Version 1.0 — in force from September 2026. Applies to every bluewine customer as part of the Terms of Service.
This Data Processing Agreement (the “DPA”) is entered into between:
It forms part of the Terms of Service for bluewine and governs any processing of personal data that we carry out on your behalf. It applies to the extent that the GDPR (Regulation (EU) 2016/679), or a national law implementing it, applies to that processing. Where this DPA and the Terms of Service conflict on a matter of data protection, this DPA prevails.
We update this DPA when what we actually do changes. Material changes are announced by email to account owners at least 30 days before they take effect, and every version keeps its own version number and date.
You are the data controller of the personal data you and your guests enter into bluewine. You decide what to collect, why, for how long, and you are responsible for having a lawful basis and for giving your guests their own privacy notice.
We are the data processor. We process that data only on your documented instructions — which, in practice, are: operating the service you subscribed to, and any specific written request you send us. We do not use your data for our own purposes.
We act as an independent controller only for the limited data we need as a business: your account and billing details, and aggregated, anonymous usage statistics that cannot identify an individual. That processing is described in our Privacy, Cookies & Terms, not here.
| Item | Detail |
|---|---|
| Subject matter | Providing the bluewine service: managing your wines and labels, experiences and bookings, cellar records, members and trade clients, through the modules you activate. |
| Duration | For as long as your account is active, plus the deletion periods in section 10. |
| Nature & purpose | Storage, organisation, retrieval, display, transmission by email, backup and deletion — solely to operate the service. |
| Categories of data subject | Your guests and visitors; your wine club members; your trade clients (restaurants, importers, wine shops) and their contact persons; your staff and collaborators. |
| Categories of personal data | Names, email addresses, phone numbers, messages and requests, booking and tasting details, wine club membership details, order and price-list data for trade clients, company names and VAT numbers. Access data for the people you invite (name, email, role, permissions). |
| Special categories | Not requested by the service. You should not enter health, biometric or other special-category data into free-text fields. |
| Children | The service is not directed at children, and alcohol-related services should not be offered to minors. You remain responsible for any age verification required by the law that applies to you. |
We undertake to:
As controller you undertake to: have a lawful basis for the data you process through bluewine; give your guests a privacy notice covering it; enter only data that is relevant and limited to what is necessary; set retention periods that comply with the tax, food-labelling and traceability rules that apply to your production; keep your account credentials secure; grant access to co-hosts, managers and accountants only to what they actually need; and give us instructions that comply with data protection law.
Taking into account the state of the art, the costs of implementation and the risks involved, we apply at least the following measures. We may update them, provided the level of security is not reduced.
We do not store payment card numbers; payments, where active, are handled by a specialised provider. We do not access the content of your account except where you ask us to, for technical support, or where strictly necessary to restore the service.
You give us general written authorisation to engage sub-processors. We impose on each of them, by contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
Our current sub-processors are:
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account and guest data you enter | EU — Frankfurt, Germany |
| Cloudflare | Hosting, CDN, DNS, WAF, web analytics | Traffic metadata, IP addresses in transit | Global CDN, EU entity |
| Resend | Transactional email (notifications, invitations, password reset) | Recipient email address and message content | USA — SCCs / DPF |
| Google Analytics 4 | Aggregated website statistics (marketing pages) | Anonymous usage data; cookies only after consent | USA — SCCs / DPF |
| Formspree | Public contact form on our marketing pages only | Name, email and message of whoever contacts us — never guest data | USA — SCCs |
We will give account owners at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, you may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees.
Requests from guests or other data subjects go to you, as controller. The panel lets you view, correct, export and delete individual records yourself, which will normally be enough to satisfy a request without our involvement.
If a data subject contacts us directly about your data, we will not respond on the merits: we will tell them to contact you and, where we can identify you, inform you without undue delay. Where you still need our help, we will assist you at no charge for reasonable requests.
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting data we process for you — comfortably inside the 72 hours you have to notify your supervisory authority under Article 33.
The notification will describe, as far as known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where we cannot provide everything at once, we will send it in phases without further undue delay. We will keep a record of breaches and assist you in meeting your own notification duties.
While the account is active, you can export all of your data at any time from the panel, in open formats (JSON, CSV).
On termination, at your choice, we will return or delete the data. In practice: your account remains accessible for export for 30 days after the subscription ends; after that period the data is permanently deleted from the live systems, and from backups within the ordinary backup rotation of our infrastructure provider, which does not exceed a further 30 days.
Trial accounts follow the cycle described in our Terms: 14-day trial, then a 30-day locked grace period, then permanent deletion of the account and all its data.
We will not retain a copy except where EU or Member State law requires it, in which case we will tell you what we must keep and for how long. On request, we will confirm deletion in writing.
On reasonable written request, and no more than once per year (unless a breach or a supervisory authority requires otherwise), we will provide the information necessary to demonstrate compliance with Article 28: a description of our security measures, our sub-processor list, and answers to a reasonable security questionnaire.
Where that is genuinely not sufficient for your own compliance, you (or an independent auditor bound by confidentiality, and not a competitor of ours) may audit the processing, with at least 30 days’ notice, during business hours, without disrupting the service and without accessing the data of other customers. You bear the cost of the audit unless it reveals a material breach of this DPA on our part.
Your operational data — accounts, bookings, guests, documents — is stored in the EU (Frankfurt, Germany) and is not transferred outside it as part of normal operation.
The limited transfers that do occur are listed in section 7: transactional email and analytics. They rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914) and, where the recipient is certified, the EU–US Data Privacy Framework, together with supplementary measures where appropriate. Where the SCCs apply, they are incorporated into this DPA by reference, with you as data exporter and the recipient as data importer, and this DPA supplies the detail required by their Annexes (sections 3, 6 and 7 above).
This DPA takes effect when you start using bluewine and lasts as long as we process personal data on your behalf; sections 9, 10 and 11 survive its termination for as long as needed.
Each party is liable for its own breaches of applicable data protection law. Any limitation of liability agreed in the Terms of Service applies to this DPA as well, except where the law does not permit it — nothing here limits a data subject’s rights under Article 82 GDPR, or either party’s liability for fraud, wilful misconduct or gross negligence.
This DPA is governed by Greek law, without prejudice to any mandatory provision of the GDPR or of the law of the data subject’s country of residence. Our supervisory authority is the Hellenic Data Protection Authority, dpa.gr.
Questions about this DPA, requests for a countersigned copy, audit requests and security questionnaires: [email protected].
| Version | Date | Change |
|---|---|---|
| 1.0 | September 2026 | First version. |
© 2026 Wise in Blue · Privacy, Cookies & Terms · Cookie policy · wiseinblue.com