// Legal

Data Processing Agreement

Last updated June 2026

This DPA is incorporated by reference into the SizeFit AI Terms of Service and applies whenever SizeFit AI processes personal data on behalf of a merchant (the "Controller") under GDPR Article 28.

1. Subject matter and duration

Processing of shopper personal data submitted via the SizeFit widget, for the term of the merchant's subscription plus a 30-day return/deletion window.

2. Nature and purpose

Provision of size recommendations, analytics, and abuse prevention.

3. Categories of data subjects and data

  • Data subjects: end shoppers of the merchant's store.
  • Personal data: body measurements (height, weight, chest, waist), fit preference, pseudonymous browser token, product viewed.
  • Special category data: body measurements may, in some jurisdictions, qualify as health-adjacent data. Consent is obtained in the widget before processing.

4. Controller obligations

  • Ensure a lawful basis exists; the SizeFit widget collects explicit consent on the Controller's behalf.
  • Provide a privacy notice that references SizeFit AI as a processor (sample wording on request).

5. Processor obligations

  • Process only on documented instructions from the Controller.
  • Confidentiality undertakings for all personnel with access.
  • Appropriate technical and organisational measures (Annex II below).
  • Assist with data subject rights, DPIAs, and authority enquiries.
  • Notify the Controller without undue delay (within 72 hours) of a personal data breach.
  • Delete or return personal data at the end of the contract.

6. Sub-processors

The Controller authorizes the following sub-processors. We will give 30 days' notice of additions via merchant dashboard; the Controller may object and terminate.

  • Supabase — primary database and authentication, EU region (Frankfurt).
  • Cloudflare — edge compute, DDoS, CDN; global.
  • Stripe Payments Europe Ltd. — billing; Ireland (with US transfer under SCCs).
  • Resend — transactional email; US (SCCs).

7. International transfers

Transfers outside the EEA rely on the 2021 Standard Contractual Clauses (Modules 2 and 3) and the supplementary technical measures listed in Annex II.

8. Audit

Once per 12-month period, on 30 days' notice, the Controller may request a summary of our most recent security assessment. On-site audits are reserved for material breach.

9. Annex II — Technical and organisational measures

  • TLS 1.2+ in transit, AES-256 at rest.
  • Row-level security per merchant tenant.
  • Least-privilege service-role credentials; production access logged.
  • Automated quota and rate limiting on the public widget API.
  • Daily encrypted backups; 30-day retention.
  • 180-day automatic deletion of shopper measurements & recommendations.
  • Incident response playbook with 72-hour notification SLA.

10. Signature

Acceptance of the Terms of Service constitutes acceptance of this DPA. A counter-signed version is available on request to legal@sizefit.ai.

Questions? Email privacy@sizefit.ai — we reply within 5 business days.