DATA PROTECTION
Data Processing Addendum
This Data Processing Addendum contains processor-contract terms required under Article 28 of the GDPR and UK GDPR, international-transfer provisions based on the European Commission’s 2021 Standard Contractual Clauses, and service-provider restrictions relevant under the California Consumer Privacy Act. ( Eur-Lex )
This document is designed for use with WardrobeIt’s merchant agreement. WardrobeIt’s actual hosting locations, subprocessors, security controls, deletion processes, Artificial Intelligence providers, and Virtual Try-On practices must match this Addendum before publication or execution.
This Data Processing Addendum, referred to as the “DPA,” forms part of the agreement governing access to and use of WardrobeIt’s services between WardrobeIt and the merchant, customer, or other organization accepting that agreement.
In this DPA:
- “WardrobeIt,” “we,” “us,” or “our” means the WardrobeIt service provider identified in the Agreement.
- “Customer,” “Merchant,” “you,” or “your” means the organization that has entered into the Agreement with WardrobeIt.
- “Agreement” means the agreement, order form, subscription terms, statement of work, or other written arrangement governing Customer’s use of WardrobeIt.
- “Services” means the WardrobeIt website, Merchant Portal, AI Shopping Assistant, conversational product-discovery tools, product recommendations, Product Q&A, Virtual Try-On, Complete-the-Look experiences, cart-related functionality, analytics, integrations, and related services made available under the Agreement.
This DPA applies when WardrobeIt processes Customer Personal Data on behalf of Customer in connection with the Services.
By entering into the Agreement, accepting this DPA, signing an order form that references this DPA, or using Services that involve the processing of Customer Personal Data, the parties agree to the terms below.
Relationship with the Agreement
This DPA is incorporated into and forms part of the Agreement.
If there is a conflict between this DPA and the Agreement concerning the processing or protection of Customer Personal Data, this DPA controls to the extent of that conflict.
If applicable Standard Contractual Clauses conflict with this DPA or the Agreement, the Standard Contractual Clauses control to the extent of that conflict.
Except as modified by this DPA, the Agreement remains in effect.
Definitions
Applicable Data Protection Law
“Applicable Data Protection Law” means any privacy, data-protection, data-security, or breach-notification law applicable to the processing of Customer Personal Data under the Agreement.
Applicable Data Protection Law may include, where relevant:
- The General Data Protection Regulation, Regulation (EU) 2016/679
- The United Kingdom General Data Protection Regulation
- The United Kingdom Data Protection Act 2018
- The Swiss Federal Act on Data Protection
- The California Consumer Privacy Act, as amended by the California Privacy Rights Act
- Other applicable United States state privacy laws
- Other national, state, provincial, or local privacy laws applicable to the Services
Customer Personal Data
“Customer Personal Data” means Personal Data processed by WardrobeIt on behalf of Customer in connection with the Services.
Customer Personal Data does not include information for which WardrobeIt independently determines the purposes and means of processing, such as certain WardrobeIt business-contact, account-administration, billing, security, legal-compliance, or direct-relationship information.
WardrobeIt’s independent processing activities are governed by the WardrobeIt Privacy Policy.
Data Subject
“Data Subject” means the identified or identifiable person to whom Customer Personal Data relates.
A Data Subject may include:
- A shopper
- A customer of the Merchant
- A merchant employee
- A merchant administrator
- An authorized Merchant Portal user
- A person communicating with Customer through WardrobeIt
Personal Data
“Personal Data” means information relating to an identified or identifiable person, household, or device and includes any equivalent term, such as “personal information,” defined under Applicable Data Protection Law.
Process and Processing
“Process,” “Processing,” and “Processed” have the meanings provided under Applicable Data Protection Law.
Controller and Processor
“Controller” means the party that determines the purposes and means of processing Personal Data.
“Processor” means a party that processes Personal Data on behalf of a Controller.
Where California privacy law applies, references to Controller and Processor include the corresponding concepts of Business, Service Provider, and Contractor where appropriate.
Subprocessor
“Subprocessor” means a third party appointed by WardrobeIt to process Customer Personal Data on behalf of Customer in connection with the Services.
Security Incident
“Security Incident” means a confirmed breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by WardrobeIt.
Security Incident does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked login attempts, network scans, unsuccessful denial-of-service attacks, pings, or other unsuccessful security events.
