fashn-logo

FASHNAI

  • Piattaforma FASHN

    App

    Crea splendidi visual su modella

    API

    Integra la prova virtuale nella tua app

    FASHN Platform

    Strumenti IA

    Prova Virtuale

    Scopri il nostro modello IA proprietario

    Prodotto su Modello

    Trasforma prodotti in scatti su modella

    Packshot

    Genera packshot da catalogo

    Cambio Modello

    Sostituisci solo la modella in una foto

    Creazione Modello

    Crea modelle di moda IA

    Video Brevi

    Aggiungi movimento alle tue prove virtuali

  • Casi d’uso

    Servizi Fotografici di Moda Virtuali

    Produci contenuti per i brand di moda

    Camerini Virtuali

    Prova interattiva dei capi per l’e-commerce

    Destinatari

    Brand di moda

    Crea immagini premium per i tuoi prodotti

    Agenzie di marketing

    Consegna le campagne più velocemente, per ogni mercato

  • Prezzi
  • Chi siamo

    La nostra missione in FASHN

    Ricerca

    Pubblicazioni e open-source

    Storie dei clienti

    Storie vere dai nostri clienti

    Lavora con noi

    Unisciti al team FASHN

    Blog

    Le ultime novità da FASHN

    Documentazione API

    Scopri come usare l’API

    Centro assistenza

    Scopri come usare l’app FASHN

    Registro aggiornamenti

    Aggiornamenti e miglioramenti FASHN

    Stato

    Controlla lo stato e la disponibilità del sistema

    Risorse
Vai all’app
Centro legaleTermini di servizioInformativa sulla privacyDPASub-responsabili

Protezione dei dati

Addendum sul trattamento dei dati

I termini applicabili quando FASHN tratta i Dati Personali del Cliente per conto di un cliente aziendale.

Ultimo aggiornamento
7 agosto 2026

In questa pagina

  1. 1. Scope, roles, and processing details
  2. 2. Instructions, use restrictions, and confidentiality
  3. 3. Security and incidents
  4. 4. Customer assistance
  5. 5. Sub-processors
  6. 6. Deletion and return
  7. 7. Compliance, audits, and transfers
  8. 8. General and regional terms
  9. Schedule 1. Details of Processing
  10. Schedule 2. Technical and organisational measures
  11. Schedule 3. International transfer terms

In questa pagina

  1. 1. Scope, roles, and processing details
  2. 2. Instructions, use restrictions, and confidentiality
  3. 3. Security and incidents
  4. 4. Customer assistance
  5. 5. Sub-processors
  6. 6. Deletion and return
  7. 7. Compliance, audits, and transfers
  8. 8. General and regional terms
  9. Schedule 1. Details of Processing
  10. Schedule 2. Technical and organisational measures
  11. Schedule 3. International transfer terms

This Data Processing Addendum (the DPA) forms part of the agreement between the Customer and FASHN LTD governing the Customer's use of the Services (the Agreement). It applies only when FASHN processes Customer Personal Data as a Processor or Sub-processor on the Customer's behalf.

FASHN LTD is registered in England and Wales under company number 14979714, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. A separately signed data processing agreement between the parties takes precedence over this public DPA to the extent of a conflict.

1. Scope, roles, and processing details

1.1 Definitions

In this DPA:

  • Customer means the person or entity identified as the customer under the Agreement.
  • Customer Content means images, video, prompts, instructions, reference media, generated outputs, and other content submitted to, generated through, or stored in the Services for the Customer.
  • Customer Personal Data means Personal Data in Customer Content or related Service records that FASHN processes on the Customer's behalf.
  • Data Protection Laws means laws and binding regulations applicable to a party's processing of Customer Personal Data under the Agreement, including the UK GDPR, EU GDPR, Swiss Federal Act on Data Protection, and applicable United States state privacy laws.
  • EU SCCs means the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914.
  • Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed by FASHN. Unsuccessful attempts that do not compromise Customer Personal Data are not Security Incidents.
  • Services means the FASHN website, applications, API, and related services covered by the Agreement.
  • UK Addendum means the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office.

Personal Data, Controller, Processor, Process, Data Subject, and Supervisory Authority have the meanings given by applicable Data Protection Laws. Sub-processor means a Processor engaged by FASHN to Process Customer Personal Data.

1.2 Roles and applicability

The Customer is the Controller of Customer Personal Data, or a Processor acting for another Controller. FASHN is the Customer's Processor or Sub-processor, as applicable. Each party will comply with the obligations that apply to it under Data Protection Laws. Where the Customer acts as a Processor for another Controller, the Customer confirms that it is authorised to engage FASHN as a Sub-processor and acts as FASHN's point of contact for that Controller.

This DPA does not apply where FASHN acts as an independent Controller, including for account, billing, relationship, and other processing described in the Privacy Policy. A record is classified according to the purpose for which it is processed, not merely the system in which it is stored.

1.3 Processing details and duration

Schedule 1 describes the subject matter, nature, purpose, duration, Personal Data, Data Subjects, and processing operations. This DPA begins when incorporated into the Agreement and remains in effect while FASHN Processes Customer Personal Data for the Customer. Obligations that must continue by their nature survive for as long as FASHN retains Customer Personal Data.

2. Instructions, use restrictions, and confidentiality

2.1 Documented instructions

FASHN will Process Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA, the Customer's use and configuration of the Services, and authenticated support requests constitute those instructions.

FASHN will inform the Customer before Processing required by law unless the law prohibits notice on important public-interest grounds. If FASHN reasonably believes an instruction infringes Data Protection Laws, it will inform the Customer and may suspend the affected Processing while the parties address the issue.

2.2 Purpose and use restrictions

FASHN will Process Customer Personal Data only to provide, secure, maintain, and support the Services, comply with applicable law, and follow the Customer's documented instructions. The Customer Content use restrictions in the Terms of Service, including the restriction on using Customer Content to train or improve AI models, form part of those instructions.

FASHN will not sell Customer Personal Data, share it for cross-context behavioural advertising, use it to create advertising profiles, or use it for an independent commercial purpose. FASHN may use measurements that no longer contain Personal Data or Customer Content and cannot reasonably be linked to a Customer or Data Subject, and will not attempt to re-identify them.

2.3 Confidentiality

FASHN will ensure that personnel authorised to Process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security instruction, and have access only where needed for their work. FASHN remains responsible for its personnel's compliance with this DPA.

2.4 Customer responsibilities

The Customer is responsible for the lawfulness of its instructions and Customer Personal Data, providing required notices, obtaining an applicable legal basis, responding to Data Subjects, and using the Services in accordance with Data Protection Laws. If Customer Personal Data includes face images or other sensitive or special-category information, the Customer confirms that it is authorised to submit that data and instruct the processing described in Schedule 1.

3. Security and incidents

3.1 Security measures

FASHN will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. Schedule 2 describes the current control families. FASHN may update individual measures as technology and risk evolve while maintaining an appropriate overall level of protection.

The Customer is responsible for protecting its accounts, API keys, credentials, client applications, devices, and networks and for limiting Service access to authorised users.

3.2 Security Incident notice

FASHN will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. As information becomes available, FASHN will provide a description of the incident, affected data or Data Subject categories, likely consequences, mitigation or remediation measures, and a contact for follow-up. FASHN will take reasonable steps to contain and remediate the incident and reasonably assist the Customer with legally required notifications.

4. Customer assistance

4.1 Data Subject requests

Taking into account the nature of the Processing, FASHN will provide reasonable technical and organisational assistance to help the Customer respond to Data Subject requests. If FASHN receives a request relating to Customer Personal Data directly from a Data Subject, FASHN will not respond on the Customer's behalf unless legally required. Where permitted, FASHN will direct the requester to the Customer or notify the Customer.

4.2 Other compliance assistance

Taking into account the nature of the Processing and information available to FASHN, FASHN will provide reasonable assistance with the Customer's obligations concerning security, personal-data breaches, data protection impact assessments, and prior consultation with a Supervisory Authority.

The Customer will provide enough authenticated information for FASHN to identify the Organization, Service, records, and requested action. Assistance materially outside standard Service functionality may be subject to reasonable fees agreed in advance, unless it is required because FASHN breached this DPA.

5. Sub-processors

5.1 General authorisation

The Customer gives FASHN general written authorisation to engage the Sub-processors in the current Subprocessor List. A provider receives Customer Personal Data only when the relevant Service path or feature uses that provider.

5.2 Obligations and responsibility

Before a Sub-processor Processes Customer Personal Data, FASHN will enter into a written agreement imposing data-protection obligations that provide substantially the same protection as this DPA for the relevant Processing. FASHN remains responsible for the Sub-processor's performance of those obligations to the extent required by Data Protection Laws, subject to the Agreement's limitations of liability.

5.3 Changes

FASHN will give affected Customers at least 15 calendar days' notice before a new Sub-processor begins Processing Customer Personal Data. The Customer may object within 10 calendar days on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If no commercially reasonable solution is available, the Customer may stop using and terminate the affected Service in accordance with the Agreement.

FASHN may make an accelerated replacement where necessary to address an urgent security, legal, availability, or service-integrity risk. FASHN will notify affected Customers as soon as reasonably practicable.

6. Deletion and return

6.1 During the Agreement

The Customer may use available Service controls or send an authenticated request to [email protected] to delete Customer Personal Data. FASHN will carry out a valid instruction without undue delay, subject to the nature of the Service and any legal requirement to retain the data, and will direct relevant Sub-processors to do the same.

6.2 End of Processing

At the Customer's choice, FASHN will delete or return Customer Personal Data after the Agreement ends and delete remaining copies, unless applicable law requires retention. If the Customer does not make a choice before termination, FASHN will delete the data.

Deleted data may remain in encrypted, access-restricted backups until overwritten through the ordinary backup cycle. FASHN will not restore deleted data to active use except where needed for disaster recovery and will reapply the deletion after restoration where practicable. Data retained by law will remain isolated and protected and will be Processed only for the legally required purpose.

7. Compliance, audits, and transfers

7.1 Compliance information and audits

FASHN will make available information reasonably necessary to demonstrate compliance with this DPA, including the DPA, current Subprocessor List, and Schedule 2. The parties will first use available documentation and remote discussion.

Where that information is insufficient to meet a legal requirement, FASHN will allow and contribute to a proportionate audit by the Customer or an independent auditor. An audit must use reasonable advance notice, occur during normal business hours, minimise disruption, protect confidential and security-sensitive information, and avoid access to another customer's data. The Customer bears its audit costs unless the audit identifies FASHN's material breach of this DPA.

7.2 International transfers

The parties will first rely on an applicable adequacy decision or regulation. Where a restricted transfer requires a contractual safeguard, the EU SCCs, UK Addendum, or another valid transfer mechanism applies as described in Schedule 3.

8. General and regional terms

8.1 California

To the extent the California Consumer Privacy Act, as amended, applies to Customer Personal Data, FASHN acts as a service provider or contractor. FASHN will Process that data only for the specific business purposes in the Agreement and the Customer's instructions; will not sell or share it; will not retain, use, or disclose it outside the direct business relationship or combine it with other personal information except as permitted by law; will provide the required level of privacy protection; will notify the Customer if it can no longer comply; and will allow the Customer to take reasonable steps to monitor, stop, and remediate unauthorised use. FASHN will bind Sub-processors to applicable equivalent restrictions.

8.2 Precedence, liability, and term

An applicable mandatory transfer instrument prevails for its subject matter. This DPA prevails over the Agreement to the extent of a conflict concerning the Processing of Customer Personal Data. The Agreement governs all other matters. The Privacy Policy is not part of this contract hierarchy.

Each party's liability arising from this DPA is subject to the exclusions and limitations in the Agreement, except where Data Protection Laws or an applicable transfer instrument prohibit that limitation.

FASHN may update this DPA under the Agreement's change process to reflect changes in law, the Services, or FASHN's data-protection practices. A separately signed DPA is not replaced by a later public DPA unless the signed agreement says otherwise.

8.3 Contact

Notices and requests under this DPA must be sent to [email protected]. FASHN may send notices to the Customer's Organization owner, account contact, or designated legal-notice address. Security questions may be sent to [email protected].

Schedule 1. Details of Processing

ItemDescription
Subject matterAI-powered media generation, editing, transformation, orchestration, delivery, storage, and related support and security services.
Nature and purposeReceiving Customer instructions and media; analysing prompts and references; generating, editing, transforming, and delivering image or video outputs; storing Customer-selected content and records; and protecting, supporting, and maintaining the Services.
DurationFor the term of the Agreement and the limited deletion, backup, and legally required periods described in Section 6.
Personal DataImages and video; facial and physical appearance; clothing and product imagery; prompts and instructions; generated outputs; reference media; media identifiers; pseudonymous account or Organization identifiers; and request or prediction metadata to the extent processed to provide the Customer-directed Service.
Data SubjectsCustomer personnel and authorised users; shoppers and end users of Customer services; models, talent, creators, and other depicted individuals; and other people whose Personal Data the Customer lawfully submits.
Sensitive dataCustomer Content may include face images or reveal information treated as sensitive or special-category data. The Customer determines whether the data may lawfully be submitted and what safeguards are required.
FrequencyOn demand or continuously, as initiated by the Customer and its authorised users or applications.
Sub-processor transfersSub-processors in the current Subprocessor List Process Customer Personal Data for the same subject matter and nature described above, limited to the listed purpose, for the duration of the relevant Service engagement.
OperationsCollection, receipt, transmission, organisation, analysis, inference, generation, modification, retrieval, hosting, storage, delivery, troubleshooting, security, deletion, and return.

