Data Processing Agreement #
Effective date: September 13, 2026
Last updated: September 13, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and EthicsPortal (“Processor”) for the provision of the EthicsPortal whistleblower reporting platform (“Service”).
The organization acceptance incorporates this DPA together with the Terms of Service identified in the same acceptance record. It does not incorporate the public DORA material. A financial entity that requires DORA-specific terms must enter a separate written DORA order signed by both parties.
Need a signed copy? Contact legal@ethicsportal.eu to request a countersigned PDF version of this DPA for your records.
A financial entity in DORA scope? The DORA contracting template identifies the subjects to be completed in a separate bilateral order. Publication, subscription or acceptance of this DPA does not make that template binding.
1. Parties #
Controller: The organization that subscribes to EthicsPortal and determines the purposes and means of processing personal data through the Service.
Processor: EthicsPortal, a trade name used by Yaroslav Shmarov, a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland (NIP: 5272755790), at ul. Obrzeżna 1A, 02-691 Warsaw, Poland. Contact: legal@ethicsportal.eu .
2. Scope and purpose of processing #
The Processor processes personal data on behalf of the Controller solely to provide the Service, which includes:
- Receiving and storing whistleblower reports
- Enabling secure communication between reporters and case handlers
- Managing case workflows (assignment, status tracking, resolution)
- Generating audit logs and compliance records
- Sending transactional email notifications to case handlers and organization administrators and, when a reporter provides an email address, receipt and new-message notifications to that reporter
The Processor does not process personal data covered by this DPA for any purpose other than providing the Service as instructed by the Controller. Account administration, contracting, billing, fraud prevention and marketing activities undertaken for the Processor’s own business purposes fall outside this DPA and are described in the Privacy Notice .
3. Types of personal data processed #
| Data category | Examples | Safeguard applied |
|---|---|---|
| Reporter identity (optional) | Name, email address, phone number | Yes (non-deterministic) |
| Report content | Description of the reported concern | Yes (non-deterministic) |
| Communication content | Messages between reporter and case handler | Yes (non-deterministic) |
| File attachments | Documents, images, audio, video uploaded by reporters | Metadata removal for supported formats; not every field guaranteed |
| Access codes | Random case identifiers used for lookup; reporter passcodes stored separately as digests | Case identifiers stored for lookup; passcodes hashed |
| Handler and admin data | Name, email address, role, organization membership | No (operational data) |
| Audit log entries | Timestamps, actor identity, action type | No (integrity-critical records) |
| Technical data | One-way hashed IP addresses used for rate limiting | Pseudonymized; treated as personal data where GDPR applies |
4. Categories of data subjects #
- Whistleblowers / reporters — individuals who submit reports through the portal (may be anonymous)
- Case handlers — individuals designated by the Controller to receive and manage reports
- Organization administrators — individuals who manage the Controller’s EthicsPortal account and settings
5. Duration of processing #
The Processor processes personal data for the duration of the Controller’s subscription to the Service. Upon termination:
- The Controller may export their data before the subscription ends.
- Before termination, report data follows the Controller’s configured retention instruction (12, 24, 36, 48, or 60 months after report closure). A report left with no activity for 18 months is closed automatically so that the retention period begins.
- Subscription termination stops ordinary Service access but does not itself override the Controller’s documented retention instructions.
- After the Service ends, the Processor will, at the Controller’s choice, return or delete personal data and delete existing copies unless EU or member state law requires storage. The Controller may give that instruction before or after the effective termination date, through available organization-deletion controls or by written request.
- Until the instruction is completed, the Processor restricts processing to secure storage, return or deletion, and processing required by law or security. Backup copies expire through the documented backup lifecycle, currently no later than 28 days after production deletion, and are not restored except for disaster recovery. Application-encrypted fields remain encrypted in database backups; whole-dump encryption is not currently verified.
6. Obligations of the Processor #
6.1 Processing instructions #
The Processor processes personal data only on documented instructions from the Controller, unless required to do so by EU or member state law. If such a legal requirement arises, the Processor will inform the Controller before processing, unless the law prohibits such notification.
6.2 Confidentiality #
All persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
6.3 Security measures #
The Processor implements and maintains the following technical and organizational measures. The Security page provides current operational detail but does not amend these agreed measures unless a signed order expressly incorporates a dated version:
- Non-deterministic application-level encryption at rest for report text, reporter contact fields, intake answers and case messages and notes
- No storage of raw reporter IP addresses in the database (one-way hashing for rate limiting only)
- Metadata stripping for supported uploaded image, document, audio and video formats before storage; embedded content and every possible metadata field cannot be guaranteed removed
- Tenant-scoped role-based access controls
- Append-only records for defined report and account events; not every read or action is logged
- Rate limiting for reporter submission, access-code lookup and message creation
- HTTPS/TLS for all connections
- CSRF protection
Security vulnerabilities and incident reports may be sent to security@ethicsportal.eu . Data-subject and privacy inquiries may be sent to privacy@ethicsportal.eu .
6.4 Sub-processors #
The Processor uses the sub-processors listed in Section 8. The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object to the change; if no resolution is reached, the Controller may terminate the agreement.
6.5 Data subject rights #
The Processor assists the Controller in responding to requests from data subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection) by providing the necessary technical capabilities within the Service.
6.6 Data breach notification #
In the event of a personal data breach, the Processor will notify the Controller without undue delay after becoming aware of the breach. To the extent available at the time, the notification will include:
- A description of the nature of the breach
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
6.7 Data Protection Impact Assessments #
The Processor assists the Controller with Data Protection Impact Assessments and prior consultations with supervisory authorities, to the extent that the Processor’s processing activities require such assistance.
6.8 Deletion and return of data #
After the end of the Service, the Processor will, at the Controller’s choice:
- Return all personal data to the Controller in the export formats made available by the Service at the time of termination, including PDF case exports and associated attachments, or
- Delete personal data from production systems and confirm completion in writing
unless EU or member state law requires continued storage. The Controller may give its choice before or after the effective termination date, through available organization-deletion controls or by written request. Until the choice is carried out, processing is restricted as described in Section 5. Backup copies are isolated from ordinary use and expire through the backup lifecycle described there. A deletion confirmation identifies any legally required retention and the applicable backup-expiry period; it is not a representation that every residual copy disappears instantaneously.
If the Controller reasonably requires an additional portability format for migration or regulatory review, the Processor will assess the request in good faith and, where technically feasible, provide it under a separate written request.
6.9 Audit rights #
The Processor makes available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations. The Controller may conduct audits, including inspections, either directly or through a mandated independent auditor, subject to reasonable advance notice (normally at least 30 days) and during normal business hours, unless a shorter period is reasonably required by a supervisory authority or documented urgent risk. The audit must relate to processing under this DPA, avoid access to other customers’ data, and observe reasonable confidentiality and security procedures. The Processor will cooperate. The Controller bears its auditor’s costs; additional Processor assistance beyond information and reasonable cooperation required by Article 28 may be charged at a rate agreed in writing before that additional work begins.
Where the Controller is a financial entity within the scope of Regulation (EU) 2022/2554 (DORA), DORA-specific cooperation, authority access and any extended rights under Article 30 are governed only by a separate DORA order signed by both parties. The Controller’s unilateral classification does not amend this DPA. Equivalent downstream rights required by Delegated Regulation (EU) 2025/532 must be verified before a CIF order is signed.
The Processor operates no office or data centre of its own. Its direct audit surface is this documentation and the application, and audit rights are exercised remotely and documentarily. Supplier environments are not represented as directly accessible unless the required rights have been verified in the signed DORA order.
6.10 No AI or LLM processing of report content #
The Processor commits that personal data processed under this DPA — including report content, reporter identity, handler messages, file attachments, and audit log entries — is not transmitted to any large language model, generative AI service, or AI-based classifier, whether operated by the Processor or by a third party (including but not limited to OpenAI, Anthropic, Google, and Mistral). The Service does not perform AI-driven categorisation, triage, summarisation, translation, or suggested replies on personal data. The Controller may rely on this commitment when assessing automated decision-making obligations under Art. 22 GDPR and when scoping sub-processor disclosure in its own privacy notices and Data Protection Impact Assessments. Any change to this commitment would be a material change to the Service and would be notified to the Controller under Section 6.4 (Sub-processors) and Section 11 (Term and termination).
Self-hosted statistical machine translation that runs entirely on Processor-controlled infrastructure (no data leaves Processor infrastructure, no external inference call) is not within the scope of this restriction and may be used to translate reporter or handler messages where the Controller has enabled it.
This commitment is reviewed annually. The “Last updated” date at the top of this DPA reflects the most recent affirmation. If the Processor at any point intends to introduce AI or LLM processing of personal data covered by this DPA, the Processor will notify the Controller in accordance with Section 6.4 and the change will take effect no earlier than the notice period stated there.
6.11 Customer-managed encryption keys (BYOK) #
The Service does not currently support customer-managed encryption keys, whether described as bring-your-own-key (BYOK), hold-your-own-key (HYOK), or external key management service (KMS) integration. The database fields listed in Section 6.3 use application-level encryption with Processor-managed keys. This does not establish whole-database, backup, or attachment encryption at rest. It is not a representation that customer-managed keys are legally incompatible with Directive 2019/1937 or that key destruction alone guarantees deletion of every copy.
The Processor’s encryption-at-rest scheme, non-deterministic encryption properties, and key isolation are documented on the Security page. A change to this position would be a material change to the Service and would be notified to the Controller under Section 6.4 (Sub-processors) and Section 11 (Term and termination).
6.12 Responsibility for personnel, sub-processors, and infrastructure #
Subject to the limitations of liability in Section 10, the Processor is responsible for:
- Personnel. The acts and omissions of its employees and any other persons it authorizes to process personal data under this DPA — each bound by the confidentiality obligation in Section 6.2 — as if they were the Processor’s own acts and omissions.
- Sub-processors. The performance of the sub-processors listed in Section 8. Where an engaged sub-processor fails to fulfil its data-protection obligations, the Processor remains liable to the Controller for the performance of that sub-processor’s obligations, in accordance with Article 28(4) GDPR.
- Infrastructure. Compliance with the security and availability obligations in this DPA for infrastructure under its control. This allocation does not create a guarantee against every outage or attack; liability depends on a breach of this DPA, the Terms, or applicable law and remains subject to Section 10. It does not extend to failures originating in the Controller’s systems, devices, or network, or to events beyond the Processor’s reasonable control.
7. Obligations of the Controller #
The Controller is responsible for:
- Ensuring a lawful basis for processing personal data through the Service
- Providing required privacy notices to data subjects (EthicsPortal displays a privacy notice on the portal submission form)
- Configuring appropriate data retention periods within the Service
- Designating authorized handlers and administrators
- Responding to data subject requests, with assistance from the Processor as described above
- Ensuring that its instructions, configurations, users and use of exports comply with applicable law
- Maintaining appropriate internal access controls, endpoint security, business continuity and tested export or exit procedures
- Providing timely and accurate information needed for assistance, cooperating with incident response, and taking reasonable steps to mitigate avoidable loss
8. Sub-processors #
The following sub-processors are authorized as of the effective date of this DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting, database, and file attachment storage | Nuremberg, Germany (EU) |
| Mailjet (Sinch) | Transactional email, including reporter notifications when email is provided | France (EU) |
| AppSignal B.V. | Error and performance monitoring of the application | Netherlands (EU) |
Stripe is used for subscription billing and payment processing. It is not used to process whistleblower reports or case data and is therefore not a sub-processor for the processing covered by this DPA. Subscription and billing processing is described separately in the Privacy Notice . Depending on the processing activity, Stripe acts as EthicsPortal’s processor and/or as an independent controller under Stripe’s applicable terms and privacy notice.
The Cloudflare-delivered marketing site is likewise outside the processing performed on the Controller’s behalf under this DPA. Its public-site role is described separately in the Privacy Notice .
No AI or LLM sub-processor. No large language model, generative AI service, or AI-based classifier is a sub-processor of the Processor. Personal data processed under this DPA is not transmitted to OpenAI, Anthropic, Google, Mistral, or any other AI inference provider. See Section 6.10.
9. International data transfers #
The application, database and file attachments are hosted in the European Union with Hetzner. That location does not establish that every supplier activity stays in the EEA. Mailjet’s published chain includes US-based support providers, and AppSignal lists a US-based transactional-email provider. Their involvement does not by itself prove that report content is transferred there; their account-specific access and data flows require verification. Where processing on the Controller’s behalf involves a restricted transfer outside the EEA, the Processor will ensure a lawful transfer mechanism and applicable safeguards under GDPR Chapter V. The Processor will disclose material changes to the sub-processor chain under Section 6.4. The Processor does not promise that all email or telemetry data remains within the EEA.
10. Liability #
Each party’s liability under this DPA is subject to the limitations of liability set out in the main service agreement between the parties. To the maximum extent permitted by law, claims arising out of or relating to this DPA form part of the same aggregate liability cap that applies to the Service.
11. Term and termination #
This DPA takes effect when the Controller begins using the Service and remains in effect for as long as the Processor processes personal data on behalf of the Controller. The obligations in this DPA survive termination to the extent necessary to complete the deletion or return of personal data.
12. Governing law #
This DPA is governed by the laws of the Republic of Poland, without regard to conflict of laws principles. The competent courts of Warsaw, Poland have jurisdiction over disputes arising from this DPA, subject to any mandatory jurisdiction rules that apply.
Contact #
For questions about this DPA or to request a signed copy:
EthicsPortal Yaroslav Shmarov ul. Obrzeżna 1A, 02-691 Warsaw, Poland legal@ethicsportal.eu
Last updated: