WFX Extensions - Privacy Policy
How our WFX PLM extensions handle your product data, supplier data and personal data
Version 1.0 · Effective 25 June 2026
This policy covers our WFX extensions. It applies to the its.fashion WFX PLM extensions listed in Section 4 - plm.report, supplier.studio, SmartFields, Smart Data Studio and the Shopify WFX Connector. These are business-to-business tools and are not directed to consumers.
Which of our policies applies? Depending on what you are using, a different policy governs:
- Our website and general dealings with us - Privacy Policy
- The WFX extensions listed above - this policy
- AI Sample Room (our AI extension) - AI Sample Room Privacy Policy
- Personal data we process on a customer's behalf as processor - Data Processing Agreement
- The contractual terms for using any extension - WFX Extensions Terms of Use
Where a product-specific policy covers what you are using, it prevails over the general Privacy Policy for that product to the extent of any difference.
1. At a glance
- What they do. These extensions connect to your existing WFX PLM to report on, automate, move or publish the product data you already hold. You must be signed in to WFX to use them, and they act on the data you choose to work with.
- No AI on your data. These extensions do not use artificial intelligence to process your product or supplier data, and do not send that data to any AI model or AI provider. An optional in-product help chatbot can answer how-to questions about using the software, but it does not access the data the extension handles.
- We act as your processor. For the WFX product data and supplier data these extensions handle, you remain the controller and we process it only on your instructions. You retain ownership of your data.
- We do not sell your data. We never sell or rent your data, and we never use it for advertising.
- We keep little. Most processing is transient. We retain only what an extension genuinely needs (for example, reports you choose to save in plm.report, or the settings and credentials needed to run an extension), plus limited diagnostic logs and your account records.
- Where it runs. Our service is hosted in a UK Tier IV, ISO 27001 certified data centre.
2. Who we are
These extensions are provided by its.fashion, the technology division of Conceptable Ltd ("its.fashion", "we", "us", "our"), registered office and correspondence address: 167-169 Great Portland Street, 5th Floor, London, England W1W 5PF, United Kingdom.
For any privacy matter relating to these extensions, contact us at privacy.contact@its.fashion.
3. Our role: controller and processor
Our role under the UK GDPR depends on the data in question:
- Your WFX product data and supplier data (we act as processor). The product records, files, supplier details and other content these extensions read from, move through, or write back to your WFX environment (and, for the Shopify WFX Connector, to your Shopify store) belong to, and are controlled by, you. We process this content only on your documented instructions, to provide the extension. This processing is governed by our Data Processing Agreement, which we will sign where your procurement requires it.
- Account and contact data (we act as controller). For the names and business email addresses of authorised users, company contact details, activation and subscription records, and service communications, we act as controller, as described in our general Privacy Policy.
Where this policy refers to "you", it means, as the context requires, your business and the individual users you authorise to use the extensions.
4. The extensions this policy covers
Each extension connects to your WFX PLM and is used only by people you invite. In summary:
- plm.report - reads your WFX data to generate reports. Reports are produced on demand; where you choose to save a report, we store it so you can access it again later (see Section 9).
- supplier.studio - reads supplier information held in WFX so you can prepare data, files and communications for your suppliers. Prepared items are held in transit until you approve them, and supplier communications are sent through your own email (SMTP) server, not ours (see Sections 7 and 10).
- SmartFields - field validation, calculation and automation within WFX. The Standard edition (included in Smart Data Studio) provides calculated values, cascading autocompletion and similar features. Bespoke SmartFields custom scripts are delivered under a separate engagement and are governed by that engagement and our Data Processing Agreement rather than this policy.
- Smart Data Studio - acts as a bridge that moves data into and out of WFX. It holds data only while it is being processed and discards it once the item has reached its status and no retry is needed.
- Shopify WFX Connector - monitors product status in WFX and creates and updates draft listings in your own Shopify store, carrying through product data, images, pricing and descriptions. It handles the product information flow from WFX to Shopify only; it does not access your shoppers' or end-customers' data.
AI, the help chatbot, and translation. These extensions do not use AI to process your product or supplier data. An optional in-product support chatbot is available to answer how-to questions about using the software; it does not access the data the extension handles. Some advanced features (for example automated translation) would involve AI; such features are offered only as bespoke custom scripts under separate terms, are not currently in use by any client, and are not covered by this policy. If we make any AI-based feature generally available, we will provide the appropriate privacy terms for it.
5. What we access and collect
- WFX data you work with: the product records, attributes, files and (for supplier.studio) supplier details that the extension needs for the task you start. The extension accesses this only while you are signed in to WFX and actively using it, and only the data needed for that task.
- Account data: the name and business email address of each authorised user, company details, and subscription/activation records.
- Settings and credentials: configuration you provide so an extension can work - including, for supplier.studio, the access details for your own email (SMTP) server so the extension can send supplier communications on your instruction. Such credentials are encrypted at rest and are never displayed back or shared (see Section 10).
- Technical and diagnostic logs: limited logs (such as timestamps, the action performed, and limited request detail) used to operate the service securely and to investigate problems.
6. How we use data and our legal bases
- To provide the extensions - reporting on, automating, moving or publishing the WFX data you choose to work with. Legal basis: performance of a contract; and, for your WFX and supplier data, processing on your instructions as processor.
- To operate, secure and support the service - authentication, troubleshooting, abuse prevention and service integrity. Legal basis: legitimate interests; legal obligations.
