This English text is a convenience translation. The legally binding version is the German version available at clipnity.com/privacy-policy. In the event of any discrepancy, the German version prevails.
Last updated: 09.08.2026.
This policy explains how Clipnity processes personal data. It has been prepared on the basis of the General Data Protection Regulation (GDPR) and German data protection law.
No data protection officer has been appointed; according to our documented assessment, the appointment obligations under Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) do not apply.
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Account creation, performance of the user agreement | Name, e-mail address, password hash, user name | Art. 6(1)(b) GDPR | Until the account is deleted; thereafter pseudonymisation and erasure once the statutory periods have expired (Section 5.3) |
| Telephone number verification | Telephone number, verification status, device signals of the verification process (Section 6.5) | Art. 6(1)(b) and (f) GDPR: performance of the contract and our legitimate interest in preventing duplicate and fake accounts | For the duration of the contractual relationship |
| Clip submission and review | Link to the clip on the third-party platform, metadata, performance data | Art. 6(1)(b) GDPR | For the duration of the remuneration process; where the records form the basis of settlements, the periods set out in Section 5.3 apply |
| Group and slot administration | Memberships, slot status, outstanding balances | Art. 6(1)(b) GDPR | For the duration of the contractual relationship, plus the statutory periods (Section 5.3) |
| Messaging and group chats including media uploads | Message content, uploaded media, sender, timestamps | Art. 6(1)(b) GDPR | Until deleted by the user or until the account is deleted |
| Provision and storage of campaign and source material of the Creators as well as of preview images of submitted clips | Uploaded media files, preview images, metadata, uploading user, timestamps | Art. 6(1)(b) GDPR | Until deleted by the user or until the account is deleted; records relevant to settlement in accordance with Section 5.3 |
| Profile, statistics and leaderboards (visibility to other users) | User name, profile details, clip statistics, rankings | Art. 6(1)(b) GDPR | For the duration of the contractual relationship |
| Social media account linking | Handle of the linked social media account, verification status | Art. 6(1)(b) GDPR | For the duration of the contractual relationship |
| Age verification | Confirmation of majority age | Art. 6(1)(b) GDPR | For the duration of the contractual relationship |
We do not host the published clips themselves; they remain on the platform on which the Clipper published them. Of the clips, we store the link, metadata, a preview image and the performance data required to calculate the remuneration. Insofar as these records document which remuneration claims have arisen, they form part of the accounting records and are subject to the statutory retention periods set out in Section 5.3; they are erased once those periods have expired.
Source of the performance data (Art. 14(2)(f) GDPR): We do not collect the performance data from you but retrieve it via the interfaces of TikTok, Instagram and YouTube. What is retrieved are view and interaction figures as well as metadata of the clip and of the publishing profile.
Account deletion: If your account is deleted, the account is deactivated, pending processes are completed, the data is pseudonymised and erased once the retention periods set out in Section 5.3 have expired.
In order to protect against automated or manipulated interactions, submitted clips are assessed by machine. Abuse detection is a mandatory platform minimum and cannot be deactivated; group operators may only set stricter thresholds. If the anomaly score exceeds the applicable threshold, the clip is blocked and initially does not trigger any further remuneration claims.
Legal basis: Art. 6(1)(b) and (f) GDPR: performance of the contract (determination of legitimate remuneration claims) and our legitimate interest in protecting the platform against manipulation.
Automated individual decision-making (Art. 22 GDPR): The blocking constitutes an automated individual decision within the meaning of Art. 22(1) GDPR. It is necessary for the performance of the contract between you and us (Art. 22(2)(a) GDPR), because remuneration claims can only arise for non-manipulated interactions and the review of the submitted clips must be carried out by machine due to their volume. As safeguards under Art. 22(3) GDPR, you have the right to obtain human intervention, to express your own point of view and to contest the decision. A final forfeiture of the remuneration only occurs after human review.
Logic involved, significance and consequences (Art. 13(2)(f) GDPR): The assessment covers interaction and history data of the submitted clip – the distribution of views over time, the ratio of views to interactions, repetition patterns and deviations from the average of the respective group – as well as public history data of the publishing social profile, such as posting frequency and profile category. We retrieve this data via the interfaces of the respective platform (Art. 14(2)(f) GDPR). An anomaly score is derived from this. Consequence: If the threshold is exceeded, the clip is blocked; initially no further remuneration claims arise for it. No profiling for other purposes takes place; the account is not blocked automatically.
Retention period: Scores and blocking decisions are retained for 24 months after completion of the respective process, or, where an objection is pending, until its conclusion. Thereafter they are erased, unless they are subject, as part of accounting records, to the periods set out in Section 5.3.
Your right to review: You may object to any blocking. The blocking will then be reviewed by a human being; you may express your point of view and contest the decision. Contact: contact@clipnity.com.
| Purpose | Data | Legal basis | Recipient |
|---|---|---|---|
| Payments and payouts | Payment data, bank details, transaction data | Art. 6(1)(b) GDPR | Stripe Payments Europe, Ltd. |
| Identity verification (KYC) for payouts | Name, date of birth, address, bank details, identity document where applicable, verification status | Art. 6(1)(b) GDPR (processing of payouts); Art. 6(1)(c) GDPR only for the mandatory data to be collected under the PStTG (Section 5.1) | Stripe Payments Europe, Ltd. |
Payouts are processed via Stripe Connect. We ourselves collect the KYC, identity and bank data required for payouts (name, date of birth, address, bank details, identity document where applicable) within our application and transfer it to Stripe Payments Europe, Ltd. (Ireland). Stripe processes this data in part as an independent controller, in particular in order to fulfil its own statutory verification and due diligence obligations, in accordance with its own privacy policy available at stripe.com/privacy.
Stripe transfers personal data within the group to Stripe, Inc. (USA). Stripe, Inc. is certified under the EU-US Data Privacy Framework; in addition, EU standard contractual clauses are in place.
Insofar as we meet the requirements of a reporting platform operator within the meaning of the Plattformen-Steuertransparenzgesetz (PStTG – German Platform Tax Transparency Act), we are obliged to report information on Clipper remuneration to the Bundeszentralamt für Steuern (BZSt – German Federal Central Tax Office). We continuously assess whether these requirements are met and only report where the reporting obligation has been established. We collect the data required for this purpose irrespective of that, because it is also needed for other tax obligations.
Note: Amounts which have been set off against a slot purchase price (see the set-off provision in the Terms of Use) also count as remuneration, even if no payout has been made. The reporting obligation continues to apply even after an account has been deleted for the year of deletion.
Invoices, settlements, set-off records and the associated master data are subject to statutory retention periods:
| Records | Period | Basis |
|---|---|---|
| Books and records, inventories, annual financial statements, opening balance sheet, organisational documents; customs documents | 10 years | § 147 Abs. 3 Satz 1 i. V. m. Abs. 1 Nr. 1 und 4a AO (German Fiscal Code) |
| Accounting vouchers (settlements, set-off records, proof of payment) | 8 years | § 147 Abs. 3 Satz 1 i. V. m. Abs. 1 Nr. 4 AO |
| Commercial and business letters received and sent, other documents of tax relevance | 6 years | § 147 Abs. 3 Satz 1 i. V. m. Abs. 1 Nr. 2, 3 und 5 AO |
| Invoices (incoming and outgoing) | 8 years | § 14b Abs. 1 Satz 1 UStG |
| Reporting data records of the platform report and the documents on which it is based | 7 years | § 93c Abs. 1 Nr. 4 AO |
The periods begin at the end of the calendar year in which the accounting voucher was created, the commercial or business letter was received or sent, or the invoice was issued (§ 147 Abs. 4 AO, § 14b Abs. 1 Satz 3 UStG). They do not expire insofar as and for as long as the documents are relevant to taxes for which the assessment period has not yet expired (§ 147 Abs. 3 Satz 5 AO). Once the periods have expired, the data is erased.
Deleting your user account does not erase this data. If an account is deleted, the account is deactivated, pending processes are completed and the remaining data is pseudonymised; settlements, set-off records and invoice data remain stored for the periods stated and are only erased once those periods have expired. The right to erasure does not apply in this respect, because the processing is necessary for compliance with a legal obligation (Art. 17(3)(b) GDPR). Within those periods, the processing of this data is restricted (Art. 18 GDPR); it is used exclusively for the fulfilment of tax obligations.
This website and the application backend run on a virtual server operated by
UnestyA further server, operated by Contabo GmbH, is located in the United States of America. It is addressed via geographically routed DNS, holds a copy of the user data, forwards changes to the German server and additionally serves as an API endpoint. Regarding the associated third-country transfer, see Section 7.
Legal basis: Art. 6(1)(b) GDPR for the operation of the service requested by you, as well as Art. 6(1)(f) GDPR: our legitimate interest in secure and reliable operation.
Log data is generated during the operation of the service. Depending on the component, it contains personal data:
| Component | Data recorded |
|---|---|
| Reverse proxy | Full IP address, user agent, referrer, request method, path, protocol, status code, timestamp |
| Authentication service | IP address, user ID, login provider, request ID, timestamp |
| Database | Client IP address, timestamp, process ID, database user and database name. Query contents are not logged; only schema changes are recorded |
| File storage | Message, level, timestamp, host name, process ID; no IP addresses |
| API layer | Errors only; no request logs |
| Realtime service | Timestamp, level, message; no IP addresses |
Purpose: Operation and stabilisation of the service, error diagnosis as well as detection and investigation of attacks and abuse.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of the service.
