Data Processing Agreement – Clippter
Last updated: 1 September 2026
This Data Processing Agreement (“DPA”) is entered into between the Customer (controller) and Movie Moose Holding B.V., trading as Clippter (processor), and forms an integral part of the Terms and Conditions. It applies where Clippter processes personal data on behalf of the Customer in the Platform, including the client portal.
EU hosting and no AI training
Customer Data is stored in the EEA (database and authentication in Frankfurt, Germany; review video in Germany; media objects in Western Europe). Clippter does not use Customer Data to train AI or machine-learning models and does not permit sub-processors to do so for their generally available models.
1. Definitions and roles
Terms used in this DPA have the meaning given in the GDPR and in the Terms. The Customer is the controller of Customer Data. Clippter is the processor. Where a term is not defined here, GDPR Article 4 applies.
This DPA implements Article 28 GDPR. It does not apply to data of which Clippter is itself controller (account, billing, marketing-website visitors), which is described in the Privacy Statement.
2. Subject matter, duration and nature
Clippter processes Customer Data to provide the Platform: hosting, storage, transmission, display, backup and related support. Processing lasts for the term of the Agreement and the deletion period in clause 11. The nature is automated processing in a multi-tenant SaaS environment. Details are in Schedule 1.
3. Instructions
Clippter processes Customer Data only on documented instructions from the Customer, including the Agreement, configuration of the workspace, and this DPA, unless EU or Member State law requires otherwise (in which case Clippter informs the Customer unless that law prohibits such information).
The Customer warrants that its instructions are lawful and that it has a valid legal basis (including for footage of identifiable persons) for the processing.
4. Confidentiality
Persons authorised to process Customer Data are bound by confidentiality and receive access only as needed to operate and support the Platform.
5. Security
Clippter implements appropriate technical and organisational measures pursuant to Article 32 GDPR, as described in Schedule 3 and on the Security & Data page. Measures may evolve provided they do not materially reduce the overall level of protection.
6. Sub-processors
The Customer authorises the sub-processors listed in Schedule 2. Clippter will impose data-protection obligations on sub-processors that are no less protective than this DPA, insofar as applicable to their processing.
Clippter remains responsible for the performance of sub-processors. For a new sub-processor that will process Customer Data, Clippter will update Schedule 2 / the Privacy Statement and give the Customer a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected service.
7. Assistance with data-subject rights
Taking into account the nature of the processing, Clippter assists the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligations to respond to requests under GDPR Chapter III. Requests received directly by Clippter that relate to Customer Data will be forwarded to the Customer without undue delay.
8. Personal data breaches
Clippter will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data (target: within 48 hours), with the information reasonably available to help the Customer meet Articles 33 and 34 GDPR. Notification of the Autoriteit Persoonsgegevens, where required, is the Customer's responsibility as controller, except where Clippter is independently required to notify as controller for its own data.
9. Assistance, DPIAs and audits
Clippter assists the Customer with data-protection impact assessments and prior consultation (Arts. 35–36 GDPR) insofar as the information is available to Clippter and relates to the Platform.
Upon written request, Clippter makes available information reasonably necessary to demonstrate compliance with Article 28. Audits are limited to once per 12 months unless a competent authority or a documented breach reasonably requires more, and shall be conducted during business hours with reasonable notice, without disrupting operations or exposing other customers' data. The Customer may alternatively accept current third-party audit reports or security documentation of Clippter or its infrastructure providers.
10. International transfers
Primary Customer Data (database, authentication, review video, media objects) is hosted in the EEA. Where a Schedule 2 provider processes limited personal data outside the EEA, Clippter uses an adequate transfer tool, typically the European Commission Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
11. Return and deletion
After the end of processing services, Clippter will, at the choice of the Customer, delete or return Customer Data, and delete existing copies, unless Union or Member State law (including the Dutch fiscale bewaarplicht for invoices) requires storage. The Customer should export data before account closure. Deletion from active systems typically occurs within thirty (30) days after closure, and from backups in accordance with the backup rotation of the infrastructure provider.
12. Liability and duration
Liability under this DPA follows Article 13 of the Terms, without prejudice to Article 82 GDPR. This DPA lasts for the term of the Agreement and survives as long as Clippter processes Customer Data. It is governed by Dutch law; disputes follow the Terms (Amsterdam courts).
Contact: support@clippter.com — Movie Moose Holding B.V., Thierensweg 8, 1411EX Naarden, The Netherlands, KvK 88876926.
Schedule 1 — Description of processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of the Clippter workspace and client portal |
| Duration | Term of the Agreement plus the deletion period in clause 11 |
| Nature | Collection, storage, organisation, retrieval, transmission, display, backup, deletion |
| Purpose | Provide CRM, quoting, projects, time tracking, finance, review, media library and portal features instructed by the Customer |
| Types of personal data | Identity and contact data; professional data; project and commercial data; images, video and audio that may include faces and voices; comments; usage logs as generated by the Customer’s use |
| Special categories | Not intended. The Customer shall not instruct processing of special-category data unless it has a lawful basis and has agreed additional measures in writing |
| Data subjects | Customer staff; clients and their staff; crew and freelancers; other persons appearing in footage or records uploaded by the Customer |
Schedule 2 — Authorised sub-processors
Current list (also in the Privacy Statement). Location refers to the primary processing region for Customer Data where applicable.
| Provider | Role | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication | Frankfurt, Germany |
| Vercel Inc. | Application hosting | EU / global edge |
| Bunny.net | Review video | Germany |
| Cloudflare, Inc. (R2) | Media object storage | Western Europe |
| Stripe Payments Europe, Ltd. | Payments (billing contacts) | Ireland / United States |
| Resend | Transactional email | United States |
| Sentry (Functional Software, Inc.) | Error diagnostics | Germany |
Google (optional sign-in), Calendly (demo booking) and advertising tags process Clipptercontroller data or optional Customer-initiated connections; they are described in the Privacy Statement. Integrations the Customer pastes into a project (YouTube, Frame.io, Dropbox, and similar) are chosen by the Customer.
Schedule 3 — Technical and organisational measures
- TLS in transit; encryption at rest with EEA hosting providers
- Tenant isolation (account scoping, row-level security patterns, CI audit)
- Optional TOTP MFA for agency members and per portal company
- Invite-only client portal; no portal file upload; optional disable of client download
- Hashed passwords; security emails on credential and MFA changes
- HSTS, frame deny, CSP and related browser security headers
- EEA primary hosting for database, review video and media objects
- No generative-AI processing of Customer Data; no training of models on Customer Data
- EEA backups maintained by the database infrastructure provider
- Breach notification process as in clause 8