Data Processing Agreement (DPA)
Last updated: July 2026
This Data Processing Agreement (hereinafter the « DPA ») is entered into between CaveauFlow (SASU, company number 107 484 222, Paris Trade and Companies Register), acting as a processor within the meaning of article 28 of the GDPR, and the Customer, acting as the controller.
This DPA forms an integral part of the Terms of Sale. It takes effect on the date the CaveauFlow subscription is taken out and remains in force for the whole term of the contract.
1. Definitions
| Controller | The Customer (restaurant, hotel, wine merchant, etc.) who determines the purposes and means of the processing of their business data. |
| Processor | CaveauFlow, which processes personal data on behalf of and on the instructions of the Controller. |
| Data processed | Any personal data contained in the imported files (supplier listings, stock counts) or entered into CaveauFlow by the Customer. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. |
| Data breach | Any breach of security leading to the accidental or unlawful destruction, loss, alteration, disclosure of, or unauthorised access to, personal data. |
2. Roles of the parties
In connection with the use of CaveauFlow, the parties have the following roles:
| Processing | Controller | Processor |
|---|---|---|
| Customer account data (name, email, restaurant profile) | CaveauFlow | — |
| Billing and payments | CaveauFlow | Stripe (sub-processor) |
| Business data imported by the Customer (listings, stock counts, supplier contacts) | The Customer | CaveauFlow |
| AI analysis of imported documents | The Customer | CaveauFlow (via Anthropic, sub-processor) |
| Wine lists created and shared publicly | The Customer | CaveauFlow |
CaveauFlow is the controller for its own management data (account, billing). CaveauFlow is the processor for the Customer's business data (listings, stock counts, etc.).
3. Nature, purposes and duration of the processing
Nature of the operations: collection, storage, structuring, consultation, automated analysis (AI), retrieval, transmission and deletion.
Purposes: provision of the CaveauFlow service as described in the Terms of Use: imports, stock counts, wine lists, supplier orders.
Categories of data processed on behalf of the Customer:
- Product and reference data (names, prices, suppliers)
- Stock data (stock levels, quantities, dates)
- Imported supplier files (PDF, Excel)
- Information about suppliers (names, contacts, terms)
- Wine lists and their content
Data subjects: the Customer's staff using the platform, and the suppliers listed.
Duration: for the whole term of the contract + 30 days after termination (see article 8 of the Terms of Sale).
4. Instructions of the controller
CaveauFlow processes the Customer's data solely on the Customer's documented instructions, as expressed through normal use of the service (imports, data entry, document generation).
If CaveauFlow considers that an instruction from the Customer infringes the GDPR or any other applicable legal provision, CaveauFlow will inform the Customer immediately in writing. CaveauFlow may then suspend the execution of the instruction until it is confirmed or corrected by the Customer.
CaveauFlow does not use the Customer's data for purposes other than providing the contractually agreed service, save where required by law.
5. CaveauFlow's obligations (processor)
CaveauFlow undertakes to:
- Process the data only for the purposes set out in this DPA
- Ensure that persons authorised to process the data are bound by an appropriate confidentiality obligation
- Implement the security measures described in article 6 of this DPA
- Not engage a sub-processor without informing the Customer (see article 7)
- Assist the Customer in responding to requests from data subjects exercising their rights
- Assist the Customer in meeting their GDPR obligations (security, breach notification, DPIA)
- Delete or return all data at the end of the contract, as the Customer chooses
- Make available to the Customer all the information necessary to demonstrate compliance with this DPA
6. Security measures
In accordance with article 32 of the GDPR, CaveauFlow implements the following technical and organisational measures to ensure a level of security appropriate to the risk:
| Category | Measures |
|---|---|
| Encryption | TLS 1.3 in transit, AES-256 at rest (Supabase/AWS) |
| Access control | JWT authentication, Row Level Security (RLS) per customer, restricted production access |
| Data isolation | Each customer has an isolated data space, with no data crossing between customers |
| Availability | Daily backups, 30-day retention, redundant AWS infrastructure |
| Incident management | Anomaly detection, 72-hour breach notification procedure (art. 33 GDPR) |
| Sub-processing | DPAs signed with all sub-processors (Anthropic, Vercel, Stripe, Resend) |
| Testing and reviews | Security review of the code before deployment to production |
7. Sub-processors
The Customer authorises CaveauFlow to use the following sub-processors to provide the service. CaveauFlow imposes on those sub-processors data protection obligations equivalent to those in this DPA.
| Sub-processor | Service | Country | Safeguards |
|---|---|---|---|
| Supabase / AWS | Database, storage, authentication | EU (Paris) | Within the EU |
| Vercel Inc. | Application hosting | USA | EC SCCs 2021/914 |
| Anthropic PBC | AI analysis of documents | USA | EC SCCs + API DPA |
| Stripe Inc. | Payments (billing data only) | USA / EU | EC SCCs + PCI-DSS |
| Resend Inc. | Transactional emails | USA | EC SCCs 2021/914 |
If a new sub-processor is added, CaveauFlow will inform the Customer by email with 30 days' notice. The Customer may object within that period on legitimate grounds. Failing an objection within that period, the new sub-processor is deemed accepted.
8. Rights of data subjects
CaveauFlow makes available to the Customer the features needed to allow the Customer to respond to requests from data subjects exercising their rights (access, rectification, erasure, portability).
If a data subject sends their request directly to CaveauFlow, CaveauFlow will forward the request to the Customer within 5 business days, without acting on it itself, unless the Customer instructs otherwise.
The data subjects of the business data processed in CaveauFlow remain the data subjects of the Customer (the controller). The Customer is solely responsible for responding to their requests.
9. Notification of data breaches
In the event of a personal data breach within the meaning of article 4(12) of the GDPR, CaveauFlow will notify the Customer within 48 hours of becoming aware of it, by email to the address registered in the account.
The notification will contain at least:
- The nature of the breach and the categories of data concerned
- The approximate number of people and records concerned
- The likely consequences of the breach
- The measures taken or planned to address the breach
- The name and contact details of the point of contact
It is then for the Customer (the controller) to assess the obligation to notify the CNIL (art. 33 GDPR) and the data subjects (art. 34 GDPR). CaveauFlow will provide assistance in that process.
10. Audit and documentation
On written request and within 15 business days, CaveauFlow will make available to the Customer the information necessary to demonstrate compliance with this DPA.
The Customer may, at their own expense and with 30 days' notice, appoint an independent auditor to verify compliance with this DPA. The audit is subject to a prior confidentiality agreement and must not disrupt the normal operation of the service. CaveauFlow may refuse the audit if it can demonstrate its compliance through equivalent third-party certifications or audit reports.
11. Return and deletion of data
At the end of the contract (termination or expiry), the Customer may ask CaveauFlow for:
- The return of the data in a structured and readable format (CSV, JSON), within 5 business days of the request.
- The secure deletion of all the Customer's data in CaveauFlow's systems, within 30 days of the end of the contract.
CaveauFlow will confirm in writing that the data has been destroyed, save where a legal obligation requires longer retention (billing data: 10 years). Technical backups are purged within 90 days.
12. Changes to the DPA
CaveauFlow may amend this DPA to reflect legal or regulatory developments, or changes in the organisation of the processing. Any substantial change is notified to the Customer with 30 days' notice. Continuing to use the service after that period constitutes acceptance.
13. Governing law
This DPA is governed by French law and the GDPR. Any dispute relating to its interpretation or performance will be subject to the same jurisdiction rules as the Terms of Sale.
