Legal

    Data Processing Addendum (DPA) — Merchant Integrations

    Last updated: 23/06/2026 · Governing law: Spain · Jurisdiction: Courts of Barcelona, Spain

    This Data Processing Addendum ("DPA") forms part of the agreement between Souldi and the merchant, brand, store, ecommerce operator, or other business customer using Souldi's services (the "Merchant").

    This DPA applies when Souldi processes personal data on behalf of the Merchant in connection with Souldi's virtual try-on, avatar, outfit visualization, styling, sizing, product recommendation, personalization, analytics, Shopify app, ecommerce integration, API, dashboard, or related services (the "Services").

    This DPA is intended to satisfy the requirements of Article 28 of the GDPR for controller-processor arrangements.

    1.Parties and roles

    1.1 Merchant as controller

    For Merchant Personal Data, the Merchant acts as the data controller and determines the purposes and means of processing.

    "Merchant Personal Data" means personal data that the Merchant provides to Souldi, makes available to Souldi, or instructs Souldi to process through the Services, including store customer data, Shopify customer data, order-related data, product interaction data, and other personal data processed by Souldi on behalf of the Merchant.

    1.2 Souldi as processor

    For Merchant Personal Data, Souldi acts as processor and will process such data only on the Merchant's documented instructions, unless applicable law requires otherwise.

    The Merchant's documented instructions include this DPA, the main commercial agreement, the Terms & Conditions, the Privacy Policy, the Merchant's configuration of the Services, Shopify app installation flows, API calls, dashboard settings, support requests, and other written instructions agreed by the parties.

    1.3 Souldi as independent controller for certain data

    Souldi may act as an independent controller for data processed for Souldi's own purposes, including:

    • Souldi user accounts;
    • Souldi account security;
    • fraud prevention and abuse detection;
    • product analytics;
    • service improvement;
    • AI model evaluation, testing, training, and improvement where Souldi determines the purposes and means;
    • direct user privacy requests;
    • legal compliance;
    • business administration.

    Such processing is governed by Souldi's Privacy Policy and is outside the processor obligations of this DPA, unless the parties expressly agree otherwise in writing.

    1.4 No joint controllership unless expressly agreed

    Nothing in this DPA creates a joint-controller relationship unless the parties expressly agree a separate joint-controller arrangement in writing.

    2.Subject matter, duration, nature and purpose of processing

    2.1 Subject matter

    Souldi processes Merchant Personal Data to provide the Services to the Merchant and its customers or users.

    2.2 Duration

    Souldi will process Merchant Personal Data for the duration of the Merchant's use of the Services and thereafter only as necessary to delete, return, secure, audit, or legally retain data in accordance with this DPA.

    2.3 Nature of processing

    The processing may include collection, upload, receipt, storage, hosting, organization, structuring, retrieval, consultation, use, transmission, adaptation, generation, transformation, analysis, deletion, return, and other processing necessary to provide the Services.

    2.4 Purpose of processing

    The purpose of processing is to provide, secure, maintain, support, and improve the Services, including:

    • virtual try-on previews;
    • avatar generation and avatar storage;
    • outfit visualization;
    • styling suggestions;
    • size guidance;
    • personalized shopping experiences;
    • product recommendation;
    • garment matching;
    • brand catalogue processing;
    • Shopify and ecommerce integrations;
    • technical support;
    • fraud prevention;
    • security monitoring;
    • debugging;
    • analytics and service improvement where permitted.

    3.Categories of personal data

    Depending on the Merchant's configuration and use of the Services, Merchant Personal Data may include:

    • customer or user identifiers;
    • account identifiers;
    • Shopify customer IDs or ecommerce platform identifiers;
    • email addresses or contact details, if provided;
    • order, cart, product, or purchase-related data;
    • product interaction data;
    • uploaded images or photos;
    • generated avatars;
    • body references;
    • image masks;
    • measurement references;
    • embeddings;
    • generated try-on results;
    • styling outputs;
    • size suggestions;
    • product recommendations;
    • technical metadata;
    • IP addresses;
    • device or browser data;
    • event logs;
    • security, fraud-prevention, debugging, and error logs;
    • support communications.

