Data Processing Agreement

This DPA (GDPR Art. 28) forms part of the agreement between the customer and Whistlechannel. It applies whenever we process personal data on the customer's behalf.

Last updated: 2026-08-04

Need a signed copy for your records? Open the countersignable version, print it or save it as PDF, sign it and return it to mikael@manpro.se. We countersign and send it back. No sales call is involved.

1. Parties and roles

Manpro AB (org. no. 556699-1807), Sweden, operates Whistlechannel. This DPA is drafted for both of the configurations below and applies according to the capacity in which the customer acts.

  • Customer as controller. The customer determines the purposes and means of processing report data; Whistlechannel is the processor. This DPA is the contract required by Article 28(3).
  • Customer as processor. Where the customer operates the channel on behalf of another organisation — a group parent, or a client whose reporting function the customer has been engaged to run — Whistlechannel is a sub-processor and this DPA is the contract required by Article 28(4). The customer’s instructions to us must be consistent with those it has received from the originating controller, and the customer warrants that it is authorised to engage us.

2. Subject-matter, nature, purpose and duration

Subject-matter: provision of an internal whistleblowing reporting channel. Nature and purpose: receiving reports through the web channel, storing them, enabling categorisation and case handling, carrying two-way communication with the reporter, and recording the case events needed to evidence the statutory deadlines. Duration:the term of the subscription, plus the retention periods in §8 and the deletion or return period in §11.

3. Categories of data and data subjects

  • Data subjects:reporters, who may be anonymous; persons named or described in a report; and the customer’s case handlers.
  • Data: report title and body, attachments, case messages and comments, case metadata and status, and handler account and activity data.

3.1 Special categories and criminal-offence data

A whistleblowing channel exists in order to receive allegations of wrongdoing. Reports therefore routinelycontain data relating to criminal offences within the meaning of Article 10 GDPR, and may contain special categories of personal data under Article 9. This is an expected characteristic of the service, not an incidental one, and the measures in §6 are applied to all report content on that basis.

The legal basis for that processing, and the assessment of what is necessary and proportionate, rest with the controller. In Sweden the processing of such data in an internal reporting channel is provided for by the Whistleblower Act (SFS 2021:890), which implements Directive (EU) 2019/1937. Whistlechannel does not determine those purposes and takes no decision concerning any data subject.

4. Boundary against our own processing

The following are processed by Whistlechannel as a controller in its own rightand fall outside this DPA: the customer’s account and contact data, billing and statutory accounting records, handler login sessions, and platform security and abuse-prevention records. They are described in our Privacy Policy. Everything else listed in §3 is processed on the customer’s behalf under this DPA.

5. Processing instructions and confidentiality

  • We process report data only on the customer’s documented instructions — this DPA, the subscription agreement, and the customer’s configuration and use of the service — unless required to process by EU or Member State law, in which case we inform the customer beforehand unless that law prohibits it.
  • We inform the customer if, in our opinion, an instruction infringes the GDPR, and may suspend performance of that instruction until the matter is resolved.
  • Persons authorised to process report data are bound by confidentiality that survives the end of their engagement. Access is limited to those who need it to operate the service.

6. Security measures (Art. 32)

  • Reporter anonymity. A reporter needs no account and is identified only by a randomly generated access code. Reporters’ IP addresses are not recorded, and analytics are suppressed on reporter-facing pages.
  • Transport. All traffic is served over TLS; edge locations are restricted to the EU.
  • At rest. Uploaded attachments are encrypted before they are written to storage. Report title, body and case messages are stored in the application database without a separate application-layer encryption envelope; access to them is controlled by authentication and tenant isolation. Customers who require content to be unreadable to the platform should not place such content in free-text fields.
  • Isolation.Data is separated by customer organisation, and access to report content is limited to that organisation’s authorised case handlers.
  • Audit trail. Case events are recorded with actor, action and timestamp so the statutory deadlines can be evidenced.
  • Programme.Our security programme is aligned with ISO 27001 and NIS 2. No formal certification is held at this time.

7. Sub-processors

The customer gives general written authorisation for the sub-processors listed at /subprocessors, which states for each one its role, the categories of data it may access and where processing occurs. That list carries its own effective date and forms part of this DPA as published on that date.

We will inform the customer in advance of any intended addition or replacement and give a reasonable opportunity to object on documented data-protection grounds before the new sub-processor begins processing report data. If no reasonable resolution is available, the customer may terminate the affected service. Each sub-processor is bound by contract to obligations no less protective than this DPA, and we remain fully liable for its performance.

8. Retention

The periods below are what the service actually applies. Erasure runs automatically each night; deletion takes effect in the live systems and residual copies then expire from backups as described in §9.

