GDPR data processing agreement
Your customers entrust you with their photos: you are the data controller, Emelva is your processor. This agreement, required by article 28 of the GDPR, governs what we do with that data — and what we refuse to do.
Agreement between each partner shop and Emelva, accepted online when the shop account is created · version 2026-08-05-sasu.
When a customer creates her silhouette at a partner shop, it is the shop that decides to collect that photo and why: the shop is the controller. Emelva merely processes that data on its behalf: we are the processor. Article 28(3) of the GDPR requires this relationship to be governed by a written contract — that is the purpose of this document.
Between the undersigned
The controller — hereinafter “the Shop”: the business identified when its Emelva account was created (name, city and SIREN/SIRET number or company identifier entered at sign-up), represented by the person who creates the account.
The processor — hereinafter “Emelva”: Emelva, société par actions simplifiée unipersonnelle with share capital of €1,000, currently being registered with the Commercial and Companies Register (RCS) of Compiègne, whose registered office is at 9 rue Notre-Dame de Bon Secours, 60200 Compiègne, France. SIREN and intra-EU VAT number pending allocation. Contact for personal-data matters: hello@emelva.com.
Article 1 — Purpose
This agreement sets out the conditions under which Emelva processes, on behalf of the Shop and on its instructions, the personal data necessary to provide the Emelva virtual fitting service. It applies for as long as the service is used and prevails, on data-protection matters, over any contrary provision.
Article 2 — Description of the processing
Nature and purpose. To allow the Shop’s customers to try on garments from its catalogue virtually, starting from a photograph they provide, to keep the resulting renderings, to exchange messages with the Shop, and to provide the Shop with usage statistics for its collection.
Duration. For the term of the contractual relationship, plus the retention periods in article 8.
Categories of data subjects. The Shop’s customers registered with the service; the shopkeeper and the members of her team who have access.
Categories of data processed.
| Category | Detail | Source |
|---|---|---|
| Identification | first name, e-mail address | provided by the person |
| Image | silhouette photograph (full body), optional portrait, photographs of personal garments | provided by the person |
| Body | sizes, shoe size, measurements (optional) | provided by the person |
| Usage | try-ons carried out, pieces viewed, pieces set aside, renderings kept | generated by the service |
| Exchanges | messages with the Shop, try-on requests | provided by the person |
| Team | name, e-mail, sales assistants’ access code | provided by the Shop |
Point of attention. Photographs of people are ordinary personal data as long as no biometric identification processing is carried out. Emelva performs no facial recognition, no biometric template and no automated identification: the images are used solely to produce a visual rendering requested by the person herself. This limit is constitutive of the service and any change to it would be the subject of an amendment.
Article 3 — Documented instructions
Emelva processes the data only on the Shop’s documented instructions. Such instructions comprise: this agreement, the general terms of the service, and the settings made by the Shop in its own space. If Emelva considers that an instruction infringes the GDPR, it informs the Shop without delay. If a legal obligation requires it to process beyond the instructions received, it informs the Shop before processing, unless the law prohibits it.
Article 4 — Confidentiality
Emelva ensures that persons authorised to process the data are bound by an obligation of confidentiality and receive the necessary training. Access to a Shop’s data is technically partitioned: every read is filtered by the shop identifier of the session. Assistance access to a Shop’s account (“impersonation”) is possible for support purposes; it is logged, signalled on screen by a permanent banner, and allows neither a password change nor access to internal support.
Article 5 — Security (article 32)
Emelva implements the following measures, currently in place:
- encryption in transit of all communications (HTTPS), and in the database (encryption at rest provided by the host);
- photographs stored outside the application, in a private space with no public access; every read goes through a signed URL expiring in one hour, every upload through a signed URL expiring in ten minutes, whose exact size is signed;
- verification of uploaded content (actual file type, size cap) before any use;
- passwords stored hashed (scrypt with salt) — never in clear, never reversible;
- rate limiting of authentication attempts, counted in the database;
- signed, revocable sessions; revoking a sales assistant takes effect on the next request;
- logging of incidents affecting data or billing, with an alert to the operator;
- weekly database backup, kept for 90 days, and point-in-time restore offered by the host over the last 24 hours.
