GDPR and Data Handling FAQ: Storage, DPA, Transfers, Deletion
What Klip Kanvas stores, how we talk about legal bases, DPAs and subprocessors, transfers, deletion, training on your data, and the obligations that still sit with the advertiser. Not legal advice.
GDPR questions on an AI UGC tool are really seven questions: what we store, why, who else processes it, where it goes, how deletion works, whether your assets train models, and what you still owe your own users. Here is a hedged, operational map — not a certificate of compliance.
01
What We Store
1.What personal data do you store in an account?
Account identity and billing: name, email, credentials, payment references via a processor, and business details you typed. Production data that may include personal data: scripts, uploaded faces and voices, custom-clone recordings, product-page pulls, brand-kit files, generation history and rendered videos. We do not need your customer CRM, your support tickets or your employee directory to render a 30-second ad, and you should not upload them. If a field is not required to make the creative, it should not be in the workspace. The live list belongs on /privacy, which will beat this FAQ when the two ever diverge. Keep the workspace boring. Boring is easier to delete later.
#What We Store
2.Do you store the content of the ads themselves?
Yes. Generated videos, drafts and the inputs that made them sit in the workspace so you can iterate, compare a 6-creative test, and re-export 9:16, 1:1 or 16:9. That history is the product. It also means a talking-head of a cloned founder is personal data sitting in a production tool, not only an MP4 on a DSP. Treat approved masters as something you copy to your own storage the day they are approved. There is no self-serve “store nothing” mode that still lets you run a creative pipeline. That is a real limitation. If a client forbids retention of likeness files, your operational answer is short retention plus a deletion request, not a magic toggle we are pretending exists in this article.
#What We Store
3.Do you collect end-customer data from Meta or Shopify?
Not as a silent overlay. Connecting a store or pasting a product URL pulls catalogue content you pointed us at — titles, images, descriptions — so the script model has product data. It should not be a pipe of your buyers’ identities, purchase histories or pixel events. If an integration surface asks for a permission that is broader than catalogue, grant the minimum. Measurement still lives in your ad accounts and your shop; we are not your CAPI server. Teams that dump CSV exports of customers “for personalisation” are creating a GDPR problem the generator does not need. Do not. A UGC ad needs a product and a claim, not a segment of 50,000 emails.
#What We Store
02
Legal Basis
4.What is your legal basis under GDPR?
For account and billing data, the usual bases in this kind of SaaS relationship are performing the contract and, where needed, legitimate interests or legal obligation — but the live /privacy wording and a signed DPA are the documents that matter, not a paraphrase in an FAQ. For a custom-clone recording, you also need a lawful path to process that person’s likeness and voice, which is often consent plus your own employment or talent contract. We will not pick a basis for your employee programme in a knowledge-base article. If you cannot name a basis for a clone, do not upload the clip. Hedging this is the honest move: basis is fact-specific, and anyone giving you a one-line global answer is guessing.
#Legal Basis
5.Are you a controller or a processor?
For your account data as a customer of the service, we determine how that account is run. For the personal data you type into the workspace to make ads — employee faces, customer footage you should usually not have uploaded, scripts that name people — you are typically the controller and we process it to provide the service. That split is why a DPA exists. Agencies sit in the middle: you may be a processor for your client and a controller for your own staff. Map it on a whiteboard before you send a questionnaire. We will not be offended if your counsel uses different labels in a review, and we will not sign a paper that says we are the advertiser. Roles follow reality, not a sales deck.
#Legal Basis
6.Do you use legitimate interests to train models on my ads?
Do not take a one-word yes from this page. Training and service-improvement uses, if any, are described on /privacy and constrained — or not — in the DPA you actually sign. Our operating policy intent is that private product assets are not used to train public foundation models; that is still a policy intent until it is a clause. If your DPIA cannot live with improvement uses, say so in the review and keep unreleased assets out of the workspace until paper matches. Legitimate interests, where used at all, still require a balancing test you should not copy from a blog. This is exactly the kind of sentence that should send you to counsel rather than to a render queue.
#Legal Basis#Training on Your Data
03
DPA & Subprocessors
7.Can we get a DPA?