- To administer accounts and bill the service - managing subscriptions, activation and invoicing. Legal basis: performance of a contract; legitimate interests.
- To communicate with you - service, security and administrative messages. Legal basis: legitimate interests; contract.
We do not use your data for automated decision-making producing legal or similarly significant effects, and we do not use your product or supplier data to train, fine-tune or improve any AI model.
7. Suppliers and your SMTP server (supplier.studio)
supplier.studio is designed to help you communicate with your suppliers, so it processes supplier contact details - which are personal data of individuals at your suppliers. For this data you are the controller and we are your processor: we handle it only to provide supplier.studio to you, on your instruction.
- You are responsible for ensuring you have a lawful basis to process and contact your suppliers, and for the content of the communications you send.
- Supplier communications are sent through your own email (SMTP) server, using the access details you store in your settings, so that messages come from you - not from its.fashion. We store those SMTP access details only to initiate sends you request, encrypted as described in Section 10.
- Data and files you prepare for a supplier are held in transit until you approve them; on approval they are sent or written back to WFX as you direct.
8. Sharing and sub-processors
We do not sell your data and do not share it except as needed to provide the service or as required by law. We use the following categories of sub-processor:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting & data-centre provider | Hosting of our cloud service and backups, in a UK Tier IV, ISO 27001 certified data centre. | United Kingdom |
| Email / SMTP provider | Sending our account, support and service-update emails to you. Supplier emails are sent through your own SMTP server, not this provider. | United Kingdom / EU |
Your connected systems. The Shopify WFX Connector writes to your own Shopify store, and supplier.studio sends through your own email server. Those are systems you control under your own agreements with those providers; they are not our sub-processors. We impose data-protection obligations on each of our sub-processors no less protective than those in this policy and our Data Processing Agreement, and a current list of named sub-processors is available to any client with an active account on request. We do not operate a card or online payment gateway; subscriptions are invoiced and settled by bank transfer, so we do not collect or process card or payment-account details through the service. We may also disclose data where required by law or to protect our rights, users or the security of the service.
9. Where your data is held, transfers and retention
Our cloud service and its backups are hosted in the United Kingdom. We do not transfer personal data outside the UK unless necessary to provide the service; where we do, we rely on an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. (Where you use the Shopify WFX Connector or your own SMTP server, any transfer arising from your own connected systems is governed by your arrangements with those providers.)
We keep data only as long as needed:
- Data processed in transit (supplier.studio, Smart Data Studio, the Shopify WFX Connector): held only while we process or move it, then discarded once the item has reached its status and no retry is needed. The authoritative copies remain in your WFX (and, where applicable, your Shopify store).
- Saved reports (plm.report): reports you choose to save are retained so you can access them again, until you delete them or your account closes.
- Settings and credentials: retained while your account is active and you keep them configured (for example your SMTP details in supplier.studio); deleted when you remove them or when your account closes.
- Diagnostic logs: limited technical logs are retained for up to 28 days and then automatically deleted, except where a longer period is needed to investigate a security incident or to meet a legal obligation.
- Account data: retained while your account is active; after closure only for as long as needed to meet legitimate business and legal obligations (for example tax and accounting), then deleted. You can request deletion at any time, subject to those obligations.
10. Security
Our service is hosted in a UK Tier IV, ISO 27001 certified data centre. We use technical and organisational measures appropriate to the risk, including encryption of data in transit using TLS with certificate verification on outbound connections, role-based and least-privilege access controls, and logging and monitoring. Credentials you provide - including your WFX access and, for supplier.studio, your SMTP access details - are encrypted at rest using AES-256-GCM; the single master key used to encrypt them is held in the application server's protected, non-web-accessible configuration, kept separate from the encrypted data, and is never displayed or shared. We restrict access to data to personnel who need it to operate or support the service. No system can be guaranteed perfectly secure, but we work to protect your data and will notify affected clients without undue delay of any personal data breach affecting their data.
11. Cookies and local storage
These extensions do not set any advertising, analytics or third-party tracking cookies. They run inside your authenticated WFX session in your browser - you must be signed in to WFX to use them - and they keep limited items in your browser's local extension storage, such as your activation token (to keep you signed in) and your settings. These remain on your device and are cleared when you uninstall the extension.
supplier.studio and your WFX session cookie. To carry out the supplier actions you start, supplier.studio reads your existing WFX session cookie, with your authorisation, and uses it only to make the WFX requests you initiate, over TLS connections with certificate verification. We do not store your WFX session cookie, and you can withdraw this access at any time, after which supplier.studio can no longer act on your WFX session.
12. Your rights
Under the UK GDPR you have rights to access, rectify, erase, restrict or object to our processing of your personal data, and to data portability. Because most of the content is held in your WFX environment (and, where relevant, your Shopify store) under your own control, requests relating to that content are often best actioned there; for personal data we hold as controller, contact us at privacy.contact@its.fashion and we will respond within one month. Where we process personal data as a processor on your behalf (including supplier data), we will refer relevant requests to you as controller and assist you in responding.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to address your concern first.
13. Children
These are business tools and are not intended for, or directed to, children under 16. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy from time to time. For material changes we will notify clients by email or through the extension, and we will update the version and effective date above. Continued use after a change takes effect constitutes acceptance of the updated policy.
15. Contact
Questions, requests or complaints about this policy or your data:
- Email: privacy.contact@its.fashion
- Post: Conceptable Ltd, its.fashion Division, 167-169 Great Portland Street, 5th Floor, London, England W1W 5PF, United Kingdom