Security and data protection: what CloudReport stores — and what it does not solve
CloudReport never stores file content. The service reads what has changed in your existing Dropbox, Google Drive and OneDrive accounts and emails links to the files where they already sit. The source provider remains both the source of truth and the data controller. What CloudReport does store is metadata: which accounts are monitored, file names and paths, change events, OAuth tokens and recipient email addresses.
This page is written so that a data protection officer can assess CloudReport without calling us first. It therefore also contains the three points where the argument does not hold. They surface in every serious security review anyway.
Exactly which data does CloudReport process?
The processing scope is deliberately narrow and can be listed exhaustively. There is no analytics layer and no document index, because there is no customer content to index.
| Data | Stored? | Why |
|---|---|---|
| File content | No | Never required. The digest contains links, not documents. |
| File name and path | Yes | Required to show what changed and where it sits. |
| Change event and timestamp | Yes | Required to diff against the last observed state of the account. |
| OAuth token for the connected account | Yes | Required to read changes without a person logging in each morning. |
| Recipient email addresses | Yes | Required for delivery and unsubscribe. |
| Document copies, previews, thumbnails | No | Never generated. |
File names are personal data. A file name on its own can disclose sensitive information — Termination_Anna_Svensson_2026.pdf is the example that keeps appearing in reviews. CloudReport stores file names and sends them in clear text in the digest email. That is a real disclosure surface under the GDPR, not a technicality, and public-sector buyers in Sweden and the wider EU should assess it explicitly rather than assume it away.
What does storing no file content actually buy you?
Three concrete things, and nothing beyond them.
- No second copy. There is no duplicate of your documents on our side that can leak, be misconfigured, or need separate deletion under a retention decision.
- No new source of truth. Versioning, permissions and retention stay where they are already governed — in Dropbox, Google Drive or Microsoft 365. CloudReport cannot drift out of sync because it holds no copy that could drift.
- A smaller blast radius. A breach at CloudReport exposes metadata and tokens. That is serious, but it is not an archive of your drawings, contracts and tender documents.
Can CloudReport read our files even if it does not store them?
Yes, technically it can, and that distinction matters. Storing no file content is not the same thing as being unable to read files. CloudReport holds OAuth tokens with read access to each connected Dropbox, Google Drive and OneDrive account. Technical capability and actual processing are two different questions, and a competent reviewer will separate them rather than accept a blanket assurance.
The honest mitigation is architectural, not contractual. Grant CloudReport the minimum OAuth scopes the provider offers, and point it at specific folders rather than whole accounts. A connection scoped to one project folder in OneDrive via Microsoft Graph gives read visibility of that folder and nothing else — a limit a reviewer can verify in the provider's own admin console.
Does this solve Schrems II and third-country transfers?
No, and we will not claim that it does. Under the EDPB's Guidelines 05/2021, mere storage in a third country — or access from one — already constitutes a transfer under Chapter V of the GDPR. If your files are in Dropbox, Google Drive or Microsoft 365, that transfer exists today, and it does not shrink because CloudReport declines to store file content. Any vendor telling a European buyer that a metadata-only architecture resolves Schrems II is selling a story that will not survive a procurement review.
What is true is narrower, and defensible: CloudReport adds no additional copy, no additional processor and no additional jurisdiction to an assessment you have already carried out. If you have documented a transfer assessment for your Microsoft 365 or Google Workspace tenancy, adding CloudReport does not require you to reopen it for the files themselves. That argument holds regardless of what happens to the EU–US Data Privacy Framework, which at the time of writing still stands but is under appeal to the Court of Justice of the European Union (case C-703/25 P) and was challenged again following the US Supreme Court's decision in Trump v. Slaughter in June 2026. It has not been annulled.
Are we in scope for NIS2?
If you are a construction firm or a haulier, almost certainly not directly. This differs sharply from what many vendors imply.
- Construction is not in scope. Construction activity appears in neither Annex I nor Annex II of the NIS2 Directive. No size threshold turns a pure construction company into an in-scope entity in Sweden or elsewhere in the EU.
- Most road logistics is not in scope either. The transport section of Annex I captures licensed operators and infrastructure — airports, rail undertakings, ports, ISM-certified shipping. Hauliers, freight forwarders and third-party logistics providers are simply not listed. Postal and courier services are Annex II, which is a genuinely different case.
- The requirements reach you anyway, through the supply chain. NIS2's supply-chain security obligations mean that municipalities, regions and utilities that are in scope must impose security requirements on their suppliers — as contract clauses, security annexes and audit rights in procurement documents.
So the useful question for a construction or logistics business in 2026 is not "must we comply with NIS2". It is "can we answer our customer's security annex". CloudReport helps there by being easy to describe accurately: one read-only integration, no additional document store, and a bounded list of processed data.
Where is the data processed, and by whom?
| Component | Provider | Location |
|---|---|---|
| Application and database | Microsoft Azure | West Europe (Netherlands) |
| Email delivery | Azure Communication Services Email | EU — set by the resource's data location |
| The files themselves | Your own Dropbox, Google Drive or OneDrive | Unchanged — CloudReport does not move them |
CloudReport introduces no new storage location for your documents, so the only processing geography it adds at all is the email path — and that runs inside Microsoft Azure alongside the application itself.
Frequently asked questions from security reviews
What happens if we cancel the service?
You revoke the OAuth grant at Dropbox, Google or Microsoft, and the metadata is deleted. Your files are untouched, because they were never moved. There is no export exercise and nothing to migrate.
Do recipients need their own accounts?
No. The digest goes to email, and recipients need no CloudReport account and no licence — unlike project platforms such as Dalux, iBinder and Interaxo, which are priced per user. A recipient who clicks a link still needs permission in the source provider to open the file. CloudReport grants no access the recipient does not already have.
Will we get a data processing agreement?
Yes. CloudReport is a processor for the metadata described above, and Archon Solutions AB is the contracting entity. You remain the controller, and Dropbox, Google and Microsoft retain their existing role for the files themselves.
How do administrators authenticate?
Administrators sign in with Microsoft Entra ID, so account lifecycle, conditional access and MFA policy stay in your existing identity platform. Each monitored storage account is connected separately over OAuth. The service is multi-tenant, and tenant data is separated at the application and database layer.
Answering a security annex?
Everything on this page is written to be pasted into a procurement response. If you need something that is not here, tell us and we will add it to the page rather than send a private email.