Privacy Statement – Clippter

Last updated: 1 September 2026

EU hosting — your workspace and media stay in Europe

Clippter is built for EU and Dutch agencies. Primary production data is hosted in the European Economic Area (EEA), with core systems in Germany:

  • Application database and authentication (Supabase): Frankfurt, Germany (AWS region eu-central-1).
  • Review video (Bunny Stream): primary storage in Germany.
  • Approved media library, review images and comment snapshots (Cloudflare R2): Western Europe.
  • Application hosting (Vercel): European infrastructure, including Frankfurt.
  • Error monitoring (Sentry): European ingest endpoint in Germany.

Supporting services such as payments and transactional email may process limited personal data outside the EEA. Those transfers are described in sections 8 and 11 and are covered by GDPR transfer tools (including Standard Contractual Clauses). They do not move your workspace database or client media out of the EEA.

No AI training on your data

Clippter does not currently offer generative AI product features. We do not use Customer Data, client portal content, review media, CRM records or other workspace content to train artificial intelligence or machine learning models.

We do not send that content to generative AI providers (including OpenAI, Anthropic or similar services) for model training or model improvement. We do not permit sub-processors to use Customer Data to train generally available AI models.

If we ever introduce optional assistive features (for example draft summaries), they will be off by default, will not train models on your media, and will be described in this Privacy Statement before they are switched on for your workspace.

1. Introduction and controller

This Privacy Statement explains how Clippter (a trade name of Movie Moose Holding B.V., “Clippter”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you visit https://clippter.com, use the Clippter platform at https://app.clippter.com, use the client portal, book a demo, or otherwise communicate with us.

Movie Moose Holding B.V. is a private limited company established in the Netherlands. Processing of personal data is governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR” / AVG), the Dutch GDPR Implementation Act (Uitvoeringswet AVG, “UAVG”) and, for cookies and similar technologies, Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet).

Official details:

  • Company: Movie Moose Holding B.V. (trade name Clippter)
  • Address: Thierensweg 8, 1411EX Naarden, The Netherlands
  • Chamber of Commerce (KvK): 88876926
  • Email: support@clippter.com

We are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy requests go to support@clippter.com.

2. Two distinct roles: controller and processor

Under the GDPR, Clippter acts in two different roles. It is important to keep them separate.

2.1 Clippter as controller

We are the controller of personal data that we collect about you as a user of the marketing website, as an account holder, as a billing contact, or as someone who books a demo or contacts support. This Privacy Statement is written primarily for that relationship.

2.2 Clippter as processor

When an organisation (the Customer) uses Clippter to run its video agency — including CRM, quotes, projects, time tracking, finance, crew, review media and client-portal content — that organisation is the controller of the personal data it uploads or generates in its workspace (“Customer Data”). Clippter is the processor. That processing is governed by our Data Processing Agreement (DPA), which forms part of the Terms and Conditions.

If you are a client, freelancer or other invitee of a Customer, the Customer decides what data is stored about you. Requests that relate only to Customer Data will be forwarded to that organisation. The security, EU-hosting, no-AI-training, transfer and breach commitments in this Privacy Statement also apply to Customer Data.

3. Personal data we collect

We collect personal data in the following categories.

A. Account data

When you create an account we collect:

  • Name and email address (required)
  • Password (stored as a salted hash; never stored or displayed in plain text)
  • Optional sign-in with Google (Google account identifier and email)
  • Workspace / organisation name and your role in that workspace

B. Profile and workspace administration

  • Optional profile photo and display name
  • Team invitations, member roles and permission settings
  • For workspace administrators: organisation details, billing contact, VAT number and registered address
  • Language and appearance preferences

C. Customer Data uploaded through the Platform

As part of normal use, Customers may enter or upload CRM records, quotes, invoices, project files, time entries, comments, images, video, audio and documents. Where these contain personal data of identifiable individuals (including faces and voices in footage), that content is Customer Data and is governed primarily by the DPA. Clippter does not claim ownership of Customer Data.

D. Client portal

Portal users are invited by a Customer. We process their email address, name, authentication data, optional MFA status, and their review activity (comments, approvals, views) on projects the Customer has shared. Portal users cannot upload files into the portal. See section 5.

E. Communications

We retain support emails, in-product notifications and messages you send to us, including demo booking details.

F. Payment and billing

We collect billing contact details, company details and VAT number. Payment card details are processed by Stripe and are not stored on Clippter systems.

G. Demo bookings

If you book a demo, the calendar is provided by Calendly. We (and Calendly) receive your name, email, company name if provided, and the meeting time, so we can hold the call and follow up.

H. Automatically collected technical data

  • IP address (security, fraud prevention, approximate region)
  • Device, browser and operating system
  • Pages and features used, approximate timestamps, and error events
  • Diagnostic reports when something fails, which may include an account identifier and the actions leading up to the error

I. Job applications

If you apply for a role, we process the CV and contact details you submit, to consider you for that opening and potential future roles.

4. How we use personal data and legal bases

We process personal data only where a GDPR Article 6 legal basis applies. Depending on the purpose:

PurposeLegal basis
Account creation, Platform delivery, seats, billing and supportPerformance of a contract (Art. 6(1)(b))
Security, fraud prevention, abuse detection, internal logsLegitimate interests (Art. 6(1)(f))
Marketing-website analytics (Google Analytics via Tag Manager on clippter.com)Consent (Art. 6(1)(a)) — cookie banner on the marketing website
Advertising measurement on the marketing website (Google Ads, Meta, Reddit, LinkedIn)Consent (Art. 6(1)(a)) — cookie banner on the marketing website
Marketing emails about the product, where you opted inConsent (Art. 6(1)(a)), withdrawable at any time
Tax, accounting and responding to lawful requestsLegal obligation (Art. 6(1)(c)), including Dutch fiscal retention
Processing Customer Data in a workspaceProcessor instructions of the Customer (Art. 28 GDPR); the Customer determines the basis

Providing an email address and billing details is required to perform the subscription contract. Without that data we cannot provide the Platform.

We do not use personal data for automated decision-making that produces legal or similarly significant effects without human involvement (GDPR Art. 22).

5. Client portal

The client portal is a separate, invite-only environment. Portal users see only projects and deliverables that the agency has shared. They do not access the agency workspace (CRM, rates, finance, team tools or other clients).

Upload is one-way: agency → Clippter → client. Portal users can review, comment and approve shared video. They cannot upload documents, PDFs, media or other files into the portal. Downloads for clients can be disabled per project.

The agency can require multi-factor authentication (TOTP) for portal users of a specific client company. Agency MFA and portal MFA are independent settings.

6. Sub-processors and service providers

We use a limited number of providers to operate the Platform. Each provider that processes personal data on our behalf is bound by a written data processing agreement and may only process data as instructed. A named list also forms Schedule 2 of the DPA. Changes that affect Customer Data are handled under the DPA.

ProviderPurposeLocation
Supabase, Inc.Database, authentication, related backend servicesFrankfurt, Germany / EEA
Vercel Inc.Application hosting and deliveryEU (including Frankfurt); global edge
Bunny.net (B-Cdn Ltd / BunnyWay)Review video encoding and streamingGermany (primary storage)
Cloudflare, Inc. (R2)Object storage for approved media, review images and snapshotsWestern Europe
Stripe Payments Europe, Ltd.Subscription billing and payment processingIreland (primary); United States under Stripe DPA / SCCs
ResendTransactional and service emailUnited States, with SCCs
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsGermany (EU ingest)
Google Ireland Ltd. / Google LLCOptional Google sign-in; Tag Manager / Analytics / Ads on the marketing website with consentEU / United States
Calendly, LLCDemo booking calendarUnited States, with SCCs
Meta Platforms Ireland Ltd.; Reddit; LinkedIn IrelandAdvertising measurement on the marketing website — with consent onlyIreland / United States

Workspace administrators may also paste third-party review or file links (for example YouTube, Frame.io, Dropbox) into a project. Data is shared with those services only when the Customer chooses to use them; their own terms apply.

7. Cookies and similar technologies

Cookies are small files stored on your device. Under Article 11.7a of the Dutch Telecommunications Act, non-essential cookies require consent. The cookie banner applies to the marketing website (clippter.com and www.clippter.com). When you first visit that site, you can accept all, reject non-essential cookies, or customise. You can change that choice later via Cookie preferences in the footer.

The application at app.clippter.com (including login, signup and the logged-in workspace) does not show a cookie banner and does not load Google Tag Manager, analytics or advertising tags. Only strictly necessary cookies are used there (session, security, language/theme).

CategoryWhat it doesConsent
Strictly necessaryAuthenticated session, security, language/theme, storing your cookie choiceNo (required to run the Platform)
AnalyticsGoogle Tag Manager / Google Analytics on the marketing website — visits to clippter.comYes — off until you allow Analytics
MarketingGoogle Ads, Meta Pixel, Reddit and LinkedIn tags on the marketing websiteYes — off until you allow Marketing

Analytics and marketing scripts are not loaded until you give the relevant consent. Withdrawing consent stops further processing; it does not erase processing that already took place. You can also block cookies in your browser; blocking strictly necessary cookies will prevent login.

Demo pages load Calendly so you can book a meeting on our site. Calendly may set its own cookies to run the booking widget. That is a functional booking flow, not advertising.

8. Sharing and disclosure

We do not sell personal data. We share it only in these situations:

  • Within your workspace: according to roles and permissions set by the Customer.
  • Shared links: if a Customer shares a review or page via a link, that content is visible to anyone with the link.
  • Service providers: the sub-processors in section 6.
  • Legal requests: when required by law, court order or a lawful government request, limited to what is required.
  • Safety: where necessary to protect users, the public or Clippter.
  • Business transfers: in a merger, acquisition or sale of assets, with reasonable notice where required.

9. International transfers

Primary workspace data, authentication, review video and media storage are hosted in the EEA, as described at the top of this statement. Some supporting providers (Stripe, Resend, Calendly, Google, advertising partners) may process limited personal data in the United States.

Where such transfers occur, we rely on the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where the recipient is certified, and supplementary measures including encryption in transit and at rest. A copy of the applicable transfer mechanism can be requested at support@clippter.com.

10. Retention

We keep personal data only as long as needed for the purposes in this statement.

CategoryRetention
Account dataWhile the account is active; deleted or anonymised within 30 days after account deletion, unless a legal duty applies
Workspace data and Customer DataFor the Customer’s subscription; after termination, export then deletion as described in the DPA (typically within 30 days after closure of the account)
Payment and invoicing recordsSeven (7) years, as required by Dutch tax and accounting law (fiscale bewaarplicht)
Support communicationsFor the duration of the relationship, then on request, subject to legal retention
Security and audit logsUp to twelve (12) months
Demo booking dataAs long as needed to hold and follow up the meeting, then deleted unless you become a customer
Job applicationsFor the recruitment process and up to one year thereafter unless you ask us to delete sooner
Aggregated / anonymised analyticsMay be kept indefinitely; no longer personal data

11. Security

We implement technical and organisational measures appropriate to the risk (GDPR Art. 32), including TLS in transit, encryption at rest with our hosting providers, row-level security and account-scoped access, optional MFA, and data processing agreements with sub-processors. Details are on our Security & Data page and in Schedule 3 of the DPA.

If a personal data breach is likely to result in a risk to individuals, we will notify the Dutch Data Protection Authority without undue delay and, where required, within 72 hours of becoming aware (Art. 33 GDPR). Where Customer Data is affected, we will notify the Customer as controller without undue delay so that the Customer can meet its own obligations.

12. Your GDPR rights

You have the following rights regarding personal data of which we are the controller:

  • Access (Art. 15): a copy of your personal data
  • Rectification (Art. 16): correction of inaccurate or incomplete data
  • Erasure (Art. 17): deletion, subject to legal retention (for example invoices)
  • Restriction (Art. 18): in the circumstances set out in the GDPR
  • Portability (Art. 20): a structured, commonly used, machine-readable copy of data you provided
  • Objection (Art. 21): to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent (Art. 7(3)): where processing is based on consent, including cookies and marketing email

To exercise these rights, email support@clippter.com. We will verify your identity. We respond within one month, and may extend by up to two months for complex requests (we will tell you within the first month). Requests about Customer Data are forwarded to the relevant Customer.

13. Right to lodge a complaint

You may lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority (Postbus 93374, 2509 AJ Den Haag, The Netherlands). Website: https://www.autoriteitpersoonsgegevens.nl. If you live in another EU/EEA member state you may also contact your local authority. We encourage you to contact us first so we can try to resolve the issue.

14. Children

The Platform is intended for business users. We do not knowingly collect personal data from anyone under sixteen (UAVG). If you believe we have, contact support@clippter.com and we will delete it.

15. Changes to this Privacy Statement

We may update this statement when the Platform, our providers or the law changes. We will post the new version on this page and update the date. For changes that materially affect your rights or our processing, we will also email the address on your account. The Dutch version is provided for convenience; if you contracted in English, the English text of the Terms prevails for the contract, while this Privacy Statement describes our processing under the GDPR in both languages.

16. Contact

Movie Moose Holding B.V.
Thierensweg 8, 1411EX Naarden, The Netherlands
KvK 88876926
Email: support@clippter.com

Related documents: Terms, Security & Data, Data Processing Agreement.