Standard Contractual Clauses
“Standard Contractual Clauses” or “SCCs” means the applicable standard contractual clauses approved for international transfers of Personal Data, including:
- The European Commission Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914
- The United Kingdom International Data Transfer Addendum or International Data Transfer Agreement, where applicable
- Any successor clauses formally adopted by a competent authority
Roles of the Parties
For Customer Personal Data processed through the Services:
- Customer generally acts as the Controller or Business.
- WardrobeIt generally acts as the Processor, Service Provider, or Contractor.
- If Customer acts as a Processor for another Controller, WardrobeIt acts as Customer’s Subprocessor.
Customer is responsible for determining whether it is acting as a Controller, Business, Joint Controller, or Processor in each relevant context.
WardrobeIt may act as an independent Controller for limited processing activities where WardrobeIt determines the purposes and means of processing, including:
- Merchant account administration
- Billing and subscription management
- WardrobeIt’s own website operations
- Business communications
- Security monitoring
- Fraud prevention
- Service protection
- Legal compliance
- Establishing, exercising, or defending legal claims
Such independent processing is outside the scope of this DPA and remains subject to Applicable Data Protection Law and the WardrobeIt Privacy Policy.
Customer Instructions
WardrobeIt will process Customer Personal Data only:
- On Customer’s documented instructions
- To provide, maintain, secure, and support the Services
- As described in the Agreement, this DPA, applicable order forms, and Customer’s configuration of the Services
- As required by Applicable Data Protection Law
The Agreement, this DPA, Customer’s use and configuration of the Services, authorized support requests, and written instructions issued by Customer constitute Customer’s documented instructions.
WardrobeIt will not process Customer Personal Data for an unrelated purpose unless:
- Customer provides additional documented instructions
- The processing is required by applicable law
- The information has been validly aggregated or de-identified so that it no longer constitutes Personal Data
If applicable law requires WardrobeIt to process Customer Personal Data other than on Customer’s instructions, WardrobeIt will notify Customer before processing unless the law prohibits notification.
WardrobeIt will promptly inform Customer if, in WardrobeIt’s reasonable opinion, an instruction infringes Applicable Data Protection Law. WardrobeIt may suspend the affected processing while the parties work to resolve the issue.
WardrobeIt is not responsible for determining whether Customer’s instructions comply with laws that apply specifically to Customer, Customer’s industry, Customer’s products, or Customer’s relationship with its shoppers.
Customer Responsibilities
Customer is responsible for:
- Complying with Applicable Data Protection Law
- Providing legally sufficient privacy notices
- Establishing an appropriate legal basis for processing
- Obtaining valid consent where required
- Ensuring that Customer’s instructions are lawful
- Ensuring that Personal Data submitted to WardrobeIt is accurate and collected lawfully
- Configuring the Services in a privacy-compliant manner
- Managing authorized users and permissions
- Protecting account credentials and store-access information
- Responding to Data Subject requests when Customer acts as Controller
- Configuring cookie and consent-management tools where required
- Providing required disclosures concerning Artificial Intelligence and Virtual Try-On
- Ensuring that product, policy, shipping, return, and merchant information supplied to WardrobeIt is accurate
- Avoiding the submission of unnecessary or unsupported sensitive information
- Ensuring that Customer has authority to instruct WardrobeIt to process Customer Personal Data
Customer will not instruct WardrobeIt to process Personal Data in a manner that violates Applicable Data Protection Law.
Customer will not use the Services to unlawfully discriminate against individuals, make prohibited decisions, collect unlawful sensitive information, or perform prohibited surveillance.
Details of Processing
The subject matter, nature, purpose, duration, categories of Personal Data, and categories of Data Subjects are described in the Processing Details section of this DPA.
Customer acknowledges that the exact processing depends on:
- The WardrobeIt features Customer enables
- Customer’s store configuration
- Customer’s product catalog
- Customer’s merchant knowledge
- Customer’s integrations
- The information submitted by shoppers
- The analytics and reporting capabilities included in Customer’s plan
Confidentiality
WardrobeIt will ensure that personnel authorized to process Customer Personal Data:
- Are subject to appropriate confidentiality obligations
- Receive access only where reasonably necessary for their responsibilities
- Process Customer Personal Data only in accordance with this DPA and applicable instructions
- Receive appropriate privacy and security guidance relevant to their roles
WardrobeIt will take reasonable steps to ensure that authorized personnel understand and comply with their confidentiality obligations.
These confidentiality obligations continue after the individual’s employment or engagement ends.
Security of Processing
WardrobeIt will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental or unlawful destruction, loss, alteration, disclosure, or access.
