How Suite Profit secures a hotel group's Profitroom data
Suite Profit is a European B2B enterprise vendor handling operational and reservation data for hotel groups on Profitroom Suite. This page documents the technical and organisational controls that go into a group procurement pack. It sits alongside the signed Data Processing Addendum and the sub-processor list your CISO's team can request from procurement.
Hosting and data residency
All production workloads run inside the European Union — primary region eu-central-1 (Frankfurt), warm secondary in a Warsaw AWS Local Zone. Data never leaves the EEA. Amazon Web Services is our infrastructure sub-processor under a signed DPA with standard contractual clauses; we do not carry US replicas and we do not use US sub-processors for personal data.
Encryption
Data in transit is protected with TLS 1.3, HSTS enforced, and a minimum cipher list refreshed quarterly against the Mozilla Modern profile. Data at rest is encrypted with AES-256 using AWS KMS-managed customer master keys, one CMK per portfolio. Backups are encrypted under a separate key. Snapshots retained for 30 days on primary and 90 days on cold storage.
Key rotation
Portfolio-scoped keys rotate on a 90-day cadence; audit-log signing keys rotate on a 30-day cadence. Rotation is automated through AWS KMS and evidence is retained inside the ISMS for the ISO 27001 audit trail.
Profitroom API credentials
Your Profitroom credentials for each property are stored encrypted with a dedicated envelope key, unique per property inside your portfolio. The plaintext is materialised only in memory at the moment of an API call, never logged, never written to disk. Revocation and re-key are first-class actions in the dashboard and in the API.
Certifications and posture
- GDPR compliant (EU 2016/679) under a named DPO
- Polish DPA 2018 aligned
- ISO 27001 external audit engaged (target 2026-Q4)
- SOC 2 Type II in progress (target report H2 2027)
- Quarterly external penetration test (rotating with two vendors)
- Public vulnerability disclosure policy with acknowledged researchers
- Secure SDLC with mandatory code review and threat modelling per module
Enterprise identity and access
- Named-user access only. Shared or service-account credentials are prohibited by policy for both employees and customers.
- Corporate SSO Hub — SAML 2.0 assertions and SCIM 2.0 provisioning across Okta, Microsoft Entra ID / Azure AD, Google Workspace and JumpCloud.
- Portfolio-scoped role bindings: Group Admin, Property Admin, District Manager, Property Manager, Reader, Auditor.
- Employee access to production is limited, audited, requires a hardware security key, and expires per session.
- All production changes pass code review with two independent approvers and pass automated policy checks before deploy.
Data retention
Live operational data (bookings, guest profiles, invoicing) is retained for the duration of the contract plus a 30-day grace period. After the grace period all customer data is deleted from primary systems within 14 days and from backups within 90 days. Group-level analytics aggregates retain no personally identifying information beyond 12 months.
Business continuity
Recovery point objective is 4 hours; recovery time objective is 8 hours. Backup and restore drills are executed quarterly with sign-off filed inside the ISMS. Runbooks are versioned and rehearsed by the SRE function.
Incident response
Suite Profit commits to notifying affected group customers within 24 hours of confirming a personal-data breach that meets the GDPR notification threshold, and to filing with the UODO within 72 hours as required by Article 33 GDPR. Non-personal incidents (feature outage) are communicated on our status page and directly to affected portfolios within 4 hours. The incident response playbook is available to customers under signed NDA on request.
Data Protection Officer
Our named Data Protection Officer is Aleksandra Kwiatkowska (COO), reachable at dpo@suiteprofit.org. GDPR data-subject requests are triaged inside two business days.
Reporting a vulnerability
Send details to abuse@suiteprofit.org encrypted with our PGP key (available on the same page). We acknowledge in one business day and target a triage response within 5 days. We do not sue researchers acting in good faith under this policy.