Privacy notice
This notice explains how personal data is processed when you visit the website, use an account or open a public e-label.
Last updated: 16 September 2026
Controller and contact
- Service provider
- lekuhe Invest GmbH
Torstraße 105
10119 Berlin
Deutschland - Managing director
- Leonhard Kühne-Hellmessen
- Contact
- team@vinum-elabel.com
1. Website and public e-labels
To deliver a page, our hosting providers Cloudflare and Supabase process technically necessary connection data, including IP address, time, requested resource and HTTP information. The legal basis is Article 6(1)(f) GDPR: our interest in securely providing the requested service and preventing abuse.
Public e-labels require no sign-in. The public viewer does not use an account session, advertising trackers or visitor identifiers. View statistics store only totals per label, day and source, not individual visitor profiles. Technically necessary hosting connections are separate from these totals.
Fonts are served from our own website. The application does not embed Google Analytics or advertising pixels.
We also count generator starts and imports as totals per event type and day, without individual user profiles or persistent visitor identifiers.
2. Accounts, wineries and collaboration
We process email addresses, names where supplied, authentication data and account settings. This includes winery, label and contact data entered by users, team assignments and, where applicable, API key metadata and custom domains. For team invitations, we receive the invited address from the person sending the invitation and use it to manage invitations and access.
The purposes are account management, creating and publishing e-labels and managing collaboration. Article 6(1)(b) GDPR applies to our contract with you. For employees and other contacts of business customers, communications and access management rely on Article 6(1)(f) GDPR, our interest in performing the contract with that customer.
Published label information is publicly accessible. Only publish information intended for the product. Where customers submit personal content for which they are the controller, our processing on their behalf is subject to Article 28 GDPR and the applicable data processing agreement.
3. Payments and subscriptions
Payments are handled by Stripe Payments Europe, Limited and the relevant Stripe entities. We supply the customer and plan data needed for billing. Stripe processes billing addresses, payment information and, where applicable, VAT IDs. We receive customer, subscription, invoice and payment status data; full card details are not stored in our application.
Legal bases are Article 6(1)(b) GDPR for the contract and Article 6(1)(c) GDPR for commercial and tax obligations. Stripe also processes certain data as an independent controller, including for fraud prevention and its legal obligations.
4. Enquiries and emails
For enquiries we process your name, email address, company if supplied, and message. Do not send passwords or payment credentials. Contract-related enquiries rely on Article 6(1)(b) GDPR; other enquiries rely on Article 6(1)(f) GDPR, our interest in responding to your request.
Account confirmations, access emails, team invitations and other operational messages are sent through Resend (Plus Five Five, Inc.), which processes recipient addresses, message content and technical delivery information. These messages support the requested service; creating an account does not constitute consent to advertising.
5. Security, error reports and activity history
Cloudflare Turnstile protects selected account forms against automated abuse. Cloudflare processes IP addresses, browser and device information, and verification results. The basis is Article 6(1)(f) GDPR, our interest in protecting accounts and infrastructure. Where device access is strictly necessary for this requested security function, section 25(2)(2) of the German TDDDG applies. Turnstile is not loaded in the public e-label viewer.
For signed-in use, certain changes are logged with account and actor identifiers, object reference, action, changed field names and time. Old and new field contents are not copied into this activity log. Technical error reports contain a reference, error category, broad page category, version and time; signed-in reports are linked to the account. Reports exclude form contents, URL parameters and full error messages. The basis is Article 6(1)(f) GDPR, our interest in resolving errors and tracing security-relevant changes. The public e-label viewer sends no such diagnostic reports.
6. Recipients and processing outside the EEA
We use Cloudflare, Inc. for hosting, delivery and abuse protection, Supabase for the database, authentication, file storage and server functions, Resend for email and Stripe for payments. Data may also be disclosed to authorities or advisers where required by law or supported by a legal basis for asserting or defending rights. The primary Supabase database is located in Frankfurt (eu-central-1).
Some providers are based in the United States or use entities there. Storage in an EU region does not automatically exclude access from third countries. Such transfers are subject to Articles 44 et seq. GDPR, including an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Contact us for information about the safeguards applicable to your data and a copy. The provider notices linked below explain their processing and transfer arrangements.
7. Retention and deletion
Account data and activity history are held to operate your account. Account deletion removes the associated data from the active application database. Simply cancelling a subscription leaves public labels available in accordance with the agreed hosting commitment; expressly deleting the account and its labels is a separate action.
Error reports older than 30 days are cleared on the next permitted diagnostic submission; deleting the account removes its reports. Support correspondence is retained according to the handling of the enquiry and any necessary evidence preservation until applicable limitation periods expire.
Business records subject to statutory retention are kept for the applicable periods: generally eight years for accounting vouchers, six years for commercial correspondence and ten years for certain accounting records, calculated from the statutory start date. Other legal requirements or ongoing proceedings may require longer retention. Payment providers may have their own retention duties. Backups and technical provider logs expire under the relevant operational deletion cycles; deleting an account does not immediately remove those copies.
8. Your rights
Subject to the legal requirements, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time for the future without affecting the lawfulness of earlier processing.
For processing based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to processing for direct marketing at any time without giving reasons.
Send requests to the email address below. We generally respond within one month of receipt. Where necessary due to complexity or the number of requests, this may be extended by up to two further months; we will explain the extension within the first month. We may request proportionate identity verification to prevent unauthorised disclosure.
You may complain to a data protection authority, particularly in the place of your residence, work or the alleged infringement. The authority for our registered office is the Berlin Commissioner for Data Protection and Freedom of Information: Alt-Moabit 59-61, 10555 Berlin, Germany; mailbox@datenschutz-berlin.de.
9. Required information and automated decisions
Information needed for registration, service delivery and billing is necessary to provide the account or contract. Without it, the relevant functions cannot be provided; optional information can be omitted. Vinum does not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR.
The cookie information explains local browser storage. Updates to this notice describe the current processing and do not replace any required consent.