bluewine
← Back to bluewine

Data Processing Agreement

Version 1.0 — in force from September 2026. Applies to every bluewine customer as part of the Terms of Service.

This Agreement satisfies Article 28 GDPR and applies automatically to all customers — no signature is needed and you do not have to request it. If your organisation requires a countersigned copy for its records, print this page (or save it as PDF) and write to [email protected]. Print / save as PDF

1. The parties and what this covers

This Data Processing Agreement (the “DPA”) is entered into between:

The Controller — you, the customer: the winery, restaurant, wine shop or company that holds a bluewine account, as identified by the account registration details.
The ProcessorWise in Blue — Sonia Marchi, Varvares Volimon, Zakynthos, Greece.
Greek Tax No. (Α.Φ.Μ.): 180201397 — Tax Office (Δ.&Ο;.Υ.): Zakynthos.
Email: [email protected] — Phone: +30 698 503 1777.

It forms part of the Terms of Service for bluewine and governs any processing of personal data that we carry out on your behalf. It applies to the extent that the GDPR (Regulation (EU) 2016/679), or a national law implementing it, applies to that processing. Where this DPA and the Terms of Service conflict on a matter of data protection, this DPA prevails.

We update this DPA when what we actually do changes. Material changes are announced by email to account owners at least 30 days before they take effect, and every version keeps its own version number and date.

2. Roles

You are the data controller of the personal data you and your guests enter into bluewine. You decide what to collect, why, for how long, and you are responsible for having a lawful basis and for giving your guests their own privacy notice.

We are the data processor. We process that data only on your documented instructions — which, in practice, are: operating the service you subscribed to, and any specific written request you send us. We do not use your data for our own purposes.

We act as an independent controller only for the limited data we need as a business: your account and billing details, and aggregated, anonymous usage statistics that cannot identify an individual. That processing is described in our Privacy, Cookies & Terms, not here.

3. What we process, and for whom

ItemDetail
Subject matter Providing the bluewine service: managing your wines and labels, experiences and bookings, cellar records, members and trade clients, through the modules you activate.
Duration For as long as your account is active, plus the deletion periods in section 10.
Nature & purpose Storage, organisation, retrieval, display, transmission by email, backup and deletion — solely to operate the service.
Categories of data subject Your guests and visitors; your wine club members; your trade clients (restaurants, importers, wine shops) and their contact persons; your staff and collaborators.
Categories of personal data Names, email addresses, phone numbers, messages and requests, booking and tasting details, wine club membership details, order and price-list data for trade clients, company names and VAT numbers. Access data for the people you invite (name, email, role, permissions).
Special categories Not requested by the service. You should not enter health, biometric or other special-category data into free-text fields.
Children The service is not directed at children, and alcohol-related services should not be offered to minors. You remain responsible for any age verification required by the law that applies to you.

4. Our obligations

We undertake to:

  1. process personal data only on your documented instructions, including for transfers outside the EU/EEA, unless required otherwise by EU or Member State law — in which case we inform you first, unless that law forbids it;
  2. inform you if, in our opinion, an instruction infringes the GDPR or other data protection law;
  3. ensure that everyone authorised to process the data is bound by an appropriate duty of confidentiality;
  4. implement the technical and organisational measures set out in section 6 (Art. 32 GDPR);
  5. respect the conditions for engaging sub-processors in section 7;
  6. assist you, by appropriate technical and organisational measures, in responding to data subject requests (section 8);
  7. assist you in complying with Articles 32–36 GDPR — security, breach notification (section 9), data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to us;
  8. delete or return the data at the end of the service, as you choose (section 10);
  9. make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits (section 11);
  10. never sell your data, never use it for advertising, and never use it to train artificial intelligence models.

5. Your obligations

As controller you undertake to: have a lawful basis for the data you process through bluewine; give your guests a privacy notice covering it; enter only data that is relevant and limited to what is necessary; set retention periods that comply with the tax, food-labelling and traceability rules that apply to your production; keep your account credentials secure; grant access to co-hosts, managers and accountants only to what they actually need; and give us instructions that comply with data protection law.

6. Security measures

Taking into account the state of the art, the costs of implementation and the risks involved, we apply at least the following measures. We may update them, provided the level of security is not reduced.

