Data Processing Agreement
Data Processing Agreement (DPA) — Article 28 GDPR
Last updated: 24 September 2026 · Version 1.0
This DPA is incorporated by reference in the Terms of Service (Section 4.5) and is accepted together with them; no separate signature is required. A countersigned copy is available on request at legal@cepaos.com.
1. Parties and Definitions
This Data Processing Agreement ("DPA", "Agreement") is entered into between:
- Data Processor: cepaos LLC, a limited liability company incorporated in the State of Wyoming, United States, with registered address at 1021 E Lincolnway, Suite 10026, Cheyenne, WY 82001 ("cepaos").
- Data Controller: the legal or natural person that contracts the cepaos Service ("the Client"), as identified during the Platform registration process.
This DPA forms an integral part of the Terms of Service and any applicable service agreement between the parties. In the event of a conflict regarding data protection matters, this DPA shall prevail.
1.1 Definitions
- "Personal Data": any information relating to an identified or identifiable natural person, as defined by the data protection law applicable to the Client (including Regulation (EU) 2016/679 — GDPR —, Argentine Law 25.326, Brazilian Law 13.709/2018 — LGPD — and the other laws listed in Section 12 of the Terms of Service).
- "Processing": any operation performed on personal data.
- "Sub-processor": a third party authorised by cepaos to process Personal Data on behalf of the Client.
- "Security Breach": a breach of security leading to the unauthorised destruction, loss, alteration, disclosure of, or access to Personal Data.
- "Standard Contractual Clauses" (SCCs): model clauses approved by the European Commission for international data transfers to third countries.
2. Categories of Personal Data Processed
cepaos processes the following Personal Data on behalf of the Client:
| Category | Data types | Affected data subjects |
|---|---|---|
| Identification data | Full name, email, role within the organisation | Employees and users of the Client |
| Access data | IP address, session timestamps, activity logs | Platform users |
| Operational data | Production records, inventories, batches, harvests, cellar movements | Client Organisation |
| Billing data | Tax ID, company name, fiscal address, payment reference | Client billing representative |
| Commercial contact data | Name, email, telephone | Client administrative staff |
cepaos does not process special categories of data (health data, ethnic origin, political affiliation, religion, biometrics, etc.) unless expressly instructed in writing by the Client.
3. Purposes of Processing
cepaos processes Personal Data solely for the following purposes:
- Service Provision: operation of the SaaS winery management Platform.
- Technical Support: incident diagnosis and resolution.
- Billing: management of charges and subscriptions.
- Security: prevention of unauthorised access, anomaly detection, and auditing.
- Legal Compliance: responding to requests from competent authorities.
cepaos will not use the Client's Personal Data for its own purposes, including advertising, market analysis, or training of artificial intelligence models.
4. Client Instructions
cepaos processes Personal Data solely in accordance with the Client's documented instructions. If cepaos considers that an instruction infringes applicable regulations, it will immediately notify the Client in writing.
A documented instruction of the Client includes, in particular, the invitation, permission configuration, and revocation of external consultant access managed by the Client through the Platform. The external consultant invited by the Client is a recipient authorised by the Client in its capacity as data controller, and not a Sub-processor of cepaos for the purposes of clause 5. cepaos keeps a record of each invitation, acceptance, and revocation.
5. Authorised Sub-processors
The Client authorises cepaos to use the following Sub-processors:
| Sub-processor | Function | Country | Transfer basis |
|---|---|---|---|
| Stripe, Inc. | Payment processing (non-LATAM markets, including Portugal) | United States (Ireland for EU customers) | SCC + EU-U.S. DPF |
| Dlocal LLP | Payment processing (LATAM: AR, BR, CL, MX, UY) | United Kingdom (contracting entity, England and Wales); processing also in the countries where dLocal operates, incl. local acquirers in the payer's country | EU adequacy decision (UK, 2021/1772) + SCC |
| Supabase, Inc. | Managed PostgreSQL database, authentication and object storage | Brazil (AWS sa-east-1, São Paulo) | EU adequacy decision (Brazil, 2026/179) + SCC |
| Resend, Inc. | Transactional email delivery | United States | SCC |
| Sentry (Functional Software, Inc.) | Application error monitoring (with PII scrubbing) | United States | SCC |
| Cloudflare, Inc. | CDN, DNS and DDoS protection | Global edge network (anycast) | SCC + EU-U.S. DPF |
| Amazon Web Services, Inc. | Underlying infrastructure (via Supabase) and selected archival storage | Brazil (sa-east-1, São Paulo) — underlying the Supabase database | EU adequacy decision (Brazil, 2026/179) + SCC |
| Upstash, Inc. | Redis cache and rate-limiting | European Union (AWS eu-central-1, Frankfurt) | Within EU/EEA |
| Anthropic, PBC | Large Language Model API for AI-assisted features (e.g. compliance watchdog summarisation) | United States | SCC |
| Railway Corp. | Application hosting and deployment platform | United States (us-west2) | SCC |
| PostHog, Inc. | Product analytics and feature flag delivery | European Union (eu.i.posthog.com, Frankfurt) | Within EU/EEA |
| Google LLC (Google Analytics 4) | Web/product analytics and conversion tracking (client-side + server-side Measurement Protocol) | United States | SCC + EU-U.S. DPF |
| ZeroBounce LLC | Email validation (deliverability checks of lead and user email addresses) | United States | SCC |
| Loops, Inc. | Marketing & lifecycle email (onboarding sequences and campaigns) | United States | SCC |
| Qik Innovations Pvt Ltd (OpenSign) | Electronic signature platform for B2B contracts, NDAs and one-shot business documents (ad-hoc use) | India (hosted SaaS at opensignlabs.com; EU instance at eu-app.opensignlabs.com — residency not contractually guaranteed) | SCC (pending signature) |
Upcoming sub-processors
| Sub-processor | Function | Country | Transfer basis |
|---|---|---|---|
| Groq LLC Effective from October 25, 2026 | Speech-to-text transcription of voice notes (server-side dictation) | United States | SCC |
cepaos will notify the Client at least 30 days in advance before adding a new Sub-processor.
