Skip to main content
Required by EU law for organizations with 50+ employees

Privacy Policy #

Effective date: February 17, 2026 Last updated: September 13, 2026

1. Introduction #

EthicsPortal (“we”, “us”, “our”) is a trade name used by Yaroslav Shmarov, a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland (NIP: 5272755790), at ul. Obrzeżna 1A, 02-691 Warsaw, Poland. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use EthicsPortal at ethicsportal.eu (the “Service”).

This notice explains our processing; it is not a request for consent. Where we rely on consent for a specific optional activity, we ask for it separately and you may withdraw it at any time.

Contact: privacy@ethicsportal.eu

Baseline contracting-party information is published on the trust page.

2. Information we collect #

2.1 Account information #

When you create an account, we collect:

Authentication is passwordless — we use magic links (one-time codes sent to your email). We do not collect or store passwords.

2.2 Payment information #

Subscription and billing payments are handled through Stripe-hosted Checkout and Billing Portal. We provide Stripe with the account email address and internal organization and customer identifiers needed to create and manage the subscription. Stripe directly collects the payer’s name, billing address, tax ID, and payment-method details. We do not receive or store full card or bank-account numbers.

For payment facilitation, Stripe processes personal data on our behalf. Stripe also processes some data as an independent controller for purposes it determines, including fraud prevention, regulatory compliance, and payment-network operation. Those activities are governed by Stripe’s Privacy Policy .

2.3 Server logs #

Our servers automatically record information when you access the Service, including:

Server logs are used for security monitoring and debugging. They are not used for advertising or tracking.

For the whistleblowing channel specifically, application logs contain no reporter IP addresses. The TLS proxy in front of the application keeps its own connection logs, which can include IP addresses and are not linked to reports.

2.4 Whistleblower report data #

When a whistleblower submits a report through an organization’s portal, we collect:

Report descriptions, reporter names, reporter contact details, and message contents are encrypted in the database using application-level encryption. Reporter IP addresses are not stored with reports, messages or audit records. Rate limiting uses a pseudonymized, keyed hash of the IP that is kept only for the rate-limit window. Application logs for the whistleblowing channel contain no IP addresses.

2.5 Personal data of third parties named in reports #

A whistleblower report may contain personal data about other people — for example, the person a report concerns, or witnesses. For this report data, EthicsPortal acts as a processor on behalf of the customer organization, which is the controller. The organization is responsible for the lawfulness of this processing and for providing any information required under Article 14 GDPR to the individuals concerned.

In line with Article 14(5)(b) GDPR and the confidentiality requirements of the EU Whistleblower Directive (2019/1937), notifying a named individual may be deferred or restricted where doing so would prejudice an investigation or compromise the protection of the whistleblower’s identity.

3. How we use your information #

We use the information we collect to:

We do not sell your personal information. We do not use your data for advertising.

4. Third-party services #

We share data with the following third-party services, only as necessary to provide the Service:

ServicePurposeData shared
StripeSubscription billing and payment processingAccount email and internal organization/customer identifiers; payer name, billing address, tax ID, and payment-method details collected directly by Stripe
Hetzner Object StorageFile uploads (avatars, attachments)Uploaded files
MailjetTransactional email delivery, including optional reporter receipts and new-message noticesRecipient email address and message content; reporter notices include a report access code and link but not the report narrative
CloudflarePublic-site CDN, DDoS protection, and Web AnalyticsVisitor IP address and request headers for delivery and security; page views, referrer, browser type, and country for analytics; no analytics cookies
Plausible AnalyticsPrivacy-friendly website analytics (EU-hosted, Germany)Page views, referrer, browser type, country (anonymous, no cookies, IP not stored, no personal data). Loaded only on the public marketing website — never on the application or the whistleblowing channel. See Plausible’s Data Policy
AppSignalError and exception tracking, application performance monitoringError details and request context from production; reporter portal requests are configured to be excluded from AppSignal transaction monitoring

Each third-party service is governed by its own privacy policy. We encourage you to review them.

5. Cookies #

We use the following cookies:

CookiePurposeDuration
_ethicsportal_sessionSession management (authentication)30 days
session_tokenSigned session identifier for persistent loginServer-side session expires after 14 days of inactivity
localeStores your language preference1 year

A temporary pending_authentication_token cookie (15 minutes) is used during the magic link sign-in process.

All first-party cookies are set with the Secure and HttpOnly flags in production. We do not use third-party tracking cookies or advertising cookies. CSRF protection is handled via tokens embedded in HTML forms, not cookies.

6. Data storage and security #

While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please contact us at security@ethicsportal.eu .

7. Data retention #

When you close your account, account-access data is removed. Limited attributed records may remain under the Controller’s documented retention instructions, applicable legal obligations, or the establishment, exercise or defence of legal claims. Section 9 sets out what remains and why.

8. Your rights under GDPR #

Because we are based in the European Union, the General Data Protection Regulation (GDPR) applies. You have the right to:

How to exercise your rights: You can manage most of your data directly through your account settings. To delete your account, visit your account settings page. For any other requests, email us at privacy@ethicsportal.eu .

If you submitted a whistleblower report: the organization whose whistleblowing channel you used is the controller of that report, and EthicsPortal acts as its processor. You can access and download a full copy of your report at any time through the online reporting form using your access code and passcode. To correct information, add a message to your report; for any other request, contact the organization (we will assist it as processor). Erasure may be limited by the Controller’s documented retention decision and any applicable legal obligation or legal-claims exception.

Data protection contact: Inquiries regarding our data protection practices may be directed to privacy@ethicsportal.eu .

Our legal basis for processing your data is:

9. Account and data deletion #

You can close your account at any time from your account settings. Your email address is replaced with a non-routable placeholder, and your two-factor credentials, active sessions, API tokens, language preference, and marketing preferences are permanently removed. You can no longer sign in, and we can no longer contact you through the Service.

If your account never acted inside an organization, the account record is deleted outright. If it did, your memberships are deactivated rather than deleted, and the case notes, messages, and audit entries attributed to them remain to preserve attribution in the organization’s compliance record. The Controller determines the retention period under its documented instructions and applicable law; GDPR erasure rights remain subject to any applicable exceptions for legal obligations or legal claims.

Three things therefore survive closure:

Deletion is refused while you own an organization, are its only administrator, or are its designated compliance officer. Transfer or reassign the role first.

10. Children’s privacy #

Customer accounts are not directed at children under 16. An organization’s whistleblowing channel may nevertheless receive a report from a minor where the organization makes that channel available. The organization is the Controller of report data and decides how a deletion request is handled; we assist it as processor. For personal data that we control directly, contact privacy@ethicsportal.eu and we will assess and act on the request under applicable law.

11. International data transfers #

Core whistleblower report data is stored on servers in Germany (EU). The public marketing site is delivered through Cloudflare (United States); the reporting and handler portals are not. This public-site processing is outside the customer-instructed reporting-data processing chain covered by the DPA. For transfers of public-site data from the EEA to the United States, Cloudflare states that it relies on the EU-U.S. Data Privacy Framework and, if its certification lapses or is invalid, Standard Contractual Clauses with supplementary measures under the Cloudflare Customer DPA .

Mailjet and AppSignal are EU-based direct suppliers, but their published downstream chains include providers outside the EEA. EU hosting does not establish that all support or telemetry processing stays in the EEA. Restricted transfers, where they occur, require the applicable safeguards under GDPR Chapter V; see the DPA for the customer-instructed processing position.

Stripe Payments Europe is established in Ireland, but Stripe may process billing and payment data in other countries. Stripe states that it uses the applicable lawful transfer mechanisms, including adequacy decisions and Standard Contractual Clauses, as described in the Stripe Data Processing Agreement .

12. Job applicants #

When you apply for a role with us (for example, by emailing careers@ethicsportal.eu ), we collect and process:

Legal basis: processing is necessary to take steps at your request prior to entering a contract, and our legitimate interest in assessing candidates and running a fair hiring process. We do not ask for, and ask that you do not send, special-category data (such as health, religion, or trade union membership) or your pay history from previous roles.

Retention: we keep application data only as long as needed to assess your application and fill the role. If you are not hired, we delete your application data after the process closes, unless you ask us to keep it on file for future roles, in which case we hold it for up to 12 months.

You have the same GDPR rights over your application data as set out in section 8. To exercise them, or to ask us to delete your application, email privacy@ethicsportal.eu .

13. Changes to this policy #

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through an in-app notification. The “Last updated” date at the top of this page indicates when the policy was last revised.

This policy is a notice, not a contract, and does not require acceptance. Changes apply from the stated effective or last-updated date, subject to any notice required by applicable law.

14. Contact us #

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

General: support@ethicsportal.eu Privacy / GDPR rights: privacy@ethicsportal.eu Data protection contact: privacy@ethicsportal.eu Security disclosures: security@ethicsportal.eu Legal / DPA: legal@ethicsportal.eu Location: Warsaw, Poland

Last updated: