ClipHow
Use casesFeaturesPricingSecurity
Log inGet started

Data Processing Agreement — GDPR Article 28

Version: DRAFT V0.1 — Under legal validation
Date: April 2026

Parties

The Data Controller (hereinafter "the Client") : the organization that has subscribed to the ClipHow platform.

The Data Processor (hereinafter "ClipHow") : ClipHow SAS, a simplified joint-stock company, registered with the Lyon Trade and Companies Register under number 104 954 961, with its registered office at 12 Rue de la Part Dieu, 69003 Lyon.
Email : contact@cliphow.com
DPO : Vincent Charles — dpo@cliphow.com

Article 1 — Purpose

This agreement defines the conditions under which ClipHow, as a data processor within the meaning of Article 28 of the GDPR, processes personal data on behalf of the Client in connection with the provision of the ClipHow platform.

ClipHow is a B2B SaaS platform for enterprise knowledge management through video. It enables automatic transcription, training course generation and provides an AI conversational agent.

Article 2 — Description of Processing

ElementDescription
Nature of processingHosting, storage, AI transcription, visual analysis (OCR), vectorization, course generation, conversational agent, error monitoring
PurposeProvision of the ClipHow video knowledge management service
Data typesIdentification data (last name, first name, email), connection data (IP, user-agent), video content (voice, faces), transcriptions, AI conversations, progress data, audit logs
Categories of data subjectsClient's employees (employees, managers, administrators)
DurationDuration of the subscription contract between the Client and ClipHow

Article 3 — Obligations of the Data Processor

3.1 Processing on documented instructions

Process personal data only on documented instructions from the Client. The Client's instructions are embodied in this agreement, the ToU, and the platform's configuration settings.

3.2 Confidentiality

Ensure that persons authorized to process personal data are subject to a confidentiality obligation.

3.3 Security (Art. 32 GDPR)

Implement appropriate technical and organizational measures:

  • Encryption : AES-256 at rest (Supabase), TLS 1.2+ in transit (HSTS preload).
  • Access control : MFA/TOTP mandatory for owners and administrators, available for all users. Row Level Security on all tables, 4 role levels, 15-minute session timeout, account lockout after failed attempts.
  • Logging : audit logs of all sensitive actions, minimum 12-month retention, write-protected.
  • Application security : HTTP headers (CSP, HSTS, X-Frame-Options), rate limiting, password validation (12 characters minimum, complexity required).

3.4 Sub-processors

SubprocessorHeadquartersData locationRole
Supabase Inc.SingaporeUE (Frankfurt)Database, auth, file storage
Vercel Inc.United StatesUE (Frankfurt)Application hosting, cron jobs
Mistral AIFranceFranceTranscription, embeddings, AI chat, course generation
Resend (optional, not deployed)To be confirmedEuropean UnionSending transactional emails (invitations, notifications)
SAML/SCIM IdP ProviderVariable (chosen by the Client)VariableSSO authentication and automatic provisioning

Change notification : ClipHow will notify the Client in writing of any change to a sub-processor with 30 days' notice.

3.5 Client Assistance

ClipHow commits to assisting the Client with :

  • Responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection).
  • Conducting data protection impact assessments (DPIAs) when necessary.
  • Notifying any data breach (see Article 5).

3.6 Data Handling at End of Contract

  1. Return : ClipHow provides the Client with a complete export of their data in a structured format (JSON/ZIP) within 30 days.
  2. Suppression : After the 30-day period, permanent deletion of all Client data, except where legal retention obligations apply.
  3. Certificate : ClipHow provides a certificate of data destruction upon request.
  4. Exception : Audit logs are retained in accordance with legal obligations (GDPR Art. 17(3)(b)).

3.7 Audit

The Client may :

  • Request a third-party compliance report (e.g. SOC 2) once per year.
  • Submit written questions to which ClipHow will respond within 30 days.

Article 4 — Transfers Outside the European Union

Personal data is stored and processed exclusively within the European Union.

The headquarters of some sub-processors (Supabase, Vercel, Stripe) are located outside the EU, but the servers used are located within the EU (Frankfurt, Germany region for most; France for Mistral). No actual data transfer outside the EU is underway.

Article 5 — Data Breach Notification

In the event of a personal data breach, ClipHow commits to:

  1. Notify the Client within a maximum of 48 hours after becoming aware of it.
  2. Provide the nature of the breach, the categories and number of data subjects affected, the likely consequences, and the measures taken or proposed.
  3. Cooperate with the Client for notification to the CNIL and to data subjects if necessary.

The Client, as data controller, is responsible for notification to the CNIL (Art. 33 GDPR) and to data subjects (Art. 34 GDPR).

Article 6 — Duration

This agreement takes effect on the date of signature and remains in force for the duration of the subscription contract. Confidentiality and security obligations survive termination.

Article 7 — Applicable Law

This agreement is governed by French law. Any dispute shall be submitted to the competent courts of the jurisdiction of the registered office of ClipHow SAS.


This document is a draft (DRAFT V0.1) under review by our legal counsel. To obtain the final signed version, contact us at contact@cliphow.com.

ClipHow

Industrial know-how, captured and activated.

Product

FeaturesUse casesSecurity

Company

Contact

Legal

Legal noticesPrivacyTerms of serviceTerms of saleCookie policyDPA (PDF)

© 2026 ClipHow. All rights reserved.