Privacy Policy for End Users FITIT
Last updated: 07/08/2026
This Privacy Policy governs the processing of personal data carried out by FITIT SAS with respect to End Users who access, view, interact with or use FITIT technological functionalities, including Size Recommendation, Try On, Catalog and any other functionality that FITIT makes available in digital environments of merchants, e-commerce websites, marketplaces or third-party integrators.
FIRST. Identification of the Controller.
1.1. The controller of the personal data processed through the use of the FITIT functionality is FITIT SAS, Tax ID No. 219354370018, with registered address at Solano García 2408, Montevideo, Oriental Republic of Uruguay.
1.2. For general inquiries related to FITIT or the exercise of rights relating to personal data, the End User may contact: legal@fitit.ai
SECOND. Scope of this Policy.
2.1. This Policy applies to the processing of personal data of End Users who access, view, interact with or use FITIT technological functionalities, including Size Recommendation, Try On, Catalog or other available functionalities, from websites, online stores, e-commerce platforms, marketplaces, mobile applications or other digital environments operated by third parties.
2.2. The FITIT functionality may be integrated, embedded, displayed or made available within the digital environment of an e-commerce website, merchant, marketplace or third-party integrator, through an add-in, widget, embedded module, API, script, connector, interface, button, window, functional flow or any other equivalent technical mechanism.
2.3. This Policy governs only the processing of personal data carried out by FITIT in connection with the access, display, interaction and use of FITIT technological functionalities, including Size Recommendation, Try On, Catalog or other functionalities that FITIT makes available to the End User.
2.4. This Policy does not govern the purchase and sale of products, prices, promotions, discounts, availability, stock, payments, billing, shipping, deliveries, exchanges, returns, cancellations, warranties, commercial support, consumer relationship or any other matters belonging to the e-commerce website, merchant, marketplace or third-party integrator.
2.5. The processing of personal data carried out by the e-commerce website, merchant, marketplace or third-party integrator shall be governed by its own terms and conditions, privacy policies, cookie policies, legal notices, consents, legal bases and preference mechanisms.
THIRD. Direct Relationship between FITIT and the End User.
3.1. By accessing, viewing, interacting with or using a FITIT functionality in any manner, the End User maintains a direct relationship with FITIT regarding the access and use of such technological functionality.
3.2. The direct relationship between FITIT and the End User is limited to the access and use of the FITIT functionalities and to the processing of personal data carried out by FITIT within that framework.
FOURTH. Personal Data Processed.
4.1. FITIT may process the personal data that the End User enters, provides, selects, confirms or makes available when using the FITIT functionality.
4.2. The processed data may include, among others:
a. usual size;
b. information, images or measurements related to reference garments that the End User uploads, enters, provides or authorizes to be used in FITIT;
c. measurements, attributes, size chart or information of the consulted product;
d. technical references linked to reference objects used to estimate scale or measurements, when the functionality so requires;
e. fit, adjustment, comfort or style preferences;
f. size equivalences;
g. answers, selections or preferences entered during the recommendation flow;
h. body measurements, height, weight, build or proportions, only when a specific functionality requests them or the End User provides them voluntarily;
i. photographs, images or visual content of the End User that are uploaded, provided, authorized or generated through a FITIT functionality, when such functionality so requires;
j. images, visualizations, simulations, compositions or results generated by FITIT functionalities, including results generated through Try On or other available visual functionalities.
4.3. FITIT may process registration, authentication, technical and interaction data associated with the use of the functionality, including:
a. name, email address, phone number, user identifier, basic profile data and any other information necessary for the registration, authentication or login of the End User, including information provided by Google or other external authentication providers when the End User uses such mechanisms;
b. IP address;
c. technical identifiers;
d. session or device identifiers;
e. browser, operating system, language, inferred country or region;
f. date and time of access;
g. source website or digital channel;
h. consulted product;
i. interaction events;
j. technical logs;
k. errors, loading times and operating records.
