Article 28 GDPR
Subprocessors
Qreportly LLC publishes the subprocessors engaged to operate the Platform. This list supplements the Data Processing Agreement. Marketing tools on the public website that do not process Channel Data are described in the Cookie Policy and are not subprocessors of the reporting channel.
Last updated: 31 August 2026
01
Scope
A subprocessor is a third party engaged by Qreportly LLC, as processor, to process personal data on behalf of the Client in connection with the Platform.
The Client provides general written authorisation for these subprocessors under the Data Processing Agreement. Report content is stored in the European Union. Ancillary providers may process limited account or operational data outside the EEA under GDPR Chapter V safeguards.
Transfer A (Customer → Qreportly LLC) uses SCC Module 2 where Chapter V applies, as described in the International Data Transfer Addendum. Transfer B (Qreportly LLC → a subprocessor) uses SCC Module 3 where a restricted transfer applies. Qreportly LLC does not claim EU-US DPF participation.
02
Current list
The following subprocessors are engaged as of the last-updated date of this page. Roles and data categories are described at the level of detail needed for a controller review, without publishing attack-relevant internals.
| Provider | Role | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase (EU hosting intended; production region not independently verified) | Production database and object storage | Channel Data: reports, attachments, workspace records | Intended European Union — production region not independently verified | Not a restricted transfer only if production hosting is verified in the EU/EEA; production region not independently verified |
| Vercel, Inc. | Application hosting and edge delivery | Channel Data in transit (report content, attachments, case APIs) plus request metadata. Not the primary store of report bodies. | United States and global edge locations | SCC Module 3 / GDPR Chapter V, where a restricted transfer applies |
| Stripe, Inc. | Subscription billing | Client account, billing and payment data — not report bodies | United States | Standard Contractual Clauses / GDPR Chapter V |
| Brevo (Sendinblue) | Transactional email | Operational and notification emails (account and case notices as configured) | France / European Union | Not a restricted transfer (EU provider) |
| Google LLC | Optional Google sign-in (OAuth), if enabled by the Client | Account identifiers of administrators who choose Google authentication | United States | Standard Contractual Clauses / GDPR Chapter V |
03
What is not on this list
The public marketing website may use analytics or advertising tools (for example Google Analytics or Meta Pixel) that are technically separated from the secure reporting channel and do not process Channel Data. Those tools, if used, are described in the Cookie Policy.
04
Changes
This list will be kept up to date. Material additions or replacements of subprocessors that will process Channel Data will be published here and notified to Clients by email or dashboard notice before the new subprocessor starts processing, so that the Client may object as described in the Data Processing Agreement.
Data protection contact
Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For this DPA, processor instructions, and data-protection requests: