Data Processing Agreement — GDPR Article 28
Version: DRAFT V0.1 — Under legal validation
Date: April 2026
Parties
The Data Controller (hereinafter "the Client") : the organization that has subscribed to the ClipHow platform.
The Data Processor (hereinafter "ClipHow") : ClipHow SAS, a simplified joint-stock company, registered with the Lyon Trade and Companies Register under number 104 954 961, with its registered office at 12 Rue de la Part Dieu, 69003 Lyon.
Email : contact@cliphow.com
DPO : Vincent Charles — dpo@cliphow.com
Article 1 — Purpose
This agreement defines the conditions under which ClipHow, as a data processor within the meaning of Article 28 of the GDPR, processes personal data on behalf of the Client in connection with the provision of the ClipHow platform.
ClipHow is a B2B SaaS platform for enterprise knowledge management through video. It enables automatic transcription, training course generation and provides an AI conversational agent.
Article 2 — Description of Processing
| Element | Description |
|---|---|
| Nature of processing | Hosting, storage, AI transcription, visual analysis (OCR), vectorization, course generation, conversational agent, error monitoring |
| Purpose | Provision of the ClipHow video knowledge management service |
| Data types | Identification data (last name, first name, email), connection data (IP, user-agent), video content (voice, faces), transcriptions, AI conversations, progress data, audit logs |
| Categories of data subjects | Client's employees (employees, managers, administrators) |
| Duration | Duration of the subscription contract between the Client and ClipHow |
Article 3 — Obligations of the Data Processor
3.1 Processing on documented instructions
Process personal data only on documented instructions from the Client. The Client's instructions are embodied in this agreement, the ToU, and the platform's configuration settings.
3.2 Confidentiality
Ensure that persons authorized to process personal data are subject to a confidentiality obligation.
3.3 Security (Art. 32 GDPR)
Implement appropriate technical and organizational measures:
- Encryption : AES-256 at rest (Supabase), TLS 1.2+ in transit (HSTS preload).
- Access control : MFA/TOTP mandatory for owners and administrators, available for all users. Row Level Security on all tables, 4 role levels, 15-minute session timeout, account lockout after failed attempts.
- Logging : audit logs of all sensitive actions, minimum 12-month retention, write-protected.
- Application security : HTTP headers (CSP, HSTS, X-Frame-Options), rate limiting, password validation (12 characters minimum, complexity required).
3.4 Sub-processors
| Subprocessor | Headquarters | Data location | Role |
|---|---|---|---|
| Supabase Inc. | Singapore | UE (Frankfurt) | Database, auth, file storage |
| Vercel Inc. | United States | UE (Frankfurt) | Application hosting, cron jobs |
| Mistral AI | France | France | Transcription, embeddings, AI chat, course generation |
| Resend (optional, not deployed) | To be confirmed | European Union | Sending transactional emails (invitations, notifications) |
| SAML/SCIM IdP Provider | Variable (chosen by the Client) | Variable | SSO authentication and automatic provisioning |
Change notification : ClipHow will notify the Client in writing of any change to a sub-processor with 30 days' notice.
3.5 Client Assistance
ClipHow commits to assisting the Client with :
- Responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection).
- Conducting data protection impact assessments (DPIAs) when necessary.
- Notifying any data breach (see Article 5).
3.6 Data Handling at End of Contract
- Return : ClipHow provides the Client with a complete export of their data in a structured format (JSON/ZIP) within 30 days.
- Suppression : After the 30-day period, permanent deletion of all Client data, except where legal retention obligations apply.
- Certificate : ClipHow provides a certificate of data destruction upon request.
- Exception : Audit logs are retained in accordance with legal obligations (GDPR Art. 17(3)(b)).
3.7 Audit
The Client may :
- Request a third-party compliance report (e.g. SOC 2) once per year.
- Submit written questions to which ClipHow will respond within 30 days.
Article 4 — Transfers Outside the European Union
Personal data is stored and processed exclusively within the European Union.
The headquarters of some sub-processors (Supabase, Vercel, Stripe) are located outside the EU, but the servers used are located within the EU (Frankfurt, Germany region for most; France for Mistral). No actual data transfer outside the EU is underway.
Article 5 — Data Breach Notification
In the event of a personal data breach, ClipHow commits to:
- Notify the Client within a maximum of 48 hours after becoming aware of it.
- Provide the nature of the breach, the categories and number of data subjects affected, the likely consequences, and the measures taken or proposed.
- Cooperate with the Client for notification to the CNIL and to data subjects if necessary.
The Client, as data controller, is responsible for notification to the CNIL (Art. 33 GDPR) and to data subjects (Art. 34 GDPR).
Article 6 — Duration
This agreement takes effect on the date of signature and remains in force for the duration of the subscription contract. Confidentiality and security obligations survive termination.
Article 7 — Applicable Law
This agreement is governed by French law. Any dispute shall be submitted to the competent courts of the jurisdiction of the registered office of ClipHow SAS.
This document is a draft (DRAFT V0.1) under review by our legal counsel. To obtain the final signed version, contact us at contact@cliphow.com.