Privacy Policy
Effective date: 20 June 2026 Controller: Operal AG, Gotthardstrasse 26, 6300 Zug, Switzerland ("we", "us"). Privacy contact: office@operal.solutions
This Policy explains how we process personal data when you use the Vinea service (the "Service"). We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP/revFADP) and, where it applies to processing of EU/EEA residents' data, the EU General Data Protection Regulation (GDPR).
It covers two distinct roles, which is important under both laws:
- We are the controller for data about our customers and their account users (e.g. who signs up and uses Vinea).
- The customer is the controller, and we are the processor, for the prospect/importer contact data that flows through the Service (discovered, scored, and contacted on the customer's behalf). For that processing, our Data Processing Agreement governs, and the customer's own privacy notice applies to the people they contact.
1. Data we process as controller (about account users)
| Category | Examples | Purpose | Lawful basis |
|---|---|---|---|
| Account & identity | name, work email, organisation, estate profile | create and manage your account | contract |
| Usage & device | log data, IP, actions in the app | operate, secure, and improve the Service | legitimate interests |
| Billing | plan, payment status | take payment, accounting | contract / legal obligation |
| Support | messages you send us | respond to you | legitimate interests |
2. Data we process as processor (prospect/importer data)
On the customer's instructions, the Service collects business-contact information about prospective wine importers and distributors from public and third-party sources (e.g. company websites via automated search and scraping). This may include the company name, website, business address, business email address, business telephone number, and public social-media profile links, and the role of a public business contact where shown. The Service stores this information, scores it for fit using AI, and helps the customer send and track outreach.
The customer determines the purposes and means of this processing and is responsible for the lawful basis (typically legitimate interests for B2B prospecting under the FADP/GDPR), for transparency to the people they contact, and for honouring objections and opt-outs. We process this data only to provide the Service and do not sell it. Any individual whose business-contact data we hold may request access, correction, or deletion by writing to office@operal.solutions, and we will action it and/or pass it to the responsible customer.
3. Sub-processors
We use the following sub-processors to provide the Service:
| Sub-processor | Function | Location / transfer mechanism |
|---|---|---|
| Vercel Inc. | Hosting & compute | US — EU SCCs / Swiss addendum as applicable |
| OpenAI | AI model inference (extraction, scoring, drafting) | US — SCCs; API data not used to train models |
| Firecrawl | Web search & scraping of public sources | US — SCCs as applicable |
| Resend | Outbound email delivery | US — SCCs as applicable |
We do not use prospect data or Customer Data to train AI models, and providers process API content under their no-training commitments.
4. International transfers
We are based in Switzerland. Where personal data is transferred abroad (including to the US sub-processors above), we rely on appropriate safeguards such as the EU Standard Contractual Clauses together with the Swiss addendum, and/or recognised adequacy, as applicable.
5. Retention
We retain account data for the life of the account and as required for legal, accounting, and security purposes. Prospect/importer data is retained per the customer's instructions and the DPA, and deleted or returned on termination, subject to legal retention obligations and backup cycles.
6. Your rights
Subject to the conditions of the FADP and, where applicable, the GDPR, you have the right to access, rectify, erase, restrict, and object to processing of your personal data, to data portability, and to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU/EEA supervisory authority. For data we process as processor (prospect data), we will forward your request to the relevant customer (the controller) and assist them. To exercise rights regarding data we control, contact office@operal.solutions.
7. Security
We implement technical and organisational measures appropriate to the risk (encryption in transit and at rest, access controls, least-privilege, logging). No system is perfectly secure; we will notify affected parties and the competent authority of personal-data breaches as required by law.
8. Cookies / similar technologies
We use a strictly necessary, first-party cookie to keep you signed in (an HMAC-signed session cookie) and essential local storage for app functionality. We do not use advertising cookies. If we introduce non-essential analytics, we will update this Policy and provide any consent mechanism required by law.
9. Children
The Service is not directed to, and may not be used by, anyone under 18.
10. Changes
We may update this Policy; material changes will be notified through the Service or by email.
11. Contact
Questions or requests: office@operal.solutions — Operal AG, Gotthardstrasse 26, 6300 Zug, Switzerland.