4.4. When the End User accesses, registers or logs in to FITIT through Google or another external authentication provider, FITIT may use the authentication data and technical identifiers associated with such login, including session identifiers, device identifiers, tokens, cookies, local storage, session storage or other similar technologies, to keep the session active, remember previous interactions, recognize future interactions from the same device, browser or technical environment, and allow the FITIT functionalities to operate automatically in future visits or interactions of the End User. Such recognition may depend on the operation of the authentication provider, the current technical session, the browser, device or technical environment used, and shall not necessarily imply a proprietary and independent identification mechanism developed by FITIT.
4.5. FITIT may receive, access, integrate, associate, link or correlate technical data, browsing data, interaction data, technical identifiers, session or device identifiers, information regarding viewed or consulted products, e-commerce events, conversion events, purchases, carts, actions performed within the Digital Environment of the Integrating Merchant or other equivalent data, when such data is provided, enabled, integrated or made available to FITIT by the Integrating Merchant, its systems, its analytics tools, its e-commerce platforms or authorized third parties. FITIT may process such data to operate the integration, contextualize the functionality used, associate the End User’s interaction with products, sessions or e-commerce events, measure performance, attribute interactions, generate metrics, improve service accuracy, resolve technical incidents, prevent misuse, audit operation, generate technical or commercial reports and develop improvements to the FITIT functionalities.
4.6. When a FITIT functionality allows the End User to upload, enter, provide or authorize the use of images, photographs, visual content or other materials, FITIT may process such content to the extent necessary to provide the requested functionality, generate visualizations, simulations, recommendations or indicative results, improve the user experience, maintain service security, resolve technical incidents and comply with the other purposes informed in this Policy.
When the End User uploads, enters, provides or authorizes the use of images, photographs or visual content of third parties, including minors where applicable, the End User represents that they have sufficient rights, authorizations, consents, legal representation, parental responsibility or other lawful standing to do so in accordance with the applicable regulations.
4.7. FITIT shall not use such images, photographs or visual content to biometrically identify the End User, diagnose medical conditions or assess health status, unless a future functionality expressly informs a different purpose and obtains the corresponding consent in accordance with the applicable regulations.
4.8. When a FITIT functionality allows the use of a card, document, reference object or other similar element to estimate scale or measurements, FITIT shall use such element solely as a technical reference to provide the corresponding functionality. For such purpose, FITIT may transiently process the image to the extent necessary to detect the reference object, estimate scale or measurements and apply the corresponding technical measures. FITIT shall not use the information contained in documents, cards or reference objects for purposes of identifying the End User. When such elements appear in images or photographs processed by FITIT, FITIT shall apply reasonable measures to hide, blur, block, remove or render illegible the visible information contained in such elements, so that such information is not persistently retained by FITIT in legible format as identification data, except for strictly necessary transient technical retention for the processing of the functionality.
4.9. When a FITIT functionality allows the End User to download, export, share or make available images, visualizations, simulations, compositions or results generated by FITIT, including Try On results, such images or results may be accessible by the persons, platforms, applications or services with which the End User decides to share them, as well as by those who receive the corresponding file or link. FITIT does not control the processing, use, retention, forwarding or subsequent dissemination that third parties or external platforms may carry out with respect to such content once it has been shared by decision of the End User.
4.10. When a FITIT functionality allows images to be captured, uploaded or transferred through linked devices, QR codes, temporary links, technical sessions or other equivalent mechanisms, FITIT may process and transmit such images, technical identifiers and session data between the devices, servers, infrastructure or services necessary to enable the capture, transfer and use of the image within the corresponding functionality.
SIXTH. Purposes of Processing.
6.1. FITIT may process personal data to provide FITIT technological functionalities, including Size Recommendation, Try On, Catalog or other available functionalities, allow the End User to interact with the tool and generate recommendations, suggestions, equivalences, measurements, visualizations, simulations, compositions or indicative results.
