Privacy Policy
How we handle personal data — both our own site data and the whistleblowing data we process on behalf of our customers.
Last updated: 2026-08-04
1. Who we are
Whistlechannel is operated by Manpro AB (org. no. 556699-1807). For our own website, account and billing data we act as the controller. For the report data that a customer organisation collects through its channel, that customer is the controller and we act as their processor under the Data Processing Agreement.
2. Data we process
- Account & billing: name, work email, organisation, and payment/subscription details (payment card data is handled by our payment processor, not by us).
- Report data (as processor): the content a reporter submits, case status, messages and any attachments. Reporters may submit fully anonymously.
- Technical: minimal operational logs. We do not log reporters’ IP addresses, and analytics are suppressed on reporter and anonymous pages.
3. Legal bases
- Providing the service and administering accounts — performance of a contract (GDPR Art. 6(1)(b)).
- Security, fraud prevention and service improvement — legitimate interests (Art. 6(1)(f)).
- Legal and compliance obligations, including support of EU Directive 2019/1937 documentation — legal obligation (Art. 6(1)(c)).
4. EU data residency & transfers
Report data is hosted within the EU/EEA and served from EU-only edge locations. We do not use US cloud providers for report content. Payment is handled by a separate processor (see sub-processors); billing data may be processed by that processor’s EU entity. AI-assisted categorisation runs on our own EU infrastructure; no third-party or US AI provider receives report content.
5. Sub-processors
We engage a small number of sub-processors to run the service. The current list, their location and data scope is published at /subprocessors.
6. Retention
As processor, we retain report data for as long as the customer’s configured retention period and applicable law require, then delete or return it. Account and billing data is retained for the life of the account and for the period required by accounting law thereafter.
7. Security
Data is encrypted in transit (TLS/AES-256), access to report content is restricted to authorised case handlers, and we do not log reporter IP addresses. Our security programme is aligned with ISO 27001 and NIS 2 (we hold no formal certification at this time and are transparent about remaining gaps).
8. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. For account/site data, contact us below. If your data was submitted through a customer’s channel, the customer is the controller — we will assist them in responding to your request.
9. Cookies
We use only the cookies strictly necessary to run the service (e.g. session and security). We do not use advertising or cross-site tracking cookies.
10. Contact
Data-protection contact: mikael@manpro.se. You also have the right to lodge a complaint with your supervisory authority (in Sweden, the Integritetsskyddsmyndigheten, IMY). See our contact page for full company details.