These measures evolve with the state of the art; their level of protection will not be reduced.
Article 6 — Sub-processors
The Shop authorises Emelva to use the sub-processors listed below. Emelva informs the Shop of any addition or replacement at least thirty days in advance, in writing. The Shop may object on reasonable data-protection grounds; failing agreement, it may terminate without penalty.
| Sub-processor | Role | Data transmitted | Location |
|---|---|---|---|
| Vercel Inc. | application hosting | all data, in transit | United States |
| Neon | database | identification, body, usage, exchanges | European Union (Frankfurt) |
| Cloudflare | image storage | photographs and renderings | European Union (Western Europe) |
| OpenAI | generating renderings | photograph + garment photo, for the duration of the rendering | United States |
| FASHN AI | generating renderings (fallback) | same | United States |
| Seedance | generating videos | source image | United States |
| Brevo | sending e-mails | first name, e-mail address | European Union |
| Stripe | payments | the Shop’s billing data; no customer data | European Union / United States |
Emelva contractually imposes on each of them obligations equivalent to those of this agreement, and remains fully liable to the Shop for their performance.
Article 7 — Transfers outside the European Union
The database is hosted in the European Union. Generating renderings involves transferring images to providers established in the United States (OpenAI, FASHN AI, Seedance), for no longer than is necessary to produce the requested rendering. These transfers are covered by the European Commission’s standard contractual clauses (decision 2021/914) and, for providers that benefit from it, by the EU–US Data Privacy Framework. No other transfer outside the European Union takes place. The Shop informs its customers of these transfers; the privacy policy published by Emelva describes them and may be relied upon against it.
Article 8 — Retention periods and fate of the data
- customer account: until deleted by the person, or after 24 months of inactivity;
- silhouette photograph: deleted from storage when replaced or when the account is deleted;
- try-on renderings: kept for as long as the person keeps them; renderings cached to avoid recomputing the same try-on are kept under a technical key that does not allow the person to be identified;
- the Shop’s billing data: ten years (accounting obligation);
- technical logs: twelve months at most.
At the end of the agreement, at the Shop’s choice expressed within thirty days: return of the data in a structured, machine-readable format, or deletion. Failing instructions, deletion at the end of that period, except where retention is required by law. Backup copies are erased according to their own cycle (90 days at most).
Article 9 — Assistance to the Shop
Emelva assists the Shop, insofar as possible and taking into account the nature of the processing:
- data subject rights: the service allows each customer to exercise directly, from her own space, her right of access (a complete export of her data) and her right to erasure (deletion of the account and the images). For any request addressed to the Shop that it could not satisfy on its own, Emelva responds within five working days;
- security, breach notification, impact assessment (articles 32 to 36): Emelva provides the information available to it.
Article 10 — Data breach
Emelva notifies the Shop of any personal data breach within forty-eight hours of becoming aware of it, by e-mail to the declared contact, stating: the nature of the breach, the categories and approximate number of persons and records concerned, the likely consequences, and the measures taken or proposed. It is for the Shop, as controller, to notify the supervisory authority and, where applicable, the data subjects.
Article 11 — Records, information and audit
Emelva maintains the record of categories of processing activities carried out on behalf of the Shop (article 30(2)) and makes available to it, on request, the information necessary to demonstrate compliance with article 28. The Shop may carry out an audit once a year, subject to reasonable notice, at the requesting party’s expense, under conditions that preserve the confidentiality of other shops’ data.
Article 12 — Liability and term
Each party is liable for damage caused by processing that infringes the GDPR, under the conditions of its article 82. This agreement takes effect upon acceptance and remains in force for as long as the service is used, as well as for the obligations that survive it (articles 4, 8 and 10).
Acceptance
This agreement is accepted online, when the shop account is created, by the person authorised to represent the Shop. Acceptance is time-stamped and kept together with the accepted version of the agreement (2026-08-05-sasu); it constitutes a signature within the meaning of article 28(9) of the GDPR (electronic form).