Privacy Statement – Clippter
Last updated: 1 September 2026
EU hosting — your workspace and media stay in Europe
Clippter is built for EU and Dutch agencies. Primary production data is hosted in the European Economic Area (EEA), with core systems in Germany:
- Application database and authentication (Supabase): Frankfurt, Germany (AWS region eu-central-1).
- Review video (Bunny Stream): primary storage in Germany.
- Approved media library, review images and comment snapshots (Cloudflare R2): Western Europe.
- Application hosting (Vercel): European infrastructure, including Frankfurt.
- Error monitoring (Sentry): European ingest endpoint in Germany.
Supporting services such as payments and transactional email may process limited personal data outside the EEA. Those transfers are described in sections 8 and 11 and are covered by GDPR transfer tools (including Standard Contractual Clauses). They do not move your workspace database or client media out of the EEA.
No AI training on your data
Clippter does not currently offer generative AI product features. We do not use Customer Data, client portal content, review media, CRM records or other workspace content to train artificial intelligence or machine learning models.
We do not send that content to generative AI providers (including OpenAI, Anthropic or similar services) for model training or model improvement. We do not permit sub-processors to use Customer Data to train generally available AI models.
If we ever introduce optional assistive features (for example draft summaries), they will be off by default, will not train models on your media, and will be described in this Privacy Statement before they are switched on for your workspace.
1. Introduction and controller
This Privacy Statement explains how Clippter (a trade name of Movie Moose Holding B.V., “Clippter”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you visit https://clippter.com, use the Clippter platform at https://app.clippter.com, use the client portal, book a demo, or otherwise communicate with us.
Movie Moose Holding B.V. is a private limited company established in the Netherlands. Processing of personal data is governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR” / AVG), the Dutch GDPR Implementation Act (Uitvoeringswet AVG, “UAVG”) and, for cookies and similar technologies, Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet).
Official details:
- Company: Movie Moose Holding B.V. (trade name Clippter)
- Address: Thierensweg 8, 1411EX Naarden, The Netherlands
- Chamber of Commerce (KvK): 88876926
- Email: support@clippter.com
We are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy requests go to support@clippter.com.
2. Two distinct roles: controller and processor
Under the GDPR, Clippter acts in two different roles. It is important to keep them separate.
2.1 Clippter as controller
We are the controller of personal data that we collect about you as a user of the marketing website, as an account holder, as a billing contact, or as someone who books a demo or contacts support. This Privacy Statement is written primarily for that relationship.
2.2 Clippter as processor
When an organisation (the Customer) uses Clippter to run its video agency — including CRM, quotes, projects, time tracking, finance, crew, review media and client-portal content — that organisation is the controller of the personal data it uploads or generates in its workspace (“Customer Data”). Clippter is the processor. That processing is governed by our Data Processing Agreement (DPA), which forms part of the Terms and Conditions.
If you are a client, freelancer or other invitee of a Customer, the Customer decides what data is stored about you. Requests that relate only to Customer Data will be forwarded to that organisation. The security, EU-hosting, no-AI-training, transfer and breach commitments in this Privacy Statement also apply to Customer Data.
3. Personal data we collect
We collect personal data in the following categories.
A. Account data
When you create an account we collect:
- Name and email address (required)
- Password (stored as a salted hash; never stored or displayed in plain text)
- Optional sign-in with Google (Google account identifier and email)
- Workspace / organisation name and your role in that workspace
B. Profile and workspace administration
- Optional profile photo and display name
- Team invitations, member roles and permission settings
- For workspace administrators: organisation details, billing contact, VAT number and registered address
- Language and appearance preferences
C. Customer Data uploaded through the Platform
As part of normal use, Customers may enter or upload CRM records, quotes, invoices, project files, time entries, comments, images, video, audio and documents. Where these contain personal data of identifiable individuals (including faces and voices in footage), that content is Customer Data and is governed primarily by the DPA. Clippter does not claim ownership of Customer Data.
D. Client portal
Portal users are invited by a Customer. We process their email address, name, authentication data, optional MFA status, and their review activity (comments, approvals, views) on projects the Customer has shared. Portal users cannot upload files into the portal. See section 5.
E. Communications
We retain support emails, in-product notifications and messages you send to us, including demo booking details.
F. Payment and billing
We collect billing contact details, company details and VAT number. Payment card details are processed by Stripe and are not stored on Clippter systems.
G. Demo bookings
If you book a demo, the calendar is provided by Calendly. We (and Calendly) receive your name, email, company name if provided, and the meeting time, so we can hold the call and follow up.
H. Automatically collected technical data
- IP address (security, fraud prevention, approximate region)
- Device, browser and operating system
- Pages and features used, approximate timestamps, and error events
- Diagnostic reports when something fails, which may include an account identifier and the actions leading up to the error
I. Job applications
If you apply for a role, we process the CV and contact details you submit, to consider you for that opening and potential future roles.
4. How we use personal data and legal bases
We process personal data only where a GDPR Article 6 legal basis applies. Depending on the purpose:
| Purpose | Legal basis |
|---|---|
| Account creation, Platform delivery, seats, billing and support | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud prevention, abuse detection, internal logs | Legitimate interests (Art. 6(1)(f)) |
| Marketing-website analytics (Google Analytics via Tag Manager on clippter.com) | Consent (Art. 6(1)(a)) — cookie banner on the marketing website |
| Advertising measurement on the marketing website (Google Ads, Meta, Reddit, LinkedIn) | Consent (Art. 6(1)(a)) — cookie banner on the marketing website |
| Marketing emails about the product, where you opted in | Consent (Art. 6(1)(a)), withdrawable at any time |
| Tax, accounting and responding to lawful requests | Legal obligation (Art. 6(1)(c)), including Dutch fiscal retention |
| Processing Customer Data in a workspace | Processor instructions of the Customer (Art. 28 GDPR); the Customer determines the basis |
Providing an email address and billing details is required to perform the subscription contract. Without that data we cannot provide the Platform.
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human involvement (GDPR Art. 22).
5. Client portal
The client portal is a separate, invite-only environment. Portal users see only projects and deliverables that the agency has shared. They do not access the agency workspace (CRM, rates, finance, team tools or other clients).
Upload is one-way: agency → Clippter → client. Portal users can review, comment and approve shared video. They cannot upload documents, PDFs, media or other files into the portal. Downloads for clients can be disabled per project.
The agency can require multi-factor authentication (TOTP) for portal users of a specific client company. Agency MFA and portal MFA are independent settings.
6. Sub-processors and service providers
We use a limited number of providers to operate the Platform. Each provider that processes personal data on our behalf is bound by a written data processing agreement and may only process data as instructed. A named list also forms Schedule 2 of the DPA. Changes that affect Customer Data are handled under the DPA.
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, related backend services | Frankfurt, Germany / EEA |
| Vercel Inc. | Application hosting and delivery | EU (including Frankfurt); global edge |
| Bunny.net (B-Cdn Ltd / BunnyWay) | Review video encoding and streaming | Germany (primary storage) |
| Cloudflare, Inc. (R2) | Object storage for approved media, review images and snapshots | Western Europe |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Ireland (primary); United States under Stripe DPA / SCCs |
| Resend | Transactional and service email | United States, with SCCs |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Germany (EU ingest) |
| Google Ireland Ltd. / Google LLC | Optional Google sign-in; Tag Manager / Analytics / Ads on the marketing website with consent | EU / United States |
| Calendly, LLC | Demo booking calendar | United States, with SCCs |
| Meta Platforms Ireland Ltd.; Reddit; LinkedIn Ireland | Advertising measurement on the marketing website — with consent only | Ireland / United States |
Workspace administrators may also paste third-party review or file links (for example YouTube, Frame.io, Dropbox) into a project. Data is shared with those services only when the Customer chooses to use them; their own terms apply.
9. International transfers
Primary workspace data, authentication, review video and media storage are hosted in the EEA, as described at the top of this statement. Some supporting providers (Stripe, Resend, Calendly, Google, advertising partners) may process limited personal data in the United States.
Where such transfers occur, we rely on the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where the recipient is certified, and supplementary measures including encryption in transit and at rest. A copy of the applicable transfer mechanism can be requested at support@clippter.com.
10. Retention
We keep personal data only as long as needed for the purposes in this statement.
| Category | Retention |
|---|---|
| Account data | While the account is active; deleted or anonymised within 30 days after account deletion, unless a legal duty applies |
| Workspace data and Customer Data | For the Customer’s subscription; after termination, export then deletion as described in the DPA (typically within 30 days after closure of the account) |
| Payment and invoicing records | Seven (7) years, as required by Dutch tax and accounting law (fiscale bewaarplicht) |
| Support communications | For the duration of the relationship, then on request, subject to legal retention |
| Security and audit logs | Up to twelve (12) months |
| Demo booking data | As long as needed to hold and follow up the meeting, then deleted unless you become a customer |
| Job applications | For the recruitment process and up to one year thereafter unless you ask us to delete sooner |
| Aggregated / anonymised analytics | May be kept indefinitely; no longer personal data |
11. Security
We implement technical and organisational measures appropriate to the risk (GDPR Art. 32), including TLS in transit, encryption at rest with our hosting providers, row-level security and account-scoped access, optional MFA, and data processing agreements with sub-processors. Details are on our Security & Data page and in Schedule 3 of the DPA.
If a personal data breach is likely to result in a risk to individuals, we will notify the Dutch Data Protection Authority without undue delay and, where required, within 72 hours of becoming aware (Art. 33 GDPR). Where Customer Data is affected, we will notify the Customer as controller without undue delay so that the Customer can meet its own obligations.
12. Your GDPR rights
You have the following rights regarding personal data of which we are the controller:
- Access (Art. 15): a copy of your personal data
- Rectification (Art. 16): correction of inaccurate or incomplete data
- Erasure (Art. 17): deletion, subject to legal retention (for example invoices)
- Restriction (Art. 18): in the circumstances set out in the GDPR
- Portability (Art. 20): a structured, commonly used, machine-readable copy of data you provided
- Objection (Art. 21): to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent (Art. 7(3)): where processing is based on consent, including cookies and marketing email
To exercise these rights, email support@clippter.com. We will verify your identity. We respond within one month, and may extend by up to two months for complex requests (we will tell you within the first month). Requests about Customer Data are forwarded to the relevant Customer.
13. Right to lodge a complaint
You may lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority (Postbus 93374, 2509 AJ Den Haag, The Netherlands). Website: https://www.autoriteitpersoonsgegevens.nl. If you live in another EU/EEA member state you may also contact your local authority. We encourage you to contact us first so we can try to resolve the issue.
14. Children
The Platform is intended for business users. We do not knowingly collect personal data from anyone under sixteen (UAVG). If you believe we have, contact support@clippter.com and we will delete it.
15. Changes to this Privacy Statement
We may update this statement when the Platform, our providers or the law changes. We will post the new version on this page and update the date. For changes that materially affect your rights or our processing, we will also email the address on your account. The Dutch version is provided for convenience; if you contracted in English, the English text of the Terms prevails for the contract, while this Privacy Statement describes our processing under the GDPR in both languages.
16. Contact
Movie Moose Holding B.V.
Thierensweg 8, 1411EX Naarden, The Netherlands
KvK 88876926
Email: support@clippter.com
Related documents: Terms, Security & Data, Data Processing Agreement.