Vaelo Compliance Whistleblowing Infrastructure
Vaelo Compliance provides secure whistleblowing channel infrastructure in full compliance with EU Directive 2019/1937 and national transpositions.
Legal / Trade Name: Vaelo Compliance Systems
Web Domain: https://vaelo.trycode.cloud
Jurisdiction & Statutory Law: European Union (GDPR Regulation 2016/679 & EU Directive 2019/1937)
Privacy Contact: contact@trycode.cloud
Under Article 4 of the EU General Data Protection Regulation (GDPR):
Our platform is built on 'Privacy by Design' principles:
IP addresses, user headers, and file metadata (EXIF, author tags) are purged at the server boundary before any database storage.
All data in transit uses TLS 1.3. Reports at rest are encrypted with individual 256-bit AES keys.
We process only the absolute minimum required for secure operation:
| Category | Data Types | Purpose |
|---|---|---|
| Anonymous Whistleblowers | Zero identifying data (Cryptographic Access Token only) | Enable two-way follow-up without identity disclosure |
| Identified Whistleblowers | Name, contact email, position (optional) | Direct communication when explicitly requested |
| Compliance Officers & Admins | Full name, work email, encrypted credentials | Multi-factor authentication (MFA) & case management |
Processing is grounded in GDPR Articles 6 and 9:
Data is retained only as long as necessary for investigation and legal proceedings:
• Unfounded / Rejected Reports: Automatically purged within 60 days of case closure.
• Resolved Investigations: Retained for the statutory period set by client organization (max 3 years under EU standards).
• Encrypted Backups: Overwritten and destroyed every 30 days.
Complete transparency regarding tracking:
Public Whistleblower Portals (/report/): ZERO tracking cookies or third-party analytics (GTM/Clarity) to guarantee absolute anonymity.
Website & Workspace: Strictly necessary session cookies and optional performance cookies.
All report data is hosted in EU data centers (Frankfurt / Dublin) under ISO 27001 and SOC 2 certifications.
Hosting Infrastructure: Cloud Infrastructure: Hetzner / Deno Deploy (EU Servers)
B2B Payments Processing: B2B Billing: Stripe Payments Europe Ltd.
Transactional Email Delivery: Transactional Email: Resend with TLS 1.3
Data subjects possess statutory rights of access, rectification, erasure, and restriction under GDPR Articles 15-22.
For questions or data subject requests, contact our privacy team:
Privacy Contact: contact@trycode.cloud
Email: contact@trycode.cloud
You retain the statutory right to lodge a complaint with your competent EU Member State Data Protection Authority.
Our compliance security team is ready to answer questions regarding GDPR and whistleblower protection laws.