Security measures will be appropriate to:
- The nature of the Customer Personal Data
- The scope and context of processing
- The available technology
- The cost of implementation
- The likelihood and severity of risks to individuals
- The features and integrations enabled by Customer
WardrobeIt’s security measures may include, as appropriate:
- Access controls
- Authentication controls
- Role-based permissions
- Least-privilege access
- Encryption in transit
- Encryption at rest where supported
- Secure credential handling
- Environment separation
- Logging and monitoring
- Vulnerability management
- Software-update processes
- Backup and recovery measures
- Service-availability measures
- Incident-response procedures
- Employee and contractor confidentiality requirements
- Subprocessor due diligence
- Secure development practices
- Change-management processes
- Data-minimization measures
- Retention and deletion controls
WardrobeIt may update its security measures as technology, risk, and the Services evolve, provided that the overall level of protection is not materially reduced during the applicable subscription period.
Customer is responsible for using the security features available through the Services and for protecting its own systems, accounts, devices, credentials, themes, integrations, and authorized-user access.
Artificial Intelligence Processing
WardrobeIt may use Artificial Intelligence and machine-learning technologies to provide features such as:
- Conversational product discovery
- Shopper-intent interpretation
- Catalog-connected recommendations
- Product comparison
- Product questions and answers
- Virtual Try-On
- Complete-the-Look experiences
- Merchant analytics
- Other Services expressly enabled by Customer
WardrobeIt will process Customer Personal Data through Artificial Intelligence systems only as necessary to provide, secure, maintain, or support the Services and in accordance with Customer’s documented instructions.
WardrobeIt will not use Customer Personal Data to train a general-purpose model for the benefit of unrelated third parties unless:
- Customer has expressly authorized that use in writing
- The information has been de-identified so that it no longer constitutes Personal Data
- The use is otherwise lawfully permitted and transparently disclosed
WardrobeIt will not knowingly use shopper conversations or Virtual Try-On images to identify individuals through biometric recognition unless expressly agreed in writing and lawfully implemented.
Customer is responsible for determining whether it must provide notices, obtain consent, or perform an impact assessment before enabling an Artificial Intelligence feature.
Virtual Try-On Processing
Where Customer enables Virtual Try-On, WardrobeIt may process:
- Images uploaded or captured by shoppers
- Selected product information
- Product images
- Selected colours or variants
- Generated try-on previews
- Technical metadata
- Session identifiers
- Processing-status information
- Error and diagnostic information
- Related product, assistant, and cart interactions
WardrobeIt will process Virtual Try-On images to provide the requested preview, operate and secure the feature, troubleshoot errors, and perform other processing authorized by Customer.
WardrobeIt will not represent a Virtual Try-On result as guaranteeing exact:
- Fit
- Size
- Scale
- Colour
- Texture
- Fabric movement
- Body appearance
- Real-world product appearance
Customer is responsible for presenting appropriate disclosures and obtaining any consent required for image processing.
Customer will not knowingly direct children to upload images without legally required parental or guardian authorization.
WardrobeIt will apply retention and deletion practices consistent with the active Virtual Try-On configuration, the Agreement, this DPA, and Applicable Data Protection Law.
Sensitive Personal Data
Customer will not submit or instruct WardrobeIt to process sensitive or special-category Personal Data unless:
- The relevant feature is expressly designed to support it
- The parties have agreed to the processing
- Customer has established a valid legal basis
- Appropriate safeguards have been implemented
Sensitive Personal Data may include:
- Government identification numbers
- Payment-card information
- Financial-account credentials
- Precise geolocation
- Health information
- Genetic information
- Biometric information used for identification
- Racial or ethnic origin
- Religious or philosophical beliefs
- Political opinions
- Trade-union membership
- Information concerning sex life or sexual orientation
- Personal Data relating to criminal convictions
- Account passwords
- Other information classified as sensitive under Applicable Data Protection Law
Customer acknowledges that shopper-provided images or conversational inputs may incidentally reveal sensitive characteristics. Customer is responsible for providing appropriate instructions, notices, and consent mechanisms where required.
Children’s Data
The Services are not designed or directed toward children under 13 or any higher minimum age required by Applicable Data Protection Law.