Encryption and access

Resilience and monitoring

What we do not do

We do not store payment card numbers; payments, where active, are handled by a specialised provider. We do not access the content of your account except where you ask us to, for technical support, or where strictly necessary to restore the service.

7. Sub-processors

You give us general written authorisation to engage sub-processors. We impose on each of them, by contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

Our current sub-processors are:

Sub-processorPurposeData processedLocation
SupabaseDatabase, authentication, file storage All account and guest data you enterEU — Frankfurt, Germany
CloudflareHosting, CDN, DNS, WAF, web analytics Traffic metadata, IP addresses in transitGlobal CDN, EU entity
ResendTransactional email (notifications, invitations, password reset) Recipient email address and message contentUSA — SCCs / DPF
Google Analytics 4Aggregated website statistics (marketing pages) Anonymous usage data; cookies only after consentUSA — SCCs / DPF
FormspreePublic contact form on our marketing pages only Name, email and message of whoever contacts us — never guest dataUSA — SCCs

We will give account owners at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, you may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees.

8. Data subject requests

Requests from guests or other data subjects go to you, as controller. The panel lets you view, correct, export and delete individual records yourself, which will normally be enough to satisfy a request without our involvement.

If a data subject contacts us directly about your data, we will not respond on the merits: we will tell them to contact you and, where we can identify you, inform you without undue delay. Where you still need our help, we will assist you at no charge for reasonable requests.

9. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting data we process for you — comfortably inside the 72 hours you have to notify your supervisory authority under Article 33.

The notification will describe, as far as known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where we cannot provide everything at once, we will send it in phases without further undue delay. We will keep a record of breaches and assist you in meeting your own notification duties.

10. Return and deletion of data

While the account is active, you can export all of your data at any time from the panel, in open formats (JSON, CSV).

On termination, at your choice, we will return or delete the data. In practice: your account remains accessible for export for 30 days after the subscription ends; after that period the data is permanently deleted from the live systems, and from backups within the ordinary backup rotation of our infrastructure provider, which does not exceed a further 30 days.

Trial accounts follow the cycle described in our Terms: 14-day trial, then a 30-day locked grace period, then permanent deletion of the account and all its data.

We will not retain a copy except where EU or Member State law requires it, in which case we will tell you what we must keep and for how long. On request, we will confirm deletion in writing.

11. Audits and information

On reasonable written request, and no more than once per year (unless a breach or a supervisory authority requires otherwise), we will provide the information necessary to demonstrate compliance with Article 28: a description of our security measures, our sub-processor list, and answers to a reasonable security questionnaire.

Where that is genuinely not sufficient for your own compliance, you (or an independent auditor bound by confidentiality, and not a competitor of ours) may audit the processing, with at least 30 days’ notice, during business hours, without disrupting the service and without accessing the data of other customers. You bear the cost of the audit unless it reveals a material breach of this DPA on our part.

12. International transfers

Your operational data — accounts, bookings, guests, documents — is stored in the EU (Frankfurt, Germany) and is not transferred outside it as part of normal operation.

The limited transfers that do occur are listed in section 7: transactional email and analytics. They rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914) and, where the recipient is certified, the EU–US Data Privacy Framework, together with supplementary measures where appropriate. Where the SCCs apply, they are incorporated into this DPA by reference, with you as data exporter and the recipient as data importer, and this DPA supplies the detail required by their Annexes (sections 3, 6 and 7 above).

13. Liability, duration and law

This DPA takes effect when you start using bluewine and lasts as long as we process personal data on your behalf; sections 9, 10 and 11 survive its termination for as long as needed.

Each party is liable for its own breaches of applicable data protection law. Any limitation of liability agreed in the Terms of Service applies to this DPA as well, except where the law does not permit it — nothing here limits a data subject’s rights under Article 82 GDPR, or either party’s liability for fraud, wilful misconduct or gross negligence.

This DPA is governed by Greek law, without prejudice to any mandatory provision of the GDPR or of the law of the data subject’s country of residence. Our supervisory authority is the Hellenic Data Protection Authority, dpa.gr.

14. Contact and version history

Questions about this DPA, requests for a countersigned copy, audit requests and security questionnaires: [email protected].

VersionDateChange
1.0September 2026First version.

© 2026 Wise in Blue · Privacy, Cookies & Terms · Cookie policy · wiseinblue.com