Skip to main content
Required by EU law for organizations with 50+ employees

Data Processing Agreement #

Effective date: September 13, 2026

Last updated: September 13, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and EthicsPortal (“Processor”) for the provision of the EthicsPortal whistleblower reporting platform (“Service”).

The organization acceptance incorporates this DPA together with the Terms of Service identified in the same acceptance record. It does not incorporate the public DORA material. A financial entity that requires DORA-specific terms must enter a separate written DORA order signed by both parties.

Need a signed copy? Contact legal@ethicsportal.eu to request a countersigned PDF version of this DPA for your records.

A financial entity in DORA scope? The DORA contracting template identifies the subjects to be completed in a separate bilateral order. Publication, subscription or acceptance of this DPA does not make that template binding.


1. Parties #

Controller: The organization that subscribes to EthicsPortal and determines the purposes and means of processing personal data through the Service.

Processor: EthicsPortal, a trade name used by Yaroslav Shmarov, a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland (NIP: 5272755790), at ul. Obrzeżna 1A, 02-691 Warsaw, Poland. Contact: legal@ethicsportal.eu .


2. Scope and purpose of processing #

The Processor processes personal data on behalf of the Controller solely to provide the Service, which includes:

The Processor does not process personal data covered by this DPA for any purpose other than providing the Service as instructed by the Controller. Account administration, contracting, billing, fraud prevention and marketing activities undertaken for the Processor’s own business purposes fall outside this DPA and are described in the Privacy Notice .


3. Types of personal data processed #

Data categoryExamplesSafeguard applied
Reporter identity (optional)Name, email address, phone numberYes (non-deterministic)
Report contentDescription of the reported concernYes (non-deterministic)
Communication contentMessages between reporter and case handlerYes (non-deterministic)
File attachmentsDocuments, images, audio, video uploaded by reportersMetadata removal for supported formats; not every field guaranteed
Access codesRandom case identifiers used for lookup; reporter passcodes stored separately as digestsCase identifiers stored for lookup; passcodes hashed
Handler and admin dataName, email address, role, organization membershipNo (operational data)
Audit log entriesTimestamps, actor identity, action typeNo (integrity-critical records)
Technical dataOne-way hashed IP addresses used for rate limitingPseudonymized; treated as personal data where GDPR applies

4. Categories of data subjects #


5. Duration of processing #

The Processor processes personal data for the duration of the Controller’s subscription to the Service. Upon termination:


6. Obligations of the Processor #

6.1 Processing instructions #

The Processor processes personal data only on documented instructions from the Controller, unless required to do so by EU or member state law. If such a legal requirement arises, the Processor will inform the Controller before processing, unless the law prohibits such notification.

6.2 Confidentiality #

All persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

6.3 Security measures #

The Processor implements and maintains the following technical and organizational measures. The Security page provides current operational detail but does not amend these agreed measures unless a signed order expressly incorporates a dated version:

Security vulnerabilities and incident reports may be sent to security@ethicsportal.eu . Data-subject and privacy inquiries may be sent to privacy@ethicsportal.eu .

6.4 Sub-processors #

The Processor uses the sub-processors listed in Section 8. The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object to the change; if no resolution is reached, the Controller may terminate the agreement.

6.5 Data subject rights #

The Processor assists the Controller in responding to requests from data subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection) by providing the necessary technical capabilities within the Service.

6.6 Data breach notification #

In the event of a personal data breach, the Processor will notify the Controller without undue delay after becoming aware of the breach. To the extent available at the time, the notification will include:

6.7 Data Protection Impact Assessments #

The Processor assists the Controller with Data Protection Impact Assessments and prior consultations with supervisory authorities, to the extent that the Processor’s processing activities require such assistance.

6.8 Deletion and return of data #

After the end of the Service, the Processor will, at the Controller’s choice:

unless EU or member state law requires continued storage. The Controller may give its choice before or after the effective termination date, through available organization-deletion controls or by written request. Until the choice is carried out, processing is restricted as described in Section 5. Backup copies are isolated from ordinary use and expire through the backup lifecycle described there. A deletion confirmation identifies any legally required retention and the applicable backup-expiry period; it is not a representation that every residual copy disappears instantaneously.

If the Controller reasonably requires an additional portability format for migration or regulatory review, the Processor will assess the request in good faith and, where technically feasible, provide it under a separate written request.

6.9 Audit rights #

The Processor makes available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations. The Controller may conduct audits, including inspections, either directly or through a mandated independent auditor, subject to reasonable advance notice (normally at least 30 days) and during normal business hours, unless a shorter period is reasonably required by a supervisory authority or documented urgent risk. The audit must relate to processing under this DPA, avoid access to other customers’ data, and observe reasonable confidentiality and security procedures. The Processor will cooperate. The Controller bears its auditor’s costs; additional Processor assistance beyond information and reasonable cooperation required by Article 28 may be charged at a rate agreed in writing before that additional work begins.

Where the Controller is a financial entity within the scope of Regulation (EU) 2022/2554 (DORA), DORA-specific cooperation, authority access and any extended rights under Article 30 are governed only by a separate DORA order signed by both parties. The Controller’s unilateral classification does not amend this DPA. Equivalent downstream rights required by Delegated Regulation (EU) 2025/532 must be verified before a CIF order is signed.

