Privacy & Data Protection Policy
Vaelo Compliance Whistleblowing Infrastructure
Table of Contents
1. Scope & Entity Identification
Vaelo Compliance provides secure whistleblowing channel infrastructure in full compliance with EU Directive 2019/1937 and national transpositions.
Legal / Trade Name: Vaelo Compliance Systems
Web Domain: https://vaelo.trycode.cloud
Jurisdiction & Statutory Law: European Union (GDPR Regulation 2016/679 & EU Directive 2019/1937)
Privacy Contact: contact@trycode.cloud
2. Legal Roles: Data Controller vs Data Processor
Under Article 4 of the EU General Data Protection Regulation (GDPR):
- Vaelo as Data Processor (Art. 28 GDPR): On public client whistleblower entry portals, Vaelo operates strictly as a Data Processor. The client company is the Data Controller.
- Vaelo as Data Controller: Vaelo acts as Data Controller solely regarding workspace administrator account data (Stripe billing, login email).
3. Anonymity, Encryption & Metadata Protection Architecture
Our platform is built on 'Privacy by Design' principles:
IP & Metadata Stripping
IP addresses, user headers, and file metadata (EXIF, author tags) are purged at the server boundary before any database storage.
AES-256 & TLS 1.3 Encryption
All data in transit uses TLS 1.3. Reports at rest are encrypted with individual 256-bit AES keys.
4. Categories of Processed Personal Data
We process only the absolute minimum required for secure operation:
| Category | Data Types | Purpose |
|---|---|---|
| Anonymous Whistleblowers | Zero identifying data (Cryptographic Access Token only) | Enable two-way follow-up without identity disclosure |
| Identified Whistleblowers | Name, contact email, position (optional) | Direct communication when explicitly requested |
| Compliance Officers & Admins | Full name, work email, encrypted credentials | Multi-factor authentication (MFA) & case management |
5. Legal Basis for Processing (GDPR & EU Directive)
Processing is grounded in GDPR Articles 6 and 9:
- Compliance with Legal Obligation (Art. 6(1)(c) GDPR): Fulfillment of EU Whistleblower Protection Directive 2019/1937 and national statutory transpositions.
- Legitimate Interest (Art. 6(1)(f) GDPR): Prevention of corporate crime, fraud, money laundering, and ethical breaches.
6. Data Retention & Automated Purging
Data is retained only as long as necessary for investigation and legal proceedings:
• Unfounded / Rejected Reports: Automatically purged within 60 days of case closure.
• Resolved Investigations: Retained for the statutory period set by client organization (max 3 years under EU standards).
• Encrypted Backups: Overwritten and destroyed every 30 days.
7. Cookies & Tracking Technologies
Complete transparency regarding tracking:
Public Whistleblower Portals (/report/): ZERO tracking cookies or third-party analytics (GTM/Clarity) to guarantee absolute anonymity.
Website & Workspace: Strictly necessary session cookies and optional performance cookies.
8. Sub-processors & EU Sovereign Hosting
All report data is hosted in EU data centers (Frankfurt / Dublin) under ISO 27001 and SOC 2 certifications.
Hosting Infrastructure: Cloud Infrastructure: Hetzner / Deno Deploy (EU Servers)
B2B Payments Processing: B2B Billing: Stripe Payments Europe Ltd.
Transactional Email Delivery: Transactional Email: Resend with TLS 1.3
9. Data Subject Rights
Data subjects possess statutory rights of access, rectification, erasure, and restriction under GDPR Articles 15-22.
10. DPO Contact & Supervisory Authority
For questions or data subject requests, contact our privacy team:
Privacy Contact: contact@trycode.cloud
Email: contact@trycode.cloud
You retain the statutory right to lodge a complaint with your competent EU Member State Data Protection Authority.
Have questions about privacy?
Our compliance security team is ready to answer questions regarding GDPR and whistleblower protection laws.