Data Processing Agreement
The terms under which Faden processes your customers' personal information on your behalf — the companion to our Privacy Policy for the businesses that use us.
Effective 14 July 2026
When you use Faden, your customers' personal information stays yours — we only ever handle it to run the Service for you. This DPA sets out that relationship in the terms your own compliance team, or your customers, will expect: our obligations as your processor, our security measures, our sub-processors, and what happens to the data when you leave.
01Scope & roles
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between you (the "Studio", "Controller") and Faden ("Faden", "Processor"). It applies where and to the extent Faden processes Personal Data contained in your Client Data on your behalf in providing the Service.
As between the parties, you are the controller of the Personal Data in your Client Data and Faden is your processor. You determine the purposes and means of processing; Faden processes only on your documented instructions, which are given through your configuration and use of the Service and this DPA. If Faden must process for another reason under a law that applies to it, it will inform you unless that law prohibits it.
This DPA is offered as part of the standard Terms. If your organisation requires a signed copy or a data-protection addendum for your records, email privacy@faden.tech.
02Definitions
"Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the Privacy Act 1988 (Cth) and, where it applies to your use, the EU/UK General Data Protection Regulation ("GDPR"). "Applicable Data Protection Law" means the privacy and data-protection laws that apply to your processing of Personal Data through the Service.
03Details of processing (Annex A)
Subject matter & duration
Provision of the Service under the Terms, for the duration of your subscription plus any post-termination export and deletion period.
Nature & purpose
Hosting, storage, organisation, retrieval, transmission and related processing of Client Data so that you can run your tailoring business — managing clients, measurements, orders, fittings, production, communications and payment records.
Categories of data subjects
Your customers and prospects, and any individuals whose details you enter (for example contacts at your suppliers).
Types of Personal Data
- Identity & contact: name, email, phone, postal address.
- Physical: body measurements and fit information.
- Commercial: orders, quotes, invoices, payments, refunds and preferences.
- Communications: messages you send to or receive from customers via the Service.
You must not enter special-category or sensitive information beyond what the Service is designed for (for example, health, biometric-identification, or government-identifier data) unless it is necessary and lawful for your business and you have the required consents.
04Faden's obligations as processor
Faden will:
- Process Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by a law that applies to it.
- Ensure personnel authorised to process Personal Data are bound by confidentiality and access it on a least-privilege, need-to-know basis.
- Implement and maintain the technical and organisational security measures described in Annex B.
- Taking into account the nature of processing, assist you by appropriate measures to respond to data-subject requests, and to meet your obligations around security, breach notification and data-protection impact assessments.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
- On termination, return or delete Client Data as set out below.
05Security measures (Annex B)
Faden maintains a layered security program, including:
- Encryption of data in transit (TLS) and at rest, with sensitive fields (customer contact details, notes and body measurements) encrypted at field level using AES-256-GCM bound to the owning account.
- Strict multi-tenant isolation enforced at the database level, so one Studio can never access another's data.
- Blind-indexed lookups so records can be matched without exposing the underlying Personal Data.
- Authentication and access controls: hashed credentials, optional/enforceable multi-factor authentication, single sign-on, session management, IP allow-listing and rate limiting.
- A tamper-evident audit log of sensitive actions, least-privilege internal access, and regular review.
- Encrypted backups and documented restoration procedures.
Faden may update these measures over time provided the level of protection is not materially reduced.
06Sub-processing
You provide a general authorisation for Faden to engage sub-processors to help provide the Service. The current sub-processors are listed at faden.tech/legal/subprocessors.
- Faden imposes data-protection obligations on each sub-processor that are materially no less protective than those in this DPA.
- Faden remains responsible to you for a sub-processor's performance of those obligations.
- Faden will give notice (via the sub-processor page and, where appropriate, by email) before adding or replacing a sub-processor, so you have the opportunity to object on reasonable data-protection grounds. If you object and the matter cannot be resolved, your remedy is to stop using the affected feature or to terminate the affected part of the Service.
07International transfers
Client Data is stored on infrastructure located in Australia. Some sub-processors operate globally and may process limited Personal Data outside Australia when you use the relevant feature.
Where an international transfer is subject to the GDPR, the parties will rely on an appropriate transfer mechanism (such as the European Commission's Standard Contractual Clauses, and the UK Addendum where relevant), which are incorporated by reference to the extent required. Where the Privacy Act applies, Faden takes reasonable steps to ensure overseas recipients handle the Personal Data consistently with the Australian Privacy Principles.
08Data-subject requests
The Service provides you with tools to access, correct, export and erase individual customer records, and to manage consent. Taking into account the nature of the processing, Faden will assist you in responding to data-subject requests, including where you cannot address a request through those tools. If Faden receives a request directly from your customer, it will not respond except on your instruction, and will refer the individual to you unless legally required to act.
09Personal data breach
Faden will notify you without undue delay after becoming aware of a personal data breach affecting your Client Data, and will provide the information reasonably available to help you meet your own notification obligations (including under the Notifiable Data Breaches scheme or the GDPR). Faden will take reasonable steps to mitigate the breach and cooperate with you. A notification is not an acknowledgement of fault.
10Audit & information
On reasonable written request, and no more than once per year unless required by a regulator or following a breach, Faden will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be conducted on reasonable notice, during business hours, subject to confidentiality, and in a way that does not compromise other customers' data or the security of the Service; Faden may satisfy audit requests by providing existing documentation or third-party reports.
11Return & deletion
On termination or expiry of the Service, you may export your Client Data using the Service's export tools for a reasonable period. After that period, Faden will delete or de-identify Client Data in its live systems, and purge it from backups in the ordinary backup cycle, except where retention is required by a law that applies to Faden — in which case the data remains protected by this DPA for as long as it is retained.
12Liability & general
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA is governed by the same law as the Terms (Queensland, Australia). If there is any conflict between this DPA and the Terms on the processing of Personal Data, this DPA prevails to the extent of the conflict.
For a signed copy or a bespoke addendum, email privacy@faden.tech. Questions? Email support@faden.tech.
This document is provided for transparency and is not legal advice. Your use of Faden is governed by the version in force at the time.