Schedule 2. Technical and organisational measures

FASHN maintains a risk-based security programme appropriate to the nature, scope, context, and purposes of Processing. Current control families include:

1. Encryption and secrets

  • Current transport encryption for data in transit.
  • Managed encryption at rest for production databases and object storage.
  • Credentials and secrets protected separately from application code.

2. Identity and access

  • Authenticated user, Organization, and API access.
  • Role-based, least-privilege production and support access.
  • Administrative access restriction and access revocation when roles change.

3. Tenant and environment separation

  • Logical Organization boundaries and authorisation checks.
  • Separation of production and non-production environments and credentials.
  • Controls designed to prevent access to another Customer's content.

4. Data minimisation and logging

  • Collection and retention limited to the data needed for the applicable purpose.
  • Controls designed to keep media content, credentials, and signed media URLs out of ordinary logs.
  • Pseudonymous identifiers, redaction, or scrubbing in monitoring where appropriate.

5. Resilience and recovery

  • Managed infrastructure, monitoring, and recovery mechanisms appropriate to the Service.
  • Controlled backups for critical records and procedures designed to preserve deletion instructions after restoration.

6. Development and monitoring

  • Version control, review, testing, dependency management, and controlled deployment appropriate to risk.
  • Operational and security monitoring, incident triage, containment, remediation, and recovery procedures.

7. People and suppliers

  • Confidentiality duties and access limited to personnel with a business need.
  • Privacy and security awareness appropriate to role.
  • Risk-based diligence and written data-protection obligations for Sub-processors.
  • Reliance on managed hosting providers' physical and environmental controls for production infrastructure.

Schedule 3. International transfer terms

1. Applicability

This Schedule applies only where a transfer of Customer Personal Data requires an approved contractual safeguard. It does not replace an applicable adequacy decision or regulation.

2. EU SCCs

The EU SCCs are incorporated by reference where required and completed as follows:

  • Module 2 applies when the Customer is a Controller and FASHN is a Processor. Module 3 applies when the Customer is a Processor and FASHN is a Sub-processor.
  • Clause 7 applies. In Clause 9, Option 2 applies with the 15-day notice period in Section 5.3. The optional language in Clause 11 does not apply.
  • Under Clauses 17 and 18, Irish law and the courts of Ireland apply.
  • The Agreement identifies the Customer as data exporter and FASHN LTD as data importer and supplies the parties' contact details. Entering the Agreement constitutes signature where required.
  • Schedule 1 completes Annex I.B, the competent Supervisory Authority under Clause 13 completes Annex I.C, and Schedule 2 completes Annex II. The Subprocessor List identifies authorised Sub-processors for Clause 9.

3. United Kingdom

The UK Addendum is incorporated where required. Its tables are completed by the party information in the Agreement, the EU SCC selections above, Schedules 1 and 2, and the Subprocessor List. The Customer is Exporter and FASHN is Importer unless the restricted-transfer roles require otherwise. Either party may end the UK Addendum as permitted by its mandatory terms only if another lawful safeguard is put in place where required for Processing to continue.

4. Switzerland

Where Swiss law governs a restricted transfer, references in the EU SCCs to the EU GDPR include the Swiss Federal Act on Data Protection; references to the European Union include Switzerland where needed to preserve Data Subject rights; and the competent authority is the Swiss Federal Data Protection and Information Commissioner. The remaining EU SCC selections apply unless mandatory Swiss law requires another result.

An applicable transfer instrument prevails over this DPA to the extent of a conflict.

Prodotti

  • App
  • iOS App
  • API

Strumenti

  • Prova Virtuale
  • Prodotto su Modello
  • Packshot
  • Cambio Modello
  • Creazione Modello
  • Modelli Coerenti
  • Video Brevi

Soluzioni

  • Servizi Fotografici di Moda Virtuali
  • Camerini Virtuali

Risorse

  • Docs API
  • Lavora con noi
  • Centro assistenza
  • Registro aggiornamenti
  • Storie dei clienti
  • Prezzi
  • Stato

Azienda

  • Chi siamo
  • Blog
  • Ricerca
  • Centro legale

Social

  • X
  • Instagram
  • YouTube
  • TikTok
  • LinkedIn
  • Discord
  • GitHub
fashn-logo

FASHNAI

© 2026 FASHN LTD. Tutti i diritti riservati.

71-75 Shelton Street, Covent Garden London, UK, WC2H 9JQ

Termini di servizioInformativa sulla privacy