Quiver LogoQuiver
Home/Legal/Data Processing Addendum (DPA)

Data Processing Addendum (DPA)

Standard Data Processing Agreement pursuant to GDPR Article 28 and international data privacy regulations for B2B agencies and corporate subscribers.

Last Updated: September 5, 2026
Effective: September 5, 2026

1. Scope & Application

This Data Processing Addendum ("DPA") supplements the Quiver Terms of Service ("Principal Agreement") between Quiver Technologies Inc. ("Processor", "Quiver") and the Customer ("Controller", "you").

This DPA applies to the processing of Personal Data originating in the European Economic Area (EEA), the United Kingdom, Switzerland, and other jurisdictions requiring a statutory processor agreement.

2. Definitions

Terms such as "Personal Data", "Controller", "Processor", "Data Subject", and "Processing" have the meanings ascribed in the General Data Protection Regulation (EU) 2016/679 (GDPR).

3. Nature, Duration & Purpose of Processing

3.1. Duration: The processing of Customer Personal Data continues for the duration of the Principal Agreement until all customer data is purged.

3.2. Purpose: Quiver processes Customer Data solely to provide the services described in the Principal Agreement: generating grounded proposal drafts, storing verified team capability profiles, maintaining audit records, and managing follow-up outreach cadences.

4. Customer as Data Controller

The Customer warrants that it has established all necessary lawful bases, consent, or legitimate interests required under applicable Data Protection Laws to provide Personal Data (including client opportunity text and team capability profiles) to Quiver for processing.

5. Quiver as Data Processor Obligations

Quiver agrees and covenants that it shall:

  • Process Personal Data solely on documented instructions from the Customer, including regarding international data transfers.
  • Ensure that all personnel authorized to process Customer Data are bound by strict contractual confidentiality obligations.
  • Implement state-of-the-art Technical and Organizational Measures (TOMs) to ensure a level of security appropriate to the risk.
  • Never use Customer Personal Data to train public foundation models or commercially monetize customer datasets.

6. Sub-processors & Prior Authorization

6.1. General Authorization: Customer grants general authorization to Quiver to engage the sub-processors listed in our Sub-processors Directory.

6.2. Notice of Changes: Quiver will notify Customer of any intended appointment or replacement of a sub-processor at least thirty (30) days in advance via email or portal notifications, giving Customer the opportunity to object on legitimate data protection grounds.

7. Technical & Organizational Security Measures (TOMs)

Quiver maintains rigorous technical measures including AES-256-GCM encryption for stored API keys, TLS 1.3 transit encryption, PostgreSQL Row-Level Security (RLS) tenant isolation, automated audit logging, and vulnerability management.

8. Data Subject Rights Assistance

Taking into account the nature of the processing, Quiver will assist Controller by appropriate technical and organizational measures to fulfill Controller's obligations to respond to Data Subject requests under GDPR Chapter III (Access, Erasure, Portability, Rectification).

9. Security Incident Notification

Quiver will notify Customer without undue delay (and in any event within forty-eight (48) hours) of becoming aware of a confirmed Personal Data Breach affecting Customer Data. Quiver will provide detailed information regarding the nature of the incident, categories of data affected, and remedial actions taken.

10. International Transfers & Standard Contractual Clauses

To the extent that the provision of Services involves an international transfer of EEA, UK, or Swiss Personal Data to a third country not recognized as providing an adequate level of data protection, the parties agree that the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) are hereby incorporated by reference into this DPA.

11. Deletion & Return of Customer Data

Upon termination of the Principal Agreement, Quiver shall, at Controller's choice, delete or return all Customer Personal Data within thirty (30) days, unless applicable statutory law requires ongoing retention (e.g. fiscal or accounting records).

Annex 1: Details of Processing

  • Categories of Data Subjects: Customer employees, team members, contractors, and prospect/client contacts referenced in opportunity briefs.
  • Categories of Personal Data: Names, contact emails, professional biographies, CVs, portfolio links, project budgets, and communication drafts.
  • Sensitive Data: Quiver does not solicit or intentionally process special category data (health, racial, biometric, political).

Annex 2: Security Measures Overview

A comprehensive breakdown of Quiver technical architecture, cryptographic algorithms, and access controls is published in our Security Architecture Disclosure.