Back to blog

6 Questions to Ask a Vendor Before It Trains on Your Pattern Data

6 Questions to Ask a Vendor Before It Trains on Your Pattern Data

If an AI platform learns from your pattern archive, it is not just reading files — it is ingesting decades of proprietary construction knowledge. Before you sign, six questions separate a vendor with genuine data governance from one with reassuring marketing copy.

Key takeaways

  • Tenant isolation is the minimum standard: your training data must never influence another customer's model outputs.
  • Model weight ownership is a contract term, not a default — ask for it in writing before the pilot begins.
  • EU procurement bodies published updated AI model contractual clauses in 2025 specifically to help buyers lock in these protections.
  • The GDPR requires processors to delete or return your data on exit and to support audits — demand the same from any AI vendor, whether or not personal data is involved.
  • Several platforms in the market today document their isolation and data-use policies publicly; others do not, and silence is itself an answer.

Why does this matter now?

Fashion AI has moved from mood-board generators to tools that ingest a brand's own technical files — DXF patterns, tech packs, grading tables — and produce production-ready outputs from them. That shift changes the risk profile entirely. A vendor that trains a shared foundation model on your archive could, in principle, let a competitor benefit from your construction logic. Most brands have not updated their procurement checklists to reflect this.

The six questions below are written for anyone evaluating an AI platform that will touch proprietary pattern or product data. They apply whether you are a sourcing director, a head of digital product creation, or a general counsel reviewing a pilot agreement.


Question 1: Is my data isolated in a separate tenant, or does it touch a shared model?

What you are really asking

Tenant isolation means your training data, fine-tuning runs, and model weights live in an environment that is logically and technically separated from every other customer. Without it, the vendor's model can, in theory, surface patterns in your construction logic when it responds to a different customer's prompt.

What good looks like

Azure OpenAI in Foundry Models documents this explicitly: your prompts, completions, embeddings, and training data are not available to other customers, are not available to OpenAI or other providers, and are not used to train any generative AI foundation model without your permission. That is the standard to hold every vendor to.

Where the market is silent

Many fashion-specific AI tools describe their outputs in detail but say nothing about their training infrastructure. If a vendor's documentation does not address cross-customer contamination, ask the question in writing and require a written answer before the pilot.

Best for: Any brand uploading proprietary technical files. Limits: Isolation claims are only as strong as the audit rights that back them up — see Question 5.


Question 2: Will my data or any derived weights be used to improve your product for other customers?

What you are really asking

Even if your raw files are isolated, a vendor might use aggregate signals from your usage — error rates, correction patterns, output preferences — to improve a shared model. 'We do not share your data' and 'we do not learn from your data to benefit others' are different statements.

What good looks like

The Azure OpenAI documentation states that customer data, prompts, and completions are not used to improve Microsoft or third-party products or services without explicit permission. Ask your vendor for an equivalent commitment, in the same plain language, in the data processing agreement.

What to watch for

Vague phrases like 'we may use anonymised data to improve our services' are a red flag. Anonymisation of pattern geometry is not a solved problem — a grading table can be re-identified by silhouette if the vendor also holds your brand metadata.

Best for: Brands with a distinctive construction signature they treat as IP. Limits: This protection is only enforceable if it appears in the contract, not just the marketing site.


Question 3: Who owns the model weights derived from my archive?

What you are really asking

When a vendor fine-tunes a model on your DXF library, the resulting weights encode your brand's construction logic. Ownership of those weights determines whether you can take them with you, whether the vendor can reuse them, and what happens if the vendor is acquired.

What good looks like

The contract should state that any weights derived exclusively from your data are your intellectual property, or are held in escrow and deleted on exit. If the vendor uses a shared base model that it fine-tunes per customer, the agreement should distinguish between the base weights (vendor's) and the per-brand adaptation layer (yours).

Where the market is silent

Most fashion AI vendors do not address weight ownership in their standard terms. It is not a hostile question to ask — it is a basic IP hygiene question, and a vendor that cannot answer it has not thought through the enterprise use case.

Best for: Any brand that considers its pattern library a competitive asset. Limits: Weight portability also requires that the vendor uses an open or exportable model format — lock-in at the infrastructure level can make contractual ownership hollow.


Question 4: What happens to my data and the derived weights when I leave?

What you are really asking

Exit rights are where data governance commitments are tested. A vendor that holds your weights after termination — even in a 'deactivated' state — retains leverage over you and a potential liability if it is breached.

What the law already requires (for personal data)

GDPR Article 28 requires processors to delete or return all personal data at the end of the service relationship, and to delete existing copies unless law requires retention. Even if your pattern files contain no personal data, this is the standard to demand contractually: deletion or return, with a written confirmation, within a defined window.

What to ask for

Request a data-return schedule (format, timeline, responsible party), a deletion certificate, and a clause that covers derived weights explicitly — not just raw input files. Ask whether backups are included in the deletion scope.

Best for: All enterprise customers, regardless of jurisdiction. Limits: Deletion certificates are only as reliable as the vendor's internal data-mapping — ask how they track where your data has propagated across their infrastructure.


Question 5: Where is my data processed, and which regulatory frameworks apply?

What you are really asking

Data residency determines which courts have jurisdiction, which regulators can investigate, and which data-transfer mechanisms are required. For EU brands, processing outside the EEA without an adequacy decision or standard contractual clauses is a GDPR violation even for non-personal technical data if it is bundled with any personal data.

The AI Act layer

The EU AI Act adds a further requirement for high-risk AI systems: training, validation, and testing data must be subject to data governance and management practices appropriate for the intended purpose. If the vendor's tool is used in a context that qualifies as high-risk under the Act — for example, automated decisions affecting workers — its data governance must meet that standard.

What to ask for

Request the vendor's data processing agreement, a list of sub-processors and their locations, and confirmation of the legal mechanism for any cross-border transfers. For EU procurement, the European Commission's updated AI model contractual clauses, published in March 2025, provide a peer-reviewed template that covers both high-risk and non-high-risk AI systems.

Best for: EU-based brands and any brand selling into the EU market. Limits: Contractual clauses do not substitute for technical controls — residency commitments should be backed by infrastructure evidence, not just DPA language.


Question 6: How is all of this contractually evidenced, and can I audit it?

What you are really asking

A vendor can make any claim in a sales call. What matters is whether the commitment appears in a signed, enforceable document and whether you have the right to verify it independently.

What GDPR Article 28 requires of processors

The regulation requires processors to make available all information necessary to demonstrate compliance and to allow audits, including inspections, conducted by the controller or a mandated auditor. Demand the same right in any AI vendor agreement, even where the data is not personal.

What good looks like

A mature vendor will offer: a data processing agreement that addresses training data specifically (not just operational data), a right to audit or to commission a third-party audit, an incident notification clause covering model-level breaches (not just file-level breaches), and a sub-processor list with update notifications.

Where the market is silent

Many fashion AI vendors offer a DPA on request but have not updated it to cover model training. If the DPA was written for a SaaS tool that stores files, it almost certainly does not address weight ownership, derived-model deletion, or cross-customer contamination. Ask the vendor's legal team — not the sales team — to confirm in writing that the DPA covers training data specifically.

Best for: Any organisation that will rely on the vendor's outputs in a production workflow. Limits: Audit rights are only useful if you have the technical capacity to exercise them — consider engaging a specialist assessor.


Which platforms document their answers?

The table below maps the six questions to the platforms covered in this article. 'Documented' means a public or contractually available statement addresses the point. 'Ask in writing' means the platform does not address the point publicly and you should require a written commitment before proceeding.

Question Azure OpenAI (Microsoft) FashionINSTA Style3D Centric PLM (Dassault) Browzwear
Tenant isolation Documented (public) Per-brand private environment Ask in writing Ask in writing Ask in writing
No cross-customer training Documented (public) Per-brand model, not shared Ask in writing Ask in writing Ask in writing
Weight ownership Ask in writing Ask in writing Ask in writing Ask in writing Ask in writing
Exit and deletion Documented (GDPR DPA) Ask in writing Ask in writing Ask in writing Ask in writing
Data residency Documented (Azure regions) Ask in writing Ask in writing Ask in writing Ask in writing
Audit rights Documented (GDPR DPA) Ask in writing Ask in writing Documented (enterprise DPA) Ask in writing

'Ask in writing' does not mean a vendor fails the question — it means the answer is not yet public and must be obtained contractually.


The platforms in brief

Azure OpenAI

Azure OpenAI in Foundry Models is Microsoft's cloud-hosted access layer for OpenAI foundation models, with fine-tuning, agent orchestration, and enterprise security tooling built in. Its public data-privacy documentation is the most detailed of any platform in this list, making it a useful benchmark for what 'documented' looks like. It is a general-purpose AI infrastructure layer, not a fashion-specific tool — brands use it to build or host their own models rather than as a ready-made pattern intelligence product.

