QReportly

QReportly

Sign in

GDPR Article 28

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service and governs processing of personal data by Qreportly LLC as processor on behalf of the Client as controller, for the internal reporting channel.

Last updated: 31 August 2026

01

Parties and roles

This DPA is concluded between the Client (the controller) and Qreportly LLC, a Wyoming limited liability company with registered office at 30 N Gould St Ste R, Sheridan, WY 82801, USA (the processor), for personal data processed in the internal reporting channel, including reports, follow-up messages, attachments, case metadata and related workspace records ("Channel Data").

For administrator accounts, billing, support and the Provider's own website, the Provider acts as controller as described in the Privacy Policy. Those controller activities are outside the scope of this DPA.

If the Client is itself a processor for another controller, the Client warrants that it is authorised to appoint the Provider as subprocessor.

02

Subject matter, nature, purpose and duration

Subject matter: provision of the QReportly software-as-a-service internal reporting channel.

Nature of processing: hosting, storage, transmission, display, search, export, backup and deletion of Channel Data as configured by the Client.

Purpose: to enable the Client to operate a confidential internal channel under Directive (EU) 2019/1937 and applicable national transposition law. The Provider does not determine the purposes of Channel Data processing and does not provide legal advice on individual reports.

Duration: the subscription term, plus any retention period configured by the Client, plus any limited period reasonably required to delete or return data after termination.

03

Data subjects

Channel Data may relate to persons who submit reports (whistleblowers), persons mentioned in reports, witnesses, designated persons and other Client staff who use the dashboard, and any other individuals whose data the Client or a reporter includes in Channel Data.

04

Categories of personal data

Channel Data may include identity and contact details (if provided), report narratives, categories of wrongdoing, case status, messages, file attachments and technical identifiers allocated by the Platform (such as a tracking code). The Provider does not require a reporter to create an account or to disclose their identity.

Channel Data may include special categories of data (Article 9 GDPR) or data relating to criminal offences (Article 10 GDPR) if a reporter or the Client includes them. The Provider does not request such data as a condition of using the channel. The Client as controller is responsible for the lawfulness of including such data.

05

Documented instructions

The Processor shall process Channel Data only on documented instructions from the Client, unless required to do so by Union or Member State law to which the Processor is subject. In that case the Processor shall inform the Client of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

Documented instructions include this DPA, the Terms of Service, the Privacy Policy, settings the Client configures in the Platform, and other written instructions that are lawful and consistent with the service.

The Processor shall immediately inform the Client if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions. The commercial subscription contract is not, by itself, the Article 6(1)(b) GDPR legal basis for processing data of whistleblowers or of persons mentioned in a report; the Client as controller determines the applicable Article 6, 9 and 10 bases.

06

Confidentiality

The Processor ensures that persons authorised to process Channel Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to perform the service, security, support or legal duties.

07

Security of processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks for data subjects, the Processor implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including encryption in transit (TLS), role-based access control, logical isolation of Client workspaces, backups of primary production data in EU-hosted infrastructure, with encryption at rest as provided by that hosting stack, security monitoring, and an incident-response process.

The Processor does not currently offer client-side end-to-end encryption of report bodies: authorised Client users with the relevant role can access case content in the dashboard. Buyer-facing architecture detail is published in the Security & Trust Center. No measure guarantees absolute security.

QReportly does not currently provide end-to-end encryption for the body of submitted reports.

08

Subprocessors

The Client provides a general written authorisation for the Processor to engage subprocessors to deliver the service.

The current list is published on the public Subprocessors page on this website. The Processor shall impose on each subprocessor data-protection obligations that are substantially equivalent to those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. The Processor remains responsible toward the Client for the subprocessor's performance of those obligations.

The Processor will notify the Client of intended additions or replacements of subprocessors — by updating the public list and, for material changes affecting Channel Data, by email or dashboard notice — in time for the Client to object before the new subprocessor processes Channel Data. If the Client objects on reasonable GDPR grounds and the parties cannot agree an alternative, the Client may terminate the affected services.

09

International transfers

Two transfer relationships must be distinguished and are not interchangeable.

