Datenschutzerklärung
legal & privacy · Updated 28 July 2026
This notice explains how TAILORED. Systems ("we", "us") processes personal data when you use our virtual try-on service. We are the data controller for your account data and a data processor for the product images you upload on behalf of your organisation.
1 · Who we are
The controller under the GDPR is the provider of this offering, TAILORED. Systems. The operating company is currently in formation; its full legal name and registered address will be added to the Impressum once incorporation is complete. Responsible contact: [email protected].
2 · What we process
Account data (name, e-mail address, workspace details), billing data handled exclusively by our payment processor Stripe, the product images you upload, and the synthetic try-on images we generate. We do not process biometric data — every model used in generation is AI-generated and depicts no real person. We do not use your uploaded images or generated outputs to train or improve our AI models without your explicit opt-in.
AI transparency
Product images generated through the service are AI-generated. We label these outputs in the application as AI-generated.
3 · Where it lives
Uploads, generated outputs, and account data are stored and processed primarily on infrastructure located within the European Union (Germany). On-model image generation is currently performed by FASHN. The New Black is the planned successor provider; its processing locations and transfer safeguards must be legally resolved (Legal Gate KLE-376) before it is activated for production traffic. Our current sub-processor list is available at /subprocessors.
4 · Legal basis
We process account and image data to perform our contract with you (Art. 6(1)(b) GDPR). For product analytics we rely on our legitimate interest (Art. 6(1)(f) GDPR), which you may object to at any time by contacting [email protected].
5 · Retention
Images are retained until you delete them or close your workspace. On deletion, uploaded product images and generated outputs are removed within 90 days (active storage and backups). Structured application logs are retained for 30 days. Account data is erased within 30 days of workspace closure, subject to statutory retention obligations.
6 · Your rights (GDPR Art. 15–21)
You have the right to access, rectify, export, restrict processing of, and erase your personal data, and to lodge a complaint with a supervisory authority (in Germany: Bayerisches Landesamt für Datenschutzaufsicht, www.lda.bayern.de). Data export and deletion requests are handled via a documented manual operator procedure — contact [email protected] and your request will be handled promptly.
7 · Cookies and tracking
We use only essential session cookies required to authenticate you. We do not deploy third-party advertising trackers. Analytics, if used, are first-party and IP-anonymised.
8 · Changes to this notice
Material changes will be communicated by e-mail and by a prominent notice in the application at least 14 days before they take effect.