The Processor operates no office or data centre of its own. Its direct audit surface is this documentation and the application, and audit rights are exercised remotely and documentarily. Supplier environments are not represented as directly accessible unless the required rights have been verified in the signed DORA order.

6.10 No AI or LLM processing of report content #

The Processor commits that personal data processed under this DPA — including report content, reporter identity, handler messages, file attachments, and audit log entries — is not transmitted to any large language model, generative AI service, or AI-based classifier, whether operated by the Processor or by a third party (including but not limited to OpenAI, Anthropic, Google, and Mistral). The Service does not perform AI-driven categorisation, triage, summarisation, translation, or suggested replies on personal data. The Controller may rely on this commitment when assessing automated decision-making obligations under Art. 22 GDPR and when scoping sub-processor disclosure in its own privacy notices and Data Protection Impact Assessments. Any change to this commitment would be a material change to the Service and would be notified to the Controller under Section 6.4 (Sub-processors) and Section 11 (Term and termination).

Self-hosted statistical machine translation that runs entirely on Processor-controlled infrastructure (no data leaves Processor infrastructure, no external inference call) is not within the scope of this restriction and may be used to translate reporter or handler messages where the Controller has enabled it.

This commitment is reviewed annually. The “Last updated” date at the top of this DPA reflects the most recent affirmation. If the Processor at any point intends to introduce AI or LLM processing of personal data covered by this DPA, the Processor will notify the Controller in accordance with Section 6.4 and the change will take effect no earlier than the notice period stated there.

6.11 Customer-managed encryption keys (BYOK) #

The Service does not currently support customer-managed encryption keys, whether described as bring-your-own-key (BYOK), hold-your-own-key (HYOK), or external key management service (KMS) integration. The database fields listed in Section 6.3 use application-level encryption with Processor-managed keys. This does not establish whole-database, backup, or attachment encryption at rest. It is not a representation that customer-managed keys are legally incompatible with Directive 2019/1937 or that key destruction alone guarantees deletion of every copy.

The Processor’s encryption-at-rest scheme, non-deterministic encryption properties, and key isolation are documented on the Security page. A change to this position would be a material change to the Service and would be notified to the Controller under Section 6.4 (Sub-processors) and Section 11 (Term and termination).

6.12 Responsibility for personnel, sub-processors, and infrastructure #

Subject to the limitations of liability in Section 10, the Processor is responsible for:


7. Obligations of the Controller #

The Controller is responsible for:


8. Sub-processors #

The following sub-processors are authorized as of the effective date of this DPA:

Sub-processorPurposeLocation
Hetzner Online GmbHApplication hosting, database, and file attachment storageNuremberg, Germany (EU)
Mailjet (Sinch)Transactional email, including reporter notifications when email is providedFrance (EU)
AppSignal B.V.Error and performance monitoring of the applicationNetherlands (EU)

Stripe is used for subscription billing and payment processing. It is not used to process whistleblower reports or case data and is therefore not a sub-processor for the processing covered by this DPA. Subscription and billing processing is described separately in the Privacy Notice . Depending on the processing activity, Stripe acts as EthicsPortal’s processor and/or as an independent controller under Stripe’s applicable terms and privacy notice.

The Cloudflare-delivered marketing site is likewise outside the processing performed on the Controller’s behalf under this DPA. Its public-site role is described separately in the Privacy Notice .

No AI or LLM sub-processor. No large language model, generative AI service, or AI-based classifier is a sub-processor of the Processor. Personal data processed under this DPA is not transmitted to OpenAI, Anthropic, Google, Mistral, or any other AI inference provider. See Section 6.10.


9. International data transfers #

The application, database and file attachments are hosted in the European Union with Hetzner. That location does not establish that every supplier activity stays in the EEA. Mailjet’s published chain includes US-based support providers, and AppSignal lists a US-based transactional-email provider. Their involvement does not by itself prove that report content is transferred there; their account-specific access and data flows require verification. Where processing on the Controller’s behalf involves a restricted transfer outside the EEA, the Processor will ensure a lawful transfer mechanism and applicable safeguards under GDPR Chapter V. The Processor will disclose material changes to the sub-processor chain under Section 6.4. The Processor does not promise that all email or telemetry data remains within the EEA.


10. Liability #

Each party’s liability under this DPA is subject to the limitations of liability set out in the main service agreement between the parties. To the maximum extent permitted by law, claims arising out of or relating to this DPA form part of the same aggregate liability cap that applies to the Service.


11. Term and termination #

This DPA takes effect when the Controller begins using the Service and remains in effect for as long as the Processor processes personal data on behalf of the Controller. The obligations in this DPA survive termination to the extent necessary to complete the deletion or return of personal data.


12. Governing law #

This DPA is governed by the laws of the Republic of Poland, without regard to conflict of laws principles. The competent courts of Warsaw, Poland have jurisdiction over disputes arising from this DPA, subject to any mandatory jurisdiction rules that apply.


Contact #

For questions about this DPA or to request a signed copy:

EthicsPortal Yaroslav Shmarov ul. Obrzeżna 1A, 02-691 Warsaw, Poland legal@ethicsportal.eu

Last updated: