Security & Data – Clippter

Last updated: 1 September 2026

Where your data lives

Clippter is operated by a Dutch company for EU and Dutch businesses. We design the Platform so that primary application data and media are hosted in the EEA.

SystemProviderRegion
Database, accounts, CRM, quotes, projectsSupabaseFrankfurt, Germany (eu-central-1)
Review videoBunny StreamGermany
Media library, review stills, comment snapshotsCloudflare R2Western Europe
Application hostingVercelEU, including Frankfurt
Error monitoringSentryGermany (EU ingest)

Payments (Stripe) and transactional email (Resend) are supporting services. They may process limited account and billing data outside the EEA under Standard Contractual Clauses. They do not host your workspace database or client media.

No AI training

Clippter does not offer generative AI product features today. We do not use Customer Data, review media or portal content to train AI or machine-learning models, and we do not send that content to OpenAI, Anthropic or similar providers for training or model improvement.

1. Who we are

Clippter is operated by Movie Moose Holding B.V., established in the Netherlands (KvK 88876926), Thierensweg 8, 1411EX Naarden, The Netherlands. Personal data is processed under the GDPR / AVG and Dutch law. Disputes relating to the Terms are subject to Dutch law and the competent court in Amsterdam. See the Terms and Conditions.

2. Hosting map (detail)

The table at the top of this page is the production map. We do not operate a US-primary database for Customer Data. Edge delivery (Vercel) may serve the application from locations close to the user; the system of record for workspace data remains Frankfurt.

More detail on categories of data is in the Privacy Statement. Processor instructions, sub-processor notice and deletion timelines are in the Data Processing Agreement.

3. Artificial intelligence

We do not currently run generative AI on Customer Data. We do not use client media to train models. Optional assistive helpers, if introduced later, will be off by default, will not train on your media, and will be described in the Privacy Statement before they are enabled.

4. Technical and organisational measures

We apply measures appropriate to a multi-tenant B2B SaaS platform (GDPR Art. 32), including:

  • Encryption in transit (HTTPS / TLS 1.2 or higher)
  • Encryption at rest with our EEA hosting providers
  • Account-scoped queries and row-level security patterns for tenant data
  • Least-privilege administrative access for named platform operators
  • Security headers (HSTS, X-Frame-Options DENY, Content-Security-Policy, nosniff)
  • Written DPAs with sub-processors that handle personal data
  • Separation of the agency workspace from the client portal

These measures are also listed in Schedule 3 of the DPA.

5. Access control, RLS and MFA

Workspace data is scoped to the Customer's account. API routes that use elevated database credentials are required to filter by account. A tenant-isolation audit runs in CI.

Multi-factor authentication (authenticator app / TOTP) is available and off by default:

  • Agency workspace: require MFA for team members who sign in to the agency app.
  • Client portal: require MFA per client company for that company's portal users.

Agency MFA and portal MFA are independent. We recommend turning MFA on for every workspace.

6. Client portal isolation

Portal users sign in with their own invite-only account. They see only projects the agency has shared. They do not get CRM, quotes, rates, finance or other clients.

Typical flow: the agency uploads into Clippter and shares with the client. Portal users can review, comment and approve. They cannot upload files into the portal. Downloads can be disabled per project. Share links, if used, are visible to anyone who has the URL; the Customer controls whether to use them.

7. Authentication and security alerts

Users may sign in with email and password or with Google. Passwords are stored as salted hashes by our authentication provider; we cannot read them. We send email alerts when a password, email address, MFA factor or linked identity changes.

8. Payments

Subscription payments are processed by Stripe. Card numbers are not stored on Clippter servers. Stripe webhooks are verified by signature; events are handled idempotently.

9. Backups and availability

Encrypted backups of the primary database are maintained by our infrastructure provider in the EEA. We do not publish a formal SLA or RPO/RTO unless agreed in writing. Planned maintenance is described in the Terms (best-efforts availability).

10. Personal data breaches

If a breach is likely to result in a risk to individuals, we notify the Autoriteit Persoonsgegevens without undue delay and, where Art. 33 GDPR requires it, within 72 hours of becoming aware. Where Customer Data is affected we notify the Customer as controller without undue delay (target: within 48 hours of becoming aware) so the Customer can inform data subjects if Art. 34 requires it.

11. Sub-processors

The named list, roles and locations are in the Privacy Statement (section 6) and Schedule 2 of the DPA. We will not use Customer Data with a new sub-processor that changes the processing in a material way without the notice mechanism in the DPA.

12. What we do not claim

Clippter does not currently hold ISO 27001 or SOC 2 certification. We do not claim otherwise. Our providers (including Supabase, Vercel, Cloudflare, Stripe and Sentry) publish their own security and compliance documentation.

13. Customer responsibilities

  • Keep Seats personal; do not share logins
  • Use MFA for the agency workspace and for portal companies that handle sensitive review
  • Invite only people who should see the shared projects
  • Treat share links as public to anyone with the URL
  • Export data before cancelling if you need an archive

14. Contact

Questions about security or data protection: support@clippter.com.

Movie Moose Holding B.V.

Thierensweg 8, 1411EX Naarden, The Netherlands
KvK 88876926