Clipsper legal
Data Processing Addendum
Version 2026-07-18-v1.0-draft-counsel-review · Effective draft dated July 17, 2026
Applicability and draft status
This DPA is applicable because Clipsper processes appointment, contact, CRM, and related customer data for shops and barbers. It is a launch-readiness draft requiring counsel review and a completed signature mechanism before production contracting.
Roles and instructions
The business is controller or business and Clipsper is processor or service provider for customer data processed to provide the contracted service. Clipsper processes that data only on documented instructions, including product configuration, the MSA, this DPA, and lawful support requests, unless law requires otherwise.
Processing details
Processing includes collection, hosting, organization, retrieval, transmission, analysis, support, security, export, and deletion. Data subjects include customers, staff, contractors, and account contacts. Data includes identifiers, contact data, appointments, preferences, CRM notes, reviews, payment-status references, device data, and support/security records. Special-category data is not intended and should not be submitted.
Confidentiality and security
Authorized personnel are bound by confidentiality. Clipsper will maintain access control, tenant-scoped authorization, encryption in transit, provider-managed encryption at rest, logging for sensitive changes, secure secret handling, vulnerability management, backups, and incident-response procedures proportionate to the service. A detailed security exhibit and audit-evidence process must be finalized.
Subprocessors
Current expected subprocessors include Supabase, Stripe, Resend, OpenAI, Apple, Google, and infrastructure used to host Clipsper. Before launch, Clipsper must publish the final list with purpose and processing location, establish a notice and objection process, and confirm written data-protection terms with each processor.
Requests and incidents
Clipsper will reasonably assist with verified data-subject requests, regulator inquiries, security assessments, breach notifications, and required impact assessments. Contractual notification timing, contact method, information content, cost allocation, and responsibility matrix require counsel and security approval.
Transfers
Where required, the parties will use approved transfer mechanisms such as applicable standard contractual clauses and supplementary measures. UK addendum, EU representative, transfer-impact assessment, and regional hosting commitments must be completed if those regions are in launch scope.
Return and deletion
During the term, business administrators can access operational data and customers can export their personal data. After termination or a valid deletion instruction, Clipsper deletes or returns processor data subject to a documented export window, backup cycle, and legal retention exception. Final schedules must be added to the production DPA.
Contact
Privacy and DPA questions may be sent to legal@clipsper.com.

