Data Processing Agreement
Version: September 2026
This document is published in English for all languages. The English text is the authoritative version. Your statutory rights under the mandatory law of your country of residence are unaffected.
This Data Processing Agreement (the “DPA”) applies where you use the Clip platform (the “Service”) to process personal data for which you are the controller. It forms part of, and is governed by, the Clip Terms & Conditions. Where this DPA conflicts with the Terms on the subject of personal data processing, this DPA prevails.
In this DPA, “Controller” means the customer, “Processor” means Clip, and “Personal Data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. The Annexes at the end form an integral part of this DPA.
1. Parties
The Processor under this DPA is:
- Clip
- Vossiusstraat 20-2
- 1071 AD Amsterdam
- The Netherlands
- Chamber of Commerce (KvK): 81707169
- VAT: NL003597297B90
The Controller is the account holder identified in the Clip account, or the organisation on whose behalf that account is operated.
2. Roles of the parties
The Controller determines the purposes and means of processing the Personal Data contained in Customer Content and instructs the Processor to process it through use of the Service. The Processor processes that Personal Data solely on behalf of the Controller.
For its own account, billing, security and website data, Clip acts as an independent controller. That processing is described in the Clip Privacy Policy and falls outside this DPA.
3. Subject matter and duration
The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects are set out in Annex 1.
This DPA takes effect when the Controller starts using the Service and continues for as long as the Processor processes Personal Data on the Controller's behalf.
4. Processing on documented instructions
The Processor processes Personal Data only on the Controller's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law; in that case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
The Controller's instructions are: this DPA, the Terms, the configuration and options the Controller selects in the Service, and the operations the Controller triggers in the Service. Additional instructions must be agreed in writing and may be subject to a reasonable fee where they require work beyond the standard Service.
The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
5. Controller obligations
The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided any required information to data subjects and obtained any required consents — including for voices, faces, likenesses and other personal data contained in uploads or reference material — and that its instructions comply with applicable law.
The Controller is responsible for the content it submits and must not submit special categories of personal data under Article 9 GDPR, data relating to criminal convictions, government identifiers or the personal data of children, unless it has a lawful basis and has agreed appropriate additional safeguards with the Processor in writing.
6. Confidentiality
The Processor ensures that persons authorised to process the Personal Data are bound by an obligation of confidentiality, and limits access to those who need it to deliver, secure or support the Service.
7. Security of processing
The Processor implements appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects. A summary of the current measures is set out in Annex 2.
The Processor may update the measures over time provided the level of protection is not reduced.
8. Sub-processors
The Controller gives the Processor general written authorisation to engage sub-processors for hosting, storage, database, authentication, AI model inference, transcription, voice synthesis, rendering, payment and operational communication. The categories are listed in Annex 3.
The current list of specific sub-processors is available on request through the contact options on the Clip website. The Processor will inform the Controller of intended changes concerning the addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds. If a reasoned objection cannot be resolved, the Controller may terminate the affected part of the Service; fees already paid for services supplied are not refunded, without prejudice to mandatory law.
The Processor imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Controller for the performance of its sub-processors' obligations.
9. International transfers
Where processing involves a transfer of Personal Data outside the European Economic Area, the Processor ensures a valid transfer mechanism under Chapter V GDPR applies — an adequacy decision, the Standard Contractual Clauses, or another approved mechanism — together with any supplementary measures required. Details of the mechanism applicable to a given sub-processor are available on request.
10. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights. The Service provides self-service export and deletion tools for this purpose.
If the Processor receives a request directly from a data subject relating to Personal Data processed on behalf of the Controller, it will not respond substantively and will forward the request to the Controller without undue delay.
11. Assistance with security, breaches and impact assessments
The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor. Assistance beyond the standard Service may be charged at reasonable rates.
12. Personal data breach
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Personal Data processed on the Controller's behalf, and provides the information reasonably available to it to enable the Controller to meet its own notification obligations, supplementing that information as it becomes available.
Notification is not an acknowledgement of fault or liability. The Controller is responsible for any notification to a supervisory authority or to data subjects.
13. Deletion and return of data
On termination of the Service, and at the Controller's choice, the Processor deletes or returns the Personal Data processed on the Controller's behalf and deletes existing copies, unless Union or Member State law requires storage. The Controller may export its content using the Service before termination.
Residual copies in routine backups are deleted on the ordinary backup rotation and remain protected by this DPA until then.
14. Audits and information
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
Audits must be requested with at least thirty days' written notice, take place during business hours, occur no more than once in any twelve-month period unless a personal data breach or a supervisory authority requires otherwise, not unreasonably disrupt the Service, and be subject to confidentiality. The Processor may first satisfy a request by providing documentation and written answers. The Processor holds no third-party security certification and claims none; it does not currently provide an external audit report.
15. AI processing of Personal Data
The Controller acknowledges that delivering the Service requires transmitting Customer Content, which may contain Personal Data, to AI and media sub-processors to produce the requested Output. This is a documented instruction under clause 4.
The Processor does not use Customer Content to train its own generative models and does not make Customer Content available to third parties for the purpose of training their models, without the Controller's separate explicit written permission.
16. Liability
Liability under this DPA is subject to the limitations and exclusions set out in the Terms, to the maximum extent permitted by applicable law. Nothing in this DPA limits any liability that cannot be limited under mandatory law, including the liability regime of Article 82 GDPR towards data subjects.
17. Term and termination
This DPA remains in force for as long as the Processor processes Personal Data on behalf of the Controller. Provisions that by their nature should survive — confidentiality, deletion, liability and audit records — survive termination.
18. Changes
This DPA is version September 2026. The Processor may update it to reflect changes in the Service, in sub-processors or in law, provided the protection afforded to data subjects is not reduced. Material changes will be announced before they take effect.
19. Governing law and jurisdiction
This DPA is governed by the laws of the Netherlands. Disputes are submitted to the competent court in Amsterdam, the Netherlands, without prejudice to any mandatory right a consumer has to bring proceedings in their country of residence.
20. Annexes
Annex 1 — Details of processing
- Subject matter: provision of the Clip platform for AI-assisted creation, editing, rendering and distribution of short-form video.
- Duration: for the term of the account, plus the retention and backup periods described in clause 13.
- Nature of processing: collection, storage, structuring, transmission to AI and media sub-processors, generation, transformation, rendering, retrieval, export, erasure.
- Purpose: producing and delivering the Output the Controller requests, and storing it in the Controller's workspace.
- Categories of data subjects: the Controller's personnel and account users; persons appearing or heard in uploaded or reference material; persons named or described in prompts, briefs, scripts, transcripts or generated Output; the Controller's own end customers where present in that content.
- Categories of Personal Data: identification and contact data of account users; images, video and audio recordings including faces and voices; likeness and biometric-adjacent characteristics contained in media supplied by the Controller; free-text prompts, briefs and transcripts which may contain any personal data the Controller chooses to include; project and usage metadata.
- Special categories: none are requested, instructed or expected. The Controller must not submit them without prior written agreement under clause 5.
Annex 2 — Technical and organisational security measures
- Encryption of data in transit using TLS; encryption at rest as provided by the hosting and storage infrastructure.
- Private-by-default media storage, with server-enforced ownership checks and short-lived signed URLs; no permanent public media addresses.
- Row-level security in the database, scoping records to the owning account and workspace.
- Server-side-only provider credentials, never exposed to the browser; secrets held in the platform secret store.
- Authenticated access with password hashing handled by the authentication provider, and password reset flows that do not disclose account existence.
- Rate limiting, concurrency limits, spend caps and abuse detection on paid operations.
- Logging of privileged and billing-relevant actions, with review by the operator.
- Idempotency, reservation-and-settlement accounting and reconciliation to avoid duplicate or lost processing.
- Least-privilege internal access, limited to those who need it to operate and support the Service.
- Backups managed by the hosting infrastructure, with restoration tested against the platform's standard procedures.
Annex 3 — Categories of authorised sub-processors
- Cloud hosting and application runtime.
- Managed database, authentication and object storage.
- AI image, video and text model inference providers.
- Speech synthesis and transcription providers.
- Video rendering and export infrastructure.
- Payment and billing providers.
- Email and operational communication providers.
- Publishing platforms, only where the Controller explicitly connects an account and instructs a publication.
The current list of named sub-processors within these categories is available on request through the contact options on the Clip website. No list of named sub-processors is reproduced here in order to avoid stating an outdated one.