Legal

Data Processing Addendum

Last updated: 3 August 2026

A note on this document. Written so a customer's legal team can read it against the product and find the two match. Still to be reviewed by qualified counsel.

1. Scope and roles

This Data Processing Addendum ("Addendum") forms part of the ClipLogger Terms of Service (the "Agreement") between the customer in Annex I ("Customer", "you") and Sous Creative LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States ("ClipLogger", "we", "us").

It applies where you use ClipLogger to process personal data about other people: Sync, because a synced project can contain names of third parties you logged, for example a roster of named athletes, and Rush, because extracted frames may show identifiable people.

DataYour roleOur role
Customer Content: synced project documents, logged names and notes, derived metadata, Rush frames and job contentControllerProcessor
Account and billing data: email, display name, subscription, seats, credit ledger, invoices, logsControllerController

For Customer Content we act only as your processor, on your instructions. For account and billing data we are an independent controller, because we decide what we need to run accounts, bill correctly, meet tax obligations and keep the service secure. That processing is described in the Privacy Policy. If you are yourself a processor for another controller, you confirm you have its authority to appoint us as a sub-processor on these terms.

"Personal data", "processing", "controller", "processor", "data subject", "supervisory authority" and "personal data breach" carry their GDPR meanings. "Data Protection Law" means the EU GDPR (2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other applicable data protection law. "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of that Act.

2. Processing on documented instructions

We process Customer Content only on your documented instructions, including for international transfers, unless a law that applies to us requires otherwise; if it does, we will tell you first unless that law prohibits it.

Your documented instructions are the Agreement, this Addendum, your configuration choices in the application and dashboard, and the jobs you submit. Nothing else instructs us, and we do not process Customer Content for our own purposes.

We do not use Customer Content to train, fine-tune or evaluate any model. We do not sell it, share it for advertising, or build datasets from it.

We will tell you if an instruction appears to infringe Data Protection Law, and may decline to act on it.

3. Confidentiality

Everyone we authorise to process Customer Content is bound by an appropriate duty of confidentiality, contractual or statutory, surviving their engagement. Access is granted on a need to know basis and removed when no longer needed.

4. Security

We implement and maintain the technical and organisational measures in Annex II, taking account of the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risk to data subjects. We may update them as the service develops, but will not reduce the level of security below Annex II.

You are responsible for your own side: the security of your credentials, who you invite into your team, their role, and what you choose to sync.

5. Sub-processors

You give us general authorisation to appoint sub-processors. Those engaged at the date of this Addendum:

Sub-processorPurposeProcessing location
SupabaseAuthentication, database, storage for frames and synced projectsAWS us-east-1, United States
NetlifySite hosting, serverless functions, request logsUnited States
StripePayments, merchant of record, billing portalUnited States and global
AnthropicRush model provider: analysis of submitted frames. Does not train on API inputs; retains them up to 30 days for trust and safety.United States
OpenRouterRush model provider: routes frames to a model vendor. Requests demand no-retention routing, so vendors that store prompts are not used.United States
Simple AnalyticsCookie-free page-view counting on the website, including signed-in pages. Receives page path and device characteristics; stores nothing on the visitor's device and receives no account identifier, so it cannot link a page view to a named user.Netherlands, European Union

Account email is sent by Supabase, already listed. No separate email provider is used

Before we add or replace a sub-processor that will process Customer Content, we will give you at least 30 days notice by email. You may object on reasonable data protection grounds within that period, and if we cannot offer a reasonable alternative you may terminate the affected part of the service, with a refund of any unused prepaid fees for it.

Each sub-processor is bound by obligations no less protective than this Addendum, and we remain fully liable for their performance.

6. Data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as reasonably possible, in responding to data subject requests for access, rectification, erasure, restriction, portability and objection.

The application already gives you direct control over most of this: you can read, edit and delete the metadata in your projects, and delete a synced project or a Rush job at any time. For anything you cannot do yourself, email hello@cliplogger.com.

If a data subject contacts us directly about Customer Content we will not respond substantively; we will point them to you and forward the request, unless the law requires otherwise.

7. Impact assessments and prior consultation

We will provide reasonable assistance with data protection impact assessments and prior consultation of a supervisory authority under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to us. This Addendum, its Annexes and the Privacy Policy should supply most of what such an assessment needs.

8. Personal data breach

If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay and in any event within 72 hours.

The notification will describe, so far as we know at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, in phases if we cannot give it all at once. We will help you meet your duties under Articles 33 and 34 GDPR. Notification is not an admission of fault.

9. International transfers

All processing under this Addendum takes place in the United States, which for data subjects in the EEA, the United Kingdom or Switzerland is a transfer under Chapter V of the GDPR.

Where a transfer from the EEA is subject to Chapter V and no other lawful mechanism applies, the SCCs, Module Two (controller to processor), are incorporated by reference and completed as follows:

  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2, general written authorisation, with the notice period in section 5.
  • Clause 11(a): the optional independent dispute resolution body is not selected.
  • Clause 17: Option 1, governed by the law of the State of Florida, United States, without regard to its conflict of laws rules, and the state and federal courts located in Pinellas County, Florida if that is an EU Member State whose law allows third party beneficiary rights, and otherwise by the law of Ireland.
  • Clause 18(b): disputes are resolved before the courts of the Member State identified in Clause 17.
  • SCC Annexes I, II and III are populated by Annex I, Annex II and the section 5 table.

For transfers subject to the UK GDPR, the UK Addendum applies to those SCCs: Table 1 is completed by Annex I.A, Tables 2 and 3 by the selections above, and in Table 4 neither party may end the UK Addendum when the Approved Addendum changes.

For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as the Swiss Federal Act on Data Protection, supervisory authorities read as the Federal Data Protection and Information Commissioner, and legal entities' data protected until Swiss law provides otherwise.

All five sub-processors publish a DPA incorporating the Standard Contractual Clauses and the UK Addendum for onward transfers, and each takes effect automatically on acceptance of that vendor's terms rather than requiring a separately signed copy. Netlify and Stripe are additionally certified under the EU-US Data Privacy Framework.

Requests can be made to the data importer at the address in Annex I.A

10. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this Addendum. In the first instance that is satisfied by documentation: this Addendum and its Annexes, the Privacy Policy, the sub-processor list, written answers to a reasonable security questionnaire, and any third party reports our sub-processors give us.

If that is genuinely insufficient, you may audit us, or appoint an independent auditor who is not a competitor and is bound by confidentiality: no more than once in any twelve month period, unless a supervisory authority requires otherwise or there has been a breach affecting your Customer Content; on at least thirty days written notice; during business hours; at your cost. Findings are our confidential information. Audits do not extend to sub-processors' systems, whose own audit terms apply, or to other customers' data.

11. Deletion and return

You can delete Customer Content yourself at any time: a synced project, a Rush job, or the whole account.

On termination or expiry of the Agreement we will delete Customer Content held on our systems within 30 days, or return it if you ask in writing within that period. Deletion propagates to backups on the ordinary cycle. Two carve-outs, disclosed rather than buried:

  1. We keep ledger, invoice and tax records for as long as tax law requires, typically six to seven years. Those are account and billing data, for which we are controller.
  2. Retention of extracted Rush frames is being put on a fixed schedule. We keep the frames from a Rush job for as long as we need them, and no longer. In practice that means for as long as the job record exists, because that is what lets a result be traced back to what produced it and lets us investigate if you tell us a result was wrong. There is no fixed calendar window, so the criteria are the honest answer: the frames go when the job goes. Delete the job, ask us to delete it, or close your account, and they are removed. Until then we will not state a deletion window we do not enforce, and you can ask us to delete any job's frames.

Nothing on your own disk is affected: sidecar metadata beside your footage is yours and stays where it is.

12. General

Liability. Each party's liability under this Addendum is subject to the limitations in the Agreement, to the extent Data Protection Law permits.

Precedence. This Addendum prevails over the Agreement on the processing of personal data; the SCCs prevail over this Addendum.

Term. It takes effect with the Agreement, or on signature if later, and continues while we process Customer Content.

Governing law. Except where the SCCs or the UK Addendum specify otherwise, this Addendum is governed by the law stated in the Agreement, at the State of Florida, United States, without regard to its conflict of laws rules, and the state and federal courts located in Pinellas County, Florida.

Signature. Effective without signature for customers who accept the Agreement. If your legal team needs a countersigned copy, email hello@cliplogger.com.


Annex I: Description of the processing

A. Parties

Data exporter (controller): the Customer. Name: ______________________ Address: ______________________ Contact person, position, email: ______________________ Activities relevant to the transfer: production and media asset management using ClipLogger.

Data importer (processor): ClipLogger. Name and address: Sous Creative LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States Contact: hello@cliplogger.com Activities relevant to the transfer: providing the ClipLogger account, project sync and Rush.

B. Description of processing

Subject matter. The ClipLogger online services: accounts, teams and seats, project sync, and Rush batch analysis of frames extracted from the Customer's footage.

Duration. The term of the Agreement, plus the deletion period in section 11.

Nature. Collection, storage, hosting, structuring, transmission to model providers, analysis, retrieval, return and deletion.

Purpose. To synchronise the Customer's project documents across its devices and authorised team members, and to return analysis results for clips it submits to Rush. No other purpose.

Categories of data subjects.

  • The Customer's own personnel holding accounts or team seats: producers, directors, crew and viewers.
  • Individuals recorded or named in the Customer's footage and project metadata, for example athletes on a roster, crew, interview subjects, and members of the public captured incidentally.

Categories of personal data.

  • Identifiers the Customer enters: names, roster entries, jersey or bib numbers, roles, notes and tags.
  • Derived metadata: transcript text, on-screen text, embeddings, face grouping identifiers and their frame regions, subject and entity records, tags and descriptions.
  • Still frames submitted to Rush, which may show identifiable individuals, plus the model output for them.
  • Account identifiers of team members: user identifier, email, display name, role, and which member spent each credit.
  • Technical data: IP addresses and request metadata in server logs.

Source footage files are not uploaded. Rush receives extracted still frames only.

Sensitive data. The Customer determines the content of its projects and should not upload special category data without an Article 9 condition. Note specifically: the application groups the same face across clips, and where the Customer uses that grouping to identify particular named individuals, the resulting data may be biometric data for the purpose of uniquely identifying a natural person, and so a special category under Article 9 GDPR. The Customer is responsible for its lawful basis and Article 9 condition for that use, and for any consents or releases required. Safeguards are those in Annex II, plus the Customer's control over what syncs and what is submitted.

Frequency. Continuous for synced project documents while sync is on. On submission, and only on submission, for Rush jobs.

Retention. Synced project documents until the Customer deletes the project or account, then section 11. Rush frames per section 11, carve-out 2. Job records for the life of the account. Server logs per sub-processor defaults, 7 days.

Sub-processors. As listed in section 5.

C. Competent supervisory authority

The authority competent for the Customer as data exporter, determined under Clause 13 of the SCCs from its establishment in Annex I.A.


Annex II: Technical and organisational measures

AreaMeasure
Minimisation by architectureThe application runs locally by default. Uploads happen only when the Customer submits a Rush batch or turns sync on, and Rush receives still frames, not video.
Tenant isolationRow Level Security on the Postgres tables holding customer data: a signed-in user reads only rows belonging to their own account or team, enforced in the database, not only in application code.
Write controlWrites to billing, credit ledger, subscription and job tables are restricted to a service role running only in server-side functions. Its key is never exposed to the browser.
Ledger integrityThe credit ledger is append only, each entry recording the actor, reason and originating payment event.
AuthenticationSupabase Auth, passwords hashed and salted, session tokens cleared on sign-out. Team membership granted by revocable invitation tokens scoped to a team and role.
Payment dataNo card data reaches our systems. Stripe processes all payments as merchant of record; we store only a customer identifier.
EncryptionTLS on all traffic between the application, browser, functions, database, storage and model providers. Database and object storage encrypted at rest.
Access controlAdministrative access to production is limited to personnel who need it, individually attributed, and removed when no longer needed. Sub-processor consoles require MFA.
LoggingJob lifecycle events, credit movements and function invocations are logged server side, supporting incident investigation and breach assessment.
Model provider handlingFrames go to providers through standard API interfaces solely to return a result, and are never used by us to train or fine-tune a model.
DeletionCustomers can delete a synced project, a Rush job, or the account. A frame retention sweep exists and is being put on a fixed schedule (section 11).
ResilienceManaged platform with platform-level redundancy and backups. daily database backups, retained 7 days
Sub-processor governanceEngaged under written terms no less protective than this Addendum, each incorporating the SCCs and UK Addendum.
PersonnelEveryone with access to Customer Content is bound by confidentiality surviving their engagement.

Annex III: Sub-processors

The table in section 5 is Annex III for the purposes of the SCCs.


Contact: hello@cliplogger.com