WONOM Showroom

Data processing agreement

Updated 17 September 2026 · Eesti keeles

This agreement describes how WONOM processes shoppers' personal data on a store's behalf when the store uses WONOM Showroom on its website. It is part of the terms of service.

1. Parties and roles

The store is the controller and Wonom Digital OÜ (registry code 17580154) is the processor within the meaning of Article 28 of the General Data Protection Regulation (EU) 2016/679. Where this agreement and the terms of service conflict on data protection, this agreement prevails.

2. Description of the processing

ItemDescription
Subject matter and durationThe try-on button service on the store's website, for as long as the terms of service apply.
Nature and purposeChecking the shopper's photo, making the look and video, applying per-shopper and store limits, and counting the store's figures and orders of tried-on products.
Data subjectsVisitors to the store's website who use the try-on button.
Categories of dataThe shopper's photo (face and body), the images and videos made, the IP address and a tag derived from it, product and page addresses, order value and hash, and what is stored on the shopper's device as described in the privacy policy.
Special categoriesThe service is not meant to process special categories of data and does not identify people biometrically. A photo may still show sensitive information, for example about health or religion.

3. The store's instructions

The store's documented instructions are the terms of service, this agreement and the store's settings in the dashboard and in the WordPress plugin. We process data only according to them, unless the law requires otherwise; we tell the store when the law does not forbid it. If we think an instruction breaks the law, we say so.

4. Confidentiality

Only people who need the data to provide the service, and who are bound by confidentiality, can access it.

5. Security measures

  • Data travels encrypted (TLS).
  • The shopper's photo is never written to disk or a database. The look is with us only during the request.
  • A finished video sits at an address with a 128-bit random name, is deleted within the hour even when no requests come in, and is never cached or indexed.
  • For per-shopper limits we keep a keyed hash instead of the IP address. The full IP address is only in the server's memory for the one-minute brake, and shortened in logs.
  • The widget's session token is signed and lasts 30 minutes. Passwords are hashed (scrypt); sessions and reset links are stored as hashes.
  • The store's server key stays on the store's server. The widget loads only our own scripts and fonts and has a strict content security policy (CSP).
  • Access to a store's data is checked on every request. Sign-up, login and fittings have abuse limits.
  • At our subprocessors: Google does not use requests for training and keeps them for up to 55 days only to detect misuse. fal.ai is told not to store the request and to expire the video within an hour.

6. Subprocessors

The store gives general authorisation for the subprocessors named on the subprocessors page. We give notice of a new subprocessor by e-mail at least 30 days in advance. If the store objects, it may end the agreement before the change takes effect. Our contracts with subprocessors give the same protection, and we are responsible for them as for ourselves.

7. Transfers outside the European Economic Area

Where a subprocessor processes data outside the European Economic Area, we rely on the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, as noted on the subprocessors page.

8. Help with data subject rights and impact assessments

We help the store answer shoppers' requests within a reasonable time, and give the information the store needs for a data protection impact assessment and for dealing with the supervisory authority. Since the photo and look do not stay with us and visitor tags expire within 36 hours, there is usually nothing to hand over or delete. The shopper can delete what is kept on the device with the widget's “Forget my photo” button.

9. Personal data breaches

We tell the store about a breach without undue delay, and no later than 48 hours after becoming aware of it, with the facts known, so that the store can meet its own 72-hour notification duty.

10. End of the agreement

When the store closes its account, we delete the store's and its shoppers' data from our database without delay. Videos expire within the hour. Invoices are kept for as long as the law requires. Our hosting providers' short-lived logs expire under their own terms.

11. Audits

We make available the information that shows this agreement is being met. The store may audit once a year, with at least 30 days' written notice, at its own cost, and in a way that does not put other customers' data at risk.

12. Liability

Liability is limited as in section 9 of the terms of service, unless the law requires otherwise.