MP
Profitroommod
Client Area Client
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Client Area Contact
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Contact
Home / Privacy Policy

Privacy Policy

Effective from: 3 August 2026. This Privacy Policy explains how Profitroommod d.o.o. handles personal data in connection with the operation of the marketplace at profitroommod.org and the Modules distributed through it. It is drafted to comply with Regulation (EU) 2016/679 («GDPR») and the Montenegrin Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti).

Independence and non-affiliation

Profitroommod is an independent third-party marketplace and is not affiliated with, sponsored by or endorsed by Profitroom S.A. or its parent company. References to Profitroom in this policy describe technical interoperation only.

1. Controller identity

The controller of the personal data collected on profitroommod.org, within the meaning of Article 4(7) GDPR, is Profitroommod d.o.o., a limited liability company organised under the laws of Montenegro, PIB 04456739, registered under CRPS 4-0070284/1, with its registered seat at ul. Njegoševa 87, 81000 Podgorica, Crna Gora, represented by its Director Dragan Kovačević. When Profitroommod processes reservation, guest or operational data on behalf of a Customer hotel through a Module, it acts as a processor within the meaning of Article 4(8) GDPR under the terms of the Data Processing Agreement.

You may contact the controller at any time: email support@profitroommod.org, telephone +382 20 741 528, IBAN ME25 505 0000 0134 5678 90.

2. Data we collect

We collect only the personal data strictly necessary for one of the purposes listed in section 3, or to which you have expressly consented. The categories are:

  • Account and contact data: business email address, first and last name of the authorised representative, hotel legal name, postal address, telephone (optional), intra-community VAT number (optional).
  • Billing data: order history, amounts invoiced, VAT applied, tokenised payment reference issued by our payment service provider (Zenthoryx). We never store full card numbers, expiry dates, CVV codes or IBANs of the payment instrument.
  • Client Area session data: passwordless magic-link tokens, session identifier, CSRF token, and, for security, the timestamp and IP address of each successful sign-in.
  • Module usage logs: for each active Module, the timestamp and endpoint of API calls made to the Profitroom API on your behalf, the HTTP status code returned, and error messages. No payload data is stored beyond what is required to reproduce a failed operation for support.
  • Profitroom API credentials: the API key you provide when activating a Module, stored encrypted at rest using AES-256, and decrypted only in memory at the moment of each API call.
  • Technical data: IP address, user-agent string, browser type and version, operating system, HTTP referrer, pages visited, duration of visit.
  • Support correspondence: the content of any message you send to our support address and any attachments.

3. Purposes and lawful bases (Article 6 GDPR)

PurposeData categoriesLawful basis (Art. 6 GDPR)
Providing the Modules and the Client AreaAccount, session, API credentials, usage logsArt. 6(1)(b) — performance of contract
Invoicing and payment collectionBilling dataArt. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation
Statutory retention of invoicesBilling dataArt. 6(1)(c) — Montenegrin tax law
Fraud prevention and security monitoringIP, user-agent, session logsArt. 6(1)(f) — legitimate interest
Service emails (incident notices, invoices)Contact dataArt. 6(1)(b) — contract
Marketing emails and newslettersContact dataArt. 6(1)(a) — consent (opt-in, revocable)
Product analytics (aggregated)Pseudonymised usage dataArt. 6(1)(f) — legitimate interest

Our transparency obligations under Articles 13 and 14 GDPR are met by this policy, by the Order confirmation email, and by contextual notices in the Client Area.

4. Data recipients and processors

Personal data is shared strictly on a need-to-know basis with the following processors and recipients:

  • Zenthoryx — EUR-NX payment rail. Purpose: processing card and SEPA payments. Data received: billing details, tokenised card reference, amount, currency.
  • European cloud hosting provider — production hosting in the European Economic Area only. Purpose: running the application and database. Data received: all data stored on our servers, encrypted at rest.
  • Transactional email provider — EU-based. Purpose: delivering magic-link sign-in emails, invoices and service notices.
  • External auditors and tax advisors — bound by professional secrecy. Purpose: statutory audit and tax reporting.
  • Competent public authorities — where required by law, court order or a valid request from a supervisory authority.

We do not sell personal data. We do not share personal data with advertising networks. We do not use personal data for automated decision-making producing legal effects within the meaning of Article 22 GDPR.

5. International transfers

All personal data is stored and processed within the European Union or the European Economic Area. We do not perform international transfers of personal data to third countries within the meaning of Chapter V GDPR. Should we ever need to change this, we will update this policy and put in place a lawful transfer mechanism (standard contractual clauses, adequacy decision or binding corporate rules) before any transfer takes place.

6. Retention periods

Data categoryRetention periodLegal basis for retention
Active account dataFor the duration of the Subscription and 3 years after the last activityContract, legitimate interest (litigation defence)
Invoices and accounting records10 yearsMontenegrin tax law
Client Area session logs12 monthsSecurity
Module usage logs90 days for debug logs, 24 months aggregatedOperations, product analytics
Profitroom API keysDeleted within 30 days of Subscription terminationContract
Marketing consent recordDuration of consent + 3 yearsProof of consent
Support correspondence3 years from last exchangeLegitimate interest

7. Your rights under GDPR (Articles 15 to 22)

You have, at any time and free of charge, the following rights over your personal data:

  • Article 15 — right of access: to obtain confirmation that we process your data and a copy of that data.
  • Article 16 — right to rectification: to have inaccurate data corrected without undue delay.
  • Article 17 — right to erasure: to have your data deleted where one of the grounds in Article 17(1) applies, subject to our legal retention obligations.
  • Article 18 — right to restriction: to obtain restriction of processing in the circumstances listed in Article 18(1).
  • Article 19 — notification obligation: we notify each recipient of any rectification, erasure or restriction we perform, unless it proves impossible or would involve disproportionate effort.
  • Article 20 — right to portability: to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Article 21 — right to object: to object at any time to processing based on legitimate interest, including profiling on that basis; and to object at any time to processing for direct marketing purposes.
  • Article 22 — no automated decision-making: we do not take decisions producing legal effects based solely on automated processing.

8. How to exercise your rights

Send a written request to privacy@profitroommod.org, including sufficient information for us to verify your identity (typically the email associated with your account) and a clear description of the right you wish to exercise. We reply within one (1) month of receipt in accordance with Article 12(3) GDPR. That period may be extended by a further two months where the request is particularly complex, in which case we will inform you within the first month and explain the reasons for the delay.

9. Cookies

profitroommod.org uses only the cookies strictly necessary to operate the site and, subject to your prior consent, functional and analytics cookies. A full description of every cookie set, its purpose, its retention and how to opt out is available in the Cookie Policy.

10. Security measures

We implement the technical and organisational measures required by Article 32 GDPR to safeguard personal data. In particular:

  • All connections to profitroommod.org are encrypted with TLS 1.3; older TLS versions are refused.
  • Personal data at rest, including Profitroom API keys, are encrypted with AES-256.
  • Access to production systems is restricted to a named list of engineers, protected by multi-factor authentication and logged on every session.
  • Passwords are not used for the Client Area; the magic-link workflow eliminates password reuse and credential-stuffing risks.
  • Vulnerability scans are performed weekly and dependencies are patched within a defined SLA.
  • An incident response plan is maintained and tested.
  • Backups are encrypted, stored in a separate EU region and tested for recoverability.

11. Breach notification (Article 33 GDPR)

In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we notify the competent supervisory authority (Agencija za zaštitu ličnih podataka — AZLP, registration 05-030/26-1073) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to affected data subjects, we also notify those data subjects without undue delay in accordance with Article 34.

12. Data Protection Officer

Profitroommod has designated an internal privacy contact who acts as its Data Protection Officer under Article 37 GDPR. You may reach them at dpo@profitroommod.org.

13. Complaints to the supervisory authority

You have the right, without prejudice to any other administrative or judicial remedy, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Article 77 GDPR). The Montenegrin supervisory authority is:

Agencija za zaštitu ličnih podataka (AZLP)
Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica
Registration of Profitroommod as controller: 05-030/26-1073
Website: azlp.me

14. Changes to this policy

This Privacy Policy may be updated to reflect changes in law, our processing operations or our security posture. The current version and its effective date are always accessible at profitroommod.org/privacy. Material changes are notified by email to the address on file at least thirty (30) days before they enter into force.

15. Contact

Profitroommod d.o.o.
ul. Njegoševa 87, 81000 Podgorica, Crna Gora
Director: Dragan Kovačević
Telephone: +382 20 741 528
Email: privacy@profitroommod.org · support@profitroommod.org
PIB: 04456739 — CRPS: 4-0070284/1
IBAN: ME25 505 0000 0134 5678 90
Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), registration 05-030/26-1073.

Effective from 3 August 2026. Next scheduled review: 3 February 2027.

Profitroommod

Modules, extensions and integrations for the Profitroom booking engine and channel manager

Independent marketplace of modules and extensions for the Profitroom booking engine and channel manager.

Shop

  • All extensions
  • Pricing
  • Compare
  • ROI calculator
  • Checkout

Resources

  • Features
  • Integrations
  • Blog
  • Guides
  • Academy
  • Changelog
  • API documentation

Company

  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Refund policy
Profitroommod d.o.o. — PIB: 04456739 — CRPS: 4-0070284/1 — ul. Njegoševa 87, 81000 Podgorica, Crna Gora — Director: Dragan Kovačević — support@profitroommod.org — Tel: +382 20 741 528 — IBAN ME25 505 0000 0134 5678 90.
Profitroommod is an independent third-party marketplace and is in no way affiliated with, sponsored by or endorsed by Profitroom S.A. or its parent company. All trademarks, product names and logos are the property of their respective owners. Supervisory authority for data protection: Agencija za zaštitu ličnih podataka (AZLP), registration no. 05-030/26-1073. Jurisdiction: Osnovni sud u Podgorici. Applicable legal framework: Zakon o zaštiti podataka o ličnosti + GDPR + Zakon o elektronskoj trgovini + Zakon o zaštiti potrošača.
© 2024–2026 Profitroommod d.o.o. All rights reserved.
Terms Privacy Cookies DPA Refunds

Your cart

Total €0.00
Checkout →

We use cookies to improve your experience and analyse site performance. Learn more