Last updated: 13 August 2026
This Data Processing Agreement (the DPA) forms part of the Terms of Service between you (the Customer) and Triple Down AB, org. nr 559333-6091, VAT SE559333609101, Skeppargatan 55, 114 59 Stockholm, Sweden (Quaterio, us, we). It applies whenever we process personal data on your behalf through the Service.
It takes effect when you accept the Terms of Service and continues for as long as we process personal data for you. If you need it signed as a separate document, email hello@quaterio.com and we will countersign this text.
Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA governs.
For the content you put into the Service, you are the controller and we are the processor. You decide what personal data goes into your documents, templates and API calls, and you are responsible for having a lawful basis to process it.
For your own account and billing data we are the controller in our own right, and our Privacy Policy governs that, not this DPA.
We process personal data only on your documented instructions, which consist of this DPA, the Terms of Service and your use of the Service, including calls you make to the API. We will tell you if we believe an instruction breaches GDPR or other EU or member state data protection law.
If we are required by EU or member state law to process personal data beyond your instructions, we will inform you before doing so unless that law forbids it.
Everyone we authorise to process your personal data is bound by confidentiality and only has access where their role requires it.
We implement appropriate technical and organisational measures under Article 32 GDPR. The measures in place today are listed in Annex II below. We may change them, but not in a way that materially reduces the level of protection.
You give us general authorisation to engage sub-processors. The current list, what each one receives and where it is located, is published at quaterio.com/subprocessors.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.
We will give you at least 30 days notice before adding a sub-processor if you ask to be on the notification list. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro rata refund of any prepaid fees.
Some sub-processors are located outside the European Economic Area, and Annex I says which. Those transfers rely on the EU Standard Contractual Clauses or another safeguard permitted by Chapter V GDPR. You authorise us to enter into those clauses with sub-processors on your behalf.
Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights. The Service also lets you access, correct, export and delete content yourself, which will usually be faster than asking us.
We will also give you reasonable help with data protection impact assessments and prior consultations under Articles 35 and 36, to the extent the information is ours to give.
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your personal data. The notice will describe what happened, the likely consequences and the measures we are taking, to the extent we know them at the time.
You can export or delete your content at any time while your account is active. When your account is deleted we retain the data for 30 days so it can be recovered, then permanently remove it.
We keep billing records for 7 years because Swedish accounting law requires it. Those records contain billing details, not the content of your documents.
We will make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits conducted by you or an auditor you appoint.
In practice, please start by asking us. We would rather answer a security questionnaire or walk you through our architecture than have you commission an audit, and that satisfies most requirements. Where an on site audit is genuinely necessary we will agree reasonable scope and timing, no more than once a year unless a regulator or a breach requires otherwise, at your cost.
Two things worth knowing when you assess us. We hold an executed Article 28 agreement with Hetzner, the provider that hosts document rendering, signed in August 2026. And Hetzner's data centres are independently audited by TÜV Rheinland i-sec, most recently in February 2026.
Both documents are marked confidential by the parties that wrote them, so we will not republish them and we cannot promise to forward them. What we can do is confirm the specifics, answer a security questionnaire against them and point you to Hetzner, who can share their own material with you directly.
To be clear about what that is and is not: Quaterio itself holds no third party security certification such as SOC 2 or ISO 27001. The audit above covers the data centres underneath us, not our application. We would rather draw that line ourselves than have you find it during procurement.
This DPA is governed by Swedish law. Disputes are resolved the same way as under the Terms of Service: before Stockholm District Court (Stockholms tingsrätt) for business customers, and for consumers in the courts of the country where they live, with their statutory rights intact.
Liability under this DPA is subject to the limitations in the Terms of Service. We carry business liability insurance with If Skadeförsäkring. Customers running procurement can request the current certificate of insurance from hello@quaterio.com.
Subject matter and duration. Provision of the Quaterio document editor and PDF generation API, for as long as you have an account.
Nature and purpose. Storing documents and templates, rendering them to PDF, replacing template variables with data you supply, delivering generated files, sending webhooks you configure and, if you choose it, AI formatting of a document you import.
Types of personal data. Whatever you put into your documents, templates and API calls. That is your choice, not ours, and it commonly includes names, addresses, contact details and invoice or contract data. Plus account data for your users: name, email address and authentication credentials.
Categories of data subjects. Your users of the Service, and any individuals appearing in the content you process through it, such as your customers, employees or contract counterparties.
Special category data. The Service is not designed for special category data under Article 9 or criminal conviction data under Article 10. If you intend to process it, contact us first.
Sub-processors and locations. See quaterio.com/subprocessors, which names each provider, what it receives and whether it is inside or outside the EEA.
The technical and organisational measures in place today: