Draft. This text is not finished. The company details are missing and no lawyer has read it yet, so nothing here can be relied on.
You do not have to ask us for this one. It applies from the
moment you create an account, and it is part of the
terms of service. If your own client needs a signed copy on
paper, write to privacy@cutlink.studio and you
get one.
This is the agreement required by article 28 of the GDPR. It exists because of
a simple situation: your client's film is not your personal data, but the name and
email address of the producer you sent the link to is. You decide what happens to
that. We only hold it because you asked us to.
01The parties and their roles
| Controller |
You, the account holder. You decide what goes into a project and who
receives the link. |
| Processor |
INVULLEN, INVULLEN, INVULLEN, Nederland, Chamber of
Commerce INVULLEN, trading as CutLink. |
Where we act as controller instead, which is for your own account data, the
privacy statement applies rather than this agreement.
02What we process, and why
| Subject matter |
Storing the files you upload, showing them on a delivery page, and
collecting what the recipients write back. |
| Purpose |
Only this: delivering your work to the people you chose. Nothing
else. |
| Duration |
As long as you have an account, and for each project as long as that
project exists. |
| Data subjects |
The people you invite to a delivery page, and anyone identifiable
inside the material you upload. |
| Categories of data |
Names and email addresses of recipients; the name someone types next to
a comment and the comment itself; a record of which file was downloaded
and when, with the country of the request; and whatever personal data
happens to sit inside the files you upload, which is yours to know and
not ours to inspect. |
| Special categories |
We do not ask for them and the service is not built for them. If the
material you upload contains them, that is your decision and your
responsibility. |
03We act on your instructions
We process this data only on your instructions. Using the service is the
instruction: create a project, invite someone, delete a file. We do not do
anything else with it, and specifically we do not use it to train models, do not
analyse it for our own ends, and do not show it to anyone who does not have your
link.
The one exception is a legal obligation under EU or Dutch law. If that ever
happens we will tell you first, unless that same law forbids it.
If we think an instruction from you breaks data protection law, we will say so
rather than quietly carry it out.
04Confidentiality
Anyone who can reach your data is bound to keep it confidential, and that
obligation outlives their involvement. Access is limited to the people who need it
to keep the service running.
05Security
The measures in place, as required by article 32:
- All traffic runs over TLS. There is no unencrypted route into the service.
- Files are stored in object storage that is not reachable from the public
internet. Every download goes through our own code, which checks the link and
its expiry first.
- Passwords are stored as hashes with a per-account salt.
- Sessions carry a random identifier, are marked
HttpOnly,
Secure and SameSite=Lax, and expire after 30
days.
- A delivery link can be given a password and an expiry date, and locks itself
for a while after repeated wrong attempts.
- Storage and database are located in Western Europe.
- Access to production systems is limited to the people who need it, and is
protected by two-factor authentication.
These are the measures as they stand today. We may change them, but not for the
worse.
06Sub-processors
You give us general permission to use the companies below. We keep the list as
short as we can, because each name is one more party you have to trust.
| Who | What for | Where |
| Cloudflare |
Hosting, database and file storage. |
Western Europe |
| Resend |
Sending invitations and notifications. |
European Union |
| Stripe |
Payment. Reaches your billing data, never your project data. |
United States, EU-US Data Privacy Framework |
| Google |
Only signing in with a Google account, and only if you choose it.
Reaches no project data. |
United States, EU-US Data Privacy Framework |
Each of these is bound to obligations no lighter than the ones in this
agreement, and we remain answerable to you for what they do. If we want to add one
or swap one out, you hear it at least 30 days beforehand at the address on your
account. Object within those 30 days and you may end the agreement without cost
for the part you have not used.
07Transfers outside the European Economic Area
Project data stays in Western Europe. The two American parties in the list
above are certified under the EU-US Data Privacy Framework, and where that is not
enough the Standard Contractual Clauses apply in addition.
08When someone exercises their rights
If a person whose data you put into CutLink comes to us directly, we will not
answer for you. We pass the request on and leave the decision to you, because it
is yours.
We will help you answer it. Everything in a project is visible and exportable
from your own account, and if you cannot get at something, ask us and we will.
09Breaches
If we discover a breach involving your data, we tell you without undue delay and
in any case within 48 hours of noticing it. You will get what we know: what
happened, which data is involved, how many people, what we are doing about it, and
what you can do. The report to the Dutch Data Protection Authority is yours to
make, because you are the controller. We will give you everything you need to make
it.
10Help with assessments
If you have to carry out a data protection impact assessment or consult a
supervisory authority, we will give you the information about our processing that
you need. For a reasonable amount of work this costs nothing.
11Deletion at the end
When your account ends, your projects and files are deleted. Ask us for a copy
first and you get one, as long as you ask before you delete the account.
Backups roll over on their own cycle and are gone within 30 days. Until then
whatever is in them is only ever used to restore the service, never for anything
else.
12Showing our work
On request we will give you the information you need to see that we are keeping
to this agreement. If you want an audit on top of that, we will cooperate with an
independent auditor you appoint, at your cost, announced at least 30 days ahead,
at most once a year, and more often only if a supervisory authority makes us.
13Duration and precedence
This agreement runs for as long as your account does, and the obligations that
by their nature outlast it, do. Where it conflicts with the
terms of service on a matter of personal data, this
agreement wins.
Dutch law applies, and the court named in the terms of service hears any
dispute.