Legal

Acceptable Use Policy

Effective date: 28 July 2026. Version 1.0.

1. Purpose and scope

This Acceptable Use Policy ("AUP") defines the rules that every user of the Suite Profit Service must respect. It supplements the Terms of Service and forms an integral part of the subscription agreement between Suite Profit Sp. z o.o., with its registered office at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska, entered in the register of entrepreneurs under KRS number 0001102845, NIP 523-456-78-90, REGON 528 145 906, share capital PLN 10 000 fully paid up, and the Customer. The AUP applies to every module offered by Suite Profit, to every user account provisioned by the Customer, to every API request generated by the Service on the Customer's behalf, and to every message dispatched to a guest through our infrastructure. The AUP applies without limitation to natural persons acting as administrators, revenue managers, hotel employees, or third-party consultants engaged by the Customer.

Because our Service interacts with third-party platforms — notably Profitroom Suite and the WhatsApp Business Cloud API — the rules below reflect not only Suite Profit's own requirements but also the acceptable-use standards of those third parties. A breach of an upstream platform rule that is committed through the Service is treated as a breach of this AUP.

2. Prohibited content

The Customer must not create, upload, publish, transmit, store, or forward through the Service any content that:

  • Infringes the intellectual property rights of a third party, including copyright, database rights, trademark rights, and design rights;
  • Constitutes hate speech, incitement to discrimination or violence, or content prohibited by Article 256 or 257 of the Polish Criminal Code;
  • Depicts or promotes child sexual abuse material, extreme violence, or terrorism;
  • Constitutes defamation or unlawful invasion of privacy under Article 23 of the Polish Civil Code;
  • Contains malicious code, exploits, spyware, keyloggers, or unauthorised data collection scripts;
  • Solicits or promotes prostitution, human trafficking, or any other activity prohibited by Polish law;
  • Contains fake or misleading reservation, review, or rate information intended to deceive guests or competitors.

3. Prohibited activities

Regardless of the content involved, the Customer must not use the Service to:

  • Facilitate unfair commercial practices prohibited by Article 5 of Directive 2005/29/EC (the Unfair Commercial Practices Directive) and by the Polish Ustawa z dnia 23 sierpnia 2007 r. o przeciwdziałaniu nieuczciwym praktykom rynkowym;
  • Publish rates that the Customer does not intend to honour, that mislead about total price (including compulsory charges), or that violate parity obligations to which the Customer is contractually bound;
  • Circumvent booking commissions or channel manager contracts of Profitroom partners in a way that violates the Customer's own agreements with those parties;
  • Harass, threaten, or defraud guests;
  • Impersonate another business, brand, or natural person;
  • Send communications that would violate anti-spam laws, in particular the Polish Ustawa z dnia 18 lipca 2002 r. o świadczeniu usług drogą elektroniczną and, where the recipient is in the EU, Article 13 of the ePrivacy Directive 2002/58/EC;
  • Use the Service to compile a database of personal data of hotel guests for a purpose other than the hotel-management purpose for which the Customer is the controller and has a lawful basis under GDPR;
  • Manipulate publicly displayed reviews or ratings, whether by soliciting fake reviews, offering incentives contingent on positive reviews, or filtering negative reviews before publication in a way that violates Article 7 point 23 of the Ustawa o przeciwdziałaniu nieuczciwym praktykom rynkowym as amended in 2023 to transpose Directive (EU) 2019/2161 (the Omnibus Directive).

4. Prohibited technical uses

The Customer must not:

  • Attempt to gain unauthorised access to Suite Profit systems, other tenants' data, or to any account, computer system, or network associated with the Service;
  • Perform automated scraping, load-testing, penetration-testing, or vulnerability-scanning against the Service or against Profitroom Suite beyond the level of API activity authorised for the Customer's own account, save with prior written authorisation from Suite Profit;
  • Bypass rate limits, quotas, or authentication mechanisms;
  • Reverse engineer, decompile, or disassemble any part of the Service, except to the limited extent expressly permitted by mandatory law under Article 75 of the Polish Ustawa z dnia 4 lutego 1994 r. o prawie autorskim i prawach pokrewnych;
  • Introduce or transmit any virus, worm, trojan, ransomware, or other malicious code;
  • Interfere with the proper operation of the Service, including denial-of-service attacks or actions that would materially degrade the experience of other Customers;
  • Use the Service to build a competing product, feature by feature, by inspecting the user interface, exporting benchmarks, or lifting proprietary methodologies.

5. API rate limits and fair use

Access to Suite Profit's public and private APIs is subject to per-tenant rate limits documented in our developer portal. The base tier permits 60 requests per minute per module with burst tolerance up to 120 requests per minute over any 10-second window. Higher limits are available for the Group plan or on request. Fair use of Profitroom API quota is a Customer responsibility: our modules operate within the quota granted to the Customer by Profitroom and are configured to back off exponentially on 429 or 5xx responses. Attempts to defeat back-off logic, to parallelise beyond the agreed thresholds, or to consume disproportionate compute time will result in throttling and, if repeated, suspension.

6. Spam and unsolicited communications

Every message dispatched through the Service must be addressed to a person with whom the Customer has an existing relationship (a confirmed reservation, a check-in in progress, or an equivalent business context) or a person who has given valid prior consent to receive that message. Bulk marketing communications through the Service are not permitted unless the Customer has captured explicit, GDPR-compliant marketing consent from each recipient and can demonstrate that consent on demand. Every non-transactional message must offer a simple mechanism to opt out. Repeated complaints or unusually low delivery quality will trigger throttling by Suite Profit and, potentially, by the upstream provider.

