WineUp is a trade name operated by Víctor Arzola, an individual sole proprietor (freelance).
Business address: 2740 Saint Paul St., Baltimore, MD 21218, United States.
This addendum is provided as a standard document. It has not been reviewed by external counsel for your specific jurisdiction; a signed, negotiated version is available on request.
1. Parties and scope
This Addendum applies between the operator of WineUp (“WineUp”) and the subscribing restaurant (“Restaurant”) and forms part of the Terms of Service. It covers personal data processed through the WineUp platform.
2. Definitions
“Personal data”, “processing”, “controller”, “processor” and “data subject” have the meaning given by applicable data-protection law. “Subprocessor” means a third party engaged by WineUp to process personal data.
3. Roles — this is not a single-role relationship
WineUp does not claim to be only a processor in every context:
- WineUp acts on the Restaurant’s documented instructions (processor-type role) for restaurant operational data: menu and wine configuration, pairing content, QR/table configuration and restaurant-specific guest-intent analytics.
- WineUp acts for its own business purposes (independent, controller-type role) for account administration, billing, fraud prevention, security, service telemetry and legal compliance.
The exact role allocation under a specific statute is reserved for attorney review; the operational commitments below apply regardless of label.
4. Subject matter, duration, nature and purpose
- Subject matter: provision of the WineUp wine-pairing and QR guest-experience platform.
- Duration: for as long as the Restaurant’s account is active, plus the retention lifecycle in §11.
- Nature and purpose: hosting, storage, extraction of menu/wine data, generation of pairing content, display to guests, analytics and support.
5. Categories of personal data and data subjects
- Restaurant owner and staff: name, email address, role, authentication data, security metadata (IP, user agent), billing contact.
- Restaurant guests: temporary session identifier, dish/wine interactions, timestamps, and technical data such as IP address and browser/device information processed to operate and secure the service. No guest name, email, phone, payment data or precise location is requested.
- No special-category data is requested or required.
6. Documented instructions
WineUp processes restaurant operational data in accordance with the Restaurant’s configuration in the dashboard, the Terms of Service, this Addendum and any additional written instruction the parties agree. WineUp informs the Restaurant if an instruction appears to conflict with applicable law.
7. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and access is granted on a least-privilege basis.
8. Security measures
WineUp implements the technical and organisational measures described on the Subprocessors & Security page, and reviews them as the service evolves.
9. Subprocessors and changes
The Restaurant authorises the subprocessors listed on the Subprocessors page. WineUp remains responsible for their performance, imposes data-protection obligations on them, and updates that page when a subprocessor is added or replaced. The Restaurant may request notice of changes and may object on reasonable data-protection grounds, in which case the parties will discuss an alternative or the Restaurant may terminate the affected service.
10. Data-subject requests
WineUp provides self-service tools (data export, deletion lifecycle, privacy request centre) and, taking into account the nature of the processing, assists the Restaurant in responding to access, correction, deletion and portability requests. Requests received directly by WineUp about a Restaurant’s data are forwarded to that Restaurant. See the Privacy Request page.
11. Security incidents
WineUp notifies the Restaurant without undue delay after becoming aware of a personal-data breach affecting the Restaurant’s data, and provides the information reasonably available to help the Restaurant meet its own notification duties. WineUp maintains an internal incident-response plan and a breach event log.
12. Deletion and return of data
On cancellation, the Restaurant retains access until the end of the paid period. A 30-day read-only recovery period then begins, during which the account can be reactivated and data exported. At the end of that period, operational records are hard-deleted from active production storage, except records WineUp must retain for legal, tax, fraud-prevention, security-incident or legal-claim reasons. Residual copies may remain in encrypted disaster-recovery backups until ordinary rotation removes them, within a maximum of 30 days; backups are not used for ordinary operations.
13. Audits and information rights
On reasonable written request, and no more than once per year unless required by a supervisory authority, WineUp provides the information reasonably necessary to demonstrate compliance with this Addendum. WineUp is a small operation and does not hold third-party audit certifications; on-site audits are replaced by written responses and documentation.
14. International transfers
WineUp is operated from the United States and its subprocessors are primarily US-based. Where a transfer of personal data from another jurisdiction is involved, the parties will put in place the transfer mechanism required by applicable law (for example, standard contractual clauses) before the transfer occurs.
15. Order of precedence and contact
In case of conflict, this Addendum prevails over the Terms of Service on data-protection matters. Everything else remains governed by the Terms. Questions: wineuptech@gmail.com.
