Data Processing Agreement (DPA)
Last updated: 3 August 2026 — Profitroomshop d.o.o. — Version 1.0
This Data Processing Agreement (the "DPA") is concluded in accordance with Article 28 of the General Data Protection Regulation (GDPR, EU 2016/679) and the Montenegrin Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti). It forms an integral part of the Profitroomshop Terms and Conditions and applies as of right to any hotel Customer using a Profitroomshop Module that processes personal data on the Customer's behalf.
1. Parties
The Controller (hereinafter the "Controller") is the hotel or hospitality Customer that has subscribed to one or more Profitroomshop Modules on profitroomshop.org, acting as controller of the personal data of its guests, travellers and prospects.
The Processor (hereinafter the "Processor" or "Profitroomshop") is Profitroomshop d.o.o., a company incorporated under the laws of Montenegro, PIB 04567892, CRPS 4-0074615/3, whose registered office is located at ul. Vasa Raičkovića 66, 81000 Podgorica, Crna Gora, represented by its director Nikola Popović, acting as processor within the meaning of Article 4(8) GDPR when it processes guest or prospect data on behalf of the Controller.
2. Subject matter, nature and purpose of the processing
Profitroomshop processes personal data on behalf of the Controller strictly within the scope of the Modules subscribed to on the Controller's Profitroomshop account. The nature of the processing includes reading, writing, synchronising, aggregating, archiving and deleting hotel-guest data through the Profitroom booking-engine and channel-manager API. Purposes include multi-channel synchronisation (Booking.com, Expedia, Airbnb), VAT-compliant invoicing, generation of analytical reports, pre-arrival guest journeys, mobile check-in, housekeeping workflows and automatic room assignment. Profitroomshop does not use these data for its own purposes, beyond what is strictly necessary to perform the Modules.
3. Duration of the processing
This DPA takes effect upon conclusion of the contract between the Controller and Profitroomshop and ends upon expiry of the last Module subscribed to by the Controller, extended by a 90 calendar-day intermediate archiving period for audit and restitution purposes. At the end of that period, all personal data processed on behalf of the Controller is irreversibly deleted, save for mandatory legal retention.
4. Categories of data subjects and data processed
Data subjects: current and past guests of the Controller's hotel property, prospects that have initiated a booking request, loyalty-programme members and corporate contacts.
Categories of data:
- Identification data: first and last name, date of birth, nationality, identity document (only where locally mandated guest-registration duties apply and only within the Cardless Check-in Extension).
- Contact data: email, phone, postal address.
- Reservation data: stay dates, room type, rate, booking channel, payment method (tokenised), special requests.
- Preference data: food allergies, bedding preferences, stay history, average spend.
- Billing data: invoiced amount, VAT applied, tourist tax.
- Technical metadata: connection IP address, timestamps, access log.
Profitroomshop does not process any special category of data within the meaning of Article 9 GDPR (sensitive data), with the sole exception of health data strictly limited to food allergies voluntarily disclosed by the guest in the pre-arrival journey, and only with their express consent recorded within the Profitroomshop portal.
5. Processor obligations
Profitroomshop undertakes, in accordance with Article 28(3) GDPR, to:
- Process personal data only on documented instructions from the Controller, including for any transfer to a third country, unless otherwise required by immediately applicable law.
- Ensure that persons authorised to process personal data are bound by a duty of confidentiality by contract or statute.
- Implement all technical and organisational measures required by Article 32 GDPR, detailed in Annex 1 to this DPA.
- Engage no additional sub-processor without the Controller's prior written authorisation, on the terms set out in section 6 below.
- Assist the Controller, taking into account the nature of the processing and by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests for the exercise of data-subject rights.
- Assist the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available.
- At the end of the service, at the Controller's option, either delete all personal data or return them and destroy any existing copies, unless retention is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or by another auditor mandated by it.
6. Sub-processors
The Controller authorises Profitroomshop to engage additional sub-processors for the performance of the Modules. Profitroomshop undertakes to conclude, with each additional sub-processor, a contract imposing the same obligations as those set out in this DPA, in particular as regards technical and organisational security measures.
Current list of additional sub-processors:
- Hetzner Online GmbH (Germany, Frankfurt) — cloud hosting, ISO 27001-certified.
- Stripe Payments Europe Ltd. (Ireland, Dublin) — payment processing, PCI-DSS Level 1 certified.
- Postmark (ActiveCampaign LLC) (United States, under Standard Contractual Clauses) — delivery of transactional emails.