7. WhatsApp Business API compliance

The Guest Messenger module uses the WhatsApp Business Cloud API supplied by Meta Platforms Ireland Limited. The Customer expressly agrees to comply with the WhatsApp Business Solution Terms and the WhatsApp Commerce Policy, as they may be updated by Meta from time to time. In particular the Customer must:

  • Use pre-approved message templates for transactional messages sent outside the 24-hour customer service window;
  • Never use the Guest Messenger to send messages of a nature prohibited by the WhatsApp Commerce Policy (regulated goods and services, adult content, weapons, etc.);
  • Honour opt-outs immediately;
  • Provide clear information about the identity of the sender and about the nature of the messages;
  • Assume responsibility for any suspension of the Customer's WhatsApp Business Account resulting from the Customer's own conduct.

8. Review-manipulation prohibition

Suite Profit strictly prohibits any use of the Service to manipulate publicly displayed reviews. Automating the submission of reviews, selectively soliciting only guests who left a positive impression during the stay in a manner that violates the transparency requirements of the Omnibus Directive, offering incentives conditional on the content of a review, and hiding lawful negative feedback are all incompatible with this AUP. Customers may of course invite every guest to leave a review through the appropriate module, provided the invitation is neutral, is sent to every guest of a given segment without selection based on expected sentiment, and complies with the applicable review-platform rules.

9. Fair use of AI features

Where the Customer enables an AI-assisted feature — for example the AI-drafted message templates or the AI-summarised guest feedback — the following additional rules apply. Prompts must not contain sensitive Personal Data beyond what is strictly necessary to the task. The Customer must review AI-generated content before publishing it externally. The Customer must not attempt to circumvent the safety mechanisms of the underlying models, to extract system prompts, or to have the model produce content prohibited under Section 2. AI feature usage is metered in tokens per month; excessive consumption above the plan allowance may be billed as a top-up. AI features do not replace professional advice, and outputs may be inaccurate; the Customer accepts responsibility for verifying the correctness of any output before acting upon it.

10. Competitive intelligence limits

The Rate Shopper module returns competitive rate information based on publicly available sources and licensed feeds. The Customer must not use that data to coordinate pricing with competitors in a way that would violate Article 6 of the Polish Ustawa z dnia 16 lutego 2007 r. o ochronie konkurencji i konsumentów or Article 101 of the Treaty on the Functioning of the European Union. Competitive intelligence exports are subject to fair use quotas and must not be redistributed to third parties. Where the Customer discovers that a rate reported by the Rate Shopper corresponds to a promotional error by a competitor, the Customer is expected to act with the diligence that a professional operator would show in the same circumstances.

11. Third-party trademarks

The Service references third-party trademarks — including Profitroom, WhatsApp, Meta, and the trademarks of Customers' partner brands — solely to identify the systems with which it interoperates. The Customer must not use those trademarks in a way that would suggest an endorsement by, or affiliation with, the trademark owner beyond the true integration relationship. Any use of the trademarks of Customer partners in communications generated through the Service must comply with the Customer's own separate agreements with those partners.

12. Security research and responsible disclosure

Suite Profit welcomes security research conducted in good faith. Researchers who identify a vulnerability should report it to security@suiteprofit.org and abide by the following rules: do not exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability; do not disrupt or degrade the Service; do not disclose the vulnerability publicly until Suite Profit has confirmed a fix or forty-five (45) days have elapsed since the initial report, whichever is earlier. Suite Profit undertakes not to pursue legal action against researchers who comply with these rules. This paragraph does not authorise unsolicited penetration testing without prior written scope agreement.

13. Enforcement

Suite Profit may enforce this AUP through a graduated response:

  1. Warning — a written notice describing the alleged breach and inviting the Customer to remedy it within a specified period.
  2. Suspension — temporary restriction or suspension of the affected feature or of the entire account where the breach is severe, is ongoing, or presents an immediate risk to Suite Profit, its Customers, or third parties.
  3. Termination — termination of the subscription for cause under the Terms of Service, without refund of fees already accrued.

The choice of remedy is proportionate to the severity, duration, and impact of the breach, and to the Customer's cooperation in remediating it. Suite Profit reserves the right to notify affected third parties (including Profitroom and Meta) where required by law or by the applicable third-party platform terms.

14. Appeal process

A Customer who considers that a warning, suspension, or termination has been imposed in error may appeal by writing to appeals@suiteprofit.org within fourteen (14) days of the decision. The appeal must set out the grounds and any evidence. An officer of Suite Profit who was not involved in the original decision will review the appeal and communicate a reasoned decision within thirty (30) days. The appeal process does not deprive the Customer of any right under Polish law to seek redress before a competent court.

15. Changes

This AUP may be amended from time to time to reflect changes in law, updates in the acceptable-use standards of upstream platforms, or the introduction of new modules. Material amendments will be notified to Customer administrators by email at least thirty (30) days before the effective date. Continued use of the Service after the effective date constitutes acceptance of the amendment. Non-material amendments (typographical corrections, clarifications) may take effect immediately upon publication. Any question about this AUP may be addressed to abuse@suiteprofit.org or to Suite Profit Sp. z o.o., ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska.