Legal
Subprocessor List
Last updated and effective 7 July 2026.
Last updated: 7 July 2026
Effective date: 7 July 2026
This Subprocessor List identifies the third-party service providers that may process Personal Data on behalf of yaava in connection with the provision of the yaava AI-powered virtual try-on Service.
1. yaava Operator
The yaava Service is operated by:
Ievgenii Solovei
Sole proprietor registered in Poland
ul. Piłsudskiego 91/1
50-019 Wrocław
Poland
NIP/VAT number: 8982302556
Email: legal@yaava.eu
Website: https://yaava.eu
For the purposes of this Subprocessor List, “yaava”, “we”, “us”, and “our” refer to Ievgenii Solovei operating the yaava platform.
2. Meaning of Subprocessor
A “Subprocessor” is a third party appointed by yaava to process Personal Data on behalf of a Merchant where:
- the Merchant acts as Controller;
- yaava acts as Processor; and
- the third party processes Personal Data to assist yaava in providing the Service.
This list does not necessarily include third parties that process Personal Data as independent Controllers, including e-commerce platforms, payment providers, tax authorities, banks, and professional advisers.
3. Current Subprocessors
| Subprocessor | Registered location | Service and purpose | Personal Data processed | Data subjects | Processing location | Transfer safeguard |
|---|---|---|---|---|---|---|
| Features & Labels Inc. — fal.ai | United States | AI infrastructure, image processing, and generation of virtual try-on results | Shopper Photos, Merchant product images, generated Shopper Outputs, temporary request identifiers, generation parameters, and limited technical metadata | Shoppers and, in limited cases, Merchant users | United States and other locations used by the provider or its infrastructure providers | European Commission Standard Contractual Clauses or another lawful transfer mechanism, where required |
3.1 fal.ai processing
yaava uses fal.ai to perform AI-powered virtual try-on image processing.
For a standard virtual try-on request, yaava may transmit:
- the Shopper Photo;
- the selected Merchant product image;
- generation parameters;
- a temporary request or session identifier;
- technical information required to perform the generation.
yaava does not intentionally transmit to fal.ai for a standard generation:
- the Shopper’s name;
- email address;
- telephone number;
- billing address;
- shipping address;
- payment card data;
- Shopify customer account credentials.
Shopper Photos and Shopper Outputs are configured to be retained for no longer than 7 days, subject to the technical operation of the relevant infrastructure and any shorter retention settings applied by yaava.
yaava uses fal.ai only for the purpose of providing the requested AI generation functionality.
yaava does not authorize fal.ai to use Shopper Photos, Shopper Outputs, or Merchant product images to train or fine-tune AI models.
yaava will not knowingly use an AI model that is excluded from fal.ai’s enterprise-ready, no-training, data protection, or DPA protections for processing Shopper Photos.
4. Underlying AI Model Providers
fal.ai may provide access to:
- models operated directly on fal.ai infrastructure; and
- third-party AI models accessed through an external model provider’s API.
Where a selected model transfers Personal Data to a separate third-party model provider, yaava will:
- assess the provider before enabling the model;
- ensure that an appropriate data processing arrangement applies;
- confirm that the provider does not use Shopper Photos or Shopper Outputs for AI training;
- apply appropriate international transfer safeguards;
- add the provider to this Subprocessor List before using it to process Shopper Personal Data.
yaava will not use a third-party model provider for Shopper Photos without the protections required by the yaava Data Processing Agreement and applicable data protection law.
5. Infrastructure Subprocessors
The following table must be completed with the actual production providers used by yaava before this document is published.
| Category | Subprocessor | Purpose | Personal Data potentially processed | Primary processing location |
|---|---|---|---|---|
| Application hosting | [HOSTING PROVIDER] | Hosting the yaava backend, merchant portal, APIs, and application services | Merchant account data, Shopify store identifiers, technical logs, session data, usage records | [LOCATION] |
| Database hosting | [DATABASE PROVIDER] | Storage of Merchant accounts, plans, Credits, configuration, consent records, and analytics data | Merchant account data, pseudonymous Shopper identifiers, usage records, analytics events | [LOCATION] |
| Object storage | [STORAGE PROVIDER] | Temporary encrypted storage of Shopper Photos and Shopper Outputs | Shopper Photos, Shopper Outputs, product images, object metadata | [LOCATION] |
| CDN and network security | [CDN / SECURITY PROVIDER] | Content delivery, DNS, DDoS protection, firewall, and network security | IP addresses, request metadata, device and browser information, security logs | [LOCATION] |
| Error monitoring | [MONITORING PROVIDER] | Application error detection and technical troubleshooting | Error messages, IP address where enabled, account or request identifier, device and application metadata | [LOCATION] |
| Product analytics | [ANALYTICS PROVIDER] | Measurement of Merchant dashboard and widget usage | Pseudonymous identifiers, interaction events, device data, conversion events | [LOCATION] |
| Transactional email | [EMAIL PROVIDER] | Account notifications, security notifications, and support-related emails | Merchant name, business email address, message metadata, delivery information | [LOCATION] |
| Customer support | [SUPPORT PROVIDER, IF ANY] | Receiving and managing Merchant support requests | Merchant contact details, support messages, attachments voluntarily submitted by the Merchant | [LOCATION] |
Shopper Photos and Shopper Outputs must not be intentionally transmitted to analytics, email, customer support, or error-monitoring providers.
