Políticas - Acordo Padrão de Processamento de Dados (DPA)
Acordo Padrão de Processamento de Dados (DPA)
Last updated: 23rd of July 2026
This Data Processing Addendum, including its Schedules and any documents incorporated into it by reference, is referred to as the “DPA.”
This DPA forms part of the Prime AI Terms of Service, any Subscription Agreement, Service Agreement, Service Order, Order Form or other written or electronic agreement entered into between:
Prime AI Limited, registered in England and Wales under company number 11599467, with its registered office at Oakwood Lodge, Thornden Wood Road, Herne Bay, CT6 7NX, United Kingdom (“Prime AI”); and
the person or legal entity subscribing to or using the Services (“Subscriber”).
The agreement incorporating this DPA is referred to as the “Agreement.”
This DPA applies where Prime AI processes Subscriber Personal Data on behalf of the Subscriber in connection with the Services.
Where the Subscriber accepts the Agreement on behalf of a company or another legal entity, the person accepting the Agreement confirms that they are authorised to bind that entity to this DPA.
1. Definições
1.1 Applicable Data Protection Laws
“Applicable Data Protection Laws” means all data protection, privacy and electronic communications legislation applicable to the processing of Subscriber Personal Data under the Agreement, including, where applicable:
a. the UK General Data Protection Regulation;
b. the Data Protection Act 2018;
c. the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended or replaced;
d. Regulation (EU) 2016/679, the General Data Protection Regulation;
e. applicable national laws implementing or supplementing the EU GDPR; and
f. other applicable data protection and privacy laws in jurisdictions in which Subscriber Personal Data is processed or the Subscriber is established.
1.2 Controller, Processor and related terms
The terms “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Supervisory Authority” e “Special Category Personal Data” have the meanings given to them under Applicable Data Protection Laws.
1.3 Agreement
“Agreement” means the Prime AI Terms of Service, Subscription Agreement, Service Agreement, Service Order, Order Form or other written or electronic agreement governing the Subscriber’s use of the Services.
1.4 Documentation
“Documentation” means the technical, security, integration and operational documentation made available by Prime AI in connection with the Services.
1.5 Personal Data Breach
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Subscriber Personal Data transmitted, stored or otherwise processed by Prime AI.
A Personal Data Breach does not include an unsuccessful attempt or activity that does not compromise the security of Subscriber Personal Data, including an unsuccessful login attempt, network scan, denial-of-service attempt or similar activity.
1.6 Restricted Transfer
“Restricted Transfer” means a transfer of Personal Data to a country or recipient that is not covered by an applicable adequacy decision or regulation and therefore requires an appropriate transfer safeguard under Applicable Data Protection Laws.
1.7 Services
“Services” means the products, software, APIs, applications, hosted services, support and related services supplied by Prime AI under the Agreement.
1.8 Subscriber Data
“Subscriber Data” means data submitted to, transmitted to, collected through or otherwise processed by the Services on behalf of the Subscriber.
1.9 Subscriber Personal Data
“Subscriber Personal Data” means Personal Data contained within Subscriber Data that Prime AI processes on behalf of the Subscriber.
1.10 Subprocessor
“Subprocessor” means a third party, including a Prime AI Affiliate, appointed by or on behalf of Prime AI to process Subscriber Personal Data in connection with the Services.
1.11 Term
“Term” means the period during which Prime AI provides the Services to the Subscriber, together with any limited post-termination period during which Prime AI processes Subscriber Personal Data for deletion, return, security, backup, legal compliance or dispute resolution purposes.
2. Scope and order of precedence
2.1 This DPA applies only to the extent that Prime AI processes Subscriber Personal Data as a Processor on behalf of the Subscriber.
2.2 This DPA does not apply to information for which Prime AI acts as an independent Controller, as described in section 4.
2.3 In the event of a conflict concerning the processing of Subscriber Personal Data, the following order of precedence applies:
a. any applicable mandatory international data transfer terms;
b. this DPA;
c. the applicable Service Order or Order Form;
d. the remaining provisions of the Agreement; and
e. the Documentation.
2.4 A separately signed data processing agreement between Prime AI and the Subscriber shall take precedence over this standard DPA to the extent of any direct conflict.
3. Roles of the parties
3.1 The Subscriber is the Controller of Subscriber Personal Data, unless the Subscriber is acting as a Processor on behalf of another Controller.
3.2 Prime AI is the Processor of Subscriber Personal Data processed on behalf of the Subscriber to provide the Services.
3.3 Each Party shall comply with the obligations applicable to it under Applicable Data Protection Laws.
3.4 The Subscriber determines:
a. the purposes for which the Services are deployed;
b. the categories of Data Subjects whose Personal Data is processed;
c. the lawful basis for the processing;
d. how outputs, identifiers, recommendations and risk signals are used;
e. the retention periods applying within the Subscriber’s own systems; and
f. any actions or decisions taken using information returned by the Services.
3.5 Nothing in this DPA relieves the Subscriber of its own responsibilities as a Controller or Processor under Applicable Data Protection Laws.
4. Prime AI acting as an independent Controller
4.1 Prime AI may process limited Personal Data as an independent Controller where necessary for:
a. administering the Subscriber’s account;
b. managing billing, payments and financial records;
c. communicating with Subscriber representatives;
d. providing customer support;
e. protecting the security and integrity of the Services;
f. detecting misuse of Prime AI systems or credentials;
g. maintaining legal, regulatory and compliance records;
h. establishing, exercising or defending legal claims; and
i. producing aggregated or de-identified service analytics.
4.2 Processing carried out by Prime AI as an independent Controller is governed by Prime AI’s Privacy Policy and Applicable Data Protection Laws and is not subject to the Processor obligations in this DPA.
5. Subscriber instructions
5.1 Prime AI shall process Subscriber Personal Data only:
a. on the Subscriber’s documented instructions;
b. as necessary to provide, maintain, secure and support the Services;
c. in accordance with the Agreement, the applicable Service Order, this DPA and the Documentation;
d. according to the configurations and functionality selected by the Subscriber; or
e. where processing is required by applicable law.
5.2 The Agreement, Service Orders, Documentation, the Subscriber’s use and configuration of the Services, and written communications from the Subscriber constitute the Subscriber’s documented instructions.
5.3 Where applicable law requires Prime AI to process Subscriber Personal Data other than on the Subscriber’s instructions, Prime AI shall inform the Subscriber before carrying out that processing unless the law prohibits such notification.
5.4 Prime AI shall immediately inform the Subscriber if, in Prime AI’s reasonable opinion, an instruction infringes Applicable Data Protection Laws.
5.5 Prime AI may suspend the affected processing until the Parties agree a lawful instruction.
5.6 Prime AI shall not:
a. sell Subscriber Personal Data;
b. use Subscriber Personal Data for unrelated advertising purposes;
c. process Subscriber Personal Data for purposes materially inconsistent with the Agreement; or
d. disclose Subscriber Personal Data except as permitted by the Agreement, this DPA, the Subscriber’s instructions or applicable law.
6. Subscriber responsibilities
6.1 The Subscriber warrants and shall ensure that:
a. its instructions to Prime AI comply with Applicable Data Protection Laws;
b. it has an appropriate lawful basis for the processing;
c. it has provided Data Subjects with all legally required privacy information;
d. it has obtained any legally required consent or authorisation;
e. its use of the Services is necessary and proportionate for the relevant purpose;
f. Subscriber Personal Data is accurate, relevant and limited to what is necessary;
g. it has implemented appropriate retention and deletion policies;
h. it responds appropriately to Data Subject requests;
i. it carries out any legally required legitimate interests assessment or data protection impact assessment; and
j. it does not use the Services in a manner that unlawfully discriminates against or unfairly affects a Data Subject.
6.2 Where the Subscriber uses the Persistent Device ID and Risk Signals API, the Subscriber is responsible for determining whether its implementation involves storing information on, or accessing information from, a user’s device.
6.3 The Subscriber is responsible for:
a. determining whether consent, an applicable exemption or another legal requirement applies under PECR or equivalent legislation;
b. providing clear and comprehensive information about the technology;
c. implementing any required consent or preference-management mechanism;
d. determining whether a simple means of objecting must be provided;
e. documenting its compliance assessment; and
f. ensuring that the Services are used only for lawful security, fraud prevention, risk management or abuse-prevention purposes.
6.4 Unless expressly agreed in writing, the Subscriber shall not submit to Prime AI through the Services:
a. account passwords or authentication secrets;
b. complete payment-card details;
c. bank-account credentials;
d. government identification numbers;
e. Special Category Personal Data;
f. biometric data used for uniquely identifying a person;
g. information concerning criminal convictions or offences; or
h. Personal Data specifically relating to children.
6.5 The Persistent Device ID and Risk Signals API is designed to receive technical device and session information. The Subscriber should not transmit names, email addresses, telephone numbers, postal addresses or other directly identifying account information through the API unless expressly required by the Documentation and agreed by Prime AI.
6.6 Where the Subscriber combines an identifier or risk signal returned by Prime AI with customer, account, transaction or identity information held by the Subscriber, the Subscriber is responsible for that combination and the resulting processing.
7. Confidentiality
7.1 Prime AI shall ensure that each person authorised to process Subscriber Personal Data:
a. is subject to an appropriate contractual or statutory duty of confidentiality;
b. is informed of the confidential nature of Subscriber Personal Data;
c. receives appropriate privacy and security training; and
d. accesses Subscriber Personal Data only where necessary for their responsibilities.
7.2 Prime AI shall limit access to Subscriber Personal Data according to the principles of least privilege and role-based access.
8. Security
8.1 Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to Data Subjects, Prime AI shall implement and maintain appropriate technical and organisational measures designed to protect Subscriber Personal Data.
8.2 Prime AI’s security measures include, as appropriate:
a. encryption of data in transit;
b. encryption at rest where appropriate to the relevant system and risk;
c. identity and access management controls;
d. multi-factor authentication for privileged access;
e. role-based and least-privilege access;
f. logging, monitoring and alerting;
g. logical separation of customer environments or records;
h. secure development and change management procedures;
i. vulnerability and patch management procedures;
j. backup, resilience and recovery procedures;
k. incident-response procedures;
l. employee confidentiality and security training;
m. Subprocessor due diligence and contractual controls; and
n. periodic review of the effectiveness of security measures.
8.3 Prime AI may update its technical and organisational measures during the Term, provided that the overall level of protection for Subscriber Personal Data is not materially reduced.
8.4 Further information concerning Prime AI’s technical and organisational measures may be made available to contracted Subscribers on reasonable written request and subject to appropriate confidentiality obligations.
8.5 The Subscriber acknowledges that no internet-based service can be guaranteed to be completely secure and that the Subscriber is responsible for securing:
a. its own websites, applications and infrastructure;
b. its API keys, passwords and access credentials;
c. its systems receiving Prime AI outputs;
d. access to identifiers and risk signals within its organisation; and
e. any Personal Data retained in the Subscriber’s own systems.
9. Personal Data Breaches
9.1 Prime AI shall notify the Subscriber without undue delay after becoming aware of a confirmed Personal Data Breach affecting Subscriber Personal Data.
9.2 The notification shall include, to the extent the information is reasonably available:
a. the nature of the Personal Data Breach;
b. the categories of Subscriber Personal Data affected;
c. the categories and approximate number of affected Data Subjects, where known;
d. the likely consequences of the Personal Data Breach;
e. the measures taken or proposed to contain, investigate and mitigate it; and
f. appropriate contact information for further communication.
9.3 Where all relevant information is not immediately available, Prime AI may provide information in phases without undue further delay.
9.4 Prime AI shall take reasonable steps to contain, investigate, remediate and mitigate the effects of the Personal Data Breach.
9.5 Prime AI shall provide reasonable cooperation to assist the Subscriber in complying with its breach-notification obligations.
9.6 A notification under this section does not constitute an admission of fault or liability by Prime AI.
9.7 The Subscriber is responsible for determining whether notification must be made to a Supervisory Authority, affected Data Subjects or another third party.
10. Data Subject rights
10.1 Taking into account the nature of the processing, Prime AI shall provide reasonable assistance to enable the Subscriber to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws.
10.2 Such rights may include:
a. access;
b. rectification;
c. erasure;
d. restriction of processing;
e. data portability;
f. objection; and
g. rights relating to automated decision-making.
10.3 If Prime AI receives a request directly from a Data Subject relating to Subscriber Personal Data, Prime AI shall:
a. not respond substantively unless authorised by the Subscriber or required by law; and
b. forward the request to the Subscriber where the relevant Subscriber can reasonably be identified.
10.4 The Subscriber acknowledges that some technical identifiers may not enable Prime AI independently to identify a particular Data Subject without additional information held by the Subscriber.
10.5 Prime AI may charge reasonable fees for assistance requiring substantial work outside the ordinary functionality of the Services, unless the assistance is required because of Prime AI’s breach of this DPA.
11. Compliance assistance
11.1 Taking into account the nature of the processing and the information available to Prime AI, Prime AI shall provide reasonable assistance to the Subscriber concerning:
a. the security of processing;
b. assessment and notification of Personal Data Breaches;
c. notification to affected Data Subjects;
d. data protection impact assessments;
e. prior consultation with a Supervisory Authority; and
f. demonstrating compliance with the Subscriber’s Controller obligations relating to Prime AI’s processing.
11.2 Prime AI may charge reasonable fees for substantial assistance not caused by Prime AI’s breach of this DPA.
12. Subprocessors
12.1 The Subscriber gives Prime AI general written authorisation to appoint the Subprocessors listed on Prime AI’s Infrastructure Sub-processors page.
12.2 Prime AI shall maintain an up-to-date list identifying:
a. each Subprocessor;
b. the services it provides;
c. the categories of processing it performs; and
d. the primary processing location.
12.3 Prime AI shall provide reasonable advance notice of an intended addition or replacement of a Subprocessor that will process Subscriber Personal Data.
12.4 The Subscriber may object to the proposed appointment on reasonable data-protection grounds by giving written notice within 10 Business Days after receiving notice of the proposed change.
12.5 The Subscriber’s objection must explain the specific data-protection concern.
12.6 The Parties shall work in good faith to resolve a valid objection, including by considering a commercially reasonable alternative where one is available.
12.7 If the Parties cannot resolve the objection and Prime AI cannot provide the affected Service without the proposed Subprocessor, either Party may terminate the affected Service.
12.8 Where the Subscriber has prepaid fees for the period following termination under section 12.7, Prime AI shall refund the prepaid fees attributable to the unused period of the affected Service.
12.9 Before a Subprocessor processes Subscriber Personal Data, Prime AI shall enter into a written agreement imposing data-protection obligations that provide an equivalent level of protection to the obligations in this DPA.
12.10 Prime AI remains responsible to the Subscriber for the performance of each Subprocessor’s data-protection obligations to the extent required by Applicable Data Protection Laws.
13. International data transfers
13.1 Prime AI primarily processes Subscriber Personal Data within the United Kingdom and the European Economic Area, subject to the applicable Service and Subprocessor arrangements identified on the Infrastructure Sub-processors page.
13.2 Prime AI shall not make a Restricted Transfer unless:
a. the transfer is made to a country or recipient covered by an applicable adequacy decision or regulation;
b. the transfer is subject to appropriate contractual safeguards;
c. another legally recognised transfer mechanism applies; or
d. the transfer is otherwise permitted under Applicable Data Protection Laws.
13.3 Appropriate safeguards may include:
a. the European Commission’s Standard Contractual Clauses;
b. the United Kingdom International Data Transfer Agreement;
c. the United Kingdom Addendum to the European Commission Standard Contractual Clauses; or
d. another approved transfer mechanism.
13.4 Prime AI shall implement supplementary technical, contractual or organisational measures where reasonably required by Applicable Data Protection Laws.
13.5 On reasonable request, Prime AI shall provide information concerning the transfer mechanism applicable to Subscriber Personal Data.
14. Return and deletion
14.1 Upon termination or expiry of the affected Services, Prime AI shall, at the Subscriber’s written choice:
a. return Subscriber Personal Data that is reasonably capable of being returned; or
b. delete Subscriber Personal Data,
unless applicable law requires Prime AI to retain it.
14.2 Where the Subscriber does not communicate its choice within 30 days after termination, Prime AI may delete Subscriber Personal Data in accordance with its standard deletion procedures.
14.3 Unless a different period is specified in the applicable Service Order or Schedule 1, Prime AI shall place Subscriber Personal Data beyond ordinary use and delete it from active production systems within 30 days after termination.
14.4 Subscriber Personal Data contained in backups may remain until the relevant backup is overwritten or deleted through Prime AI’s normal backup cycle, provided that:
a. the data remains appropriately protected;
b. access is restricted;
c. the data is not restored except for legitimate disaster-recovery or security purposes; and
d. the data is deleted when the relevant backup is overwritten.
