FAQAccountRights & ComplianceAdvanced

Enterprise and Security Review FAQ: DPA, Data Handling, Access

What procurement and security teams actually get from a Klip Kanvas review — questionnaires, data handling, retention, access control, DPAs, support, and model-training policy.

Updated 2026-02-1714 min read

Security and procurement teams reviewing an AI UGC vendor ask the same seven things: how the review works, what we store, how long we keep it, who can access it, whether a DPA exists, what support looks like, and whether your assets train models. Here is the candid version, limits included.

01

Security Review

1.How does a security or procurement review actually start?

Start with sales, not with a support ticket. Enterprise reviews exist for requirements self-serve checkout cannot express: a signed DPA, a subprocessor list, a questionnaire, purchase-order billing, or a defined support commitment. Send the questionnaire and the list of must-have controls in one pack. We will not invent certifications we do not currently publish, and we will not fill a 200-row spreadsheet from a free-plan inbox. If you only need more credits and seats, an agency tier is faster than a custom contract and gets you rendering the same day — check /pricing before you open a six-week review for capacity alone.

#Security Review

2.Do you have SOC 2 or ISO 27001 certification?

We do not currently publish a SOC 2 Type II report or an ISO 27001 certificate in product materials, and this FAQ will not invent either. If a named certification is a hard gate in your vendor policy, treat that as a live question for sales rather than as a yes on a landing page. What we can describe without over-claiming is the operating posture: encryption in transit, access scoped to the people who run the service, and contractual terms for processors. A review that requires a specific report number should ask for the current artefact list in writing. Do not treat marketing copy as an audit letter.

#Security Review

3.Is there a self-serve trust centre with downloadable reports?

No. There is no public portal where a prospect can download audit letters, penetration-test summaries or a live subprocessor inventory without talking to us. That is a real limitation for teams used to a Trust Centre login. The workable path is a named review: sales shares the documents that exist for the current period under NDA if needed, and legal shares the DPA and MSA drafts. Budget calendar time for that exchange rather than assuming a same-day download. If your process cannot start without a self-serve pack, say so in the first email so nobody wastes a month discovering the gap.

#Security Review

4.How long does a typical enterprise review take?

Budget two to six weeks from a complete questionnaire to a signed paper pack, depending on how many of your controls are must-haves versus nice-to-haves. Reviews stall when the first send is a 200-row spreadsheet with no ranking, or when legal, security and media sit in separate threads. Send one pack, mark blockers in bold, and name a single counterpart on your side. Rendering does not have to wait for the MSA if a standard paid plan already covers the work — many teams generate on a paid workspace while paper is in flight, then migrate commercial terms when the contract lands. Unusual volume still goes through sales.

#Security Review

5.What should security review versus what should legal review?

Split the pack. Security owns data flows, access, retention, incident notice, subprocessors and whether your assets can train models. Legal owns the DPA, the MSA, governing law, indemnity, and whether your advertising use of synthetic performers is described honestly in your own client contracts. Mixing the two into one questionnaire produces slow, contradictory answers. Klip Kanvas can support both tracks; we cannot be your counsel on whether a given ad is lawful in a given market. The advertiser still owns advertising compliance, disclosure and claims. Put that sentence in your internal brief so the review does not try to buy a legal opinion from a software vendor.

#Security Review#Contracts & DPA

6.Does a security review make our ads legally compliant?

No. A security review answers how the vendor handles data. It does not answer whether a Meta disclosure is required, whether a supplement claim is substantiated, whether an avatar may be presented as a real customer, or whether a landing page matches the ad. Those duties sit with the advertiser in every market we see. Klip Kanvas provides generation tooling, recommended disclosure prompts where we can, and licensed stock avatars; we do not certify an ad, a claim or an account as compliant. If your procurement pack tries to buy advertising-law cover from a software DPA, send it back. Pair this hub with the Meta, TikTok and commercial-rights FAQs rather than stretching security paper to cover creative risk.

#Security Review
02

Data Handling

7.What customer data do you actually store?

Account data and production data. Account data is what you typed at sign-up and billing: name, email, credentials, payment references via a processor, business details. Production data is what you put into the workspace to make ads: product URLs and scraped page text, uploaded footage and images, scripts, brand kits, generation history, custom-avatar reference recordings, and the rendered files. We process those inputs to generate the video you asked for. We do not need your customer lists, your Meta pixel events or your Shopify order history to render a 30-second ad, and you should not upload them. If a field is not required to make the creative, leave it out of the workspace.

#Data Handling

8.How is data protected in transit and at rest?

Traffic to the product runs over encrypted connections, and stored production assets sit on the cloud infrastructure that hosts the service rather than on laptops. That is industry-standard hygiene, not a unique control, and it is not the same thing as a certified information-security programme. Payment card data is handled by the payment processor, not stored as raw card numbers in the workspace. No transmission over the public internet is 100% secure, which is the honest limit rather than a slogan. If your questionnaire asks for named cipher suites, key-management diagrams or a customer-managed key, those details are a sales-review item, not a self-serve toggle in the editor.

#Data Handling

9.Can we choose a data-residency region?

Not as a self-serve toggle. The platform runs on shared infrastructure, which is what keeps a typical 30-second ad in the 3–5 minute render window and lets new avatars ship monthly to every account at once. A dedicated region, a private cloud or an on-premise install is not a product feature you can click on. If residency is a contractual requirement, raise it in the enterprise review and get the current hosting footprint in writing. If the requirement is “EU-only processing with no exceptions,” assume that is a negotiation rather than a checkbox, and do not brief your board that residency is already guaranteed because an FAQ mentioned encryption.

#Data Handling

10.Do you scrape extra data about our customers from the open web?

No. Product-page import pulls the public content of the URL you give us — title, description, images — so the script model has something to write against. That is a fetch you initiated, not a background dossier on your buyers. We do not append data-broker profiles, social graphs or purchase histories onto your workspace. If your security team is mapping “what the vendor knows about our customers,” the accurate answer is: whatever you uploaded or pointed us at, plus account and billing records. Keep customer PII, support tickets and CRM exports out of the asset library. The less you put in, the smaller the deletion and transfer conversation later.

#Data Handling

11.Are third-party model or cloud providers in the generation pipeline?

Yes. Rendering, storage, payments and some model calls run on specialised providers rather than on a single box we own. That is normal for an AI video product and it is why a subprocessor list exists as a document you can request, not as a secret. What we will not do in an FAQ is publish a frozen vendor table that goes stale the week after it is copied into a wiki. Ask sales for the current list and the purpose of each processor. If a named subprocessor is a hard block for you, that belongs in the review before you generate production ads, because swapping a model vendor is not a customer-facing toggle.

#Data Handling#Contracts & DPA
03

Retention & Deletion

12.How long do you keep generated videos and uploads?

Workspaces keep generation history, uploads and rendered files so you can re-export, iterate and compare tests — that is the product, not a hidden archive. There is no self-serve “delete everything older than 30 days” retention slider today, which is a genuine gap for teams with a strict destruction schedule. Operational retention for backups and logs is measured in service needs, not in a marketing number we can quote as a guarantee. If you need a named retention period in a contract, that is a sales term. Practically, treat the workspace as a production environment: copy approved MP4s to your own storage on the day they are approved, then request deletion of what you no longer need.

#Retention & Deletion

13.How do I delete an account and the data in it?

Cancel the subscription in the billing panel so you stop accruing charges, download anything you still need, then request deletion in writing so production data is taken out of the live workspace. Deletion removes custom avatars and assets from future generations; videos you already exported and stored elsewhere remain in your possession because they left our system when you downloaded them. Backup cycles mean “gone from the product” is not the same as “gone from every replica in the same hour.” If a regulator or a client contract requires a written confirmation, ask for it as part of the request rather than assuming a dashboard receipt. Privacy and legal contacts live on /privacy and /terms.

#Retention & Deletion

14.What happens to a custom clone if we ask you to delete it?

Deletion removes the private avatar from the workspace so nobody on your seats can generate with it again. That is the control you want when a founder leaves or a talent agreement ends. It does not reach into ad accounts, CDNs or folders where you already placed finished files — those copies are yours to pull down. Budget the human step: tell media to pause ads that still use that face, then replace the creative in the next 48–72 hour test cycle. Cloning itself sits on higher-tier plans and includes a consent review that we will not automate away; deletion is the matching off-switch and should be in your offboarding checklist, not discovered during an incident.

#Retention & Deletion
04

Access Control

15.Who inside Klip Kanvas can see our workspace?

Access is scoped to people who operate the service — support investigating a ticket you opened, engineering diagnosing a failed render, and the systems that actually generate the video. It is not a browsing library for the company. We will not discuss the contents of your workspace with a third party who emails claiming to be your client; support is provided to the account holder. That boundary is why agencies should keep clients out of the login if they want a clean chain. If your questionnaire needs a named access-control policy, request the current description through the review. Do not upload credentials, unreleased financials or customer databases “just in case support needs them.”

#Access Control

16.Do you support SSO, SAML or SCIM?

Single sign-on and automated provisioning are not self-serve features on standard plans, and this page will not pretend they are a toggle next to the avatar picker. Identity requirements of that kind are an enterprise-review item: tell sales whether you need SAML, which identity provider you run, and whether SCIM is a must-have or a later phase. Many teams ship their first creative batch on email-and-password seats while identity paper is in flight; that is a risk acceptance your security team should make explicitly, not a workaround we recommend as policy. If SSO is a hard gate before anyone may log in, say so in the first questionnaire so the timeline is honest.

#Access Control

17.Can I restrict what each seat can do?

Seats are the unit of access: people who generate, edit and export. There is not a deep enterprise RBAC matrix with custom roles, field-level permissions and per-folder ACLs. That is a real limitation if you expected a bank-grade entitlement model. The practical control that actually prevents damage is coarser and more reliable: one workspace per brand or client, the minimum number of seats, and clients kept on review links rather than logins. Credits are pooled at workspace level, so a heavy renderer on one seat draws from the same allowance as the rest. Size seats to the people who actually produce, not to headcount, and check included seats on /pricing.

#Access Control

18.Can we run Klip Kanvas on-premise or in a dedicated VPC?

No. There is no self-hosted installer, no customer-managed cluster and no custom-domain deployment of the product UI. Shared infrastructure is the trade that keeps render times in the 3–5 minute range for a typical 30-second ad. If on-premise is a hard requirement in your architecture standard, this is the wrong vendor to force into that shape, and you should learn that in week one of the review rather than after legal has redlined an MSA. Dedicated or isolated arrangements, if they exist at all for a given deal, are negotiated — they are not a plan card on /pricing. Do not promise your board an air-gapped avatar farm.

#Access Control
05

Contracts & DPA

19.Can we get a DPA?

Yes, on request through sales as part of an enterprise or procurement review, not as a PDF attached to every self-serve checkout. If your process cannot transact without a signed DPA, a subprocessor list and an MSA, that is exactly the route the custom plan exists for. The DPA is a data-processing contract; it is not a certificate that your ads are lawful, and it does not move advertising-policy risk onto us. Have your counsel read it against your own roles: you are typically the controller of the personal data you type into the account; we process it to provide the service. Do not skip that mapping. Details of transfers and deletion belong in the signed paper, not in an FAQ paraphrase.

#Contracts & DPA

20.Where do we get the subprocessor list?

Request the current list through sales during the review. It will name categories you already expect — cloud hosting, payments, email, and the specialised providers in a generation pipeline — with a purpose for each. We will not freeze a vendor table inside this article because lists change and a stale FAQ is worse than no FAQ. If a named processor is unacceptable, that is a blocker to raise before you put unreleased product footage into the workspace. Agencies whose end-clients ask for the list should treat Klip Kanvas as a tool or processor in their own vendor register, not as a subcontractor performing services for the end-client. There is a fuller agency angle in the white-label FAQ.

#Contracts & DPA

21.Can we sign a custom MSA and bill on a purchase order?

Yes, through sales rather than through the self-serve card form. Custom paper exists for unusual render volume, security terms, invoice-on-PO billing, and a defined support commitment. It is slower and more expensive than picking a published tier, which is why it should be reserved for requirements a public plan cannot express. If you just need more credits, seats or 4K export, buy the published tier on /pricing and skip the MSA. Annual versus monthly commercial terms still follow the same logic as everyone else: do not commit annually in month one before you know your real render count. Mid-term custom terms are whatever you actually sign, not whatever this page implies.

#Contracts & DPA
06

Uptime & Support

22.What uptime SLA do you publish?

We do not publish a public uptime percentage in this FAQ, and you should not copy a number from a competitor’s marketing site into your client contract and attribute it to us. Standard plans run as a shared service; enterprise availability commitments, if any, are negotiated in procurement and written into the MSA. Promise your own internal users a delivery window that has slack — for example an approved batch inside a stated number of working days — with a carve-out for platform outages. Agencies that pass through an invented SLA discover it at the first incident. If a hard figure is a must-have, get the current position from sales in writing before you sign with your own customer.

#Uptime & Support

23.How does support work on an enterprise deal?

Support is provided to the account holder. You raise a ticket, reproduce the fault, and we investigate workspace-level issues such as stuck renders, failed exports or seat access. We do not staff an always-on war room for every self-serve workspace, and we do not join your client’s Slack as an unnamed vendor. Defined response commitments are a sales term, not a badge on the help widget. A typical 30-second ad still renders in 3–5 minutes when the queue is healthy; priority rendering is a higher-tier capacity feature, not an incident SLA. If your media calendar cannot absorb a failed batch, keep approved exports in your own storage so a platform blip does not take live ads down.

#Uptime & Support

24.Will we be notified of a security incident?

Incident notice belongs in the DPA and MSA, not in a blog paragraph. We will not quote a made-up “within X hours” clock here because a number that is not in your contract is not a commitment. What you should insist on in paper is how you are contacted, who on your side is named, and what a notice contains — nature of the incident, data categories, and steps taken — without turning the FAQ into a substitute agreement. Internally, decide who in your company receives that mail before you need it. If you are an agency, your client notice obligations are yours; we notify the account holder, not every end-brand on your roster.

#Uptime & Support#Contracts & DPA
07

Model Training

25.Do you train public models on our private product assets?

Our operating policy intent is that private product assets — your uploads, brand kits, product-page pulls and custom-clone recordings — are not used to train public foundation models. That is a policy statement, not a certified guarantee and not a substitute for a contractual restriction. The live privacy policy on /privacy is the document that governs how generated content and inputs may be processed to operate and improve the service. If your board needs a no-training clause with audit rights, ask for it in the MSA rather than highlighting a sentence in an FAQ. Do not upload material you would be unwilling to have a processor see under that policy.

#Model Training

26.Do you use our generated videos to improve the product?

Operating and improving a generation product involves processing inputs and outputs; the live /privacy page is the accurate description, including that generated content may be stored in connection with improving models. That is a broader statement than “we train public models on your unreleased SKU footage,” and the two should not be collapsed. If you need a narrower processing purpose, that is exactly what a DPA plus a negotiated training restriction is for. A practical control you already have: keep unreleased formulas, unannounced packaging and customer-identifying footage out of the workspace until paper matches your risk appetite, and use stock avatars from the 50+ library instead of cloning while the review is open.

#Model Training

27.Can we get a contractual clause forbidding training on our data?

You can ask, and enterprise paper is the place to ask. Whether a given deal includes a hard prohibition, a limitation to service improvement, or an opt-out for specific asset classes depends on what is actually signed, not on this article. Treat “we do not train public models on your private product assets” as the default policy intent you are trying to lock, not as a certificate you can wave at a regulator. Legal should map that clause against subprocessors as well as against us, because a restriction that stops at our front door and ignores the generation pipeline is incomplete. Raise it in the first questionnaire so it does not appear as a last-week blocker.

#Model Training#Contracts & DPA

Ready to put this into practice?

Create your first AI UGC video ad in minutes — no filming, no actors, no editing.

Try Klip Kanvas free

More in this section

Ready to make ads like these?

Paste a product link and Klip Kanvas writes the script, casts the creator and renders the ad — no filming, no actors, no editing.