Last updated: August 2026
This Data Processing Agreement (DPA) applies to Shopify merchants, kiosk store owners, and API customers using Corlen. It describes how we process personal data on your behalf when your customers use Corlen's try-on features through your store or your integration. Where data protection law (such as the GDPR) applies, you act as the data controller for your customers' data, and Corlen acts as your data processor.
Corlen processes personal data solely to provide the virtual try-on service described in your active subscription or API plan, for as long as that plan remains active, and for the limited retention period described below afterward.
Corlen receives a photo submitted by an end shopper and a garment image from your catalog, and generates an image showing the shopper wearing that garment. That single purpose, generating a try-on preview, is the only reason customer photos are processed.
The personal data involved is limited to: photos submitted by end shoppers for the purpose of generating a preview, and, where a shopper chooses to leave one, an email address for follow-up or receiving their result. The data subjects are the end shoppers who use the try-on feature on your store or kiosk. We do not process special category or biometric data; we never run face recognition or facial analysis on any photo.
We use the following sub-processors to operate Corlen. We will update this list if it changes.
We apply the following measures to protect the data we process on your behalf:
If an end shopper contacts you to exercise a data protection right (such as requesting deletion of a photo or email they left with your store), we will assist you in fulfilling that request. You can also have us act on such a request directly by contacting privacy@corlen.io with enough detail to locate the data (store name and approximate date is usually enough).
Our sub-processors operate infrastructure in multiple regions. Where personal data is transferred outside the country it originated in, we rely on the safeguards those providers make available (such as standard contractual clauses) to ensure an equivalent level of protection.
If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay after becoming aware of it, with the information available to us at the time.
This DPA remains in effect for as long as you have an active Corlen account, and applies to any personal data processed under it even after your account is closed, until that data is deleted per our retention practices.
Questions about this Data Processing Agreement can be sent to privacy@corlen.io.