Data processing agreement
Last updated 24 August 2026Byte Shift Ltd, company number 13244292
1. Scope and precedence
This agreement applies where Byte Shift Ltd (company number 13244292, registered in England and Wales), the processor, processes personal data on behalf of a business customer, the controller, in providing the service. It forms part of our terms of service and satisfies Article 28 of the UK GDPR. No signature is required: it takes effect when you accept those terms.
Where this agreement conflicts with the terms of service on the processing of personal data, this agreement prevails. Words defined in UK GDPR carry those meanings here.
2. The processing, in the terms Article 28 requires
- Subject matter: providing an AI photography service that reads product photographs supplied by the controller and generates new photographs from them.
- Duration:for as long as the controller's account is open, plus the short deletion periods in section 8.
- Nature and purpose: storage, transmission, cropping, automated image analysis, prompt construction and image generation, and the delivery of the results back to the controller.
- Types of personal data: images that may contain the likeness of identifiable individuals, and any personal data the controller chooses to type into product or shoot descriptions.
- Categories of data subject: individuals appearing in photographs the controller uploads, such as models the controller has engaged.
Account data about the controller's own staff is processed by us as a controller, not under this agreement; our privacy policy covers it.
3. Processing only on documented instructions
We process personal data only on the controller's documented instructions, which are given by configuring and using the service, and as required by law. If a legal requirement forces us to process otherwise, we will tell the controller first unless the law forbids it.
We will tell the controller if we consider an instruction to breach data protection law. We do not use personal data processed under this agreement to train, fine tune or evaluate AI models, and we do not use it for any purpose of our own.
4. The controller's responsibilities
The controller warrants that it has a lawful basis for the material it uploads, has given the required transparency information to the individuals in it, and holds any consent or release needed for that material to be reworked into generated imagery. Where a photograph depicts an identifiable person, obtaining and evidencing that permission is the controller's responsibility, not ours.
5. Confidentiality and staff
Access is limited to personnel who need it to provide or support the service, each bound by confidentiality obligations and trained in their data protection responsibilities. Administrative access uses a separate authentication system from customer accounts and is logged.
6. Security
We implement appropriate technical and organisational measures under Article 32, including encryption in transit, hashed credentials and session tokens, per account authorisation on every asset request, least privilege access, network isolation of the database and job queue, rate limiting, and spend controls that bound automated processing. Our privacy policy describes these in plainer terms.
7. Subprocessors
The controller gives general authorisation for us to engage subprocessors. The current list is published at our subprocessor page. We impose data protection obligations on each of them no less protective than these, and we remain fully liable to the controller for their performance.
We will give at least 15 days notice before a new subprocessor begins processing. The controller may object on reasonable data protection grounds within 10 days; if we cannot offer an alternative, the controller may terminate and receive a refund of unused credits.
8. Data subject rights, deletion and return
The service lets the controller access, correct, export and delete the material it has uploaded directly, which will usually be the fastest route to answering a request. Where it is not, we will provide reasonable assistance, taking into account the nature of the processing.
Deleting a project deletes its uploads, product crops and generated photographs from our storage. On termination we delete personal data processed under this agreement within 30 days, except where law requires retention. Backups age out on their own cycle and are not restored into production once deleted.
9. Breach notification and assistance
We will notify the controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting its data, with the information reasonably available to us. We will assist the controller with Articles 32 to 36, including data protection impact assessments and consultation with the Information Commissioner's Office, taking into account the information available to us.
10. International transfers
Some subprocessors are outside the UK. Transfers rely on UK adequacy regulations where available, and otherwise on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment. Where the EU GDPR applies to the controller, the corresponding standard contractual clauses apply.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with Article 28 and, on reasonable written notice and no more than once a year, allow an audit by the controller or an independent auditor bound by confidentiality. Audits must not disrupt the service or compromise other customers' data, and the controller bears its own costs.
12. Contact
For anything under this agreement, including breach notifications and audit requests, write to support@fashionstudioapp.com. If you need a countersigned copy for your records, ask and we will provide one.
Questions about this document: support@fashionstudioapp.com. Byte Shift Ltd is registered in England and Wales.