Data Processing Agreement

This DPA (GDPR Art. 28) forms part of the agreement between the customer (controller) and Whistlechannel (processor). It applies whenever we process personal data on the customer's behalf.

Last updated: 2026-08-04

1. Roles

The customer is the controller of the report data collected through its channel. Manpro AB (org. no. 556699-1807) is the processor, processing that data only on the customer’s documented instructions, including this DPA and the customer’s use of the service.

2. Subject-matter, duration, nature & purpose

Subject-matter: provision of a whistleblowing reporting channel. Duration: the term of the subscription plus the deletion/return period below. Nature & purpose: receiving, storing, categorising and enabling case handling and two-way communication for reports.

3. Categories of data & data subjects

  • Data subjects: reporters (who may be anonymous), persons named in a report, and the customer’s case handlers.
  • Data: report content and attachments, case metadata and messages, and handler account data. Reports may contain special-category or criminal-offence data depending on what a reporter submits.

4. Processor obligations

  • Process only on the controller’s documented instructions, and inform the controller if an instruction appears to infringe the GDPR.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Art. 32) — see §6.
  • Respect the sub-processor conditions in §5.
  • Assist the controller with data-subject requests and with Art. 32–36 obligations, taking into account the nature of processing.
  • Delete or return the data at the end of provision (see §9).
  • Make available the information needed to demonstrate compliance and allow for and contribute to audits (see §8).

5. Sub-processors

The controller gives general authorisation for the sub-processors listed at /subprocessors. We will inform the controller before adding or replacing a sub-processor and give the controller the opportunity to object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this DPA.

6. Security measures (Art. 32)

  • Encryption in transit (TLS/AES-256); access to report content restricted to authorised case handlers.
  • No logging of reporters’ IP addresses; analytics suppressed on reporter/anonymous pages.
  • Tenant isolation between customer organisations; timestamped audit logging of case events.
  • A security programme aligned with ISO 27001 and NIS 2 (no formal certification held at this time).

7. International transfers

Report data is processed within the EU/EEA and served from EU-only edge locations; we do not use US cloud providers for report content. Where any billing-related processor operates outside the EEA, appropriate safeguards (e.g. its EU entity or Standard Contractual Clauses) apply — see sub-processors.

8. Audits

On reasonable request and no more than once per year (or after a personal-data breach), we will make available the information necessary to demonstrate compliance with this DPA and contribute to an audit conducted by the controller or an independent auditor bound by confidentiality.

9. Personal-data breaches

We will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller’s data, with the information the controller needs to meet its own obligations.

10. Deletion & return

At the end of provision, at the controller’s choice, we delete or return the report data and delete existing copies, unless EU or Member State law requires storage. Export is available before deletion.

11. Governing law

This DPA is governed by the laws of Sweden and forms part of the Terms of Service. Contact: mikael@manpro.se.

Připraveni splnit zákon č. 171/2023 Sb.?

Provoz během minut. Bez instalace, bez závazku, bez kreditní karty pro zkušební verzi.