Vinius Data Processing Agreement

    Version: 1.0
    Effective Date: September 21, 2026
    Last updated: August 19, 2026

    This Data Processing Agreement ("DPA") governs Vinius's processing of personal data on behalf of your organization. It forms part of the Vinius Terms and Conditions and applies where Vinius acts as processor and your organization acts as controller, as described in clause 5.6 of the Terms.

    If you have signed a separate negotiated data processing agreement with Vinius, that agreement controls to the extent of any conflict.

    Terms defined in the Terms and Conditions have the same meaning here. "GDPR" means Regulation (EU) 2016/679. "Customer Data" means personal data that you or your users upload to, or generate within, the Platform and for which you are the controller.

    1. Roles of the parties

    You act as controller for Customer Data. Vinius acts as processor for Customer Data and processes it only on your documented instructions.

    Where Vinius determines the purposes and means of processing itself, Vinius acts as an independent controller and this DPA does not apply. Those purposes are set out in Section 1 of the Privacy Policy and include account administration, platform security, fraud prevention, billing, product development, and Aggregated Market Insight. Aggregated Market Insight is described in Section 7 of the Privacy Policy and clause 5.4 of the Terms, and is subject to an unconditional opt-out.

    Where you and Vinius are each independent controllers for the same data, neither party is a joint controller with the other unless expressly agreed in writing.

    2. Subject matter and duration

    The subject matter of the processing is the provision of the Platform to you under the Terms. Processing continues for the duration of your subscription, plus the export and deletion periods described in Section 9.

    The nature, purpose, categories of data subject, and categories of personal data are set out in Annex I.

    3. Your instructions

    Vinius processes Customer Data only on your documented instructions, including with regard to international transfers, unless required otherwise by Union or Member State law. Where such a legal requirement applies, Vinius will inform you before processing unless that law prohibits it on important grounds of public interest.

    Your use of the Platform, together with the Terms and this DPA, constitutes your complete and final documented instructions. Additional instructions outside that scope require separate written agreement and may be subject to a fee.

    Vinius will inform you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

    4. Confidentiality

    Vinius ensures that persons authorised to process Customer Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and are subject to appropriate training on their responsibilities.

    Access to Customer Data is granted on a least-privilege basis and only to personnel who require it to provide, support, or secure the Platform.

    5. Security

    Vinius implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

    Those measures are described in Annex II. Vinius may update them over time provided the level of security is not materially reduced.

    6. Sub-processing

    You give Vinius general written authorisation to engage sub-processors, subject to this section.

    Vinius maintains a current list of sub-processors identifying each one, its purpose, the categories of personal data it receives, its location, and the applicable transfer safeguard. The list in force at the effective date of this DPA is reproduced in Annex III.

    Before adding or replacing a sub-processor, Vinius will give you at least 30 days' notice by email and by updating the sub-processor list. You may object on reasonable data protection grounds within that period. If you object and the parties cannot agree a resolution, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the unexpired term.

    Vinius imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA. Vinius remains fully liable to you for the performance of each sub-processor's obligations.

    7. Assistance with data subject rights

    Taking into account the nature of the processing, Vinius assists you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

    The Platform provides self-service functionality for access, correction, export, and deletion of Customer Data. Where a request cannot be fulfilled through that functionality, Vinius will provide reasonable assistance on request.

    If Vinius receives a request from a data subject relating to Customer Data, it will not respond directly except to confirm receipt and direct the data subject to you, and will inform you of the request without undue delay.

    8. Assistance with security, breach notification, and impact assessments

    Vinius assists you, taking into account the nature of processing and the information available to it, in complying with your obligations under Articles 32 to 36 GDPR.

    Personal data breach. Vinius notifies you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Vinius will provide further information as it becomes available.

    Impact assessments. Vinius provides reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, where these relate to processing of Customer Data by Vinius.

    9. Return and deletion

    On termination of your subscription, and at your choice, Vinius will delete or return Customer Data.

    • For 30 days after termination you may request an export of your inventory, lot, supplier, order, and transaction records in a structured, commonly used, machine-readable format. Vinius will provide it within 14 days of a valid request at no charge.
    • After that period Vinius will delete Customer Data, including from backups in accordance with its backup rotation schedule, unless retention is required by Union or Member State law.

    Data that has been anonymised so that it can no longer be attributed to a data subject, including data incorporated into published Aggregated Market Insight, is not Customer Data and is not subject to this section.

    10. Audits and information

    Vinius makes available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.

    In practice this means:

    • Vinius will respond to a reasonable written security and privacy questionnaire once per twelve-month period at no charge
    • Vinius will provide any third-party audit reports or certifications it holds, on request
    • Where the above is insufficient to demonstrate compliance, you may conduct an on-site audit on 30 days' written notice, no more than once per twelve-month period, during business hours, subject to confidentiality obligations and without unreasonable disruption. You bear your own costs, and Vinius's reasonable costs where the audit exceeds one working day
    • Where a supervisory authority requires an audit, the frequency and notice limits above do not apply

    11. International transfers

    Vinius hosts the Platform and stores Customer Data in the European Union.

    Hosting and AI inference are both contracted with EU-established entities, so those two do not involve a transfer outside the EEA at this level.

    Where a sub-processor processes Customer Data outside the EEA, Vinius relies on an appropriate transfer mechanism under Chapter V GDPR, being Standard Contractual Clauses, the EU-US Data Privacy Framework where the recipient is certified, or another lawful mechanism. The applicable mechanism for each sub-processor is recorded in the sub-processor list.

    Where the EU Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.

    12. Liability

    Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except where those limitations cannot lawfully be applied to liability under data protection law.

    13. Term and changes

    This DPA takes effect on the effective date above and continues for as long as Vinius processes Customer Data on your behalf.

    Vinius may update this DPA where required by a change in law, a decision of a supervisory authority, or a change in its sub-processors or security measures. Material changes are subject to the notice and rejection rights in clause 18 of the Terms.

    14. Contact

    • Data protection: privacy@govinius.com
    • Data Protection Officer: bruno@govinius.com
    • Vinius V.O.F., Kattendansstraat 82, 3500 Hasselt, Belgium. VAT BE 1021.970.422
    • Lead supervisory authority: Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données)

    Annex I: Details of processing

    Nature and purpose of processing

    Provision of the Vinius platform, being a wine operating system for hospitality businesses and collectors. This includes inventory and lot management, stock movements and audit trails, pricing and margin calculation, wine list and wine card generation, procurement and reorder workflows, POS and third-party integrations, AI-assisted data enrichment, club and community features, messaging, and analytics presented to you about your own operation.

    Duration

    For the term of the subscription, plus the export and deletion periods in Section 9.

    Categories of data subject

    • Your personnel and authorised users, including staff, managers, and administrators
    • Your club members and customers, where you record them in the Platform
    • Your business contacts at suppliers, distributors, and other counterparties
    • Individuals identified within content you upload

    Categories of personal data

    • Identity and contact data: name, email address, telephone number, job role
    • Account and authentication data: user identifiers, hashed credentials, roles, permissions, access scopes
    • Organizational data: organization name, address, VAT identifier, billing contact, site assignments
    • Operational data: user actions recorded in audit logs and stock movement history, attributable to a named user
    • Content data: tasting notes, reviews, comments, messages, images, and other user-generated content
    • Commercial data: supplier and customer contact records, order records, and transaction history
    • Technical data: IP address, device and browser identifiers, timestamps, log data

    Special categories of personal data

    None are required by the Platform, and Vinius does not request them. You should not upload special category data. If you do, you remain controller for it and are responsible for the lawful basis and any additional conditions under Article 9 GDPR.


    Annex II: Technical and organisational measures

    Vinius applies the following measures. They are described honestly as implemented, not as aspiration.

    Access control

    • Role-based access control with organization and site level scoping, enforced at the API boundary
    • Least-privilege access for personnel; production access limited to those who require it
    • Authentication and identity managed through a dedicated identity provider, supporting SSO
    • API access governed by scoped tokens with enforced permission checks

    Encryption

    • Personal data encrypted in transit using TLS
    • Data at rest encrypted by the hosting provider at the storage layer

    Segregation

    • Customer Data logically segregated by organization, with authorization enforced on every organization-scoped and site-scoped operation
    • Separate production and non-production environments; production data is not used in development

    Logging and monitoring

    • Audit logging of security-relevant and data-modifying events, including the acting user
    • Application and infrastructure logging retained for operational and security review

    Resilience and recovery

    • Managed PostgreSQL with automated backups operated by the hosting provider
    • Object storage with provider-level durability guarantees

    Organisational measures

    • Confidentiality obligations for all personnel with access to Customer Data
    • Written agreements with all sub-processors imposing equivalent obligations
    • Documented breach response procedure with a 48-hour customer notification commitment
    • Documented data subject request procedure
    • Record of processing activities maintained

    Data residency

    Application hosting, PostgreSQL, object storage, and cache are located in the European Union (France). The hosting region is fixed by agreement with the hosting provider and is not subject to unilateral relocation outside the EEA.


    Annex III: Sub-processors

    The authoritative and current list is published at govinius.com/sub-processors. The list in force at the effective date of this DPA is:

    Sub-processorPurposePersonal data processedLocation
    DeltaBlue NV, on OVHcloud infrastructureApplication hosting, PostgreSQL database, object storage, cacheAll Customer Data stored in or processed by the PlatformFrance, EU
    OpenAI Ireland LtdAI inference for the AI Sommelier and data enrichment featuresPrompt content submitted by the user, which may include free text and wine context. Not used to train or improve OpenAI modelsIreland, EU
    WorkOS, Inc.Authentication and identity, including login, SSO, and organization membershipEmail address, name, authentication identifiers, organization membershipUnited States
    Resend (Plus Five Five, Inc.)Transactional and lifecycle email deliveryEmail address, name, message contentUnited States

    No analytics, advertising, or marketing trackers are loaded by the Platform, so there are no advertising or analytics sub-processors.