This Data Processing Addendum (this "DPA") is part of the Cutvey Terms of Service. It is incorporated into the Terms by reference.
You do not need to sign it, and you may. It applies automatically to every customer of the Cutvey subscription service ("the Service") whose use of the Service involves personal data that Cutvey handles on the customer's behalf. If you use the Service, this DPA and the Standard Contractual Clauses it incorporates are in force between you and Cutvey from the date you accepted the Terms of Service, and no signature is required, because Article 28(9) of the GDPR allows a processing contract to be in electronic form. If your organization's process requires an executed copy, complete the Signature Page in Annex IV, sign it, and email it to [email protected]. Cutvey will countersign and return it within five business days. The executed copy has the same terms as this document and takes effect from the date you first accepted the Terms of Service. Cutvey signs this document as published and does not negotiate customer-specific terms.
If this DPA conflicts with the Terms of Service, this DPA wins on the subject of personal data protection. If this DPA conflicts with the Standard Contractual Clauses in Section 11, the Standard Contractual Clauses win.
One list sits outside this DPA and is incorporated by reference, so it can be kept current without a new version of this document: the subprocessor list at https://cutvey.com/legal/subprocessors.
The security measures are in Annex II of this DPA. Annex II is the contractual statement of them. If Cutvey ever publishes a separate security page describing the same measures, that page is a description and not a replacement, and where the two differ the more protective description applies. A change that materially reduces the level of security described is a material change under Section 15 and is notified accordingly.
Words defined in the Terms of Service keep their meaning here.
2.1 Cutvey as processor. For Customer Personal Data, the customer is the Controller and Cutvey is the Processor. This is the data the customer's studio puts into its workspace: its clients, leads, crew, talent, contacts, project content, files, messages, and documents, and the personal data of the people the customer invites into a client portal or asks to sign a document.
Where the customer is itself a processor acting on behalf of another controller, the customer is a Processor and Cutvey is a Subprocessor, and this DPA applies with that reading. The customer confirms it has that controller's authorization to engage Cutvey, and remains responsible as between the parties for the instructions it gives.
2.2 Cutvey as controller. Cutvey is an independent Controller for a defined set of data it needs to run its own business: account holder and billing contact details, the account owner's authentication and security records, subscription and payment records, support correspondence, website visitor data, and Cutvey's own platform-level security and infrastructure logs, meaning logs generated outside any workspace for the purpose of operating and defending the platform as a whole. The in-workspace audit log of user actions, which the customer can see and export, is Customer Personal Data and Cutvey processes it as Processor. Cutvey's Privacy Policy, not this DPA, governs the processing for which Cutvey is Controller.
2.3 Customer obligations. The customer confirms that:
it has a lawful basis for the Personal Data it puts into the Service, and has given the notices and obtained the consents that Data Protection Law requires from the people the data is about;
its instructions to Cutvey comply with Data Protection Law;
the Service is not designed for, and the customer will not use it as a system of record for, special category data under GDPR Article 9, criminal offense data under Article 10, payment card or financial account numbers, health records, or biometric identifiers used for unique identification.
Two things this does not prohibit. First, the customer's own tax and engagement paperwork for the people it hires, including a completed W-9 or an equivalent form carrying a taxpayer identification number, is ordinary business administration that the Service is built to hold, and the customer may store it. Second, a government identifier that appears incidentally inside footage, a scan, or an attachment the customer uploads is not a breach of this bullet. In both cases the customer remains responsible for restricting who in its workspace can see the record, and for any state law that imposes specific duties on the holder of a social security or equivalent number.
Health and education data. Cutvey is not a HIPAA business associate, does not enter business associate agreements, and is not a school official under FERPA. The Service is not designed to hold protected health information or education records, and the customer will not use it as a system of record for either. Where a shoot for a healthcare or education client captures an identifiable patient or student, the consent, the release, and the lawful basis are the customer's responsibility, and the resulting footage is ordinary Customer Personal Data under this DPA.
The parties acknowledge that ordinary production records held in the Service may contain data that Data Protection Law treats as special category data, in particular trade union membership in crew records and, where the customer records them, dietary, accessibility, or medical requirements on call sheets, and that release records may relate to minors. The Service is designed to hold that data as part of ordinary production administration, the measures in Annex II apply to all Customer Personal Data without distinction, and the customer remains responsible for its own lawful basis, for the condition in Article 9(2) or its local equivalent, and for not using the Service where the risk requires controls beyond those in Annex II;
where it uses the Service to send email with open and click tracking, to collect e-signatures, or to record a call sheet or release, it is responsible for the lawfulness of doing so.
2.4 The native apps. Cutvey's native apps can sign in to a Cutvey workspace and sync content with it. Content an app pushes into the workspace, and content the workspace sends to an app, is Customer Personal Data and is covered by this DPA in the same way as anything else in the workspace. Content that stays on a user's device, or in that user's own iCloud (CloudKit private database), is not processed by Cutvey at all, and Cutvey cannot access it.
Product usage analytics and crash reports that the apps send to Cutvey, and the sign-in and device records described in the Cutvey App License Agreement, are processed by Cutvey as an independent Controller under its Privacy Policy, not under this DPA. They are technical and, by default, anonymous, and they are designed and filtered so that they do not contain workspace content. Where they can be linked to an individual, Cutvey is responsible for informing that individual under its Privacy Policy. The Cutvey App License Agreement governs the apps themselves.
