Legal

Privacy Policy

Effective Date: 1 April 2026 · 5SEC Ltd

Important: 5SEC collects and processes sensitive personal data including facial photographs, body measurements, and AI-generated biometric analysis. Please read this policy carefully before using our services. By submitting any photograph or body measurement data, you explicitly consent to the processing described in this policy.

LEGAL REVIEW REQUIREDThis page contains placeholder legal structure only. The final legal copy must be reviewed and approved by qualified counsel before public launch. Do not treat this as a binding legal document in its current form.

1. Who We Are

5SEC Ltd ("5SEC", "we", "us", or "our") operates the 5SEC platform and services, accessible at 5sec.app and related subdomains. We provide personal styling, wardrobe management, colour analysis, fit profiling, and related advisory services.

For the purposes of applicable data protection law, 5SEC Ltd is the data controller responsible for the personal data you provide to us. Our principal place of business is New York, NY, United States.

For all privacy-related enquiries, data subject requests, or complaints, contact our Data Protection contact at: [email protected].

2. Data We Collect

We collect the following categories of personal data, depending on the services you use:

2.1 Account & Identity Data

Name, email address, username, password (hashed), account creation date, and authentication tokens.

2.2 Contact & Communication Data

Email correspondence, support messages, booking enquiries, and any information you voluntarily provide when contacting us.

2.3 Payment & Transaction Data

Payment method type, billing address, transaction identifiers, and order history. We do not store full card numbers or CVV codes. Payment processing is handled by PayPal (see Section 7). We retain transaction records for legal and accounting purposes.

2.4 Profile & Lifestyle Data

Lifestyle questionnaire responses including work style, social context, travel frequency, dress level preferences, age, and personal style preferences provided during onboarding or assessment.

2.5 Body Measurement Data

Physical measurements you provide or that are derived from analysis, including but not limited to: height, weight, shoulder width, chest circumference, waist circumference, hip circumference, inseam length, neck circumference, thigh circumference, and posture classification. This data is used exclusively to generate your fit profile.

2.6 Photographic Data

Facial photographs and full-body photographs submitted for colour analysis, fit analysis, and wardrobe profiling. This data is classified as sensitive personal data and is subject to additional protections described in Section 3.

2.7 AI-Generated Analysis Data

Derived data produced by our automated analysis systems, including: skin undertone classification, skin tone depth (Fitzpatrick scale), colour saturation classification, fit profile archetype, silhouette type, proportion analysis, wardrobe archetype, and associated recommendations. This derived data is linked to your account and profile.

2.8 Usage & Technical Data

IP address, browser type and version, device type, operating system, pages visited, time on page, referral source, and interaction events. Collected via server logs and analytics tools.

3. Biometric & Sensitive Data — Special Notice

This section is particularly important. Please read it carefully.

5SEC processes data that may constitute biometric data and special category personal data under applicable law, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Illinois Biometric Information Privacy Act (BIPA) where applicable.

3.1 What Constitutes Sensitive Data in Our Services

The following data we collect is classified as sensitive or biometric:

  • Facial photographs — images of your face submitted for colour and undertone analysis
  • AI-derived facial characteristics — skin undertone, skin tone depth, colour saturation derived from photo analysis
  • Body measurements — precise physical measurements used for fit profiling
  • Posture classification — derived from measurements and/or photographs
  • Full-body photographs — submitted for fit and silhouette analysis

3.2 Explicit Consent

We collect and process biometric and photographic data only with your explicit, informed consent. You provide this consent at the point of data submission (during the assessment or onboarding flow) by actively confirming your agreement to this policy. You may withdraw consent at any time — see Section 10 for your rights.

Withdrawal of consent for biometric data processing will result in the deletion of your photographs and AI-derived analysis from our systems. It may affect the quality or availability of personalised recommendations.

3.3 Purpose Limitation

Biometric and photographic data is used exclusively for the following purposes:

  • Generating your personal colour profile and palette recommendations
  • Generating your personal fit profile and silhouette strategy
  • Generating your wardrobe archetype and system recommendations
  • Enabling Professor Nedo Bellucci or authorised stylists to review and refine your profile

We do not use biometric data for identity verification, surveillance, marketing profiling, or any purpose beyond the personalised styling services described above.

3.4 Storage & Security of Biometric Data

Photographs and biometric-derived data are stored in encrypted cloud storage (Amazon S3 with server-side AES-256 encryption). Access is restricted to authorised personnel on a strict need-to-know basis. We do not store raw facial geometry, facial recognition templates, or fingerprint data.

3.5 No Sale of Biometric Data

We do not sell, lease, trade, or otherwise profit from your biometric data or photographs. We do not share biometric data with third parties except as strictly necessary to provide the service (e.g., cloud storage providers acting as data processors under written contract).

3.6 Illinois BIPA Notice (US Residents)

If you are an Illinois resident, you have rights under the Illinois Biometric Information Privacy Act (BIPA). Our biometric data retention schedule provides for deletion of biometric identifiers within 3 years of collection or within 1 year of your last interaction with us, whichever is earlier. You may request earlier deletion at any time by contacting [email protected].

4. How We Use Your Data

We use your personal data for the following purposes:

PurposeData Used
Providing and managing your accountAccount & identity data
Processing payments and managing subscriptionsPayment & transaction data
Generating your colour, fit, and wardrobe profilePhotos, measurements, questionnaire, AI analysis
Delivering personalised recommendationsProfile data, AI analysis, lifestyle data
Enabling stylist review and consultationPhotos, measurements, profile data
Sending service communications (receipts, updates, onboarding)Email, account data
Responding to support enquiriesContact & communication data
Improving our analysis engines (anonymised only)Aggregated, anonymised usage data only
Complying with legal obligationsAs required by applicable law
Fraud prevention and platform securityUsage & technical data, account data

We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review. All profile outputs are reviewed by Professor Nedo Bellucci or an authorised stylist before delivery.

6. AI Analysis & Automated Processing

6.1 What the AI Does

When you submit a selfie or photograph, our AI system analyses visual characteristics including skin undertone (warm/cool/neutral), skin tone depth (Fitzpatrick scale 1–6), and colour saturation (bright/muted). These outputs are combined with your questionnaire responses to generate your colour profile.

6.2 Human Review

All AI-generated profiles are reviewed by Professor Nedo Bellucci or an authorised stylist before being released to you. The AI output is a starting point for expert review, not a final automated decision. You are informed of this review process at the point of assessment submission.

6.3 Right to Contest AI Outputs

If you believe your AI-generated profile is inaccurate, you have the right to request human review, correction, or deletion of the analysis. Contact us at [email protected] with your request.

6.4 Third-Party AI Services

Our AI analysis is powered by large language model services. Photographs submitted for analysis are transmitted to these services under data processing agreements that prohibit retention for training purposes. See Section 7.

7. Data Sharing & Third Parties

We do not sell your personal data. We share data only with the following categories of recipients:

7.1 Service Providers (Data Processors)

  • Amazon Web Services — hosting, storage, and database services. Data stored in encrypted form.
  • PayPal — payment transactions. PayPal's privacy policy governs their processing of payment data.
  • Resend — transactional email delivery.
  • AI analysis services — photograph analysis for colour profiling. No retention for training purposes.
  • Analytics providers — anonymised usage analytics only.

7.2 Authorised Personnel

Professor Nedo Bellucci and designated 5SEC stylists have access to your profile data, photographs, and measurements for the purpose of reviewing and refining your profile. All personnel are bound by confidentiality obligations.

7.3 Legal Disclosure

We may disclose personal data to law enforcement, regulators, or courts where required by applicable law, court order, or to protect the rights, property, or safety of 5SEC, our users, or the public.

7.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred. Biometric data will not be transferred without your renewed explicit consent.

8. International Data Transfers

5SEC operates from the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, your data may be transferred to and processed in the United States.

We ensure such transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable. You may request a copy of the transfer safeguards applicable to your data by contacting [email protected].

9. Data Retention

Data CategoryRetention Period
Account & identity dataDuration of account + 2 years after closure
Payment & transaction records7 years (legal/accounting obligation)
Photographs (facial & body)Active membership + 1 year, or 3 years from collection, whichever is earlier. Deleted immediately on request.
AI-derived biometric analysisSame as photographs. Deleted with photographs on request.
Body measurementsActive membership + 1 year after cancellation
Questionnaire & lifestyle dataActive membership + 1 year after cancellation
Usage & technical data13 months from collection
Support communications3 years from last interaction
Book waitlist emailUntil publication or until you unsubscribe

When retention periods expire, data is securely deleted or anonymised. You may request earlier deletion at any time (subject to legal retention obligations).

10. Your Rights

Depending on your jurisdiction, you have the following rights. We respond to all verified requests within 30 days.

Right of Access

Request a copy of all personal data we hold about you, including photographs, measurements, and AI analysis.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure ('Right to be Forgotten')

Request deletion of your personal data, including all photographs and biometric analysis. Certain data may be retained where required by law.

Right to Withdraw Consent

Withdraw consent for biometric data processing at any time. This does not affect the lawfulness of prior processing.

Right to Data Portability

Receive your personal data in a structured, machine-readable format where technically feasible.

Right to Restrict Processing

Request that we limit how we use your data while a dispute is resolved.

Right to Object

Object to processing based on legitimate interests.

Right Not to Be Subject to Automated Decisions

Request human review of any AI-generated profile or recommendation.

CCPA Rights (California Residents)

Right to know, right to delete, right to opt out of sale (we do not sell data), right to non-discrimination.

BIPA Rights (Illinois Residents)

Right to deletion of biometric identifiers within the retention schedule.

To exercise any of these rights, contact us at [email protected] with the subject line "Data Subject Request — [Right Type]". We may ask you to verify your identity before processing the request.

If you are in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

11. Cookies & Tracking Technologies

We use cookies and similar tracking technologies on our platform. For full details, see our Cookie Policy.

Essential Cookies

Required for authentication and core platform functionality. Cannot be disabled without breaking the service.

Analytics Cookies

Privacy-respecting analytics to understand platform usage. Aggregated and anonymised. You may opt out via browser settings.

No Advertising Cookies

We do not use advertising cookies, retargeting pixels, or third-party tracking for advertising purposes.

12. Children's Privacy

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. We do not collect biometric data from minors under any circumstances. If you believe a minor has provided us with personal data, contact us at [email protected] and we will delete the data promptly.

13. Security

We implement the following technical and organisational security measures:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and role-based permissions limiting data access to authorised personnel
  • Secure cloud infrastructure with regular security assessments
  • Password hashing using industry-standard algorithms
  • Regular review of data processing procedures and access logs

No method of transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities as required by law.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes — particularly to how we process biometric or sensitive data — we will notify you by email and display a prominent notice on the platform at least 30 days before the changes take effect.

Your continued use of our services after the effective date constitutes acceptance of the updated policy. Previous versions are available on request.

15. Contact & Data Requests

For all privacy-related enquiries, data subject requests, consent withdrawals, or complaints:

5SEC Ltd

Data Protection Contact

New York, NY, United States

[email protected]

We aim to respond to all data subject requests within 30 days. For urgent biometric data deletion requests, mark your email: "URGENT — Biometric Data Deletion Request".

This Privacy Policy was last reviewed and updated on 1 April 2026. 5SEC Ltd · New York, NY, United States · [email protected]