payments Europe Limited — Dublin, Ireland. Role: card-payment reconciliation where the Customer opts in to card payments as an alternative to bank transfer.
- Anthropic Ireland Ltd. — Dublin, Ireland. Role: large language model inference for optional AI-assisted features.
- OpenAI Ireland Ltd. — Dublin, Ireland. Role: large language model inference for optional AI-assisted features, used interchangeably with Anthropic Ireland Ltd.
- Twilio Ireland Limited — Dublin, Ireland. Role: transactional SMS fall-back for guest messaging.
- Meta Platforms Ireland Limited — Dublin, Ireland. Role: WhatsApp Business Cloud API for guest messaging.
- Postmark (ActiveCampaign, LLC) — with EU processing region enabled where applicable. Role: transactional email delivery for account notifications.
5. Sub-processor change notification
Suite Profit will inform the Customer of any intended changes to the list of sub-processors, giving the Customer at least thirty (30) days' notice by email and, in parallel, updating the sub-processor page at suiteprofit.org. During that notice period the Customer may object to the change on reasonable grounds relating to data protection. If the Customer objects and the Parties cannot agree on a resolution within a further thirty (30) days, the Customer may terminate the affected part of the Service by written notice without penalty; fees paid in advance for the terminated part will be refunded pro-rata. In exceptional situations, for example the urgent replacement of a sub-processor due to a security incident or a sudden withdrawal of service, the notice period may be shortened; in that case Suite Profit will inform the Customer as soon as reasonably possible and offer the same right to object.
6. Security measures (Annex II)
Suite Profit implements the following technical and organisational measures:
- Encryption — TLS 1.2 or higher in transit with modern cipher suites; AES-256 at rest for primary storage and backups; encrypted volume snapshots.
- Access control — role-based access with least-privilege defaults; identity federated through single sign-on with mandatory multi-factor authentication for staff; automatic session expiry; access reviews performed quarterly.
- Secrets management — API keys and cryptographic material stored in a hardened secret manager with per-environment separation; automatic rotation for machine-to-machine credentials.
- Segregation — logical multi-tenancy with per-tenant identifiers enforced at the database layer and validated by automated test suites; strict separation of production and non-production environments.
- Backups and recovery — encrypted backups with a Recovery Point Objective of 24 hours and a Recovery Time Objective of 4 hours; annual disaster-recovery drill.
- Monitoring and incident response — 24-hour on-call rotation; centralised structured logging with 90-day retention; documented incident-response runbooks; blameless post-incident review.
- Change management — mandatory peer review for code changes affecting personal data; automated static analysis; software composition analysis for dependency vulnerabilities.
- Physical security — provided by the underlying cloud infrastructure provider; certifications include ISO/IEC 27001 and SOC 2 Type II.
- Personnel — background verification proportionate to role; annual security and privacy training; confidentiality obligations that survive termination of employment or engagement.
7. Data subject requests
Where a data subject exercises a right under Chapter III GDPR directly against Suite Profit and the request relates to Personal Data processed on behalf of the Customer, Suite Profit will forward the request to the Customer without undue delay and will not respond to the data subject on the merits, save to acknowledge receipt and indicate that the request has been forwarded to the responsible controller. Where the Customer asks Suite Profit to assist with the fulfilment of a request, Suite Profit will provide reasonable assistance through documented functionality in the Service (data export, data deletion, correction interfaces) and, where necessary, through additional support at no extra cost for reasonable volumes.
8. Personal data breach notification
Suite Profit will notify the Customer without undue delay, and in any event within twenty-four (24) hours of becoming aware of a personal data breach concerning Personal Data processed on behalf of the Customer, in order to give the Customer time to comply with its own seventy-two (72) hour notification obligation to the Prezes Urzędu Ochrony Danych Osobowych under Article 33 GDPR. The notification will include, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its adverse effects. Suite Profit will supplement the initial notification with further information as the investigation progresses.
9. International transfers
Where processing takes place outside the European Economic Area or where a sub-processor's parent company might in some scenarios receive an access request from an authority outside the EEA, the Parties enter into the Standard Contractual Clauses of 4 June 2021 published by the European Commission ("SCCs") for the transfer of Personal Data to third countries. Module 2 (controller-to-processor) applies to transfers from the Customer to Suite Profit where the Customer is established outside the EEA, and Module 3 (processor-to-processor) applies to transfers from Suite Profit to sub-processors established outside the EEA. The SCCs are incorporated by reference and are supplemented by the technical and organisational measures described in Section 6.
10. Audit rights
Suite Profit will provide the Customer with the information necessary to demonstrate compliance with Article 28 GDPR. Once per calendar year the Customer may exercise its audit right by submitting a written request specifying the scope, the auditor, and the proposed timing. Suite Profit will support one such on-site or remote audit per calendar year at the Customer's expense. In place of a Customer-led audit, the Customer may accept an equivalent third-party attestation (for example an ISO/IEC 27001 certificate, a SOC 2 report, or a report by an accredited auditor). Additional audits may be required and shall be conducted at the Customer's expense in the event of a personal data breach affecting the Customer's data, or when required by a supervisory authority.
11. Return or deletion at end of contract
At the choice of the Customer, expressed in writing within thirty (30) days after the end of the provision of the Service, Suite Profit will return the Personal Data to the Customer in a commonly used, structured, machine-readable format, or delete it. In the absence of instructions Suite Profit will delete Personal Data upon expiry of the grace period. Deletion covers Personal Data in primary storage; Personal Data in encrypted backups is overwritten on the ordinary rotation schedule described in Section 6. Confirmation of deletion will be provided on request.
12. Liability
The liability of the Parties under this DPA is subject to the aggregate limitation of liability set out in the Terms of Service, save that nothing in the DPA or the Terms limits or excludes liability that cannot be lawfully limited or excluded, including liability for damage caused by intentional misconduct or by a failure to comply with a specific obligation under Chapters III or IV GDPR when acting outside the lawful instructions of the Controller.
13. Governing law
This DPA is governed by the laws of the Republic of Poland and, to the extent that the SCCs are incorporated, by the law designated in Clause 17 thereof for each transfer. Disputes arising out of this DPA shall be resolved in accordance with the dispute-resolution clause of the Terms of Service, with exclusive jurisdiction of the Sąd Okręgowy w Warszawie. In respect of matters concerning the supervisory authority the competent authority is the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.