Best for: Brands building proprietary AI applications on a well-governed cloud infrastructure. Limits: It is infrastructure, not a fashion workflow — you bring your own models, prompts, and integration work.

FashionINSTA

FashionINSTA is a private per-brand AI platform that learns from a brand's own DXF pattern archive in a tenant-isolated environment. It delivers production-ready patterns, tech packs, BOM, cost estimates, feasibility analysis, and 3D-compatible DXF outputs (compatible with CLO3D, Gerber, Browzwear, and Lectra) via a graph of specialist agents. Because each deployment is trained exclusively on one brand's archive, the cross-customer contamination risk that applies to shared-model platforms does not apply in the same way — though weight ownership and exit terms should still be confirmed in the service agreement. It is available as an enterprise deployment.

Best for: Large brands that want to leverage their own pattern library in a private, isolated environment and receive production-ready patterns, tech packs, and 3D previews as outputs. Limits: Enterprise-oriented by design — not the right fit for a solo designer or a small studio without an existing DXF archive.

Style3D

Style3D provides an AI and 3D platform for the apparel industry covering garment design, 3D digital sampling, fabric digitisation, manufacturing collaboration, and physics-based simulation. It also offers AI agent tools for measurement, design, try-on, and recommendation. Its data governance documentation is not detailed in public-facing materials, so brands considering it for training on proprietary data should request a full DPA and sub-processor list before proceeding.

Best for: Manufacturers and brands that want an integrated 3D simulation and AI design environment, particularly for digital sampling workflows. Limits: Public documentation on training-data isolation and weight ownership is limited — procurement teams will need to negotiate these terms directly.

Centric PLM

Centric PLM, part of Dassault Systemes, is an AI-powered product lifecycle management platform covering fashion, cosmetics, food and beverage, and retail. It manages product development workflows including tech packs, approvals, and supplier collaboration, and has expanded into planning, pricing, and product experience management. As an enterprise PLM, it typically operates under detailed DPAs — but those agreements are negotiated per customer and are not public, so training-data-specific terms need to be confirmed in the contract.

Best for: Brands that need an end-to-end PLM covering the full product development lifecycle, from concept through supplier collaboration. Limits: PLM-focused rather than pattern-intelligence-focused — it manages product data rather than training AI on pattern geometry.

Browzwear

Browzwear offers a 3D digital product creation platform — VStitcher, Lotta, and SmartDesign — that enables fashion brands to design garments using physics-based simulation, validate fit with AI, collaborate on approvals, and generate technical and e-commerce assets. Its AI capabilities are focused on fit validation and on-model imagery rather than on training from a brand's own pattern archive, which changes the data-governance question somewhat — but any platform that processes your technical files should still be asked about data residency and sub-processors.

Best for: Brands focused on 3D digital sampling, fit validation, and reducing physical prototypes. Limits: Not designed for training on a proprietary pattern archive — its AI layer operates on simulation and imagery rather than on a brand's historical DXF library.


FAQ

What does 'tenant isolation' mean in the context of AI training? It means your training data, fine-tuning runs, and model weights are held in a technically separate environment from other customers. No other customer's queries can draw on your data, and your outputs cannot be influenced by theirs.

Does GDPR apply to pattern files that contain no personal data? GDPR applies to personal data, so pattern geometry alone is not covered. However, if pattern files are bundled with any personal data — designer names, supplier contacts — the whole dataset may be in scope. Regardless, GDPR Article 28 sets a useful contractual standard for deletion and audit rights that applies to any sensitive data.

Can I ask a vendor to delete the model weights it trained on my data? Yes, and you should ask for this in writing before signing. The contract should specify which weights are covered, the deletion timeline, and how deletion will be confirmed. Not all vendors have addressed this in their standard terms.

What are the EU AI model contractual clauses? They are a set of peer-reviewed template contract terms published by the European Commission's procurement community to help public and private buyers include AI-specific protections — covering data governance, transparency, and liability — in vendor agreements. An updated version was released in early 2025.

Which question is most commonly skipped in fashion AI pilots? In our experience, weight ownership is the question most often left unresolved at the pilot stage. Brands focus on output quality during the pilot and address contract terms later — by which point the vendor has already trained on the archive and the leverage has shifted.

Share this article: