WhistleTrack (hereinafter referred to, collectively and interchangeably, as “WhistleTrack”, “we”, “our” or “us”) considers the privacy of individuals to be fundamental, both for visitors to the Website or the platform and for any other affected parties who provide us with information as part of the provision of services (hereinafter and collectively, “you” or the “user”, and in the plural, “you” or the “users”).
In this regard, WhistleTrack undertakes to process your data in accordance with the personal data protection regulations applicable and in force at any given time. Specifically, WhistleTrack will comply with the requirements set out in Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (“LOPDGDD”), as well as those of Regulation (EU) 2016/679, of 27 April 2016, of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (“GDPR”), and any other applicable correlative regulations in force at any given time.
On this basis, WhistleTrack sets out its Privacy Policy in order to inform users about the processing of their data, as well as the fundamental principles on personal data protection that it applies. To this end, please refer to the sections below:
Who is the controller of your data?
Identity of the data controller: CPTI Consultores Técnicos, S.L.
Tax ID (N.I.F.): B80815038
Postal address: Calle Méjico nº 13, 28028, Madrid, Spain.
Email: info@whistletrack.com
What are the main purposes of processing your data?
The personal data provided and collected, whether through the forms available on the platform, website, emails and/or calls, will be used for the following purposes: (a) to respond to, attend to and manage the queries, questions and/or requests made by the various users; (b) to provide our services in accordance with the Legal Notice; (c) to ensure the correct technical operation of the Website and the whistleblowing platform; and (d) to use them for any other purpose required or permitted by applicable law or for which you have given your consent.
What is the legal basis for processing your data?
The legal bases for processing your personal data are: (a) the existence of a pre-contractual and/or contractual relationship; (b) where necessary for the satisfaction of legitimate interests pursued by WhistleTrack; (c) where you have given your consent; and (d) where necessary to comply with WhistleTrack's legal and regulatory obligations.
How long will we keep your data?
The data obtained will be kept for as long as your relationship with us is maintained, and even after its termination for the period necessary for the formulation, exercise or defense of claims and legal and contractual obligations, always duly blocked.
In the case of the platform, given that Law 2/2023, of 20 February, on the protection of persons who report regulatory infringements and the fight against corruption, requires its deletion and/or anonymization within a maximum period of 3 months, exceptionally extendable to 6, we will proceed accordingly on the platform once those deadlines are reached.
Who may be recipients of the data communication?
Depending on the purposes for which the personal information is collected, the following persons may access such information, interchangeably:
We process your data within the European Economic Area and, as a general rule, we engage service providers also located within the European Economic Area or in countries that have been declared to have an adequate level of protection.
If we need to use service providers that carry out processing outside the European Economic Area or in countries that have not been declared to have an adequate level of protection, we would ensure the security and legitimacy of the processing of your data.
To this end, we require appropriate safeguards from those service providers in accordance with the GDPR so that they have, for example, binding corporate rules guaranteeing the protection of information in a manner similar to that established by European standards, or that they sign the European Union's standard contractual clauses.
We will not sell or disclose to third parties any information or personal data that you have provided on our website and that may identify you directly or indirectly.
What are your rights when you provide us with your data?
If you have given consent for a specific purpose, you may withdraw it whenever you wish, without affecting the lawfulness of the processing based on consent prior to its withdrawal.
To exercise your rights, please notify us in writing to CPTI Consultores Técnicos, S.L., at C/ Méjico nº 13, 28028, Madrid, Spain,
or send us an email to: info@whistletrack.com.
If there are doubts about your identity, it may be necessary to provide a photocopy of your ID card or equivalent legally valid document proving your identity. To do so, you may use the templates and forms on the various rights provided by the Spanish Data Protection Agency on its official page).
We inform you of your right to file a complaint with the Supervisory Authority, specifically with the Spanish Data Protection Agency, and other competent public bodies for any claim arising from your personal data.
How do we protect your personal data?
In order to ensure the security of the information, WhistleTrack applies various technical and organizational measures to guarantee the appropriate level of security in accordance with applicable regulations. For the user's peace of mind, we inform you that our servers are hosted on Amazon Web Services, so we benefit from server-level security under ISO 27001.
In any case, WhistleTrack will take appropriate technical and organizational measures, both when designing the data processing system and at the time of processing itself, to preserve security and prevent unauthorized processing. However, despite the diligent implementation of such measures, the user should be aware that security measures on the Internet are not impregnable. WhistleTrack is not responsible for the actions of third parties who, breaching such measures, access the aforementioned data and information.
Confidentiality
The professionals working at WhistleTrack who have any kind of involvement in the services provided to the user are committed not to disclose or make use of the information they have accessed. The information supplied by the user shall, in any case, be considered confidential and may not be used for purposes other than those related to the management linked to their requests and the services contracted with WhistleTrack, where applicable. In this regard, we undertake not to disclose or reveal information about the user's claims, the reasons for the advice requested or the duration of their relationship with us.
Links
The Website may contain links to other websites. Please note that we are not responsible for the privacy and data processing of other websites. This Privacy Policy applies exclusively to the information collected on the Website. We recommend that you read the privacy and data processing policies of other websites that you link to from our Website or that you visit in any other way.
Social media
WhistleTrack has a presence on some of the main social media networks on the Internet, in respect of which it acts as data controller in relation to the data published by WhistleTrack.
WhistleTrack will process the data on each social network according to the rules established for that purpose by each social network. Therefore, and unless WhistleTrack states otherwise, we may inform our followers on the relevant social network about our activities, events and other related matters, including follower support, through the channels that the social network provides for that purpose.
WhistleTrack will not extract personal data from social networks unless the user gives us their express consent.