Privacy statement of FAIM B.V.
Privacy.
FAIM makes product images for fashion brands: from a photo of the garment to colour variants and images on a model, largely with artificial intelligence. To do so, we process data of visitors to our website, of people who contact us and of the staff of brands who work in our portal. This page explains in plain language which data that is, why we use it, who we work with and what your rights are.
Last updated: 18 September 2026
In short
- We process nothing about consumers. Images belong to your brand's account, never to an individual shopper. We cannot see who later views your images in a web shop.
- No trackers, no advertising. Our website and the portal run no analytics and no advertising pixel. We never sell data.
- The portal is by invitation only. From your brand, a colleague or us.
- Your product images go to AI image models, through temporary, secure links and solely to make your images. Some of these models run outside the EU.
- A model is either an AI person who does not exist, or a real model who does. An AI person is not based on photos of an existing individual. When the AI dresses a real model or places that model in a different setting, this only happens with the model's consent. Every AI image carries an AI label.
- Your data and images are stored in the EU, on servers in Frankfurt.
- A FAIM employee can temporarily view your portal for support. View only, for 30 minutes at most, and always logged.
- You can always ask what we hold about you, have something corrected or deleted, and object.
1Who is responsible
FAIM B.V., located at Amstelbeststraat 26, 1096 GD Amsterdam, the Netherlands, and registered with the Dutch Chamber of Commerce (KvK) under number 42062725, is responsible for the data you leave on our website and for the data that belongs to your account and your work in the FAIM portal.
For the images and files a brand puts in the portal, the brand decides. We then act on the brand's instructions and do nothing with them other than what the brand asks. For accounts, the website, our logs and share links we decide ourselves, and we are responsible. The arrangements for acting on a brand's instructions are in the data processing agreement that comes with the customer agreement: the Standard Clauses for Processing from the NLdigital Terms, supplemented by our Data Pro Statement. If your brand does not have it yet, we will send it on request.
Questions about your privacy?
E-mail: privacy@faimstudio.com
We respond within one month. If your question concerns images or files of your brand, we coordinate the answer with your brand.
2Who this statement applies to
This statement is for everyone whose data FAIM uses:
- Visitors to faimstudio.com.
- People who request a demo or e-mail us, and contacts at brands we do business with or are in talks with.
- Staff of customer brands with an account in the portal, as owner, reviewer or viewer.
- Guests invited for a single collection or release, such as retouchers, agencies and photographers.
- Recipients of a share link through which a brand shows images.
- Operators of THE FRAIM, our capture station, and of the FAIM Capture app (see chapter 3).
- FAIM staff themselves.
Not for the consumers who later see the images in a web shop: we process nothing about them; that is the relationship between your brand and its customers.
Were you invited by your brand or a colleague? Then we received your name and e-mail address from them. Without an e-mail address we cannot create an account; your name, profile photo and notifications are optional.
3What data we use
The website and the demo form
You do not have to fill anything in on our website unless you request a demo: there is no account and no newsletter. In the demo form you enter your name, work e-mail address, brand name, the number of items per month, your role and, if you like, a message. The request reaches us as an e-mail; we do not store it in a database. To prevent abuse of the form, we briefly keep track per internet address of how often the form is sent, at most five times an hour. That happens in the server's memory and is not stored. Like any web server, our hosting provider processes your IP address to deliver the page and keeps short-lived technical logs of it. Your request, or an e-mail to us, arrives in our mailbox; the next paragraph covers that.
Contact with customers and prospective customers
If you work at a brand we do business with or are in talks with, we keep your name, company, job title and contact details, our correspondence and notes of conversations. This is stored in our mailboxes and documents, and we use it to maintain the relationship and honour agreements. None of it goes to advertisers or data brokers.
Your account and signing in
You only get access to the portal by invitation. We store your e-mail address, display name, any profile photo, language choice, your role within your brand and the time you last signed in. Signing in works without a password, with a link by e-mail, or with your Google account if that address was invited. You can turn on two-step verification; its key is held by our authentication service. An invitation contains your e-mail address and a unique code. An invitation for a guest expires after 14 days.
Your work in the portal
While you work, we record what you order and the notes you write with it, the designs or reference images you upload, which images you review and approve, what you download, and your notification preferences. A brand's owner fills in the company profile: company name, billing address, VAT and Chamber of Commerce number. We never store payment details.
Images and AI generation
The product photo of an article, any reference images and the instruction for the model (we call it the recipe) go through our automation layer to AI image models. For each image made, we record which model, recipe and settings produced it, who reviewed it and when. That is the image's passport, and it stays with the image. You can only download AI images on a model, in motion or in a setting once your brand's owner has given consent for that type, with a switch in the brand settings. More about AI in chapter 5.
Jules, the assistant
Jules is the voice and chat assistant in the portal. Jules does nothing until you click it. In voice mode your browser asks permission to use the microphone; your voice and the text of the conversation go to our voice supplier, which also engages the language model behind Jules. To help you, Jules sees your display name, your brand's name and the screen you are on, not your e-mail address and not your role. FAIM does not store your conversations with Jules. How long the voice supplier keeps them is in chapter 7.
Share links
A brand's owner or a FAIM employee can share a selection of images through a link, for example with an agency or a customer. The link comes with a title, the recipient's name and an optional note. By default the link works for 30 days and can be revoked sooner. We record no IP address and no browser details of whoever opens the link. We do register that images were viewed or downloaded, which file and when, and our team is notified straight away. Download links already issued keep working after revocation until they expire by themselves.
THE FRAIM and the Capture app
THE FRAIM is our capture station: a photo station that can stand at a brand's premises and in which a garment on a hanger is photographed the same way every time. The FAIM Capture app is the iPhone app a staff member uses to operate the station, check the shots and send them to the portal.
If you photograph with THE FRAIM and the Capture app, for each capture session we record which account started the session, the operator's label, details of the device used (app and system version, connection to the station, error messages), the status of the station itself (connection, firmware version), the station's serial number and the times. Each shot comes with a technical log line that we keep to trace problems and keep the station and the app working.
E-mail and notifications
We only send e-mail that belongs to your work in the portal: invitations, sign-in links, messages about your orders and images, and a weekly overview. You can switch off the overview and most notifications per topic. For every e-mail sent, we keep the recipient, the subject, the status and whether it was delivered.
Security, logs and support views
The portal keeps a log of what happens to images: who placed an order, who approved an image, who downloaded something. That log cannot be altered and is the basis of each image's passport.
Sometimes a FAIM employee views your portal, to answer a support question or find an error. That is viewing only, not changing, lasts 30 minutes at most and is recorded: who, in whose portal, when and from which device. Would you rather this only happens when you ask for it? E-mail us.
4Why we use it
For every purpose we have a legal basis. In plain language:
- To fulfil our agreement with your brand (contract): accounts, orders, making and delivering images, the passport per image, keeping the capture station and the app working, and the e-mail that goes with it.
- Because we have a legitimate interest: answering a demo request, keeping in touch with customers and prospective customers, securing the portal and keeping the log, viewing your portal for support, informing the team when a share link is used, and sending the weekly overview. We always weigh that interest against your privacy, and you can object to it.
- With your consent: the microphone for Jules, and per brand the consent to have AI images made on a model, in motion or in a setting. You can always withdraw consent.
- Because the law requires it: we must keep our invoicing records for seven years.
We make no automated decisions about you as a person. The AI makes images, not decisions about people. We build no profiles, sell no data and show no advertising.
5AI images: what does and doesn't happen
If a model appears in an image, it can come about in two ways. For privacy that difference matters, so we describe them separately.
A model the AI invents. That person does not exist. The image is made by the model and not based on photos of a real person. A chance resemblance to someone can never be fully ruled out; we make no images meant to look like a particular real person, and we remove an image if someone rightly recognises themselves in it.
An existing model, dressed or placed in a scene by the AI. Here we start from photos of a real person. The AI changes the clothing, the pose or the setting, not who is standing there. Such photos and the images that follow from them are personal data of that model. Therefore: whoever supplies the model makes sure the model has consented to this use. If your brand supplies the model, you arrange it; if we work with a model engaged by FAIM, we arrange it. We use the photos solely for your assignment, they go through temporary, secure links only to an AI supplier with whom we have a data processing agreement, and we keep them as set out in chapter 7. We only offer this route when that is in place. If the model withdraws that consent, let us know; we will then delete the photos and the images made with them.
Are there real people in what you upload for another reason, for example in a reference image? Then too you make sure that is allowed, we use those photos only for your assignment and send them only to a supplier with a data processing agreement.
Most product photos contain no personal data. We do treat them as confidential: they go only through temporary, secure links to the AI suppliers, who may use them solely to carry out your assignment. Chapters 6 and 7 set out per supplier what they see and how long they keep anything.
What the AI changes is the context: model, pose, setting. We never make up the product itself. We only make a colour or pattern variant from a real design or fabric swatch of your brand; we call that our Visual Truth principle.
Every image made with AI is labelled as such in the portal, and that label is also in the image's passport. If you publish the image, you make sure your customers see that label too; the European AI Act asks this of both of us.
6Who we work with
FAIM does not build everything itself. For storage, hosting, e-mail, AI models and the assistant we use specialised companies. They work on our instructions and may only use your data to do their work for us. We make arrangements on security and confidentiality with each of them. Suppliers with whom we have a data processing agreement may not use your data to train their own AI models. Suppliers that see no personal data, such as the supplier of our fabric scans, are not listed here.
For each part you see the kind of company, what it sees and where it works. Staff of customer brands see the same table with the names of the companies once they are signed in at portal.faimstudio.com/privacy.
| What for | Who helps us | What they see | Where, and under which agreement |
|---|---|---|---|
| Storage, accounts and signing in | A database service with servers in Frankfurt | All portal data: accounts, orders, images and the keys for two-step verification | Germany (EU)Standard contractual clauses |
| Website and portal | A hosting provider with a global network | Every request to the site or the portal: IP address and technical logs | United StatesPortal: processing in the EUData Privacy Framework |
| An e-mail delivery service | E-mail address, subject and content of every e-mail, and the delivery status | United StatesData Privacy Framework | |
| Automation | A European hosting provider for our automation layer | Order numbers, temporary links to images and the recipes; no names or e-mail addresses | Germany (EU) |
| AI image generation | An AI image gateway and the American model supplier it engages for us; during outages a second American AI supplier | The product photo, designs and the recipe; no images with recognisable people | United States |
| Upscaling images | An American supplier of upscaling software, through the same gateway | The generated image | United StatesStandard contractual clauses |
| Jules, the assistant | An American supplier of voice and language models, plus the supplier of the language model it engages | Your voice and the text of the conversation, your display name, brand name and the screen you are on | United StatesData Privacy Framework |
| Help writing recipes (our team only) | An American supplier of language models | Recipe text and temporary links to images | United StatesData Privacy Framework |
| Signing in with Google | Your e-mail address and your Google account's identifier, only if you sign in with it | United StatesData Privacy Framework | |
| Our own work | Office software, our ticketing system and code management | Your contact details and support questions if you e-mail us | United States and EUData Privacy Framework |
Data outside the EU
Your data and images are stored in the EU. Some of the services we use run outside the EU, mainly in the United States. For every transfer we use an arrangement the European Union recognises: the Data Privacy Framework for American companies that have joined it, or the European Commission's standard contractual clauses. Those standard contractual clauses are fixed contract terms drawn up by the European Commission; a supplier outside the EU signs them and thereby promises to protect your data there just as well as here. The text of the standard contractual clauses is on the European Commission's website; which American companies have joined the Data Privacy Framework you can see at dataprivacyframework.gov. We will send you a copy of the arrangement with a particular supplier on request; e-mail privacy@faimstudio.com. Where possible we choose processing within the EU; the portal itself runs in Frankfurt and our automation in Nuremberg.
7How long we keep data
We keep data no longer than necessary. If you delete something or a period ends, it also disappears from our backups within 30 days.
| Data | How long |
|---|---|
| Demo request through the form or by e-mail, or another question by e-mail | As long as the conversation continues, and up to 12 months after the last contact |
| Contact with customers and prospective customers | As long as the relationship continues, and up to 24 months after the last contact |
| Account | As long as you are active. Within 30 days after a deletion request or the end of the agreement. If you have not signed in for 24 months, we warn you and delete the account |
| Invitations | The code works for 14 days; we delete the invitation itself 90 days after it expires |
| Orders, delivered images and the passport | As long as the agreement with your brand runs. After that deleted or returned to your brand within 30 days |
| AI variants that were not chosen (for each assignment the AI makes several versions; what your brand does not choose is deleted automatically) | 90 days |
| Download packages (zip) | 7 days |
| Share links | The link 30 days (or shorter, if you revoke it); who viewed or downloaded when 90 days, after that only counts |
| Portal log | As long as the image exists, and up to 12 months after the end of the agreement. If we delete your account, we remove your name from the log |
| Support views by FAIM staff | 12 months |
| E-mail sent (recipient, subject, status) | 12 months |
| Conversations with Jules | Not at FAIM. At the voice supplier 5 days: the text of the conversation is deleted after that, and the audio is not stored |
| Capture sessions with THE FRAIM | 12 months; data about the station itself as long as it is in use |
| Company profile and invoices | 7 years after the financial year, because tax law requires it |
8How we protect data
- Storage in the EU, in a data centre in Frankfurt, with encrypted connections.
- Access by invitation only. Each brand sees only its own data; this is enforced at database level, row by row.
- Two-step verification for anyone who wants it, and mandatory for FAIM staff.
- Images go to suppliers only through temporary, signed links; those links expire by themselves.
- The portal itself has no administrator key to the database; that key exists only outside the portal, with our team.
- Support views by FAIM are logged and time-limited (see chapter 3).
- We test with every change and periodically that a brand cannot reach another brand's data, and that an outsider cannot reach anything.
- In case of a data breach we report it to the Dutch Data Protection Authority within 72 hours and inform the brands it affects.
9Your rights
Access
Ask which data we hold about you, for what purpose, and with which companies we share it. You then also get the names of the companies in chapter 6.
Correction
Something not right? You adjust your name and profile yourself in the portal; we correct the rest.
Erasure
Have your account and the data that belongs to it deleted. Data the law lets us keep, such as invoices, remains.
Restriction
Ask us to temporarily stop using data, for example while we assess a correction.
Portability
Receive the data you gave us in a common file format.
Objection
Object to processing based on our legitimate interest, such as support views or the weekly overview.
How to arrange it
E-mail privacy@faimstudio.com. We respond within one month and sometimes ask you to confirm it is you, for example by replying from your account's e-mail address. You cannot yet delete your account yourself in the portal; for that too, e-mail us.
Do you work at a brand that is a FAIM customer? Then you can also turn to your brand's owner, who can manage your account and role. If your request concerns images or files of your brand, we forward it to your brand, because the brand decides on them. If you are a guest, you can also ask the person who invited you.
11Questions or a complaint
Do you have a question about this statement or about your data? E-mail privacy@faimstudio.com. If you disagree with how we handle a request, you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
12Changes
FAIM keeps developing and adds new features. If that affects your privacy, we update this statement and put the new date at the top. For a major change we also let the brands' owners know by e-mail.