Data Processing Agreement (DPA)

FR EN

This Data Processing Agreement (the “DPA”) is entered into pursuant to Article 28 of the GDPR and supplements the General Terms and Conditions of Use and Sale accepted by the Client. In the event of a conflict relating to personal data protection, this Agreement prevails.

It is entered into between the Client, as controller of the content and business data entrusted to Tidecut, and SARL RIOU STICHELBAUT, trading under the Polaryse brand, SIREN 844 114 942, 40 avenue de la Perrière, 56100 Lorient, France, publisher of Tidecut, acting as processor.

1. Subject matter, nature and duration of processing

  • Subject matter: provision of the Tidecut service for uploading, storing, organising, indexing, searching, viewing, transcoding, downloading and sharing files.
  • Operations: collection from Authorised Users, transmission, storage, structuring, consultation, alteration, retrieval, backup, return and deletion.
  • AI-assisted features: keyword generation after a folder has been authorised, audio transcription, translation and subtitle synchronisation. Subsequent searches are performed against stored keywords and do not query an AI.
  • Duration: for the duration of the Service, followed only by the periods required for return, deletion, disaster-recovery backups or compliance with an applicable legal obligation.

2. Data and data subjects

  • Data: business accounts, identity and contact details, roles and permissions, files of any kind, photographs, videos, audio, subtitles, transcripts, translations, metadata, keywords, sharing data and technical logs.
  • Data subjects: the Client’s Users and members, persons appearing or heard in content, partners, guests, authors, customers or other persons whose data is imported by the Client.
  • Special categories of data: content may reveal sensitive data without Tidecut being able to identify it in advance. The Client entrusts such data only where its processing is lawful and necessary.

Facial recognition is not currently offered to Users and its automatic activation is disabled. Any reactivation will require a separate documented instruction, an update to this Agreement and compliance with Articles 6 and 9 of the GDPR. General AI permission for a folder does not constitute permission for biometric processing.

3. Instructions and obligations of the Client

The Client:

  • determines the purposes and essential means of the processing carried out on its content;
  • documents its instructions through the contract, these clauses and the actions of its Authorised Users in Tidecut;
  • has an appropriate legal basis, informs data subjects and handles their requests to exercise their rights;
  • ensures that only authorised persons upload content and initiate optional processing;
  • does not use Tidecut for unlawful or discriminatory purposes, prohibited surveillance or purposes that disproportionately infringe the rights of individuals.

4. Obligations of Polaryse

Polaryse undertakes to:

  • process data only on documented instructions from the Client, unless otherwise required by law;
  • inform the Client if an instruction appears to infringe the GDPR;
  • restrict access to persons who need it and who are subject to a duty of confidentiality;
  • implement technical and organisational measures appropriate to the risk;
  • reasonably assist the Client with data-subject requests, personal data breaches, impact assessments and consultations with supervisory authorities;
  • make available the information necessary to demonstrate compliance with this Agreement;
  • delete or return the data at the end of the Service in accordance with Article 10.

5. Sub-processors

The Client grants general authorisation for the use of the categories of sub-processors listed below. Polaryse informs the Client of any material change so that the Client may raise a reasoned objection. Polaryse may entrust data to a sub-processor only to the extent necessary for the Service and subject to data protection obligations compatible with Article 28 of the GDPR.

Provider or categoryFunctionKnown location
AWSWebsite, PostgreSQL, transcoding, backup Node server and backupseu-west-1, Ireland; CloudFront uses a global network
WasabiObject storage for fileseu-west-2 corresponding to Paris
Tidecut / Free Pro infrastructureMain media API and local modelsFrance
GandiDomain name and domain email-related servicesDepending on the service concerned
StripePayments, subscriptions and billingDepending on the applicable Stripe service and agreement
GladiaAudio-track transcriptionDepending on the infrastructure, regions and sub-processors documented by Gladia
OpenAITranslation and subtitle synchronisation; other possible processing depending on the subscriptionOpenAI Ireland for EEA clients; onward transfers governed by the OpenAI DPA and, where necessary, Standard Contractual Clauses
Mistral AIPossible AI processing depending on the subscriptionDepending on the infrastructure and sub-processors documented by Mistral AI
Google/GeminiPossible AI processing depending on the subscriptionDepending on the region of the service used and the applicable Google data processing addendum
Google Fonts, cdnjs and jsDelivrFonts and libraries loaded on certain pagesGlobal networks; technical connection information may be processed outside the EU

6. International transfers

The main Wasabi and AWS regions are located in the European Union, but CloudFront and certain providers, affiliates or sub-processors may process data from third countries. Polaryse therefore does not guarantee that all data remains within the European Union.

Any transfer to a third country must be based on an adequacy decision, European Commission Standard Contractual Clauses accompanied, where necessary, by an assessment and supplementary measures, or another valid mechanism. For each service used, Polaryse relies on the mechanism set out in the relevant provider’s data processing terms. Information about the mechanism applicable to specific processing may be requested at contact@polaryse.com.

7. Security

Demonstrable measures include, in particular:

  • User authentication and permission management by organisation, company and project;
  • logical separation of Client environments and restriction of operations to authorised Users;
  • HTTPS protection for public interfaces and application safeguards, including protection against unauthorised cross-site requests;
  • storage of the mobile token in secure storage provided by the operating system;
  • logging of certain technical or sensitive actions;
  • PostgreSQL backups retained for up to seven days in AWS eu-west-1.

8. Personal data breaches

Polaryse informs the Client without undue delay after becoming aware of a breach affecting data processed on the Client’s behalf and provides the relevant information then available. The Client remains responsible for assessing notifications to the supervisory authority and, where applicable, to data subjects.

9. Assistance, rights and audits

Polaryse forwards to the Client requests primarily relating to content under the Client’s responsibility and provides reasonable assistance. An audit may be requested on reasonable notice, subject to conditions protecting security, confidentiality, trade secrets and the data of other clients.

10. Data at the end of the Service

At the end of the Service, Polaryse deletes or returns the data in accordance with the Client’s instructions, unless retention is required by law. An organisation’s content is not deleted merely because a member leaves. Where a company is fully deleted, Tidecut deletes its projects and remote media before declaring the operation complete.

Data deleted from the active system may remain in disaster-recovery backups for up to seven days before expiring. Billing records, evidence of requests and information required to establish, exercise or defend legal claims may be retained for the justified period.

Last updated: 3 August 2026 — Version 2026-08-03