What data protection means
Personal data is information connected to an identifiable person—for example a name, email, phone number or invoice linked to a customer. Protecting it means using it lawfully, fairly and transparently; collecting only what is needed; keeping it accurate; limiting retention; and respecting the person’s rights.
Two responsibilities
Accounts and the service
VINCEDOTCODE LTD decides how account, security and support data is used and must answer requests about that data.
Your customer records
Your business decides which customer details to record. You must have a lawful reason, give required notice and respond to those people. Bienzoli processes that data for you.
How the service is protected
- HTTPS and strict transport-security headers protect data in transit.
- Supabase authentication manages passwords and sessions; Bienzoli does not store plaintext passwords.
- Server credentials stay outside browser code and are restricted to production systems.
- Every application query is scoped to the signed-in business organisation.
- Database tables have row-level security as a second boundary for direct public access.
- Security headers, automated dependency checks and a responsible-disclosure contact reduce common web risks.
- Access and data are kept to what the service needs; no advertising profiles are created.
Provider and transfer register
| Provider | Purpose | Typical processing |
|---|---|---|
| Supabase | Authentication and PostgreSQL database | Singapore region; account and business data |
| Vercel | Application hosting, functions, CDN and anonymous public-page analytics | Singapore function region and global delivery network; aggregated marketing-page usage |
| Resend | Transactional authentication email | Email address and message delivery data |
| UPCitemdb / Open Food Facts | Optional product-code suggestions | Barcode or product code only; no customer or account details |
Core personal data may therefore be processed outside Mauritius. We use provider data-processing terms and appropriate technical and contractual safeguards, and maintain records of these transfers.
How to exercise a right
- Email vince@vincedotcode.com from the address connected to the account.
- Say whether you want access, correction, deletion, restriction, objection or information about processing.
- We verify identity so another person cannot obtain or erase your information.
- We respond without excessive delay, normally within 30 days, or explain if lawful additional time is required.
If the request concerns a customer record entered by a Bienzoli business, contact that business first. We will assist it as processor.
If something goes wrong
We investigate suspected incidents, contain access, preserve evidence and assess affected data and people. Where required, a controller must notify the Mauritius Data Protection Commissioner without undue delay and, where feasible, within 72 hours of awareness. High-risk breaches must also be communicated to affected people without undue delay.
Report a suspected vulnerability or data incident privately to vince@vincedotcode.com. Do not include sensitive data beyond what is needed to identify the issue.