QReportly

QReportly

Sign in

GDPR Chapter V

International Data Transfer Addendum

This Addendum identifies the parties, roles, transfers and annex information for Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses. It does not replace or rewrite the official SCC text.

Last updated: 31 August 2026

01

Official SCC — not recreated

Where a restricted transfer of personal data from the EEA (or from a jurisdiction that requires an equivalent instrument) is subject to Article 46 GDPR, the parties rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, including the official modules and annexes, as published by the European Commission.

Qreportly LLC does not publish a homemade substitute for the Commission SCC. This Addendum completes the information that the SCC annexes require (parties, roles, description of transfer, technical and organisational measures). The official SCC text remains the contractual legal instrument.

The current Commission decision and SCC text are available on EUR-Lex under Commission Implementing Decision (EU) 2021/914. Nothing in this Addendum silently alters that text.

02

Parties, exporter and importer

Data exporter (Transfer A): the Customer identified in the applicable commercial agreement (Terms of Service and, where applicable, an order form). Role: controller / data exporter.

Data importer (Transfer A): Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States. Role: processor / data importer.

For Transfer B, Qreportly LLC acts as processor / data exporter toward the subprocessor listed on the public Subprocessors page, which acts as processor / data importer. Module 2 is not used for Transfer B. Module 3 is not used for Transfer A.

03

Transfer A — Customer → Qreportly LLC (Module 2)

Where the Customer is established in the EEA (or otherwise restricted from transferring personal data to the United States without a Chapter V mechanism) and Qreportly LLC processes Channel Data as processor, the applicable SCC module is Module 2 (controller to processor), to the extent required by GDPR Chapter V.

This transfer exists because Qreportly LLC is established in the United States and processes Channel Data on documented instructions, including where primary storage is hosted in the European Union and Qreportly LLC may access that data remotely for hosting operations, support, security or maintenance. EU hosting of the database does not, by itself, remove the Customer → US processor relationship.

This Addendum describes the architecture as implemented. It is not a substitute for the Customer's own transfer impact assessment.

04

Transfer B — Qreportly LLC → subprocessors (Module 3)

Where Qreportly LLC engages a subprocessor that processes personal data in a third country without an adequacy decision, or where Chapter V otherwise requires a transfer tool, the applicable module between Qreportly LLC and that subprocessor is Module 3 (processor to processor), to the extent required.

Verified application hosting: Vercel, Inc. delivers the Next.js application. Report submission and case APIs therefore transmit Channel Data, including report content and attachments in transit, through that hosting layer. Vercel is not the primary store of report bodies; those are stored in the EU-hosted database and object storage. The Subprocessors page states this data flow explicitly.

Qreportly LLC does not claim participation in the EU-US Data Privacy Framework. A vendor’s DPF certification, if any, is that vendor’s status and is not QReportly’s certification. Transfer tools for subprocessors are described on the Subprocessors page as Standard Contractual Clauses / GDPR Chapter V where a restricted transfer applies, or as not a restricted transfer where the provider and processing are in the EU/EEA as verified.

05

Description of the transfer

The transfer concerns personal data processed by QReportly on behalf of the Customer for operation of the internal reporting platform (Channel Data), and, separately, limited account, billing or operational data processed to provide the SaaS.

Frequency: continuous / as required to provide the service, including on each report submission, message, attachment upload, dashboard access, backup cycle operated by the EU hosting stack, and support event.

Nature: hosting, storage, transmission, display, search, export, backup and deletion as configured by the Customer.

06

Categories of data subjects

Channel Data may relate to reporters / whistleblowers; persons mentioned in reports; witnesses; case managers; authorised users; administrators; employees; contractors; and other persons whose personal data is legitimately included in reports or workspace records.

07

Categories of personal data

The following may be processed depending on the content submitted to the Platform and on how the Customer configures the workspace. QReportly does not actively require every listed category as a condition of using the channel:

Names; contact details; professional role; user identifiers; case identifiers; report content; communications; attachments; timestamps; case status; technical information required to operate the service.

Special-category data under Article 9 GDPR and data relating to criminal convictions and offences under Article 10 GDPR may be processed where legitimately included in a report or by the Customer. The Customer as controller is responsible for the lawfulness of including such data. QReportly does not request Article 9 or Article 10 data as a condition of submitting a report.

