Vaelo ComplianceSecure Transparency Protocol
Effective Date: July 22, 2026
Compliant with GDPR & EU Whistleblower Directive 2019/1937

Privacy & Data Protection Policy

Vaelo Compliance Whistleblowing Infrastructure

AES-256 Encryption
Zero IP/Metadata Logs
EU Sovereign Cloud
ISO/IEC 27001 Certified

Table of Contents

1. Scope & Entity Identification

Vaelo Compliance provides secure whistleblowing channel infrastructure in full compliance with EU Directive 2019/1937 and national transpositions.

Legal / Trade Name: Vaelo Compliance Systems

Web Domain: https://vaelo.trycode.cloud

Jurisdiction & Statutory Law: European Union (GDPR Regulation 2016/679 & EU Directive 2019/1937)

Privacy Contact: contact@trycode.cloud

2. Legal Roles: Data Controller vs Data Processor

Under Article 4 of the EU General Data Protection Regulation (GDPR):

  • Vaelo as Data Processor (Art. 28 GDPR): On public client whistleblower entry portals, Vaelo operates strictly as a Data Processor. The client company is the Data Controller.
  • Vaelo as Data Controller: Vaelo acts as Data Controller solely regarding workspace administrator account data (Stripe billing, login email).

3. Anonymity, Encryption & Metadata Protection Architecture

Our platform is built on 'Privacy by Design' principles:

IP & Metadata Stripping

IP addresses, user headers, and file metadata (EXIF, author tags) are purged at the server boundary before any database storage.

AES-256 & TLS 1.3 Encryption

All data in transit uses TLS 1.3. Reports at rest are encrypted with individual 256-bit AES keys.

4. Categories of Processed Personal Data

We process only the absolute minimum required for secure operation:

CategoryData TypesPurpose
Anonymous WhistleblowersZero identifying data (Cryptographic Access Token only)Enable two-way follow-up without identity disclosure
Identified WhistleblowersName, contact email, position (optional)Direct communication when explicitly requested
Compliance Officers & AdminsFull name, work email, encrypted credentialsMulti-factor authentication (MFA) & case management

5. Legal Basis for Processing (GDPR & EU Directive)

Processing is grounded in GDPR Articles 6 and 9:

  • Compliance with Legal Obligation (Art. 6(1)(c) GDPR): Fulfillment of EU Whistleblower Protection Directive 2019/1937 and national statutory transpositions.
  • Legitimate Interest (Art. 6(1)(f) GDPR): Prevention of corporate crime, fraud, money laundering, and ethical breaches.

6. Data Retention & Automated Purging

Data is retained only as long as necessary for investigation and legal proceedings:

• Unfounded / Rejected Reports: Automatically purged within 60 days of case closure.

• Resolved Investigations: Retained for the statutory period set by client organization (max 3 years under EU standards).

• Encrypted Backups: Overwritten and destroyed every 30 days.

7. Cookies & Tracking Technologies

Complete transparency regarding tracking:

Public Whistleblower Portals (/report/):

Public Whistleblower Portals (/report/): ZERO tracking cookies or third-party analytics (GTM/Clarity) to guarantee absolute anonymity.

Institutional Website & Admin Workspace:

Website & Workspace: Strictly necessary session cookies and optional performance cookies.

8. Sub-processors & EU Sovereign Hosting

All report data is hosted in EU data centers (Frankfurt / Dublin) under ISO 27001 and SOC 2 certifications.

Hosting Infrastructure: Cloud Infrastructure: Hetzner / Deno Deploy (EU Servers)

B2B Payments Processing: B2B Billing: Stripe Payments Europe Ltd.

Transactional Email Delivery: Transactional Email: Resend with TLS 1.3

9. Data Subject Rights

Data subjects possess statutory rights of access, rectification, erasure, and restriction under GDPR Articles 15-22.

Note on Anonymous Submissions:Since no IP addresses or technical identifiers are logged for anonymous submissions, attribution without the Access Token is technically impossible.

10. DPO Contact & Supervisory Authority

For questions or data subject requests, contact our privacy team:

Privacy Contact: contact@trycode.cloud

Email: contact@trycode.cloud

You retain the statutory right to lodge a complaint with your competent EU Member State Data Protection Authority.

Have questions about privacy?

Our compliance security team is ready to answer questions regarding GDPR and whistleblower protection laws.