Data Processing Agreement
For merchants who add the TryItOn try-on to their store: how we process your shoppers’ personal data on your behalf, and the commitments we make as your processor.
1. Introduction and Scope
This Data Processing Agreement (“DPA”) forms part of, and is subject to, the Terms of Service (the “Terms”) between TryItOn (“we”, “us”, “Processor”) and the business that installs or uses the TryItOn virtual try-on on its own store (the “Merchant”, “you”, “Controller”). It applies where and to the extent we process Personal Data on your behalf in connection with the Services.
This DPA reflects the parties’ agreement on the processing of Personal Data in accordance with the requirements of Applicable Data Protection Law. Where there is a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails. It does not need to be signed to be effective; it applies automatically when you use the Services to process Personal Data of your shoppers.
2. Definitions
Capitalized terms not defined here have the meaning given in the Terms or Applicable Data Protection Law.
- Applicable Data Protection Law — all laws and regulations applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable US state privacy laws (such as the CCPA/CPRA).
- Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach — as defined in the GDPR (or the equivalent terms, such as “business,” “service provider,” and “consumer,” under US state law).
- Sub-processor — any third party engaged by us to process Personal Data on the Merchant’s behalf.
- Standard Contractual Clauses (SCCs) — the clauses approved by the European Commission (Decision 2021/914) and the UK International Data Transfer Addendum, for transfers of Personal Data to third countries.
- Shopper — a visitor to or customer of the Merchant’s store who uses the try-on.
3. Roles of the Parties
For Personal Data processed through the Services in connection with your store, you are the Controller and we are the Processor acting on your documented instructions. Where you are yourself a processor for another controller, we act as your Sub-processor and the same obligations apply.
Each party will comply with its obligations under Applicable Data Protection Law. You are responsible for the lawfulness of the Personal Data you (and your Shoppers, through the try-on) provide to us, and for having a valid legal basis and any required consents and notices — including for the upload of Shopper images and, where you enable the newsletter feature, for email-marketing consent.
4. Processing on Your Instructions
We will process Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law — in which case we will inform you of that legal requirement before processing, unless the law prohibits it. Your instructions are set out in this DPA, the Terms, and your configuration and use of the Services (for example, enabling the newsletter feature and selecting a destination list).
We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law. We will not sell Shopper Personal Data, nor process it for our own independent purposes, nor for advertising, and will not retain, use, or disclose it outside the direct business relationship or as otherwise prohibited by the CCPA/CPRA.
5. Details of the Processing
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1 (Details of Processing).
6. Confidentiality
We ensure that persons authorized to process the Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are made aware of the confidential nature of the Personal Data. Access is limited to personnel who need it to provide the Services.
7. Security of Processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (Technical and Organizational Measures). You are responsible for the secure configuration and use of the Services within your control, including safeguarding any credentials (such as email-provider API keys) that you supply.
8. Sub-processors
You provide a general authorization for us to engage Sub-processors to process Personal Data, provided that we: (a) maintain an up-to-date list of Sub-processors in Annex 3; (b) impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA; and (c) remain liable to you for a Sub-processor’s performance of its obligations.
We will give you reasonable prior notice of the addition or replacement of a Sub-processor (for example, by updating Annex 3 and, where you have subscribed to notifications, by email). If you have a reasonable, data-protection-based objection, you may raise it with us at [email protected] and we will work with you in good faith to address it; if we cannot, you may stop using the affected feature.
9. Assisting with Data-Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights (such as access, correction, deletion, restriction, portability, and objection). If a Shopper contacts us directly about Personal Data we process on your behalf, we will, unless legally required to respond, advise them to contact you and, where appropriate, forward the request to you.
10. Personal Data Breach Notification
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf, and will provide you with information reasonably available to us to help you meet your own notification obligations to supervisory authorities and Data Subjects. Our notification is not an acknowledgement of fault or liability.
11. Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you with any data protection impact assessments and prior consultations with supervisory authorities that you are required to carry out under Applicable Data Protection Law in respect of the Services.
12. International Transfers
We process Personal Data in the United States and Germany and may transfer it to other countries where we or our Sub-processors operate (see Annex 3). Where such a transfer is subject to Applicable Data Protection Law, we rely on an appropriate transfer mechanism, including the Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and completed with the information in the Annexes. A copy is available on request.
13. Return and Deletion of Data
Shopper images uploaded for a try-on are deleted automatically shortly after the result is produced. For other Personal Data processed on your behalf, at your choice we will delete or return it to you after the end of the provision of the Services, and delete existing copies unless Applicable Data Protection Law requires storage. Personal Data captured through the newsletter feature is forwarded to your designated email provider and not retained by us; from that point it is held by that provider and by you as Controller.
14. Audits and Information
We will make available to you information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. To minimize disruption, we may satisfy audit requests by providing existing certifications, reports, or a written response to a reasonable data-security questionnaire, where these adequately address your request. Audits are limited to once per year unless required by a supervisory authority or following a Personal Data Breach.
15. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to a party’s liability means the aggregate liability of that party under the Terms and this DPA together.
16. Term, Precedence, and Governing Law
This DPA takes effect when you begin using the Services to process Personal Data and continues until we no longer process any Personal Data on your behalf. Sections that by their nature should survive termination will survive.
Except where Applicable Data Protection Law (including the SCCs) requires otherwise, this DPA is governed by the same law and dispute-resolution provisions as the Terms. If any provision is found invalid, the remainder stays in effect.
Annex 1 — Details of Processing
- Subject matter. Provision of the TryItOn virtual try-on and related features on the Merchant’s store.
- Duration. For the term of the Terms and until deletion/return in accordance with Section 13.
- Nature and purpose. Generating virtual try-on results from Shopper-provided images; operating store features (such as try-on limits and aggregate analytics for the Merchant); and, where enabled by the Merchant, capturing a Shopper’s newsletter sign-up and forwarding it to the Merchant’s designated email provider.
- Types of Personal Data. Shopper-uploaded photographs; the product image tried on; a store-assigned visitor identifier and related technical/usage data; and, where the newsletter feature is used, the Shopper’s email address and marketing-consent indication.
- Special categories. We do not require or request special-category data. Shopper photographs are processed only to generate the try-on and are not used to identify Data Subjects or to create biometric identifiers.
- Categories of Data Subjects. The Merchant’s Shoppers and site visitors who use the try-on.
Annex 2 — Technical and Organizational Measures
We maintain measures appropriate to the risk, including:
- encryption of Personal Data in transit (TLS);
- access controls and role-based access limited to personnel who need it, with authentication controls;
- logical separation of environments and least-privilege service credentials;
- automatic deletion of Shopper-uploaded images shortly after the try-on result is produced;
- network and application security controls, including bot/abuse protection at the try-on endpoints;
- monitoring, logging, and error/crash reporting to detect and respond to incidents;
- vendor due diligence and contractual data-protection terms with Sub-processors;
- regular review of these measures, which we may update provided the level of security is not reduced.
Annex 3 — Sub-processors
We engage the following categories of Sub-processors to process Personal Data on the Merchant’s behalf:
- AI try-on and image generation — Black Forest Labs (BFL GmbH), Google, and Replicate (processing the uploaded image and product image to generate the result).
- Cloud hosting, storage, and content delivery — Amazon Web Services (including Amazon CloudFront) and Hetzner Online GmbH.
- Newsletter delivery (only if the Merchant enables it) — the email provider the Merchant connects, which may be Shopify, Mailchimp, or Klaviyo, to which we forward the Shopper’s email on the Merchant’s behalf.
- Analytics and monitoring — PostHog (product analytics, configured without direct identification) and Sentry (error monitoring).
The current list may be updated in accordance with Section 8. To request the latest list or to raise an objection, email [email protected].
Contact
Questions about this DPA, or requests to exercise the rights described here, can be sent to [email protected].

Start trying on
A photoreal fitting room in every shop you visit. Free to start — no credit card, no returns.
Available on Chrome, Edge, Windows, iPhone, and Android.
Try it for free. No card required.