This Data Processing Agreement ("DPA") applies when Uncorked Together processes personal data on behalf of a partner winery, event host, or other business customer ("Customer") — for example, when a Customer sends us a list of contacts or we handle enquiries submitted through a Customer's listing. It forms part of our Terms of Use.
This DPA covers business-to-business processing only. If you're an app user, your data is covered by our Privacy Policy and Data Rights page.
1. Roles
The Customer is the controller and Uncorked Together is the processor for personal data the Customer provides or directs us to process. Under California law, Uncorked Together acts as a service provider and does not sell or share that data.
2. Scope of processing
- Subject matter: providing the Uncorked Together platform and related services.
- Duration: for as long as the business relationship is active, plus the deletion window in section 8.
- Nature and purpose: hosting, storage, display, moderation, communication, and analytics necessary to deliver the service.
- Types of personal data: names, business contact details, email addresses, and any content the Customer submits.
- Categories of data subjects: the Customer's staff, contacts, and prospective customers.
3. Our obligations
- Process personal data only on the Customer's documented instructions, unless required by law.
- Never sell, share, retain, or use the data for our own purposes or for advertising.
- Ensure everyone with access is bound by confidentiality obligations.
- Assist the Customer with data subject requests, impact assessments, and regulator consultations.
4. Security
We maintain appropriate technical and organizational measures, including encryption in transit (HTTPS) and at rest, row-level access controls in our database, least-privilege administrative access, and multi-factor authentication on administrative accounts.
5. Subprocessors
The Customer authorizes the subprocessors listed on our Subprocessors page. We impose data protection obligations on each one no less protective than this DPA and remain liable for their performance. We will give notice before adding a new subprocessor, and the Customer may object on reasonable data protection grounds.
6. International transfers
Our infrastructure is located in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, the transfer relies on the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.
7. Personal data breaches
We will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the Customer's data, with the information reasonably available to us and updates as the investigation progresses.
8. Deletion and return
On termination, or at the Customer's written request, we will delete or return the Customer's personal data within 30 days, except where retention is required by law. Backup copies age out within 90 days.
9. Audits
On reasonable written request, no more than once per year, we will provide the information necessary to demonstrate compliance with this DPA and cooperate with audits conducted by the Customer or an independent auditor, subject to confidentiality and reasonable notice.
10. Signing this DPA
This DPA applies automatically to business customers as part of our Terms. If you need a countersigned copy for your records, email privacy@uncorkedtogether.com with your legal entity name and address and we'll send one over.
This document is provided by Uncorked Together and is not legal advice. Have your own counsel review it before relying on it in a commercial agreement.