1. Controller identification
The controller of your personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") is Suite Profit Sp. z o.o., a limited liability company incorporated under the laws of the Republic of Poland, with its registered office at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska, entered in the register of entrepreneurs kept by Sąd Rejonowy dla m.st. Warszawy, XII Wydział Gospodarczy Krajowego Rejestru Sądowego under KRS number 0001102845, NIP 523-456-78-90, REGON 528 145 906, share capital PLN 10 000 fully paid up. In this Policy Suite Profit is also referred to as "we", "us", or "the Company".
This Privacy Policy describes how we process personal data when we operate the suiteprofit.org website and when we deliver our subscription modules to hotel operators that connect us to their Profitroom Suite tenant. Where our Customer (the hotelier) determines the purposes and means of processing guest data, our Customer is the controller and Suite Profit acts as a processor on the Customer's behalf under Article 28 GDPR — the terms of that processing are set out in the Data Processing Addendum available at /legal/dpa.
2. Data Protection Officer
We have appointed a Data Protection Officer (Inspektor Ochrony Danych) in accordance with Article 37 GDPR and Article 8 of the Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych. The DPO is Aleksandra Kwiatkowska. You may contact the DPO in writing at the postal address above (with the envelope marked "IOD") or by email at dpo@suiteprofit.org. The DPO is bound to secrecy and is available to answer questions from data subjects, to receive rights requests, and to cooperate with the Polish supervisory authority.
3. Legal framework
We process personal data in compliance with the GDPR, the Polish Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych ("Polish DPA 2018"), and the Ustawa z dnia 18 lipca 2002 r. o świadczeniu usług drogą elektroniczną (the Polish e-services law). Where a specific processing activity is regulated by additional statutes (for example the tax and accounting laws for invoice retention, or the Ustawa z dnia 16 lipca 2004 r. Prawo telekomunikacyjne for telecommunications data), we observe those laws in addition to the general rules described here.
4. Categories of personal data
We process the following categories of personal data:
- Contact data of Customer users — full name, business email address, business telephone number, job title, and preferred language.
- Authentication data — hashed passwords, session identifiers, IP address at login, browser fingerprint used only to detect suspicious sessions, and time-based one-time passwords for multi-factor authentication.
- Billing data — company name, VAT identification number, invoicing address, bank account number, and payment history.
- Guest data received via the Profitroom API — reservation identifier, arrival and departure date, room type, guest name, guest email or phone (where the Customer has captured it and has a lawful basis to share it with us), rate code, and stay value. This category is processed under the Customer's controller responsibility.
- Communication data — messages sent through the Guest Messenger over the WhatsApp Business Cloud API, delivery receipts, and read receipts.
- Technical logs — HTTP request logs, API access logs, error stack traces, and audit trails showing who did what and when in the dashboard.
- Cookies and similar technologies — see the Cookie Policy at /legal/cookies for a full description.
5. Purposes and legal bases
We process personal data on the following legal bases within the meaning of Article 6(1) GDPR:
- To conclude and perform the subscription contract with the Customer — Article 6(1)(b) GDPR. This covers account provisioning, invoicing, technical support, and the day-to-day delivery of the Service.
- To comply with legal obligations to which Suite Profit is subject — Article 6(1)(c) GDPR. This includes the retention of invoices for five years plus the current year under Article 74(2) of the Ustawa z dnia 29 września 1994 r. o rachunkowości and cooperation with public authorities upon a valid request.
- For the legitimate interests of Suite Profit and of third parties — Article 6(1)(f) GDPR. Our legitimate interests include the security and integrity of the Service, the prevention of fraud, the enforcement of our rights, direct communication with existing Customers about related products, and the compilation of aggregate statistics that do not identify individuals.
- Based on freely given, specific, informed and unambiguous consent — Article 6(1)(a) GDPR. Consent is used for non-essential cookies, for the receipt of marketing communications by prospects who are not existing Customers, and for optional AI features that transmit anonymised prompts to language-model providers.
6. Sources of data
We collect personal data directly from the Customer at signup and from Customer users during their normal interaction with the Service. Guest data flows from the Customer's Profitroom Suite tenant into our platform through the official Profitroom API using the API Credentials that the Customer authorises. Message-delivery metadata flows from Meta Platforms Ireland Limited (WhatsApp Business Cloud API) and from Twilio Ireland Limited (SMS fall-back). Payment metadata flows from Stripe Payments Europe Limited where a card-based payment mechanism is used instead of standard bank transfer.
7. Recipients of personal data
We do not sell personal data. We disclose personal data to the following categories of recipient strictly to the extent needed for the purposes above:
- Cloud infrastructure providers — Amazon Web Services EMEA SARL for hosting in Frankfurt (region eu-central-1) and secondary backup in Dublin (region eu-west-1).
- Payment processors — Stripe Payments Europe Limited (Dublin, Ireland) where card payments are chosen, and Blue Media S.A. for open-banking initiation of Polish PLN payments where offered.
- Communication providers — Meta Platforms Ireland Limited for WhatsApp Business Cloud API, Twilio Ireland Limited for SMS, Postmark (a service of ActiveCampaign) for transactional email.
