Privacy Policy
Effective date: 8 October 2026
This Privacy Policy explains how COMPANY_LEGAL_NAME, operating the Klipt Studio service ("Klipt Studio", "we", "us", "our"), collects, uses, and shares personal data in connection with the Service. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and equivalent laws (including the UK GDPR for UK clients).
Klipt Studio is a B2B service. Our direct clients are businesses; this Policy covers personal data we process about (a) the individuals who use the client portal on a Client's behalf (owners, approvers, viewers), and (b) personal data that may appear within Client content or audience/engagement data as part of delivering the Service.
1. Controller and processor roles
- We act as data controller for: account and billing data of Client users and prospects, portal usage and security logs, marketing-site analytics, and our own business records (contracts, invoices, support communications). See Section 3.
- We act as data processor, on the Client's documented instructions, for: Brand Information, Client Media, drafts, captions, conversation content tied to a content item, and social audience/engagement data imported from the Client's connected accounts. Our Data Processing Agreement (GDPR Article 28) governs this processing; the Client is the controller of that data and is responsible for having a lawful basis to supply it to us (for example, consent from individuals shown in photos or testimonials).
This split follows our internal data-governance policy: client business/content data is processed strictly under instructions; account/subscription administration is ours to control.
2. Categories of personal data
| Category | Examples |
|---|---|
| Account data | name, work email, role (owner/approver/viewer), authentication identifiers |
| Billing data | company name, billing address, VAT number, subscription status; card data is held by Stripe, not by us |
| Brand Information (processor role) | website, social handles, industry, goals, tone, brand rules |
| Client Media (processor role) | photos/videos/testimonials the Client uploads, which may depict identifiable people |
| Conversations (processor role) | messages exchanged in the portal, attachments, approval/change-request history |
| Social audience data (processor role) | aggregated post and account metrics (reach, engagement, followers) imported from connected networks; we do not seek individual follower identities |
| Technical data | IP address, device/browser information, timestamps, security and audit logs |
| Communications | support requests sent to hello@klipt-ai.com |
We ask Clients not to supply special-category personal data (health, political opinions, biometric data, etc.) unless strictly necessary and lawfully justified, and never data about children without a lawful basis.
3. Purposes and legal bases (controller role)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and administer the Client account and portal users | Performance of a contract |
| Billing, invoicing, tax compliance | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention, access logs | Legitimate interests |
| Respond to support requests | Performance of a contract; legitimate interests |
| Operate, debug, and improve the Service | Legitimate interests |
| Send service communications (and marketing, where separately consented) | Legitimate interests / consent |
| Comply with legal, accounting, and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have weighed those interests against the rights of the individuals concerned; you may object at any time (Section 8).
4. Automated processing and AI
We use AI systems, under human supervision, to draft content, read supplied Brand Information, and answer portal conversations. See our AI Transparency page for how this works and how it is disclosed. This processing is carried out to perform the contract with the Client and does not, by itself, produce legal or similarly significant decisions about an individual within the meaning of GDPR Article 22: content is reviewed and approved by the Client (or governed by the autopilot rules the Client itself configured) before publication.
We do not use Client content, Client Media, or portal conversations to train our own or third parties' general-purpose AI models. Our AI and media sub-processors' commercial terms likewise exclude training on this data; see Sub-processors for the Anthropic-specific policy basis.
5. Sub-processors and recipients
We share personal data with service providers acting on our behalf under data processing agreements, listed in full on our Sub-processors page, including providers of hosting, database/auth/storage, AI content and media generation, voice synthesis, social publishing, payments, and email delivery. We do not sell personal data. We will notify Clients of changes to this list as described in our Data Processing Agreement.
6. International transfers
We host application data in the EU (Supabase, AWS eu-west-3, Paris; Scaleway, France). Where a
sub-processor transfers personal data outside the European Economic Area (notably United States-based
providers), we rely on the European Commission's Standard Contractual Clauses and, where the recipient
is self-certified, the EU-U.S. Data Privacy Framework, as appropriate safeguards under GDPR Chapter V.
Details are available on request at hello@klipt-ai.com.
7. Retention
| Data | Retention |
|---|---|
| Account/billing data | duration of the contract + statutory accounting/tax retention (see our retention schedule, available on request) |
| Client content, media, conversations | duration of the contract; exported or deleted on request or within the period stated in the DPA after termination |
| Security/audit logs | limited period necessary for security purposes |
| Marketing-site analytics | aggregated, cookieless; see Cookie Policy |
Exact durations are defined in our retention schedule (available on request) and may be adjusted to meet French commercial/accounting-record retention rules.
8. Your rights
Subject to applicable law, individuals have the right to access, rectify, erase, restrict, and port their personal data, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. To exercise these rights, contact PRIVACY_CONTACT_EMAIL (or hello@klipt-ai.com). We will respond within the timeframes required by law. You may also lodge a complaint with your supervisory authority; in France, the Commission Nationale de l'Informatique et des Libertés (CNIL), www.cnil.fr.
9. Security
We apply technical and organizational measures appropriate to the risk, summarized in our Data Processing Agreement (security annex), including tenant isolation, encryption in transit, access controls, and least-privilege credentials. No system is perfectly secure.
10. Data protection contact
DATA_PROTECTION_CONTACT — at our current scale we have assessed that a statutory Data Protection Officer is not mandatory under GDPR Article 37; this contact handles privacy requests and can be reached at the address above.
11. Children
The Service is directed to businesses and is not intended for use by children. Client Media must not include content involving minors except where the Client has a lawful basis and appropriate consent.
12. Cookies
See our Cookie Policy: the marketing site uses cookieless analytics and the client portal uses only strictly necessary cookies.
13. Changes
We may update this Policy; material changes will be notified as described in our Terms of Service. The "Effective date" above reflects the latest version.