Biometrics. No Cutvey product sends a biometric identifier, or face or hand geometry, to Cutvey, and no Cutvey product stores a biometric template. Where an app detects a face, a hand, or a body on the device, that detection stays on the device, is used for that moment only, and is not retained.
A person who only bought an app has no account. Where a person unlocks an app by a one-time purchase in a platform store and never signs in, Cutvey receives nothing about that purchase and creates no account, so there is no personal data of theirs for Cutvey to hold, disclose, or delete.
2.5 Cutvey is not a party to the customer's own contracts. Cutvey is not a party to any agreement between a customer and that customer's clients, crew, or talent, and takes no responsibility for them.
3.1 Documented instructions. Cutvey processes Customer Personal Data only on the customer's documented instructions, which are: this DPA, the Terms of Service, the customer's configuration and use of the Service through its interfaces and APIs, and any other written instruction the parties agree. Providing, securing, maintaining, and supporting the Service are within those instructions, as is generating the usage and account records Cutvey needs to bill the customer, which Cutvey then processes as Controller under Section 2.2.
Cutvey also produces aggregated statistics about how the Service is used, in order to operate and improve it. Those statistics are irreversibly aggregated, identify no person and no customer, and no output can be attributed to a customer's workspace. Cutvey does not use Customer Personal Data for any other purpose of its own.
3.2 Where the law requires otherwise. Cutvey may process Customer Personal Data where EU, member state, UK, or other applicable law requires it to. In that case Cutvey will inform the customer of the requirement before processing, unless that law forbids telling the customer on important grounds of public interest.
3.3 Unlawful instructions. If Cutvey considers that an instruction infringes Data Protection Law, it will inform the customer immediately, and may suspend performance of that instruction until the parties resolve it.
3.4 No sale, no advertising, no training. Cutvey does not sell Customer Personal Data, does not share it for cross-context behavioral advertising, does not disclose it to data brokers or advertising networks, and does not use it to build, train, or fine-tune artificial intelligence models, except where the customer has switched on a feature that expressly does so, in which case Cutvey processes only within that instruction and the customer may withdraw it at any time. Cutvey does not use Customer Personal Data for any purpose outside providing the Service, except as Sections 3.1, 3.2, and 10.5 permit.
3.5 AI features. Where a customer's user invokes an AI feature, the content that user directs the feature at, which may include text the user types and workspace records the user selects, together with the output generated from it, is processed by the AI Subprocessor identified in the published subprocessor list, solely to produce the requested output. Under that provider's commercial terms, inputs and outputs are not used to train models and are retained only as long as needed to deliver the response and to meet the provider's own trust and safety obligations. No AI feature runs unless a user invokes it. Output can be wrong, and the customer is responsible for checking it before relying on it.
3.6 Confidentiality. Cutvey ensures that every person authorized to process Customer Personal Data is bound by a duty of confidentiality, contractual or statutory, that survives the end of their engagement, and that access is limited to those who need it to do their job.
3.7 Diagnostics. Cutvey and its native apps generate crash and error reports so that faults can be diagnosed and fixed. This covers both the Service and the apps, and the reports are processed by Cutvey and by the crash-reporting provider named on the published subprocessor list, which is listed for both.
Those reports carry technical diagnostics: the software and operating system version, the device or server context, the operation that failed, memory and timing figures, and a stack trace. They are designed and filtered so that they do not contain Customer Personal Data or customer content, and Cutvey applies redaction on the paths it controls, including removing account names, volume names, file and folder names, and access tokens before a report is sent. Cutvey does not promise that no personal data ever appears in the text of an error, and treats any report that does contain Customer Personal Data as Customer Personal Data subject to this DPA, including for deletion and for Section 7. Where a user can turn crash reporting off, the setting is in the product's privacy settings.
3.8 Details of processing. Annex I sets out the subject matter, duration, nature and purpose of processing, the categories of Data Subject, and the types of Personal Data.
4.1 Measures. Cutvey implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing and the risks involved. Those measures are described in Annex II.
4.2 Changes. Cutvey may update its security measures as technology and threats change, provided it does not materially reduce the overall level of security.
4.3 No certification is claimed. Cutvey holds no third-party security certification and makes no claim to one. Cutvey is not certified under SOC 2, ISO 27001, or any equivalent scheme, and is not certified under the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Data Privacy Framework. Annex II describes what Cutvey actually does. Nothing in this DPA should be read as claiming an audit, attestation, certification, or seal that Cutvey does not hold.
5.1 General authorization. The customer gives Cutvey general written authorization to engage Subprocessors, subject to this section.
5.2 Current list. Cutvey's Subprocessors are listed at https://cutvey.com/legal/subprocessors. That list is incorporated into this DPA by reference and forms part of it. The list at the effective date is reproduced in Annex III. If the two differ, the published list is current.
5.3 Terms with Subprocessors. Cutvey enters a written contract with each Subprocessor before it processes any Customer Personal Data. That contract imposes data protection obligations no less protective than those in this DPA, to the extent they apply to the service that Subprocessor provides. It includes:
Cutvey will provide a copy of the data protection terms of any such contract to the customer on request, with commercial terms redacted.
An affiliate of Cutvey is a Subprocessor. Where a company in Cutvey's corporate group processes Customer Personal Data, it is engaged, listed, and notified under this Section 5 in the same way as any other Subprocessor.
5.4 Liability for Subprocessors. Cutvey remains fully liable to the customer for a Subprocessor's performance of its data protection obligations, subject to Section 13.
5.5 Notice of changes and the right to object. Cutvey will give every customer at least 30 days' written notice by email before a new Subprocessor begins processing Customer Personal Data, or before an existing Subprocessor takes on a materially different role. Notice goes to the workspace owner and the billing contact on record, who are enrolled automatically and cannot be unenrolled while the subscription is live. Cutvey will also update the published subprocessor list and its "last updated" date on or before the date of the notice. A customer may add further recipients by emailing [email protected] with "Subprocessor notifications" in the subject line.
The customer may object on reasonable data protection grounds within 30 days of that notice, by emailing [email protected] and explaining the grounds. The parties will discuss it in good faith, and Cutvey will try to offer a reasonable alternative or a change of configuration. If Cutvey cannot, the customer may terminate its subscription by written notice given within that 30-day window. Termination takes effect at the end of the customer's current paid period. No refund or proration is given, consistent with the Terms of Service. Until that date, where technically possible, Cutvey will keep that customer's Customer Personal Data off the new Subprocessor. Where that is not technically possible, the customer may instead end the subscription with immediate effect by saying so in its notice, again without refund, and Cutvey will not transfer that customer's Customer Personal Data to the new Subprocessor.
Termination under this section is the customer's remedy for the objection itself. Nothing in this section limits any right the customer has under Clause 9 or Clause 16 of the Standard Contractual Clauses, or any other right or remedy it has for a breach of this DPA by Cutvey.
5.6 Urgent replacement. Where a Subprocessor fails, is compromised, or ceases to provide its service without warning, and Cutvey must appoint a replacement to keep the Service running or to protect its security, Cutvey will give the customer notice by email at the same time as it makes the appointment, together with the reason and a description of the safeguards applied. The objection right in Section 5.5 applies from the date of that notice, and where the customer objects Cutvey will, so far as technically possible, suspend the transfer of that customer's Customer Personal Data to the replacement while the objection is discussed. Where the transfer is subject to the Standard Contractual Clauses, this Section 5.6 does not reduce the notice Clause 9(a) requires, and Cutvey will not rely on this Section in a way that contradicts Clause 9.
5.7 Recipients that are not Subprocessors. Some recipients of data act on their own account for part of what they do, and are independent Controllers for that part rather than Cutvey's Subprocessors. The published subprocessor list identifies them and explains which part is which. Payment processors acting under their own regulatory and financial-crime obligations, and platform operators acting under their own terms with the end user, are the present examples. Cutvey is not responsible for processing a recipient carries out as an independent Controller, and this DPA does not apply to it.
6.1 Data subject requests. Taking into account the nature of the processing, Cutvey will help the customer by appropriate technical and organizational measures, so far as possible, to respond to requests from Data Subjects exercising rights of access, rectification, erasure, restriction, portability, objection, or the right not to be subject to automated decision making.
The Service gives the customer self-service tools that do most of this directly: access to and editing of every record in the workspace, machine-readable export of workspace data, per-client erasure, and workspace deletion. The customer will use those tools first.
6.2 Requests that reach Cutvey. If a Data Subject contacts Cutvey directly about Customer Personal Data, Cutvey will not respond to the substance except to say that the request should go to the customer, and will forward the request to the customer without undue delay, unless the customer has instructed otherwise or the law requires a different response.
6.3 Further help. Where the customer needs help beyond the self-service tools, Cutvey will provide reasonable assistance. Cutvey may charge a reasonable fee for assistance that is not attributable to a failure by Cutvey and that takes significant effort, after telling the customer the fee in advance. Cutvey will not charge for assistance that takes fewer than four hours in any twelve-month period, and will not charge at all where the request arises from a Personal Data Breach or from Cutvey's failure to perform.
6.4 Impact assessments and prior consultation. Cutvey will provide the customer with reasonable information and assistance for data protection impact assessments under GDPR Article 35 and prior consultation with a Supervisory Authority under Article 36, so far as they relate to Cutvey's processing and the customer cannot get the information itself. Annex II, Section 9.5, and this DPA are the starting point for most such assessments.
6.5 Government and law enforcement requests. If a public authority asks Cutvey for Customer Personal Data, Cutvey will do all of the following, unless legally prohibited.
Cutvey will keep a record of such requests and make it available to the customer on request, so far as the law allows. Where a non-disclosure order prevents notice, Cutvey notifies the customer as soon as the bar lifts, and asks the authority to shorten or end the order where there are grounds.
6.6 Requests from private parties, and the legal process policy. Cutvey requires valid legal process before it discloses anything, served at the notice address at the head of this DPA.
The fuller statement of this policy is in the Cutvey Terms of Service and the Cutvey Privacy Policy, and this Section is the version that binds Cutvey as processor. Where they differ as to Customer Personal Data, this Section applies.
7.1 Notice. Cutvey will notify the customer of a Personal Data Breach affecting that customer's Customer Personal Data without undue delay after becoming aware of it, and in any event within 48 hours of becoming aware. Cutvey becomes aware when it has a reasonable degree of certainty that a security incident has occurred that led to Personal Data being compromised. Cutvey will not delay the notice in order to complete its investigation; where information is still being established, Cutvey will notify with what it has and supplement it under Section 7.2.
This Section applies whether the breach occurred in systems Cutvey operates or in those of a Subprocessor. Cutvey will notify the customer on the same timetable, running from Cutvey's own awareness, and will pass on what the Subprocessor tells it as it receives it.
7.2 Content of notice. The notice will describe, so far as Cutvey knows at the time: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for more information. Where Cutvey cannot provide everything at once, it will provide what it has and the rest as it becomes available.
7.3 Cooperation. Cutvey will cooperate reasonably with the customer, and take the reasonable steps the customer directs, to investigate, mitigate, and remedy the breach.
