TailorPic

Photo Types

Legal

Data Processing Agreement

This Data Processing Agreement (“DPA”) describes how TailorPic processes Personal Data on behalf of its customers and forms part of the agreement between the parties for use of the TailorPic service. It is intended to meet the requirements of Article 28 of the GDPR.

Last updated: September 2026

01

Parties

This DPA is entered into between:

  • TailorPic (the “Data Processor”), the provider of the AI headshot generation service available at https://www.tailorpic.com.
  • The Customer (the “Data Controller”), the individual or organization that creates an account and uses the TailorPic service.

This DPA applies whenever TailorPic processes Personal Data on behalf of the Customer in the course of providing the service, and takes effect when the Customer accepts the TailorPic terms of service or otherwise begins using the service. In the event of a conflict between this DPA and the terms of service concerning the Processing of Personal Data, this DPA prevails.

02

Definitions

Terms used in this DPA have the meaning given in the GDPR. For convenience, the key terms are summarized below.

Data Controller
The natural or legal person that determines the purposes and means of the processing of Personal Data. Under this DPA, the Customer is the Data Controller for the photos and account information it provides.
Data Processor
The entity that processes Personal Data on behalf of the Data Controller. Under this DPA, TailorPic acts as the Data Processor.
Personal Data
Any information relating to an identified or identifiable natural person, including photographs and facial images, names, email addresses, and account details submitted to the Service.
Processing
Any operation performed on Personal Data, such as collection, storage, adaptation, use, transmission, erasure, or destruction.
Sub-processor
A third party engaged by TailorPic to process Personal Data on behalf of the Customer.
Data Protection Laws
All laws applicable to the Processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (GDPR) and, where applicable, the UK GDPR and the California Consumer Privacy Act (CCPA).
03

Scope of Processing

TailorPic processes Personal Data only on the Customer’s documented instructions, which consist of this DPA, the terms of service, and the Customer’s use of the service features. The Processing consists of the following activities:

  1. 1

    Photo upload

    The Customer uploads photographs of themselves or of individuals for whom they hold the necessary rights and consents. Photos are received over encrypted connections and stored in secured storage.

  2. 2

    AI model training

    Uploaded photos are used to train a personalized AI model for the individual depicted. This model is created solely to generate that individual’s headshots and is not used to serve other customers.

  3. 3

    Result generation

    The personalized model is used to generate the headshots ordered by the Customer, which are then made available for download in the Customer’s account.

Categories of data subjects
Customers and the individuals depicted in photos they upload.
Types of Personal Data
Photographs and facial images, name, email address, account and order information.
Duration
For as long as the Customer uses the service, subject to the retention and deletion terms in Section 6.

The Customer is responsible for ensuring it has a lawful basis for processing the photos it uploads, including any consent required from the individuals depicted. TailorPic will not process Personal Data for its own purposes, will not sell Personal Data, and will inform the Customer if it believes an instruction infringes Data Protection Laws. TailorPic ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.

04

Data Security Measures

TailorPic implements technical and organizational measures appropriate to the risk of the Processing. These include:

  • Encryption

    Data is encrypted at rest using AES-256 and in transit using TLS 1.3.

  • Access control

    Role-based access controls apply across internal systems. Only authorized personnel can access production data, and only when necessary to operate the Service or provide support.

  • Logging and monitoring

    Access to customer data is logged and audited. Our hosting infrastructure is continuously monitored, with automated backups and network isolation.

  • Purpose limitation

    Customer photos are used solely to provide the Service. We do not sell facial or biometric data, and photos are not shared outside the platform other than with the Sub-processors listed below.

  • Payment data

    TailorPic does not store credit card numbers or sensitive payment details. Payments are handled by Stripe.

For a broader overview of our practices, see our Security & Data Protection page.

05

Sub-processors

The Customer gives TailorPic general authorization to engage the following Sub-processors. TailorPic remains responsible for its Sub-processors and imposes data protection obligations on them that are no less protective than those in this DPA.

  • Supabase

    Infrastructure

    Provides database, authentication, and file storage. Stores account information, uploaded photos, and generated results on behalf of TailorPic.

  • Stripe

    Payment processing

    Processes payments and handles billing details. Receives payment and billing information needed to complete a transaction; card details are not stored by TailorPic.

  • Replicate

    AI processing

    Runs the AI workloads used for model training and headshot generation. Receives the photos and prompts required to perform these tasks.

TailorPic will inform the Customer of any intended addition or replacement of Sub-processors, giving the Customer the opportunity to object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may stop using the service and request deletion of its data.

06

Data Retention and Deletion

Uploaded photos and the training data derived from them are automatically and permanently deleted within 30 days after processing is complete and the results have been delivered.

The Customer may request earlier deletion of its Personal Data at any time by contacting us. Upon termination of the service or on written request, TailorPic will delete or return Personal Data, and delete existing copies, unless retention is required by applicable law. Limited billing and order records may be retained by TailorPic and Stripe as needed to meet legal, tax, and accounting obligations.

TailorPic will assist the Customer, taking into account the nature of the Processing, in responding to data subject requests to exercise their rights of access, rectification, erasure, restriction, portability, and objection. Requests received directly from data subjects will be forwarded to the Customer where appropriate.

07

Data Breach Notification

TailorPic will notify the Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Customer’s Personal Data.

The notification will, to the extent known at the time, include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and records affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its effects.
  • A contact point from whom more information can be obtained.

Where all information is not available at once, it may be provided in phases. TailorPic will reasonably cooperate with the Customer in meeting its own obligations to notify supervisory authorities and data subjects.

08

Audit Rights

TailorPic will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

Audit requests should be sent in writing to support@tailorpic.com with reasonable advance notice. Audits will be conducted during normal business hours, limited to what is necessary and proportionate, subject to reasonable confidentiality obligations, and carried out in a manner that minimizes disruption to the service and does not compromise the security or confidentiality of other customers’ data. Each party bears its own costs of an audit unless the audit reveals a material breach of this DPA by TailorPic.

09

International Data Transfers

TailorPic and its Sub-processors may process Personal Data in countries outside the European Economic Area (EEA) and the United Kingdom, including the United States.

Where Personal Data originating from the EEA or the UK is transferred to a country without an adequacy decision, TailorPic will ensure an appropriate transfer mechanism is in place as required by Data Protection Laws, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where necessary. Upon request, the Customer may obtain further information on the safeguards applied by contacting us.

10

Contact

For questions about this DPA, to request deletion of your data, to report a concern, or to exercise audit rights, contact us at:

support@tailorpic.com

To report a security vulnerability, please see our Security page. Last updated: September 2026.