Legal · DPA
Data Processing Agreement
When Clipsie clips your stream it handles personal data belonging to other people — your chat, your guests, anyone audible or visible in the footage. For that data you are the controller and we are your processor. This document is the written contract GDPR Art. 28 requires between us. It takes effect automatically when you accept the Terms; you don't need to sign anything.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Yari Eugster, Sole proprietorship (Einzelunternehmen), Grubenstrasse 15, 8322 Madetswil, Switzerland ("Processor", "Clipsie", "we"). Where this DPA and the Terms conflict on the processing of personal data, this DPA wins.
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). Where the Swiss Federal Act on Data Protection ("FADP") applies instead, references to the GDPR are read as references to the equivalent FADP provisions, "EU" includes Switzerland, and the FDPIC is the competent authority.
Roles
You are the controller of the personal data that reaches Clipsie through the channels and accounts you connect: you decide which stream to clip, what happens to the result, and where it gets published. We are your processor for that data and act only on your instructions.
We are an independent controller for a narrower set of data we determine ourselves: your account and billing records, our security and operational logs, and product telemetry. That processing is governed by our Privacy Policy, not by this DPA.
Scope of processing
Subject matter and nature. Automated detection of clip-worthy moments in livestream content, transcription, scoring, rendering into short-form video, hosting for your review, and publication to the third-party accounts you authorise.
Purpose. Providing the Clipsie service to you, and nothing else. We do not use your data to train our own models, to build profiles, or for advertising.
Duration. For as long as your account is active, plus the retention windows described in the Privacy Policy (review media up to 30 days; rejected or failed review media normally removed within 7 days; crop-debug images 7 days).
Categories of data subject.
- Participants in your stream chat.
- People who are visible or audible in the source footage — you, your guests, and anyone the stream captures.
- People named or discussed in the stream and therefore in transcripts.
- Members of your team who you give dashboard access.
Types of personal data.
- Chat messages and the display names attached to them.
- Audio and video containing voices and likenesses.
- Transcripts generated from that audio, and titles, captions and scores derived from it.
- Channel, account and video identifiers on Twitch, YouTube and TikTok.
- OAuth access and refresh tokens for the accounts you connect.
Clipsie is not designed for special categories of personal data under Art. 9 GDPR or for criminal-offence data under Art. 10. Live footage can nonetheless capture such data incidentally; you remain responsible for deciding whether streaming and clipping it is lawful.
Processing on instructions
We process personal data only on your documented instructions, including for transfers to a third country. Your instructions are: this DPA, the Terms, and the settings and actions you take in the dashboard — the channels you connect, the destinations you authorise, your review and auto-publish choices, and your retention settings.
We process outside your instructions only where EU or member-state law requires it, and in that case we will tell you before processing unless that law forbids the notice.
If we consider an instruction to infringe data-protection law, we will tell you and may suspend that processing until it is resolved.
Confidentiality
Clipsie is operated by one person, Yari Eugster, who is bound to confidentiality in respect of all personal data processed under this DPA. If we ever engage staff or contractors, they will be placed under an equivalent written confidentiality obligation before being given access, and access will be granted only to the extent their work requires it.
Security measures
We implement appropriate technical and organisational measures under Art. 32 GDPR. As at the date above, these are:
- Encryption in transit: HTTPS/TLS for all web, dashboard and API traffic; the domain is HSTS-preloaded.
- Encryption at rest: OAuth access and refresh tokens are encrypted before storage. Database and object storage are encrypted at rest by the providers.
- Access control: row-level security so a tenant can only read its own records; separation between the public client key and the service role; OAuth client secrets and token-encryption keys are never sent to the browser.
- Least privilege: we request the narrowest workable OAuth scope. The production YouTube connection is upload-only and cannot read your channel, videos, comments, subscribers or analytics.
- Data minimisation: transcript text is not written to application logs; one-time authorisation codes and PKCE verifiers are redacted once a connection completes.
- Retention limits: automated expiry of review media and debug artefacts on the schedules stated above, so material does not accumulate indefinitely.