08

Purposes

Purposes technically supported by the implementation: platform provision; hosting; storage; processing; backup; security; maintenance; support; notifications; account administration; technical operations; billing of the Customer subscription (billing data, not report bodies).

QReportly does not use Channel Data for QReportly’s own marketing or advertising. Optional analytics or advertising tools, if configured, apply only to public marketing pages after consent and are not subprocessors of Channel Data.

09

Duration

Duration follows the subscription term, plus retention periods configured by the Customer in the Platform, plus any limited period reasonably required to delete or return data after termination, plus backup rotation of the EU hosting stack.

Default Channel Data retention for closed cases is configured per workspace (platform default five years, with a three-year default for jurisdictions such as Germany where that term is configured). Attachments are scheduled for purge 180 days after a case is marked closed. These are product defaults and Customer-configurable periods, not invented statutory guarantees. The Provider does not invent a single fixed retention period for all Customers.

10

Subprocessors and technical measures

Subprocessors are listed on the public Subprocessors page, which forms part of this Addendum by reference. Material changes affecting Channel Data are notified as described in the Data Processing Agreement.

Technical and organisational measures include TLS in transit; organisation-scoped access control and logical isolation of Client workspaces; bcrypt password hashes for accounts; encrypted TOTP secrets where MFA is enabled; backups of primary production data in EU-hosted infrastructure, with encryption at rest as provided by that hosting stack; sanitisation of certain attachment metadata on upload; and an incident-response process as described in the DPA.

QReportly does not currently provide end-to-end encryption for the body of submitted reports. Authorised Client users with the relevant role can access case content in the dashboard. Tenant environments are logically isolated. QReportly does not claim ISO 27001, SOC 2, PCI DSS, HIPAA, FedRAMP or EU-US DPF certification of Qreportly LLC.

11

Supplementary measures

Supplementary measures currently implemented include: primary production database and object storage intended to be in the European Union. The live production region is not independently verified from the application repository; no application-database persistence of reporter IP addresses; hashing of client IPs in memory for rate limiting on public reporter endpoints; exclusion of advertising/analytics scripts from reporting-channel routes; access limited to personnel who need it for the service, security, support or legal duties; and contractual confidentiality obligations.

Infrastructure providers may still process request metadata, including network-level IP addresses and, for the application host, request payloads in transit. That fact is disclosed on the Subprocessors page and is not described as “metadata only” where report content transits the host.

12

Public-authority requests

In the event of a legally binding request from a public authority concerning Customer Data, QReportly will follow the obligations applicable under the relevant transfer mechanism and applicable law. To the extent legally permitted, QReportly will notify the Customer, limit disclosure to what is legally required, and assess available means to challenge or narrow the request.

If disclosure to the Customer is legally prohibited, QReportly will not disclose information that it is legally prohibited from disclosing.

This Addendum does not state that US authorities cannot access data, that QReportly is not subject to the CLOUD Act, that FISA does not apply, or that government access is impossible. Those questions require jurisdiction-specific legal review.

13

Article 27 and EU-US Data Privacy Framework

Qreportly LLC has not appointed an EU representative under Article 27 GDPR as of the last-updated date of this Addendum. No representative name, address or email is published because none is verified in the project data. Whether Article 27 applies, and whether an exemption applies, is a matter for legal review and is not concluded in this Addendum. An Article 27 representative is not an EU subsidiary.

Qreportly LLC does not claim participation in the EU-US Data Privacy Framework. No DPF certification number is published. A subprocessor’s DPF status, if any, is not QReportly’s DPF status.

14

Relationship with the DPA, precedence and execution

This Addendum forms part of the Data Processing Agreement and the Terms of Service for processor activities. In the event of conflict regarding international transfers of Channel Data, the official SCC (Decision 2021/914) prevail over this Addendum as to the SCC text; this Addendum prevails over the DPA and Terms solely as to the annex information and module allocation described here; the DPA prevails over the Terms solely as to processor obligations for Channel Data.

By accepting the Terms of Service and the DPA, the Customer agrees to this Addendum. Whether click-wrap execution of the SCC is sufficient in a given Member State is a matter for legal review.

Nothing in this Addendum limits the powers of a supervisory authority or the rights of data subjects under applicable law. Mandatory provisions of the GDPR continue to apply.

Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For this Addendum, SCC annex information and processor instructions: