For business customers who need this in writing, and for anyone who wants to know exactly which systems touch their footage.
For the video material you upload, you are the controller and we are the processor. We act only on your instructions, which in practice means: process this file into clips using these settings, then delete it.
For your account and billing information we are the controller in our own right. That is covered by the privacy notice.
Processing lasts for the duration of a job plus the retention windows stated below. It ends when you delete the material or close your account.
| Purpose | Data seen | Region |
|---|---|---|
| Object storage & delivery | Source video, finished clips | EU |
| Render compute | Source video, audio | EU (own servers) |
| GPU transcription | Extracted audio only, never video | EU where available |
| Payments | Billing data only โ no footage | EU / US (SCCs) |
| Transactional email | Email address only | EU / US (SCCs) |
Note the third row: only extracted audio is sent to GPU capacity for transcription. Your video never leaves our own servers.
We prefer EU regions throughout. Where a provider operates outside the EEA, transfers rely on Standard Contractual Clauses together with supplementary technical measures โ principally encryption and data minimisation.
Studio customers may request our current security documentation and a written answer to a reasonable due-diligence questionnaire once per year.
If your organisation needs a countersigned agreement, write to legal@vigge.pro and we will provide one.