Last updated · February 2026
This Data Processing Agreement ("DPA") supplements the TailorFlow Terms of Service between TailorFlow ("Processor") and the Retailer ("Controller") and governs the processing of Personal Data by TailorFlow on behalf of the Retailer. It is designed to comply with GDPR Article 28 and to satisfy CCPA/CPRA service-provider requirements.
The Retailer is the Controller. TailorFlow is the Processor and acts only on the Controller's documented instructions. Each party shall comply with all applicable data-protection laws in its role.
TailorFlow shall:
The Controller authorises TailorFlow to engage the Subprocessors listed in the current Privacy Policy for the purposes described there. TailorFlow will:
To the extent that the processing of Personal Data involves transfers from the European Economic Area, the United Kingdom or Switzerland to a country not deemed adequate by the relevant authority, the parties agree that such transfers shall be governed by the current EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and, for UK transfers, the UK International Data Transfer Addendum, both of which are incorporated by reference and shall prevail over any inconsistent term in this DPA.
Where End-Client photographs contain biometric or facial features (which may qualify as special-category data under GDPR Article 9 or as "biometric information" under state laws such as Illinois BIPA), the Controller represents that it has obtained explicit written consent from each End-Client in accordance with the applicable law before uploading such photographs. TailorFlow does not process biometric data for the purpose of uniquely identifying a natural person; it processes photographs solely to render garment previews on behalf of the Controller.
If TailorFlow receives a request directly from a Data Subject, it will refer the Data Subject to the Controller and notify the Controller within 5 business days. TailorFlow will assist the Controller in responding to such requests at no additional charge for reasonable volumes.
For processing subject to the California Consumer Privacy Act, as amended:
TailorFlow shall make available to the Controller, on reasonable request, information necessary to demonstrate compliance with this DPA (e.g. current SOC 2 report when available, security whitepaper, penetration test summary). On-site audits will be permitted no more than once every 12 months, at the Controller's expense, on 30 days' written notice, and shall not unduly disrupt TailorFlow's operations.
This DPA is effective from the Controller's acceptance and remains in force for as long as TailorFlow processes Personal Data on behalf of the Controller. On termination, the parties will follow the deletion / return procedure described in Section 4.
In case of conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data. The EU SCCs (where applicable) prevail over both.
For a countersigned copy of this DPA, contact legal@tailorflow.tech.