14.5 Prime AI may retain limited information where necessary for:
a. legal or regulatory compliance;
b. billing and financial records;
c. security and misuse prevention;
d. dispute resolution; or
e. establishing, exercising or defending legal claims.
14.6 Information retained under section 14.5 shall remain protected and shall not be processed for another purpose.
15. Demonstration of compliance and audits
15.1 Prime AI shall maintain records and information reasonably necessary to demonstrate compliance with its obligations under this DPA.
15.2 On reasonable written request, Prime AI shall provide relevant compliance information.
15.3 The Parties agree that relevant documentation and independent assurance materials should ordinarily be used before an on site audit is requested.
15.4 Where the information provided under section 15.2 is not reasonably sufficient, the Subscriber may conduct an audit of Prime AI’s compliance with this DPA, subject to the following conditions:
a. no more than one audit may be conducted in any 12-month period, except following a confirmed Personal Data Breach or where required by a Supervisory Authority;
b. the Subscriber must provide at least 30 days’ written notice, unless a shorter period is required by law or a Supervisory Authority;
c. the audit must take place during normal business hours;
d. the audit must be limited to systems, records and processing relevant to the Subscriber;
e. the audit must not unreasonably interfere with Prime AI’s operations;
f. the auditor must be independent, appropriately qualified and subject to confidentiality obligations;
g. the auditor must not be a direct competitor of Prime AI;
h. the audit must not provide access to another customer’s data, Prime AI source code, vulnerability information or information that would compromise the security of the Services; and
i. the Subscriber shall bear its own audit costs and Prime AI’s reasonable costs of supporting the audit, unless the audit identifies a material breach of this DPA by Prime AI.
15.5 Prime AI shall inform the Subscriber if, in Prime AI’s reasonable opinion, an audit instruction infringes Applicable Data Protection Laws or creates an unreasonable security risk.
16. Liability
16.1 Each Party’s contractual liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability contained in the Agreement.
16.2 Nothing in this DPA limits or excludes:
a. either Party’s statutory responsibilities under Applicable Data Protection Laws;
b. liability that cannot legally be limited or excluded;
c. liability for fraud or fraudulent misrepresentation; or
d. liability for death or personal injury caused by negligence.
16.3 Nothing in section 16.1 prevents a Data Subject or Supervisory Authority from exercising rights or powers available under Applicable Data Protection Laws.
17. Term and survival
17.1 This DPA takes effect when the Subscriber:
a. accepts the Prime AI Terms of Service electronically;
b. selects a checkbox or other electronic mechanism confirming acceptance of this DPA;
c. enters into a Service Order or other Agreement incorporating this DPA;
d. installs or activates a Prime AI application through a third-party platform where this DPA is clearly incorporated into the applicable terms; or
e. signs this DPA or another Agreement incorporating it.
17.2 This DPA remains in force for as long as Prime AI processes Subscriber Personal Data.
17.3 Obligations concerning confidentiality, security, deletion, audits, liability and international transfers survive termination for as long as Prime AI retains Subscriber Personal Data.
18. Changes to this DPA
18.1 Prime AI may update this DPA where reasonably necessary to:
a. comply with changes in Applicable Data Protection Laws;
b. reflect changes to the Services or processing activities;
c. implement new regulatory guidance;
d. improve the clarity of the DPA; or
e. maintain appropriate safeguards.
18.2 Prime AI shall identify the date on which the DPA was last updated.
18.3 Prime AI shall give affected Subscribers reasonable advance notice of a material change, except where an immediate change is required by law, a regulator or an urgent security requirement.
18.4 A material update shall not intentionally reduce the overall protection provided to Subscriber Personal Data.
18.5 Where a separately signed agreement specifies a different amendment process, that process shall apply.
19. Governing law and jurisdiction
19.1 This DPA is governed by the governing law specified in the Agreement.
19.2 Where the Agreement does not specify governing law, this DPA is governed by the laws of England and Wales.
19.3 The courts specified in the Agreement shall have jurisdiction over disputes relating to this DPA.
19.4 Where the Agreement does not specify jurisdiction, the courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rights or powers under Applicable Data Protection Laws.
