On this page
- 1. Definitions and Interpretation
- 2. Scope and Roles of the Parties
- 3. Processing on Documented Instructions
- 4. Personnel and Confidentiality
- 5. Security of Processing
- 6. Sub-processing
- 7. Assistance with Data Subject Rights
- 8. Personal Data Breach Notification
- 9. Deletion or Return of Customer Personal Data
- 10. Audit Rights and Compliance
- 11. International Data Transfers
- 12. United States State Privacy Laws Addendum
- 13. Data Residency
- 14. General Provisions
- Annex I — Description of the Processing
- A. Parties
- B. Categories of data subjects
- C. Categories of Personal Data
- D. Special category data
- E. Frequency, nature, purpose and duration
- Annex II — Technical and Organisational Measures
- Access control and authentication
- Encryption and key handling
- System and network security
- Logging, monitoring and integrity
- Resilience and recovery
- Organisational measures
- Annex III — List of Sub-processors
Data Processing Addendum
This Data Processing Addendum governs how ClipVision, Ltd. processes personal data on behalf of its business customers when providing the Inoue AI platform, in accordance with Article 28 of the GDPR and equivalent data-protection laws.
Last updated · v1.0
This Data Processing Addendum (the “DPA”) forms part of, and is incorporated by reference into, the agreement between ClipVision, Ltd. (the operator of the Inoue AI platform, “ClipVision”, “we”, “us” or “Processor”) and the business customer identified in that agreement (the “Customer” or “Controller”) under which the Customer subscribes to or otherwise uses the Inoue AI services (the “Agreement” and the “Services” respectively). This DPA reflects the parties’ agreement on the processing of Personal Data in connection with the Services and applies to the extent ClipVision processes Customer Personal Data as a processor on the Customer’s behalf.
Where the Customer uses the Services as a consumer rather than on behalf of an organisation, the Privacy Policy (under which ClipVision acts as a controller of account data) governs, and this DPA does not apply. This DPA is entered into by the Customer on its own behalf and, to the extent required by applicable Data Protection Laws, in the name of and on behalf of its Authorised Affiliates.
Parties
- Processor
- ClipVision, Ltd. (a Delaware corporation)Principal place of business: Via Giacomo Matteotti 55, 21020 Barasso (Varese), ItalyCompany register number: [ClipVision to supply: company register number]VAT identification number: [ClipVision to supply: VAT ID]
- Data-protection contact
- [email protected]
- Legal notices
- [email protected]
1. Definitions and Interpretation
Capitalised terms used but not defined in this DPA have the meaning given to them in the Agreement. The following definitions apply:
- “Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including (as applicable) Regulation (EU) 2016/679 (the “GDPR”), the GDPR as it forms part of the law of the United Kingdom (the “UK GDPR”) together with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”) and other U.S. state privacy laws, and the Australian Privacy Act 1988 and the Australian Privacy Principles (“APPs”).
- “Controller”, “processor”, “data subject”, “personal data breach”, “processing” and “supervisory authority” have the meanings given to them in the GDPR; “process”, “processes” and “processed” are construed accordingly.
- “Customer Personal Data” means any Personal Data that ClipVision processes on behalf of the Customer in the course of providing the Services, as more particularly described in Annex I.
- “Personal Data” means any information relating to an identified or identifiable natural person that is protected as “personal data”, “personal information” or an equivalent term under Data Protection Laws.
- “Special Category Data” means Personal Data revealing the categories described in Article 9(1) GDPR, and includes biometric data processed for the purpose of uniquely identifying a natural person.
- “Standard Contractual Clauses” or “SCCs” means (i) for transfers subject to the GDPR, the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”); (ii) for transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner (the “UK Addendum”); and (iii) for transfers subject to the FADP, the EU SCCs as adapted for Switzerland.
- “Sub-processor” means any third party engaged by ClipVision (including a ClipVision affiliate) to process Customer Personal Data in connection with the Services.
2. Scope and Roles of the Parties
This DPA applies to ClipVision’s processing of Customer Personal Data carried out to provide the Services. With respect to Customer Personal Data, the parties agree that the Customer is the controller (or, where the Customer is itself a processor acting on behalf of a third-party controller, a processor) and ClipVision is the processor (or sub-processor, as applicable).
