Legal

Subprocessor List

Last updated and effective 7 July 2026.

Last updated: 7 July 2026
Effective date: 7 July 2026

This Subprocessor List identifies the third-party service providers that may process Personal Data on behalf of yaava in connection with the provision of the yaava AI-powered virtual try-on Service.

1. yaava Operator

The yaava Service is operated by:

Ievgenii Solovei
Sole proprietor registered in Poland
ul. Piłsudskiego 91/1
50-019 Wrocław
Poland
NIP/VAT number: 8982302556
Email: legal@yaava.eu
Website: https://yaava.eu

For the purposes of this Subprocessor List, “yaava”, “we”, “us”, and “our” refer to Ievgenii Solovei operating the yaava platform.

2. Meaning of Subprocessor

A “Subprocessor” is a third party appointed by yaava to process Personal Data on behalf of a Merchant where:

  • the Merchant acts as Controller;
  • yaava acts as Processor; and
  • the third party processes Personal Data to assist yaava in providing the Service.

This list does not necessarily include third parties that process Personal Data as independent Controllers, including e-commerce platforms, payment providers, tax authorities, banks, and professional advisers.

3. Current Subprocessors

SubprocessorRegistered locationService and purposePersonal Data processedData subjectsProcessing locationTransfer safeguard
Features & Labels Inc. — fal.aiUnited StatesAI infrastructure, image processing, and generation of virtual try-on resultsShopper Photos, Merchant product images, generated Shopper Outputs, temporary request identifiers, generation parameters, and limited technical metadataShoppers and, in limited cases, Merchant usersUnited States and other locations used by the provider or its infrastructure providersEuropean Commission Standard Contractual Clauses or another lawful transfer mechanism, where required

3.1 fal.ai processing

yaava uses fal.ai to perform AI-powered virtual try-on image processing.

For a standard virtual try-on request, yaava may transmit:

  • the Shopper Photo;
  • the selected Merchant product image;
  • generation parameters;
  • a temporary request or session identifier;
  • technical information required to perform the generation.

yaava does not intentionally transmit to fal.ai for a standard generation:

  • the Shopper’s name;
  • email address;
  • telephone number;
  • billing address;
  • shipping address;
  • payment card data;
  • Shopify customer account credentials.

Shopper Photos and Shopper Outputs are configured to be retained for no longer than 7 days, subject to the technical operation of the relevant infrastructure and any shorter retention settings applied by yaava.

yaava uses fal.ai only for the purpose of providing the requested AI generation functionality.

yaava does not authorize fal.ai to use Shopper Photos, Shopper Outputs, or Merchant product images to train or fine-tune AI models.

yaava will not knowingly use an AI model that is excluded from fal.ai’s enterprise-ready, no-training, data protection, or DPA protections for processing Shopper Photos.

4. Underlying AI Model Providers

fal.ai may provide access to:

  • models operated directly on fal.ai infrastructure; and
  • third-party AI models accessed through an external model provider’s API.

Where a selected model transfers Personal Data to a separate third-party model provider, yaava will:

  • assess the provider before enabling the model;
  • ensure that an appropriate data processing arrangement applies;
  • confirm that the provider does not use Shopper Photos or Shopper Outputs for AI training;
  • apply appropriate international transfer safeguards;
  • add the provider to this Subprocessor List before using it to process Shopper Personal Data.

yaava will not use a third-party model provider for Shopper Photos without the protections required by the yaava Data Processing Agreement and applicable data protection law.

5. Infrastructure Subprocessors

The following table must be completed with the actual production providers used by yaava before this document is published.

CategorySubprocessorPurposePersonal Data potentially processedPrimary processing location
Application hosting[HOSTING PROVIDER]Hosting the yaava backend, merchant portal, APIs, and application servicesMerchant account data, Shopify store identifiers, technical logs, session data, usage records[LOCATION]
Database hosting[DATABASE PROVIDER]Storage of Merchant accounts, plans, Credits, configuration, consent records, and analytics dataMerchant account data, pseudonymous Shopper identifiers, usage records, analytics events[LOCATION]
Object storage[STORAGE PROVIDER]Temporary encrypted storage of Shopper Photos and Shopper OutputsShopper Photos, Shopper Outputs, product images, object metadata[LOCATION]
CDN and network security[CDN / SECURITY PROVIDER]Content delivery, DNS, DDoS protection, firewall, and network securityIP addresses, request metadata, device and browser information, security logs[LOCATION]
Error monitoring[MONITORING PROVIDER]Application error detection and technical troubleshootingError messages, IP address where enabled, account or request identifier, device and application metadata[LOCATION]
Product analytics[ANALYTICS PROVIDER]Measurement of Merchant dashboard and widget usagePseudonymous identifiers, interaction events, device data, conversion events[LOCATION]
Transactional email[EMAIL PROVIDER]Account notifications, security notifications, and support-related emailsMerchant name, business email address, message metadata, delivery information[LOCATION]
Customer support[SUPPORT PROVIDER, IF ANY]Receiving and managing Merchant support requestsMerchant contact details, support messages, attachments voluntarily submitted by the Merchant[LOCATION]

Shopper Photos and Shopper Outputs must not be intentionally transmitted to analytics, email, customer support, or error-monitoring providers.

6. Parties That Are Generally Not yaava Subprocessors

The following providers may receive or process information in connection with the Service but are generally not appointed by yaava as subprocessors for Shopper Photos.

6.1 Shopify

Shopify provides the e-commerce platform through which the Merchant operates its store and installs the yaava application.

Depending on the processing activity, Shopify may act as:

  • an independent Controller;
  • a processor for the Merchant;
  • a platform provider under its direct agreement with the Merchant.

Shopify may process:

  • Merchant account information;
  • Shopify store information;
  • product information;
  • customer and order information;
  • app installation information;
  • billing information;
  • technical and security data.

Shopify’s processing is governed by the applicable agreements and privacy terms between Shopify and the Merchant.

6.2 Paddle

Where used, Paddle may provide:

  • payment processing;
  • subscription billing;
  • invoicing;
  • tax calculation and collection;
  • fraud prevention;
  • chargeback management;
  • Merchant of Record services.

For Merchant of Record, checkout, payment, invoicing, tax, and fraud-prevention activities, Paddle generally processes relevant information under its own legal obligations and privacy terms.

Paddle may process:

  • Merchant contact details;
  • billing details;
  • transaction information;
  • invoice information;
  • tax information;
  • payment status;
  • payment method information.

yaava does not provide Shopper Photos or Shopper Outputs to Paddle.

6.3 Professional advisers and authorities

Lawyers, accountants, insurers, auditors, banks, tax authorities, courts, and regulatory authorities are not treated as subprocessors where they process Personal Data as independent Controllers or under their own legal obligations.

7. Subprocessor Requirements

Before appointing a Subprocessor, yaava will take reasonable steps to assess whether the Subprocessor provides appropriate privacy and security protections.

yaava requires its Subprocessors, as applicable, to:

  • process Personal Data only for the agreed purposes;
  • comply with documented instructions;
  • maintain appropriate confidentiality obligations;
  • implement appropriate technical and organizational security measures;
  • notify yaava of relevant Personal Data breaches without undue delay;
  • assist with data subject requests where required;
  • delete or return Personal Data at the end of the applicable service;
  • comply with applicable international transfer requirements;
  • impose appropriate data protection obligations on any further subprocessors.

yaava remains responsible for the performance of its Subprocessors to the extent required by applicable law and the yaava Data Processing Agreement.

8. International Data Transfers

Some Subprocessors may process Personal Data outside Poland or the European Economic Area.

Where Personal Data is transferred to a country that is not covered by an applicable European Commission adequacy decision, yaava will use an appropriate safeguard where required, including:

  • European Commission Standard Contractual Clauses;
  • contractual supplementary measures;
  • encryption;
  • access restrictions;
  • data minimization;
  • another lawful transfer mechanism.

Further information about international transfers may be requested by contacting legal@yaava.eu.

9. Changes to the Subprocessor List

yaava may appoint, replace, or remove Subprocessors where necessary to provide, secure, maintain, or improve the Service.

Where required by the applicable Data Processing Agreement, yaava will provide Merchants with prior notice of a new material Subprocessor.

The notice may be provided:

  • by email;
  • through the yaava dashboard;
  • through the Shopify application;
  • by updating this page;
  • through another reasonable electronic method.

Unless a different period is stated in the applicable Data Processing Agreement, yaava will provide at least 14 days’ notice before a new material Subprocessor begins processing Personal Data.

10. Merchant Objections

A Merchant may object to the appointment of a new Subprocessor where the Merchant has reasonable and documented data protection concerns.

The objection must:

  • be submitted within 14 days after the relevant notice;
  • identify the relevant Subprocessor;
  • explain the specific data protection concern;
  • be sent to legal@yaava.eu.

yaava and the Merchant will attempt in good faith to identify a commercially reasonable solution.

A reasonable solution may include:

  • applying additional safeguards;
  • limiting the relevant processing;
  • using an alternative provider;
  • disabling an affected optional feature;
  • terminating the affected part of the Service where no reasonable alternative is available.

An objection may not be based solely on commercial preference or general disagreement with the use of third-party service providers.

11. Updates and Version History

The “Last updated” date at the top of this document indicates when the Subprocessor List was most recently revised.

yaava may maintain a version history containing:

  • the name of the added or removed Subprocessor;
  • the purpose of the change;
  • the effective date;
  • the categories of Personal Data affected.

12. Contact

Questions about yaava’s Subprocessors may be submitted to:

yaava

Operator: Ievgenii Solovei
Address: ul. Piłsudskiego 91/1, 50-019 Wrocław, Poland
NIP/VAT number: 8982302556
Email: legal@yaava.eu
Website: https://yaava.eu