7.3A The customer's cooperation. The customer will cooperate reasonably with Cutvey's investigation of an incident affecting it, will preserve the logs, devices, and records on its own side that are relevant to it, and will name a single contact for the incident. The customer will not make a public statement attributing the incident to Cutvey before the parties have established the facts, unless the law requires the statement or the customer must make it to meet its own notification duty. Nothing in this Section delays or limits any notice the customer must give under Data Protection Law.
7.4 Who notifies whom. The customer, as Controller, is responsible for notifying Supervisory Authorities and Data Subjects where the law requires it. Cutvey will not notify the customer's Data Subjects or a Supervisory Authority on the customer's behalf unless the customer asks in writing or the law requires Cutvey to.
7.5 Not an admission. Cutvey's notice of a breach, and the steps it takes, are not an acknowledgment of fault or liability.
7.6 Cutvey's own obligations. Cutvey will comply with the breach notification duties that apply to it directly, including under Florida Statutes section 501.171 and the breach notification laws of any other jurisdiction whose law applies to the incident.
8.1 Information first. Cutvey will make available to the customer the information needed to show compliance with GDPR Article 28 and this DPA. The first route is documentary: this DPA, Annex II, the published subprocessor list, Cutvey's Privacy Policy, and Annex II of this DPA.
8.2 Questionnaire. Once in any twelve-month period, and in addition after a confirmed Personal Data Breach affecting that customer, the customer may send a reasonable written security questionnaire. Cutvey will answer within 30 days. Cutvey may answer with an industry-standard questionnaire it has already completed, such as a CAIQ or SIG Lite, where that covers the questions asked.
8.3 Third-party reports. If Cutvey obtains a third-party audit report or certification in the future, it will make the current report available to the customer under confidentiality, and that report will satisfy the customer's audit right for the period it covers. Cutvey holds no such report today.
8.4 On-site audit. Where Data Protection Law gives the customer or a Supervisory Authority a right to an on-site inspection that Sections 8.1 to 8.3 cannot satisfy, Cutvey will allow one. It is subject to the following.
Each party bears its own costs. The customer bears the fees of any third-party auditor it appoints, except where the audit uncovers material non-compliance by Cutvey, in which case Cutvey reimburses the customer's reasonable costs. An inspection required by a Supervisory Authority is not subject to the frequency or notice limits in this section. Nothing in this Section limits Clause 8.9 of the Standard Contractual Clauses, which prevails for the transfers it governs.
8.5 Supervisory Authorities. Cutvey will cooperate with a Supervisory Authority exercising its powers over the customer's processing.
8.6 Records of processing. Cutvey maintains a record of the categories of processing it carries out on behalf of its customers, as GDPR Article 30(2) requires, and will make it available to a Supervisory Authority on request, and to the customer so far as it concerns the customer's processing, on written request.
8.7 Customer security testing. The customer may test the security of its own workspace with Cutvey's written agreement, which Cutvey will not unreasonably withhold, once in any twelve-month period. Ask at [email protected] at least 10 business days beforehand, with the scope, the dates, the source addresses, and the name of the tester. Testing must stay inside the customer's own workspace, must not target another customer's data or shared infrastructure, must not include denial of service or load testing, and must stop if Cutvey asks it to stop. The customer gives Cutvey the full findings, each party treats the other's information as confidential, the customer bears its own costs, and Cutvey tells the customer what it is doing about anything found. Once Cutvey holds a third-party penetration test summary it may offer that instead, and where that summary covers the question being asked, it satisfies this Section.
9.1 Where data is processed. Cutvey processes Customer Personal Data in the United States, on infrastructure operated by the hosting provider named on the published subprocessor list. Annex III records the provider and the region as at the effective date. Subprocessors process in the countries shown in the subprocessor list and in Annex III. By using the Service, the customer instructs Cutvey to transfer Customer Personal Data to the United States and to those countries. A change of hosting provider or region is a subprocessor change and follows Section 5.5.
9.2 Transfer mechanism. Where Cutvey's processing of Customer Personal Data is a restricted transfer out of the EEA, the UK, or Switzerland, the transfer is made under the Standard Contractual Clauses as set out in Section 11, together with the UK Addendum and the Swiss adaptations in Section 12, and Cutvey applies the supplementary measures in Annex II and the assessment in Section 9.5.
9.3 No Data Privacy Framework certification. Cutvey is not certified under the EU-US Data Privacy Framework, its UK Extension, or the Swiss-US Data Privacy Framework, and does not rely on them.
9.4 Alternative mechanisms. If a competent authority or court invalidates, suspends, or replaces a transfer mechanism relied on in this Section, or if a new mechanism becomes available that the parties can lawfully use, Cutvey will notify the customer and the parties will work in good faith to adopt a lawful replacement without undue delay. Cutvey will publish an updated version of this DPA incorporating the replacement mechanism in its default, unamended form, and that version applies from the date stated in the notice unless the customer objects in writing within 30 days, in which case the parties will agree an alternative or the customer may terminate. Cutvey will not amend, and does not have authority to amend, any transfer mechanism on the customer's behalf. Where a mechanism cannot be replaced, Cutvey will suspend the affected transfer or offer the customer termination on the basis set out in Section 5.5.
9.5 Transfer impact assessment. The parties have assessed the transfer under Clause 14 of the Standard Contractual Clauses and record the following.
(a) What is transferred. Ordinary business contact, project, scheduling, commercial and media data of the categories in Annex I. No special category data is requested by the Service, subject to what Section 2.3 records about ordinary production records. The data is not of a kind that United States intelligence authorities have shown any interest in collecting.
(b) Who receives it. Cutvey LLC, a small private Florida limited liability company with no government contracts, hosting a business software product for video production companies.
(c) The relevant United States law. The provisions capable of applying are section 702 of the Foreign Intelligence Surveillance Act (50 U.S.C. 1881a), Executive Order 12333, and the Clarifying Lawful Overseas Use of Data Act. Cutvey does not assert that it falls outside the definition of an "electronic communication service provider" in 50 U.S.C. 1881(b)(4), and it therefore assesses section 702 as potentially applicable rather than inapplicable. Executive Order 14086 and the redress mechanism established under it, together with the Data Protection Review Court, apply to any such collection, whether or not Cutvey participates in the Data Privacy Framework.
(d) Practical experience. As at the effective date of this DPA, Cutvey had received no order or directive under section 702, no national security letter, no request under Executive Order 12333, and no other request from a public authority for Customer Personal Data. Cutvey keeps a record of any such request under Section 6.5 and makes it available to the customer so far as the law allows. Cutvey gives no commitment to restate or update this paragraph, because a legal prohibition on disclosure could prevent it from doing so.
(e) Supplementary measures. Those in Annex II, in particular encryption in transit, encryption at rest of files and backups by the storage provider, tenant isolation, minimization, the government request policy in Sections 6.5 and 6.6, and the commitment in Section 9.6. Cutvey does not encrypt backups client-side today, so the keys for backup storage are held by the storage provider and this measure does not defeat legal process served on that provider. Annex II states the position exactly.
(f) Conclusion. The parties consider that, taking (a) to (e) together, the transfer does not prevent Cutvey from complying with the Standard Contractual Clauses. Cutvey will re-perform this assessment at least annually, and whenever it becomes aware of a change in United States law or practice, or of any request from a public authority, that affects it, and will notify the customer under Clause 14(e) and Clause 15 if it can no longer comply.
9.6 No back doors, and challenge commitment. Cutvey warrants that it has not been required to modify the Service, or to build any facility or capability, to give a public authority access to Customer Personal Data, and that it has installed no back door and holds no cryptographic key or process for the purpose of giving a public authority such access. Cutvey will challenge any request it considers unlawful or overbroad, including by seeking interim measures, and will exhaust available appeals where there is a reasonable prospect of success.
9.7 Region selection. Where Cutvey offers a customer the choice of a processing region, the region selected in that customer's workspace settings is the primary place of processing for that customer's Customer Personal Data, and Annex I is read accordingly. Sections 9.2 to 9.6 and Section 11 apply to any transfer out of that region, including transfers to Subprocessors. Selecting a region does not change where a Subprocessor processes unless the subprocessor list says so for that region.
10.1 During the subscription. The customer can export its workspace data in machine-readable form at any time through the Service, and can delete records, files, and individual people's data itself.
10.2 After termination. The customer chooses. At the end of the subscription or trial, the customer may instruct Cutvey in writing to (a) return Customer Personal Data in a machine-readable export and then delete it, or (b) delete it immediately, or (c) retain it for the 60-day grace period described below and then delete it. The customer may give that instruction at any time before the end of the subscription and up to the end of the grace period.
Cutvey deletes or returns, and keeps nothing else. Whichever option applies, Cutvey deletes all copies of Customer Personal Data at the end of it, as Clause 8.5 and Clause 16(d) of the Standard Contractual Clauses require, subject only to Sections 10.4 and 10.5. Cutvey does not retain a copy for its own purposes, and does not keep a workspace after the customer has left.
If the customer gives no instruction, option (c) applies by default: Cutvey keeps Customer Personal Data for 60 days after the subscription or trial ends, so the customer can export it or reactivate, and then deletes it. Export remains available to the customer through the Service throughout the grace period at no charge. Where the customer chooses (a), Cutvey will provide the data in a commonly used machine-readable format within 30 days, charging only its reasonable costs where the request goes beyond the standard export. Sections 10.4 and 10.5 apply to every option.
10.3 Self-service deletion. The customer can delete its whole workspace at any time from the Service. Deletion is confirmed by email and takes effect after a 7-day cooling-off period, during which it can be canceled.
10.4 Backups. Deleted data persists in backups until those backups age out on a rolling schedule of up to 30 days, after which it is gone. Those backups are encrypted at rest by the storage provider, using keys the provider manages. They are not restored except to recover the Service, and they remain subject to this DPA until deleted.
10.5 Retention required by law, and holds. Cutvey may keep Customer Personal Data where the law requires it, including financial and tax records, and data subject to a legal hold that Cutvey is required to observe or that the customer has asked for in writing under the Cutvey Terms of Service. It will keep only what the law requires, only for as long as required, and this DPA continues to apply to it.
Electronic signature records are not an exception. A signed document and its signature audit record live inside the customer's workspace, and they are deleted with the workspace, like everything else in it. Cutvey keeps no separate archive of them after a customer leaves. Signers are told at the time of signing to download or email themselves a copy of what they signed and its signing record, and Cutvey emails a copy to every signer on completion. The customer should keep its own copies of signed documents and not rely on Cutvey as its archive.
10.6 Confirmation of deletion. Cutvey will confirm in writing that deletion has taken place, including the date it completed and the date on which the last backup containing the data aged out, on the customer's written request made at any time within twelve months after the end of the subscription. Cutvey will also send that confirmation without a request where the customer instructed immediate deletion under Section 10.2(b).
11.1 Incorporation. Where the GDPR applies to a transfer of Customer Personal Data to Cutvey, whether because the data exporter is established in the EEA or because the exporter is subject to the GDPR under Article 3(2), the Standard Contractual Clauses are incorporated into this DPA by reference and form part of it. The full text is published by the European Commission at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. Cutvey will provide a copy on request.
11.2 The choices, pre-filled. The parties agree that:
| Item | Choice |
|---|---|
| Modules used | Module Two (controller to processor) where the customer is a Controller, and Module Three (processor to processor) where the customer is itself a Processor. The module that applies follows the customer's actual role for the data transferred, as Section 2.1 explains. Every selection below applies to whichever module applies |
| Data exporter | the customer |
| Data importer | Cutvey LLC |
| Clause 7, docking clause | included. An entity that is not a party may accede as an additional data exporter by completing the Signature Page in Annex IV, marking it "Accession under Clause 7", and delivering it to [email protected]. Accession takes effect on Cutvey's written acknowledgment |
| Clause 9, subprocessors | Option 2, general written authorization, with the notice period in Clause 9(a) set to 30 days, operated as described in Section 5 of this DPA. The same selection applies for Module Three |
| Clause 11(a), redress | the optional independent dispute resolution body paragraph is not included |
| Clause 13, supervisory authority | as identified in Annex I.C |
| Clause 17, governing law | Option 1 is used. The Clauses are governed by the law of Ireland, being an EU member state that allows for third-party beneficiary rights |
| Clause 18(b), forum | the courts of Ireland, without prejudice to a Data Subject's right under Clause 18(c) to bring proceedings in the member state of their habitual residence |
| Annex I.A, parties | as set out in Annex I of this DPA, in the customer's account record, and on any executed Annex IV Signature Page |
| Annex I.B, description of transfer | as set out in Annex I of this DPA |
| Annex I.C, competent authority | as identified in Annex I.C of this DPA |
| Annex II, technical and organizational measures | as set out in Annex II of this DPA |
| Annex III, list of subprocessors | as set out in Annex III of this DPA and, as updated from time to time, at the published subprocessor list |
| Frequency of transfer | continuous, for as long as the customer uses the Service |
11.3 Precedence. If the SCCs conflict with any other part of this DPA or the Terms of Service, the SCCs prevail as to the transfers they govern.
11.4 Signature. Acceptance of the Terms of Service, which incorporate this DPA, constitutes execution of the SCCs and their Annexes by both parties, and no separate signature is required. A customer whose process requires a signed copy uses Annex IV, and Cutvey will countersign it without changing any term.
11.5 Affiliates. Where the customer's affiliates use the Service under the customer's subscription, the customer enters this DPA on their behalf as well as its own, and the customer remains responsible for their compliance and is the single point of contact for every right and obligation under this DPA. An affiliate that requires its own contractual relationship may accede under Clause 7 as set out above.
12.1 United Kingdom. For transfers subject to the UK GDPR, the SCCs as incorporated in Section 11 apply as amended and supplemented by the UK Addendum, including Part 2 of the UK Addendum (the Mandatory Clauses), which is incorporated into this DPA in full and unamended. For the purposes of Part 1:
| Table | Entry |
|---|---|
| Table 1, parties and start date | the customer as Exporter and Cutvey LLC as Importer, with the details in Annex I and the customer's account record. Start date: the date the customer first accepted the Cutvey Terms of Service, or the date shown on an executed Annex IV Signature Page. Key contact for the Importer: [email protected] |
| Table 2, selected SCCs | the SCCs incorporated by Section 11, with the modules and options selected in Section 11.2 |
| Table 3, appendix information | Annex I, Annex II, and Annex III of this DPA |
| Table 4, ending the Addendum when the Approved Addendum changes | Exporter |
References in the SCCs to the GDPR are read as references to the UK GDPR, references to EU member state law are read as references to UK law, the governing law is the law of England and Wales, the courts are the courts of England and Wales, and the supervisory authority is the Information Commissioner's Office.
12.2 Switzerland. For transfers subject to the Swiss FADP, the SCCs as incorporated in Section 11 apply with these adaptations, consistent with the recognition given by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP and its ordinance; the competent supervisory authority under Clause 13 and Annex I.C is the Federal Data Protection and Information Commissioner; and the term "member state" must not be read to prevent Data Subjects in Switzerland from bringing proceedings in their place of habitual residence under Clause 18(c). The revised FADP, in force since 1 September 2023, protects the personal data of natural persons only.
12.3 Brazil. For transfers subject to the LGPD, the parties adopt the standard contractual clauses approved by the ANPD in Resolution CD/ANPD No. 19 of 23 August 2024, in their approved form, which are incorporated into this DPA by reference for those transfers. Cutvey is the operator and the customer is the controller. Where those clauses conflict with this DPA, they prevail for the transfers they govern. Cutvey will provide a copy on request.
13.1 Each party's liability under or in connection with this DPA, including under the Standard Contractual Clauses as between the parties, is subject to the exclusions and limitations in the Cutvey Terms of Service, except as set out in Section 13.2.
13.2 For claims arising from Cutvey's breach of this DPA or of the Standard Contractual Clauses, including a Personal Data Breach caused by Cutvey's failure to implement the measures in Annex II, Cutvey's aggregate liability will not exceed the greater of (a) three times the fees paid by the customer in the twelve months before the event giving rise to the claim, or (b) US$5,000. That limit is the same limit as the security cap in the Terms of Service, not an additional one: a single amount shared between this DPA and the Terms, so that the two can never be added together for the same incident. The exclusion of liability for lost or corrupted data in the Terms of Service does not apply to a Personal Data Breach caused by Cutvey.