- Resilience and recovery: managed database backups from our infrastructure providers; the pipeline is restartable and re-derives working state.
- Personnel: a single operator with individually authenticated access to production systems.
We are transparent about what we do not have: Clipsie holds no ISO 27001 certification and no SOC 2 report, and has not undergone an independent penetration test. If your risk assessment requires either, tell us before you sign up rather than after.
These measures may change as the service evolves. We will not reduce the overall level of security during the term of your subscription.
Sub-processors
You give us general written authorisation to engage sub-processors. The current list, with what each one does and where it processes, is at clipsie.app/subprocessors and forms Annex II to this DPA.
We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
Before a new sub-processor starts processing your data, we will give you at least 30 days' notice by email and by updating that page. If you object on reasonable data-protection grounds within those 30 days, tell us at [email protected] and we will try to offer an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
International transfers
Your account records, clip metadata and encrypted tokens are stored in the European Union (Frankfurt, Germany). Clip processing runs in Switzerland, which holds an EU adequacy decision, so no further safeguard is needed for that leg.
Some sub-processors process data in the United States — see Annex II for which. For those transfers we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module 3, processor-to-processor) together with the Swiss addendum recognised by the FDPIC, supplemented by the technical measures in section 05. Where a provider is certified under the EU–U.S. or Swiss–U.S. Data Privacy Framework, we may rely on that instead.
Data subject requests
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in meeting your obligations to respond to requests to exercise rights under Chapter III GDPR.
In practice: the dashboard lets you find, review and delete clips yourself, and disconnect any platform. For anything you cannot do there, write to [email protected] and we will help within 5 working days.
If a data subject contacts us directly about data we process on your behalf — for example a chat participant asking to be removed from a clip — we will not respond substantively. We will forward the request to you without undue delay, because the decision is yours to make.
Personal data breaches
We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting data we process for you. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of it at once, we will supply it in phases as it becomes available.
We assist you with your own obligations under Arts. 33 and 34 GDPR, and with data protection impact assessments and prior consultations under Arts. 35 and 36, taking into account the nature of the processing and the information available to us.
Audits and information
We make available to you all information necessary to demonstrate compliance with Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice, please start by asking: most questions are answered by this DPA, the sub-processor list and a written response from us. Where that is not enough, you may audit once per twelve-month period on 30 days' written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. You bear your own audit costs; we bear ours unless the audit reveals a material breach by us. Additional audits may be carried out where a supervisory authority requires one or following a personal data breach.
Deletion and return
You can delete clips and disconnect platforms yourself at any time from the dashboard.
On termination of the service, we delete personal data processed on your behalf, including connected-account tokens, within 30 days, unless EU or member-state law requires us to keep it — in which case we keep only what the law requires, for as long as it requires, and continue to protect it under this DPA. If you ask for a copy before deletion, we will provide your clip records in a machine-readable format.
Videos already published to YouTube, TikTok or elsewhere stay under your control on those platforms. Deleting your Clipsie account does not remove them, and we cannot remove them for you once we no longer hold a valid token.
Your obligations
As controller you warrant that:
- you have a lawful basis for the processing you instruct, and have given the required information to the data subjects involved;
- you have the right to stream, record and clip the content you route through Clipsie, including the rights of anyone appearing in it;
- your instructions to us comply with data-protection law;
- you keep the credentials and connected accounts of your Clipsie tenancy secure.
A practical note rather than a legal one: your chat participants did not sign up with us, and in most jurisdictions your stream's own terms and platform notices are what covers them. It is worth checking that they do.
Term, liability and changes
This DPA takes effect when you accept the Terms and continues for as long as we process personal data on your behalf. Sections that by their nature should survive — confidentiality, deletion, liability — survive termination.
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by applicable data-protection law.
We may update this DPA to reflect changes in the service or in the law. Where a change materially reduces your rights we will give you 30 days' notice by email before it takes effect, and you may terminate if you do not accept it.
Questions: [email protected].