GDPR & Data Protection
Privacy Policy
This document describes how QReportly processes personal data in connection with Platform service delivery, in compliance with Regulation (EU) 2016/679 (GDPR) and applicable national law.
Last updated: 31 August 2026
01
Introduction and Scope
Qreportly LLC ("QReportly", the "Platform", or the "Provider"), a limited liability company registered in the State of Wyoming, United States, with registered office at 30 N Gould St Ste R, Sheridan, WY 82801, USA, assigns fundamental importance to the protection of personal data and the confidentiality of individuals using its services. GDPR applies to processing of personal data of individuals in the EEA in accordance with Article 3 GDPR.
This Privacy Policy applies to: (i) processing carried out by the Provider as Data Controller for its own activities (administrator accounts, billing, support); and (ii) processing carried out by the Provider as Data Processor on behalf of Clients, for data included in reports and internal reporting channel operations.
For the public reporting channel accessible to reporters, the Provider applies advanced technical and organizational data minimization measures, as detailed in the dedicated sections below.
Qreportly LLC has not appointed an EU representative under Article 27 GDPR as of the last-updated date of this Policy. No representative name, company, address or email is published because none is verified. An Article 27 representative is not an EU subsidiary. Whether Article 27 applies is a matter for legal review and is not concluded here.
02
Data Processing Roles (GDPR)
With respect to personal data contained in reports submitted through the internal channel, case records, messages, attached files, and operational metadata related to case management, the Client — the Enrolled Legal Entity — acts as Data Controller.
QReportly acts strictly as Data Processor (technical provider), processing data exclusively on documented instructions from the Client, for provision of contracted services, and within the limits of this Policy and the Terms of Service.
For administrator account data, billing data, and commercial communications, the Provider acts as an independent Data Controller and must provide data subjects with the information required by GDPR.
Controller-Processor Relationship
The Provider does not use report content for its own marketing, profiling, or commercial analytics purposes. Provider personnel access to Client data is strictly limited to authorized staff for maintenance, technical support, security, and legal compliance, and is subject to confidentiality obligations.
The Client is responsible for lawfulness of processing, data subject information duties, handling rights requests relating to reports, and notifying supervisory authorities where required.
03
Categories of Processed Data
Depending on how the Platform is used, the following categories of data may be processed:
- Identification data of Client administrators: name, email address, phone number (if provided), role, language preferences;
- Service communications and, occasionally, short follow-up messages after a trial or after a subscription ends, sent to the account email;
- Organizational data: workspace name, country of registration, compliance settings, pricing plan;
- Billing and payment data: processed primarily by Stripe; the Provider may store transaction references, but not full card details;
- Report content: text, categories, attached files, messages from secure chat, procedural statuses, timestamps;
- Limited technical data for administration sessions: security logs, session identifiers, authentication events;
- Data voluntarily provided by reporters: name, contact details, or other elements, only when the reporter chooses identified reporting.
04
Identity-minimising architecture (anonymous reporting)
The Platform is structurally designed not to collect, log, or store IP addresses, geolocation data, or digital fingerprints (browser fingerprinting) of whistleblowers accessing the public reporting channel.
This minimization architecture is intended to reduce the risk of re-identification of reporters who choose anonymous reporting and to support the Client in meeting legal confidentiality obligations.
The Provider does not use behavioral tracking technologies, advertising profiling, or invasive analytics within the reporting flow intended for reporters. Any analytics applied on the public presentation site is technically separated from the secure reporting channel.
QReportly does not persist reporter IP addresses in the application database. Public reporter endpoints apply an in-memory rate limit that hashes the client IP for the duration of the window. Infrastructure providers that deliver the application (including the application host) may still observe network-level IP addresses and request metadata. The Platform does not treat continued browsing as analytics consent.
Identified Reporting
If a reporter explicitly opts for identified reporting, voluntarily provided data is accessible to the Client's Designated Person and protected through technical encryption and access control measures. The Client remains the responsible Controller for such data processing.
05
Metadata, Attachments, and Sanitization
All files attached to reports (PDF documents, DOCX documents, PNG/JPG/JPEG images) are subject, at upload, to an automatic cryptographic metadata sanitization process, including but not limited to EXIF image data, document author information, embedded properties, edit timestamps, and other elements that could facilitate inadvertent re-identification.
The sanitization process takes place before final storage of files in the Platform infrastructure. The Client is responsible for assessing whether information remaining in visible document content is appropriate for the investigation purpose.
Files that cannot be processed safely or exceed established technical limits may be automatically rejected without retention of original content.
06
Data Retention and Automatic Purging
The Provider applies strict retention and automatic deletion policies designed to limit data exposure beyond periods necessary for service provision and legal compliance.
Media Files and Evidentiary Documents
Media files and documents uploaded as evidence in reports are permanently and irreversibly deleted from servers 6 months (180 calendar days) after the case is marked as "Closed" in the Platform. Purging is executed automatically through scheduled procedures, without manual intervention.
Textual History and Register
Textual history of secure chat, procedural records, and data associated with the electronic report register are retained for the standard legal period configured in the Client workspace: 5 (five) years as the default duration, and 3 (three) years for jurisdictions requiring that term — such as Germany — after which they are automatically removed through a Hard Delete procedure (irreversible physical deletion from active production systems).
The Client may configure retention periods within limits permitted by law applicable to its organization. The Provider does not guarantee retention beyond configured periods or beyond contractual termination, except where mandatory legal obligations apply to the Provider.