6. Parties That Are Generally Not yaava Subprocessors
The following providers may receive or process information in connection with the Service but are generally not appointed by yaava as subprocessors for Shopper Photos.
6.1 Shopify
Shopify provides the e-commerce platform through which the Merchant operates its store and installs the yaava application.
Depending on the processing activity, Shopify may act as:
- an independent Controller;
- a processor for the Merchant;
- a platform provider under its direct agreement with the Merchant.
Shopify may process:
- Merchant account information;
- Shopify store information;
- product information;
- customer and order information;
- app installation information;
- billing information;
- technical and security data.
Shopify’s processing is governed by the applicable agreements and privacy terms between Shopify and the Merchant.
6.2 Paddle
Where used, Paddle may provide:
- payment processing;
- subscription billing;
- invoicing;
- tax calculation and collection;
- fraud prevention;
- chargeback management;
- Merchant of Record services.
For Merchant of Record, checkout, payment, invoicing, tax, and fraud-prevention activities, Paddle generally processes relevant information under its own legal obligations and privacy terms.
Paddle may process:
- Merchant contact details;
- billing details;
- transaction information;
- invoice information;
- tax information;
- payment status;
- payment method information.
yaava does not provide Shopper Photos or Shopper Outputs to Paddle.
6.3 Professional advisers and authorities
Lawyers, accountants, insurers, auditors, banks, tax authorities, courts, and regulatory authorities are not treated as subprocessors where they process Personal Data as independent Controllers or under their own legal obligations.
7. Subprocessor Requirements
Before appointing a Subprocessor, yaava will take reasonable steps to assess whether the Subprocessor provides appropriate privacy and security protections.
yaava requires its Subprocessors, as applicable, to:
- process Personal Data only for the agreed purposes;
- comply with documented instructions;
- maintain appropriate confidentiality obligations;
- implement appropriate technical and organizational security measures;
- notify yaava of relevant Personal Data breaches without undue delay;
- assist with data subject requests where required;
- delete or return Personal Data at the end of the applicable service;
- comply with applicable international transfer requirements;
- impose appropriate data protection obligations on any further subprocessors.
yaava remains responsible for the performance of its Subprocessors to the extent required by applicable law and the yaava Data Processing Agreement.
8. International Data Transfers
Some Subprocessors may process Personal Data outside Poland or the European Economic Area.
Where Personal Data is transferred to a country that is not covered by an applicable European Commission adequacy decision, yaava will use an appropriate safeguard where required, including:
- European Commission Standard Contractual Clauses;
- contractual supplementary measures;
- encryption;
- access restrictions;
- data minimization;
- another lawful transfer mechanism.
Further information about international transfers may be requested by contacting legal@yaava.eu.
9. Changes to the Subprocessor List
yaava may appoint, replace, or remove Subprocessors where necessary to provide, secure, maintain, or improve the Service.
Where required by the applicable Data Processing Agreement, yaava will provide Merchants with prior notice of a new material Subprocessor.
The notice may be provided:
- by email;
- through the yaava dashboard;
- through the Shopify application;
- by updating this page;
- through another reasonable electronic method.
Unless a different period is stated in the applicable Data Processing Agreement, yaava will provide at least 14 days’ notice before a new material Subprocessor begins processing Personal Data.
10. Merchant Objections
A Merchant may object to the appointment of a new Subprocessor where the Merchant has reasonable and documented data protection concerns.
The objection must:
- be submitted within 14 days after the relevant notice;
- identify the relevant Subprocessor;
- explain the specific data protection concern;
- be sent to legal@yaava.eu.
yaava and the Merchant will attempt in good faith to identify a commercially reasonable solution.
A reasonable solution may include:
- applying additional safeguards;
- limiting the relevant processing;
- using an alternative provider;
- disabling an affected optional feature;
- terminating the affected part of the Service where no reasonable alternative is available.
An objection may not be based solely on commercial preference or general disagreement with the use of third-party service providers.
11. Updates and Version History
The “Last updated” date at the top of this document indicates when the Subprocessor List was most recently revised.
yaava may maintain a version history containing:
- the name of the added or removed Subprocessor;
- the purpose of the change;
- the effective date;
- the categories of Personal Data affected.
12. Contact
Questions about yaava’s Subprocessors may be submitted to:
yaava
Operator: Ievgenii Solovei
Address: ul. Piłsudskiego 91/1, 50-019 Wrocław, Poland
NIP/VAT number: 8982302556
Email: legal@yaava.eu
Website: https://yaava.eu