Privacy

Privacy Policy

This privacy policy explains which personal data is processed when using Hinweisportal and for which purposes.

Last updated: June 2026

A

Controller

The controller responsible for processing personal data in Hinweisportal is ePhilos AG.

B

Data we process

When using the portal, the following data in particular may be processed:

  • Account data such as name, email address, role and password hash for registered users.
  • Report data such as title, category, description, priority, status and timestamps.
  • Voluntary contact details from whistleblowers, if provided.
  • Messages and attachments submitted as part of a report.
  • Technical usage data required for sessions, security, language settings and operation.
C

Anonymous reports

Reports can be submitted without providing a name, email address or phone number. In that case, a one-time access code is generated so the report can later be accessed and communication can continue.

If you voluntarily provide contact details, they are used only to handle the relevant report.

D

Purposes and legal bases

Processing takes place to provide the whistleblowing portal, handle incoming reports, enable secure communication between whistleblowers and authorised persons, and fulfil legal documentation and compliance obligations.

The legal bases include Art. 6(1)(b), (c) and (f) GDPR and, where applicable, statutory obligations under whistleblower protection laws.

E

Cookies and technical data

The portal uses technically necessary cookies and similar storage mechanisms, for example for login, session protection, CSRF protection and language settings.

Analytics, marketing or tracking cookies are not set unless they are separately displayed and voluntarily accepted.

F

Recipients and access

Only authorised persons entrusted with handling reports have access to reports. Data is shared with third parties only where legally required, necessary for handling the report, or based on explicit consent.

Data is not shared for advertising purposes.

G

Retention

Personal data is stored only for as long as required for handling, documentation and statutory retention obligations.

Data that is no longer needed is deleted or anonymised unless legal obligations prevent this.

H

Security

The portal uses technical and organisational measures to protect data against unauthorised access, loss or misuse. These include access restrictions, encrypted transmission and role-based permissions.

I

Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. You may also withdraw consent at any time with effect for the future.

You also have the right to lodge a complaint with a competent data protection supervisory authority.

J

Changes to this policy

This privacy policy may be updated if the portal, processing activities or legal requirements change. The current version is always available on this page.

Questions about privacy?

If you have questions about the processing of your personal data or want to exercise your GDPR rights, please contact the controller.