20. Contact information
Prime AI Limited
Registered in England and Wales under company number 11599467
Oakwood Lodge
Thornden Wood Road
Herne Bay
CT6 7NX
Reino Unido
Privacy contact: [email protected]
You may also contact Prime AI through the Contact Us page.
Schedule 1: Details of Processing
1. General processing information
Subject matter
The processing of Subscriber Personal Data as necessary to provide, maintain, secure and support the Services selected by the Subscriber.
Duração
The Term of the applicable Service, together with the limited deletion, backup and legal-retention periods described in this DPA and the applicable Service Order.
Frequency
Continuous, periodic or event-driven, depending on the Service and the Subscriber’s use and configuration of it.
Data subjects
Depending on the Services selected, Data Subjects may include:
a. visitors to the Subscriber’s websites or applications;
b. registered and unregistered users;
c. customers and prospective customers of the Subscriber;
d. shoppers and users of e-commerce services;
e. employees or authorised users of the Subscriber;
f. individuals appearing in images submitted to visual Services; and
g. other individuals whose Personal Data is submitted to the Services by or on behalf of the Subscriber.
Special Category Personal Data
The Services are not intended to process Special Category Personal Data, biometric data used for uniquely identifying a person, criminal-offence data or data specifically relating to children unless expressly agreed in writing.
2. Persistent Device ID and Risk Signals API
Propósito
To provide device and session intelligence for legitimate security, fraud prevention, risk management and abuse-prevention purposes.
Potential use cases include:
a. recognising returning devices;
b. detecting account recreation or multiple-account activity;
c. identifying free-trial, promotion or referral abuse;
d. detecting automation or bot activity;
e. identifying suspicious browser, device, network or session behaviour;
f. supporting the Subscriber’s review of potentially fraudulent or abusive activity; and
g. protecting accounts, transactions, digital content and services.
Nature of processing
The processing may include:
a. collection and receipt;
b. transmission;
c. organisation and structuring;
d. comparison and matching;
e. analysis;
f. generation of persistent or session identifiers;
g. generation of confidence indicators and risk signals;
h. storage and retrieval;
i. security monitoring; and
j. deletion.
Categories of Personal Data
Depending on the Subscriber’s implementation, the processing may include:
a. IP address and general network information;
b. browser type and version;
c. operating-system and device information;
d. device and browser configuration attributes;
e. screen, language, locale and timezone information;
f. online, device, session and request identifiers;
g. timestamps and request metadata;
h. the Subscriber domain or application from which a request originates;
i. device and session consistency information;
j. private or incognito browsing indicators;
k. VPN and data-centre network indicators;
l. automation, bot or headless-browser indicators;
m. developer-tools activity indicators;
n. browser-tampering or manipulation indicators;
o. timezone and network inconsistencies;
p. confidence scores, risk levels and recommended-action fields; and
q. API usage and security logs.
Outputs
Prime AI may return:
a. persistent device identifiers;
b. session identifiers;
c. returning-device indicators;
d. technical telemetry;
e. confidence indicators;
f. risk signals;
g. risk levels; and
h. recommended-action or customer-defined decision-support fields.
The Subscriber determines how these outputs are interpreted and used.
Retention
Persistent Device ID and Risk Signals API event, device and session data is retained for 360 days, unless a different period is specified in the applicable Service Order or Documentation.
Security, billing and API usage records may be retained for longer where reasonably necessary for security, legal compliance, billing or dispute-resolution purposes.
3. Clothing, footwear and bra sizing Services
Propósito
To provide product sizing, fit recommendations and related analytics to the Subscriber and its users.
Nature of processing
The processing may include collection, transmission, analysis, comparison, recommendation generation, storage, retrieval and deletion.
Categories of Personal Data
Depending on the relevant Service and configuration, the processing may include:
a. height;
b. weight;
c. age range;
d. sex or gender selection where provided by the user;
e. body, garment or footwear measurements;
f. fit preferences;
g. product and size selections;
h. sizing questionnaire responses;
i. purchase, return or product-interaction information supplied by the Subscriber;
j. pseudonymous customer or session identifiers;
k. photographs voluntarily submitted for measurement or recommendation purposes; and
l. recommendation results and associated confidence information.
The Services are not intended to infer health information or other Special Category Personal Data.
4. Visual Search
Propósito
To analyse an image or product information submitted by or on behalf of the Subscriber and identify visually similar products or content.
Nature of processing
The processing may include receipt, transmission, image analysis, feature extraction, comparison, search-result generation, temporary storage and deletion.
Categories of Personal Data
The processing may include:
a. images uploaded by users or the Subscriber;
b. product images;
c. image metadata;
d. session or pseudonymous identifiers; and
e. search and interaction information.
The Subscriber shall ensure that it has the necessary rights and lawful basis to submit images to the Service.
5. Virtual Try-On, AI Photoshoot and visualisation Services
Propósito
To generate visualisations, virtual try-on results, edited images or other visual outputs requested by the Subscriber or its users.
Nature of processing
The processing may include secure transmission, temporary storage, image analysis, transformation, generation of outputs and deletion.
Categories of Personal Data
The processing may include:
a. photographs submitted by the Subscriber or its users;
b. images of models or other individuals;
c. image metadata;
d. garment or product information;
e. session or pseudonymous identifiers; and
f. generated visual outputs.
Technology partners
Prime AI may securely transmit submitted images to an authorised Subprocessor solely to perform the processing necessary to generate the requested result.
Unless otherwise specified in the Service Order or Documentation, images used for transient processing are not retained by Prime AI after the result has been generated, except where:
a. the Subscriber requests storage;
b. temporary retention is technically necessary to deliver the result;
c. retention is required for security or troubleshooting; or
d. retention is required by law.
These Services are not intended to perform biometric identification or determine a person’s identity.
6. Support and account administration
Propósito
To provide technical support, investigate errors, protect the Services and administer the Subscriber’s account.
Categories of Personal Data
The processing may include:
a. names and business contact details of Subscriber personnel;
b. support communications;
c. technical logs;
d. account information;
e. screenshots or files voluntarily provided to support personnel; and
f. information required to investigate an issue.
Prime AI may act as an independent Controller for certain account, security and business-administration processing, as described in section 4 of this DPA.
Schedule 2: Technical and Organisational Measures
Prime AI maintains technical and organisational measures appropriate to the nature of the Services and the risks associated with the processing.
These measures include, as appropriate:
1. Information security governance
a. documented security responsibilities;
b. internal security and privacy policies;
c. periodic review of security controls;
d. risk assessment and remediation procedures; and
e. management oversight of security issues.
2. Access control
a. role-based access;
b. least-privilege access;
c. unique user accounts;
d. multi-factor authentication for appropriate systems;
e. password and credential-management requirements;
f. periodic access review; and
g. prompt removal of access when it is no longer required.
3. Confidentiality and personnel security
a. contractual confidentiality obligations;
b. privacy and security training;
c. access limited according to job responsibilities; and
d. appropriate procedures for employees and contractors joining, changing roles or leaving.
4. Encryption and transmission security
a. encryption of data in transit using appropriate transport-security protocols;
b. encryption at rest where appropriate to the relevant system and risk;
c. secure management of encryption keys and credentials; and
d. controls designed to prevent unauthorised interception or disclosure.
5. Infrastructure and application security
a. secure configuration;
b. network and infrastructure controls;
c. vulnerability identification and remediation;
d. patch-management procedures;
e. secure development and change-management practices;
f. separation of development and production access where appropriate; and
g. controls intended to prevent malicious code and unauthorised access.
6. Logging and monitoring
a. logging of appropriate administrative and security events;
b. monitoring for suspicious activity;
c. alerting and investigation procedures; and
d. retention of relevant security logs according to documented requirements.
7. Availability and resilience
a. backup procedures;
b. redundancy and resilience measures appropriate to the Services;
c. recovery and restoration procedures;
d. incident-response planning; and
e. periodic review of business-continuity arrangements.
8. Data separation and minimisation
a. logical separation of customer data or environments where appropriate;
b. processing limited to data necessary to provide the relevant Service;
c. restricted access to production data; and
d. deletion or anonymisation procedures.
9. Incident management
a. documented incident-response procedures;
b. escalation and investigation processes;
c. containment and remediation procedures;
d. breach-notification procedures; and
e. post-incident review where appropriate.
10. Supplier management
a. due diligence before appointing relevant Subprocessors;
b. written data protection and confidentiality obligations;
c. review of relevant supplier security measures; and
d. ongoing oversight proportionate to the processing risk.