Trust

Trust

This page summarizes Apshan's compliance posture. The detailed policies linked below govern in case of inconsistency.

Last reviewed: May 2, 2026 · Next review: August 2, 2026

Position

Apshan is a fashion intelligence platform. Apshan delivers structured, sourced information to inform human decisions. Apshan does not make decisions for you.

This page summarizes Apshan's compliance posture and points to the detailed policies that operationalize it. The compliance posture is reviewed quarterly. The detailed policies govern in case of any inconsistency.

Scope

Apshan answers questions about fashion and textile, plus the industries that materially shape them: weather and climate, supply chain, finance and macroeconomics, geopolitics, agriculture, and culture, insofar as they affect fashion outcomes.

Questions outside this scope are declined. Apshan responds to out-of-scope queries with a brief refusal, not a fabricated answer. This boundary is the source of Apshan's calibration: depth in one domain produces sharper, more cited answers than shallow breadth across many.

AI Act stance

Apshan is positioned as a Limited Risk AI system under Regulation (EU) 2024/1689 (the EU AI Act). Apshan does not operate in any of the high-risk categories listed in Annex III of the Act.

What Apshan does not do:

  • employment screening or workforce management decisions;
  • creditworthiness or credit scoring;
  • biometric identification or categorization of natural persons;
  • determinations of access to essential public or private services;
  • law enforcement or judicial decision support;
  • migration, asylum, or border control.

Article 50 transparency obligations are met inline at every product surface: AI-generated content is disclosed at first interaction, and synthetic outputs carry machine-readable provenance markers.

How Apshan handles your data

Apshan does not use Customer Data to train AI models. Apshan does not sell Customer Data. Apshan does not use Customer Data for advertising profiling.

Customer queries are kept inside your session. Retention periods are bounded per data category and documented in the Privacy policy. The named list of third parties that process data on our behalf is published at /subprocessors with a thirty-day notice commitment for any material change.

Sources and provenance

Every Apshan output cites the sources it was built from. Sourceless answers are not Apshan answers.

For synthetic content (generated images, videos, and text):

  • C2PA metadata is embedded in generated media;
  • invisible watermarks tie the output to the generating account;
  • digital fingerprints support downstream traceability;
  • Article 50(2) machine-readable marking is applied to AI-generated and AI-manipulated outputs.

Stripping these provenance signals to misrepresent origin violates the Acceptable Use Policy.

Human in the loop

Apshan is a tool for human decision-makers, not a substitute for them. Three operational commitments make that real:

Sources surfaced
Every output exposes its source citations. You can verify the underlying material before acting.
Confidence indicated
Where a claim is uncertain, contested, or based on limited evidence, the output says so.
Challenge channel
If you believe an Apshan output is wrong, write to hello@apshan.com. We log challenges, respond within a defined service-level commitment, and use them to improve calibration.

Sovereignty

Apshan's platform is EU-resident by default. Apshan SAS is incorporated in France and operates from Paris. Customer queries and product systems run in the European Union.

The end-to-end footprint of your data depends on the AI client you connect through. Customers who require a fully EU-sovereign data flow can configure for it today; customers whose enterprise AI stack runs on non-EU providers may use those configurations where officially supported. The list of supported clients, with the data-residency profile of each, is documented separately, so you can choose the configuration that matches your compliance requirements.

Apshan curates the supported client list to providers whose data residency and compliance posture align with these commitments. Unsupported clients are declined.

Limitations

Apshan is honest about what it does not do well. Outputs are research-grade information, not regulated advice.

  • Forecasts are probabilistic. Apshan's predictive layer surfaces calibrated probabilities, not certainties. Confidence is exposed; users decide.
  • Coverage is uneven. Some markets, materials, and supply chain segments are sparsely sourced. Apshan flags coverage gaps rather than fabricating coverage.
  • Knowledge is time-bound. Outputs reflect the most recent ingest, not real-time data, except where explicitly labeled.
  • Source rights are respected. Apshan does not retrieve information from behind paywalls or NDAs without authorization.
  • No regulated advice. Apshan outputs are not financial, legal, medical, or investment advice. Use them to inform decisions, not as decisions.

Compliance review

Apshan reviews this trust posture and the underlying policies on a quarterly cadence. The "Last reviewed" date at the top of every compliance page reflects the most recent review.

Last review
May 2, 2026
Next review
August 2, 2026
Cadence
Quarterly, with material changes announced before they take effect.
Incident notification
Personal-data breaches notified to the CNIL within seventy-two hours of discovery, per GDPR Article 33. Affected users informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34).

Where to learn more

For the detailed legal and operational artifacts that underpin this posture:

Privacy
What we collect, why, how long we keep it, and your rights: /privacy.
Terms
The contract that governs use of the Service: /terms.
Acceptable use
What users may not do with the Service: /aup.
Security
Infrastructure security, encryption, and incident response: /security.
Subprocessors
Named list of third parties that process data on our behalf: /subprocessors.
Data requests
How to submit a GDPR data subject access request: /data-requests.
Legal notice
Corporate identification per LCEN Article 6 III: /legal-notice.

Contact

privacy@apshan.com
Apshan, 6 Rue d'Armaillé, 75017 Paris, France.

The intelligence exists before the question.

Invite-only. Request access now.