1. Purpose of this Policy
This Acceptable Use Policy (the "AUP") is issued by Suite Profit Sp. z o.o. to describe the boundaries within which Customer organisations, their Authorised Users, and any integrator acting on their behalf may use the Service. The AUP forms an integral part of the Master Subscription Agreement available at /legal/terms and applies to every Module supplied by Suite Profit, whether under a Group tier subscription, an Enterprise tier subscription, or a Pilot Programme. Its objective is to preserve the integrity of the Service for the benefit of every Customer, to safeguard hotel guests whose data flows through the Modules, and to protect the reputation of the wider Profitroom Suite ecosystem with which the Service interoperates.
2. Prohibited content
The Customer must not upload to the Service, generate through it, or transmit through it any content that: (a) is unlawful under Polish or European Union law, including content that infringes intellectual property rights, violates competition law, or breaches the rules on unfair commercial practices; (b) is defamatory, discriminatory, obscene, or otherwise designed to harass or intimidate any person; (c) contains malicious code, whether in the form of viruses, worms, ransomware, or any other executable payload intended to compromise the confidentiality, integrity, or availability of an information system; (d) misrepresents the identity of the sender, the origin of a communication, or the identity of a legal person; or (e) infringes the rights of hotel guests in any manner, including by exposing their reservation details to a third party without a lawful basis.
3. Prohibited activities
The Customer must not, and must not permit any Authorised User or integrator to: (a) attempt to gain unauthorised access to the Service, to another Customer's tenant, or to any underlying infrastructure; (b) share user credentials between individuals, since every Authorised User must correspond to a single natural person accountable for the actions performed under those credentials; (c) scrape, crawl, or otherwise systematically extract data from the operator console outside the officially documented programming interfaces and beyond the volume that is reasonable for legitimate business use; (d) reverse-engineer the Service or attempt to derive its source code, save to the extent that such activity cannot be prohibited under Applicable Law; (e) engage in load abuse by submitting requests at a rate designed to degrade the Service for other Customers, or by intentionally holding open a large number of long-lived connections; (f) resell, sublicense, or otherwise commercially distribute access to the Service without the prior written consent of Suite Profit; or (g) use the Service to build a competing product that replicates its material features.
4. Security responsibilities
The Customer is responsible for the confidentiality of the credentials issued to it and to its Authorised Users. Passwords must not be shared with colleagues, dictated over the telephone, transmitted through unencrypted channels, or written down in a location accessible to unauthorised persons. Multi-factor authentication must be enabled for every Authorised User and must not be defeated by shared tokens, sticky notes, or one-time-code forwarding. Where the Customer believes that a credential has been compromised, the Customer must revoke it immediately from the operator console and notify Suite Profit at support@suiteprofit.org within twenty-four (24) hours of discovery, so that Suite Profit may take proactive steps to protect the Customer's tenant.
5. API usage
The programming interfaces of the Service are subject to documented rate limits published in the developer portal. The Customer must respect those limits, must implement exponential back-off in the case of transient errors, and must not attempt to circumvent the limits through techniques such as rotating identities, distributed request pools operated by third parties, or headless browsers that impersonate an Authorised User. Suite Profit may temporarily reduce a rate limit for a specific Customer where the Customer's usage pattern threatens the availability of the Service for the wider tenant base. Where higher volumes are needed on a sustained basis, the Customer is invited to open a commercial discussion at sales@suiteprofit.org so that a dedicated capacity envelope may be provisioned as part of the applicable Order Form.
6. Rate governance
The Autopricer and the Group Sync engine assist the Customer in orchestrating rates across a portfolio of Properties. The Customer must not use the Service to publish rates below a net-average-daily-rate floor that has not been explicitly authorised by the party entitled to set it — whether a franchisor, a management company, or the property owner. Systematic dumping of rates below such a floor may distort competition on the wider hospitality market and may trigger contractual, regulatory, or reputational consequences that fall outside the scope of the Service. Suite Profit may suspend the publication of rate changes that materially deviate from the parameters that the Customer has configured, and will contact the Customer's revenue-management lead before resuming automated publication.
7. Guest communications
The Guest Messenger Module allows the Customer to communicate with hotel guests through the WhatsApp Business Cloud API and SMS fall-back. The Customer must not use the Module to send unsolicited marketing content to any guest who has not provided a valid marketing consent under the ustawa o świadczeniu usług drogą elektroniczną, the ustawa Prawo telekomunikacyjne, and the GDPR. Templates used for transactional communications must comply with the WhatsApp Business API rules on template approval and must not attempt to bypass such approval by disguising promotional content as service updates. The Customer is responsible for the accuracy of the guest data on which communications are based and for honouring guest opt-out requests within the statutory delays.
8. Fair use of the platform
Even where a Module is not subject to an explicit rate limit, the Customer must use the Service in a manner consistent with the reasonable expectations of an enterprise-grade hospitality platform. Fair use excludes, for example, importing hundreds of thousands of historical reservations solely for the purpose of stress-testing the reporting queries, executing multi-year exports on a hot database instead of the dedicated export path, or repeatedly cancelling and re-creating templates in the Guest Messenger merely to explore the behaviour of the queue. Suite Profit will contact the Customer's operational lead before applying any remedial action.
