Data Processing Agreement – Clippter

Last updated: 1 September 2026

This Data Processing Agreement (“DPA”) is entered into between the Customer (controller) and Movie Moose Holding B.V., trading as Clippter (processor), and forms an integral part of the Terms and Conditions. It applies where Clippter processes personal data on behalf of the Customer in the Platform, including the client portal.

EU hosting and no AI training

Customer Data is stored in the EEA (database and authentication in Frankfurt, Germany; review video in Germany; media objects in Western Europe). Clippter does not use Customer Data to train AI or machine-learning models and does not permit sub-processors to do so for their generally available models.

1. Definitions and roles

Terms used in this DPA have the meaning given in the GDPR and in the Terms. The Customer is the controller of Customer Data. Clippter is the processor. Where a term is not defined here, GDPR Article 4 applies.

This DPA implements Article 28 GDPR. It does not apply to data of which Clippter is itself controller (account, billing, marketing-website visitors), which is described in the Privacy Statement.

2. Subject matter, duration and nature

Clippter processes Customer Data to provide the Platform: hosting, storage, transmission, display, backup and related support. Processing lasts for the term of the Agreement and the deletion period in clause 11. The nature is automated processing in a multi-tenant SaaS environment. Details are in Schedule 1.

3. Instructions

Clippter processes Customer Data only on documented instructions from the Customer, including the Agreement, configuration of the workspace, and this DPA, unless EU or Member State law requires otherwise (in which case Clippter informs the Customer unless that law prohibits such information).

The Customer warrants that its instructions are lawful and that it has a valid legal basis (including for footage of identifiable persons) for the processing.

4. Confidentiality

Persons authorised to process Customer Data are bound by confidentiality and receive access only as needed to operate and support the Platform.

5. Security

Clippter implements appropriate technical and organisational measures pursuant to Article 32 GDPR, as described in Schedule 3 and on the Security & Data page. Measures may evolve provided they do not materially reduce the overall level of protection.

6. Sub-processors

The Customer authorises the sub-processors listed in Schedule 2. Clippter will impose data-protection obligations on sub-processors that are no less protective than this DPA, insofar as applicable to their processing.

Clippter remains responsible for the performance of sub-processors. For a new sub-processor that will process Customer Data, Clippter will update Schedule 2 / the Privacy Statement and give the Customer a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected service.

7. Assistance with data-subject rights

Taking into account the nature of the processing, Clippter assists the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligations to respond to requests under GDPR Chapter III. Requests received directly by Clippter that relate to Customer Data will be forwarded to the Customer without undue delay.

8. Personal data breaches

Clippter will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data (target: within 48 hours), with the information reasonably available to help the Customer meet Articles 33 and 34 GDPR. Notification of the Autoriteit Persoonsgegevens, where required, is the Customer's responsibility as controller, except where Clippter is independently required to notify as controller for its own data.

9. Assistance, DPIAs and audits

Clippter assists the Customer with data-protection impact assessments and prior consultation (Arts. 35–36 GDPR) insofar as the information is available to Clippter and relates to the Platform.

Upon written request, Clippter makes available information reasonably necessary to demonstrate compliance with Article 28. Audits are limited to once per 12 months unless a competent authority or a documented breach reasonably requires more, and shall be conducted during business hours with reasonable notice, without disrupting operations or exposing other customers' data. The Customer may alternatively accept current third-party audit reports or security documentation of Clippter or its infrastructure providers.

10. International transfers

Primary Customer Data (database, authentication, review video, media objects) is hosted in the EEA. Where a Schedule 2 provider processes limited personal data outside the EEA, Clippter uses an adequate transfer tool, typically the European Commission Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

11. Return and deletion

After the end of processing services, Clippter will, at the choice of the Customer, delete or return Customer Data, and delete existing copies, unless Union or Member State law (including the Dutch fiscale bewaarplicht for invoices) requires storage. The Customer should export data before account closure. Deletion from active systems typically occurs within thirty (30) days after closure, and from backups in accordance with the backup rotation of the infrastructure provider.

12. Liability and duration

Liability under this DPA follows Article 13 of the Terms, without prejudice to Article 82 GDPR. This DPA lasts for the term of the Agreement and survives as long as Clippter processes Customer Data. It is governed by Dutch law; disputes follow the Terms (Amsterdam courts).

Contact: support@clippter.comMovie Moose Holding B.V., Thierensweg 8, 1411EX Naarden, The Netherlands, KvK 88876926.

Schedule 1 — Description of processing

ItemDescription
Subject matterHosting and operation of the Clippter workspace and client portal
DurationTerm of the Agreement plus the deletion period in clause 11
NatureCollection, storage, organisation, retrieval, transmission, display, backup, deletion
PurposeProvide CRM, quoting, projects, time tracking, finance, review, media library and portal features instructed by the Customer
Types of personal dataIdentity and contact data; professional data; project and commercial data; images, video and audio that may include faces and voices; comments; usage logs as generated by the Customer’s use
Special categoriesNot intended. The Customer shall not instruct processing of special-category data unless it has a lawful basis and has agreed additional measures in writing
Data subjectsCustomer staff; clients and their staff; crew and freelancers; other persons appearing in footage or records uploaded by the Customer

Schedule 2 — Authorised sub-processors

Current list (also in the Privacy Statement). Location refers to the primary processing region for Customer Data where applicable.

ProviderRoleLocation
Supabase, Inc.Database, authenticationFrankfurt, Germany
Vercel Inc.Application hostingEU / global edge
Bunny.netReview videoGermany
Cloudflare, Inc. (R2)Media object storageWestern Europe
Stripe Payments Europe, Ltd.Payments (billing contacts)Ireland / United States
ResendTransactional emailUnited States
Sentry (Functional Software, Inc.)Error diagnosticsGermany

Google (optional sign-in), Calendly (demo booking) and advertising tags process Clipptercontroller data or optional Customer-initiated connections; they are described in the Privacy Statement. Integrations the Customer pastes into a project (YouTube, Frame.io, Dropbox, and similar) are chosen by the Customer.

Schedule 3 — Technical and organisational measures

  • TLS in transit; encryption at rest with EEA hosting providers
  • Tenant isolation (account scoping, row-level security patterns, CI audit)
  • Optional TOTP MFA for agency members and per portal company
  • Invite-only client portal; no portal file upload; optional disable of client download
  • Hashed passwords; security emails on credential and MFA changes
  • HSTS, frame deny, CSP and related browser security headers
  • EEA primary hosting for database, review video and media objects
  • No generative-AI processing of Customer Data; no training of models on Customer Data
  • EEA backups maintained by the database infrastructure provider
  • Breach notification process as in clause 8