Data Processing Agreement
Effective date: 8 October 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service between the Client ("Controller") and COMPANY_LEGAL_NAME, operating Klipt Studio ("Processor", "we", "us"), and reflects the requirements of Article 28 of the GDPR. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. Capitalized terms not defined here have the meaning given in the Privacy Policy.
1. Subject matter and scope
We process personal data on the Controller's behalf strictly to provide the Service: receiving Brand Information, Client Media, and portal conversations; drafting, producing, submitting for approval, revising, and publishing content; and importing social audience/engagement metrics. The duration of processing is the term of the subscription plus the retention period in Section 8.
2. Nature, purpose, categories of data, and data subjects
| Nature of processing | Collection, storage, drafting/generation assistance, review, publication, analytics |
| Purpose | Delivery of the social-media content agency Service described in the Terms |
| Categories of data | Identification data of Controller's users and any individuals appearing in Client Media; contact details; images/video/audio; social engagement metrics |
| Categories of data subjects | Controller's personnel (owner/approver/viewer), individuals depicted in Client Media (e.g., staff, customers, testimonials), the Controller's social media audience (aggregated metrics only) |
3. Processor obligations
We shall:
(a) process personal data only on the Controller's documented instructions (including as to international transfers), unless required to do otherwise by EU or Member State law, in which case we will inform the Controller first unless the law prohibits this;
(b) ensure persons authorized to process the data are bound by confidentiality;
(c) implement the technical and organizational measures described in Annex 1 (Security Measures);
(d) respect the conditions in Section 4 for engaging sub-processors;
(e) assist the Controller, taking into account the nature of the processing, in responding to requests from individuals exercising their GDPR rights, through the portal functionality described in Section 6 and by reasonable additional assistance on request;
(f) assist the Controller with its obligations under GDPR Articles 32–36 (security, breach notification, impact assessments, prior consultation), taking into account the information available to us;
(g) at the Controller's choice, delete or return all personal data at the end of the provision of services, and delete existing copies, as set out in Section 8, unless EU or Member State law requires storage;
(h) make available to the Controller the information necessary to demonstrate compliance with this Article and allow for, and contribute to, audits as set out in Section 7.
4. Sub-processors
The Controller gives general authorization for us to engage the sub-processors listed on our Sub-processors page as of the effective date. We will:
- maintain that list current and give the Controller at least 14 days' prior notice (by email or in-app notice) before authorizing a new sub-processor or replacing an existing one;
- impose, by contract, data protection obligations on each sub-processor no less protective than those in this DPA, and remain liable to the Controller for a sub-processor's performance of its obligations;
- allow the Controller to object, on reasonable data-protection grounds, within 14 days of notice; if the parties cannot resolve the objection, the Controller may terminate the affected part of the Service without penalty for convenience, as its sole remedy.
5. International transfers
Where a sub-processor processes personal data outside the EEA, we ensure an appropriate transfer mechanism under GDPR Chapter V applies (the European Commission's Standard Contractual Clauses, and/or the EU-U.S. Data Privacy Framework where the recipient is self-certified), as detailed per provider on the Sub-processors page.
6. Data subject requests
The client portal lets the Controller directly export, correct, or delete Client Media and conversation content, and manage its users' access. Where a request requires our assistance beyond the self-service tools, we will respond within 5 business days of the Controller's request.
7. Audit and records
We maintain records of processing activities as required by GDPR Article 30 and will make available to the Controller, no more than once per 12-month period (or more often if required by a supervisory authority or following a confirmed personal data breach), a summary of our then-current security measures and, on reasonable written notice and subject to confidentiality and reasonable scheduling, the results of an independent third-party audit or certification we hold, or access to conduct or mandate an audit of our processing of the Controller's personal data, at the Controller's expense unless a material non-compliance is found.
8. Deletion or return of data; retention
Upon termination of the subscription, the Controller may, within 30 days, export its data via the portal or by written request. After that period, or earlier on the Controller's written instruction, we will delete all personal data processed on the Controller's behalf, including copies, within 90 days, except for data we must retain under EU or French law (e.g., invoicing records) or within backups, which are deleted on our standard backup-rotation schedule described in Annex 1. The exact schedule is set out in our retention schedule (available to the Controller on request).
9. Personal data breach notification
We will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's personal data, by email to the Controller's registered account contact, including (to the extent known at the time, supplemented as more information becomes available): the nature of the breach; categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed to address the breach and mitigate its effects. This is a contractual commitment that is faster than, and does not replace, any statutory notification obligation the Controller may independently owe to its own regulator or data subjects.
10. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except that those limitations do not apply to a party's liability for infringement of a data subject's rights or to administrative fines imposed directly on a party by a supervisory authority for its own non-compliance.
11. Annex 1 — Security measures (summary)
- Tenant isolation: row-level security per organization, a dedicated workspace and ephemeral, network-restricted container per processing job, job-scoped access tokens (no direct database, storage, or publishing credentials inside the content-generation process).
- Encryption: in transit (TLS) for all application and storage traffic; provider-managed encryption at rest for database and object storage.
- Access control: role-based access (owner/approver/viewer) for Controller users; staff/admin access requires a dedicated staff role plus multi-factor authentication; least-privilege service credentials.
- Logging and monitoring: audit log of administrative actions; job and publishing logs retained for operational troubleshooting and security review.
- Secrets management: credentials for sub-processors are held only on the engine host, never in the application database or in the content-generation process.
- Backups: database point-in-time recovery; workspace backups to EU object storage on a nightly schedule.
- Change and incident management: documented breach procedure (part of our internal security and incident-response policy, available to the Controller on request) with the 48-hour Controller notification commitment in Section 9.
Full technical detail is maintained in our internal security and incident-response policy, available to the Controller on request for audit purposes under Section 7.