Security & Data – Clippter
Last updated: July 22, 2026
Who we are
Clippter is operated by Movie Moose Holding B.V., a company established in the Netherlands (KvK 88876926). We design and run the platform for EU and Dutch businesses. Processing of personal data is governed by the EU General Data Protection Regulation (GDPR / AVG) and applicable Dutch law. Disputes relating to our Terms and Conditions are subject to Dutch law and the competent court in Amsterdam, as set out in our Terms and Conditions.
Where we store data
We design Clippter so that primary application data and media are hosted in the European Economic Area (EEA). Current production locations:
- Application database and authentication (Supabase): Frankfurt, Germany (AWS region eu-central-1).
- Review video (Bunny Stream): primary storage in Germany (DE).
- Approved media library, review images, and comment snapshots (Cloudflare R2): Western Europe (WEUR).
- Application hosting (Vercel): served from European infrastructure (including Frankfurt).
More detail on categories of data and sub-processors is in our Privacy Statement.
Client portal and uploads
The client portal is a separate experience from the agency workspace. Portal users sign in with their own account (invite-only) and only see projects and deliverables that the agency has shared with them. They do not get access to agency CRM, quotes, rates, finance, or internal team tools.
Typical review flow: the agency uploads into Clippter and shares with the client; portal users can interact with and review videos (feedback and approve). They cannot upload anything into the portal — no documents, PDFs, media, or other files. Upload is one-way: agency → Clippter → client. Downloads for clients can be disabled per project.
Optional multi-factor authentication
MFA (authenticator app / TOTP) is optional and off by default. Agencies control it in two places:
- Agency workspace: require MFA for team members who sign in to the Clippter agency app (yes/no for the workspace).
- Client portal (per company): require MFA for portal users of a specific client company (yes/no per company).
When enabled for a portal company, those portal users must complete MFA after sign-in before accessing shared projects. Agency MFA and portal MFA are independent settings.
Artificial intelligence
Clippter does not currently offer generative AI product features. We do not use Customer Data or client portal content to train artificial intelligence or machine learning models, and we do not share that content with third parties for AI training or model improvement.
Security measures
We apply technical and organisational measures appropriate to a multi-tenant B2B SaaS platform, including encryption in transit (HTTPS/TLS), encryption at rest with our hosting providers, account-scoped access controls, and row-level security patterns for tenant data. We conclude data processing agreements with sub-processors that handle personal data on our behalf.
Transfers outside the EEA
Some supporting providers (for example payment processing, transactional email, or error monitoring) may process limited personal data outside the EEA. Where that happens, we rely on GDPR-compliant transfer mechanisms such as the European Commission's Standard Contractual Clauses, and we keep primary workspace and media storage in the EEA as described above.
Contact
Questions about security or data protection: support@clippter.com.