ClipVision processes certain Personal Data as an independent controller — in particular account-administration data, billing and tax records, security and audit logs, and data processed to operate, secure and improve the Services. That controller-side processing is governed by the Privacy Policy and not by this DPA. The Customer remains solely responsible for determining the lawful basis for, and the lawfulness of, its instructions and of the Customer Personal Data it submits to the Services.
3. Processing on Documented Instructions
ClipVision will process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to process it by applicable law to which ClipVision is subject. Where such a legal requirement applies, ClipVision will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Agreement (including the Customer’s configuration and use of the Services), this DPA and Annex I constitute the Customer’s complete and final documented instructions for the processing of Customer Personal Data. Additional or alternative instructions must be agreed in writing and may be subject to additional fees where they require a change to the Services.
ClipVision will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws. ClipVision is not obliged to, and will not, monitor the Customer’s compliance with Data Protection Laws or assess the lawfulness of the Customer’s instructions.
4. Personnel and Confidentiality
ClipVision will ensure that any person it authorises to process Customer Personal Data is subject to an appropriate duty of confidentiality (whether a contractual or statutory duty) and processes Customer Personal Data only on ClipVision’s instructions, except where disclosure is required by applicable law.
ClipVision limits access to Customer Personal Data to those personnel who need access to provide, support, secure and improve the Services, applies role-based access controls, and provides its personnel with appropriate data-protection and security training.
5. Security of Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, ClipVision implements and maintains appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, as described in Annex II.
The Customer is responsible for independently determining whether the technical and organisational measures described in Annex II meet the Customer’s requirements and for securing its own account credentials, access tokens and the systems it uses to access the Services. ClipVision may update its security measures from time to time, provided that such updates do not materially reduce the overall level of security of the Services during the term of the Agreement.
6. Sub-processing
The Customer provides ClipVision with a general authorisation to engage Sub-processors to process Customer Personal Data in connection with the Services, subject to this Section 6. The Sub-processors engaged as at the effective date of this DPA are listed in Annex III.
Where ClipVision engages a Sub-processor, it will impose on that Sub-processor, by way of a written contract, data-protection obligations that are no less protective than those set out in this DPA, including obligations to implement appropriate technical and organisational measures. ClipVision remains fully liable to the Customer for the performance of each Sub-processor’s data-protection obligations.
ClipVision will give the Customer at least thirty (30) days’ prior notice of the addition or replacement of a Sub-processor (the “Notice Period”), by updating Annex III and/or by an electronic notification mechanism to which the Customer may subscribe at [email protected]. If, within the Notice Period, the Customer reasonably objects to a new Sub-processor on legitimate data-protection grounds, the parties will work together in good faith to find a commercially reasonable resolution. If no such resolution can be found, the Customer may, as its sole and exclusive remedy, terminate the affected Services by giving written notice to ClipVision, and ClipVision will refund any prepaid fees covering the remainder of the then-current term for the terminated Services.
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, ClipVision will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer’s obligation to respond to requests by data subjects to exercise their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, data portability and objection).
ClipVision provides self-service functionality within the Services that enables the Customer to access, correct, export and delete Customer Personal Data, which the Customer may use to respond to data-subject requests. If ClipVision receives a request from a data subject relating to Customer Personal Data, it will, unless prohibited by law, promptly direct the data subject to the Customer and will not respond to the request itself except on the Customer’s documented instructions or as required by law. The Customer may contact ClipVision for additional assistance at [email protected].
ClipVision will also provide the Customer with reasonable assistance in ensuring compliance with the Customer’s obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data-protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to ClipVision.
8. Personal Data Breach Notification
ClipVision will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will, to the extent then known to ClipVision and as such information becomes available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed to address it and to mitigate its possible adverse effects.
ClipVision will take reasonable steps to contain, investigate and remediate the breach. ClipVision’s notification of, or response to, a personal data breach under this Section 8 is not an acknowledgement by ClipVision of any fault or liability. The Customer is solely responsible for fulfilling any third-party notification obligations applicable to the Customer (including notifications to supervisory authorities and affected data subjects).
9. Deletion or Return of Customer Personal Data
Upon termination or expiry of the Agreement, ClipVision will, at the Customer’s choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires continued storage of the Personal Data. The Customer may export Customer Personal Data using the self-service functionality of the Services before termination.
ClipVision applies a soft-deletion model: when Customer Personal Data is deleted, the underlying record is first marked as deleted and made inaccessible through the Services, and the associated stored media objects and records are then irreversibly removed in accordance with ClipVision’s retention schedule. Residual copies of Customer Personal Data may persist in encrypted, time-limited backups for the backup-retention period stated in the Privacy Policy, after which they expire and are overwritten. While they persist, such backups are isolated from active processing and are processed solely for disaster-recovery purposes.
10. Audit Rights and Compliance
ClipVision will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
The Customer may exercise its audit right by submitting a written request to [email protected]. The parties agree that ClipVision may satisfy an audit request by providing then-current third-party certifications, audit reports or written responses to a reasonable security questionnaire. Where an audit report or questionnaire response does not provide the information reasonably required, the Customer may, on at least thirty (30) days’ prior written notice and no more than once in any twelve-month period (except where required by a supervisory authority or following a personal data breach), conduct an on-site audit during regular business hours, subject to ClipVision’s confidentiality and security requirements and without unreasonably disrupting ClipVision’s operations or those of its other customers. Each party bears its own costs of an audit unless the audit reveals a material non-compliance by ClipVision, in which case ClipVision bears the reasonable costs of that audit.
11. International Data Transfers
Customer Personal Data stored as media objects is hosted in the European Union (London region). ClipVision and its Sub-processors may, however, process certain Customer Personal Data in countries outside the European Economic Area, the United Kingdom and Switzerland, including the United States, as described in Annex III.
Where ClipVision transfers Customer Personal Data from the EEA, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision, the transfer is made pursuant to the applicable Standard Contractual Clauses, which are hereby incorporated into this DPA by reference and completed as follows: (i) the Customer is the “data exporter” and ClipVision is the “data importer”; (ii) for transfers from ClipVision to a Sub-processor, the module reflecting a processor-to-processor (or processor-to-sub-processor) relationship applies; (iii) the optional docking clause applies; (iv) for the purposes of Clause 9, the general written authorisation and Notice Period in Section 6 apply; (v) for the purposes of Clauses 17 and 18, the governing law and forum are those of Ireland unless Data Protection Laws require otherwise; and (vi) Annexes I, II and III to this DPA populate the corresponding annexes to the SCCs. For transfers subject to the UK GDPR, the UK Addendum applies and is completed using the information in this DPA; for transfers subject to the FADP, references to the GDPR are read as references to the FADP and the competent authority includes the Swiss Federal Data Protection and Information Commissioner.
ClipVision will implement supplementary technical, organisational and contractual measures where necessary to ensure that transferred Customer Personal Data enjoys a level of protection essentially equivalent to that guaranteed within the EEA.
12. United States State Privacy Laws Addendum
This Section 12 applies to the extent ClipVision processes Personal Data that is subject to the CCPA or another U.S. state privacy law. With respect to such Personal Data, ClipVision acts as a “service provider” (or “processor”, as such terms are defined under the applicable law) and processes that Personal Data solely on behalf of, and for the business purposes specified by, the Customer.
- ClipVision does not sell or share Customer Personal Data, and does not retain, use or disclose it for any purpose other than the specific business purpose of providing the Services, or as otherwise permitted by the applicable law.
- ClipVision does not retain, use or disclose Customer Personal Data outside the direct business relationship between the parties, and does not combine it with Personal Data received from other sources, except as permitted by the applicable law.
- ClipVision certifies that it understands the restrictions set out in this Section 12 and will comply with them.
- ClipVision will notify the Customer if it determines that it can no longer meet its obligations under the applicable law, and the Customer may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data.
13. Data Residency
User-generated media submitted to and produced by the Services — including uploaded images, identity and likeness images, and generated images and video — is stored at rest in the European Union, in ClipVision’s object-storage region located in London, United Kingdom (“lon1”). Structured account and transactional data is stored in ClipVision’s primary database hosted within the European Union. Where the provision of a specific feature requires Customer Personal Data to be processed by a Sub-processor located outside the EEA, that processing is described in Annex III and is governed by Section 11.
14. General Provisions
In the event of a conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
This DPA takes effect on the effective date stated above and continues for as long as ClipVision processes Customer Personal Data on the Customer’s behalf. It is governed by the law and subject to the jurisdiction stated in the Agreement, except to the extent Data Protection Laws or the Standard Contractual Clauses require otherwise. The Customer’s use of the Services is also subject to the Terms of Service and the Acceptable Use Policy.
Annex I — Description of the Processing
A. Parties
Data exporter / controller: the Customer identified in the Agreement. Data importer / processor: ClipVision, Ltd., Via Giacomo Matteotti 55, 21020 Barasso (Varese), Italy, operating the Inoue AI platform.
B. Categories of data subjects
- The Customer’s authorised users and administrators of the Services.
- Individuals depicted in images, audio or video that the Customer uploads to, or generates with, the Services (including faces, likenesses and voices used to create virtual-influencer models).
- The Customer’s own customers, contacts, audience members and other third parties whose Personal Data the Customer submits to the Services (for example, participants in conversations managed through a connected creator-CRM account).
C. Categories of Personal Data
- Account and identity data: email address, display name, organisation membership, and account preferences.
- Authentication data: password (stored only as an Argon2id hash), two-factor-authentication secrets (encrypted) and recovery-code hashes, and session and device identifiers.
- User-generated content: text prompts and inputs, uploaded images, audio and video, identity/likeness images, and generated output media, together with associated metadata (file hashes, dimensions, MIME types).
- Voice and audio data: voice recordings and samples submitted for transcription, text-to-speech or voice cloning.
- Billing data: tokenised payment-provider identifiers (customer, subscription, invoice, payment-intent, price and product identifiers), billing email, and order amounts and currency. Full payment-card numbers are entered directly with the payment processor and are never received or stored by ClipVision.
- Connected-account data: OAuth access and refresh tokens (encrypted), connected social-account handles, display names and avatars, published content and captions, and per-account analytics; and, for connected creator-CRM accounts, conversation and direct-message content and participant data.
- Device and network data: IP address and user-agent strings associated with sessions and push-notification subscriptions, and push-notification endpoints and keys.
- Usage and log data: usage and credit ledgers, audit logs, and job and status history.
D. Special category data
ClipVision does not intentionally collect Special Category Data. However, images, audio or video that the Customer uploads or generates may incidentally contain Special Category Data, and facial or likeness images used to create or drive virtual-influencer models may, depending on how they are used, constitute biometric data. ClipVision processes any such data solely on the Customer’s instructions and in reliance on the Customer’s confirmation that it has obtained any explicit consent or other lawful basis required under Article 9 GDPR.
E. Frequency, nature, purpose and duration
- Frequency: continuous, for the duration of the Agreement.
- Nature and purpose: hosting, generation, transcription, captioning, scheduling, publishing, analytics, billing, communication and support operations necessary to provide the Inoue AI Services as instructed by the Customer.
- Duration: for the term of the Agreement and thereafter only as required to comply with the deletion and retention provisions of this DPA and the Privacy Policy.
The competent supervisory authority for ClipVision is the Italian Garante per la protezione dei dati personali. The categories of Personal Data and the retention periods applicable to each are described in the Privacy Policy.
Annex II — Technical and Organisational Measures
ClipVision implements and maintains the following technical and organisational measures, which it may update from time to time provided the overall level of security is not materially reduced.
Access control and authentication
- Passwords are stored only as Argon2id hashes; plaintext passwords are never stored or logged.
- Optional two-factor authentication (time-based one-time passwords) is available, with two-factor secrets and recovery codes stored encrypted or hashed.
- Role-based access controls and least-privilege principles govern access to production systems and Customer Personal Data; access is restricted to authorised personnel bound by confidentiality obligations.
- Row-level security and tenant-scoping controls isolate each customer’s data within shared infrastructure.
Encryption and key handling
- Personal Data in transit is protected with TLS.
- Sensitive secrets — including third-party OAuth access and refresh tokens, two-factor-authentication secrets and customer-supplied provider API keys — are encrypted at rest.
- Webhook and inter-service messages are authenticated with HMAC signatures and nonce-based replay protection.
System and network security
- Production services run on hardened, access-controlled infrastructure with database connections brokered through a connection pooler and outbound integrations isolated from core data stores.
- Per-IP and per-user rate limiting and abuse controls protect authentication and other sensitive endpoints.
- Input validation and bounded request handling protect against malformed or oversized payloads.
Logging, monitoring and integrity
- Audit logs record security-relevant actions; application errors and performance are monitored through an error-tracking and tracing pipeline.
- A soft-deletion and tombstone model preserves data integrity and prevents accidental irreversible loss while enabling controlled, scheduled erasure.
Resilience and recovery
- Encrypted, time-limited database backups support disaster recovery and are retained for a defined backup-retention period, after which they expire.
- User-generated media is stored in the European Union with content-delivery caching at the edge.
Organisational measures
- Personnel with access to Customer Personal Data are bound by confidentiality obligations and receive data-protection and security guidance.
- Changes to production code pass automated quality and security gates before release.
- Sub-processors are subject to written data-protection terms no less protective than this DPA and are reviewed before engagement.
Annex III — List of Sub-processors
The following Sub-processors are engaged to process Customer Personal Data in connection with the Services as at the effective date of this DPA. “Processing location” indicates where the relevant Sub-processor processes Customer Personal Data; where a Sub-processor’s processing location depends on its own data-processing terms, both the European and United States locations are indicated.
| Sub-processor | Personal data processed | Purpose | Processing location |
|---|---|---|---|
| Stripe | Tokenised billing identifiers, billing email, order amounts and currency. | Payments, subscriptions, one-off credit purchases and refunds. | United States and European Union. |
| Kie.ai | Text prompts, input and reference images, identity and likeness images, generated output media. | AI image and video generation. | United States. |
| ElevenLabs | Voice recordings and samples, text-to-speech input, and customer-supplied ElevenLabs API keys (encrypted). | Voice generation, text-to-speech and voice cloning. | United States. |
| Deepgram | Audio and video submitted for transcription, and resulting transcript text. | Speech-to-text transcription. | United States. |
| AssemblyAI | Audio and video submitted for transcription, and resulting transcript text. | Speech-to-text transcription (alternate provider). | United States. |
| Remotion | Transcript text and media submitted for caption rendering. | Burned-in caption rendering. | United States. |
| MotionMuse | Generation input and output media. | MotionMuse generation flow. | United States. |
| TikTok | OAuth tokens (encrypted), connected-account handle, display name and avatar, published video content and captions, and per-account analytics. | Social-account connection, publishing and analytics. | United States and global. |
| Meta Platforms (Threads) | OAuth tokens (encrypted), published content and captions, and insights. | Threads publishing and insights. | United States and global. |
| Meta Platforms (Instagram) | OAuth tokens (encrypted), published media and captions, and insights. | Instagram publishing and insights (available where enabled by the Customer). | United States and global. |
| Google (YouTube) | OAuth tokens (encrypted), uploaded video content and metadata, and insights. | YouTube publishing and insights (available where enabled by the Customer). | United States and global. |
| Fanvue | OAuth tokens (encrypted), connected-account identity, conversation and direct-message content and participant data, and published content. | Creator-CRM messaging, posting and account connection. | European Union and United States. |
| DigitalOcean (Spaces object storage) | All user-generated media at rest (uploaded and generated images and video, model dataset and identity images, downloaded media). | Primary media object storage and content-delivery origin. | European Union (London — lon1). |
| DigitalOcean (managed infrastructure) | All structured account and transactional Personal Data described in Annex I. | Managed PostgreSQL database and compute hosting. | European Union. |
| Cloudflare | Prompts and media references in transit within signed dispatch payloads, and public asset URLs served and cached at the edge. | Asynchronous-flow dispatch and content-delivery / edge caching. | Global edge network. |
| Resend | Recipient email address and transactional email content (verification, password-reset and service messages). | Transactional email delivery. | United States. |
| Sentry | Error and exception telemetry, which may include request context, trace identifiers and actor identifiers. | Error monitoring and application performance tracing. | European Union and/or United States. |
ClipVision also relies on operator-hosted infrastructure components — including a managed cache (Redis) and a message queue (RabbitMQ) — which process Customer Personal Data only transiently as part of operating the Services and which are hosted within the same European Union infrastructure as the primary database. These components act as infrastructure sub-processors rather than independent data recipients.