9. Compliance with Applicable Law
The Customer warrants that its use of the Service will comply at all times with every Applicable Law, including: the Polish Civil Code (Kodeks cywilny); the Polish Labour Code (Kodeks pracy) where the Service is used to reflect internal staffing rosters or to route operational events to a specific team; the ustawa z dnia 30 maja 2014 r. o prawach konsumenta where the Customer conducts direct-to-consumer transactions; the ustawa o zwalczaniu nieuczciwej konkurencji; the ustawa Prawo telekomunikacyjne; the ustawa o świadczeniu usług drogą elektroniczną; the ustawa o podatku od towarów i usług (including the ustawa o krajowym systemie e-Faktur where applicable); and the GDPR together with the Polish DPA 2018. Where the Service is used to reflect operations conducted in another Member State, the Customer must additionally comply with the local implementations of the ePrivacy Directive and the local consumer-protection rules.
10. Anti-money laundering
The Customer undertakes to comply with the ustawa z dnia 1 marca 2018 r. o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu (the Polish AML Act) and with the applicable European Union AML directives and regulations. The Customer must not use the Service, and in particular the Payment Console, to structure payments in a manner designed to evade AML reporting obligations, to disguise the origin or beneficial ownership of funds, or to launder proceeds of illegal activity. Suite Profit cooperates with acquiring banks and payment processors in relation to AML controls and may pause the settlement of transactions that trigger a plausible AML alert while the Customer clarifies the underlying flow.
11. Sanctions compliance
The Customer undertakes to comply with the sanctions regimes administered by the European Union, the United Nations, the United States Office of Foreign Assets Control, the United Kingdom Office of Financial Sanctions Implementation, and any other body whose measures are directly binding on it. The Customer must not use the Service to receive payments from, or send communications to, a person or entity subject to comprehensive sanctions to the extent that such interaction would infringe those sanctions. Where a Customer is itself listed on a sanctions list, Suite Profit is required to suspend the Service without notice and to cooperate with the competent authorities.
12. Reporting violations
Any person may report a suspected violation of this AUP by email to abuse@suiteprofit.org. Reports should describe the facts as precisely as possible, identify the Customer tenant concerned where known, and attach supporting evidence such as screenshots, headers of received messages, or reference numbers. Reports are treated confidentially. Suite Profit investigates every report and may contact the reporter for additional information. Reports that appear vexatious or unfounded are documented and closed.
13. Enforcement
Where Suite Profit reasonably concludes that this AUP has been breached, it may apply one or more of the following remedies, in escalating order of severity: (a) a warning notice sent to the Customer's administrator with a request to remediate the breach within a defined period; (b) suspension of the specific functionality that has been misused, without prejudice to the remainder of the Service; (c) suspension of the affected Authorised User; (d) full suspension of the tenant for a duration proportionate to the severity of the breach; and (e) termination of the affected Order Form for cause in accordance with the Master Subscription Agreement. Where the breach represents an imminent risk to other Customers, to hotel guests, or to the security of the platform, Suite Profit may apply the appropriate remedy without prior notice, subject to a post-hoc communication to the Customer's administrator.
14. Cooperation with authorities
Suite Profit reserves the right to cooperate with competent Polish and European Union public authorities in the investigation of suspected breaches of Applicable Law that come to its attention through the operation of the Service. Where legally permissible, Suite Profit will inform the Customer of the request received and give the Customer a reasonable opportunity to seek judicial protection before information is disclosed. Where confidentiality is imposed by the requesting authority under a valid legal instrument, Suite Profit will comply with that confidentiality until it lapses.
15. Effect of suspension and termination
Suspension of the Service under this AUP does not release the Customer from its obligation to pay fees due for the period preceding the suspension and does not extend the Subscription Term. Where the Customer remediates the breach that triggered the suspension, service is restored within one (1) Business Day. Where the breach cannot be remediated within a reasonable period, Suite Profit may terminate the affected Order Form for cause, in which case the treatment of prepaid fees is governed by the Cancellation, Credit and SLA Policy at /legal/refund.
16. Interaction with data protection obligations
Nothing in this AUP diminishes the Customer's status as controller of guest data or reduces its own data-protection obligations. In particular, the Customer remains solely responsible for the lawful basis on which guest contact data is captured and transmitted to Suite Profit, for the exercise of data subject rights by guests, and for the reflection of guest opt-out preferences in the templates configured in the Guest Messenger. Suite Profit's role as processor for that data is governed by the Data Processing Addendum at /legal/dpa.
17. Changes to this Policy
Suite Profit may amend this AUP from time to time to reflect changes in Applicable Law, guidance from competent regulators, evolutions of the Modules, or lessons learned from incident handling. Material amendments are notified to Customer administrators by email at least thirty (30) days before their effective date and are also announced on the suiteprofit.org changelog. Non-material amendments (clarifications, typographical corrections, cross-reference updates) may be published without prior notice. The version and effective date at the top of this Policy identify the current text.
18. Contact
Questions about this AUP may be addressed to support@suiteprofit.org. Reports of suspected abuse should be sent to abuse@suiteprofit.org. Data-protection questions may be addressed to the Data Protection Officer, Aleksandra Kwiatkowska, at dpo@suiteprofit.org. Suite Profit Sp. z o.o. is registered under KRS 0001102845, NIP 523-456-78-90, REGON 528 145 906, with fully paid-up share capital of PLN 10 000, seated at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska, and supervised for data protection by the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.