Data Processing Agreement

How we process personal data on behalf of our business customers, across its.fashion services and WFX extensions

Version 1.0 · Effective 25 June 2026

This is our site-wide Data Processing Agreement. It governs the personal data we process on a customer's behalf as processor, across all its.fashion services and WFX extensions (including AI Sample Room). It supplements, and is incorporated into, our WFX Extensions Terms of Use and any order form. We will sign a countersigned copy on request where a customer's procurement requires one.

Which of our policies applies? Depending on what you are using, a different policy governs:

1. Parties and definitions

This Data Processing Agreement ("DPA") is between its.fashion, the technology division of Conceptable Ltd ("Processor", "we", "us"), of 167-169 Great Portland Street, 5th Floor, London, England W1W 5PF, United Kingdom, and the business customer that uses our services or extensions ("Controller", "you").

"UK GDPR", "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, "Data Protection Laws"). "Services" means the its.fashion services and WFX extensions you use. "Sub-processor" means any processor we engage to process Personal Data on your behalf. Terms defined in the applicable terms of use or a product-specific privacy policy have the same meaning here.

2. Roles and scope

You are the controller and we are your processor in respect of the Personal Data we process on your behalf when providing the Services, as described in Annex I. Each party will comply with its obligations under Data Protection Laws. You are responsible for the lawfulness of the Personal Data you (or your users) submit and of your instructions, and for ensuring you have a lawful basis and all necessary notices and consents, including for any third-party personal data contained in the data you provide.

Much of the content processed through our Services is commercial business information (such as product records, Bills of Materials, colourways, trims and product imagery) that generally does not contain Personal Data. This DPA applies to the extent that we process Personal Data on your behalf.

Account data (processed by us as controller). Separately, we process the names and business email addresses of your authorised users and your company contact details as a controller, in order to administer accounts, provide support and billing, and send service communications. That processing is described in our Privacy Policy and is not governed by this DPA.

3. Our processing obligations

We will:

  • process Personal Data only on your documented instructions (including those in the applicable terms, this DPA, and your configuration and use of the Services), unless required otherwise by law, in which case we will inform you unless legally prohibited;
  • ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations;
  • implement and maintain the technical and organisational security measures described in Annex II, taking account of Article 32 of the UK GDPR;
  • assist you, taking into account the nature of the processing, to respond to data subject rights requests;
  • assist you in complying with Articles 32 to 36 of the UK GDPR (security, breach notification, impact assessments and prior consultation), taking into account the nature of processing and the information available to us;
  • delete or return Personal Data as described in Annex I and the applicable product-specific privacy policy, and at the end of the Services delete or return remaining Personal Data at your choice and delete existing copies, unless legal requirements require continued storage.

4. Personal data breach

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Personal Data we process on your behalf, with the information reasonably available to us to help you meet your own obligations. You are responsible for notifying the Information Commissioner's Office and affected data subjects where required.

5. Sub-processors

You provide general authorisation for us to engage Sub-processors (including AI model providers, hosting providers, and communication providers) to process Personal Data, provided we impose obligations on each Sub-processor no less protective than this DPA and remain responsible to you for their performance. The categories of Sub-processor we engage are set out in Annex III, and the current list of named Sub-processors is available to any customer with an active account on request. As AI models and provider terms evolve, we may change or add providers so that the Services continue to meet customer needs. We will inform you of any intended change to Sub-processors and allow you at least 30 days to object on reasonable data-protection grounds.

6. International transfers

By using the Services, you authorise and instruct us to host and process your data in the United Kingdom, unless a different hosting location is specifically agreed with you in writing. The United Kingdom is our default hosting location. Where any Sub-processor (including an AI model provider) processes Personal Data outside the United Kingdom, we will not make that transfer unless an appropriate safeguard is in place, namely the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required. Prompt deletion of source and generated content (see Annex I) further limits the Personal Data involved in any such processing.

7. Audit and information

We will make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits on reasonable prior notice, no more than once per year except where required by a supervisory authority or following a personal data breach, subject to confidentiality and to not compromising the security of other customers.

8. Liability and duration

This DPA takes effect when you start using the Services and continues for as long as we process Personal Data on your behalf. Liability under this DPA is subject to the limitations of liability in the applicable terms of use. In the event of conflict with those terms in respect of the processing of Personal Data, this DPA prevails.

Annex I - Details of processing

  • Subject matter: provision of the its.fashion Services and WFX extensions you use.
  • Duration: the term of the applicable terms of use.
  • Nature and purpose: reading the product data and images you make available, performing the requested processing (including AI image generation and analysis), and returning results to your environment.
  • Types of Personal Data: the names and business email addresses of your authorised users and your company contact details (held by us as controller for account management); and any Personal Data you include within the content you submit, which should be minimised. The Services are not designed to process consumer data.
  • Categories of data subject: your personnel and authorised users, and any individuals referenced in the content you submit.
  • Deletion: for AI Sample Room and similar extensions, source images and generated outputs are deleted from our systems once returned to your environment; only minimal job metadata and short-lived technical logs are retained, as set out in the relevant product-specific privacy policy.

Annex II - Security measures

Measures include: hosting in a UK Tier IV, ISO 27001 certified data centre; encryption of Personal Data in transit (TLS) and of stored data at rest; protection of API keys and integration secrets using a hardware-backed, non-exportable key held in a Hardware Security Module certified to FIPS 140-2 Level 3 (Google Cloud Key Management Service), where the key material is supplied to the application only at run time, held in memory during operation, and never written to disk or to any log; role-based access controls and least-privilege access; prompt deletion of source and generated content once returned to your environment; logging and monitoring; and staff confidentiality undertakings and data-protection awareness. We review these measures periodically and update them to maintain a level of security appropriate to the risk.

Annex III - Sub-processors

We engage the following categories of Sub-processor to provide the Services. The current list of named Sub-processors may be requested by any customer with an active account at any time, and we will notify you of changes in line with Section 5. We may change or add providers as AI models and provider terms evolve so that the Services continue to meet customer needs.

  • AI model provider(s) - image generation and analysis from the content you submit. Our current provider is Google (Gemini API), used on a paid, billing-enabled basis under which your content is not used to train the provider's models.
  • Hosting and data-centre provider (United Kingdom) - operating the Services and backups from a UK Tier IV, ISO 27001 certified data centre.
  • Email / communications provider - account, support and service-update communications.

Contact

For any data-protection matter under this DPA, contact privacy.contact@its.fashion. its.fashion is the technology division of Conceptable Ltd, 167-169 Great Portland Street, 5th Floor, London, England W1W 5PF, United Kingdom.