6.2. FITIT may process personal data directly or with the support of providers, technology partners or third parties necessary to provide, operate, maintain, protect or improve the FITIT functionalities. When such third parties process personal data for their own purposes, independent commercial purposes or purposes not necessary for the provision of the functionality requested by the End User, FITIT shall obtain the specific consent that corresponds in accordance with the applicable regulations.
6.3. FITIT may process personal data, technical data, usage data, browsing events, interaction events, e-commerce events, recommendation results, technical identifiers, session or device identifiers, acceptance records, logs, product information, session data, purchase, conversion or behavior events within the Digital Environment of the Integrating Merchant, to the extent that they are processed by FITIT, generated through the FITIT functionalities or received, enabled, integrated or made available to FITIT by the Integrating Merchant, its systems, its analytics tools, its e-commerce platforms or authorized third parties, in order to obtain metrics, perform analytics, evaluate performance, measure accuracy, attribute interactions, improve the user experience, generate technical or commercial reports, resolve incidents, audit operation and develop new functionalities.
6.4. FITIT may anonymize, aggregate or transform information so that it does not allow the End User to be directly or indirectly identified by reasonable means. Anonymized or aggregated information may be used by FITIT for statistical, technical, commercial, analytical, research, development, training, validation, auditing, algorithmic improvement, internal reporting, reporting to integrating merchants or business partners, and functionality evolution purposes.
When the information is associated with technical identifiers, session identifiers, device identifiers, user identifiers or other elements that reasonably allow it to be linked to a specific End User, session, profile or interaction, FITIT shall apply the protection measures that correspond under the applicable regulations.
6.5. The recommendations, equivalences, visualizations, simulations, metrics or results generated by FITIT are technological, informational, indicative or illustrative in nature, depending on the applicable functionality. FITIT does not make automated decisions that produce legal effects on the End User, nor decisions that, by themselves, determine the purchase, rejection, contracting, availability, price, delivery, exchange or return of products of the Integrating Merchant.
SEVENTH. Legal Bases for Processing.
7.1. FITIT shall process personal data on the basis of the End User’s free, prior, express, informed and documented consent, when such consent is necessary under the applicable regulations, as well as on any other valid legal basis that may correspond for purposes of providing the FITIT functionalities, registration, authentication, session maintenance, technical operation, security, prevention of misuse, legal compliance, handling of requests, preservation of evidence or defense of rights.
7.2. In particular, FITIT shall request the specific consent that corresponds for commercial communications, non-essential personalization, extended recommendations, use of cookies or non-essential technologies, optional analytics, certain uses by business partners or processing of special categories of data when applicable.
EIGHTH. Withdrawal of Consent.
8.1. The End User may withdraw consent at any time through the mechanisms indicated in this Policy, in the corresponding use flow or by contacting legal@fitit.ai.
8.2. Withdrawal of consent shall not affect the lawfulness of processing carried out previously, nor shall it prevent the retention of information when necessary to comply with legal obligations, preserve evidence, handle requests, prevent abuse, resolve incidents, exercise defenses or protect the rights of FITIT, the End User or third parties.
NINTH. Providers and Third Parties.
9.1. FITIT may allow access to personal data to external providers of infrastructure, hosting, cloud services, communications, security, analytics, support, processing, monitoring, technical tools, connectivity, maintenance or equivalent services, for the purpose of providing the service. Such providers may include cloud service providers, technology infrastructure providers or technical tools, including Google Cloud, Amazon Web Services or other current or future providers that FITIT uses or contracts to host, run, support or complement the FITIT functionality.
9.2. FITIT may communicate or make available to the Integrating Merchant minimum, proportionate and reasonably necessary data to operate the integration, contextualize the Size Recommendation, associate the interaction with a product, size chart, digital channel or session, resolve technical incidents, measure the operation of the service, address inquiries related to the integration, maintain security or comply with applicable obligations. Likewise, FITIT may make available to the Integrating Merchant, within dashboards, reports or administration tools accessible only by authorized users of the Integrating Merchant, metrics, recommendation results, random examples or representative samples of use of the FITIT functionalities, including images of reference garments uploaded, entered, provided or authorized by the End User and recommended sizes, without including the End User’s name, email address, direct identifiers or other data intended to directly identify the End User.
Images of reference garments may contain incidental elements incorporated by the End User when uploading, entering, providing or authorizing the use of such images; notwithstanding the foregoing, FITIT shall apply the reasonable measures that correspond with respect to reference objects, documents, cards or other visible elements in accordance with this Policy.
9.3. FITIT may allow access to personal data to providers, technology partners or third parties when necessary to provide, operate, maintain, protect, analyze or improve the FITIT functionalities, under reasonable confidentiality, security and processing conditions in accordance with the purposes informed by FITIT.
9.4. When a third party intends to process personal data for its own purposes, independent commercial purposes or purposes not necessary for the provision of the functionality requested by the End User, FITIT shall request the specific consent that corresponds in accordance with the applicable regulations.
TENTH. International Transfers.
10.1. FITIT may process, host, store, back up, transmit or allow access to the End User’s personal data from jurisdictions other than the one in which the End User is located, including Uruguay, the United States of America, countries of the European Union or other jurisdictions in which FITIT, its providers, technology partners, business partners or authorized third parties operate.
10.2. International transfers may occur, among other cases, due to the use of providers of infrastructure, hosting, cloud services, communications, security, analytics, support, processing, monitoring, connectivity, maintenance, technical tools or equivalent services necessary or convenient to provide, operate, protect, scale or improve the FITIT functionality.
10.3. When the European Union General Data Protection Regulation or equivalent regulations apply, FITIT shall seek to ensure that international transfers of personal data are carried out on the basis of valid transfer mechanisms, including, as applicable, adequacy decisions, standard contractual clauses, binding corporate rules, explicit consent of the End User where appropriate, contractual necessity, defense of rights or other legally recognized mechanisms.
ELEVENTH. Retention of Personal Data.
11.1. FITIT shall retain personal data for the period necessary to fulfill the purposes informed in this Policy, including the provision of the FITIT functionalities, maintenance of the End User’s account or profile, retention of reference garments, generation of recommendations, visualizations or indicative results, operation, maintenance, security, auditing, measurement, service improvement, handling of requests, management of consents, preservation of evidence and compliance with applicable obligations.
When personal data is no longer necessary for the purposes that justified its processing, FITIT may delete it, anonymize it, aggregate it or retain it in a limited manner when necessary to comply with legal obligations, preserve evidence of consent, handle requests, prevent abuse, resolve incidents, exercise defenses, protect the rights of FITIT, the End User or third parties, maintain technical records, generate metrics, perform audits, improve the FITIT functionalities or comply with other legitimate purposes informed in this Policy.
11.2. Anonymized, aggregated or statistical information that does not allow the End User to be directly or indirectly identified by reasonable means may be retained and used by FITIT for an indefinite period for statistical, technical, commercial, analytical, research, development, functionality improvement, training, validation, auditing, metrics, internal reporting, reporting to integrating merchants or business partners, and service evolution purposes.
THIRTEENTH. Security.
13.1. FITIT shall apply reasonable and appropriate technical and organizational measures to protect the personal data processed through the FITIT functionality against loss, alteration, destruction, unauthorized access, unauthorized disclosure, improper processing or use incompatible with this Policy.
13.2. Security measures may include, as applicable, access controls, technical records, authentication mechanisms, encryption or pseudonymization where reasonable, segregation of environments, backups, monitoring, incident management, availability controls, business continuity measures, internal access restrictions, confidentiality obligations, controls over technology providers and other reasonable measures.
13.3. The End User acknowledges that no technological system, online service, integration, communications network, cloud infrastructure, external provider or digital environment can guarantee absolute security, permanent availability or total absence of vulnerabilities, unlawful access, technical failures, errors, interruptions, security incidents, acts of God, force majeure or circumstances beyond FITIT’s reasonable control.