Customer will not knowingly use the Services to collect or process children’s Personal Data without:
- WardrobeIt’s prior written approval
- A lawful basis
- Legally required parental or guardian consent
- Appropriate notices
- Age-appropriate safeguards
- Any additional contractual terms requested by WardrobeIt
If WardrobeIt reasonably believes Customer Personal Data has been collected from a child contrary to the Agreement or Applicable Data Protection Law, WardrobeIt may suspend the affected processing and notify Customer.
Subprocessors
Customer grants WardrobeIt general written authorization to appoint Subprocessors necessary to provide, maintain, support, secure, and improve the Services.
Subprocessors may provide services such as:
- Cloud hosting
- Data storage
- Database services
- Artificial Intelligence processing
- Image processing
- Virtual Try-On generation
- Content delivery
- Error monitoring
- Analytics
- Communications
- Customer support
- Billing
- Payment processing
- Security
- Fraud prevention
- Catalog synchronization
- Ecommerce integrations
- Technical support
WardrobeIt will:
- Conduct reasonable due diligence before appointing a Subprocessor
- Enter into a written agreement requiring the Subprocessor to protect Customer Personal Data
- Impose data-protection obligations appropriate to the processing
- Restrict the Subprocessor to authorized purposes
- Remain responsible for the Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law
A current Subprocessor list will be made available to Customer through a designated WardrobeIt webpage, Merchant Portal location, contractual disclosure, or upon request at:
hi@wardrobeit.com
Changes to Subprocessors
WardrobeIt will provide reasonable advance notice before appointing a new Subprocessor that will materially process Customer Personal Data.
Notice may be provided through:
- The Merchant Portal
- A Subprocessor notification page
- A service notice
- Another reasonable electronic method
Customer may object to a new Subprocessor on reasonable data-protection grounds by contacting:
hi@wardrobeit.com
Customer must submit its objection within the period stated in the notice or, if no period is stated, within fifteen days after receiving notice.
The objection must explain the specific data-protection concern.
The parties will work in good faith to resolve the objection. WardrobeIt may:
- Provide additional information
- Apply additional safeguards
- Offer a reasonable configuration change
- Avoid using the Subprocessor for Customer where technically and commercially reasonable
- Permit Customer to discontinue the materially affected Service
If no reasonable resolution is available, either party may terminate the affected portion of the Services according to the Agreement.
An objection does not relieve Customer of payment obligations arising before the effective termination date.
Assistance with Data Subject Requests
Taking into account the nature of the processing, WardrobeIt will provide reasonable assistance to Customer in responding to valid Data Subject requests concerning Customer Personal Data.
Requests may concern:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Portability
- Withdrawal of consent
- Opt-out rights
- Rights relating to automated decision-making
- Other rights available under Applicable Data Protection Law
If WardrobeIt receives a request directly from a Data Subject concerning Customer Personal Data, WardrobeIt may:
- Direct the person to Customer
- Notify Customer
- Forward the request to Customer
- Take another reasonable action consistent with Applicable Data Protection Law
WardrobeIt will not independently respond to the substance of a request where Customer is responsible for the response, unless:
- Customer instructs WardrobeIt to respond
- Applicable law requires WardrobeIt to respond
- The request concerns processing for which WardrobeIt acts as an independent Controller
Customer remains responsible for:
- Verifying the requester’s identity
- Determining whether the request is valid
- Determining whether an exception applies
- Communicating with the Data Subject
- Meeting applicable response deadlines
WardrobeIt may charge reasonable fees for assistance that is unusually complex, repetitive, excessive, or outside the standard functionality of the Services, where permitted by the Agreement and Applicable Data Protection Law.
Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to WardrobeIt, WardrobeIt will provide reasonable assistance where Customer is required to conduct:
- A data-protection impact assessment
- A privacy impact assessment
- A transfer impact assessment
- A legitimate-interests assessment
- A risk assessment concerning Artificial Intelligence or automated processing
- Another assessment required under Applicable Data Protection Law
Customer remains responsible for determining whether an assessment is required and for completing, approving, and maintaining that assessment.
WardrobeIt may provide relevant documentation concerning the Services, security measures, processing operations, or subprocessors, subject to confidentiality and security restrictions.
Regulatory Consultations
WardrobeIt will provide reasonable assistance if Customer is required to consult a supervisory authority concerning processing performed through the Services.
Customer remains responsible for:
- Determining whether consultation is required
- Communicating with the supervisory authority
- Preparing submissions
- Obtaining any required authorization
WardrobeIt may charge reasonable fees for substantial assistance outside the ordinary operation of the Services.
Security Incident Notification
WardrobeIt will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
Notification may be delivered to Customer’s account administrator, designated security contact, or another contact associated with Customer’s account.
