Skip to main content

Microsoft WOPI and Q-Hub

Updated 2 August 2026 · 5 min read

Q-Hub now lets you create and edit Word, Excel and PowerPoint files without leaving the platform. Your documents continue to live in Q-Hub's UK storage, that remains the only permanent home for them. When someone opens a file to edit, Microsoft's Office for the web service requests a temporary copy from Q-Hub, the person edits it in the browser, and the saved result is written straight back into Q-Hub.

1. What the feature does

From Doc Hub, users can create a new Word, Excel or PowerPoint file, or open an existing one, and edit it in the familiar Microsoft interface in their browser. Several people can work on the same file at once. Files created or edited this way behave like any other Q-Hub document — they carry version history and go through the normal review and approval (up-issue) process.

This uses WOPI (Web Application Open Platform Interface), the standard protocol Microsoft publishes for cloud storage providers who want Office for the web to open files held in their service. Q-Hub is an approved member of the Microsoft 365 Cloud Storage Partner Program, which is what makes the integration possible.

2. The important point about where files live

Microsoft's own programme rules require that a partner like Q-Hub stores all end-user files at rest in storage the partner owns or leases. Office for the web does not become a second copy of your document library, and your files are not moved into Microsoft's storage.

Your documents remain in Q-Hub's UK storage, encrypted at rest, exactly as they were before this feature existed. Microsoft receives a copy of a file's contents only for the duration of an editing or viewing session, in order to render it in the browser and hand back the changes.

3. What happens when someone edits a document

  1. A user clicks to edit a document in Q-Hub. Q-Hub checks they are allowed to open that file.

  2. Q-Hub issues a short-lived access token, valid for that one person and that one file, and opens the Microsoft Office for the web editor.

  3. Office for the web calls back to Q-Hub using that token and requests the file contents.

  4. The user edits the document in their browser. Changes are saved back to Q-Hub over the same protocol.

  5. The token expires, and the document in Q-Hub is the current version.

All traffic between your browser, Q-Hub and Microsoft is encrypted in transit. Q-Hub verifies cryptographically that incoming requests genuinely originate from Microsoft's service and not from somewhere else.

4. What Microsoft receives

Microsoft needs the content of your document in order to edit it. The content of the documents are transmitted to and processed by Microsoft's Office for the web service during the session. That is how a browser-based Office editor works, the rendering and editing happen on Microsoft's side, not inside Q-Hub.

What Microsoft receives:

  • The contents of the specific file being opened, and the changes made to it.

  • Basic file information such as name, size and version.

  • The identity of the signed-in Microsoft 365 user, where one is used for editing.

Microsoft's service caches file content to improve performance when a document is reopened. This behaviour is documented by Microsoft as part of the protocol. Microsoft's handling of that data is governed by Microsoft's own terms and privacy commitments, which sit alongside our agreement with them as a sub-processor.

What Microsoft does not receive: your wider Q-Hub content. There is no access to your other documents, form entries, audits, registers, user list or any other platform data. The integration is scoped to one file at a time.

5. Where processing takes place

Stage

Handled by

Location

Document storage at rest (the permanent copy)

Q-Hub, on AWS

UK — London

Access control and token issuing

Q-Hub

UK — London

Viewing and editing session

Microsoft Office for the web

Worldwide

(No regional commitment)

The Microsoft WOPI service is listed on our Sub-Processor List, which is the authoritative record and is kept current. To be notified of changes to sub-processors, email support@q-hub.co.uk.

6. Version control and audit trail stay with Q-Hub

Everything that makes a document controlled rather than merely stored continues to be managed by Q-Hub, not by Microsoft:

  • Version history and up-issue records.

  • Review and approval workflow, including who approved what and when.

  • Document areas, folders and access permissions.

  • Read and understood tracking.

  • Links to processes, forms, audits and other records.

Microsoft is not part of your compliance record. It provides the editing surface.

7. Microsoft licensing — your responsibility

Editing takes place in Microsoft Office for the web. This is a Microsoft service, and use of it is subject to Microsoft's terms of use and privacy statement.

Microsoft requires business users to hold a valid Microsoft 365 licence in order to edit documents in Office for the web. This requirement applies even though your users sign in to Q-Hub rather than to Microsoft, the Q-Hub sign-in controls access to the file, not entitlement to the Microsoft editing service.

By enabling the WOPI editor on your account, you confirm that every user who will use it holds a valid Microsoft 365 licence, and you accept responsibility for maintaining that coverage. Licence entitlement is a matter between your organisation and Microsoft. Q-Hub does not supply, resell or verify Microsoft licences, and cannot accept responsibility for shortfalls in your licence coverage.

Q-Hub may request written confirmation of licence coverage for accounts with the WOPI editor enabled. We also intend to introduce a requirement for Q-Hub user accounts to be linked to a Microsoft account, at which point licence status will be established at sign-in. We will give notice before that change takes effect.

If you are not able to confirm licence coverage for all users, please do not enable the WOPI editor. Documents can still be downloaded, edited locally and re-uploaded as before.

8. If you would rather not use it

The Microsoft editor is one route into a document, not the only one. Users can continue to download a file, edit it locally, and upload the replacement, this remains fully supported by leaving WOPI off.

If your organisation needs the Microsoft editing route switched off entirely, or has a strict UK-only processing requirement, contact us and we will confirm the options available for your account.

9. Legal position

Intelligent Quality Ltd (trading as Q-Hub) holds ISO 27001 and Cyber Essentials certification and operates in line with the UK GDPR and the Data Protection Act. You remain the controller of your data and Q-Hub acts as processor. Microsoft is engaged as a sub-processor for this feature, and our Data Processing Agreement and Sub-Processor List cover that relationship.


Explore the Q-Hub platform

Was this article helpful?

Ready to try it? Get started