Legal / DPA

Data processing addendum

This addendum forms part of the agreement between OmnyFit and the merchant where OmnyFit processes personal data on the merchant's behalf.

Last updated — 1 August 2026

1. Roles

The merchant is controller for shopper personal data processed through the widget. OmnyFit is processor and acts only on documented instructions from the merchant.

2. Subject matter and duration

Processing covers garment rendering, fit-confidence scoring and related analytics for the duration of the subscription term plus any agreed wind-down period.

3. Categories of data and data subjects

Data subjects: shoppers who choose to use the widget, and merchant staff with admin access. Data: photographs, derived body measurements, session events, and merchant account identifiers.

4. Security measures

TLS 1.3 in transit, encryption at rest, in-memory-only photo processing, scoped keys, SSO and MFA for internal access, logging and least-privilege separation between systems.

5. Sub-processors

OmnyFit maintains a current sub-processor list and gives 30 days' notice of additions, during which the merchant may object on reasonable data-protection grounds.

6. Breach notification

OmnyFit notifies the merchant without undue delay and in any event within 48 hours of becoming aware of a personal data breach, with the information needed for the merchant's own notification duties.

7. Audit and assistance

OmnyFit provides security documentation and penetration-test summaries under NDA, and assists with data-subject requests and impact assessments.

8. Deletion and return

On termination, OmnyFit deletes merchant and shopper-derived data within 30 days, except where retention is required by law, and confirms deletion in writing on request.

Questions about this document? Email legal@omnyfit.com.

CONTACT US

Ready to reduce returns? Talk to us.

Tell us about your store and we will set up a personalized demo for you!

Send a message