Privacy Policy
Last updated: 3 August 2026 — Profitroomshop d.o.o. — Version 1.0
Applicable legal framework: General Data Protection Regulation (GDPR, EU 2016/679); Zakon o zaštiti podataka o ličnosti (Montenegrin Personal Data Protection Act, as amended). Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica, controller registration No. 05-030/26-2148.
1. Identity and contact details of the controller
The controller responsible for personal data collected through https://profitroomshop.org is Profitroomshop d.o.o., a company incorporated under the laws of Montenegro, PIB 04567892, CRPS 4-0074615/3, with its registered office at ul. Vasa Raičkovića 66, 81000 Podgorica, Crna Gora, represented by its director Nikola Popović. Profitroomshop acts as a controller within the meaning of Article 4(7) GDPR when it alone determines the purposes and means of the processing, and as a processor within the meaning of Article 4(8) GDPR when it processes reservation records, guest data or operational logs on behalf of its hotel Customers (see also our Data Processing Agreement at /dpa).
2. Definitions
The terms used in this policy have the meaning given to them in Article 4 GDPR. In particular, "personal data" means any information relating to an identified or identifiable natural person (name, email, address, IP address, customer identifier, reservation identifier, etc.), and "processing" means any operation performed on such data (collection, recording, consultation, transmission, erasure, etc.).
3. Categories of data collected
We collect only the categories of data that are strictly necessary for the performance of the contract, compliance with our legal obligations, our legitimate interest or, where applicable, on the basis of your express consent. These categories are:
- Identification and contact data: first and last name, email address, postal address, name of the hotel or property, phone number (optional), EU VAT number (optional).
- Billing data: order history, invoiced amounts, payment method (tokenised reference only — the full card number is never stored, and is handled by our PCI-DSS Level 1 payment processor), invoices issued, VAT applied.
- Technical data: IP address, browser type and version, operating system, screen resolution, pages visited, session duration, HTTP referrer.
- Profitroom API credentials: Profitroom API key, API endpoint, connected Profitroom property IDs, encrypted at rest with AES-256 and in transit with TLS 1.3.
- Operational logs: log of synchronisations with the Profitroom API, timestamp, outcome (success/error), volume of data synchronised, latency.
- Support correspondence: emails exchanged with support@profitroomshop.org, tickets opened and replies provided.
4. Purposes and legal bases of processing
Each processing activity relies on a specific legal basis, in accordance with Article 6 GDPR:
- Performance of the contract (Art. 6(1)(b)): order management, activation and maintenance of Modules, invoicing, technical support. Retention: for the duration of the contractual relationship plus five years as proof of the transaction.
- Legal obligation (Art. 6(1)(c)): retention of invoices and accounting records for the periods required by Montenegrin tax law and any mandatory local law applicable to the Customer.
- Legitimate interest (Art. 6(1)(f)): securing the platform (fraud detection, access logging), improving our services (anonymised usage statistics), and limited commercial prospecting to existing Customers for similar Modules. Retention: three years from last contact.
- Consent (Art. 6(1)(a)): sending newsletters, placement of non-essential cookies, commercial communications to prospects. Retention: until consent is withdrawn plus three years.
5. Detailed retention periods
Retention periods applied by Profitroomshop are as follows, counted from the trigger event indicated:
- Active Customer account: for the duration of the contractual relationship.
- Terminated Customer account: intermediate archive for three years as proof (basis: legitimate interest).
- Invoices and accounting records: ten years from the close of the financial year (basis: legal obligation).
- Profitroom API log: rolling thirteen-month window to allow audit and debugging (basis: legitimate interest).
- Support correspondence: three years from last contact.
- Non-essential cookies: maximum thirteen months, renewable only with fresh consent.
- Prospects (contact form): three years from last contact.
6. Recipients and processors
Your data is never sold, rented or communicated to third parties for commercial purposes. It may be transmitted exclusively to the following categories of recipients, strictly within the limits of their needs:
- Authorised staff of Profitroomshop d.o.o. bound by a duty of confidentiality.
- ISO 27001-certified cloud host located in the European Union (Frankfurt, Germany) — processor within the meaning of Article 28 GDPR, bound by a compliant data processing agreement.
- PCI-DSS Level 1 payment processor located in the European Union, for the handling of card transactions.
- External accountant and statutory auditor, within the scope of their statutory assignments.
- Judicial or administrative authorities, upon lawful request.
The full up-to-date list of our sub-processors is available on request at privacy@profitroomshop.org. No transfer of data to a third country outside the EU/EEA is carried out without first putting in place a mechanism compliant with Article 46 GDPR (in particular, the European Commission's Standard Contractual Clauses).
7. Your rights as a data subject
In accordance with Articles 15 to 22 GDPR and Articles 22 to 30 of the Montenegrin Personal Data Protection Act, you may at any time exercise the following rights over your personal data:
- Right of access (Art. 15 GDPR): obtain confirmation that data concerning you is being processed and receive a copy of it.
- Right to rectification (Art. 16 GDPR): have any inaccurate or incomplete data corrected.
- Right to erasure (Art. 17 GDPR): request deletion of your data when the purpose of processing is met or when you withdraw your consent.
- Right to restriction of processing (Art. 18 GDPR): request temporary suspension of the processing of your data.
- Right to data portability (Art. 20 GDPR): receive your data in a structured, commonly used and machine-readable format (JSON, CSV).
- Right to object (Art. 21 GDPR): object, on grounds relating to your particular situation, to any processing based on our legitimate interest or on the performance of a task carried out in the public interest.
- Right to withdraw consent (Art. 7(3) GDPR): at any time, where the processing is based on your consent.
- Right to give post-mortem directives concerning the retention, deletion and communication of your data after your death.
- Right to lodge a complaint with a supervisory authority, in particular AZLP in Montenegro or the competent supervisory authority in your country of residence.
These rights are exercised free of charge, by email to privacy@profitroomshop.org or by post to our registered office. Proof of identity may be requested in the event of reasonable doubt as to your identity. We undertake to respond to your request within a maximum of one month, extendable by two months for complex requests, with prior notice.
8. Technical and organisational security measures
Profitroomshop implements all the technical and organisational measures required by Article 32 GDPR to ensure a level of security appropriate to the risk, in particular: encryption of data at rest (AES-256) and in transit (TLS 1.3), two-factor authentication for administrators, web application firewall (WAF), annual external penetration testing, encrypted incremental daily backups, strict access control on a need-to-know basis, logging of administrator access with timestamp and IP address, quarterly review of authorisations, annual staff training on data protection and information security, and a business continuity and disaster recovery plan tested annually.
9. Personal data breach notification
In accordance with Articles 33 and 34 GDPR, in the event of a personal data breach likely to result in a risk to your rights and freedoms, Profitroomshop undertakes to notify AZLP within 72 hours of becoming aware of it, and to notify the affected data subjects without undue delay where the breach is likely to result in a high risk. The notification will include the nature of the breach, the categories and approximate number of persons concerned, the likely consequences, and the measures taken or proposed to address the breach.
10. Cookies and trackers
The use of cookies and trackers on profitroomshop.org is described in detail in our Cookie Policy. Placement of cookies that are not strictly necessary for the operation of the website is subject to your prior consent, obtained through a click on "Accept" in the cookie banner presented on first access. You may withdraw this consent at any time.
11. Changes to this policy
This Privacy Policy may be modified at any time to reflect legal, judicial or operational developments. The date of the most recent update is shown at the top of this document. In the event of a substantial modification, in particular where it entails a change of purpose or recipient, affected persons will be notified by email at least thirty days before the changes take effect.
12. Controller and data protection officer contact details
Controller:
Profitroomshop d.o.o.
ul. Vasa Raičkovića 66, 81000 Podgorica, Crna Gora
PIB 04567892 — CRPS 4-0074615/3
Director: Nikola Popović
Email: privacy@profitroomshop.org — Phone: +382 20 852 964
Data Protection Officer (DPO): Profitroomshop has appointed an external DPO in accordance with Article 37 GDPR. You may contact the DPO directly at dpo@profitroomshop.org for any question relating to the processing of your personal data or the exercise of your rights.
Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), Bulevar Svetog Petra Cetinjskog 147, 81000 Podgorica, phone +382 20 634 883, www.azlp.me. Controller registration: No. 05-030/26-2148. Jurisdiction for disputes: Osnovni sud u Podgorici.
Version 1.0 — published 3 August 2026. Next scheduled review: 3 February 2027.