Retention period: Log data is erased after 30 days, unless an individual entry is required for longer in order to investigate a specific security incident.
Transactional e-mails (registration, invoices, settlements, confirmations) are sent from our own mail server and delivered via Amazon Simple Email Service in the Europe (Frankfurt) region. The recipient address and the content of the message are processed for this purpose.
Legal basis: Art. 6(1)(b) GDPR.
If you write to us, by e-mail or via the form on our contact page, we process the details you provide in order to handle your enquiry.
| Data | Legal basis | Retention period |
|---|---|---|
| Name, e-mail address, subject, content of your message | Art. 6(1)(b) GDPR insofar as your enquiry concerns a contractual relationship with us, otherwise Art. 6(1)(f) GDPR: our legitimate interest in answering the enquiries addressed to us | Until your enquiry has been dealt with and no further queries are to be expected. If the correspondence is of tax relevance, the periods set out in Section 5.3 apply instead |
The provision of this data is neither required by law nor by contract. Without it, however, we cannot reply to you.
Messages sent via the form are transmitted to our own API and forwarded from there to our mailbox. No third-party form service is involved.
For the verification of telephone numbers we use the service Prelude (prelude.so). The telephone number you provide, the verification status as well as device signals of the verification process (device platform, signals identifier) are processed.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR: our legitimate interest in preventing duplicate and fraudulent accounts.
Personal data is disclosed to:
Beyond that, we only pass on data where we are legally obliged to do so or where this is necessary for the establishment, exercise or defence of legal claims.
The identity of individual Clippers is not disclosed to Creators. Clipnity provides the campaign service to the Creator in its own name and for its own account and commissions Clippers in its own name and for its own account; there is no contract between Creator and Clipper. The invoice issued to the Creator sets out exclusively the service provided by Clipnity in a single line item and contains no names, addresses or tax numbers of Clippers.
Settlement with the Clipper is carried out by means of a self-billed credit note from Clipnity to the Clipper (§ 14 Abs. 2 Satz 5 UStG). It is transmitted to the Clipper, not to the Creator.
Exception. If a third party asserts a statutory right to information or a public authority requests information, we examine the legal basis and scope, limit the disclosure to what is necessary, record every disclosure and inform the data subject insofar as this is legally permissible. Legal basis: Art. 6(1)(c) GDPR in the case of a legal obligation, otherwise Art. 6(1)(f) GDPR (establishment, exercise or defence of legal claims).
The server described in Section 6.1 and operated by Contabo GmbH is located in the United States of America and holds a copy of the user data. This therefore constitutes a transfer to a third country within the meaning of Chapter V GDPR.
An adequacy decision of the European Commission (EU-US Data Privacy Framework) has been in place for the USA since 10.07.2023. However, it applies only to US companies certified under that framework and does not cover this transfer. The transfer therefore takes place on the basis of the EU standard contractual clauses (Implementing Decision (EU) 2021/914) together with supplementary measures (encryption in transit, encryption at rest). In addition, a data processing agreement (Art. 28 GDPR) is in place with the provider. You may obtain a copy of the standard contractual clauses via contact@clipnity.com.
Notwithstanding the above, data on the US server may be subject to access by US authorities; the legal remedies available there do not fully correspond to those under Union law.
Regarding the intra-group transfer by Stripe to Stripe, Inc. (USA), see Section 4.
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17; restricted insofar as statutory retention obligations exist, see Section 5.3), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) as well as the right to withdraw consent given with effect for the future (Art. 7(3) GDPR). In connection with the automated decision under Section 3, you additionally have the rights under Art. 22(3) GDPR (human intervention, expression of your own point of view, contestation).
Contact: contact@clipnity.com
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). This concerns in particular the log data under Section 6.2 as well as those parts of the abuse detection which are based on our legitimate interest under Section 3; insofar as the abuse detection is necessary for the performance of the contract (Art. 6(1)(b) GDPR), it cannot be switched off, and in that respect you have the rights under Art. 22(3) GDPR. We will then no longer process the data based on Art. 6(1)(f) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
The objection may be submitted without any particular form to: contact@clipnity.com
This notice is given expressly and separately from the other information in accordance with Art. 21(4) GDPR.
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI) (Thuringian State Commissioner for Data Protection and Freedom of Information)We will amend this policy if the legal situation or our processing changes. The version published on this website applies.
Version: 09.08.2026