6. Technical and Organisational Measures (TOM)
6.1 Technical Measures
- Encryption in transit: HTTPS/TLS 1.2+ for all communications.
- Encryption at rest: AES-256 for data stored in Supabase.
- Tenant isolation: Row Level Security (RLS) in PostgreSQL.
- Authentication: short-lived JWT tokens (Supabase Auth), MFA support.
- Access control: principle of least privilege.
- Backups: automatic backups every 24 hours, 30-day retention.
- Monitoring: real-time security alerts (Sentry + internal logs).
- Pseudonymisation: active PII scrubbing in Sentry.
6.2 Organisational Measures
- Internal security policy: documented procedures.
- Staff training: data protection awareness training.
- Confidentiality: all staff bound by confidentiality obligations.
- Incident management: documented response protocol with defined timelines.
- Periodic assessments: annual security review and updates.
7. Data Subject Rights
cepaos will cooperate with the Client to facilitate the exercise of data subject rights under the applicable law (GDPR Articles 15 to 22, ARCO rights under Argentine Law 25.326, LGPD Article 18 and equivalent rights).
Maximum response time: 30 calendar days (Access), 5 business days (Rectification/Deletion). Contact: privacidad@cepaos.com.
8. International Data Transfers
cepaos LLC is established in the United States. The primary database is hosted in Brazil (Supabase, AWS sa-east-1, São Paulo); every other Sub-processor, its location and its transfer basis are listed in Section 5.
- Brazil (primary database): Brazil benefits from a European Commission adequacy decision (Implementing Decision (EU) 2026/179); as Supabase, Inc. and Amazon Web Services, Inc. are United States entities, their Standard Contractual Clauses also apply.
- Client → cepaos (GDPR): where the Client is subject to the GDPR, the transfer of Personal Data to cepaos LLC is governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), incorporated into this DPA by reference: Clause 9, option 2 (general written authorisation, 30 days' notice); Clause 11, optional wording not used; Clause 13, the supervisory authority of the Member State in which the Client is established; Clause 17, option 2 (law of the Member State in which the Client is established or, where that law does not allow third-party beneficiary rights, Irish law); Clause 18, the courts of that Member State. Annex I corresponds to Sections 1 to 3, Annex II to Section 6 and Annex III to Section 5 of this DPA.
- Onward transfers: cepaos binds each Sub-processor located outside the EEA by the Standard Contractual Clauses (Module Three) or, where the Sub-processor is certified under the EU-U.S. Data Privacy Framework, by that framework, as shown in the "Transfer basis" column of Section 5. cepaos LLC itself is not certified under the EU-U.S. Data Privacy Framework.
- Switzerland: the Standard Contractual Clauses apply with the adaptations recognised by the Federal Data Protection and Information Commissioner (FDPIC) for transfers subject to the Federal Act on Data Protection.
- Brazil: transfers subject to the LGPD are governed by the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024.
- United Kingdom (Dlocal LLP): Payments in Latin America are processed by Dlocal LLP (England and Wales, United Kingdom). The transfer to the United Kingdom relies on the European Commission's adequacy decision (Commission Implementing Decision (EU) 2021/1772, extended until 27 December 2031 by Implementing Decision (EU) 2025/2574). dLocal also processes payment data in the countries where it operates and through local acquirers in the payer's country; according to dLocal's privacy notice, transfers to countries without an adequacy decision are protected by EU- and UK-approved standard contractual clauses. The countries of processing may include Uruguay, which has an adequacy decision (Commission Implementing Decision 2012/484/EU).
9. Data Retention and Deletion
| Data type | Retention period | Action upon expiry |
|---|---|---|
| Active operational data | Duration of the contract | Export available in CSV/JSON |
| Post-cancellation data | 30 days | Permanent deletion |
| Billing records | 10 years | Restricted-access retention |
| Security logs | 12 months | Automatic deletion |
| Backups | 30-day rotation | Automatic overwriting |
10. Security Breach Notification
In the event of a security breach, cepaos will notify the Client within 72 hours. Contact: seguridad@cepaos.com.
11. Audits
cepaos will facilitate audits with 30 days' notice, maximum annual frequency, during business hours. Costs borne by the Client unless cepaos is in breach.
12. Liability and Limitation
Liability is subject to the limitations set out in the Terms of Service.
Except where the Standard Contractual Clauses provide otherwise (Clauses 17 and 18), this DPA is governed by the law, and subject to the forum, set out in Section 12 of the Terms of Service for the Client's market.
13. Contact — Privacy Officer
- Email: privacidad@cepaos.com
- Entity: cepaos LLC — Wyoming, United States
- Address: 1021 E Lincolnway, Suite 10026, Cheyenne, WY 82001
These terms may be updated from time to time. The current version is the one published at cepaos.com. For legal inquiries, contact legal@cepaos.com.