13.3 Nothing in this DPA limits a Data Subject's rights under the Standard Contractual Clauses, a party's liability to a Data Subject, or a party's liability to a Supervisory Authority, and nothing limits liability that the law does not allow to be limited.
13.4 Liability between the parties is apportioned so that each bears the share of any damage, fine, or compensation that corresponds to its responsibility for the event, consistent with Clauses 12(d) and 12(e) of the Standard Contractual Clauses.
13.5 Carve-outs. The limits in this Section do not apply to liability for Cutvey's fraud or willful misconduct, or for gross negligence to the extent applicable law does not allow liability for it to be limited. Where the law does allow it to be limited, the limits apply to gross negligence to the maximum extent permitted.
13.6 Insurance. Cutvey makes no representation in this DPA about insurance it carries. It will answer honestly if asked.
14.1 Roles. Where the CCPA applies, the customer is a Business and Cutvey is a Service Provider processing Personal Information on the customer's behalf under a written contract, which is this DPA.
14.2 Cutvey's commitments. Cutvey:
Cutvey certifies that it understands the restrictions in this Section 14 and will comply with them.
14.3 No monetary or other valuable consideration. The parties acknowledge that no Personal Information is disclosed by the customer to Cutvey as consideration for the Service or for anything else of value.
14.4 Deidentified data. If either party gets deidentified data, it will not try to reidentify it, will keep it deidentified, and will contractually oblige anyone it gives it to do the same.
14.5 Other US state laws. Where the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, or another comparable US state privacy law applies, the customer is the controller and Cutvey is the processor, and this DPA sets out the processing instructions, duty of confidentiality, security obligations, subprocessor terms, assistance, deletion and return, and audit rights those laws require of a processor contract. Cutvey processes only on the customer's instructions and helps the customer meet its own obligations under those laws.
14.6 Other jurisdictions. Where Quebec's Law 25, PIPEDA, the Australian Privacy Act, Japan's APPI, or Korea's PIPA applies to a customer's use of the Service, Cutvey acts on the customer's behalf and behind the customer's own obligations. It processes only on the customer's instructions, keeps the information confidential, applies the measures in Annex II, uses Subprocessors only under Section 5, assists with access, correction, and deletion requests under Section 6, notifies confidentiality incidents under Section 7, and returns or deletes the information under Section 10. For Quebec, this Section, Annex II, and Section 9.5 are the information the customer needs for its privacy impact assessment before communicating personal information outside Quebec.
A. The parties
The data exporter's name, registered address, contact person, and the date on which it accepted this DPA are recorded in Cutvey's systems at the time of acceptance, and Cutvey will issue that record to the customer on request as a completed Annex I.A. Where the parties execute the Signature Page in Annex IV, the details on that page are the completed Annex I.A, and the Clauses take effect from the date the customer first accepted the Terms of Service.
B. Description of the transfer
| Item | Detail |
|---|---|
| Categories of Data Subject | the customer's own personnel and workspace users; the customer's clients and client contacts; leads and prospects; crew and freelancers; on-screen talent and people who sign releases; recipients of the customer's emails, proposals, invoices, call sheets, galleries, and review links; people appearing in media the customer uploads |
| Categories of Personal Data | name, business and personal contact details, job title and role, company, mailing and billing addresses; project, booking, and scheduling data; call sheet details including call times and locations; message and email content, including open and click events for emails the customer sends through the Service; proposal, contract, invoice, and payment metadata; electronic signature records including signer name, email, signature image, timestamp, and IP address; files, images, video, and documents the customer uploads, and any personal data inside them; comments and timecoded review notes; account and login records for the customer's own users; usage and in-workspace audit log entries |
| Sensitive data | Trade union membership in crew and contact records; where the customer records them, dietary, accessibility, or medical requirements on call sheets; personal data of minors where the customer records a release for one. Restrictions applied: the measures in Annex II apply to all Customer Personal Data without distinction, and access is role-based and workspace-scoped. No other special category data is requested or required, and the customer agrees not to use the Service as a system of record for the categories listed in Section 2.3 |
| Frequency of transfer | continuous, for as long as the customer uses the Service |
| Nature of processing | collection, recording, organization, structuring, storage, retrieval, use, transmission, display, backup, and erasure, by automated means, in order to operate the Service |
| Purpose of processing | providing, securing, maintaining, and supporting the Cutvey Service, and the features the customer chooses to use |
| Retention | for as long as the customer's subscription lasts, then as the customer elects under Section 10.2, and otherwise 60 days followed by deletion, subject to backup aging of up to 30 days and to retention required by law. Signed documents and their signature audit records are deleted with the workspace, as Section 10.5 says |
| Subprocessor processing | each Subprocessor in Annex III processes for the purpose and duration stated in that table, and for no longer than needed for that purpose |
C. Competent supervisory authority
The competent supervisory authority is the supervisory authority of the EU member state in which the data exporter is established, as identified in the customer's account record and confirmed on any executed Annex IV Signature Page. Where the data exporter is not established in the European Union but has appointed a representative under GDPR Article 27, it is the supervisory authority of the member state in which that representative is established. Where the data exporter is not established in the European Union and relies on GDPR Article 3(2), it is the supervisory authority of the member state in which the Data Subjects whose Personal Data is transferred are located, and the parties record that authority as the Irish Data Protection Commission unless the customer names a different competent authority on the Annex IV Signature Page.
