Privacy Policy
Last updated: 25 July 2026
1. Controller
The controller is ProWebSolutions GmbH, Aurelienstr. 48, 04177 Leipzig, Germany. Email: info@mywinolog.com, phone: +49 176 10347813.
2. Account and service data
When you register and use the service, we process your name, email address, encrypted password, verification and reset data, and the storage locations, wines, stock levels, ratings and notes you create. This is necessary to provide your MyWinolog account (Art. 6(1)(b) GDPR).
3. Server logs and session
For secure delivery, the hosting provider processes data such as IP address, time, requested URL, referrer, browser and operating system. The legal basis is our legitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR). A technically necessary session cookie maintains your login and language preference.
4. Email delivery
Confirmation and password emails are sent through our SMTP mail server. Recipient address, display name, message content and technical delivery data are processed under Art. 6(1)(b) GDPR.
5. AI-assisted wine-label recognition
When you deliberately start a scan, the selected label images are sent through the OpenAI API to OpenAI, L.L.C. and processed to identify wine data. Do not photograph people, addresses or other private content. OpenAI states that API inputs and outputs are not used for model training by default. Processing may take place in third countries, particularly the United States, using the contractual safeguards provided for this purpose. The legal basis is the feature you requested under Art. 6(1)(b) GDPR.
6. AI results
Recognised data may be incomplete or inaccurate. It is placed only in the form and becomes part of your account only after you review and explicitly save it. Scan calls are counted per user to prevent misuse; individual count records are deleted after the technical review period.
7. Google AdSense and AdMob
We use Google AdSense on the web and Google AdMob in the mobile app. They may process device identifiers, IP addresses, usage data, cookies or similar storage for delivery, measurement and possible personalisation. In the EEA, UK and Switzerland, services requiring consent load only after your choice through a Google-certified consent management platform. Consent can be withdrawn at any time through the privacy and cookie settings. The legal basis is Art. 6(1)(a) GDPR; no personalised ads load without consent.
8. Recipients and processors
Recipients may include hosting, email and technical providers and, when used, OpenAI for scanning and Google for activated advertising. Providers receive data only as necessary and are contractually bound as processors where required.
9. Retention and account deletion
Account and cellar data is retained until account deletion or for as long as legal obligations require. Deleting an account removes personal cellar data; shared wine master data without an account reference may remain. Logs and security data are kept only as long as necessary for operation, troubleshooting and abuse prevention. Reset links remain valid for 24 hours and can be used once.
10. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent for the future. You may also lodge a complaint with a data protection authority.
11. Security and changes
We use appropriate technical and organisational safeguards and update this policy when features, providers or legal requirements change.