- AI providers — Anthropic Ireland Ltd. (Claude models) and OpenAI Ireland Ltd. (GPT models) for optional AI features. When these are used only minimal data required to fulfil the feature is transmitted and no data is used by these providers to train foundation models under our commercial terms with them.
- Analytics — Plausible Insights OÜ (Estonia) for privacy-preserving, cookieless website analytics.
- Professional advisers — external legal counsel, statutory auditors, and tax advisers under professional duties of confidentiality.
- Public authorities — the Polish Tax Administration, the National Labour Inspectorate, courts, and law-enforcement bodies where we are legally compelled to disclose.
8. International transfers
Our default is to keep personal data within the European Economic Area. Where a sub-processor forms part of a group with parents or affiliates outside the EEA, transfers take place only when protected by an adequacy decision of the European Commission or by the Standard Contractual Clauses of 4 June 2021 (Modules 2 and 3 as applicable), completed by supplementary technical and organisational measures including encryption in transit and at rest, tenant-level segregation, and short retention. A full list of sub-processors and their locations is maintained in the Data Processing Addendum and updated as needed.
9. Retention periods
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected. Contract data is kept for the duration of the subscription and for thirty (30) days after termination to allow migration and support requests. Backups containing personal data are rotated on a 90-day cycle and are then irreversibly destroyed. Invoices and related accounting records are retained for five years counted from the end of the calendar year in which the fiscal obligation arose, in accordance with Article 74(2) of the Accounting Act. Aggregate, non-identifying statistics used for benchmarking and product improvement may be kept for up to one year and, once anonymised beyond the possibility of re-identification, indefinitely.
10. Data subject rights
Under Articles 15 to 22 GDPR you have the right to obtain from us confirmation as to whether personal data concerning you is being processed and, where that is the case, access to that data (Article 15); to obtain the rectification of inaccurate personal data (Article 16); to obtain the erasure of personal data ("right to be forgotten") where the conditions of Article 17 are met; to obtain the restriction of processing in the situations listed in Article 18; to receive the personal data you provided in a structured, commonly used and machine-readable format and to transmit it to another controller under Article 20; to object to processing based on legitimate interests at any time (Article 21); to withdraw a consent previously given, without affecting the lawfulness of processing based on consent before its withdrawal (Article 7(3)); and not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22). Requests may be sent to privacy@suiteprofit.org. We answer requests within one month and may extend that period by two further months for complex or numerous requests, in which case we inform you of the extension and its reasons.
You also have the right to lodge a complaint with the Polish supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych (UODO), if you consider that processing infringes the GDPR.
11. UODO contact
Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, telephone +48 22 531 03 00, website uodo.gov.pl. The e-PUAP address and further channels for filing complaints are published on the UODO website.
12. Security measures
We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Our measures include encryption in transit (TLS 1.2 or higher with modern cipher suites) and at rest (AES-256), tenant-level segregation of Customer data, least-privilege access controls managed through single sign-on with mandatory multi-factor authentication for staff, quarterly access reviews, centralised secret management, immutable audit logs, network isolation via private VPC subnets, dependency vulnerability scanning, and annual penetration testing by an accredited third party. Additional information on our security programme is available at /security.
13. Cookies and similar technologies
The suiteprofit.org website uses cookies and similar technologies to keep sessions active, to remember display preferences, and, subject to consent, to measure aggregate traffic. The full description of each cookie, its provider, purpose and duration, together with instructions for withdrawing consent, is available in the Cookie Policy at /legal/cookies. That Policy also implements Article 173 of the Polish e-services law.
14. Automated decision-making
The Autopricer module analyses market and demand signals and suggests price adjustments. The Customer's revenue manager reviews and approves or rejects each suggestion before it is transmitted back to Profitroom Suite. There is therefore no decision based solely on automated processing that produces legal effects or similarly significantly affects any data subject within the meaning of Article 22 GDPR. Customers may configure "auto-apply" thresholds for micro-adjustments (for example, plus or minus 3% within pre-defined rate ceilings). Even where auto-apply is enabled, the framework operates within Customer-defined boundaries and can be paused at any time; documentation, training material, and a manual override option are provided.
15. Children
Our Service is a business-to-business service for hotel operators. It is not directed at children and we do not knowingly process personal data of natural persons under the age of 16. Where guest data flowing from Profitroom Suite relates to a minor, the Customer as controller of guest data is responsible for the lawfulness of that processing.
16. Changes to this Policy
We may amend this Privacy Policy from time to time to reflect changes in law, guidance from the UODO or the European Data Protection Board, changes in our processing activities, or changes in the list of recipients. Material changes will be notified to Customer administrators by email at least thirty (30) days before the effective date. The current version and the date of its adoption are always visible at the top of this page.
17. Contact
For any question about this Privacy Policy or about the processing of your personal data please write to privacy@suiteprofit.org or to Suite Profit Sp. z o.o., Data Protection Officer, ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska. General support is available at support@suiteprofit.org.