Data Processing Agreement (DPA)
WineCRM · Version 1.2 · Effective 24 September 2026 · Compliant with Article 28 GDPR · Applies to free and paid accounts · English translation provided for convenience; the French version prevails.
1. Parties and purpose
This agreement is entered into between the Customer, as controller of the personal data it records in WineCRM, and FlowLabs SAS, with share capital of €5,000, registered with the Bordeaux Trade and Companies Register under number 100 545 003, whose registered office is at 2 chemin de Peyrouley, 33360 Carignan-de-Bordeaux, France, as processor (« FlowLabs »). Contact: contact@winecrm.app · +33 6 35 23 93 63.
It sets out the conditions under which FlowLabs processes personal data contained in Customer Data on behalf of the Customer. It is accepted at sign-up and, as regards this processing, prevails over any conflicting provision of the Terms of Use and Terms of Sale. Processing carried out by FlowLabs on its own behalf is governed by the Privacy Policy.
2. Description of the processing
The characteristics of the processing (subject matter, duration, nature, purpose, types of data, categories of data subjects) are described in Annex 1.
3. Customer instructions
FlowLabs processes the data only on the Customer’s documented instructions. The Terms of Use, the Terms of Sale, this agreement and the settings and actions made by the Customer in the Service constitute its instructions. FlowLabs immediately informs the Customer if an instruction appears to infringe applicable law.
If EU or Member State law requires FlowLabs to carry out processing not provided for in the instructions, FlowLabs informs the Customer beforehand, unless the law prohibits it.
4. Customer obligations
The Customer warrants that it has a legal basis for its processing, informs data subjects where required, respects their rights and the rules applicable to marketing, and limits the data to the needs of its business. It does not record special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences. Where required by law, it obtains the consent of persons whose voice appears in audio recordings.
5. Confidentiality
FlowLabs ensures that persons authorised to process the data are bound by an obligation of confidentiality. Development contractors have no access to real production data.
6. Security
FlowLabs implements the technical and organisational measures described in Annex 2 and adapts them to the risks, without ever reducing their overall level.
7. Sub-processors
The Customer authorises FlowLabs to use the sub-processors listed in Annex 3. FlowLabs imposes on each of them data protection obligations equivalent to those of this agreement and remains liable to the Customer for their performance.
FlowLabs informs the Customer of any addition or replacement of a sub-processor at least 30 days in advance, by email or in the app. The Customer may object in writing, with reasons, during this period. If no solution is found, the Customer may cancel its subscription free of charge before the change takes effect and obtain a refund of the unused prepaid period.
8. Transfers outside the European Union
Data is hosted in France. Some sub-processors may process data outside the European Union, as indicated in Annex 3. These transfers are covered by an adequacy decision (EU-US Data Privacy Framework) where the sub-processor is certified, and by the European Commission’s standard contractual clauses.
9. Assistance to the Customer
FlowLabs assists the Customer, through appropriate technical and organisational measures and insofar as possible:
- in responding to requests from data subjects exercising their rights: the Service allows data to be viewed, corrected, exported and deleted; any request received directly by FlowLabs is forwarded to the Customer without delay;
- in ensuring the security of processing and, where applicable, carrying out a data protection impact assessment and consulting the supervisory authority, by providing the information available to FlowLabs.
10. Personal data breach
FlowLabs notifies the Customer of any personal data breach affecting Customer Data within a maximum of 48 hours of becoming aware of it, by email to the account address. The notification includes, where available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Missing information is provided as soon as it becomes known.
11. End of processing: return and deletion
The Customer can export its Customer Data at any time from the Service in a structured format. On account deletion, the Customer has 30 days to export its data or request restoration of the account. After this period, FlowLabs deletes Customer Data from production. Backups are erased when they expire, within a maximum of 7 further days. If a backup is restored, earlier deletions are reapplied before the data is put back into service.
Switching from a paid plan to the free Starter plan does not delete any data.
FlowLabs may retain data whose retention is required by law, with restricted access and only for the required period.
12. Audit
FlowLabs makes available to the Customer the information needed to demonstrate compliance with this agreement. The Customer may request further information in writing; FlowLabs replies within a reasonable time. If this information is insufficient, the Customer may have an audit carried out, no more than once a year, by an independent auditor bound by confidentiality, with 30 days’ notice, at its own expense and without disrupting the Service or accessing other customers’ data.
13. Term and liability
This agreement applies for as long as the Service is used and until Customer Data has actually been deleted. Each party’s liability is governed by the Terms of Use and Terms of Sale, without prejudice to the rights that data subjects derive from the GDPR.
Annex 1 — Description of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of the WineCRM sales management service |
| Duration | Duration of use of the Service, then 30-day recovery period and backup purge period |
| Nature of operations | Hosting, storage, organisation, consultation, extraction of contact details from a photo, address geocoding, calculation of follow-up suggestions, export and deletion |
| Purpose | Enabling the Customer to manage its business relationship with its professional customers and prospects |
| Types of data | Identity and job title; business contact details (email, phone, establishment address); text notes; audio recordings; business card photos (not kept after extraction); sales, visit and appointment histories; tasks; documents |
| Data subjects | The Customer’s customers, prospects, partners and business contacts; where applicable, persons whose voice appears in recordings |
Annex 2 — Security measures
- Encryption of communications (HTTPS/TLS).
- Encryption at rest of the PostgreSQL database.
- Passwords stored in hashed form; sign-in possible via Google or Apple.
- Logical separation of data between customers.
- Administrative access to production limited to the authorised FlowLabs person, from France, with strong authentication on infrastructure accounts; no access by development contractors to real data.
- Business card photos processed in memory and not kept by FlowLabs.
- Daily backups of the PostgreSQL database, kept for 7 days.
- Data export available to the Customer at any time.
Annex 3 — Sub-processors
| Sub-processor | Service | Location | Transfer safeguards |
|---|---|---|---|
| Scaleway SAS (France) | Application server, PostgreSQL, storage of files and audio | Paris, France | No transfer |
| Vercel Inc. | Hosting and delivery of the application’s web interface | Global network, including the EU and the United States | DPF / standard contractual clauses |
| MongoDB, Inc. (Atlas), on Amazon Web Services | Sales history database | Paris, France (eu-west-3) | Possible access from the United States: DPF / standard contractual clauses |
| Google Ireland Ltd / Google LLC | Business card extraction (Gemini); geocoding and maps (Google Maps Platform) | EU and United States; no region guaranteed for Gemini | DPF / standard contractual clauses |
| Brevo (Sendinblue SAS, France) | Sending transactional emails containing, where applicable, Customer Data | European Union | Possible access from the United States and India: DPF / standard contractual clauses |