Legal

Privacy Policy

How we process personal data.

Last updated: August 2026

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for this website and the operation of the Hinweisbox platform is Hanvia GmbH, Gräfelfing, Germany (address as stated in the imprint). Where a company uses Hinweisbox as its internal reporting channel, that company is the controller for the processing of incoming reports; in that respect we act as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Collection and processing

When you access this website, our server automatically processes access data (IP address, date and time, requested resource, status code, user agent) in server log files. This data is required for operation, security and abuse prevention. If you submit a report through the reporting portal, we process only the content you voluntarily enter: category, urgency and your report text. If you register through a company area, we additionally process your email address, name and role.

Purposes of processing

Provision and operation of the platform, receipt and handling of reports within the meaning of the German Whistleblower Protection Act (HinSchG) and EU Directive 2021/1937, communication with whistleblowers via the access code, management of user accounts, and safeguarding IT security.

Reports are processed to fulfil a legal obligation of the reporting company (Art. 6 (1) (c) GDPR in conjunction with §§ 10, 11 HinSchG). Website operation and security logging are based on our legitimate interest (Art. 6 (1) (f) GDPR). Contract-related processing in the customer account is based on Art. 6 (1) (b) GDPR. Where a report contains special categories of personal data, processing is governed by Art. 9 (2) (g) GDPR in conjunction with § 10 HinSchG.

Anonymous reports

The reporting portal requires no sign-in, no name and no email address. The report record itself contains no identifying attributes and no IP address. You are identified solely by a randomly generated access code in the format HBX-XXXXXXXXXXXXXXXX, which is shown only to you and cannot be recovered by us. Please note that your IP address — as with any website request — briefly appears in the technical server log files; these log files are not linked to the report record. If you wish to remain fully anonymous, do not include details in the report text that could identify you.

Encryption

The report text and all messages within a case are stored encrypted with AES-256-GCM. Transport takes place exclusively over TLS. Without the decryption key the content is unreadable even if the database is accessed.

Hosting

The platform is operated on servers located in Germany. No personal data is transferred to third countries outside the European Economic Area as part of the reporting operation.

Retention period

Reports are stored for the retention period configured by the respective company and are then deleted automatically; the default is 90 days. § 11 (5) HinSchG provides for deletion three years after the proceedings have been concluded, unless longer statutory retention obligations apply. Server log files are deleted after a short period. Account data is stored for the duration of the contractual relationship.

Recipients

Access to a report is limited to the authorised individuals designated by the respective company for its internal reporting office. As technical service providers we use an email delivery service for notifications and our hosting provider; both are contractually bound as processors. Report content is not disclosed to any other third parties.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object (Art. 21 GDPR). In the case of anonymous reports we cannot attribute these rights for lack of identifiability (Art. 11 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority.

Cookies

This website does not use tracking or marketing cookies. For the operation of the signed-in area, an access token is stored locally in your browser; it is removed when you sign out.

Contact form

If you write to us via the contact form, we process your name, email address and message in order to handle your enquiry (Art. 6 (1) (b) or (f) GDPR). The contact form is not a reporting channel — to submit a report, please use only the reporting link provided by your organisation.

Data protection officer

For any data protection question and to exercise your data subject rights, contact us at [email protected].

Changes

We will adapt this privacy policy if the legal situation or our processing changes. The version published on this page at the time applies.