Data Processing Addendum (DPA)
Last updated: September 6, 2026
This Data Processing Addendum ("DPA") forms part of the Ustyle Terms of Service (the "Terms") entered into between Ustyle SRL, c/o I3P, Incubatore del Politecnico di Torino, Corso Castelfidardo 30/A, 10129 Torino TO, Italy, VAT IT13348390017 ("Ustyle" or "Processor") and the merchant entity using the Ustyle service ("Merchant" or "Controller"), together the "Parties". It is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and governs the processing of End User personal data that Ustyle carries out on behalf of the Merchant in connection with the Ustyle AI-powered styling platform (the "Service").
This DPA is accepted electronically when the Merchant creates an Account or installs the Ustyle app, whichever occurs first, and is binding from that moment. Capitalized terms not defined here have the meaning given in the Terms. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
1. Scope, Roles, and Duration
1.1 Scope
This DPA applies to all personal data of End Users that Ustyle collects, receives, or synchronizes from the Merchant's storefront or Platform account in order to provide the Service ("End User Data"). The subject matter, nature, purpose, and duration of the processing, the categories of data subjects, and the categories of personal data are described in Annex 1.
1.2 Roles
For End User Data, the Merchant is the data controller and Ustyle is the data processor. This DPA does not apply to personal data of the Merchant's own staff and administrators (account, billing, and support data), for which Ustyle is an independent controller and which is governed by the Ustyle Privacy Policy.
1.3 Duration
This DPA applies for as long as Ustyle processes End User Data on behalf of the Merchant, that is, for the term of the Subscription and until the deletion or return of End User Data under Section 9.
2. Processing on Documented Instructions
2.1 Ustyle shall process End User Data only on the documented instructions of the Merchant, including with regard to transfers to third countries, unless required to do so by European Union or Member State law to which Ustyle is subject. In that case Ustyle shall inform the Merchant of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
2.2 The Merchant's complete instructions are set out in the Terms, this DPA, and the Annexes. Further instructions may be given in writing (including by email to [email protected]) and, where they exceed the scope of the Service, may be subject to a reasonable fee.
2.3 Ustyle shall immediately inform the Merchant if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. Ustyle may suspend the execution of that instruction until the Merchant confirms or modifies it.
2.4 Ustyle shall not use End User Data for its own purposes, and in particular shall not use End User Data, in identifiable form, to train, fine-tune, or improve generalized AI models, whether its own or those of any third party. Ustyle may produce and use aggregated statistics that do not identify the Merchant, its store, or any End User.
2.5 No End User Data is submitted to third-party generative AI providers. Only the Merchant's catalog data (product images, titles, descriptions, and metadata) is submitted to such providers for the generation of outfit combinations and imagery.
3. Confidentiality
Ustyle shall ensure that all persons authorized to process End User Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those persons who need it to perform the Service.
4. Security of Processing
4.1 Ustyle shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, in accordance with Article 32 GDPR. The measures currently in place are described in Annex 2.
4.2 Ustyle may update the measures in Annex 2 from time to time, provided that the updates do not reduce the overall level of security.
5. Sub-processors
5.1 The Merchant gives Ustyle general written authorization to engage sub-processors for the performance of the Service. The sub-processors engaged at the date of this DPA are listed in Annex 3 and on the Sub-processor List published on the Ustyle website.
5.2 Ustyle shall notify the Merchant by email, at the Merchant's registered Account address, of any intended addition or replacement of a sub-processor at least thirty (30) days before the new sub-processor starts processing End User Data. The Merchant may object in writing within that period on reasonable, documented data protection grounds.
5.3 If the Merchant objects and the Parties cannot reach a solution within fifteen (15) days of the objection, the Merchant may terminate the Subscription with respect to the affected Service, and Ustyle will refund any prepaid fees for the unused portion of the Subscription. If the Merchant does not object within the notice period, the new sub-processor is deemed authorized.
5.4 Ustyle shall impose on each sub-processor, by way of a written contract, data protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures. Ustyle remains fully liable to the Merchant for the performance of the sub-processor's obligations.
6. Assistance to the Controller
6.1 Data Subject Requests
6.1.1 Taking into account the nature of the processing, Ustyle shall assist the Merchant, by appropriate technical and organizational measures, in fulfilling its obligation to respond to requests by data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection).
