Data Processing Agreement
For merchants using Fesch Virtual Try-On · Effective 18 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant installing the Fesch app (the Controller) and Fesch (the Processor) and governs the processing of personal data under Article 28 GDPR. It applies automatically upon installation of the app.
1. Subject matter and duration
The Processor renders virtual try-on previews for the Controller's shoppers. Processing lasts for the duration of the app installation. Upon uninstallation, the Controller's shop record and all associated try-on and consent records are deleted; stored photos and renders expire automatically within 72 hours in any case.
2. Nature and purpose of processing
Receiving a shopper-submitted photo, running an automated usability check, compositing the garment image onto the photo via an image-generation provider, and returning the resulting render to the shopper's browser. No other use is made of the data. Shopper photos and renders are never used to train AI models.
3. Categories of data and data subjects
- Data subjects: shoppers of the Controller's store who voluntarily use the try-on feature.
- Data categories: shopper-submitted photos, generated try-on renders, an anonymous per-browser shopper token, consent records (token, shop domain, policy version, timestamp, optionally a hashed IP address), and pseudonymous try-on job records (token, product reference, job status). No names, contact details, or store account identifiers are processed; no biometric identification is performed.
4. Obligations of the Processor
- Process personal data only to provide the try-on service and per the Controller's documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures, including: processing exclusively within the European Union; encryption of stored photos at rest (AES-256); access to photos and renders only via short-lived signed URLs; automatic deletion of photos and renders after 72 hours via storage lifecycle rules; and a shopper-facing self-service deletion control ("Remove my photo").
- Assist the Controller in responding to data-subject requests. Because records are keyed only by an anonymous token, shopper-initiated deletion in the widget is the primary erasure path; the Processor also honours Shopify's
customers/redactandshop/redactcompliance webhooks. - Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's shoppers.
- Delete the Controller's data upon termination (uninstallation), as described in Section 1.
- Make available information reasonably necessary to demonstrate compliance with Article 28 GDPR.
5. Subprocessors
The Controller grants general authorisation for the subprocessors listed below. The Processor will update this page before adding or replacing a subprocessor; continued use of the app after an update constitutes acceptance, and the Controller may object by uninstalling the app.
| Subprocessor | Service | Purpose | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, object storage (S3), Amazon Bedrock | App hosting; encrypted storage of photos and renders with 72-hour lifecycle deletion; automated pre-generation photo usability check (Bedrock, via an EU-only inference profile) | eu-central-1 (Frankfurt, Germany); Bedrock routed within EU regions only |
| Black Forest Labs | FLUX virtual try-on API | Generating the try-on render from the shopper photo and garment image | EU endpoint (api.eu.bfl.ai) |
| Supabase | Managed PostgreSQL database | Consent records and pseudonymous try-on job metadata (no images) | Frankfurt, Germany (EU) |
Shopify is the commerce platform through which the app is distributed and operates under the merchant's own agreement with Shopify; it is not a subprocessor of Fesch.
6. International transfers
Shopper photos, renders, and try-on records are processed exclusively in the European Union.
7. Contact
Questions about this DPA: privacy@fesch.app. The shopper-facing policy is at /legal/privacy.