- Sentry.io (Functional Software Inc.) (United States, under Standard Contractual Clauses and with pre-transmission anonymisation of personal data) — application error monitoring.
Any change to this list, including the addition of a new sub-processor or the replacement of an existing one, will be notified to the Controller by email at least thirty calendar days before it takes effect, with the option for the Controller to object on reasoned written grounds during that period. In the event of an objection, the parties will seek an amicable solution; failing that, the Controller may terminate the contract without penalty.
7. International transfers
The primary processing of personal data takes place within the European Union (Germany, Frankfurt) and in Montenegro (Profitroomshop's registered office). Some additional sub-processors are established outside the EU/EEA, in particular in the United States. In such cases, Profitroomshop has put in place the Standard Contractual Clauses adopted by the European Commission by implementing decision of 4 June 2021 (2021/914/EU), supplemented by the additional measures required by the Schrems II case-law (CJEU, 16 July 2020, C-311/18), to ensure a level of protection essentially equivalent to that offered within the European Union.
8. Personal data breach notification
In accordance with Article 33(2) GDPR, Profitroomshop shall notify the Controller of any personal data breach within a maximum of twenty-four (24) hours from becoming aware of it. The notification shall include, at a minimum: the nature of the breach, the categories and approximate number of persons concerned, the categories and approximate number of data records concerned, the likely consequences, and the measures taken or proposed to address the breach. Profitroomshop shall provide the Controller with all necessary assistance so that the Controller can meet, within the 72-hour deadline set by Article 33(1) GDPR, its own obligations to notify the supervisory authority and, where applicable, the data subjects.
9. Data protection impact assessment
Profitroomshop makes available to the Controller a detailed factsheet for each Module, including all information useful for carrying out a data protection impact assessment (DPIA) under Article 35 GDPR. Profitroomshop assists the Controller, on request and within a reasonable timeframe, in the performance of such assessments and, where relevant, in the prior consultation with the supervisory authority provided for in Article 36 GDPR.
10. Audit and control
The Controller has an annual right to audit the technical and organisational measures implemented by Profitroomshop. The audit may be conducted by the Controller directly or by an auditor mandated by it, subject to prior signature of a confidentiality agreement. The audit is conducted during business hours, with at least thirty days' written notice, and must not unreasonably disrupt Profitroomshop's activity. Alternatively, Profitroomshop may satisfy its audit obligation by providing the Controller with an independent audit report (ISO 27001, SOC 2 Type II) issued within the preceding twelve months.
11. Liability
Each party is liable for damages caused by processing carried out in breach of the GDPR, on the terms provided for in Article 82 GDPR. Profitroomshop is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed at processors, or where it has acted outside or contrary to lawful instructions of the Controller.
12. Termination of the DPA — Return or destruction
At the end of the service, the Controller has a 90 calendar-day period to notify Profitroomshop in writing whether it wishes (i) full return of the data in structured JSON format, or (ii) irreversible destruction. Failing an express choice, destruction is applied by default. A destruction certificate is sent to the Controller within thirty days of the operation, upon simple request.
13. Annex 1 — Technical and organisational security measures
Profitroomshop implements, among others, the following measures pursuant to Article 32 GDPR:
- Encryption of data at rest with AES-256 and in transit with TLS 1.3.
- Two-factor authentication for all administrators and technical staff.
- Web application firewall (WAF) with OWASP Top 10 rulesets.
- Annual external penetration testing by an independent provider.
- Encrypted incremental daily backups, tested monthly through restoration drills.
- Logging of administrator access with timestamp, IP address and action performed.
- Quarterly review of authorisations on a strict need-to-know basis.
- Separation of development, pre-production and production environments.
- Internal endpoint management policy (disk encryption, automatic updates, VPN).
- Annual staff training on information security and data protection.
- Business continuity and disaster recovery plan, tested annually.
- Anonymisation or pseudonymisation of data wherever it does not compromise the purpose.
14. Contact details and remedies
Profitroomshop d.o.o.
ul. Vasa Raičkovića 66, 81000 Podgorica, Crna Gora
PIB: 04567892 — CRPS: 4-0074615/3
Director: Nikola Popović
DPO: dpo@profitroomshop.org
Privacy: privacy@profitroomshop.org
Phone: +382 20 852 964
IBAN: ME25 505 0000 0145 6789 01
Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica, controller registration No. 05-030/26-2148. Jurisdiction: Osnovni sud u Podgorici (Montenegro).
Version 1.0 — published 3 August 2026. Next scheduled review: 3 February 2027.