Data Processing Agreement (DPA)

WineCRM · Version 1.2 · Effective 24 September 2026 · Compliant with Article 28 GDPR · Applies to free and paid accounts · English translation provided for convenience; the French version prevails.

1. Parties and purpose

This agreement is entered into between the Customer, as controller of the personal data it records in WineCRM, and FlowLabs SAS, with share capital of €5,000, registered with the Bordeaux Trade and Companies Register under number 100 545 003, whose registered office is at 2 chemin de Peyrouley, 33360 Carignan-de-Bordeaux, France, as processor (« FlowLabs »). Contact: contact@winecrm.app · +33 6 35 23 93 63.

It sets out the conditions under which FlowLabs processes personal data contained in Customer Data on behalf of the Customer. It is accepted at sign-up and, as regards this processing, prevails over any conflicting provision of the Terms of Use and Terms of Sale. Processing carried out by FlowLabs on its own behalf is governed by the Privacy Policy.

2. Description of the processing

The characteristics of the processing (subject matter, duration, nature, purpose, types of data, categories of data subjects) are described in Annex 1.

3. Customer instructions

FlowLabs processes the data only on the Customer’s documented instructions. The Terms of Use, the Terms of Sale, this agreement and the settings and actions made by the Customer in the Service constitute its instructions. FlowLabs immediately informs the Customer if an instruction appears to infringe applicable law.

If EU or Member State law requires FlowLabs to carry out processing not provided for in the instructions, FlowLabs informs the Customer beforehand, unless the law prohibits it.

4. Customer obligations

The Customer warrants that it has a legal basis for its processing, informs data subjects where required, respects their rights and the rules applicable to marketing, and limits the data to the needs of its business. It does not record special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences. Where required by law, it obtains the consent of persons whose voice appears in audio recordings.

5. Confidentiality

FlowLabs ensures that persons authorised to process the data are bound by an obligation of confidentiality. Development contractors have no access to real production data.

6. Security

FlowLabs implements the technical and organisational measures described in Annex 2 and adapts them to the risks, without ever reducing their overall level.

7. Sub-processors

The Customer authorises FlowLabs to use the sub-processors listed in Annex 3. FlowLabs imposes on each of them data protection obligations equivalent to those of this agreement and remains liable to the Customer for their performance.

FlowLabs informs the Customer of any addition or replacement of a sub-processor at least 30 days in advance, by email or in the app. The Customer may object in writing, with reasons, during this period. If no solution is found, the Customer may cancel its subscription free of charge before the change takes effect and obtain a refund of the unused prepaid period.

8. Transfers outside the European Union

Data is hosted in France. Some sub-processors may process data outside the European Union, as indicated in Annex 3. These transfers are covered by an adequacy decision (EU-US Data Privacy Framework) where the sub-processor is certified, and by the European Commission’s standard contractual clauses.

9. Assistance to the Customer

FlowLabs assists the Customer, through appropriate technical and organisational measures and insofar as possible:

  • in responding to requests from data subjects exercising their rights: the Service allows data to be viewed, corrected, exported and deleted; any request received directly by FlowLabs is forwarded to the Customer without delay;
  • in ensuring the security of processing and, where applicable, carrying out a data protection impact assessment and consulting the supervisory authority, by providing the information available to FlowLabs.

10. Personal data breach

FlowLabs notifies the Customer of any personal data breach affecting Customer Data within a maximum of 48 hours of becoming aware of it, by email to the account address. The notification includes, where available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Missing information is provided as soon as it becomes known.

11. End of processing: return and deletion

The Customer can export its Customer Data at any time from the Service in a structured format. On account deletion, the Customer has 30 days to export its data or request restoration of the account. After this period, FlowLabs deletes Customer Data from production. Backups are erased when they expire, within a maximum of 7 further days. If a backup is restored, earlier deletions are reapplied before the data is put back into service.

Switching from a paid plan to the free Starter plan does not delete any data.

FlowLabs may retain data whose retention is required by law, with restricted access and only for the required period.

12. Audit

FlowLabs makes available to the Customer the information needed to demonstrate compliance with this agreement. The Customer may request further information in writing; FlowLabs replies within a reasonable time. If this information is insufficient, the Customer may have an audit carried out, no more than once a year, by an independent auditor bound by confidentiality, with 30 days’ notice, at its own expense and without disrupting the Service or accessing other customers’ data.

13. Term and liability

This agreement applies for as long as the Service is used and until Customer Data has actually been deleted. Each party’s liability is governed by the Terms of Use and Terms of Sale, without prejudice to the rights that data subjects derive from the GDPR.

Annex 1 — Description of the processing

ItemDescription
Subject matterProvision of the WineCRM sales management service
DurationDuration of use of the Service, then 30-day recovery period and backup purge period
Nature of operationsHosting, storage, organisation, consultation, extraction of contact details from a photo, address geocoding, calculation of follow-up suggestions, export and deletion
PurposeEnabling the Customer to manage its business relationship with its professional customers and prospects
Types of dataIdentity and job title; business contact details (email, phone, establishment address); text notes; audio recordings; business card photos (not kept after extraction); sales, visit and appointment histories; tasks; documents
Data subjectsThe Customer’s customers, prospects, partners and business contacts; where applicable, persons whose voice appears in recordings

Annex 2 — Security measures

  • Encryption of communications (HTTPS/TLS).
  • Encryption at rest of the PostgreSQL database.
  • Passwords stored in hashed form; sign-in possible via Google or Apple.
  • Logical separation of data between customers.
  • Administrative access to production limited to the authorised FlowLabs person, from France, with strong authentication on infrastructure accounts; no access by development contractors to real data.
  • Business card photos processed in memory and not kept by FlowLabs.
  • Daily backups of the PostgreSQL database, kept for 7 days.
  • Data export available to the Customer at any time.

Annex 3 — Sub-processors

Sub-processorServiceLocationTransfer safeguards
Scaleway SAS (France)Application server, PostgreSQL, storage of files and audioParis, FranceNo transfer
Vercel Inc.Hosting and delivery of the application’s web interfaceGlobal network, including the EU and the United StatesDPF / standard contractual clauses
MongoDB, Inc. (Atlas), on Amazon Web ServicesSales history databaseParis, France (eu-west-3)Possible access from the United States: DPF / standard contractual clauses
Google Ireland Ltd / Google LLCBusiness card extraction (Gemini); geocoding and maps (Google Maps Platform)EU and United States; no region guaranteed for GeminiDPF / standard contractual clauses
Brevo (Sendinblue SAS, France)Sending transactional emails containing, where applicable, Customer DataEuropean UnionPossible access from the United States and India: DPF / standard contractual clauses