Transfer A — Customer → Qreportly LLC: where the Customer (controller / data exporter) is subject to GDPR Chapter V in respect of a transfer to Qreportly LLC (processor / data importer, established in the United States), the parties rely on Module 2 of the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, completed by the International Data Transfer Addendum published on this website. Module 3 is not used for Transfer A.

Primary production database and object-storage workloads for Channel Data are intended to be hosted in the European Union. The live production region is not independently verified from the application repository. EU storage does not, by itself, remove Transfer A: Qreportly LLC is a US processor and may access Channel Data remotely for hosting operations, support, security and maintenance.

Transfer B — Qreportly LLC → subprocessors: where a subprocessor processes personal data in a third country without an adequacy decision, or where Chapter V otherwise requires a transfer tool, Qreportly LLC (processor / data exporter) uses Module 3 of Decision (EU) 2021/914 with that subprocessor (processor / data importer), to the extent required. Module 2 is not used for Transfer B. The current list, locations and data categories are on the Subprocessors page.

Channel Data, including report content and attachments, transits the application host (Vercel, Inc.) because the Next.js application handles report and case APIs. That host is not the primary store of report bodies. Transactional email (Brevo) receives operational notices that include tracking codes and organisation names as implemented; it does not receive report bodies in the current email templates. Billing (Stripe) and optional Google sign-in process account data, not report bodies.

Qreportly LLC does not claim participation in the EU-US Data Privacy Framework. A vendor’s certification is not QReportly’s certification.

In the event of a legally binding request from a public authority concerning Customer Data, QReportly will follow the obligations applicable under the relevant transfer mechanism and applicable law. To the extent legally permitted, QReportly will notify the Customer, limit disclosure to what is legally required, and assess available means to challenge or narrow the request.

If disclosure to the Customer is legally prohibited, QReportly will not disclose information that it is legally prohibited from disclosing.

10

Assistance to the controller

Taking into account the nature of processing and the information available to it, the Processor shall assist the Client in fulfilling the Client's obligation to respond to data-subject requests under Chapter III GDPR, by providing Platform features and, where those are insufficient, reasonable additional assistance.

The Processor shall assist the Client in ensuring compliance with Articles 32 to 36 GDPR (security, personal-data-breach notification, data-protection impact assessments and prior consultation), including notifying the Client without undue delay after becoming aware of a personal-data breach affecting Channel Data.

11

Deletion and return

During the subscription, the Client may export Channel Data using Platform features.

After the end of the processing services, the Processor shall, at the choice of the Client, delete Channel Data or return it to the Client and delete existing copies, unless Union or Member State law requires storage. Retention settings configured by the Client, legal obligations, and backup rotation cycles may delay complete deletion for a limited period.

12

Information and audits

The Processor shall make available to the Client all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Client or another auditor mandated by the Client.

Audits are subject to reasonable prior written notice (at least 30 days, except where a supervisory authority requires a shorter period), confidentiality undertakings, a limit of one audit per 12 months unless a confirmed personal-data breach or a supervisory-authority request justifies an additional audit, and a manner that does not disrupt the service or compromise the security of other clients.

The Processor may satisfy an audit request in whole or in part by providing written responses, relevant policies, and summaries of independent assessments if and when such assessments exist. The Processor does not claim ISO, SOC or similar certifications that it does not hold.

13

Precedence, liability and governing law

In the event of conflict, this DPA prevails over the Terms of Service solely with respect to processing of Channel Data as processor.

Liability remains as set out in the Terms of Service, without prejudice to mandatory rights of data subjects or of supervisory authorities under the GDPR.

This DPA is governed by the laws of the State of Wyoming, United States of America, and disputes are subject to the state and federal courts located in Sheridan County, Wyoming, except that mandatory provisions of the GDPR and of the law of the EU Member State where the Client is established or where data subjects are located continue to apply to the processing of personal data as required by those laws. Nothing in this DPA limits a data subject's rights under the GDPR.

Nothing in these Terms excludes or limits any liability, right or obligation that cannot lawfully be excluded or limited, including mandatory rights of data subjects and mandatory obligations applicable to personal data processing.

Nothing in these Terms limits the powers of a supervisory authority or rights of data subjects under applicable law.

Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For this DPA, processor instructions, and data-protection requests: