Legal / DPA
Data processing addendum
This addendum forms part of the agreement between OmnyFit and the merchant where OmnyFit processes personal data on the merchant's behalf.
Last updated — 1 August 2026
1. Roles
The merchant is controller for shopper personal data processed through the widget. OmnyFit is processor and acts only on documented instructions from the merchant.
2. Subject matter and duration
Processing covers garment rendering, fit-confidence scoring and related analytics for the duration of the subscription term plus any agreed wind-down period.
3. Categories of data and data subjects
Data subjects: shoppers who choose to use the widget, and merchant staff with admin access. Data: photographs, derived body measurements, session events, and merchant account identifiers.
4. Security measures
TLS 1.3 in transit, encryption at rest, in-memory-only photo processing, scoped keys, SSO and MFA for internal access, logging and least-privilege separation between systems.
5. Sub-processors
OmnyFit maintains a current sub-processor list and gives 30 days' notice of additions, during which the merchant may object on reasonable data-protection grounds.
6. Breach notification
OmnyFit notifies the merchant without undue delay and in any event within 48 hours of becoming aware of a personal data breach, with the information needed for the merchant's own notification duties.
7. Audit and assistance
OmnyFit provides security documentation and penetration-test summaries under NDA, and assists with data-subject requests and impact assessments.
8. Deletion and return
On termination, OmnyFit deletes merchant and shopper-derived data within 30 days, except where retention is required by law, and confirms deletion in writing on request.
Questions about this document? Email legal@omnyfit.com.