Yes, on request through sales as part of a procurement review, not as an automatic PDF on every self-serve checkout. If you cannot transact without a DPA, a subprocessor list and an MSA, that is the enterprise route. The DPA is a processing contract. It is not a certificate that your ads are lawful, that Meta disclosure is correct, or that a clone is valid in Illinois. Have counsel read the roles, the transfer language, the deletion assistance, and the subprocessors. Standard-plan customers who need a DPA should still ask rather than inventing one from this FAQ. We would rather send a real document than watch a wiki fill with guessed clauses. Details live in the signed paper.
#DPA & Subprocessors
8.Where is the subprocessor list?
Request the current list through sales. It will cover the categories you already expect in an AI video product: cloud hosting, payments, email, and specialised generation or storage providers. We will not freeze a vendor table in this article because lists change and a stale FAQ is worse than none. If a named subprocessor is a blocker, raise it before you upload a founder’s consent video. Agencies should list us as a tool or processor in their own register rather than as a subcontractor performing services for the end-brand. If your client forbids a category of processor, that constraint is yours to enforce by not putting their data in the workspace. Paper without operational discipline is decoration.
#DPA & Subprocessors
9.Do subprocessors include foundation-model vendors?
Generation pipelines commonly include specialised model and cloud providers. That is why the list exists as a living document rather than as a slogan that “everything runs on our metal.” If your policy forbids a named model vendor, the review has to happen before production ads, because swapping a model is not a customer-facing toggle. Ask for purpose, data categories, and location in the current list. Then decide whether a stock-avatar campaign on non-sensitive product copy is acceptable while a founder clone is not. That split is a reasonable interim control. Pretending there are no subprocessors is not. Shared infrastructure is also why render times stay in the 3–5 minute range for a typical 30-second ad.
#DPA & Subprocessors
10.Are you certified under GDPR, ISO or the UK ICO?
We do not currently publish a GDPR certification, an ISO 27001 certificate, or an ICO-approved code-of-conduct badge in product materials, and this FAQ will not invent them. Certification is not how GDPR works for most processors anyway; contracts, minimisation and actual handling are. If a named certificate is a hard gate, ask sales for the current artefact list and treat silence as absence. Security questionnaires belong on the enterprise review track. Privacy questionnaires belong here, with the same candour. The limitation is real: teams that can only onboard certified vendors may not be able to onboard us on the timetable they hoped. Better to learn that from a honest page than from a fictional badge.
#DPA & Subprocessors
04
Transfers
11.Where is data hosted and does it leave the EU/UK?
The product runs on shared cloud infrastructure. There is no self-serve EU-only residency toggle, no on-premise install, and no customer-managed key in the editor. Transfers are therefore a live topic for EU, UK and similar regimes, not a solved checkbox. The transfer tool — standard contractual clauses, a UK addendum, or whatever is current — belongs in the DPA, not in an FAQ that would go stale. If “no extra-EEA processing ever” is a hard gate, raise it in week one of the review and be prepared for a no on self-serve. India-based corporate presence and US governing-law language in /terms are extra reasons not to assume an EU-only story. Get the current footprint in writing.
#Transfers
12.How do you handle India, US and other non-EU transfers?
As a cross-border SaaS reality, not as a brochure about local-only data. US, India and other locations may appear in corporate, support or infrastructure maps; the accurate picture is the one sales and the DPA give you for the current period. Adequacy, SCCs and supplementary measures are counsel’s analysis against that picture. We will not certify that a given transfer is “GDPR approved.” If you are an Indian company selling to EU residents, or an EU brand using a tool with non-EU infrastructure, both facts belong in your DPIA. Hiding either one is how DPIAs fail. Operationally, minimise what you upload so the transfer conversation is about account data and ads, not about a customer database you never needed to store here.
#Transfers
13.Do you have a data-residency option for enterprise?
Not as a published plan card on /pricing. Isolated hosting, if it exists for a given deal, is negotiated. Most teams should not open a six-week residency project to run 9:16 product ads; they should minimise personal data and sign a DPA. If residency is genuinely mandatory in your sector, ask early and accept that the answer may be that this vendor is the wrong shape. Shared infrastructure is the trade that keeps new avatars shipping monthly to every account and keeps typical renders in minutes. We will not invent a region-pin in this FAQ. Candid beats a fictional map. Pair the hosting question with the enterprise-and-security-review hub so security and privacy are not answering in two different voices.
#Transfers
05
Deletion Requests
14.How do I access or export my data?
You can already download generated videos, scripts and many workspace assets from the product — that is the practical access path for production files. For account-level access or a more complete pack, request it in writing via the privacy contact on /privacy. Say whether you need account metadata, invoices, clone recordings, or renders. Build in calendar time; this is not a 3–5 minute render. Agencies asking on behalf of a client should be the account holder or have authority, because we will not dump a workspace to a third party who emails claiming to be “the brand.” Portability is a right in many regimes; it is also not a substitute for keeping your own archive of approved masters as you go.
#Deletion Requests
15.How do deletion requests work?
Download what you need, cancel if you are closing the account, then request deletion so live workspace data — including custom avatars — is taken out of production use. Confirm in the request whether you mean a single clone, a workspace, or the whole account. Backup cycles mean the product going dark is not the same as every replica vanishing in an hour; if you need written confirmation, ask for it. We will not promise a made-up 24-hour statutory clock in this article. Identity-check the requester. If a data subject whose face you cloned writes to us, we still expect you, the controller of that talent relationship, to be in the loop. Put privacy@klipkanvas.com in your own ROPA as a vendor contact, not as your only process.
#Deletion Requests
16.Can you delete a video that is already running as an ad?
We can remove it from the workspace so you cannot re-export from us. We cannot reach into Meta, TikTok, YouTube, CDNs or your Google Drive. Pausing ads is a media-operations step on your side, and it should be on the same runbook as clone revocation. If a data subject asks to be taken down, stopping spend is the first hour, not the fifth day. Keep ad IDs mapped to avatars so this is a filter, not a forensic hunt. This split — processor deletes what it hosts, advertiser deletes what it published — is the obligation people forget when they say “just GDPR it.” The generator does not control the internet. You do control Ads Manager. Use it.
#Deletion Requests#Your Obligations
17.How do we contact you about privacy?
Use the privacy contact on /privacy — privacy@klipkanvas.com — and put the company legal name, the workspace email, and whether you are asking for a DPA, an access pack, a deletion, or a subprocessor list. Legal questions about terms go to the contact on /terms. Support tickets are for stuck renders, not for SCC annexes. If you are an agency, say so, and do not expect us to brief your end-client without the account holder. We are a New Delhi–based company with terms that point at Delaware law; those facts belong in your vendor record. Response times are operational, not a published SLA in this FAQ. Enterprise notice clocks, if any, live in the MSA. Ask for the paper you need, once, completely.
#Deletion Requests#DPA & Subprocessors
06
Training on Your Data
18.Do you train public models on our private product assets?
Our operating policy intent is that private product assets — uploads, brand kits, product-page pulls, custom-clone recordings — are not used to train public foundation models. That is a policy statement, not a certified guarantee and not a substitute for a contractual restriction. The live /privacy page currently describes that generated content may be stored in connection with improving models, which is a broader service-improvement statement you should read as written. If you need a hard prohibition, ask for it in the DPA and keep unreleased formulas out of the workspace until it is signed. Do not upload what you would be unwilling to have a processor see under the current policy. Intent plus paper beats intent alone.
#Training on Your Data
19.Can we opt out of training and improvement uses?
Ask. Enterprise paper is the place an opt-out or a narrowed purpose gets written, if it is available for that deal. There is no self-serve “never improve anything from my account” switch next to the render button, which is a genuine product limitation for teams that expected a consumer-style toggle. Until paper says otherwise, assume the privacy policy governs. A practical partial control: use stock avatars and non-sensitive catalogue copy during evaluation, and hold founder clones and unreleased packaging until the clause exists. Fifty free credits are enough to test the format without sending your crown jewels. That is risk management, not a legal basis. Counsel should still read the clause you get.
#Training on Your Data
20.Does using 50+ stock avatars put actor personal data in our account?
You are generating with a licensed character; you are not receiving the actor’s passport or payroll file. Your workspace stores the fact that you used that avatar and the videos you made. That is still production data. It is a different, lighter shape than a custom clone, which stores a recording of a person you named. If your DPIA is triaging risk, stock-library campaigns are the lower-friction starting point, which is also why we tell people not to gate month one on cloning. Actors’ licences sit at the platform layer. Your residual duty is not to use those faces in prohibited or defamatory ways. A DPIA that ignores the clone recording and obsesses over stock-cast metadata is looking at the wrong pile.
#Training on Your Data#What We Store
07
Your Obligations
21.What GDPR obligations still sit with the advertiser?
Most of the interesting ones. You decide to run ads, collect leads, drop pixels, send events via CAPI, clone an employee, upload customer footage, and disclose AI to platforms. You need a basis for your targeting, a notice on your site, a vendor register, and a process for people who object to a likeness. You need to not upload children’s data — our service is not directed at children under 13, and ads that target children are not a use case we want. You need substantiation for claims, which is advertising law, and it still sits beside privacy law rather than inside it. Buying a generator does not buy you a DPO. If that sentence is unwelcome, you are the audience for it.
#Your Obligations
22.Can we upload customer testimonials or user photos?
Only if you already have the rights and a lawful basis to put those people into a new processing purpose — generating and running ads — which a website review or a tagged Instagram photo often does not give you. Default to no. Film a new consented testimonial, or keep the ad in product-explainer language with licensed stock avatars. Uploading a folder of “happy customers” to face-map onto UGC is how you recreate a deepfake problem with extra GDPR on top. Our uploader is not a consent oracle. If you cannot produce the release, do not upload the file. Hybrid remains the grown-up path: licensed avatar for the hook, consented real footage for proof. That also performs better where hands and product demo matter.
#Your Obligations
23.Who answers a data-subject request about an ad they saw?
You do, if you are the advertiser. A person who wants to know why they were targeted is asking about your Meta or Google account, not about our renderer. A person whose face you cloned is asking about your talent processing, and we will assist as a processor on what we host. Do not auto-forward every DSAR to privacy@klipkanvas.com and call it a process; triage first. If they want the ad taken down, pause it in Ads Manager in the same afternoon. If they want a copy of their consent video, that artefact should already be in your legal files. Build this runbook before you clone anyone. The 48–72 hour creative readout is a media habit; deletion and access need a similar clock on your side.
#Your Obligations#Deletion Requests
24.Does a DPA make our Meta and TikTok ads GDPR-compliant?
No. A DPA governs how this vendor processes workspace data. It does not govern your pixels, your lookalikes, your consent banner, your children’s-content flags, or whether an EU user saw a health claim they should not have. Mixing those files in a procurement pack is how companies buy the wrong comfort. Run a privacy review of the ad stack and a separate vendor review of the generator. Then run a policy review of the creative. Three files, three owners. Klip Kanvas can help on the middle one. We cannot sign the other two. Anyone who offers a single “compliant AI ads” stamp is selling a future argument with a regulator or a platform, and we will not join them on that stamp.
#Your Obligations
25.What should we put in our own DPIA for this tool?
Describe the real flow: account data, product assets, optional clone recordings, renders, subprocessors, likely extra-EEA infrastructure, ads run on Meta/TikTok/YouTube, and the fact that you remain the advertiser. List the mitigations you actually use: no CRM dumps, stock avatars unless a clone is necessary, deletion on offboarding, disclosure of synthetic media, human claims pass, voiceover instead of uncleared music. Cite the DPA once you have it. Do not copy marketing adjectives into a DPIA. Residual risks to name: likeness misuse, over-retention of renders, transfer complexity, and the generator’s willingness to speak a reckless script you typed. That last one is a product limitation with a privacy flavour. Your control is the brief.
#Your Obligations#Legal Basis
Ready to put this into practice?
Create your first AI UGC video ad in minutes — no filming, no actors, no editing.