DataRetention
Closed reports, with their attachments, comments, messages and analysesDeleted 365 days after the report was submitted. Stored attachment files are removed from storage in the same operation.
Open reportsRetained while the case is open. The customer decides when a case is closed, which starts the period above.
Reporter name and email address, where the reporter chose to identify themselvesRemoved 90 days after submission, once the case is closed. An open case keeps them, so that feedback within the statutory three months remains possible.
Case audit trail (actor, action, timestamp, handler IP address and user agent)730 days.
Handler login sessionsDeleted when the session expires.
Reporter IP addressesNot recorded at any point.

The customer may delete an individual report at any time; that removes it, its attachments and the stored files from the live systems without undue delay. Records we are required to keep by law, such as accounting records, are covered by §4 and are not report data.

9. Backups

The application database is backed up daily. Backups containing personal data are retained for 7 days and expire automatically. Where report data has been deleted from the live systems, residual copies may therefore persist in backups for up to that period. Backups are not restored or otherwise processed in the interim except as part of restoring the service as a whole.

10. Data subject rights

Taking into account the nature of the processing, we assist the customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests under Chapter III GDPR. If we receive a request directly, we forward it to the customer and do not respond to the data subject ourselves unless required to by law.

10.1 What anonymity means for these requests

Two limits follow from how the service is built, and we state them rather than leave them to be discovered:

  • Where a reporter has reported anonymously, neither the customer nor Whistlechannel can identify them, and we cannot authenticate a person claiming to be that reporter. A request concerning an anonymous reporter’s own data cannot be serviced by us.
  • A person named in a report has rights under Article 15, and answering such a request in full may reveal, directly or by inference, who reported. Deciding what may be disclosed is the controller’s decision and is constrained by the confidentiality that whistleblowing legislation requires. We provide the information the customer needs to make that decision; we do not make it.

11. Personal data breach

We notify the customer without undue delay after becoming aware of a personal data breach affecting report data, describing its nature, the categories and approximate number of data subjects and records concerned where known, the likely consequences, and the measures taken or proposed. We document breaches and assist the customer, and where applicable the originating controller, in meeting its own obligations under Articles 33 and 34. We do not notify a supervisory authority or data subject on the customer’s behalf unless instructed to in writing.

12. International transfers

Report data is processed within the EU/EEA and served from EU-only edge locations. We do not use US cloud providers for report content. Where a sub-processor outside the scope of report data operates outside the EEA, or has a non-EEA parent, appropriate safeguards apply — its EU entity, an adequacy decision, or Standard Contractual Clauses with any supplementary measures a transfer impact assessment requires. The position for each sub-processor is stated at /subprocessors. We will not transfer report data outside the EEA except on the customer’s documented instructions and in compliance with Chapter V GDPR.

13. Assistance with Articles 32–36

Taking into account the nature of the processing and the information available to us, we assist the customer with the security of processing under Article 32, with breach notification under Articles 33 and 34 in accordance with §11, with data protection impact assessments under Article 35 by supplying information about the nature and categories of processing, the measures in §6 and the transfer position in §12, and with prior consultation under Article 36.

14. Audits

We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits by the customer or an auditor it mandates. Audits normally require 30 days’ notice in writing, take place during business hours, and occur no more than once per calendar year — except following a personal data breach, where a supervisory authority requires it, or where the customer has a well-founded suspicion of a material deficiency, in which case they take place as soon as reasonably practicable. Auditors must be bound by confidentiality and must not be our competitors. Where the customer acts as a processor, this right may be exercised for the benefit of the originating controller.

15. Deletion and return on termination

At the end of provision, at the customer’s election, we delete or return the report data and delete existing copies, unless EU or Member State law requires continued storage. Export is available before deletion and should be requested before termination takes effect. Residual copies in backups expire in accordance with §9. Where data must be retained to comply with a legal obligation, it is isolated from production, restricted to the purpose requiring its retention, and deleted when that obligation lapses. We confirm deletion in writing on request.

16. Term and survival

This DPA takes effect when the customer begins using the service and remains in effect for as long as we process report data on the customer’s behalf. For as long as we retain any report data after termination — including data retained under a legal obligation and residual copies in backups — this DPA continues to apply in full to that data. Once all report data has been deleted or returned, the confidentiality, audit and governing-law provisions survive for as long as necessary to give them effect.

17. Changes to this DPA

We may update this DPA and the sub-processor list to reflect changes in law or in the service. Material changes are notified a reasonable time in advance where possible; a change required by law or made to address a security vulnerability may take effect immediately, with notice without undue delay afterwards. A change that materially reduces the protection afforded to report data does not take effect without the customer’s agreement. Each version carries the effective date shown at the top of this page.

18. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms of Service, save that nothing limits either party’s liability to the extent such limitation is not permitted by law, nor affects the rights of data subjects under Article 82 GDPR. This DPA is governed by the laws of Sweden and forms part of the Terms of Service.

Data protection contact: mikael@manpro.se. A countersigned copy of this DPA is available on request to the same address.

Redo att uppfylla Visselblåsarlagen?

Kom igång på minuter. Ingen installation, ingen bindningstid, ingen kreditkortsuppgift för trial.