To the extent known and reasonably available, WardrobeIt’s notification may include:
- The nature of the Security Incident
- The date or estimated period of the Security Incident
- The categories of affected Data Subjects
- The categories of affected Customer Personal Data
- The approximate number of affected records or individuals
- The likely consequences
- Measures taken or proposed
- Steps Customer may consider
- A contact point for further information
WardrobeIt may provide information in stages as the investigation continues.
WardrobeIt’s notification of a Security Incident does not constitute an admission of fault, liability, or violation of law.
WardrobeIt will:
- Investigate the Security Incident
- Take reasonable steps to contain and remediate it
- Preserve relevant information where appropriate
- Cooperate reasonably with Customer
- Provide updates where material information becomes available
Customer is responsible for determining whether it must notify:
- Data Subjects
- Supervisory authorities
- Regulators
- Insurers
- Business partners
- Other third parties
WardrobeIt will not notify Data Subjects or authorities on Customer’s behalf unless:
- Customer instructs WardrobeIt to do so
- Applicable law requires WardrobeIt to act directly
- Immediate action is reasonably necessary to prevent harm and consultation with Customer is not practicable
Return and Deletion of Customer Personal Data
During the term of the Agreement, Customer may access, retrieve, correct, or delete Customer Personal Data through available Service functionality.
After termination or expiration of the Agreement, WardrobeIt will, according to Customer’s instructions and subject to the Agreement:
- Return Customer Personal Data
- Make Customer Personal Data available for export where supported
- Delete Customer Personal Data
- De-identify Customer Personal Data
WardrobeIt may retain Customer Personal Data where required by law, provided that:
- The retained information remains protected
- Processing is limited to the legally required purpose
- The information is deleted when the legal requirement ends
Customer Personal Data may remain temporarily in backups or disaster-recovery systems until overwritten according to WardrobeIt’s standard retention cycle.
WardrobeIt is not required to restore archived backups solely to delete individual records where:
- The data is not available in an active production system
- The backup is protected and access-restricted
- The data will be deleted through the normal backup lifecycle
- The data will not be used for another purpose
WardrobeIt may retain aggregated or de-identified information that no longer identifies a Data Subject.
Audits and Compliance Information
WardrobeIt will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA and Applicable Data Protection Law.
Compliance information may include:
- Security documentation
- Policies and procedures
- Subprocessor information
- Questionnaire responses
- Independent audit reports, where available
- Certifications, where obtained
- Penetration-testing summaries, where available and appropriate
- Other relevant compliance materials
Customer should first use the documentation WardrobeIt makes available remotely.
If that information is insufficient to address a reasonable compliance concern, Customer may request an audit.
Any audit must:
- Be limited to processing relevant to Customer
- Be conducted during normal business hours
- Be scheduled with reasonable advance notice
- Avoid unreasonable disruption
- Protect the confidentiality of WardrobeIt and other customers
- Avoid access to other customers’ information
- Be performed by an independent auditor subject to confidentiality obligations
- Follow reasonable security and site-access requirements
- Occur no more than once in a twelve-month period unless required by law or prompted by a material Security Incident
Customer is responsible for its audit costs.
WardrobeIt may charge reasonable fees for substantial audit support, unless the audit identifies a material breach by WardrobeIt of this DPA.
WardrobeIt may object to an auditor that is:
- A direct competitor
- Not appropriately qualified
- Unable to provide adequate confidentiality commitments
- A security risk
- Otherwise reasonably unsuitable
Nothing in this section limits a competent supervisory authority’s lawful audit or investigation powers.
International Data Transfers
WardrobeIt may process Customer Personal Data in countries other than the country where Customer or the Data Subject is located.
Where Applicable Data Protection Law requires a transfer mechanism, the parties will use an appropriate safeguard, which may include:
- An adequacy decision
- Standard Contractual Clauses
- The United Kingdom International Data Transfer Addendum
- The United Kingdom International Data Transfer Agreement
- A legally recognized certification or code
- Binding corporate rules
- Another valid transfer mechanism
WardrobeIt will apply reasonable supplementary safeguards where required by Applicable Data Protection Law and the circumstances of the transfer.
European Economic Area Transfers
Where Customer Personal Data protected by the GDPR is transferred to WardrobeIt in a country that has not received an applicable adequacy decision, the European Commission Standard Contractual Clauses are incorporated into this DPA by reference.
The SCCs will be completed as follows:
- Module Two applies where Customer is a Controller and WardrobeIt is a Processor.
- Module Three applies where Customer is a Processor and WardrobeIt is a Subprocessor.
- Clause 7, the docking clause, applies.
- Under Clause 9, general written authorization for Subprocessors applies.
- WardrobeIt will provide advance notice of Subprocessor changes as described in this DPA.
- The optional independent dispute-resolution language in Clause 11 does not apply unless the parties agree otherwise.
- The supervisory authority is determined according to Clause 13 of the SCCs.
- The governing law under Clause 17 will be the law of an EU Member State that permits third-party beneficiary rights. Unless otherwise specified in the Agreement, the laws of Ireland apply.
- The courts under Clause 18 will be the courts corresponding to the governing law selected under Clause 17.
- Annex I of the SCCs is completed using the information in the Processing Details section of this DPA.
- Annex II of the SCCs is completed using the Security Measures section of this DPA.
- Annex III is completed using WardrobeIt’s current Subprocessor list where applicable.
If the SCCs are revised, replaced, or invalidated, the parties will cooperate in good faith to implement a valid replacement mechanism.
United Kingdom Transfers
Where Customer Personal Data protected by United Kingdom data-protection law is transferred to a country without an applicable adequacy regulation, the parties will use:
- The United Kingdom International Data Transfer Addendum to the EU SCCs
- The United Kingdom International Data Transfer Agreement
- Another legally valid United Kingdom transfer mechanism
Where the United Kingdom Addendum applies:
- The EU SCCs are completed as described in this DPA.
- References to the GDPR are interpreted to include applicable United Kingdom data-protection law.
- The competent authority is the United Kingdom Information Commissioner’s Office.
- The governing law and courts will be determined as required by the applicable United Kingdom transfer mechanism.
Swiss Transfers
Where Customer Personal Data protected by Swiss data-protection law is transferred internationally, the SCCs apply with modifications required under Swiss law.
References to:
- The GDPR include the Swiss Federal Act on Data Protection where applicable.
- An EU supervisory authority include the Swiss Federal Data Protection and Information Commissioner.
- An EU Member State include Switzerland where legally appropriate.
Data Subjects in Switzerland may enforce rights available to them under applicable Swiss law.
California Service Provider and Contractor Terms
Where the California Consumer Privacy Act applies to Customer Personal Data:
- Customer discloses Customer Personal Data to WardrobeIt only for the limited and specified business purposes described in the Agreement and this DPA.
- WardrobeIt will process the information only to provide the Services, perform the specified business purposes, and comply with applicable law.
- WardrobeIt will not sell or share Customer Personal Data.
- WardrobeIt will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law.
- WardrobeIt will not retain, use, or disclose Customer Personal Data for a commercial purpose other than the business purposes specified in the Agreement and this DPA.
- WardrobeIt will not combine Customer Personal Data with Personal Data received from another person or collected from WardrobeIt’s independent interaction with a consumer, except where legally permitted.
- WardrobeIt will provide the same level of privacy protection required of a Service Provider or Contractor under applicable California law.
- WardrobeIt will notify Customer if it determines that it can no longer meet its applicable obligations.
- Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
- WardrobeIt will require applicable Subprocessors to comply with appropriate service-provider or contractor restrictions.
The parties acknowledge that Customer is making Customer Personal Data available to WardrobeIt for the limited purposes described in the Agreement and not as consideration for money or another unrelated commercial benefit.
Other United States State Privacy Laws
Where another United States state privacy law applies, WardrobeIt will:
- Process Customer Personal Data according to Customer’s instructions
- Maintain confidentiality
- Implement appropriate security measures
- Assist with applicable consumer-rights requests
- Provide information reasonably necessary for Customer’s compliance
- Use Subprocessors under appropriate contractual restrictions
- Delete or return Customer Personal Data as required
- Allow reasonable compliance assessments
- Avoid selling or using Customer Personal Data for unrelated targeted advertising where prohibited
The parties will interpret this DPA to satisfy equivalent Controller-Processor requirements under applicable state law.
Government and Law-Enforcement Requests
If WardrobeIt receives a legally binding request from a public authority for Customer Personal Data, WardrobeIt will, where legally permitted:
- Review the request
- Verify that it is valid and appropriately scoped
- Challenge unlawful or disproportionate requests where reasonable
- Disclose only the information legally required
- Notify Customer before disclosure
- Document the request and response
If WardrobeIt is legally prohibited from notifying Customer, WardrobeIt may take reasonable steps to seek permission to provide notice.
WardrobeIt will not voluntarily provide public authorities with direct, unrestricted, or bulk access to Customer Personal Data.
Records and Cooperation
WardrobeIt will maintain records of processing activities where required by Applicable Data Protection Law.
The parties will reasonably cooperate to demonstrate compliance with this DPA.
Each party is responsible for maintaining the records, notices, policies, and assessments required for its own role.
Liability
Each party’s liability arising from this DPA is subject to the exclusions, limitations, disclaimers, and remedies stated in the Agreement, except where Applicable Data Protection Law prohibits such limitation.
Nothing in this DPA limits:
- A Data Subject’s rights under Applicable Data Protection Law
- A supervisory authority’s powers
- Liability that cannot lawfully be limited
Term and Termination
This DPA begins when the Agreement becomes effective and continues for as long as WardrobeIt processes Customer Personal Data on Customer’s behalf.
Obligations that by their nature should survive termination will remain in effect, including obligations relating to:
- Confidentiality
- Security
- Deletion
- International transfers
- Regulatory cooperation
- Liability
- Audit records
Updates to This DPA
WardrobeIt may update this DPA where reasonably necessary to:
- Comply with changes in law
- Adopt a new approved transfer mechanism
- Reflect changes to the Services
- Improve privacy or security protections
- Address regulatory guidance
- Correct errors or clarify existing terms
WardrobeIt will not materially reduce its data-protection obligations during an active subscription period without providing reasonable notice, unless a change is required by law.
If an update materially affects Customer’s rights or obligations, WardrobeIt may provide notice through:
- The Merchant Portal
- The WardrobeIt website
- An updated order form
- Another reasonable electronic method
Contact WardrobeIt
Questions, privacy requests, Subprocessor objections, compliance inquiries, and notices relating to this DPA should be sent to:
hi@wardrobeit.com
Subject Matter
WardrobeIt processes Customer Personal Data to provide the WardrobeIt Services requested by Customer.
The Services may include:
- Merchant onboarding
- Account administration
- Ecommerce store connection
- Catalog synchronization
- AI-assisted shopping conversations
- Product discovery
- Catalog-only recommendations
- Product comparison
- Product and store questions
- Size and fit guidance
- Virtual Try-On
- Complete-the-Look experiences
- Product and variant selection
- Cart actions
- Checkout continuation
- Usage analytics
- Outcome reporting
- Technical support
- Security and fraud prevention
Duration
Processing continues for:
- The term of the Agreement
- Any period during which WardrobeIt provides the Services
- A limited period afterward for deletion, return, backups, legal compliance, dispute resolution, and security
Specific retention periods depend on the category of information, Customer’s configuration, the Agreement, and Applicable Data Protection Law.
Nature of Processing
Processing may include:
- Collection
- Receipt
- Recording
- Organization
- Structuring
- Hosting
- Storage
- Retrieval
- Consultation
- Analysis
- Classification
- Matching
- Generation
- Transmission
- Display
- Synchronization
- Modification
- Restriction
- Aggregation
- De-identification
- Deletion
- Destruction
Purposes of Processing
WardrobeIt processes Customer Personal Data to:
- Provide the Services
- Maintain merchant accounts
- Synchronize approved store and catalog information
- Interpret shopper requests
- Recommend merchant products
- Answer product and store questions
- Generate Virtual Try-On previews
- Support product comparison
- Support Complete-the-Look experiences
- Confirm product and variant selections
- Support cart and checkout actions
- Provide analytics and outcome reporting
- Maintain security
- Prevent abuse and fraud
- Troubleshoot errors
- Provide support
- Comply with documented Customer instructions
Categories of Data Subjects
Customer Personal Data may relate to:
- Shoppers
- Merchant customers
- Website users
- Merchant employees
- Merchant administrators
- Merchant contractors
- Authorized Merchant Portal users
- Customer-support contacts
- Individuals appearing in submitted images
- Other individuals whose Personal Data Customer lawfully submits to the Services
Categories of Customer Personal Data
Depending on Customer’s configuration, WardrobeIt may process:
Identity and Contact Information
- Name
- Email address
- Customer or account identifier
- Merchant-user identifier
- Support contact information
Account and Access Information
- Login information
- Authentication records
- Role and permission information
- Account settings
- Session identifiers
Shopper Conversation Information
- Questions
- Requests
- Product needs
- Product preferences
- Style preferences
- Colour preferences
- Budget information
- Size and fit preferences
- Occasion information
- Product concerns
- Delivery questions
- Return questions
- Conversation history
Product and Shopping Information
- Products viewed
- Products recommended
- Product comparisons
- Recommendation clicks
- Product questions
- Selected variants
- Sizes
- Colours
- Cart contents
- Cart value
- Cart actions
- Checkout progression
- Purchase outcomes
- Returns, refunds, and cancellations where connected
Virtual Try-On Information
- Uploaded or captured images
- Generated previews
- Selected products
- Selected colours or variants
- Try-on session information
- Processing-status information
- Technical diagnostics
Technical Information
- Internet Protocol address
- Browser information
- Device information
- Operating system
- Language
- Approximate location derived from technical information
- Date and time
- Referrer
- Landing page
- UTM parameters
- Application logs
- Error information
- Security events
- Cookie and local-storage identifiers
Support Information
- Support requests
- Troubleshooting details
- Attachments
- Communications
- Feedback
Order and Transaction Information
Where supported and connected:
- Order identifier
- Product and variant details
- Quantity
- Price
- Currency
- Discounts
- Shipping information
- Order status
- Refund or cancellation information
Complete payment-card details should ordinarily be processed by the applicable payment provider rather than WardrobeIt.
Sensitive Data
Sensitive or special-category information is not required for the ordinary use of WardrobeIt.
Images or free-text conversations may incidentally reveal sensitive characteristics. Customer must not intentionally use WardrobeIt to process sensitive information unless the processing is supported, lawful, and expressly agreed.
Processing Frequency
Processing may occur:
- Continuously during active Services
- When Customer synchronizes its store
- When a shopper interacts with WardrobeIt
- When an authorized merchant user accesses the Merchant Portal
- When Customer requests support
- When supported commerce events occur
- When necessary for security, backups, and maintenance
WardrobeIt will maintain measures appropriate to the applicable risk. Depending on the Services and environment, measures may include the following.
Access Control
- Role-based access
- Least-privilege permissions
- Restricted production access
- Authentication requirements
- Periodic access review
- Account deactivation following role changes
- Confidentiality obligations
Data Protection
- Encryption in transit
- Encryption at rest where supported
- Secure credential storage
- Separation of merchant environments or tenant-scoped access
- Controls designed to prevent unauthorized cross-merchant access
- Data-minimization practices
- Controlled deletion procedures
Application and Infrastructure Security
- Secure software-development practices
- Code review
- Dependency and patch management
- Vulnerability monitoring
- Logging and alerting
- Environment separation
- Network protections
- Rate limiting and abuse prevention where appropriate
Availability and Recovery
- Backup procedures
- Recovery processes
- Availability monitoring
- Incident-response procedures
- Business-continuity measures appropriate to the Services
- Capacity and performance monitoring
Personnel Security
- Confidentiality commitments
- Role-appropriate privacy and security guidance
- Access based on job responsibilities
- Removal of access when no longer required
- Contractor controls where applicable
Subprocessor Management
- Due diligence
- Written data-protection obligations
- Purpose limitations
- Security requirements
- Confidentiality requirements
- International-transfer safeguards where required
- Ongoing review appropriate to the risk
Incident Management
- Security-event monitoring
- Incident assessment
- Containment procedures
- Remediation processes
- Documentation
- Customer notification procedures
- Post-incident review where appropriate
Data Lifecycle Management
- Retention controls
- Customer-directed deletion
- Account-termination procedures
- Backup expiration
- Secure disposal
- De-identification where appropriate
Artificial Intelligence and Image-Processing Controls
Where applicable:
- Authorized-purpose restrictions
- Input and output access controls
- Subprocessor restrictions
- Technical logging
- Temporary processing controls
- Image-retention controls
- Deletion workflows
- Measures designed to prevent unauthorized use of Customer Personal Data
WardrobeIt may use Subprocessors to provide infrastructure, Artificial Intelligence processing, Virtual Try-On, analytics, communications, support, billing, security, and related functionality.
The current list of Subprocessors, their processing purpose, and applicable processing locations will be available through the designated WardrobeIt disclosure or upon request at:
hi@wardrobeit.com
This DPA is accepted when Customer:
- Signs an Agreement or order form incorporating it
- Accepts it electronically
- Activates a WardrobeIt subscription governed by it
- Continues using the applicable Services after receiving and accepting the contractual terms
WardrobeIt privacy contact:
hi@wardrobeit.com