Last updated: 5 April 2026
The data controller within the meaning of Regulation (EU) 2016/679 (GDPR) is:
WhistleBox is designed on the principle of "privacy by design" and collects personal data on a minimal basis:
/r/) do not set cookies, do not collect IP addresses, and do not use fingerprinting or tracking mechanisms.Minimal / zero collection:
We do not sell, rent or share users' personal data with third parties for marketing purposes.
We process personal data on the following legal bases (Art. 6 GDPR):
| Legal basis | Applicability |
|---|---|
| Performance of a contract (Art. 6.1.b) | Provision of the reporting channel service to the Client organisation. |
| Legal obligation (Art. 6.1.c) | Compliance with Directive (EU) 2019/1937, GDPR, tax and accounting legislation. |
| Legitimate interest (Art. 6.1.f) | IT security, prevention of abuse, operation of the Platform. |
Personal data may be accessed or processed by the following sub-processors:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, server infrastructure | Germany (EEA) | Not required — within the EEA |
| Resend | Transactional email | USA | SCCs (Standard Contractual Clauses) |
| NETOPIA Payments | Card payment processing | Romania (EEA) | Not required — within the EEA |
| SmartBill | Electronic invoicing | Romania (EEA) | Not required — within the EEA |
For data transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
Important: Report contents are E2E encrypted and are not accessible to any sub-processor.
Under the GDPR, you are entitled to the following rights:
To exercise your rights, send an email to contact@whistle-box.eu with the subject "GDPR Request WhistleBox".
Note regarding whistleblowers: If you submitted an anonymous report and did not identify yourself, the Operator does not hold any personal data about you.
We implement appropriate technical and organisational measures to protect personal data:
/r/) do not set cookies and do not collect identifying data.The Operator may update this policy periodically. Users shall be notified by email and/or through an announcement on the Platform at least 15 days before significant amendments come into effect.
Operator:
Supervisory authority: