CoreClips AI, operated by Critso
Last updated: July 17, 2026 (draft)
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or enterprise order form (the "Agreement") entered into between Critso ("Processor," "Critso," "we") and the customer entity identified in the Agreement ("Controller," "Customer," "you"), and applies to the extent Critso processes Personal Data on Customer's behalf in connection with the Service.
1.1"Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Sub-processor," and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.
1.2"Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the Indian Digital Personal Data Protection Act, 2023.
1.3"Customer Personal Data" means Personal Data contained in Customer Content that Critso Processes on Customer's behalf in the course of providing the Service, as further described in Annex 1.
1.4"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), as may be updated from time to time, or the equivalent UK International Data Transfer Addendum, as applicable.
2.1As between the parties, Customer is the Controller (or, where Customer itself Processes Customer Personal Data on behalf of a third-party controller, a Processor) of Customer Personal Data, and Critso is a Processor (or sub-processor, as applicable) acting on Customer's documented instructions.
2.2This DPA applies only to Critso's Processing of Customer Personal Data in its capacity as Processor. It does not apply to Critso's Processing of personal data as an independent controller — for example, account and billing data of Customer's own personnel used to administer the commercial relationship — which is governed by Critso's Privacy Policy.
3.1Critso will Process Customer Personal Data only:
3.2Customer instructs Critso to Process Customer Personal Data to:
3.3If Critso believes an instruction from Customer infringes Applicable Data Protection Law, Critso will promptly inform Customer, and may suspend performance of that instruction until Customer confirms or modifies it.
4.1Critso will ensure that personnel authorized to Process Customer Personal Data are subject to a binding confidentiality obligation (whether contractual or statutory).
5.1Critso will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. These measures include, at minimum, those described in our Security, such as:
5.2Customer is responsible for configuring the account-level security controls made available by the Service (such as role assignments within an organization account) appropriately for its own use case.
6.1Customer provides general authorization for Critso to engage Sub-processors to Process Customer Personal Data, provided that Critso:
6.2Critso will provide notice of any intended addition or replacement of a Sub-processor by updating the Subprocessor List [PLACEHOLDER: confirm the notice mechanism your team can actually commit to — e.g. an email notification or an RSS/changelog subscription, in addition to the list itself, is often expected by enterprise customers]. If Customer reasonably objects to a new Sub-processor on data protection grounds within [PLACEHOLDER: e.g. 30] days of notice, the parties will discuss in good faith; if no resolution is reached, Customer may terminate the affected portion of the Service as its sole remedy.
7.1Where Critso transfers Customer Personal Data originating in the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, the parties agree that such transfer is subject to the Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), which are incorporated into this DPA by reference and deemed executed by the parties upon execution of the Agreement. [PLACEHOLDER: attach the actual SCC module text or a clear incorporation clause with the annexes completed — counsel should confirm whether the EU SCCs, the UK Addendum, or both are needed based on Customer's location and data subjects.]
7.2[PLACEHOLDER: confirm whether Critso needs to appoint an EU and/or UK representative under Article 27 GDPR / UK GDPR. This is typically required if Critso has no establishment in the EU/UK but processes personal data of individuals located there at scale or involving special category data — a decision for counsel based on actual customer base.]
8.1Critso will, taking into account the nature of the Processing, provide reasonable assistance to Customer, by appropriate technical and organizational measures, to help Customer respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law.
8.2If Critso receives a request directly from a Data Subject concerning Customer Personal Data, Critso will not respond to that request directly (except to confirm receipt and redirect the individual to Customer), unless legally required to do so, and will promptly forward the request to Customer.
9.1Critso will notify Customer without undue delay, and in any event within [PLACEHOLDER: e.g. 48–72 hours, confirm your operational commitment] after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, providing the information reasonably available to Critso at the time, including: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects and records affected; (c) the likely consequences; and (d) measures taken or proposed to address the breach.
9.2Critso will provide reasonable cooperation to Customer in investigating, mitigating, and remediating a Personal Data Breach, and in Customer's own notification obligations to Supervisory Authorities or affected Data Subjects, where applicable.
9.3Notification under this Section is not an acknowledgment of fault or liability by Critso.
10.1Subject to Section 5 of the Privacy Policy (retention), on termination of the Agreement or on Customer's written request, Critso will delete or, where technically feasible and requested by Customer, return Customer Personal Data, except to the extent applicable law requires continued retention (for example, financial and billing records, as described in the Privacy Policy Section 5.4).
10.2Backup copies of deleted Customer Personal Data may persist for a limited period consistent with Critso's standard backup retention cycle before being permanently purged, as described in the Privacy Policy Section 5.5.
11.1On reasonable prior written notice (at least [PLACEHOLDER: e.g. 30] days) and no more than once per 12-month period (except following a confirmed Personal Data Breach, or where required by a Supervisory Authority), Critso will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may take the form of: (a) a summary of relevant third-party audit reports or certifications then held by Critso, if any; or (b) responses to a reasonable written security/compliance questionnaire.
11.2[PLACEHOLDER: confirm whether Critso is prepared to offer on-site or remote audit access beyond documentation review, and any conditions (confidentiality, cost allocation, use of a mutually agreed third-party auditor rather than Customer directly) — this is a common negotiation point for larger EU enterprise deals and should be decided with counsel and leadership before this DPA is offered externally.]
12.1Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement (see Terms of Service, Section 14), unless applicable Data Protection Law prohibits limiting such liability.
13.1This DPA remains in effect for as long as Critso Processes Customer Personal Data under the Agreement, and terminates automatically on termination of the Agreement, subject to Section 10 (Deletion and Return of Data).
14.1In the event of a conflict between this DPA and the Agreement (excluding the SCCs, where incorporated), this DPA controls with respect to the parties' data protection obligations. In the event of a conflict between this DPA and the SCCs, the SCCs control.
| Field | Detail |
|---|---|
| Subject matter | Provision of the CoreClips AI video intelligence platform (upload, transcription, summarization, highlight generation, and related processing) |
| Duration | For the term of the Agreement, plus the retention/deletion periods described in the Privacy Policy |
| Nature and purpose of Processing | Storage, transcription (speech-to-text), AI-assisted summarization and highlight generation, hosting, and related technical operations necessary to deliver the Service |
| Categories of Data Subjects | Customer's account users; individuals who appear, speak, or are discussed in Customer Content uploaded to the Service (e.g. meeting participants, interview subjects, patients, students, depending on Customer's use case) |
| Categories of Personal Data | Names, voices, likenesses, and spoken content captured in video/audio; account identity data (name, email); [PLACEHOLDER: confirm with Customer whether special category data (e.g. health information, in medical use cases) may be included in their specific Uploaded Content — this materially changes the required safeguards and should be addressed per-customer, not assumed generically here] |
| Sub-processors | Subprocessor List, incorporated by reference |
[PLACEHOLDER: signature block — entity names, signatory names/titles, dates, for both Critso and Customer. Typically executed as part of the enterprise order form process rather than signed standalone; confirm execution mechanism with counsel.]