For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office. For transfers subject to the Swiss FADP, it is the Federal Data Protection and Information Commissioner.
These are the measures Cutvey actually applies. No certification, audit, or attestation is claimed, and none is held. Cutvey may improve or replace a measure so long as the overall level of security is not materially reduced.
Access control and authentication
Tenant isolation and authorization
Encryption
Data governance
Logging, monitoring, and accountability
Resilience and backup
Secure development and change management
Infrastructure
Personnel
Vulnerability and patch management
Subprocessor management
Supplementary measures for international transfers
Incident response
This annex reproduces the published subprocessor list at https://cutvey.com/legal/subprocessors as at the effective date. The published list is the current one and is incorporated by reference. Where a provider trades under a brand, the published list names the contracting entity where Cutvey has confirmed it from the executed vendor agreement.
| Subprocessor | Purpose | Personal data touched | Location of processing | Duration of processing |
|---|---|---|---|---|
| DigitalOcean, LLC | Application hosting and database | All Customer Personal Data in the workspace | USA (New York) | For the life of the subscription, plus the retention and backup periods in Section 10 |
| Cloudflare, Inc. | File storage for uploads and deliverables, backup storage, bot protection on forms, DNS and CDN | Uploaded files and their contents, database backups, both encrypted at rest by Cloudflare with keys Cloudflare manages, IP address and request metadata for bot protection and routing | United States for stored objects and backups. Request routing and bot protection occur at Cloudflare edge locations worldwide, where request metadata including IP address is processed transiently | For the life of the subscription, plus the retention and backup periods in Section 10. Edge metadata is transient |
| Stripe, Inc. | Subscription billing for the customer's Cutvey plan and App licenses. Separately, where the customer connects its own Stripe account through Stripe Connect, Stripe acts for the customer directly under the customer's own agreement with Stripe and is not Cutvey's Subprocessor for that flow; Cutvey transmits invoice and payer details to the customer's connected account at the customer's instruction and never holds funds | Names, email addresses, billing addresses, payment metadata. Card numbers go directly to Stripe and never reach Cutvey | United States, with regional processing by Stripe group entities including in the European Union, under Stripe's own data protection terms | For the life of the subscription, plus the record retention periods Stripe applies as a regulated payment processor |
| Resend, Inc. | Transactional and product email delivery | Recipient names and email addresses, email content, delivery, bounce, open and click events | USA | For the period needed to deliver the message and report delivery events, then per the provider's retention schedule |
| Postmark (ActiveCampaign, LLC) | Fallback delivery of sign-in code emails, used only when the primary provider is unavailable | Recipient email address, sign-in code email content | USA | As above |
| Google LLC (Google Workspace) | Business email for [email protected], which is how Cutvey receives and answers support, privacy, legal, and abuse correspondence | The content of email sent to Cutvey and Cutvey's replies, the sender's email address, and any attachment sent | USA, with Google's global infrastructure | For the support correspondence retention period in the Cutvey Privacy Policy |
| Anthropic, PBC | AI assistant features, invoked by a user | The text or workspace data a user points an AI feature at, and the generated output. Not used to train models | USA | For the duration of the API call, with no retention for training |
| Sentry (Functional Software, Inc.) | Crash and error reporting for the native apps and for the Service | Technical diagnostics: app, operating system and release version, device or server context, the operation that failed, memory figures, and the stack trace, with system library names. Reports are designed and filtered so that they do not carry customer content, and account names, volume names, file and folder names, and access tokens are removed on the paths Cutvey controls before a report is sent. Where personal data nevertheless appears in the text of an error, Cutvey treats that report as Customer Personal Data | USA | For the provider's configured retention period for error events |
| Apple Inc. | Push notification delivery through APNs for the native apps and the companion app | Device push tokens | USA and Apple's global infrastructure | For as long as the Apple service requires |
| Open-Meteo GmbH | Weather for call sheets | Shoot location coordinates only, requested by Cutvey's servers, with no identifier and no user IP address | EU (Germany) | No personal data is retained |
| GitHub, Inc. (Microsoft) | Source code hosting and continuous integration | None. No Customer Personal Data is stored in the repository | USA | Not applicable, no Customer Personal Data |
Apple also acts as an independent controller, not as Cutvey's Subprocessor, for App Store distribution and purchases, for the end user's Apple Account, and for the end user's own private CloudKit database, which Cutvey cannot read. Stripe likewise acts as an independent controller for its own fraud prevention, financial-crime, and regulatory obligations. Apple's and Stripe's own terms and privacy policies govern that processing, and Section 5.7 applies to it.
Crash and error reports also go to an endpoint Cutvey operates itself on app.cutvey.com. That is Cutvey, not a third party, so it is not a Subprocessor and is not in the table above.
Cutvey's professional advisers, such as its accountants and lawyers, act under their own professional duties of confidentiality and are not Subprocessors, provided they receive Customer Personal Data only incidentally and not for the purpose of processing it on Cutvey's behalf.
This page, when signed by both parties, evidences the Data Processing Addendum and the Standard Contractual Clauses incorporated by it, completes Annex I.A, and takes effect from the date the customer first accepted the Cutvey Terms of Service. The terms are the published terms and are not negotiated.
Data exporter
Data importer
Accession under Clause 7 (docking). An additional entity may accede as a data exporter by completing this page, marking it "Accession under Clause 7", and delivering it to [email protected]. Accession takes effect on Cutvey's written acknowledgment.
End of Data Processing Addendum.