Last updated: August 13, 2026
Quaterio is operated by Triple Down AB, org. nr 559333-6091, VAT SE559333609101, Skeppargatan 55, 114 59 Stockholm, Sweden. We are the data controller for the personal data processed through our Service. You can reach us at our contact page or by email at hello@quaterio.com.
We collect the following categories of personal data:
We use your data to:
We do not use your data for advertising. We do not build advertising profiles. We do not sell your data.
We process your data based on:
We do not sell your personal data. We share data only with service providers (sub-processors) who help us operate the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (Frankfurt) |
| Vercel | Application hosting and content delivery | Global edge network |
| Hetzner | Virtual server running our PDF rendering and document import service | EU (Germany) |
| Stripe | Payment processing and subscription billing | US and EU |
| Resend | Transactional email delivery | US |
| Google Gemini | AI formatting of an imported document, only when you choose to use it | US |
| Condux (self hosted) | Error monitoring | EU (Germany), on our own Hetzner server |
| Google reCAPTCHA | Bot detection on the contact form | US |
| Upstash | Job queue for asynchronous parsing of documents you import | EU (Belgium), provider incorporated in the US |
| Umami (self hosted) | Cookieless analytics and sampled session replay | EU (Germany), on our own Hetzner server |
We engage each sub-processor under a data processing agreement, and where data is transferred outside the EU we rely on Standard Contractual Clauses or an equivalent safeguard. What each provider receives, and a link to its own privacy policy, is listed on our sub-processors page.
When you import a document you can ask us to format it with AI. If you do, the text of that document is sent to Google Gemini, which returns structured content. This is the only time your document content leaves our infrastructure for a purpose other than rendering it.
It is your choice every time. Skip AI formatting and nothing is sent, and we skip it automatically for files that are already structured. We do not use your documents to train any model, and we do not send them anywhere for that purpose.
Some of our sub-processors are based in the United States. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses and the sub-processor's own compliance certifications.
We retain your account data for as long as your account is active. After account deletion, we retain data for 30 days before permanent removal to allow for recovery. Billing records are retained for 7 years as required by Swedish accounting law. Anonymized analytics data is retained indefinitely as it cannot be linked to any individual. Session recordings are retained for 30 days, then automatically deleted.
Under the GDPR, you have the right to:
To exercise these rights, contact us at our contact page. We will respond within 30 days. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.
We use a minimal set of essential cookies. We do not use advertising or tracking cookies. Cookieless analytics (page views, screen size, Core Web Vitals) runs on the legitimate interest legal basis and does not require consent. Optional session recording runs only after you grant Measurement consent through our consent banner. You can change or withdraw that consent at any time. See our Cookie Policy for details.
We use industry standard security measures including encrypted data transmission (TLS), hashed credentials (bcrypt), hashed API tokens (SHA-256), role based access controls and row level security at the database layer. We conduct regular security reviews and promptly address vulnerabilities.
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will delete it promptly.
We may update this policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.
For privacy related questions or to exercise your rights, contact us at our contact page or by email at hello@quaterio.com.