WhistleHub Data Processing Addendum

Version 1 · August 2026

WhistleHub OÜ · Registry code 16567393 · Estonia

This Addendum forms part of the WhistleHub Terms of Service. It applies whenever we handle personal data on your behalf. Terms defined in the Terms of Service have the same meaning here.

In plain English

  • You are the controller. You decide why reports are collected and what happens to them.
  • We are your processor. We run the platform and follow your instructions.
  • Your data stays in the EU.
  • We use Google Cloud as our infrastructure provider. We will tell you before we add anyone else.
  • If something goes wrong, we tell you quickly and help you deal with it.
  • When you leave, we delete your data.
  • Whistleblowing reports often contain sensitive information about health, alleged crimes, or personal circumstances. Both of us need to treat them accordingly.

1. Roles

You are the controller. You determine why and how personal data is processed through the service.

We are your processor. We process personal data only to provide the service and only on your documented instructions.

The Terms of Service, this Addendum, your Order Form and your configuration of the service together make up your instructions. If we think an instruction breaches data protection law, we will tell you.

Anonymous reporting. Where you enable anonymous reporting, you instruct us to operate the channel so that a reporter can submit without providing identifying information, and so that reporter identity and network information are not exposed to you or to anyone else. This is your instruction, implemented by us as processor. It does not make us a controller of that data.

Translation. The service includes an optional message translation feature. Translation happens only when a user asks for it, and only the text of the message being translated is sent — no account data, case metadata or attachments. If the message text itself contains personal data (for example a name the writer typed into it), that content is translated as written. If you or your users choose to use it, that choice is your instruction. If you do not, no message text leaves the platform for this purpose.

We do not determine the purposes of processing report data, and we do not use it for any purpose of our own.

We act as an independent controller only for data we process for our own administration — billing, account management and our own legal obligations. That processing is covered by our Privacy Policy, not this Addendum.

2. What we process

The details required by Article 28(3) GDPR are in Annex 1.

3. Confidentiality

Everyone we authorise to process your personal data is bound by confidentiality obligations that survive the end of their engagement, and is trained appropriately.

Access to report content is limited to the minimum number of our personnel necessary, and only where required for support, security or legal compliance. Every such access is logged.

4. Security

We implement and maintain the technical and organisational measures in Annex 2.

We keep those measures under review and may improve them. We will not reduce the overall level of protection during your subscription.

5. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 3.

If we want to add or replace one, we will tell you at least 30 days in advance. If you reasonably object on data protection grounds within that period, we will propose an alternative. If no alternative is acceptable to you, you may cancel the affected part of the service and we will refund the unused part of your fee.

We remain responsible to you for our sub-processors, and we impose the same obligations on them that apply to us.

6. Where data is stored

Personal data is stored and processed in the European Union.

We do not transfer personal data outside the EU or EEA except where you instruct us to, or where a sub-processor listed in Annex 3 requires it. Any such transfer uses a lawful mechanism under Chapter V GDPR, including Standard Contractual Clauses where applicable.

7. Helping you with data subject rights

Reporters and people named in reports have rights under the GDPR. Those rights interact with whistleblower protection law, which restricts what may be disclosed and to whom.

We will:

  • pass on any request we receive directly, without responding to it ourselves, unless you tell us otherwise;
  • give you the tools and information you reasonably need to respond;
  • not disclose a reporter’s identity to you, to a person named in a report, or to anyone else except where the law requires it and you have instructed us in writing.

8. Helping you with your obligations

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with:

  • data protection impact assessments and prior consultation;
  • security of processing;
  • notifying breaches to regulators and data subjects.

9. If there is a breach

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours.

Our notification will describe what happened, which categories and approximate numbers of data subjects and records are affected, the likely consequences, and what we are doing about it. Where we do not have all of that at first, we will send what we have and follow up.

We will not notify your regulator or your data subjects on your behalf unless you ask us to in writing.

10. Audit

We will give you the information you need to demonstrate compliance with Article 28 GDPR. In practice this means:

  • our Security Documentation and current certifications or audit reports;
  • a completed security questionnaire once a year on request.

If that is not sufficient — for example after a breach, or where your regulator requires it — you or an independent auditor may audit us. You give us 30 days’ notice, we agree scope and timing, the auditor signs a confidentiality agreement, and the audit does not disrupt our service or expose other customers’ data. You bear the cost, unless the audit finds a material breach by us.

11. Deletion and return

You can export your data at any time during your subscription and for 90 days afterwards.

After that period we delete it, including from backups within our normal backup cycle, which does not exceed 90 days.

We will keep data longer only where the law requires it. If so, we tell you what and why, and we keep it protected and process it no further.

Your own retention obligations. Whistleblowing law may require you to keep records for a defined period. You are responsible for meeting those obligations. Export what you need before your access ends.

12. Liability

The liability provisions in the Terms of Service apply to this Addendum, including the enhanced cap for data protection breaches.

Nothing here limits either party’s liability to data subjects or regulators under data protection law.

13. Duration

This Addendum applies for as long as we process personal data on your behalf. The obligations relating to confidentiality, deletion and liability continue after it ends.

Annex 1 — Details of processing

Version 1 · August 2026

Subject matter. Providing the WhistleHub reporting and case management platform.

Duration. For the term of the subscription, plus the export and deletion periods in clause 11.

Nature and purpose. Receiving, storing, transmitting and making available reports of suspected wrongdoing and related communications; enabling case handling by your designated handlers; maintaining an audit trail; providing support.

Types of personal data.

Category

Examples

Reporter data

Name and contact details where given; pseudonymous identifiers where the report is anonymous; message content

Data about people named in reports

Names, roles, alleged conduct, any other detail the reporter includes

Handler and administrator data

Name, work email, role, access rights, activity logs

Case data

Report content, attachments, follow-up correspondence, internal notes, status and timestamps

Technical data

Log data necessary for security and audit integrity. IP addresses are processed briefly for security and abuse prevention, are never disclosed to you, and are removed from the logs visible to your organisation

Special categories and criminal data. We cannot control what a report contains. Reports may include data revealing health, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, and personal data relating to criminal offences, allegations or proceedings (Articles 9 and 10 GDPR). You are responsible for having a lawful basis for that processing and for meeting the additional conditions that apply to it.

Categories of data subjects. Reporters; people named or referred to in reports; your handlers and administrators; your employees, workers, contractors, suppliers, applicants, volunteers and other people in a work-related relationship with you.

Annex 2 — Technical and organisational measures

Version 1 · August 2026

Hosting and location. Google Cloud Platform, region europe-west1 (Belgium). All processing takes place in the European Union, except on-demand message translation, which uses Google infrastructure that is not restricted to the EU (see Annex 3).

Encryption. Report content and attachments are encrypted at the application level using AES-256-GCM. Encryption keys are managed through Google Cloud KMS. All data in transit is encrypted using TLS.

Anonymity by design. A reporter can submit a report without an account, an email address or a phone number. Reporter identity and network information are not exposed on organisation-facing surfaces.

Access control. Role-based access. Handlers see only the cases assigned to their organisation. Our own personnel have no routine access to report content; where access is required for support or security, it is authorised, minimised and logged.

Tenant isolation. Each customer’s data is logically separated. Isolation is tested.

Audit integrity. Significant activity is recorded in a hash-chained audit log. Log integrity is periodically anchored to a public blockchain. Only cryptographic hashes are written to the blockchain — never report content or personal data.

Resilience. Encrypted backups with defined retention. Restoration is tested.

Personnel. Confidentiality obligations, access only where necessary for a person’s role, and security training.

Certification. Our infrastructure provider holds ISO/IEC 27001, 27017 and 27018 certifications. Those certifications apply to Google’s infrastructure and not to WhistleHub. WhistleHub’s own ISO/IEC 27001:2022 certification programme is underway, with certification targeted for 2027.

The current version of these measures is maintained in our Security Documentation.

Annex 3 — Sub-processors

Version 1 · August 2026

Each row states the sub-processor, its role, and where it processes personal data.

  • Google Cloud EMEA Limited — cloud infrastructure and hosting: application, database, file storage and encryption keys — European Union (Belgium)
  • Google Ireland Limited (Gemini API) — on-demand message translation, used only when a user requests it. Input is not used to train Google’s models — Google infrastructure, not restricted to the EU. An EU-resident translation path is implemented and will replace this entry when it is enabled
  • Google Ireland Limited (Google Workspace) — inbound email intake for reporting addresses — European Union
  • Zone Media OÜ (veebimajutus.ee) — outbound email delivery: notifications and invoices — Estonia
  • Infobip d.o.o. — SMS delivery, only where an organisation switches SMS notifications on — European Union (Croatia)

The current list is maintained at whistlehub.eu/sub-processors. You can subscribe there to be notified of changes.

We use essential cookies and local storage to keep our service running securely. No tracking or advertising cookies are used. Learn more