1. Who is the controller
The controller of personal data described in this Privacy Notice, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), is Suite Profit Sp. z o.o., a Polish limited liability company established at ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska. The company is entered in the register of entrepreneurs kept by Sąd Rejonowy dla m.st. Warszawy, XII Wydział Gospodarczy Krajowego Rejestru Sądowego under KRS number 0001102845. Its tax identification number is NIP 523-456-78-90, its statistical identification is REGON 528 145 906, and its share capital of PLN 10 000 has been fully paid.
This Privacy Notice describes how Suite Profit processes personal data as controller — for example, when a prospective Customer contacts the sales team, when an Authorised User signs in to the operator console, or when the accounts team invoices a Customer. When Suite Profit processes personal data on behalf of a Customer (for instance, guest data flowing from the Customer's Profitroom Suite tenant into the Guest Messenger), Suite Profit acts as processor under Article 28 GDPR and the applicable terms are set out in the Data Processing Addendum at /legal/dpa.
2. Data Protection Officer
Suite Profit has appointed a Data Protection Officer (Inspektor Ochrony Danych, "DPO") in accordance with Article 37 GDPR and Article 8 of the ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych. The DPO is Aleksandra Kwiatkowska. She may be reached in writing at the postal address above (envelope marked "IOD") or by electronic mail at dpo@suiteprofit.org. The DPO is bound to secrecy under Article 38(5) GDPR and coordinates all data subject requests, breach management, and cooperation with the Polish supervisory authority.
3. Legal framework
Suite Profit processes personal data in compliance with the GDPR, the Polish Data Protection Act 2018 (ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych), the ustawa z dnia 18 lipca 2002 r. o świadczeniu usług drogą elektroniczną on the provision of services by electronic means, and the sector-specific statutes that regulate individual processing activities. For invoice retention we rely on the ustawa z dnia 29 września 1994 r. o rachunkowości and the ustawa z dnia 11 marca 2004 r. o podatku od towarów i usług. For statutory sanctions screening we rely on the ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu and the applicable EU sanctions regulations.
4. Categories of data subjects
The data subjects concerned by this Privacy Notice belong principally to the following categories: (a) prospective and existing Customer contacts (revenue managers, procurement leads, IT directors, finance controllers, and executive sponsors); (b) Authorised Users who sign in to the operator console under Customer instructions; (c) hotel guests whose reservation and communication data flows through the Modules where Suite Profit is a processor for a Customer; (d) visitors to the suiteprofit.org public website; (e) candidates who apply for open positions with Suite Profit; and (f) contract counterparties such as sub-processors, advisers, and suppliers.
5. Categories of personal data
Suite Profit processes the following categories of personal data as controller:
- Identity data — first and last name, professional title, employer, and preferred language.
- Contact data — business email address, business telephone number, business postal address, and the identifiers of workplace collaboration tools (for example, a Microsoft Teams or Slack handle where the Customer opts in to a shared support channel).
- Professional data — role in the Customer's revenue-management, IT, or finance organisation, involvement in specific procurement processes, and the reasons stated for evaluating the Service.
- Technical data — Internet Protocol (IP) address at the moment of connection, browser fingerprint used to detect suspicious sessions, device type, operating system, and locale.
- Operator console usage data — timestamps of sign-ins, records of actions performed inside the operator console, error events, and support tickets opened by the user.
- Billing data — company name, tax identification number, invoicing address, bank account, and payment history.
- Marketing data — recorded consents, unsubscribe events, and preferences declared during webinars or industry events.
6. Purposes and legal bases
Suite Profit processes personal data on the following legal bases within the meaning of Article 6(1) GDPR:
- To perform a contract with the Customer or to take steps at the Customer's request prior to entering into a contract — Article 6(1)(b) GDPR. This covers the qualification of leads, the drafting of Order Forms, the provisioning of the Service, ongoing support, invoicing, and the operation of a productive supplier relationship.
- To comply with a legal obligation to which Suite Profit is subject — Article 6(1)(c) GDPR. Examples include the retention of invoices under the Accounting Act, sanction and beneficial-ownership checks, and disclosures to tax and law-enforcement authorities in response to a valid legal request.
- For the legitimate interests of Suite Profit or of a third party — Article 6(1)(f) GDPR. Legitimate interests include information security and fraud prevention, the enforcement of contractual and legal claims, the operation of a lawful supplier ecosystem, the assessment of aggregated product usage for quality and capacity planning, and direct communication with existing Customer contacts about closely related product improvements.
- On the basis of consent freely given, specific, informed, and unambiguous — Article 6(1)(a) GDPR. Consent is used for non-essential cookies, for marketing communications sent to prospects who are not existing Customers, and for the transmission of anonymised operator prompts to language-model providers when a Customer opts in to optional artificial-intelligence features.
7. Sources of personal data
Personal data is collected directly from the data subject in the ordinary course of the commercial relationship: for example, when a prospect completes a contact form on suiteprofit.org, when a Customer signs an Order Form, or when an Authorised User signs in to the operator console. In limited cases, personal data of Customer contacts is collected from public professional sources such as company registers, corporate websites, and business-oriented professional networks, in accordance with Article 14 GDPR and subject to the transparency requirements it imposes.
8. Recipients and processors
Suite Profit does not sell personal data. Personal data is disclosed to the following categories of recipient strictly to the extent required for the purposes above and under written agreements imposing appropriate confidentiality and security obligations:
- Cloud infrastructure — Amazon Web Services EMEA SARL for primary hosting in Frankfurt (region eu-central-1) and secondary hosting in Warsaw (region eu-central-2).
- Payment processors — Stripe Payments Europe Limited (Dublin, Ireland) and PayU S.A. (Poznań, Polska) for the reconciliation of card payments where offered.
- Identity providers — where the Customer connects the operator console to its own Okta or Microsoft Entra ID (Azure AD) tenant, authentication events are reflected against that tenant on the Customer's own infrastructure.
- Communications providers — Meta Platforms Ireland Limited for WhatsApp Business Cloud API, Twilio Ireland Limited for SMS fall-back, SendGrid Ireland Limited for transactional email.
- Professional advisers — external legal counsel, statutory auditors, and tax advisers who are subject to professional duties of confidentiality.
- Public authorities — the Polish Tax Administration (Krajowa Administracja Skarbowa), courts, the police, and other authorities where disclosure is legally compelled.
9. International transfers
The default posture for personal data processed by Suite Profit is to remain within the European Economic Area. Where a sub-processor forms part of a group with affiliates outside the EEA, transfers take place only when protected by an adequacy decision of the European Commission or by the Standard Contractual Clauses adopted by Commission Implementing Decision 2021/914 of 4 June 2021 (Modules 2 and 3 as applicable), completed by supplementary technical and organisational measures such as encryption in transit and at rest, tenant-level segregation, and the shortest retention consistent with the purpose. Suite Profit does not rely on informal derogations such as one-off consents to justify systematic transfers.
10. Retention periods
Personal data is retained for no longer than necessary to achieve the purpose for which it was collected. Retention periods currently applied are:
- Accounting records and invoices — five (5) years counted from the end of the calendar year in which the fiscal obligation arose, in accordance with Article 74(2) of the Accounting Act.
- Contracts, Order Forms, and amendments — six (6) years from the end of the year in which the contract expires, corresponding to the general limitation period for commercial claims under Article 118 of the Polish Civil Code.
- Prospect data — three (3) years from the last meaningful interaction, unless the data subject withdraws consent earlier.
- Marketing consent records — three (3) years after withdrawal or the last confirmation of active status, whichever is later.
- Operational logs — twelve (12) months for standard events; up to twenty-four (24) months for security-relevant events.
Once a retention period expires, personal data is deleted, aggregated into non-identifiable statistics, or archived in a segregated and access-controlled cold storage strictly for the fulfilment of a specific legal obligation.
11. Data subject rights
Under Articles 15 to 22 GDPR data subjects have the right to obtain confirmation as to whether Suite Profit processes personal data concerning them and, where that is the case, to access such data (Article 15); to obtain the rectification of inaccurate personal data (Article 16); to obtain the erasure of personal data ("right to be forgotten") where the conditions of Article 17 are met; to obtain the restriction of processing in the situations listed in Article 18; to receive personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller under Article 20; to object to processing based on legitimate interests at any time (Article 21); and, where processing is based on consent, to withdraw such consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)).
Requests are addressed to privacy@suiteprofit.org or by post to the DPO at the postal address above. Suite Profit responds within one (1) month of receipt, extendable by two (2) further months for complex or numerous requests. Where a request cannot be honoured, Suite Profit explains the reasons in writing and informs the data subject of the possibility to lodge a complaint with the supervisory authority.
12. Complaint to the supervisory authority
Data subjects have the right to lodge a complaint with the Polish supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych ("UODO"), if they consider that the processing of their personal data by Suite Profit infringes the GDPR or the Polish DPA 2018. The UODO may be contacted at ul. Stawki 2, 00-193 Warszawa, telephone +48 22 531 03 00, website uodo.gov.pl. The electronic filing channels published on the UODO website are available in Polish and, in part, in English.
13. Automated decision-making
Suite Profit does not take decisions concerning data subjects that produce legal effects or similarly significantly affect them and that are based solely on automated processing within the meaning of Article 22 GDPR. Certain optional Modules use machine-learning models to suggest price adjustments or to draft guest messages: in every case a human operator of the Customer reviews and confirms the suggestion before it is transmitted downstream, and the ranges within which auto-application is permitted are configured by that operator within pre-defined boundaries.
14. Security measures
Suite Profit implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Measures include: encryption in transit (TLS 1.2 or higher with modern cipher suites) and at rest (AES-256); tenant-level segregation of Customer data at the storage and application layers; least-privilege access with single sign-on and mandatory multi-factor authentication for staff; quarterly access reviews; centralised secret management using a hardware-security-module-backed key store; immutable audit logs; network isolation using private VPC subnets; automated dependency vulnerability scanning; and annual penetration testing by an accredited third party. Additional information is available at /security and in Annex II of the Data Processing Addendum.
15. Cookies and similar technologies
Details of the cookies and similar technologies used on the suiteprofit.org website, including their purpose, provider, and duration, are set out in the Cookie Notice at /legal/cookies. That Notice also implements Article 173 of the Polish ustawa Prawo telekomunikacyjne on terminal equipment access.
16. Marketing communications
Suite Profit sends commercial communications to prospects on the basis of freely given consent and to existing Customers on the basis of the "soft opt-in" for closely related product improvements permitted by the ustawa o świadczeniu usług drogą elektroniczną and the ustawa Prawo telekomunikacyjne. Every commercial email includes a clearly labelled unsubscribe mechanism operable in one click. Withdrawal of consent does not affect the lawfulness of processing before withdrawal and does not prevent Suite Profit from sending transactional messages required to perform the Service.
17. Recruitment
Personal data of candidates who apply for open positions is processed on the basis of Article 6(1)(b) GDPR (steps at the request of the data subject before entering into a contract) and, in respect of data going beyond what is required by the Polish Labour Code, on the basis of consent. Candidate data is kept for the duration of the recruitment process and, where the candidate consents, for a further twelve (12) months for consideration for future openings. Suite Profit does not sell candidate data and does not use it for marketing.
18. Website analytics
The suiteprofit.org website is measured using self-hosted analytics running on Suite Profit infrastructure inside the European Union. No third-party analytics service such as Google Analytics is used. The analytics dataset is aggregated on the fly, contains no persistent identifier tied to an individual visitor, and does not enable cross-site tracking.
19. Children
The Service is a business-to-business enterprise service for hotel groups. It is not directed at children and Suite Profit does not knowingly process the personal data of children under the age of sixteen (16) as controller. Where guest data flowing through the Modules relates to a minor, the Customer is the controller of that guest data and remains responsible for the lawfulness of the underlying processing.
20. Data breach management
Suite Profit maintains a documented incident-response plan that is exercised at least twice a year. Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, Suite Profit notifies the UODO without undue delay and, where feasible, no later than seventy-two (72) hours after having become aware of it, in accordance with Article 33 GDPR. Data subjects are notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR.
21. Changes to this Notice
Suite Profit may amend this Privacy Notice from time to time to reflect changes in Applicable Law, guidance from UODO or the European Data Protection Board, changes in processing activities, or changes to the list of recipients. Material amendments are notified to Customer administrators by email at least thirty (30) days before their effective date. The current version and its adoption date are always displayed at the top of this page, and past versions are available on request at privacy@suiteprofit.org.
22. Contact
For any question about this Privacy Notice or about the processing of personal data by Suite Profit, data subjects may write to privacy@suiteprofit.org, to the DPO at dpo@suiteprofit.org, or by post to Suite Profit Sp. z o.o., Inspektor Ochrony Danych, ul. Nowogrodzka 42 lok. 11, 00-695 Warszawa, Polska. General support is available at support@suiteprofit.org. Sales enquiries are handled at sales@suiteprofit.org. Suite Profit Sp. z o.o. is registered under KRS 0001102845, NIP 523-456-78-90, REGON 528 145 906, with fully paid-up share capital of PLN 10 000.