Privatlivspolitik
Privatlivspolitikken findes kun på engelsk. Teksten her er den samme som i PDF'en.
1. Who we are
WhistleSafe ApS, Danish CVR 44412667, Ndr Dragørvej 151, DK-2791 Dragør, Denmark. Contact: kontakt@whistlesafe.dk.
For data we process for our own purposes (invoicing, marketing, employees), we are the Controller. For data we process on the WhistleSafe platform on behalf of customer organisations (whistleblower reports, case-handler accounts, audit logs within a tenant), the customer organisation is the Controller and we are the Processor — see the relevant Data Processing Agreement.
2. What this notice covers
This privacy notice covers our public website (whistlesafe.dk) and the WhistleSafe platform (app.whistlesafe.dk, api.whistlesafe.dk). Detailed technical descriptions of all processing activities are in our internal records of processing under GDPR Art. 30, our Data Protection Impact Assessment under Art. 35, and our Government Access Policy.
3. Different roles, different rules
What we collect depends on who you are:
- Visitor to whistlesafe.dk — Section 4
- Case handler / Manager / Partner using the platform — Section 5
- Reporter (whistleblower) submitting a report — Section 6
- Billing contact at a customer organisation — Section 7
- Inquirer who contacts us via the support form or kontakt@whistlesafe.dk — Section 8
4. Marketing website visitors
When you visit https://whistlesafe.dk:
- What we collect: nothing identifiable. The site is statically hosted, sets no cookies, embeds no third-party trackers (no Google Analytics, no Plausible, no Facebook Pixel, no Hotjar, no captcha). Your dark-mode preference is stored in your browser’s localStorage; we never see it.
- What we do not collect: no IP address logging beyond standard webserver request metadata, no device fingerprinting, no cross-site tracking, no advertising profiles.
- Contact form submissions are routed to our support inbox via Microsoft Graph (Microsoft 365 EU Data Boundary). See Section 8.
5. Case handlers using the platform
When you log into https://app.whistlesafe.dk as a manager / partner / employee user of a customer’s WhistleSafe tenant:
- Categories of data: name, email, phone (optional), password hash (PBKDF2), role assignments, optional 2FA TOTP secret + recovery codes (encrypted at rest), language preference, refresh-token records (stored only as hashes), sign-in and account-security events (sign-ins, failed sign-ins, lockouts, 2FA and password-reset events; no IP address), audit-log entries (who viewed/changed what).
- Source: you, when you register or accept an invitation.
- Purposes: authenticating you, authorising what you see, keeping a record of sign-ins and account-security events so misuse of your account can be spotted, sending transactional emails about reports you handle, generating PDF reports.
- Lawful basis: GDPR Art. 6(1)(b) — performance of the customer’s contract under which you access the platform; for partner-program accounts that we hold directly, Art. 6(1)(b) and (f). The sign-in record and application logs also rest on Art. 6(1)(f) — the legitimate interest in keeping the platform and your account secure.
- Sub-processors: Microsoft Azure (App Service, SQL Database, Blob Storage), Microsoft Application Insights (application logs and telemetry), Microsoft Graph (email).
- Retention: lifetime of your account; a refresh token expires 180 minutes after it is issued and is replaced at every refresh, so a session ends after 180 minutes without activity; sign-in and account-security events 90 days; application logs and telemetry 90 days (log lines identify your account by its user id, and email addresses are removed from log entries before they are exported or written to the server’s console log, which is kept for 2 days); audit-log entries retained alongside the report or company they relate to.
- Who sees your sign-in record: managers of your organisation who hold the activity permission see your last sign-in and your recent security events (lockouts, 2FA changes, password resets, recovery-code use). WhistleSafe administrators see the full record, including changes they made to your account. Your “my data” download lists your events and their times.
- Links in account emails: password-reset, email-confirmation and invitation links are protected with keys we keep in a private storage container, encrypted with a key held in Azure Key Vault.
- Your rights: see Section 9. Self-service: “my data” download at /api/Authentication/my-data after login; delete account at Manager → My Profile.
6. Reporters (whistleblowers)
When you submit a whistleblower report through a WhistleSafe-hosted reporting page operated by a customer organisation:
- Categories of data: the free-text content of your report (subject, description), optional notification email if you supply one, attachments. Attachments are stored under a neutral file name (attachment-1.jpg, …); your own file names are not kept. Identifying metadata is stripped before storage — whether a file is attached with the report or added later: image attachments (JPEG, PNG, GIF, BMP, WebP, TIFF) lose their EXIF / IPTC / XMP data (GPS coordinates, device serials, capture time); PDF and Word / Excel / PowerPoint (.docx, .xlsx, .pptx) files lose their author, company and other document properties, and the authors of comments and tracked changes become “Author 1”, “Author 2”, …. Audio, video, ZIP and password-protected files are stored as uploaded and can still contain such details (for example the recording device or a location); the upload page says so. The content of a file is never changed. Your report category is stored as a language-neutral key, and when you read a case handler’s message we record only the day, which the case handler sees once that day is over.
- What we explicitly do not collect: your IP address (stripped at telemetry export by an OpenTelemetry processor and at logging by a Serilog enricher), device fingerprint, browser fingerprint, geolocation, or any cross-session identifier. There is no personal account or login for reporters: the reporting link uses one shared account per organisation.
- Application logs and telemetry: the method, route, status and timing of each request, without your IP address and with your Report ID removed or replaced by a one-way reference, kept 90 days in Microsoft Application Insights.
- Source: you, voluntarily.
- Purpose: delivering your report to the case handlers nominated by the customer organisation to receive reports.
- Lawful basis: the customer organisation processes your report under the EU Whistleblower Directive 2019/1937 transposed into Danish law (Lov om beskyttelse af whistleblowere, Act No. 1436 of 29 June 2021). We process it on their behalf as Processor.
- Sub-processors: Microsoft Azure (storage of report and attachments), Microsoft Application Insights (application logs and telemetry, without your IP address), Microsoft Graph (email — and only if you supplied a notification email; that address is never written to our logs, telemetry, or CSV exports, by an enforced privacy invariant). The platform sends email without saving a copy in our mailbox. Microsoft 365 keeps a message trace of every email sent — sender, recipient address, subject and delivery status — for 90 days; our support staff search it only for staff addresses, never for reporter notifications.
- Retention: per the customer organisation’s retention policy. If they have configured one, your report and its attachments are auto-deleted after the configured number of days from when the report was closed or marked as spam. If they haven’t, the report is retained until they manually delete it. A notification email you supplied is deleted when the report is closed or marked as spam; after that you get no more emails, and you can still open the report with your Report ID.
- Special protections: Danish Whistleblower Act §§ 25 and 26 make the confidentiality of your identity a statutory obligation — see Section 11.
- Your rights: to exercise GDPR rights, contact the customer organisation that operates the reporting scheme (they are the Controller). For escalation, email kontakt@whistlesafe.dk.
7. Billing contacts at customer organisations
When your organisation subscribes to WhistleSafe:
- Categories of data: business name, organisation name, VAT/CVR, billing address, billing email, invoice history, subscription status.
- Source: the person who completes your organisation’s subscription signup.
- Purpose: invoicing and managing the customer relationship.
- Lawful basis: Art. 6(1)(b) — performance of contract.
- Sub-processors: Stripe Payments Europe Ltd. (Ireland) for payment processing. Stripe only receives billing information: we send it the organisation’s name, email address, postal address, CVR/VAT number and preferred language, the chosen plan and any discount code. Card details are entered directly on Stripe’s own checkout and billing-portal pages and never pass through WhistleSafe’s servers. Reports, cases, messages, attachments and information about reporters are never sent to Stripe. Stripe transfers the billing data to Stripe, LLC in the United States — see Section 15.
- Retention: duration of the subscription + 5 years to comply with Danish bookkeeping law (bogføringsloven).
- Your rights: see Section 9.
8. Inquirers who contact us
When you fill out the contact form on whistlesafe.dk or email kontakt@whistlesafe.dk:
- Categories of data: name, email, message content, date received.
- Source: you.
- Purpose: responding to your enquiry.
- Lawful basis: Art. 6(1)(f) — our legitimate interest in responding to enquiries.
- Retention: 24 months from last interaction.
- Sub-processors: Microsoft 365 (email mailbox).
9. Your rights under GDPR
You have the rights to:
- Access (Art. 15) — get a copy of personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure (Art. 17) — be deleted, subject to legal retention duties.
- Restriction (Art. 18) — limit processing pending dispute resolution.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to legitimate-interest-based processing.
- Withdraw consent where processing is consent-based.
To exercise these rights:
- As a case handler: use the self-service “my data” download at /api/Authentication/my-data after logging in. To delete your account, go to Manager → My Profile. For other requests, email kontakt@whistlesafe.dk.
- As a reporter: contact the customer organisation operating the reporting scheme (they are the Controller). For escalation, email kontakt@whistlesafe.dk.
- As a billing contact or inquirer: email kontakt@whistlesafe.dk.
We respond within one month (extendable by two further months for complex requests, with notice to you).
You also have the right to lodge a complaint with the Danish Data Protection Authority:
Datatilsynet
Carl Jacobsens Vej 35, 2500 Valby
dt@datatilsynet.dk
+45 3319 3200
10. Sub-processors
A current public list of sub-processors is at https://api.whistlesafe.dk/api/Public/sub-processors. We will give 30 days’ notice before adding or replacing a sub-processor (per our Data Processing Agreement).
11. Special protections for whistleblowers under Danish law
The Danish Whistleblower Act (Lov om beskyttelse af whistleblowere, Act No. 1436 of 29 June 2021) makes the confidentiality of a reporter’s identity a statutory obligation, not merely a policy preference:
- § 25: whoever is designated to receive and follow up on reports has a duty of confidentiality about the information in them.
- § 26, stk. 1: information that can directly or indirectly identify the reporter may not be disclosed without the reporter’s explicit consent to anyone other than the authorised staff who receive or follow up on reports.
- § 26, stk. 2: without that consent, it may be disclosed only to another public authority, and only to counter breaches covered by the Act or to safeguard the right of defence of the persons concerned.
- § 26, stk. 4: the reporter must be informed before a disclosure under stk. 2, unless that would jeopardise related investigations or court proceedings.
We apply this protection regardless of who is asking. See our Government Access Policy at https://api.whistlesafe.dk/api/Public/government-access-policy for the full procedure we follow on receiving a request from any authority.
12. Children’s data
The platform is designed primarily for adults in employment, contracting, or member relationships. Customers operating educational institutions may receive reports from pupils under 18.
We apply identical anonymity safeguards regardless of reporter age — no IPs collected, no device fingerprints, attachment metadata stripped, etc.
Reporting does not rest on the reporter’s consent: the customer organisation, as Controller, processes reports — including an optional notification email — under a legal obligation in the whistleblower legislation or, for a voluntary scheme, another lawful basis in GDPR Art. 6(1), and remains responsible for that basis. GDPR Art. 8 sets conditions only where consent is the basis for an information society service offered directly to a child (in Denmark, from age 15: databeskyttelsesloven § 6, stk. 2), so it does not govern reports.
13. Automated decision-making
The platform performs no automated decision-making within the meaning of GDPR Art. 22. All case decisions, state changes, and follow-up communications are made by human case handlers nominated by the customer.
14. Cookies and similar technologies
The platform sets no cookies, on any subdomain. We do not use third-party trackers, captchas, or chat widgets. State that would normally be in a cookie is in browser storage (sessionStorage for JWT auth tokens, localStorage for language and dark-mode preferences), and is strictly necessary for the service you have explicitly requested.
We do not use Cloudflare or any other CDN that would inject its own cookies; traffic is served directly by Azure App Service and Kestrel.
15. International transfers
All platform data is hosted in Microsoft Azure North Europe (Dublin, Ireland), within the EU Data Boundary. We do not have a U.S. presence; no parent or affiliate is incorporated in a jurisdiction that would expose data to direct foreign subpoena.
Where a sub-processor’s global engineering may incidentally access data from outside the EU/EEA, the European Commission’s Standard Contractual Clauses adopted under Article 46(2) GDPR are incorporated by reference.
Billing data (Section 7) also goes to Stripe, which transfers it to Stripe, LLC in the United States. Stripe, LLC is certified under the EU-U.S. Data Privacy Framework. Stripe’s Data Transfers Addendum makes the Framework the transfer mechanism, and the European Commission’s Standard Contractual Clauses apply where the Framework does not.
16. Updates to this notice
We publish updates at the same URL (/api/Public/privacy-policy) with an updated “Last updated” date and version footer. Material changes affecting your rights are communicated via email to active account holders before they take effect.
17. Contact
For privacy questions, data subject requests, or any other matter relating to this notice:
Paw Ormstrup Madsen
WhistleSafe ApS
Ndr Dragørvej 151, DK-2791 Dragør, Denmark
kontakt@whistlesafe.dk