1. Parties
This Data Processing Addendum (the "DPA") supplements the Master Subscription Agreement concluded between Suite Profit Sp. z o.o., a Polish limited liability company established at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska, entered in the register of entrepreneurs under KRS 0001102845, NIP 523-456-78-90, REGON 528 145 906 (the "Processor" or "Suite Profit"), and the Customer identified on the applicable Order Form (the "Controller"). Together the Controller and the Processor are the "Parties" to this DPA.
This DPA is incorporated by reference into every Order Form under the Master Subscription Agreement. Where a term in this DPA conflicts with a term in the Master Subscription Agreement or an Order Form, the term in this DPA prevails for the subject matter it addresses. Where a term in an executed Standard Contractual Clauses annex conflicts with a term in this DPA, the term in the Standard Contractual Clauses prevails.
2. Definitions
Capitalised terms not otherwise defined here have the meaning given to them in the Master Subscription Agreement, in Regulation (EU) 2016/679 (the "GDPR"), or in the Polish ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych. "Personal Data" bears the meaning given in Article 4(1) GDPR. "Processing" bears the meaning given in Article 4(2) GDPR. "Sub-processor" means a third party retained by the Processor to perform any part of the Processing on behalf of the Controller. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by Commission Implementing Decision 2021/914 of 4 June 2021, Modules 2 and 3 as applicable.
3. Subject matter and duration
The subject matter of the Processing performed under this DPA is the operation of the Modules ordered by the Controller under the Master Subscription Agreement — including the Autopricer, the Group Sync engine, the Guest Messenger, the Payment Console, and the Reporting Studio — in order to provide the Service to the Controller and its Authorised Users. The duration of the Processing corresponds to the Subscription Term stated on each Order Form, extended by the return-or-deletion period set out in section 19.
4. Nature and purpose of the Processing
The Processor Processes Personal Data on behalf of the Controller solely for the purpose of providing the Service and of complying with legal obligations to which the Processor is subject as a Polish limited liability company established inside the European Union. The nature of the Processing includes collection through the officially documented Profitroom Suite application programming interfaces, structured storage inside the Processor's cloud environment, computation of rate suggestions and communication templates, transmission to the Controller's Authorised Users through the operator console, and, where the Controller has instructed, transmission of guest communications through third-party messaging providers.
5. Categories of data subjects
The Processing concerns the following categories of data subjects: (a) hotel guests whose reservation records are held in the Controller's Profitroom Suite tenant and are synchronised into the Modules; (b) Authorised Users of the Controller who sign in to the operator console; (c) staff members of the Controller who feature in operational events processed inside the Modules (for example, the identity of the operator who applied a specific rate override).
6. Categories of Personal Data
The Processing concerns the following categories of Personal Data: (a) reservation identifiers, arrival and departure dates, room and rate codes, and stay values; (b) guest names, email addresses, and mobile telephone numbers where the Controller has captured them and where the Controller has a lawful basis to share them with the Processor; (c) message payloads exchanged with guests through the Guest Messenger; (d) the identity data, professional data, and technical usage data of Authorised Users, as described in the Privacy Notice; (e) operational metadata such as timestamps and outcome codes attached to each event Processed by the Modules.
7. Special categories of data
The Modules are not designed to Process special categories of Personal Data within the meaning of Article 9 GDPR. The Controller undertakes not to instruct the Processor to Process such categories through the Service and, where such data is nonetheless found to have been transmitted through free-text guest communications, to take reasonable steps to prevent recurrence. The Processor will treat any special category data that it becomes aware of with heightened confidentiality and will initiate the incident-management process described in section 13.
8. Controller instructions
The Processor Processes Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data outside the European Union, except where an obligation under Applicable Law otherwise requires. The Master Subscription Agreement, each Order Form, the technical documentation of the Modules, and the configuration options that the Controller sets inside the operator console together constitute the standing documented instructions of the Controller. Any instruction that requires the Processor to act beyond that scope must be issued in writing and signed by an authorised representative of the Controller. The Processor promptly notifies the Controller if, in its opinion, an instruction infringes the GDPR or another data protection provision of European Union or Polish law.
9. Confidentiality of personnel
The Processor ensures that persons authorised to Process Personal Data on its behalf have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Confidentiality obligations survive termination of the individual's engagement with the Processor. Training in data protection, information security, and incident response is provided to every new hire at onboarding and refreshed annually thereafter.
10. Security measures
The Processor implements the technical and organisational measures set out in Annex II below to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Annex II is treated as an integral part of this DPA and is updated as measures evolve; the Controller is notified of any material change at least thirty (30) days before it takes effect.
11. Sub-processors
The Controller grants the Processor a general authorisation to engage Sub-processors, subject to the notification and objection mechanism described below and to the conditions of Article 28(2) and 28(4) GDPR. The current list of Sub-processors is set out in Annex III. Before appointing a new Sub-processor or replacing an existing Sub-processor, the Processor will notify the Controller by email at least thirty (30) days in advance. Within that period the Controller may object on reasonable data-protection grounds. Where a reasonable objection cannot be resolved, the Controller may terminate the affected Order Form with a pro-rated credit for unused prepaid fees.
Each Sub-processor is bound by a written contract imposing on it data-protection obligations no less stringent than those imposed on the Processor by this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations.
12. Assistance with data subject rights
Taking into account the nature of the Processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Controller's obligation to respond to requests for exercising data subjects' rights under Chapter III of the GDPR. Where a data subject contacts the Processor directly in relation to Personal Data Processed on the Controller's behalf, the Processor promptly forwards the request to the Controller and does not itself respond on the merits unless the Controller has issued a written instruction to do so.
13. Personal data breach notification
The Processor notifies the Controller without undue delay and in any event within seventy-two (72) hours after becoming aware of a Personal Data breach affecting the Controller's Personal Data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where full information is not immediately available, an initial notification is provided within the seventy-two (72) hours and completed by successive updates as investigation progresses.
14. DPIA and prior consultation assistance
The Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR, in particular the obligation to conduct a data protection impact assessment where required and to seek the prior consultation of the supervisory authority in the cases identified by Article 36 GDPR. Assistance is provided by making available the security documentation of Annex II, the Sub-processor list of Annex III, and a written response to reasonable questions from the Controller's Data Protection Officer.
15. International transfers
The default posture of the Processor is to keep Personal Data inside the European Economic Area and to select Sub-processors whose relevant operations are located in the European Union. Where the Processor is unable to avoid a transfer of Personal Data to a third country not covered by an adequacy decision of the European Commission, the Processor will execute the applicable modules of the Standard Contractual Clauses with the recipient and will implement the supplementary technical and organisational measures identified in its transfer impact assessment. Suite Profit does not rely on informal derogations such as one-off consents to justify systematic transfers.
16. Audit rights
The Processor makes available to the Controller all information necessary to evidence compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor's standard artefact of compliance is its annual SOC 2 Type II report, made available under a non-disclosure agreement. Where the Controller reasonably considers that additional assurance is necessary, the Controller may audit the Processor no more than once per calendar year, on at least sixty (60) days' prior written notice, during normal business hours, and subject to reasonable safety and confidentiality controls. The Controller bears the cost of the audit unless the audit reveals a material breach of this DPA, in which case the reasonable cost is borne by the Processor.
17. Records of Processing
The Processor maintains a record of Processing activities carried out on behalf of the Controller in accordance with Article 30(2) GDPR and makes that record available to the Controller and to the competent supervisory authority upon reasonable request. The record covers the categories of Processing, transfers to third countries, and a general description of the technical and organisational measures.
18. Liability
The liability of each Party under this DPA is subject to the limitations set out in the Master Subscription Agreement, without prejudice to any provision of Applicable Law that requires a broader remedy for data subjects. Where more than one Party is found jointly liable in relation to a data subject under Article 82 GDPR, the Parties will apportion the liability between them in proportion to their respective responsibility for the damage caused.
19. Return or deletion of Personal Data
On termination of the Master Subscription Agreement or of the last Order Form in force between the Parties, the Processor returns to the Controller, or at the Controller's option deletes, all Personal Data Processed on the Controller's behalf. The return-or-deletion period is thirty (30) days from termination, extendable to sixty (60) days at the Controller's written request to allow a coordinated transition. Backups containing Personal Data are irreversibly destroyed on the ordinary ninety-day (90-day) rotation cycle.
20. Governing law
This DPA is governed by the laws of the Republic of Poland. Any dispute is submitted to the exclusive jurisdiction of the Sąd Okręgowy w Warszawie (Regional Court in Warsaw), subject to any mandatory competence rule under the GDPR that grants a data subject a right of action before another court.
Annex I — Subject matter and details of the Processing
Annex I to this DPA identifies the subject matter, the duration, the nature and purpose of the Processing, the categories of Personal Data, and the categories of data subjects. In accordance with sections 3 to 6 above, the entries of Annex I are the following: subject matter — operation of the Modules ordered by the Controller; duration — the Subscription Term extended by the return-or-deletion period; nature and purpose — provision of the Service and compliance with the Processor's own legal obligations; categories of data subjects — hotel guests, Authorised Users, staff members of the Controller; categories of Personal Data — reservation and stay data, guest contact data, guest communications, Authorised User identity and usage data, operational metadata. No special category data is intended to be Processed.
Annex II — Technical and organisational security measures
The Processor implements the following measures. Pseudonymisation and encryption: TLS 1.2 or higher with modern cipher suites in transit; AES-256 at rest; tenant-level segregation of Customer data. Confidentiality, integrity, availability and resilience: least-privilege access managed through single sign-on with mandatory multi-factor authentication for staff; role-based access control; immutable audit logs; network isolation via private VPC subnets. Restoration of availability: multi-availability-zone deployment in AWS Frankfurt (region eu-central-1) with automated fail-over; backup rotation every twenty-four (24) hours with a ninety-day (90-day) retention window; documented recovery time objective of four (4) hours and recovery point objective of one (1) hour. Testing, assessing and evaluating: annual penetration testing by an accredited third party; quarterly access reviews; annual SOC 2 Type II attestation; internal red-team exercise no less than once a year. Incident response: documented playbooks; twenty-four seven (24/7) on-call rotation; forensic retention on secure, tamper-evident storage. Personnel: pre-employment background screening in accordance with Polish labour law; contractual confidentiality obligations that survive termination; annual training in security and data protection with completion evidence retained by the human-resources function.
Annex III — Sub-processors
The following Sub-processors are engaged by the Processor at the effective date of this DPA:
- Amazon Web Services EMEA SARL — cloud infrastructure hosting (primary region eu-central-1 in Frankfurt, secondary region eu-central-2 in Warsaw). Purpose: virtual machines, storage, databases, load balancing, network isolation.
- Stripe Payments Europe Limited — Dublin, Ireland. Purpose: reconciliation and Strong Customer Authentication for card payments captured through the Payment Console.
- PayU S.A. — Poznań, Polska. Purpose: reconciliation of card and PLN account-to-account payments for Polish domestic Properties.
- Twilio SendGrid Ireland Limited — Dublin, Ireland. Purpose: transactional email delivery for operator notifications and receipts.
- Twilio Ireland Limited — Dublin, Ireland. Purpose: SMS fall-back for guest communications where the primary WhatsApp Business Cloud API path is unavailable.
The Processor may add or replace Sub-processors in accordance with section 11. The current list is also available at /security/subprocessors and is updated in real time. Notification of changes is made by email to the administrator contact designated by the Controller on the applicable Order Form.
Contact
Questions about this DPA may be addressed to the Data Protection Officer of Suite Profit, Aleksandra Kwiatkowska, at dpo@suiteprofit.org, or by post to Suite Profit Sp. z o.o., Inspektor Ochrony Danych, ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska. Suite Profit Sp. z o.o. is registered under KRS 0001102845, NIP 523-456-78-90, REGON 528 145 906, with fully paid-up share capital of PLN 10 000, and is supervised for data-protection purposes by the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.