Back

Data Processing Agreement

Data Processing Agreement (DPA) — Article 28 GDPR

Last updated: 24 September 2026 · Version 1.0

This DPA is incorporated by reference in the Terms of Service (Section 4.5) and is accepted together with them; no separate signature is required. A countersigned copy is available on request at legal@cepaos.com.

1. Parties and Definitions

This Data Processing Agreement ("DPA", "Agreement") is entered into between:

  • Data Processor: cepaos LLC, a limited liability company incorporated in the State of Wyoming, United States, with registered address at 1021 E Lincolnway, Suite 10026, Cheyenne, WY 82001 ("cepaos").
  • Data Controller: the legal or natural person that contracts the cepaos Service ("the Client"), as identified during the Platform registration process.

This DPA forms an integral part of the Terms of Service and any applicable service agreement between the parties. In the event of a conflict regarding data protection matters, this DPA shall prevail.

1.1 Definitions

  • "Personal Data": any information relating to an identified or identifiable natural person, as defined by the data protection law applicable to the Client (including Regulation (EU) 2016/679 — GDPR —, Argentine Law 25.326, Brazilian Law 13.709/2018 — LGPD — and the other laws listed in Section 12 of the Terms of Service).
  • "Processing": any operation performed on personal data.
  • "Sub-processor": a third party authorised by cepaos to process Personal Data on behalf of the Client.
  • "Security Breach": a breach of security leading to the unauthorised destruction, loss, alteration, disclosure of, or access to Personal Data.
  • "Standard Contractual Clauses" (SCCs): model clauses approved by the European Commission for international data transfers to third countries.

2. Categories of Personal Data Processed

cepaos processes the following Personal Data on behalf of the Client:

CategoryData typesAffected data subjects
Identification dataFull name, email, role within the organisationEmployees and users of the Client
Access dataIP address, session timestamps, activity logsPlatform users
Operational dataProduction records, inventories, batches, harvests, cellar movementsClient Organisation
Billing dataTax ID, company name, fiscal address, payment referenceClient billing representative
Commercial contact dataName, email, telephoneClient administrative staff

cepaos does not process special categories of data (health data, ethnic origin, political affiliation, religion, biometrics, etc.) unless expressly instructed in writing by the Client.

3. Purposes of Processing

cepaos processes Personal Data solely for the following purposes:

  • Service Provision: operation of the SaaS winery management Platform.
  • Technical Support: incident diagnosis and resolution.
  • Billing: management of charges and subscriptions.
  • Security: prevention of unauthorised access, anomaly detection, and auditing.
  • Legal Compliance: responding to requests from competent authorities.

cepaos will not use the Client's Personal Data for its own purposes, including advertising, market analysis, or training of artificial intelligence models.

4. Client Instructions

cepaos processes Personal Data solely in accordance with the Client's documented instructions. If cepaos considers that an instruction infringes applicable regulations, it will immediately notify the Client in writing.

A documented instruction of the Client includes, in particular, the invitation, permission configuration, and revocation of external consultant access managed by the Client through the Platform. The external consultant invited by the Client is a recipient authorised by the Client in its capacity as data controller, and not a Sub-processor of cepaos for the purposes of clause 5. cepaos keeps a record of each invitation, acceptance, and revocation.

5. Authorised Sub-processors

The Client authorises cepaos to use the following Sub-processors:

Sub-processorFunctionCountryTransfer basis
Stripe, Inc.Payment processing (non-LATAM markets, including Portugal)United States (Ireland for EU customers)SCC + EU-U.S. DPF
Dlocal LLPPayment processing (LATAM: AR, BR, CL, MX, UY)United Kingdom (contracting entity, England and Wales); processing also in the countries where dLocal operates, incl. local acquirers in the payer's countryEU adequacy decision (UK, 2021/1772) + SCC
Supabase, Inc.Managed PostgreSQL database, authentication and object storageBrazil (AWS sa-east-1, São Paulo)EU adequacy decision (Brazil, 2026/179) + SCC
Resend, Inc.Transactional email deliveryUnited StatesSCC
Sentry (Functional Software, Inc.)Application error monitoring (with PII scrubbing)United StatesSCC
Cloudflare, Inc.CDN, DNS and DDoS protectionGlobal edge network (anycast)SCC + EU-U.S. DPF
Amazon Web Services, Inc.Underlying infrastructure (via Supabase) and selected archival storageBrazil (sa-east-1, São Paulo) — underlying the Supabase databaseEU adequacy decision (Brazil, 2026/179) + SCC
Upstash, Inc.Redis cache and rate-limitingEuropean Union (AWS eu-central-1, Frankfurt)Within EU/EEA
Anthropic, PBCLarge Language Model API for AI-assisted features (e.g. compliance watchdog summarisation)United StatesSCC
Railway Corp.Application hosting and deployment platformUnited States (us-west2)SCC
PostHog, Inc.Product analytics and feature flag deliveryEuropean Union (eu.i.posthog.com, Frankfurt)Within EU/EEA
Google LLC (Google Analytics 4)Web/product analytics and conversion tracking (client-side + server-side Measurement Protocol)United StatesSCC + EU-U.S. DPF
ZeroBounce LLCEmail validation (deliverability checks of lead and user email addresses)United StatesSCC
Loops, Inc.Marketing & lifecycle email (onboarding sequences and campaigns)United StatesSCC
Qik Innovations Pvt Ltd (OpenSign)Electronic signature platform for B2B contracts, NDAs and one-shot business documents (ad-hoc use)India (hosted SaaS at opensignlabs.com; EU instance at eu-app.opensignlabs.com — residency not contractually guaranteed)SCC (pending signature)

Upcoming sub-processors

Sub-processorFunctionCountryTransfer basis
Groq LLC
Effective from October 25, 2026
Speech-to-text transcription of voice notes (server-side dictation)United StatesSCC

cepaos will notify the Client at least 30 days in advance before adding a new Sub-processor.

6. Technical and Organisational Measures (TOM)

6.1 Technical Measures

  • Encryption in transit: HTTPS/TLS 1.2+ for all communications.
  • Encryption at rest: AES-256 for data stored in Supabase.
  • Tenant isolation: Row Level Security (RLS) in PostgreSQL.
  • Authentication: short-lived JWT tokens (Supabase Auth), MFA support.
  • Access control: principle of least privilege.
  • Backups: automatic backups every 24 hours, 30-day retention.
  • Monitoring: real-time security alerts (Sentry + internal logs).
  • Pseudonymisation: active PII scrubbing in Sentry.

6.2 Organisational Measures

  • Internal security policy: documented procedures.
  • Staff training: data protection awareness training.
  • Confidentiality: all staff bound by confidentiality obligations.
  • Incident management: documented response protocol with defined timelines.
  • Periodic assessments: annual security review and updates.

7. Data Subject Rights

cepaos will cooperate with the Client to facilitate the exercise of data subject rights under the applicable law (GDPR Articles 15 to 22, ARCO rights under Argentine Law 25.326, LGPD Article 18 and equivalent rights).

Maximum response time: 30 calendar days (Access), 5 business days (Rectification/Deletion). Contact: privacidad@cepaos.com.

8. International Data Transfers

cepaos LLC is established in the United States. The primary database is hosted in Brazil (Supabase, AWS sa-east-1, São Paulo); every other Sub-processor, its location and its transfer basis are listed in Section 5.

  • Brazil (primary database): Brazil benefits from a European Commission adequacy decision (Implementing Decision (EU) 2026/179); as Supabase, Inc. and Amazon Web Services, Inc. are United States entities, their Standard Contractual Clauses also apply.
  • Client → cepaos (GDPR): where the Client is subject to the GDPR, the transfer of Personal Data to cepaos LLC is governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), incorporated into this DPA by reference: Clause 9, option 2 (general written authorisation, 30 days' notice); Clause 11, optional wording not used; Clause 13, the supervisory authority of the Member State in which the Client is established; Clause 17, option 2 (law of the Member State in which the Client is established or, where that law does not allow third-party beneficiary rights, Irish law); Clause 18, the courts of that Member State. Annex I corresponds to Sections 1 to 3, Annex II to Section 6 and Annex III to Section 5 of this DPA.
  • Onward transfers: cepaos binds each Sub-processor located outside the EEA by the Standard Contractual Clauses (Module Three) or, where the Sub-processor is certified under the EU-U.S. Data Privacy Framework, by that framework, as shown in the "Transfer basis" column of Section 5. cepaos LLC itself is not certified under the EU-U.S. Data Privacy Framework.
  • Switzerland: the Standard Contractual Clauses apply with the adaptations recognised by the Federal Data Protection and Information Commissioner (FDPIC) for transfers subject to the Federal Act on Data Protection.
  • Brazil: transfers subject to the LGPD are governed by the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024.
  • United Kingdom (Dlocal LLP): Payments in Latin America are processed by Dlocal LLP (England and Wales, United Kingdom). The transfer to the United Kingdom relies on the European Commission's adequacy decision (Commission Implementing Decision (EU) 2021/1772, extended until 27 December 2031 by Implementing Decision (EU) 2025/2574). dLocal also processes payment data in the countries where it operates and through local acquirers in the payer's country; according to dLocal's privacy notice, transfers to countries without an adequacy decision are protected by EU- and UK-approved standard contractual clauses. The countries of processing may include Uruguay, which has an adequacy decision (Commission Implementing Decision 2012/484/EU).

9. Data Retention and Deletion

Data typeRetention periodAction upon expiry
Active operational dataDuration of the contractExport available in CSV/JSON
Post-cancellation data30 daysPermanent deletion
Billing records10 yearsRestricted-access retention
Security logs12 monthsAutomatic deletion
Backups30-day rotationAutomatic overwriting

10. Security Breach Notification

In the event of a security breach, cepaos will notify the Client within 72 hours. Contact: seguridad@cepaos.com.

11. Audits

cepaos will facilitate audits with 30 days' notice, maximum annual frequency, during business hours. Costs borne by the Client unless cepaos is in breach.

12. Liability and Limitation

Liability is subject to the limitations set out in the Terms of Service.

Except where the Standard Contractual Clauses provide otherwise (Clauses 17 and 18), this DPA is governed by the law, and subject to the forum, set out in Section 12 of the Terms of Service for the Client's market.

13. Contact — Privacy Officer

  • Email: privacidad@cepaos.com
  • Entity: cepaos LLC — Wyoming, United States
  • Address: 1021 E Lincolnway, Suite 10026, Cheyenne, WY 82001

These terms may be updated from time to time. The current version is the one published at cepaos.com. For legal inquiries, contact legal@cepaos.com.