Underdatabehandlere
Listen findes kun på engelsk. Teksten her er den samme som i PDF'en.
WhistleSafe ApS engages the following sub-processors to deliver the platform. Each is bound by a written agreement that imposes the same data protection obligations as those WhistleSafe accepts in our Data Processing Agreement with you.
We will give 30 days’ written notice (typically email to the company contact) before adding or replacing a sub-processor. You may object to changes; if we cannot reasonably accommodate the objection, you may terminate the affected service.
Active sub-processors
| Sub-processor | Role | Data category | Region |
|---|---|---|---|
| Microsoft Azure (App Service, SQL Database, Blob Storage) | Hosting, application database, attachment storage | All platform data: account profiles, reports, attachments, messages, audit log | North Europe (Ireland) — within the EU Data Boundary |
| Microsoft Application Insights | Application telemetry and error logging | Request metadata, error messages and stack traces, and log lines that identify accounts and companies by id. Reporter IPs are stripped before export by an OpenTelemetry processor, and Report IDs are removed or replaced by a one-way reference. Kept for 90 days. | North Europe (Ireland) |
| Microsoft Graph (Outlook for Business mail send) | Outbound transactional email | Recipient address, subject and body of platform-generated emails. Sent without saving a copy in the sending mailbox. Microsoft’s message trace keeps the sender, recipient, subject and delivery status of each email for 90 days, reporter notifications included; WhistleSafe support searches it only for staff addresses, never for reporter notifications. | EU multi-region (Microsoft 365 EU Data Boundary) |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Billing information only: the organisation’s name, email address, postal address, CVR/VAT number and preferred language, the chosen plan and any discount code; the card details the customer enters on Stripe’s own checkout page, which never pass through WhistleSafe; invoices and subscription status. No report, case, message, attachment or reporter data. | Ireland (EU); transferred to Stripe, LLC in the United States under the EU-U.S. Data Privacy Framework |
Things we explicitly do not use
For transparency, the following common third-party services are NOT sub-processors of personal data on the platform:
- No web analytics (Google Analytics, GTM, Hotjar, Mixpanel, etc.)
- No advertising or tracking pixels
- No third-party CDNs for fonts (Inter is self-hosted) or icons
- No SMS / phone-call providers (the platform does not offer voice or SMS intake)
- No content-delivery network for protected attachments — they are kept in a private Azure storage account, and our API streams each one only after checking access to the case.
International transfers
Microsoft stores and processes the platform’s personal data within the EU/EEA under its EU Data Boundary commitments, and offers the European Commission’s Standard Contractual Clauses for any transfer that may nonetheless cross EU borders (e.g. for global support engineering during incidents). These SCCs are referenced and incorporated into our Data Processing Agreement.
Stripe only receives billing information; reports, cases, messages, attachments and information about reporters are never sent to Stripe. Stripe processes that billing data outside the EU: under Stripe’s Data Processing Agreement, the data is transferred to Stripe, LLC in the United States. Stripe, LLC is certified under the EU-U.S. Data Privacy Framework, which Stripe’s Data Transfers Addendum makes the transfer mechanism; the European Commission’s Standard Contractual Clauses apply where the Framework does not.
Notifications of changes
We post sub-processor changes on this register and notify the company contact (typically the manager who registered the WhistleSafe account) at least 30 days before a change takes effect. To object to a change, reply to the notification email or contact kontakt@whistlesafe.dk.