Privacy Policy

How we handle personal data — both our own site data and the whistleblowing data we process on behalf of our customers.

Last updated: 2026-08-04

1. Who we are

Whistlechannel is operated by Manpro AB (org. no. 556699-1807). For our own website, account and billing data we act as the controller. For the report data that a customer organisation collects through its channel, that customer is the controller and we act as their processor under the Data Processing Agreement.

2. Data we process

  • Account & billing: name, work email, organisation, and payment/subscription details (payment card data is handled by our payment processor, not by us).
  • Report data (as processor): the content a reporter submits, case status, messages and any attachments. Reporters may submit fully anonymously.
  • Technical: minimal operational logs. We do not log reporters’ IP addresses, and analytics are suppressed on reporter and anonymous pages.

3. Legal bases

  • Providing the service and administering accounts — performance of a contract (GDPR Art. 6(1)(b)).
  • Security, fraud prevention and service improvement — legitimate interests (Art. 6(1)(f)).
  • Legal and compliance obligations, including support of EU Directive 2019/1937 documentation — legal obligation (Art. 6(1)(c)).

4. EU data residency & transfers

Report data is hosted within the EU/EEA and served from EU-only edge locations. We do not use US cloud providers for report content. Payment is handled by a separate processor (see sub-processors); billing data may be processed by that processor’s EU entity. AI-assisted categorisation runs on our own EU infrastructure; no third-party or US AI provider receives report content.

5. Sub-processors

We engage a small number of sub-processors to run the service. The current list, their location and data scope is published at /subprocessors.

6. Retention

As processor, we retain report data for as long as the customer’s configured retention period and applicable law require, then delete or return it. Account and billing data is retained for the life of the account and for the period required by accounting law thereafter.

7. Security

Data is encrypted in transit (TLS/AES-256), access to report content is restricted to authorised case handlers, and we do not log reporter IP addresses. Our security programme is aligned with ISO 27001 and NIS 2 (we hold no formal certification at this time and are transparent about remaining gaps).

8. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. For account/site data, contact us below. If your data was submitted through a customer’s channel, the customer is the controller — we will assist them in responding to your request.

9. Cookies

We use only the cookies strictly necessary to run the service (e.g. session and security). We do not use advertising or cross-site tracking cookies.

10. Contact

Data-protection contact: mikael@manpro.se. You also have the right to lodge a complaint with your supervisory authority (in Sweden, the Integritetsskyddsmyndigheten, IMY). See our contact page for full company details.

Gatavi izpildīt Trauksmes celšanas likumu?

Darbojas dažu minūšu laikā. Bez instalēšanas, bez saistībām.