6.1.2 Shopify stores. Ustyle is integrated with Shopify's mandatory privacy webhooks. Upon receipt of a customers/data_request webhook, Ustyle will make available to the Merchant, within thirty (30) days, all End User Data it holds that is linked to the requesting shopper. Upon receipt of a customers/redact webhook, Ustyle will erase all End User Data linked to that shopper from its production systems within forty-eight (48) hours and from backups within thirty (30) days.
6.1.3 WooCommerce and other Platforms. Where no automated webhook is available, the Merchant may submit data subject requests by email to [email protected], indicating the store, the request type, and the shopper identifier (such as the hashed customer ID or the order number). Ustyle will respond within ten (10) business days and in any case within the time needed for the Merchant to meet the one-month deadline under Article 12(3) GDPR.
6.1.4 If Ustyle receives a request directly from a data subject relating to End User Data, it shall not respond on the merits but shall forward the request to the Merchant without undue delay and inform the data subject that the request has been forwarded to the controller.
6.2 Security, Breach Notification, and Impact Assessments
6.2.1 Taking into account the nature of the processing and the information available to Ustyle, Ustyle shall assist the Merchant in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).
6.2.2 Ustyle shall notify the Merchant without undue delay, and in any case no later than forty-eight (48) hours after becoming aware of a personal data breach affecting End User Data, by email to the Merchant's registered Account address. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available. Ustyle shall not inform data subjects or supervisory authorities of a breach on the Merchant's behalf unless instructed to do so or required by law.
6.2.3 On request, Ustyle shall provide the Merchant with the information reasonably necessary to carry out a data protection impact assessment relating to the Service, to the extent such information is not already available in this DPA, its Annexes, and the Ustyle documentation.
7. Audits and Information
7.1 Ustyle shall make available to the Merchant all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, including, on request, summaries of security assessments, penetration test results, and the certifications or audit reports of its infrastructure sub-processors.
7.2 The Merchant, or an independent auditor mandated by the Merchant and bound by confidentiality, may audit Ustyle's compliance with this DPA no more than once per twelve (12) months, or additionally following a personal data breach or at the request of a supervisory authority. Audits require at least thirty (30) days' written notice, shall take place during business hours, shall not unreasonably disrupt Ustyle's operations, and shall be conducted at the Merchant's cost. Ustyle shall respond to written audit questionnaires within twenty (20) business days. Audit findings are Confidential Information of both Parties.
8. International Transfers
8.1 Ustyle stores and processes End User Data in the European Economic Area, on infrastructure located in Italy, the Netherlands, Ireland, and Germany, as set out in Annex 3.
8.2 Ustyle shall not transfer End User Data to a country outside the EEA that is not covered by an adequacy decision unless the transfer is covered by appropriate safeguards under Chapter V GDPR, namely (a) the EU-US Data Privacy Framework, for recipients certified under it, or (b) the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), together with any supplementary measures identified in a transfer impact assessment. The Merchant authorizes Ustyle to enter into such clauses with sub-processors on its behalf.
8.3 The Merchant's catalog data submitted to AI Providers may be processed outside the EEA, in the countries identified in the Sub-processor List. Such catalog data does not contain End User Data.
9. Deletion and Return of Data
9.1 Upon termination of the Subscription, uninstallation of the app, or the Merchant's written request, Ustyle shall, at the Merchant's choice, delete or return all End User Data and delete existing copies, unless Union or Member State law requires storage of the personal data.
9.2 Shopify stores. Uninstallation of the app triggers the shop/redact webhook. Ustyle shall permanently delete all End User Data, synchronized catalog data, SKU mappings, dashboard files, and transaction logs relating to that store from its production systems within thirty (30) days of uninstallation and from backups within a further thirty (30) days.
9.3 WooCommerce and other Platforms. Deactivating or deleting the plugin, or emailing [email protected], triggers the same deletion process and timeline.
9.4 Return. Where the Merchant requests return of End User Data before deletion, Ustyle shall provide it in a commonly used, machine-readable format (such as CSV or JSON) within thirty (30) days of the request. Ustyle shall confirm deletion in writing on request.
9.5 Retention required by law (for example tax and accounting records relating to the Merchant's Subscription) applies only to Merchant account data, not to End User Data.
10. Liability
10.1 Each Party's liability arising out of or related to this DPA is subject to the limitations and exclusions set out in Section 18 of the Terms. These limitations do not apply to either Party's liability towards data subjects under Article 82 GDPR, to fines imposed by a supervisory authority on a Party for its own infringement, or to wilful misconduct or gross negligence.
10.2 Where both Parties are involved in the same processing and are responsible for damage caused by processing, each Party is liable to the other only for the part of the damage attributable to its own responsibility, in accordance with Article 82(5) GDPR.
11. General Provisions
11.1 Ustyle shall maintain a record of the categories of processing activities carried out on behalf of the Merchant in accordance with Article 30(2) GDPR.
11.2 Ustyle has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. Data protection enquiries may be sent to [email protected].
11.3 The Merchant shall provide End Users with a privacy notice that discloses the processing carried out by Ustyle. Ustyle recommends the following wording, which the Merchant may adapt: "We use Ustyle (Ustyle SRL, Turin, Italy), an AI styling service that suggests outfits on our store. Ustyle processes your browsing and purchase activity on our store on our behalf, as our data processor, to show outfit suggestions and measure their performance. Data is stored in the European Union and deleted within 30 days. See Ustyle's Privacy Policy at https://ustyle.it for details."
11.4 This DPA is governed by the law and jurisdiction clause of the Terms, without prejudice to the mandatory provisions of the GDPR and of the Member State law applicable to the Merchant.
11.5 Ustyle may amend this DPA to reflect changes in law, in guidance from supervisory authorities, or in the Service, with thirty (30) days' notice by email, provided that the amendments do not reduce the level of protection for End User Data. The Merchant may object as set out in Section 5.3.
Annex 1: Description of the Processing
Subject matter and nature
Ingestion, storage, structuring, and analysis of End User behavioral data and order data from the Merchant's storefront, in order to display pre-generated outfit combinations through the Ustyle widget and to compute conversion and revenue attribution metrics for the Merchant's dashboard.
Purposes
- Serving pre-generated outfit combinations through the storefront widget
- Linking widget interactions to add-to-cart and checkout events to compute conversion and revenue attribution
- Populating the Merchant's performance dashboard
- Executing automated catalog and order synchronization via Platform APIs
- Responding to data subject requests forwarded by the Merchant or the Platform
Categories of data subjects
Visitors, shoppers, and customers of the Merchant's online store who view, click, or otherwise interact with the Ustyle widget, and customers whose orders fall within the 60-day attribution window.
Categories of personal data
- Online identifiers: pseudonymized IP address (truncated or hashed upon ingestion), Ustyle widget cookie identifier, Platform customer or session identifier, browser type and version, operating system, device type, and language.
- Behavioral data: pages and products viewed, widget impressions and clicks, outfit selections, add-to-cart events, timestamps.
- Order data (Shopify: "protected customer data", limited to the fields needed for attribution): order ID, order date, line items (product and variant IDs, quantities, prices), order total, currency, and hashed customer identifier. Ustyle does not store End User names, email addresses, postal addresses, phone numbers, or payment details.
- Approximate location: country and region derived from the IP address at ingestion, used for regional reporting; precise geolocation is not collected.
Special categories of data
None. The Merchant shall not configure the Service to process special categories of personal data.
Duration of processing and retention
For the term of the Subscription. Raw event data containing online identifiers is deleted or irreversibly aggregated within thirty (30) days of collection. Order data is retained for the sixty (60) day attribution window and then deleted or aggregated. All End User Data is deleted within thirty (30) days of uninstallation or termination in accordance with Section 9.
Annex 2: Technical and Organizational Measures
Pseudonymization and minimization
IP addresses are truncated or hashed at ingestion and are not stored in full. Customer identifiers received from the Platform are hashed before storage. Only the order fields listed in Annex 1 are retrieved. No End User Data is submitted to generative AI providers.
Encryption
All data in transit between the storefront widget, the Platform APIs, and Ustyle's backend is encrypted using TLS 1.2 or higher. Data at rest is encrypted using the storage encryption of the cloud provider (AES-256).
Access control
Access to production systems is limited to named personnel with a need to know, protected by individual accounts, multi-factor authentication, and role-based permissions. Access rights are reviewed at least every six months and revoked promptly upon change of role or departure. Administrative access is logged.
Logging and monitoring
Application and infrastructure logs are retained for security monitoring. Alerts are configured for anomalous access patterns and availability incidents.
Availability and resilience
Production data is hosted on infrastructure with redundancy within the EU region. Backups are taken regularly, encrypted, and stored within the EEA. Restoration procedures are tested periodically.
Segregation
Data of each Merchant store is logically segregated by store identifier. Development and testing environments do not contain production End User Data.
Secure development
Code changes are reviewed before deployment. Dependencies are monitored for known vulnerabilities and updated. Secrets are stored in a managed secrets vault and not in source code.
Incident management
A documented incident response procedure covers detection, containment, assessment, notification under Section 6.2, and post-incident review.
Personnel
All personnel with access to End User Data are bound by confidentiality obligations and receive data protection and security awareness training on joining and periodically thereafter.
Sub-processor management
Sub-processors are assessed before engagement, bound by written data processing terms, and reviewed periodically. Infrastructure sub-processors hold recognized security certifications (such as ISO/IEC 27001 or SOC 2).
Annex 3: Authorized Sub-processors
The list below reflects the sub-processors authorized at the date of this DPA. The current list is maintained on the Sub-processor List page of the Ustyle website, which prevails in case of difference.
- Microsoft Azure (Microsoft Ireland Operations Ltd.): core web application hosting and storage. Location: North Europe (Ireland). Processes End User Data.
- Amazon Web Services (Amazon Web Services EMEA SARL): DynamoDB database operations. Location: EU (Frankfurt, Germany). Processes End User Data.
- Cloudflare (Cloudflare, Inc.): CDN, DNS, and DDoS protection at the network edge. Location: global edge network; End User Data in transit only (IP address and request metadata), covered by Cloudflare's Data Processing Addendum including the Standard Contractual Clauses and Cloudflare's EU-US Data Privacy Framework certification.
- Google Cloud Platform (Vertex AI generative models) (Google Ireland Ltd. and Google LLC): machine learning inference and image generation. Location: EU and United States. Processes Merchant catalog data only; does not process End User Data. Covered by Google's Cloud Data Processing Addendum, under which customer data is not used to train Google's models.
- Other AI Providers: Ustyle may engage additional or alternative AI model providers for inference and image generation. Any such provider processes Merchant catalog data only, never End User Data, is engaged under terms that prohibit training on Merchant data, and is added to the Sub-processor List before use. Because such providers do not process End User Data, their addition does not require notification under Section 5.2, but is notified under Section 12.3 of the Terms.
- PostHog (PostHog Inc., EU-hosted instance): product usage analytics of the Ustyle merchant dashboard. Location: EU (Frankfurt, Germany). Processes Merchant staff usage data only; does not process End User Data.
Annex 4: Managed Advertising Services
This Annex applies only to Merchants that subscribe to a Managed Plan under Section 25 of the Terms. It supplements Annexes 1 to 3 for the processing carried out in performing those services. All provisions of this DPA apply to that processing.
Subject matter and nature
Configuration and management of the Merchant's advertising campaigns on advertising platforms named in the Order Form, including set-up of conversion tracking, creation of audiences, and performance reporting, using access granted by the Merchant to its own advertising accounts.
Purposes
- Measuring conversions attributable to advertising campaigns
- Building custom, retargeting, and lookalike audiences on the Merchant's instructions
- Optimizing campaign targeting and bidding
- Reporting campaign performance to the Merchant
Categories of data subjects
Visitors and customers of the Merchant's online store, and persons on customer lists that the Merchant provides for audience creation.
Categories of personal data
- Conversion and event data collected by the pixels and tags installed on the Merchant's store (page views, add-to-cart, purchases, order value, hashed identifiers), transmitted to the advertising platforms under the Merchant's own agreements with them
- Customer lists provided by the Merchant for audience creation (email addresses, phone numbers, names, and similar identifiers), hashed before upload where the platform supports it
- Aggregated campaign performance data made available by the advertising platforms
Special categories of data
None. The Merchant shall not provide customer lists that reveal special categories of data, and audiences shall not be built on such attributes.
Location and recipients
Ustyle accesses the data within the advertising platforms' own tools and does not copy it to Ustyle systems except for temporary working files needed to prepare audience uploads and reports. The advertising platforms (for example Meta Platforms Ireland Ltd. and Google Ireland Ltd.) are engaged by the Merchant directly, act under the Merchant's agreements with them, and are not sub-processors of Ustyle.
Retention
Customer lists received for audience creation are deleted from Ustyle systems within seven (7) days of upload to the platform. Working files and reports containing personal data are deleted within thirty (30) days after the end of the Managed Plan. Ustyle's access to the Merchant's advertising accounts is removed within five (5) business days after the end of the Managed Plan.
Merchant instructions and warranties
The Merchant instructs Ustyle to carry out the processing described in this Annex and warrants that it has a lawful basis, an adequate privacy notice, and, where required, valid consent for the collection of conversion data on its store and for the use of customer lists in advertising.