FOURTEENTH. Rights of the End User.
14.1. The End User may exercise, to the extent applicable under the relevant regulations, the rights of access, information, knowledge, rectification, update, inclusion, cancellation, suppression, deletion, objection, restriction of processing, data portability, withdrawal or revocation of consent and any other right recognized by the applicable personal data protection regulations. Such rights may be exercised by contacting legal@fitit.ai or any other contacts that FITIT may indicate from time to time.
14.2. Before handling a request related to the exercise of rights, withdrawal of consents, management of preferences or processing of personal data, FITIT may request information reasonably necessary to verify the identity of the requester, the authenticity of the request, the authorization of the representative, the ownership of the personal data involved or the connection between the request and the FITIT functionality.
14.3. When the FITIT functionality allows it, the End User may manage or request the deletion of their account, images, photographs, visual content, reference garments, recommendation results, Try On results or other associated information directly from the mechanisms available in the FITIT tool, without prejudice to the possibility of exercising their rights by contacting legal@fitit.ai.
FIFTEENTH. Relationship with the Integrating Merchant.
FITIT does not control or assume responsibility for the processing of personal data, privacy policies, cookie policies, forms, databases, payment gateways, analytics tools, commercial communications, providers, systems, platforms, processing practices, purposes, means or decisions of the Integrating Merchant with respect to the personal data that such Integrating Merchant processes under its own responsibility.
SIXTEENTH. Amendments to this Policy.
16.1. FITIT may update, amend, supplement or replace this Policy whenever it considers it necessary or convenient for legal, regulatory, technical, operational, commercial, security, compatibility, service evolution reasons, changes in the FITIT functionality, changes in the purposes of processing, legal bases, categories of processed data, recipients, providers, business partners, international transfers or consent mechanisms.
16.2. When the amendments are relevant to the End User, FITIT shall notify them through reasonable mechanisms, such as publication of an updated version, notice within the functionality, banner, updated link, pop-up window, electronic communication, contextual notice, preference panel, new acceptance flow or equivalent means.
16.3. When an amendment involves new, different or additional processing that requires consent under the applicable regulations, FITIT shall request such consent before applying the corresponding processing, without prejudice to processing that may validly rely on another applicable legal basis.
16.4. The amendment of this Policy, the lack of acceptance of an amendment or the withdrawal of consent shall not affect the lawfulness of processing previously carried out on a valid legal basis.
SEVENTEENTH. Governing Law, Jurisdiction and Mandatory Rights.
17.1. This Policy shall be governed by and interpreted, to the extent applicable, in accordance with the laws of the Oriental Republic of Uruguay, without prejudice to any mandatory rules on personal data protection, privacy, consumer protection, e-commerce or other mandatory rules that may apply.
17.2. To the extent permitted by the applicable regulations, any dispute, difference, action, claim or matter arising from the interpretation, application, validity, performance, breach, termination or effects of this Policy shall be submitted to the jurisdiction of the competent Courts and Tribunals of the Department of Montevideo, Oriental Republic of Uruguay, unless an applicable mandatory rule provides for a different jurisdiction, forum, supervisory authority or claim mechanism.
17.3. When the European Union General Data Protection Regulation, regulations of the European Economic Area, the United Kingdom or other equivalent mandatory regulations apply, the End User shall retain the rights, remedies, guarantees, complaint mechanisms and powers to refer matters to supervisory authorities or competent courts that such regulations mandatorily recognize.
17.4. When the End User is located in a jurisdiction other than Uruguay, or when mandatory local regulations on personal data protection, privacy, e-commerce or consumer protection apply, FITIT shall respect the rights, guarantees, legal bases, complaint mechanisms and obligations that such regulations mandatorily recognize for the End User.
The date of this "Privacy Policy" is 07/08/2026.