Legal
Data Processing Addendum
Effective Date: | Last Updated:
This Data Processing Addendum (“DPA”) is offered by Style Keeper AI Inc. to business customers that require GDPR Article 28 processor terms. Consumer accounts are governed by our Privacy Policy and Terms of Service and do not require a separate DPA. To countersign, email privacy@stylekeeperai.com with your legal entity name, address, and the Style Keeper AI account email.
1. Parties & scope
This DPA is entered into between the business customer identified in the countersignature (“Customer” / controller) and Style Keeper AI Inc., a Delaware corporation with offices at 680 North Lake Shore Drive, Suite 110 PMB 1067, Chicago, IL 60611, USA (“Style Keeper AI” / processor). It applies whenever Style Keeper AI Processes Personal Data on behalf of the Customer in the course of providing the Service, and forms part of the Terms of Service between the parties.
Capitalized terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679), the UK GDPR, or the Terms of Service.
2. Roles & instructions
Customer is the controller and Style Keeper AI is the processor of Customer Personal Data. Style Keeper AI will Process Customer Personal Data only:
- to provide, secure, and support the Service in accordance with the Terms;
- on documented instructions from the Customer, including via configuration of the Service; and
- as required by applicable law, in which case Style Keeper AI will (unless prohibited) notify the Customer.
3. Subject-matter of processing
- Duration: the term of the Customer’s subscription plus the retention windows in the Privacy Policy.
- Nature & purpose: providing AI-assisted fit and style analysis, account management, billing, and support.
- Types of Personal Data: account identifiers, body measurements, size profile, uploaded photos of clothing (or, at user option, of the user), style preferences, product analyses, support communications, and technical logs.
- Categories of data subjects: the Customer’s authorized end users and administrators.
- Sensitive data: body measurements and user-uploaded photos may qualify as sensitive personal information under the CPRA and equivalent U.S. state laws; they are not special-category data under Art. 9 GDPR.
4. Confidentiality
Style Keeper AI ensures that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and receive training on their data-protection responsibilities.
5. Security (Art. 32 GDPR)
Style Keeper AI implements and maintains technical and organizational measures designed to protect Customer Personal Data, including:
- encryption in transit (TLS 1.2+) and at rest for databases and file storage;
- Postgres row-level security segregating data between accounts;
- least-privilege access controls, unique credentials, and audit logging for administrative access;
- vulnerability management, dependency scanning, and secure software-development practices;
- incident-detection tooling and a documented incident-response process; and
- regular backups with defined recovery objectives.
6. Subprocessors
Customer provides a general authorization for Style Keeper AI to engage the subprocessors listed on our Subprocessors page. Style Keeper AI: (a) enters into written agreements with each subprocessor imposing data-protection obligations no less protective than those in this DPA; (b) remains liable for the acts and omissions of its subprocessors as if they were its own; and (c) will provide at least 30 days’ prior notice of any new subprocessor. Customer may object on legitimate data-protection grounds by emailing privacy@stylekeeperai.com within that notice period; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service for a pro-rata refund of prepaid unused fees.
7. Data-subject requests
Taking into account the nature of the Processing, Style Keeper AI will assist the Customer, by appropriate technical and organizational measures, in responding to requests to exercise data-subject rights under Chapter III of the GDPR. Style Keeper AI will forward any such request received directly from a data subject to the Customer without undue delay.
8. Personal-data breach
Style Keeper AI will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information reasonably required for the Customer to meet its own notification obligations under Art. 33 and 34 GDPR.
9. DPIA & prior consultation
Style Keeper AI will provide reasonable assistance to the Customer with any data-protection impact assessment or prior consultation with a supervisory authority that Customer is required to carry out under Art. 35 or 36 GDPR, taking into account the nature of the Processing and the information available to Style Keeper AI.
10. International transfers
Where Style Keeper AI transfers Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a country not the subject of an adequacy decision, the transfer is governed by:
- the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated by reference; and
- for UK transfers, the ICO’s International Data Transfer Addendum to the SCCs, as issued 21 March 2022 and in force from 21 March 2022.
The parties agree to the docking clause and to the Option 2 general subprocessor authorization. For the purposes of the SCC annexes, the details of Processing in Section 3 above, the security measures in Section 5, and the subprocessors listed on our Subprocessors page are incorporated into Annex I, II, and III respectively.
11. Audits
Style Keeper AI will make available to the Customer all information reasonably necessary to demonstrate compliance with Art. 28 GDPR, including third-party certifications and, where reasonably requested, written responses to security questionnaires. On-site audits are limited to once per twelve-month period, on 30 days’ prior written notice, during normal business hours, subject to reasonable confidentiality obligations, and at the Customer’s cost.
12. Return & deletion
On termination of the Service, Style Keeper AI will, at the Customer’s election, return or delete Customer Personal Data in accordance with the retention windows in the Privacy Policy, except to the extent that continued storage is required by applicable law. Backups are overwritten on Style Keeper AI’s standard rotation.
13. Order of precedence & governing law
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the Processing of Personal Data. In the event of a conflict between this DPA and the SCCs or UK IDTA, the SCCs or UK IDTA (as applicable) prevail. This DPA is governed by the law and jurisdiction of the Terms of Service, except where the SCCs or UK IDTA require otherwise.
14. Contact
Style Keeper AI Inc.Attn: Privacy & Legal
680 North Lake Shore Drive, Suite 110 PMB 1067
Chicago, IL 60611, USA
privacy@stylekeeperai.com