QReportly

QReportly

Sign in

Article 28 GDPR

Subprocessors

Qreportly LLC publishes the subprocessors engaged to operate the Platform. This list supplements the Data Processing Agreement. Marketing tools on the public website that do not process Channel Data are described in the Cookie Policy and are not subprocessors of the reporting channel.

Last updated: 31 August 2026

01

Scope

A subprocessor is a third party engaged by Qreportly LLC, as processor, to process personal data on behalf of the Client in connection with the Platform.

The Client provides general written authorisation for these subprocessors under the Data Processing Agreement. Report content is stored in the European Union. Ancillary providers may process limited account or operational data outside the EEA under GDPR Chapter V safeguards.

Transfer A (Customer → Qreportly LLC) uses SCC Module 2 where Chapter V applies, as described in the International Data Transfer Addendum. Transfer B (Qreportly LLC → a subprocessor) uses SCC Module 3 where a restricted transfer applies. Qreportly LLC does not claim EU-US DPF participation.

02

Current list

The following subprocessors are engaged as of the last-updated date of this page. Roles and data categories are described at the level of detail needed for a controller review, without publishing attack-relevant internals.

ProviderRolePersonal dataLocationTransfer safeguard
Supabase (EU hosting intended; production region not independently verified)Production database and object storageChannel Data: reports, attachments, workspace recordsIntended European Union — production region not independently verifiedNot a restricted transfer only if production hosting is verified in the EU/EEA; production region not independently verified
Vercel, Inc.Application hosting and edge deliveryChannel Data in transit (report content, attachments, case APIs) plus request metadata. Not the primary store of report bodies.United States and global edge locationsSCC Module 3 / GDPR Chapter V, where a restricted transfer applies
Stripe, Inc.Subscription billingClient account, billing and payment data — not report bodiesUnited StatesStandard Contractual Clauses / GDPR Chapter V
Brevo (Sendinblue)Transactional emailOperational and notification emails (account and case notices as configured)France / European UnionNot a restricted transfer (EU provider)
Google LLCOptional Google sign-in (OAuth), if enabled by the ClientAccount identifiers of administrators who choose Google authenticationUnited StatesStandard Contractual Clauses / GDPR Chapter V

03

What is not on this list

The public marketing website may use analytics or advertising tools (for example Google Analytics or Meta Pixel) that are technically separated from the secure reporting channel and do not process Channel Data. Those tools, if used, are described in the Cookie Policy.

04

Changes

This list will be kept up to date. Material additions or replacements of subprocessors that will process Channel Data will be published here and notified to Clients by email or dashboard notice before the new subprocessor starts processing, so that the Client may object as described in the Data Processing Agreement.

Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For this DPA, processor instructions, and data-protection requests: