Sub-processors Directory
Official list of third-party service providers authorized to process data on behalf of Quiver Technologies Inc. in compliance with GDPR Article 28.
1. Overview & Commitments
In accordance with the Quiver Data Processing Addendum and European General Data Protection Regulation (GDPR) Article 28, this Sub-processors Directory provides full transparency regarding all third-party vendors engaged by Quiver Technologies Inc.
All sub-processors are bound by strict contractual data protection agreements ensuring data security, confidentiality, and zero-training commitments.
2. Current Sub-processors Registry
| Sub-processor | Category & Purpose | Processing Location | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|
| Supabase Inc.Database & Authentication | Managed PostgreSQL database, Row Level Security, user authentication, and capability profile storage. | United States / EU | User identity, encrypted credentials, CV data, opportunity briefs. | Data Processing Agreement & Standard Contractual Clauses (SCCs) |
| Stripe, Inc.Payment Processing & Invoicing | Processing credit card transactions, managing subscriptions, and generating tax invoices. | United States / Global | Customer billing details, payment tokens, tax identifiers, billing contact info. | Stripe DPA & Standard Contractual Clauses (SCCs) |
| Anthropic PBCAI Inference (Claude 3.5 & Sonnet 5) | Executing proposal draft completions and evaluation quality checks via enterprise API. | United States | Ephemeral prompt text and capability context (Zero data retention agreement). | Enterprise API Zero-Training Agreement & SCCs |
| OpenAI LLCAI Inference (GPT-4o & o3-mini) | Executing proposal draft completions and evaluation quality checks via enterprise API. | United States | Ephemeral prompt text and capability context (Zero data retention agreement). | Enterprise API Zero-Training Agreement & SCCs |
| OpenRouter (Router Inc.)AI Inference Routing | Unified routing to multi-engine open-source and proprietary models. | United States | Ephemeral prompt text (Zero data retention agreement). | Enterprise API Zero-Training Agreement & SCCs |
| Vercel Inc.Edge Hosting & Application Delivery | Web application hosting, edge middleware routing, and content delivery network (CDN). | Global Edge / United States | Encrypted HTTP traffic, IP addresses for security rate-limiting. | Vercel DPA & Standard Contractual Clauses (SCCs) |
3. Sub-processor Vetting & Security Due Diligence
Prior to onboarding any sub-processor, Quiver performs comprehensive technical and legal reviews:
- Security Audits: Verification of SOC 2 Type II, ISO 27001, or equivalent third-party certifications.
- Data Protection Agreements: Mandatory execution of Article 28 DPAs with Standard Contractual Clauses (SCCs).
- Zero Model Training: Explicit contractual guarantee that customer prompts are never used to train public or proprietary foundation models.
4. Notice of Changes & Customer Objection Rights
Quiver will provide at least thirty (30) days prior notice before appointing any new sub-processor by updating this page and sending an email notice to subscribed organization administrators. Customers may object to any new sub-processor on reasonable data protection grounds by contacting privacy@quiver.app.
5. Inquiries & Sub-processor Notifications
To subscribe to sub-processor change notifications or submit an inquiry, please contact:
Quiver Privacy & Vendor Management
Email: privacy@quiver.app
Subject: Sub-processor Inquiries