Privacy Policy

Privacy Policy
Last Updated: July 30, 2026
CLIPr Co. ("CLIPr," "we,""us," or "our") welcomes you. 

Our Services are subject to the following privacy policy(the "Privacy Policy"), which may be updated by us from time to time without notice to you. By accepting this Privacy Policy, accessing or using the Services, or otherwise manifesting your assent to this Privacy Policy, you agree to be bound by this Privacy Policy and the accompanying Terms of Use, which together make up the Agreement.

If you do not agree to (or cannot comply with) all of the terms of this Privacy Policy or any other terms of the Agreement, you may not access or use the Services.

If you accept or agree to this Agreement on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to the Agreement and, in such event, "you" and "your" will refer and apply to that company or other legal entity. Capitalized terms not defined in this Privacy Policy shall have the meaning set forth in our Terms of Use.

OUR ROLE: DATA CONTROLLER vs. DATA PROCESSOR

CLIPr operates in two distinct capacities depending on the context of data processing:

When CLIPr Acts as a Data Controller

CLIPr is the Data Controller for personal data we collect directly from:

SiteVisitors — individuals who browse our website (clipr.ai)
DirectUsers — individuals who sign up for a CLIPr account on their own behalf
BusinessContacts — prospective and current customer contacts, vendor contacts, and marketing leads

For this data, CLIPr determines the purposes and means of processing and this Privacy Policy governs our use of that information.

When CLIPr Acts as a Data Processor / Service Provider

When CLIPr provides services to Enterprise Customers under a Master Services Agreement (MSA), Master Platform Access Agreement, or similar commercial contract, CLIPr acts as a Data Processor (under GDPR) or Service Provider (under US state privacy laws) with respect to:

Customer Data — video recordings, audio files, transcripts, and other content submitted by or on behalf of the Enterprise Customer
Service Data — recaps, clips, AI-generated summaries, reports, and any other outputs generated from Customer Data
End-UserData — personal data of the Enterprise Customer's employees, clients, or other individuals processed through CLIPr's services 

In this capacity:

• The Enterprise Customer is the Data Controller and determines the purposes and means of processing
• CLIPr processes Customer Data and Service Data solely on the instructions of the Enterprise Customer
• Processing is further governed by a Data Processing Addendum (DPA) or equivalent contractual terms
• CLIPr does not use Customer Data or Service Data for any purpose other than delivering the contracted services, unless expressly authorized in writing

THE INFORMATION WE COLLECT AND HOW WE USE IT

In the course of operating the Services, CLIPr collects or receives the following types of information, which may include personal information.

Contact Information

We collect contact information through our Services; contact information typically includes your name, email address, postal address, username and password, and any information you provide in messages to us. We use such contact information for purposes such as adding you to the invitation list to use the Services, registering you for an account, providing you with information about the Services, responding to your inquiries, sending you email alerts (including marketing emails), or providing you the Services.

Activity Information

The Services allow you to submit Recordings and to receive Recaps (Clips) of such Recordings. We will therefore collect and have access to any content contained in such Recordings. We will only use Recordings to provide the Services.

For Direct Users (non-enterprise): We may use Recaps(Clips), which may contain parts of Recordings, for the purposes of promotingCLIPr's Services, unless you opt out by contacting us at legal@clipr.ai.

For Enterprise Customers (B2B): Recordings, Recaps(Clips), transcripts, and all other Customer Data and Service Data processed on behalf of Enterprise Customers under a Master Services Agreement (MSA) or other commercial contract are treated as strictly confidential Customer Data. Such data:

Will NOT be used for marketing, promotional, or advertising purposes without the Enterprise Customer's explicit prior written consent
• Will be processed solely for the purpose of delivering the contracted services
• Will not be shared with third parties except as necessary to deliver the services or as required by law
• Will be subject to the confidentiality, security, and data handling obligations in the governing MSA and/or DPA

Third-Party Data Integrations

We may collect information about you through third-partyintegrations such as our integration with Google API Services("Third-Party User Data"). We will only use Third-Party User Data to provide the Services to you and to improve the Services.

Google API Services

We comply with the Google API Services User Data Policy and the Limited Use requirements applicable to restricted scope data("Restricted Scope Data"). We will only transfer Restricted Scope Data to others if that transfer is (a) necessary to provide or improve related features, (b) to comply with applicable laws, or (c) in connection with a business transfer. We will not use Restricted Scope Data to serve advertisements.

Server Log Information

Our servers keep log files that record data each time a device accesses those servers, including IP address, user agent string, pages visited, and usage data. We use these for monitoring, troubleshooting, traffic analysis, and optimizing user experience.

Cookies

We may collect information using "cookie" and other similar technologies.

Session Cookies: Expire when you close the Services; used for navigation.
Persistent Cookies: Remain on your device for an extended period; used for storing passwords and personalizing experience.

Third-Party Analytics Providers

We use third-party analytics services to evaluate use of the Services. Any third-party data processing is strictly for helping us provide the service, not for the third party's own use. For Google Analytics:https://www.google.com/analytics. For Hotjar: https://www.hotjar.com.

Aggregate Data

We may analyze information in aggregate form to operate and improve the Services. This aggregate information does not identify you personally. We do not sell or share any user data, even in aggregate form.

Note: Aggregate analytics do not include Customer Data or Service Data processed on behalf of Enterprise Customers. Enterprise Customer data is excluded from all aggregate data pools unless the Enterprise Customer provides explicit written consent. 

ENTERPRISE CUSTOMER DATA — ADDITIONAL PROTECTIONS

This section applies specifically to data processed by CLIPr on behalf of Enterprise Customers under a commercial agreement.

Data Processing Addendum (DPA)

Enterprise data processing is governed by a Data Processing Addendum (DPA) executed between CLIPr and the Enterprise Customer. The DPA addresses:

• Scope and purpose of processing
• Categories of personal data and data subjects
• Data retention and deletion obligations
• Sub-processor management and notification
• International data transfer mechanisms (including EU Standard Contractual Clauses)
• Data subject rights assistance
• Data breach notification procedures
• Audit rights

In the event of any conflict between this Privacy Policy and the terms of an executed DPA or MSA, the DPA or MSA shall prevail with respect to Enterprise Customer Data.

Technical and Organizational Measures (TOMs)

CLIPr maintains appropriate technical and organizational security measures to protect Customer Data, including:

Encryption— Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
Access Controls — Role-based access with principle of least privilege; MFA for admin access
Infrastructure— Hosted on AWS with SOC 2 Type 1 certification; data residency options(US, EU/Ireland)
Monitoring— Continuous security monitoring, intrusion detection, and logging
Incident Response — Documented procedures with defined notification timelines per DPA
Personnel— Background checks; mandatory security awareness training
Business Continuity — Regular backups, disaster recovery, and tested restoration

Sub-Processor Management

CLIPr maintains a list of authorized sub-processors. Enterprise Customers are:

• Provided with the current sub-processor list upon request
• Notified in advance of new sub-processor additions
• Assured that all sub-processors are bound by equivalent data protection obligations

Data Retention and Deletion

For Enterprise Customer Data:

• Data is retained only for the duration necessary to provide the contracted services
• Upon termination, CLIPr will delete or return all Customer Data within 30 days(unless retention required by law)
• Deletion certificates are available upon request

ONWARD TRANSFER TO THIRD PARTIES

Like many businesses, we hire other companies to perform certain business-related services. We may disclose personal information tothird-party companies only to the extent needed to enable them to provide such services (hosting, technical assistance, database management, analytics, email marketing, customer service).

Enterprise Customer Data exclusion: Enterprise Customer Data is never shared for marketing or promotional purposes. This provision applies only to CLIPr-controlled data (e.g., marketing leads, site visitor data).

BUSINESS TRANSFERS

In the event of a merger, dissolution, reorganization, or sale of substantially all of our assets, information we have collected would be transferred to the surviving or acquiring entity, subject to this Privacy Policy. For Enterprise Customer Data, any such transfer is additionally subject to the applicable DPA and MSA, and the Enterprise Customer will be notified accordingly.

DISCLOSURE TO PUBLIC AUTHORITIES

We are required to disclose personal information in response to lawful requests by public authorities, including for national security or law enforcement. Where legally permitted, CLIPr will notify the relevant Enterprise Customer of any legal request for disclosure of their Customer Data prior to disclosure, unless prohibited by law.

OPT-OUT FOR DIRECT MARKETING; DELETION REQUESTS

You may opt out from direct marketing by emailingmktg@clipr.ai or clicking "Unsubscribe" in any marketing email. You may request deletion of your personal information by emailing mktg@clipr.ai.

HOW WE PROTECT YOUR INFORMATION

CLIPr implements reasonable security measures designed to protect your personal information from loss, misuse, and unauthorized access. For Enterprise Customers, additional security commitments are set forth in the applicable DPA and MSA.

CHILDREN

We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact legal@clipr.ai.

IMPORTANT NOTICE TO NON-US RESIDENTS

Our servers are located in the US and elsewhere (includingEU/Ireland for European data residency). For Enterprise Customers in the EEA or UK, international data transfers are governed by the applicable DPA with appropriate transfer mechanisms (e.g., EU Standard Contractual Clauses).

CALIFORNIA PRIVACY RIGHTS

California residents may obtain information about types of personal information shared with third parties for direct marketing by emailinglegal@clipr.ai.

NEVADA PRIVACY RIGHTS

Nevada residents may opt out of the sale of certain personal information by contacting legal@clipr.ai. We do not currently sell personal information.

DO NOT TRACK

CLIPr does not respond to "Do Not Track" settings at this time.

CHANGES TO THIS PRIVACY POLICY

We may change this Privacy Policy from time to time. For Enterprise Customers, material changes will be communicated in accordance with the notification provisions of the applicable DPA or MSA.

HOW TO CONTACT US

For general privacy inquiries: legal@clipr.ai (subject: "Privacy Policy")

For Enterprise Customer data protection inquiries:legal@clipr.ai (subject: "Enterprise Data Protection") 

© 2026 CLIPr Co. All rights reserved.