This Privacy Policy explains how we handle your personal data on the Cellaris Platform. Read together with our Terms & Conditions (Section 10).

Last Updated: September 30, 2025

CELLARIS SAS
RCS Toulouse 952 076 198
2 rue Raymond Boulogne C41, 31500 Toulouse, France
contact@cellaris.com

1. DATA CONTROLLER

Cellaris SAS is responsible for your personal data.

Privacy contact: contact@cellaris.com

2. DATA WE COLLECT

Personal Information

• Name, email, phone, date of birth

• Billing address

• Payment details (via Stripe)

For Sellers

• Business documents (KBIS, VAT, SIRET)

• Identity documents and bank details

• Professional certifications

Automatic Collection

• IP address, browser, device information

• Pages visited and usage patterns

• Cookies (see Section 5)

Third-Party Data

• Age and identity verification results

• Payment confirmations (Stripe)

• Analytics: Google Analytics privacy policy

We're not responsible for third-party privacy practices.

3. HOW WE USE YOUR DATA

Services

• Account and authentication

• Order processing and payments

• Wine authentication (blockchain) : Wine authentication data stored on blockchain is permanent and cannot be deleted. We use pseudonymization - only wine details, not personal identifiers, appear on-chain.

• Customer support

Legal Requirements:

• Tax obligations (10-year retention)

• Age verification: Platform only for legal drinking age. We don't collect minor data. If discovered, we delete immediately.

• AML compliance and reporting

Marketing (with consent):

• Newsletters and promotions. Unsubscribe: Link in every email or account settings. Essential emails (orders, security) continue regardless

Security:

• Fraud prevention and platform security

Full details in Terms & Conditions Section 10.

4. YOUR RIGHTS (GDPR)

✓ Access your data

✓ Correct inaccurate data

✓ Delete your data

✓ Restrict processing

✓ Export your data

✓ Object to processing

✓ Withdraw consent

Exercise rights: Email contact@cellaris.com with "Data Privacy Request"

Response: Within 30 days

Some data must be kept for legal obligations (e.g., tax records).

5. COOKIES

Essential (always on):

• Functional

• Performance

Optional (with consent):

• Analytics

• Advertising

Manage: Cookie banner on first visit or Cookies Settings in the footer

6. DATA SECURITY

• SSL/TLS encryption

• Secure storage and password hashing

• Blockchain for wine authentication (Polygon)

• PCI-DSS compliance (Stripe)

• Access controls and monitoring

7. DATA SHARING

We share data only with:

• PSP : Stripe - Payment processing (PSP - Stripe: stripe.com/privacy)

• Service providers - Platform hosting, analytics, support

• Authorities - When legally required (tax, AML)

All bound by data protection contracts.

8. INTERNATIONAL TRANSFERS

Data stored in EU. Transfers outside EU (e.g., Stripe - USA) use:

• Standard Contractual Clauses

• EU-approved safeguards