How we secure your Profitroom data and ours
Suite Profit is a European B2B software business handling operational data from hotels using Profitroom. This page documents the technical and organisational controls we apply. It complements the Data Processing Addendum available in the legal section.
Hosting and data residency
All production workloads run in the European Union — primary region eu-central-1 (Frankfurt), warm standby in eu-west-3 (Paris). We use a single provider (Amazon Web Services) with a signed Data Processing Addendum, and we do not transfer personal data outside the EEA except where the customer explicitly asks for a cross-border integration.
Encryption
Data in transit is protected with TLS 1.3, HSTS enforced, and a minimum cipher list refreshed quarterly against the Mozilla Modern profile. Data at rest is encrypted with AES-256 using AWS KMS-managed keys. Backups are encrypted with a separate key. Full database snapshots are retained for 30 days.
Profitroom API key handling
Your Profitroom API key is stored encrypted with a dedicated envelope key, unique per customer. The plaintext key is materialised only in memory at the moment of an API call, never logged, never written to disk. Rotation is a first-class action in the dashboard — you can revoke and re-key at any time.
Certifications and posture
- GDPR compliant (EU 2016/679)
- Polish DPA 2018 aligned
- ISO 27001 audit in progress (target 2026-Q4)
- SOC 2 Type I roadmap 2027-Q1
- Yearly penetration test by NCC Group
- Vulnerability disclosure policy public
Access controls
- Named-user access only. Shared credentials are prohibited by policy for both employees and customers.
- SSO for the Suite Profit dashboard on Pro and Group plans (SAML 2.0).
- Role-based permissions inside the dashboard (Owner, Manager, Viewer).
- Employee access to production is limited, audited, and requires hardware security key.
- All production changes go through code review with at least one independent approver.
Data retention
Live operational data (bookings, guest profiles) is retained for the duration of the subscription plus a 30-day grace period. After the grace period all customer data is deleted from primary systems within 14 days and from backups within 90 days. Analytics aggregates retain no personally identifying information beyond one year.
Incident response
We commit to notifying affected customers within 24 hours of confirming a personal-data breach that meets the GDPR notification threshold, and to filing with the UODO within 72 hours as required by Article 33 GDPR. Non-personal incidents (feature outage) are communicated on our status page and directly to affected customers within 4 hours.
Reporting a vulnerability
Send details to abuse@suiteprofit.org encrypted with our PGP key (available on the same page). We acknowledge in one business day and target a triage response within 5 days. We do not sue researchers acting in good faith under this policy.