← Back to TailorFlow

Data Processing Agreement

Last updated · February 2026

This Data Processing Agreement ("DPA") supplements the TailorFlow Terms of Service between TailorFlow ("Processor") and the Retailer ("Controller") and governs the processing of Personal Data by TailorFlow on behalf of the Retailer. It is designed to comply with GDPR Article 28 and to satisfy CCPA/CPRA service-provider requirements.

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person uploaded to or generated by the Service (End-Client photos, names, contact details, generated renderings, style profile).
  • Data Subject — the End-Client whose Personal Data is processed.
  • Processing — has the meaning given in GDPR.
  • Subprocessor — a third party engaged by TailorFlow to help deliver the Service.

2. Roles

The Retailer is the Controller. TailorFlow is the Processor and acts only on the Controller's documented instructions. Each party shall comply with all applicable data-protection laws in its role.

3. Nature and purpose of processing

  • Subject matter: virtual fitting, AI-rendered garment previews, client-card lookbook delivery, order-support communication.
  • Duration: for the term of the Retailer's subscription plus any retention window described in the Privacy Policy.
  • Categories of data subjects: End-Clients of the Retailer.
  • Categories of data: photographs (potentially containing facial features), names, contact details, body measurements, garment preferences, order history.

4. Processor obligations

TailorFlow shall:

  • Process Personal Data only on the Controller's documented instructions
  • Ensure personnel with access to Personal Data are bound by confidentiality
  • Implement and maintain appropriate technical and organisational security measures (encryption in transit and at rest, JWT + HttpOnly cookies, tenant isolation at the database query layer, access controls)
  • Notify the Controller of any personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware
  • Assist the Controller in responding to Data Subject requests (access, rectification, deletion, portability)
  • On termination, delete or return all Personal Data at the Controller's choice, except where legally required to retain
  • Make available all information necessary to demonstrate compliance with this DPA and allow reasonable audits

5. Subprocessors

The Controller authorises TailorFlow to engage the Subprocessors listed in the current Privacy Policy for the purposes described there. TailorFlow will:

  • Impose data-protection obligations on Subprocessors that are no less protective than those in this DPA
  • Remain liable to the Controller for the acts and omissions of Subprocessors
  • Give the Controller at least 30 days' prior notice of any new Subprocessor, giving the Controller the right to object on reasonable grounds

6. International transfers

To the extent that the processing of Personal Data involves transfers from the European Economic Area, the United Kingdom or Switzerland to a country not deemed adequate by the relevant authority, the parties agree that such transfers shall be governed by the current EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and, for UK transfers, the UK International Data Transfer Addendum, both of which are incorporated by reference and shall prevail over any inconsistent term in this DPA.

7. Special-category and biometric data

Where End-Client photographs contain biometric or facial features (which may qualify as special-category data under GDPR Article 9 or as "biometric information" under state laws such as Illinois BIPA), the Controller represents that it has obtained explicit written consent from each End-Client in accordance with the applicable law before uploading such photographs. TailorFlow does not process biometric data for the purpose of uniquely identifying a natural person; it processes photographs solely to render garment previews on behalf of the Controller.

8. Data Subject requests

If TailorFlow receives a request directly from a Data Subject, it will refer the Data Subject to the Controller and notify the Controller within 5 business days. TailorFlow will assist the Controller in responding to such requests at no additional charge for reasonable volumes.

9. CCPA / CPRA — service provider terms

For processing subject to the California Consumer Privacy Act, as amended:

  • TailorFlow acts as a "service provider" as defined in the CCPA/CPRA
  • TailorFlow does not sell or share Personal Data
  • TailorFlow will not retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than the Business Purpose specified in the Terms and this DPA
  • TailorFlow will not combine Personal Data received from the Controller with Personal Data received from other sources except as permitted by the CCPA
  • TailorFlow certifies that it understands and will comply with these restrictions

10. Audits

TailorFlow shall make available to the Controller, on reasonable request, information necessary to demonstrate compliance with this DPA (e.g. current SOC 2 report when available, security whitepaper, penetration test summary). On-site audits will be permitted no more than once every 12 months, at the Controller's expense, on 30 days' written notice, and shall not unduly disrupt TailorFlow's operations.

11. Term and termination

This DPA is effective from the Controller's acceptance and remains in force for as long as TailorFlow processes Personal Data on behalf of the Controller. On termination, the parties will follow the deletion / return procedure described in Section 4.

12. Precedence

In case of conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data. The EU SCCs (where applicable) prevail over both.

For a countersigned copy of this DPA, contact legal@tailorflow.tech.

Powered by TailorFlow