Privacy Policy

Last updated: February 2026

1. Introduction

WhistleHub ("we", "our", "us") is committed to protecting the privacy and confidentiality of all individuals who use our whistleblowing platform services. This Privacy Policy explains how we collect, use, and protect your information.

2. Data Controller

WhistleHub is the data controller for the personal data processed through our Services. For organization-specific reports, the subscribing organization is the data controller for report contents.

3. Information We Collect

3.1 For Organizations

  • Company registration information
  • User account details (name, email, role)
  • Billing and payment information
  • Usage data and analytics

3.2 For Whistleblowers

We are designed to protect whistleblower anonymity. We minimize data collection:

  • IP addresses are temporarily processed for security (rate limiting, abuse prevention) but are never shared with the reporting organization and are stripped from all company-visible audit logs
  • We do not collect browser fingerprints or device identifiers
  • We do not collect location data
  • No personally identifiable information is collected unless voluntarily provided by the reporter

Reports are submitted through secure, encrypted channels. Company administrators never see IP addresses, user agents, or other metadata that could identify the reporter.

4. How We Use Information

We use collected information to:

  • Provide and maintain our Services
  • Process subscriptions and payments
  • Send service-related communications
  • Improve and develop our Services
  • Comply with legal obligations

5. Legal Basis for Processing

We process personal data based on:

  • Contract performance (to provide our Services)
  • Legitimate interests (to improve our Services)
  • Legal obligations (compliance with EU regulations)
  • Consent (where specifically requested)

6. Data Security

We implement robust security measures including:

  • Application-level encryption of report content at rest (AES-256-GCM, a separate key per report, wrapped by Google Cloud KMS)
  • TLS encryption for all data in transit
  • Encrypted database and file storage hosted in the EU (Google Cloud, europe-west1)
  • Role-based access controls, so only designated handlers can open a report
  • Tamper-evident audit trail of every handling action
  • Regular internal security reviews and automated dependency vulnerability scanning, on ISO 27001-certified infrastructure

7. Data Retention

We retain data for the period necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Organizations can configure retention policies according to their legal requirements.

8. International Data Transfers

Our Services are hosted within the European Economic Area (EEA). We do not transfer personal data outside the EEA unless adequate safeguards are in place.

9. Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict processing
  • Data portability
  • Object to processing
  • Lodge a complaint with a supervisory authority

10. Whistleblower Protection

In accordance with EU Directive 2019/1937 and national implementations, we are committed to protecting the identity of whistleblowers. We will not disclose whistleblower identity except:

  • With the whistleblower's explicit consent
  • When required by law for judicial proceedings

11. Cookies & Local Storage

11.1 Essential Storage

We use the following browser storage items that are strictly necessary for our Services to function. These are classified as "essential" under ePrivacy rules and do not require consent:

NameTypePurpose
i18nextLnglocalStorageLanguage preference (EN / ET)
whistlehub-themelocalStorageTheme preference (light / dark / system)
whistlehub-authlocalStorageCompany session authentication state
company-auth-storagelocalStorageCompany login session token
whistlehub-cookie-consentlocalStorageYour cookie consent choice
Session cookieHTTP cookieServer-side session for authenticated users

11.2 Analytics

On our public marketing website (whistlehub.eu) we use Google Analytics 4, provided by Google Ireland Limited, to understand how visitors find and use our pages. It loads only after you choose "OK, understood" in the cookie banner; if you choose "Essential Only", no analytics script is loaded at all. IP addresses are truncated, and we do not send names, e-mail addresses or anything you type into a form to Google. Google Analytics is never loaded on the application (app.whistlehub.eu) or on any organisation's reporting site: people who submit reports are not tracked. Google may transfer analytics data to the United States under the EU-US Data Privacy Framework. You can withdraw your consent at any time as described in 11.4.

11.3 Marketing & Advertising

We do not use marketing or advertising cookies. If this changes in the future, consent will be required before any such scripts are loaded.

11.4 Managing Your Preferences

When you first visit our site, a consent banner lets you choose between "Accept All" and "Essential Only." You can reset your choice at any time by clearing your browser's local storage for this site, which will cause the banner to reappear.

12. Third-Party Services

We may use third-party services for:

  • Payment processing (Montonio)
  • Cloud infrastructure (Google Cloud Platform)
  • Email delivery
  • AI-powered message translation (see Section 13 below)

All third-party providers are bound by data processing agreements and comply with GDPR requirements.

13. AI-Powered Translation Services

13.1 Purpose and Scope

Our Services include an optional on-demand message translation feature that enables case handlers and reporters to translate messages into their preferred language. This feature uses Google Gemini (a large language model provided by Google LLC) to perform translations when requested by the user.

13.2 Data Processed

When a user requests a translation, the following data is sent to Google Gemini:

  • The text content of the message(s) being translated
  • The target language code

No personally identifiable information (names, email addresses, report IDs, or company identifiers) is included in translation requests. Only the message text is transmitted.

13.3 Data Retention by Third Party

Google Gemini processes translation requests in real time. Under Google's API Terms of Service for paid API usage, input and output data are not used to train Google's models. We cache translation results in our own database to minimize repeated external API calls.

13.4 Legal Basis

Translation processing is based on legitimate interest (GDPR Article 6(1)(f)) — enabling effective cross-language communication in whistleblowing cases. Translations are triggered only by explicit user action (clicking a "Translate" button), not automatically.

13.5 Opt-Out

Translation is entirely optional. Users who do not wish their messages to be processed by an external AI service may simply choose not to use the translation feature. No translation occurs without an explicit user request.

13.6 Audit Trail

All translation requests are logged in our audit system, recording the requesting user, timestamp, source type, target language, and the number of messages translated. These logs are available to company administrators in the audit log.

14. Changes to This Policy

We may update this Privacy Policy periodically. We will notify users of material changes via email or through our Services.

15. Contact Us

For privacy-related inquiries or to exercise your rights, please contact our Data Protection Officer at info@whistlehub.eu

We use essential cookies and local storage to keep our service running securely. No tracking or advertising cookies are used. Learn more