Privacy Policy
Effective from: 3 August 2026. This Privacy Policy explains how Profitroommod d.o.o. handles personal data in connection with the operation of the marketplace at profitroommod.org and the Modules distributed through it. It is drafted to comply with Regulation (EU) 2016/679 («GDPR») and the Montenegrin Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti).
Independence and non-affiliation
Profitroommod is an independent third-party marketplace and is not affiliated with, sponsored by or endorsed by Profitroom S.A. or its parent company. References to Profitroom in this policy describe technical interoperation only.
1. Controller identity
The controller of the personal data collected on profitroommod.org, within the meaning of Article 4(7) GDPR, is Profitroommod d.o.o., a limited liability company organised under the laws of Montenegro, PIB 04456739, registered under CRPS 4-0070284/1, with its registered seat at ul. Njegoševa 87, 81000 Podgorica, Crna Gora, represented by its Director Dragan Kovačević. When Profitroommod processes reservation, guest or operational data on behalf of a Customer hotel through a Module, it acts as a processor within the meaning of Article 4(8) GDPR under the terms of the Data Processing Agreement.
You may contact the controller at any time: email support@profitroommod.org, telephone +382 20 741 528, IBAN ME25 505 0000 0134 5678 90.
2. Data we collect
We collect only the personal data strictly necessary for one of the purposes listed in section 3, or to which you have expressly consented. The categories are:
- Account and contact data: business email address, first and last name of the authorised representative, hotel legal name, postal address, telephone (optional), intra-community VAT number (optional).
- Billing data: order history, amounts invoiced, VAT applied, tokenised payment reference issued by our payment service provider (Zenthoryx). We never store full card numbers, expiry dates, CVV codes or IBANs of the payment instrument.
- Client Area session data: passwordless magic-link tokens, session identifier, CSRF token, and, for security, the timestamp and IP address of each successful sign-in.
- Module usage logs: for each active Module, the timestamp and endpoint of API calls made to the Profitroom API on your behalf, the HTTP status code returned, and error messages. No payload data is stored beyond what is required to reproduce a failed operation for support.
- Profitroom API credentials: the API key you provide when activating a Module, stored encrypted at rest using AES-256, and decrypted only in memory at the moment of each API call.
- Technical data: IP address, user-agent string, browser type and version, operating system, HTTP referrer, pages visited, duration of visit.
- Support correspondence: the content of any message you send to our support address and any attachments.
3. Purposes and lawful bases (Article 6 GDPR)
| Purpose | Data categories | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Providing the Modules and the Client Area | Account, session, API credentials, usage logs | Art. 6(1)(b) — performance of contract |
| Invoicing and payment collection | Billing data | Art. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation |
| Statutory retention of invoices | Billing data | Art. 6(1)(c) — Montenegrin tax law |
| Fraud prevention and security monitoring | IP, user-agent, session logs | Art. 6(1)(f) — legitimate interest |
| Service emails (incident notices, invoices) | Contact data | Art. 6(1)(b) — contract |
| Marketing emails and newsletters | Contact data | Art. 6(1)(a) — consent (opt-in, revocable) |
| Product analytics (aggregated) | Pseudonymised usage data | Art. 6(1)(f) — legitimate interest |
Our transparency obligations under Articles 13 and 14 GDPR are met by this policy, by the Order confirmation email, and by contextual notices in the Client Area.
4. Data recipients and processors
Personal data is shared strictly on a need-to-know basis with the following processors and recipients:
- Zenthoryx — EUR-NX payment rail. Purpose: processing card and SEPA payments. Data received: billing details, tokenised card reference, amount, currency.
- European cloud hosting provider — production hosting in the European Economic Area only. Purpose: running the application and database. Data received: all data stored on our servers, encrypted at rest.
- Transactional email provider — EU-based. Purpose: delivering magic-link sign-in emails, invoices and service notices.
- External auditors and tax advisors — bound by professional secrecy. Purpose: statutory audit and tax reporting.
- Competent public authorities — where required by law, court order or a valid request from a supervisory authority.
We do not sell personal data. We do not share personal data with advertising networks. We do not use personal data for automated decision-making producing legal effects within the meaning of Article 22 GDPR.
5. International transfers
All personal data is stored and processed within the European Union or the European Economic Area. We do not perform international transfers of personal data to third countries within the meaning of Chapter V GDPR. Should we ever need to change this, we will update this policy and put in place a lawful transfer mechanism (standard contractual clauses, adequacy decision or binding corporate rules) before any transfer takes place.
6. Retention periods
| Data category | Retention period | Legal basis for retention |
|---|---|---|
| Active account data | For the duration of the Subscription and 3 years after the last activity | Contract, legitimate interest (litigation defence) |
| Invoices and accounting records | 10 years | Montenegrin tax law |
| Client Area session logs | 12 months | Security |
| Module usage logs | 90 days for debug logs, 24 months aggregated | Operations, product analytics |
| Profitroom API keys | Deleted within 30 days of Subscription termination | Contract |
| Marketing consent record | Duration of consent + 3 years | Proof of consent |
| Support correspondence | 3 years from last exchange | Legitimate interest |
7. Your rights under GDPR (Articles 15 to 22)
You have, at any time and free of charge, the following rights over your personal data:
- Article 15 — right of access: to obtain confirmation that we process your data and a copy of that data.
- Article 16 — right to rectification: to have inaccurate data corrected without undue delay.
- Article 17 — right to erasure: to have your data deleted where one of the grounds in Article 17(1) applies, subject to our legal retention obligations.
- Article 18 — right to restriction: to obtain restriction of processing in the circumstances listed in Article 18(1).
- Article 19 — notification obligation: we notify each recipient of any rectification, erasure or restriction we perform, unless it proves impossible or would involve disproportionate effort.
- Article 20 — right to portability: to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Article 21 — right to object: to object at any time to processing based on legitimate interest, including profiling on that basis; and to object at any time to processing for direct marketing purposes.
- Article 22 — no automated decision-making: we do not take decisions producing legal effects based solely on automated processing.
8. How to exercise your rights
Send a written request to privacy@profitroommod.org, including sufficient information for us to verify your identity (typically the email associated with your account) and a clear description of the right you wish to exercise. We reply within one (1) month of receipt in accordance with Article 12(3) GDPR. That period may be extended by a further two months where the request is particularly complex, in which case we will inform you within the first month and explain the reasons for the delay.
9. Cookies
profitroommod.org uses only the cookies strictly necessary to operate the site and, subject to your prior consent, functional and analytics cookies. A full description of every cookie set, its purpose, its retention and how to opt out is available in the Cookie Policy.
10. Security measures
We implement the technical and organisational measures required by Article 32 GDPR to safeguard personal data. In particular:
- All connections to profitroommod.org are encrypted with TLS 1.3; older TLS versions are refused.
- Personal data at rest, including Profitroom API keys, are encrypted with AES-256.
- Access to production systems is restricted to a named list of engineers, protected by multi-factor authentication and logged on every session.
- Passwords are not used for the Client Area; the magic-link workflow eliminates password reuse and credential-stuffing risks.
- Vulnerability scans are performed weekly and dependencies are patched within a defined SLA.
- An incident response plan is maintained and tested.
- Backups are encrypted, stored in a separate EU region and tested for recoverability.
11. Breach notification (Article 33 GDPR)
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we notify the competent supervisory authority (Agencija za zaštitu ličnih podataka — AZLP, registration 05-030/26-1073) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to affected data subjects, we also notify those data subjects without undue delay in accordance with Article 34.
12. Data Protection Officer
Profitroommod has designated an internal privacy contact who acts as its Data Protection Officer under Article 37 GDPR. You may reach them at dpo@profitroommod.org.
13. Complaints to the supervisory authority
You have the right, without prejudice to any other administrative or judicial remedy, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Article 77 GDPR). The Montenegrin supervisory authority is:
Agencija za zaštitu ličnih podataka (AZLP)
Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica
Registration of Profitroommod as controller: 05-030/26-1073
Website: azlp.me
14. Changes to this policy
This Privacy Policy may be updated to reflect changes in law, our processing operations or our security posture. The current version and its effective date are always accessible at profitroommod.org/privacy. Material changes are notified by email to the address on file at least thirty (30) days before they enter into force.
15. Contact
Profitroommod d.o.o.
ul. Njegoševa 87, 81000 Podgorica, Crna Gora
Director: Dragan Kovačević
Telephone: +382 20 741 528
Email: privacy@profitroommod.org · support@profitroommod.org
PIB: 04456739 — CRPS: 4-0070284/1
IBAN: ME25 505 0000 0134 5678 90
Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), registration 05-030/26-1073.
Effective from 3 August 2026. Next scheduled review: 3 February 2027.