07
Legal Bases for Processing
As Processor for report content, case records, messages and attachments, the Provider processes personal data on documented instructions of the Client as Controller, under Article 28 GDPR and the data-processing terms in this Policy and the Terms of Service. The Client, as Controller, determines the applicable Article 6 GDPR legal basis (and, where relevant, Articles 9 and 10 GDPR), the purposes, retention, and how data-subject rights are handled for report data. The commercial subscription contract is not, by itself, the Article 6(1)(b) legal basis for processing the personal data of whistleblowers or of persons mentioned in a report.
As Controller for administration accounts, billing and the Provider's own commercial communications, legal bases include contract performance (Article 6(1)(b) GDPR), legitimate interest in Platform security and fraud prevention (Article 6(1)(f) GDPR), legal accounting and tax obligations (Article 6(1)(c) GDPR), and consent where explicitly requested (for example, marketing communications, if enabled).
An administrator’s phone number, if provided, is processed solely for operational communications about the account, organisation, billing and support (Article 6(1)(b) GDPR — contract performance). It is not used for marketing campaigns or promotional messages.
Communications with the Client
During the relationship, we may email the account for service matters: confirmations, the trial period, billing, security, or important Platform changes. These messages form part of the contract, not advertising.
We may send communications strictly related to the service. Where permitted by applicable law, we may also send commercial follow-up messages (for example after a trial ends) under the conditions of that law, with a clear way to object or opt out. Messages required for the account, payment or security may still be sent. We do not sell data to third parties for advertising.
You may object to these follow-up messages at any time by writing to the contact address at the end of this document or by using the instructions in the email, where provided. Messages required for the account, payment or security may still be sent.
08
Data Subject Rights
Data subjects benefit from rights provided by GDPR: access, rectification, erasure, restriction, portability, objection, and the right not to be subject to decisions based solely on automated processing, under applicable legal conditions.
For data contained in reports, rights requests should be addressed primarily to the Client as Data Controller. The Provider will assist the Client, to a reasonable extent and in accordance with contract, in handling such requests.
For data processed by the Provider as Controller (administrator accounts, billing), requests may be submitted using the contact details at the end of this document. The Provider will respond within GDPR timelines.
Data subjects have the right to lodge a complaint with the competent supervisory authority in the Member State of their habitual residence, place of work, or place of the alleged infringement.
09
Security Measures
The Provider implements appropriate technical and organizational measures to protect data, including encryption in transit (TLS), role-based access controls, logical isolation between workspaces, security monitoring, incident response procedures, and backups in EU-hosted infrastructure, with encryption at rest as provided by that hosting stack.
No system can guarantee absolute security. In the event of a security incident affecting Client data, the Provider will notify the Client without undue delay, in accordance with applicable contractual and legal obligations.
QReportly uses technical and organisational measures designed to reduce security risks. Connections are protected using TLS. Tenant environments are logically isolated. QReportly does not currently provide end-to-end encryption for the body of submitted reports. Encryption at rest is that of the EU hosting stack; QReportly does not claim a separate per-tenant AES key or ISO/SOC certification.
10
International transfers
Two transfer relationships must be distinguished and are not interchangeable.
Transfer A — Customer → Qreportly LLC: where the Customer (controller / data exporter) is subject to GDPR Chapter V in respect of a transfer to Qreportly LLC (processor / data importer, established in the United States), the parties rely on Module 2 of the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, completed by the International Data Transfer Addendum published on this website. Module 3 is not used for Transfer A.
Primary production database and object-storage workloads for Channel Data are intended to be hosted in the European Union. The live production region is not independently verified from the application repository. EU storage does not, by itself, remove Transfer A: Qreportly LLC is a US processor and may access Channel Data remotely for hosting operations, support, security and maintenance.
Transfer B — Qreportly LLC → subprocessors: where a subprocessor processes personal data in a third country without an adequacy decision, or where Chapter V otherwise requires a transfer tool, Qreportly LLC (processor / data exporter) uses Module 3 of Decision (EU) 2021/914 with that subprocessor (processor / data importer), to the extent required. Module 2 is not used for Transfer B. The current list, locations and data categories are on the Subprocessors page.
Channel Data, including report content and attachments, transits the application host (Vercel, Inc.) because the Next.js application handles report and case APIs. That host is not the primary store of report bodies. Transactional email (Brevo) receives operational notices that include tracking codes and organisation names as implemented; it does not receive report bodies in the current email templates. Billing (Stripe) and optional Google sign-in process account data, not report bodies.
Qreportly LLC does not claim participation in the EU-US Data Privacy Framework. A vendor’s certification is not QReportly’s certification.
In the event of a legally binding request from a public authority concerning Customer Data, QReportly will follow the obligations applicable under the relevant transfer mechanism and applicable law. To the extent legally permitted, QReportly will notify the Customer, limit disclosure to what is legally required, and assess available means to challenge or narrow the request.
If disclosure to the Customer is legally prohibited, QReportly will not disclose information that it is legally prohibited from disclosing.
11
Policy Changes
The Provider may update this Policy to reflect legal, technical, or operational developments. The current version is published on the Platform with the update date.
In case of material changes, the Client will be informed through reasonable channels (dashboard notification or email). Continued use of services after entry into force constitutes acceptance of the updates, to the extent permitted by law.
Data Protection Contact
Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For requests regarding data processing, exercise of rights, or GDPR clarifications, please contact: