Privacy policy & GDPR
Last updated: July 2026
CaveauFlow is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act no. 78-17 of 6 January 1978 as amended.
1. Data controller
CaveauFlow, a French simplified joint-stock company with a sole shareholder (SASU), company number 107 484 222 (Paris Trade and Companies Register)
Address: 47 rue Vivienne, 75002 Paris, France
Personal data contact: privacy@caveauflow.com
If you wish to exercise your rights or make a complaint, use this address. Response time: 30 calendar days.
2. Data collected
Note: CaveauFlow processes two distinct types of data. Personal data (categories a, c, d) relates to identified natural persons. Business data (category b) is mainly commercial data (product references, stock, prices) which does not necessarily constitute personal data, unless it contains information about identifiable natural persons (e.g. the name of a supplier contact).
a) Personal data: account and profile
- Surname, first name, professional email address
- Name of the restaurant / venue, type of venue
- Postal address, city, country, phone (optional)
- Venue logo (optional)
b) Business data entrusted by the Customer (may contain personal data)
- Products and references entered into the database
- Imported files (PDF/Excel supplier listings)
- Stock data (stock levels, quantities)
- Wine lists created and their content
- Supplier orders generated
- Notification and account preferences
For business data containing personal data (e.g. supplier contacts), CaveauFlow acts as a processor within the meaning of art. 28 GDPR. See the DPA.
c) Technical and connection data
- IP address, connection timestamps
- Browser type, operating system
- Application access logs
d) Billing data
- Subscription and payment history
- Billing information (managed by Stripe · CaveauFlow does not store bank card data)
3. Purposes and legal bases (art. 6 GDPR)
| Purpose of processing | GDPR legal basis |
|---|---|
| Creating and managing the user account | Performance of the contract (art. 6.1.b) |
| Providing the service (stock, wine list, imports, orders) | Performance of the contract (art. 6.1.b) |
| Billing, managing subscriptions and payments | Performance of the contract (art. 6.1.b) |
| Sending transactional emails (confirmation, alerts, reports) | Performance of the contract (art. 6.1.b) |
| AI analysis of imported documents via the Anthropic API | Performance of the contract (art. 6.1.b) |
| Monthly stock reports by email (a feature of the service) | Performance of the contract (art. 6.1.b) |
| Fraud prevention, security of the service | Legitimate interest (art. 6.1.f) |
| Improving the service (anonymised metrics) | Legitimate interest (art. 6.1.f) |
| Retention of billing data | Legal obligation (art. 6.1.c, 10 accounting years) |
| Handling requests to exercise GDPR rights | Legal obligation (art. 6.1.c) |
4. Processors and transfers outside the EU
CaveauFlow uses the following processors. Each of them is bound by a data processing agreement compliant with article 28 of the GDPR.
| Processor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Supabase / AWS | Database, authentication, storage | EU, Paris (eu-west-3) | Hosted within the EU, no transfer outside the EU |
| Vercel Inc. | Hosting, application delivery and associated technical processing (edge, logs) | USA | EC SCCs decision 2021/914 |
| Anthropic PBC | AI analysis of imported documents | USA | EC SCCs + Anthropic API DPA |
| Stripe Inc. | Payment processing and billing data | USA / EU | EC SCCs + PCI-DSS certification |
| Resend Inc. | Sending transactional emails | USA | EC SCCs decision 2021/914 |
5. Retention periods
| Category of data | Retention period | Justification |
|---|---|---|
| Active account data | Duration of the subscription | Performance of the contract |
| Inactive account data (after termination) | 30 days | Possibility of reactivation / export |
| Business data (products, stock counts, wine lists) | Subscription duration + 30 days | Performance of the contract |
| Billing data and invoices | 10 years | Statutory accounting obligation (art. L. 123-22 French Commercial Code) |
| Connection and security logs | Rolling 12 months (extended in the event of a security incident or a legal obligation) | Legitimate interest, security |
| Requests to exercise GDPR rights | 3 years | Evidence of processing, legitimate interest |
Once the periods above have expired, the data is irreversibly deleted or anonymised. Backups are purged within a maximum of 90 further days.
6. Your GDPR rights
Under articles 15 to 22 of the GDPR, you have the following rights:
| Right | Description | How to exercise it |
|---|---|---|
| Access (art. 15) | Obtain a copy of the personal data processed about you | Personal data contact |
| Rectification (art. 16) | Correct inaccurate or incomplete data about you | Account area or personal data contact |
| Erasure (art. 17) | Request the deletion of your account and your data, subject to legal retention obligations. See the box below: deleting the account is separate from terminating a paid subscription. | Account area (« Account ») or personal data contact |
| Portability (art. 20) | Export your data (products, stock counts, wine lists) in a readable format (CSV/JSON), at any time | Account area (« Account ») or personal data contact |
| Objection (art. 21) | Object to processing based on legitimate interest, giving legitimate grounds | Personal data contact |
| Restriction (art. 18) | Temporarily restrict contested processing | Personal data contact |
| Withdrawal of consent (art. 7) | Withdraw consent at any time, without affecting earlier processing | Account settings or personal data contact |
Send your request to the personal data contact: privacy@caveauflow.com stating your identity and the right exercised. Response time: 30 calendar days (which may be extended to 3 months for a complex request, with prior notice).
If the response is unsatisfactory or if there is no response, you can refer the matter to the CNIL (the French data protection authority, 3 Place de Fontenoy, 75007 Paris).
7. Data security
CaveauFlow implements the following technical and organisational measures:
- Encryption of data in transit (TLS 1.3 / HTTPS)
- Encryption of data at rest (AES-256 via Supabase/AWS)
- Secure authentication with time-limited JWT sessions
- Isolation of data per customer via Row Level Security (Supabase)
- Rate limiting on all APIs
- Daily backups with 30-day retention
- Access to production data restricted to authorised staff and logged
- Security review of the code before deployment to production
In the event of a personal data breach, CaveauFlow will notify the CNIL within 72 hours in accordance with article 33 of the GDPR, and will inform the data subjects where the risk is high (art. 34 GDPR).
8. CaveauFlow's roles depending on the data
CaveauFlow has two distinct roles under the GDPR depending on the nature of the data:
| Data | CaveauFlow's role | Applicable document |
|---|---|---|
| Account, email, billing, security | Data controller | This policy |
| Business data entrusted by the Customer (listings, stock counts, supplier contacts) | Processor (art. 28 GDPR) | CaveauFlow DPA |
In the event of a personal data breach for which CaveauFlow is the controller, CaveauFlow will notify the CNIL within 72 hours (art. 33 GDPR) and will inform the data subjects if the risk to their rights and freedoms is high (art. 34 GDPR).
In the event of a breach concerning data for which the Customer is the controller, CaveauFlow will inform the Customer within 48 hours in accordance with the DPA, and it is then for the Customer to assess their own notification obligations.
9. Cookies
For more information about cookies, see our Cookie policy.
10. Changes to this policy
This policy may be updated to reflect legal or regulatory changes, or changes in our practices. In the event of a substantial change, you will be notified by email with 30 days' notice. The version in force can always be consulted at this address, with the date it was last updated.