    4.Categories of data subjects

    The data subjects may include:

    • Merchant customers;
    • Souldi users;
    • online store visitors;
    • Merchant staff or administrators;
    • support contacts;
    • users who upload images, generate avatars, or interact with Souldi features.

    5.Merchant obligations

    The Merchant shall:

    • comply with applicable data-protection laws;
    • provide all legally required privacy notices to its customers and users;
    • ensure it has a valid legal basis to collect and share personal data with Souldi;
    • ensure that any personal data made available to Souldi is lawful, accurate, relevant, and limited to what is necessary;
    • not instruct Souldi to process personal data unlawfully;
    • not upload or cause users to upload images of minors or third parties without a valid legal basis and required permissions;
    • configure the Services in accordance with applicable law;
    • respond to data-subject requests where the Merchant is the controller, with reasonable assistance from Souldi as described in this DPA.

    6.Souldi processor obligations

    Souldi shall:

    • process Merchant Personal Data only on documented instructions from the Merchant;
    • promptly inform the Merchant if, in Souldi's opinion, an instruction infringes applicable data-protection law;
    • ensure that persons authorized to process Merchant Personal Data are subject to confidentiality obligations;
    • implement appropriate technical and organizational measures;
    • assist the Merchant with data-subject requests where reasonably possible;
    • assist the Merchant with security, breach, DPIA, and consultation obligations where reasonably possible;
    • use subprocessors only in accordance with this DPA;
    • delete or return Merchant Personal Data after termination as described in this DPA;
    • make available information reasonably necessary to demonstrate compliance with this DPA.

    7.Subprocessors

    7.1 General authorization

    The Merchant gives Souldi general written authorization to engage subprocessors to provide the Services.

    7.2 Current subprocessors

    Souldi's current or expected subprocessors include:

    • AWS — hosting, storage, infrastructure, security, compute, networking, and related services.
    • Supabase — database, authentication, storage, backend infrastructure, and related services.

    7.3 New subprocessors

    Souldi will provide at least 30 days' prior notice before adding or replacing a material subprocessor that processes Merchant Personal Data.

    The notice may be provided by email, dashboard notice, update to the subprocessor list, or another reasonable method.

    7.4 Merchant objection

    The Merchant may object to a new material subprocessor on reasonable data-protection grounds within the notice period.

    If the parties cannot resolve the objection, Souldi may, where commercially reasonable, offer an alternative. If no alternative is available, either party may terminate the affected Services.

    7.5 Subprocessor obligations

    Souldi shall impose data-protection obligations on subprocessors that are substantially equivalent to those in this DPA, to the extent applicable to the relevant processing.

    Souldi remains responsible to the Merchant for the performance of its subprocessors' obligations in relation to Merchant Personal Data.

    8.International transfers

    Souldi aims to host and process production user data in European Union or European Economic Area regions where technically and commercially available.

    Where Souldi selects an EU or EEA region, core production data is intended to be stored in that selected region.

    However, some providers, subprocessors, support operations, security operations, diagnostics, account administration, or legally required disclosures may involve processing or transfers of personal data outside the European Economic Area.

    Where such transfers occur, Souldi shall rely on appropriate legal safeguards required by applicable data-protection law, such as:

    • adequacy decisions;
    • Standard Contractual Clauses;
    • data processing agreements;
    • technical and organizational security measures;
    • encryption, access controls, minimization, and other appropriate safeguards.

    9.Security measures

    Souldi shall implement appropriate technical and organizational measures designed to protect Merchant Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure.

    These measures may include, as appropriate:

    • encryption in transit;
    • access controls;
    • least-privilege access;
    • authentication controls;
    • logging and monitoring;
    • vulnerability management;
    • secure infrastructure configuration;
    • backup and recovery procedures;
    • incident response procedures;
    • data minimization;
    • internal confidentiality obligations;
    • subprocessor due diligence;
    • deletion and retention controls.

    A summary of technical and organizational measures is included in Annex 2.

    10.Personal data breaches

    Souldi shall notify the Merchant without undue delay and, where reasonably practicable, within 48 hours after confirming a Personal Data Breach affecting Merchant Personal Data.

    The notification shall include, where available:

    • nature of the breach;
    • categories and approximate number of affected data subjects;
    • categories and approximate number of affected records;
    • likely consequences;
    • measures taken or proposed to address the breach;
    • contact point for follow-up.

    Souldi's notification or cooperation shall not be interpreted as an admission of fault or liability.

    The Merchant remains responsible for determining whether notification to supervisory authorities or data subjects is required, except where Souldi is acting as an independent controller for the affected processing.

    11.Data-subject requests

    Where the Merchant is the controller, Souldi shall reasonably assist the Merchant in responding to data-subject requests relating to Merchant Personal Data.

    This may include assistance with:

    • access requests;
    • deletion requests;
    • correction requests;
    • restriction requests;
    • portability requests;
    • objection requests;
    • opt-out or exclusion requests relating to AI-training or product-improvement uses where applicable.

    For Shopify integrations, Souldi may support relevant privacy flows through Shopify compliance webhooks and related endpoints, including customer data requests, customer redaction, and shop redaction, where applicable.

    If Souldi receives a direct data-subject request relating to Merchant Personal Data, Souldi may direct the requester to the Merchant unless Souldi is legally required to respond directly.

    12.Deletion and return after termination

    Upon termination or expiry of the Merchant's agreement, Souldi shall, at the Merchant's choice and subject to applicable law, delete or return Merchant Personal Data.

    Unless otherwise agreed:

    • active Merchant Personal Data will be deleted or returned within 30 days after termination;
    • generated avatars and generated results associated with Merchant-controlled accounts or integrations will be deleted or returned within 30 days after termination, unless the user has an independent Souldi account relationship or applicable law requires otherwise;
    • deleted data may remain in encrypted backups for up to 60 days before automatic deletion through backup rotation;
    • technical, security, fraud-prevention, debugging, and error logs may be retained for up to 90 days, unless longer retention is necessary for security, fraud prevention, dispute resolution, legal compliance, enforcement, or investigation of misuse.

    Souldi may retain limited information where required by law or necessary for legitimate security, fraud-prevention, dispute-resolution, accounting, compliance, or enforcement purposes.

    13.Audits and compliance information

    Souldi shall make available information reasonably necessary to demonstrate compliance with this DPA.

    The Merchant may request reasonable information about Souldi's security and data-processing practices.

    Any audit shall be subject to reasonable notice, confidentiality obligations, normal business hours, minimal disruption, and reasonable scope.

    Souldi may satisfy audit requests by providing documentation, security summaries, certifications, third-party reports, or written responses where appropriate.

    14.Confidentiality

    Each party shall keep confidential any non-public information received from the other party in connection with this DPA, including security information, technical information, customer data, business information, and audit materials.

    15.AI training, improvement, and role distinction

    Where Souldi processes Merchant Personal Data strictly on behalf of the Merchant, Souldi shall process such data according to the Merchant's documented instructions.

    Where Souldi determines the purposes and means of processing for AI model evaluation, testing, training, product improvement, security, fraud prevention, analytics, or service improvement, Souldi may act as an independent controller for that processing, as described in Souldi's Privacy Policy.

    Souldi shall not use uploaded images, generated avatars, embeddings, or related image-derived data for biometric identification, biometric verification, authentication, facial recognition, or to uniquely identify a person.

    Souldi shall provide users with the ability to request exclusion from AI-training and product-improvement uses as described in the Privacy Policy.

    16.Liability

    Liability under this DPA shall be governed by the main commercial agreement between Souldi and the Merchant, unless applicable data-protection law requires otherwise.

    Nothing in this DPA limits liability where such limitation is prohibited by applicable law.

    17.Governing law and jurisdiction

    This DPA is governed by the laws of Spain.

    Subject to any mandatory data-protection or consumer-protection rights that may apply, any dispute relating to this DPA shall be submitted to the Courts of Barcelona, Spain.

    18.Order of precedence

    In case of conflict between this DPA and the main commercial agreement, this DPA shall prevail only with respect to data-protection obligations for Merchant Personal Data.

    In case of conflict between this DPA and Souldi's Privacy Policy regarding Souldi-controlled processing, the Privacy Policy shall govern Souldi's independent controller processing unless otherwise required by law.

    19.Updates

    Souldi may update this DPA from time to time where required by law, security, infrastructure changes, subprocessor changes, product changes, or business needs.

    Material changes will be notified to Merchants by reasonable means.

    20.Acceptance

    The Merchant accepts this DPA by installing, accessing, enabling, subscribing to, or using the Services, or by signing or accepting an agreement that incorporates this DPA.

    Annex 1 — Processing Details

    Subject matter

    Provision of Souldi's virtual try-on, avatar, outfit visualization, styling, sizing, personalization, product recommendation, ecommerce integration, analytics, support, and related services.

    Duration

    For the term of the Merchant's agreement with Souldi, plus the deletion, return, backup, log, security, legal, and compliance periods described in this DPA.

    Nature and purpose

    Collection, receipt, storage, hosting, processing, transformation, generation, analysis, retrieval, consultation, support, transmission, deletion, and return of personal data to provide, maintain, secure, support, and improve the Services.

    Categories of personal data

    • customer identifiers;
    • account identifiers;
    • email or contact data where provided;
    • order, cart, product, and interaction data;
    • uploaded images;
    • generated avatars;
    • image masks;
    • measurement references;
    • embeddings;
    • generated results;
    • styling outputs;
    • size suggestions;
    • product recommendations;
    • technical metadata;
    • device, browser, and log data;
    • security, fraud-prevention, debugging, and error logs;
    • support communications.

    Categories of data subjects

    • Merchant customers;
    • store visitors;
    • Souldi users;
    • Merchant staff and administrators;
    • support contacts.

    Annex 2 — Technical and Organizational Measures

    Souldi applies technical and organizational measures designed to protect personal data. These may include:

    Access control

    • role-based access;
    • least-privilege principles;
    • account authentication;
    • internal access limitation to authorized personnel.

    Data security

    • encryption in transit where technically available;
    • secure hosting and infrastructure providers;
    • storage controls;
    • backup procedures;
    • deletion and retention controls.

    Operational security

    • logging and monitoring;
    • debugging and error tracking;
    • incident response procedures;
    • abuse, fraud, and misuse detection;
    • vulnerability and patch management where applicable.

    Organizational measures

    • confidentiality obligations;
    • internal access policies;
    • subprocessor review;
    • data minimization;
    • privacy and security review of material product changes.

    Retention controls

    • original uploaded images deleted after processing and in any case within 24 hours, unless limited retention is required;
    • generated avatars retained until user deletion, deletion request, account deletion, or termination handling;
    • generated results retained until user deletion, deletion request, account deletion, or termination handling;
    • logs retained up to 90 days unless longer retention is necessary;
    • encrypted backups may retain deleted data for up to 60 days before automatic deletion.

    Annex 3 — Subprocessor List

    Current subprocessors

    AWS

    • Purpose: hosting, storage, compute, networking, security, infrastructure and related services.
    • Location: EU/EEA regions where selected and technically available.
    • Transfer safeguards: applicable AWS data processing terms, SCCs or other safeguards where required.

    Supabase

    • Purpose: database, authentication, storage, backend infrastructure and related services.
    • Location: EU/EEA regions where selected and technically available.
    • Transfer safeguards: applicable Supabase data processing terms, SCCs or other safeguards where required.

    Annex 4 — Merchant Installation Clause

    The following clause may be included in the Merchant Terms, Shopify installation flow, or onboarding flow:

    By installing, accessing, enabling, subscribing to, or using Souldi, you agree to Souldi's Terms & Conditions, Privacy Policy, and Data Processing Addendum. If you use Souldi on behalf of a company, store, or brand, you confirm that you have authority to bind that entity to these terms.