MP
Profitroommod
Client Area Client
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Client Area Contact
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Contact
Home / Data Processing Agreement

Data Processing Agreement (DPA)

Effective from: 3 August 2026. This Data Processing Agreement («DPA») is entered into pursuant to Article 28 of Regulation (EU) 2016/679 («GDPR») and the Montenegrin Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti). It forms an integral part of the Terms and Conditions and applies automatically to every Customer whose use of a Profitroommod Module involves the processing of personal data on the Customer’s behalf.

Independence and non-affiliation

Profitroommod is an independent third-party marketplace and is not affiliated with, sponsored by or endorsed by Profitroom S.A. or its parent company. Nothing in this DPA creates any obligation on Profitroom S.A. or brings Profitroom S.A. within the scope of this DPA.

1. Parties

The Controller («Controller») is the Customer hotel that has purchased one or more Modules on profitroommod.org and that determines the purposes and means of processing of personal data of its guests, prospects and staff.

The Processor («Processor» or «Profitroommod») is Profitroommod d.o.o., a limited liability company organised under the laws of Montenegro, PIB 04456739, registered under CRPS 4-0070284/1, with its registered seat at ul. Njegoševa 87, 81000 Podgorica, Crna Gora, represented by its Director Dragan Kovačević.

The Controller and the Processor are together referred to as the «Parties». By accepting the Terms and Conditions at Order and by activating any Module that processes personal data, the Controller enters into this DPA in accordance with Article 28(9) GDPR (agreement in electronic form).

2. Definitions

Capitalised terms not defined here have the meaning given to them in Article 4 GDPR. In particular:

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data.
  • Sub-processor: a third party engaged by the Processor to process personal data on behalf of the Controller.
  • Data subject: the individual to whom the personal data relate.
  • Supervisory authority: the competent public authority for personal data protection, in Montenegro Agencija za zaštitu ličnih podataka (AZLP), registration 05-030/26-1073.

3. Subject matter and duration

The subject matter of this DPA is the processing by Profitroommod, on behalf of the Controller, of personal data of the Controller’s guests, prospects and staff, strictly for the purpose of operating the Modules subscribed to on profitroommod.org. This DPA takes effect on the day the first Module involving personal data is activated and remains in force for the duration of any active Subscription, plus the retention periods listed in section 7(g).

4. Nature and purpose of the processing

Processing performed by Profitroommod on behalf of the Controller consists of reading, writing, synchronising, aggregating, archiving and deleting personal data through the official Profitroom API in order to (i) operate the subscribed Modules; (ii) store and use the Controller’s Profitroom API key to authenticate calls; (iii) synchronise reservations, guest records and rate plans; (iv) generate operational and analytical reports; (v) support the guest journey, including the digital registration card and pre-arrival communications; and (vi) provide technical support on request. Profitroommod does not process the personal data for its own purposes.

5. Types of personal data

Data categoryExamples
Guest identificationFirst name, last name, salutation, nationality, date of birth (where required by local police-registration law)
Guest contactEmail address, mobile telephone number, postal address of residence
ReservationBooking reference, arrival and departure dates, room number, rate plan, price, number of guests, special requests
Identification documentType, number and expiry date of the ID document uploaded to the digital registration card Module (where enabled and authorised by local law)
Hotel staffBusiness email, first and last name, role, sign-in log for the Client Area
CommunicationsContent of automated pre-arrival messages sent through the Module, delivery status

No special category of data within the meaning of Article 9 GDPR is processed unless the Controller has expressly enabled a specific Module that requires it (for example, dietary preferences in an F&B Module), in which case the Controller warrants that a valid Article 9(2) legal basis exists.

6. Categories of data subjects

  • Guests of the Controller’s hotel (past, current and confirmed future).
  • Prospects who have initiated a reservation but not completed it.
  • Staff members of the Controller with access to the Client Area.
  • Corporate contacts of the Controller (for group bookings and long-stay accounts).

7. Processor obligations under Article 28(3) GDPR

(a) Documented instructions

Profitroommod processes personal data only on documented instructions from the Controller. Acceptance of the Terms, Order of a Module and configuration in the Client Area jointly constitute the initial documented instructions. Additional instructions are given in writing by email. Where an instruction infringes GDPR or Montenegrin law, Profitroommod informs the Controller without undue delay.

(b) Confidentiality

Profitroommod ensures that every person authorised to process personal data has committed to confidentiality in writing or is under an appropriate statutory obligation of confidentiality. Access to production data is restricted to a named list of engineers, protected by multi-factor authentication.

(c) Security measures (Article 32 GDPR)

Profitroommod implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption in transit with TLS 1.3; older TLS versions refused.
  • Encryption at rest with AES-256 for personal data and for stored Profitroom API keys.
  • Passwordless authentication (magic link) for the Client Area; no password reuse risk.
  • Role-based access control with least-privilege by default.
  • Immutable access logs retained for twelve (12) months.
  • Weekly vulnerability scans and a defined patching SLA.
  • Documented incident-response plan tested at least annually.
  • Encrypted backups stored in a separate EU region, tested for recoverability.
  • Segregation of environments (production, staging, development) with no personal data in non-production environments.

(d) Sub-processors

The Controller grants the Processor general authorisation to engage sub-processors, subject to the notification and objection rights described below. The current list of sub-processors is:

Sub-processorRoleLocation
ZenthoryxPayment service provider (EUR-NX rail)European Union
European cloud hosting providerProduction hosting of application and databaseEuropean Union
Transactional email providerDelivery of magic-link, invoice and service emailsEuropean Union

Profitroommod notifies the Controller of any intended change to the list of sub-processors, giving details of the new sub-processor and its role, at least thirty (30) days before the change takes effect. The Controller has the right to object to the change on reasonable grounds within that period; if the objection cannot be resolved by the Parties, the Controller may terminate the affected Subscription without penalty. Profitroommod imposes on every sub-processor, by written contract, obligations that are at least as protective as those set out in this DPA.

(e) Assistance with data subject rights

Taking into account the nature of the processing, Profitroommod assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights under Articles 15 to 22 GDPR. Standard export and deletion features are available from the Client Area at no charge.

(f) Assistance with breach notification and DPIA

Profitroommod assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR. In the event of a personal data breach affecting personal data processed on the Controller’s behalf, Profitroommod escalates internally within 24 hours and notifies the Controller in writing without undue delay and in any event no later than 36 hours after becoming aware of the breach, so that the Controller can meet its own 72-hour deadline under Article 33 GDPR. The notification includes, so far as available at the time, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address the breach and mitigate its adverse effects.

(g) Deletion or return of data on termination

At the choice of the Controller, expressed in writing at the latest thirty (30) days after termination of the Subscription, Profitroommod either deletes or returns to the Controller all personal data processed on its behalf, and deletes any existing copies, unless retention is required by Montenegrin or EU law (in particular for invoices, retained for ten years under Montenegrin tax law). Deletion is performed within ninety (90) days of the termination and confirmed in writing on request. Profitroom API keys are irreversibly deleted within thirty (30) days of termination.

(h) Audit rights

Profitroommod makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits may be performed once per calendar year, on thirty (30) days’ written notice, at the Controller’s expense, during business hours and in a manner that does not disrupt Profitroommod’s operations or the confidentiality of other customers’ data. As an alternative to on-site audit, the Controller accepts the current independent audit report (ISO 27001, SOC 2 Type II or equivalent) issued to Profitroommod.

8. International transfers

All personal data processed under this DPA is stored and processed within the European Economic Area. Profitroommod performs no international transfer to a third country within the meaning of Chapter V GDPR. Should this ever change, Profitroommod will put in place, before any transfer, a lawful transfer mechanism (standard contractual clauses adopted by the European Commission, adequacy decision or binding corporate rules) and will notify the Controller in advance.

9. Liability

Each Party is liable for damage caused by processing in breach of GDPR to the extent provided by Article 82 GDPR. As between the Parties, Profitroommod’s aggregate liability under this DPA is subject to the liability cap stated in the Terms and Conditions, save for liability that cannot lawfully be limited, including for wilful misconduct or gross negligence.

10. Term and termination

This DPA is effective for the term of the underlying Subscription and any related retention period. Termination of the Subscription terminates the operational obligations of this DPA, save for those obligations that by their nature survive termination, including confidentiality, security of retained data, and cooperation with supervisory authorities.

11. Governing law and jurisdiction

This DPA is governed by the laws of Montenegro, in particular the Zakon o zaštiti podataka o ličnosti and, within its territorial scope, Regulation (EU) 2016/679. Any dispute arising out of or in connection with this DPA falls within the exclusive jurisdiction of the Osnovni sud u Podgorici (Basic Court of Podgorica), without prejudice to the mandatory competence of the supervisory authority in matters within its remit.

12. Signatures — acceptance by use of the service

In accordance with Article 28(9) GDPR, this DPA is validly concluded in electronic form. Acceptance is manifested by acceptance of the Terms and Conditions and by activation of any Module that processes personal data. A copy of this DPA in force on the date of activation is available at any time in the Client Area under «Legal documents». A signed PDF copy is issued on written request to dpo@profitroommod.org.

13. Contact

Profitroommod d.o.o.
ul. Njegoševa 87, 81000 Podgorica, Crna Gora
Director: Dragan Kovačević
Data Protection Officer: dpo@profitroommod.org
Telephone: +382 20 741 528
Email: privacy@profitroommod.org · support@profitroommod.org
PIB: 04456739 — CRPS: 4-0070284/1
IBAN: ME25 505 0000 0134 5678 90
Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica, registration 05-030/26-1073.

Effective from 3 August 2026. Next scheduled review: 3 February 2027.

Profitroommod

Modules, extensions and integrations for the Profitroom booking engine and channel manager

Independent marketplace of modules and extensions for the Profitroom booking engine and channel manager.

Shop

  • All extensions
  • Pricing
  • Compare
  • ROI calculator
  • Checkout

Resources

  • Features
  • Integrations
  • Blog
  • Guides
  • Academy
  • Changelog
  • API documentation

Company

  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Refund policy
Profitroommod d.o.o. — PIB: 04456739 — CRPS: 4-0070284/1 — ul. Njegoševa 87, 81000 Podgorica, Crna Gora — Director: Dragan Kovačević — support@profitroommod.org — Tel: +382 20 741 528 — IBAN ME25 505 0000 0134 5678 90.
Profitroommod is an independent third-party marketplace and is in no way affiliated with, sponsored by or endorsed by Profitroom S.A. or its parent company. All trademarks, product names and logos are the property of their respective owners. Supervisory authority for data protection: Agencija za zaštitu ličnih podataka (AZLP), registration no. 05-030/26-1073. Jurisdiction: Osnovni sud u Podgorici. Applicable legal framework: Zakon o zaštiti podataka o ličnosti + GDPR + Zakon o elektronskoj trgovini + Zakon o zaštiti potrošača.
© 2024–2026 Profitroommod d.o.o. All rights reserved.
Terms Privacy Cookies DPA Refunds

Your cart

Total €0.00
Checkout →

We use cookies to improve your experience and analyse site performance. Learn more