Tarif de lancement : Verrouillez 39,99 €/mois tant que les tarifs de lancement sont disponibles.
Politique de confidentialité

Confidentialité et protection des données

Découvrez comment nous protégeons vos données personnelles et respectons votre vie privée.

Date d'entrée en vigueur: Mai 2025

Société: Umbrella Rank Ltd (operator of Disclosurely)

Site web: disclosurely.com

Contact: privacy@disclosurely.com

Siège social: Londres, EC1V 2NX, Royaume-Uni

1. Introduction

Disclosurely is a software product owned and operated by Umbrella Rank Ltd ("Disclosurely", "we", "us" or "our"), a company registered in England and Wales with registered office at London, EC1V 2NX, United Kingdom. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal data when you use our whistleblowing and compliance platform at disclosurely.com (the "Service").

Nous traitons les données personnelles conformément aux exigences applicables du Règlement général sur la protection des données (UE 2016/679), du RGPD britannique (tel qu’énoncé dans la loi de 2018 sur la protection des données), de la directive européenne sur les lanceurs d’alerte (2019/1937) et des autres textes applicables en matière de protection des données.

This Privacy Policy applies to all users of the Service, including: (a) Customers (organisations subscribing to the Service); (b) Authorised Users (employees and agents of Customer organisations); (c) Whistleblowers (individuals submitting reports); and (d) website visitors. Different sections may apply to different user types as indicated.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, you must not use the Service.

2. Contrôleur de données et Processeur de données

Lorsque nous fournissons le Service aux organisations (le "Client"), cette organisation agit en tant que Contrôleur de données pour les rapports de lanceurs d'alerte et toutes les données personnelles qu'elle collecte.

Disclosurely agit en tant que Processeur de données, traitant les données personnelles uniquement sur les instructions documentées du Client.

Pour les données liées à votre propre utilisation de disclosurely.com (par exemple, votre compte, facturation), Disclosurely est le Contrôleur de données.

For Website Analytics: Disclosurely acts as the Data Controller for anonymised website usage data collected through essential cookies.

Contact Information: For questions about how your personal data is processed, Customers should contact privacy@disclosurely.com. Whistleblowers should contact the organisation to which they submitted their report, as that organisation is the Data Controller for report content.

3. Données personnelles que nous collectons

Nous pouvons collecter et traiter les catégories de données suivantes:

a) Des clients (titulaires de compte)

  • Nom, détails de l'entreprise, coordonnées
  • Détails de facturation et de paiement
  • Identifiants de connexion (nom d'utilisateur, e-mail, mot de passe – crypté)
  • Organisation information: company registration details, number of employees, industry sector, organisational structure
  • Communication data: correspondence with our support team, feedback, survey responses

b) Des lanceurs d'alerte (rapporteurs)

  • Informations que vous choisissez de soumettre dans un rapport (qui peuvent inclure des données personnelles, des données sensibles ou des catégories spéciales de données)
  • Coordonnées facultatives si vous choisissez de les fournir
  • Métadonnées telles que l'adresse IP, le type de navigateur, les informations sur l'appareil (sauf si le signalement anonyme est activé)
  • Technical and metadata: For non-anonymous reports, we may collect IP address, browser type and version, device type, operating system, time zone setting, browser plug-in types and versions, screen resolution, and timestamp. For anonymous reports, technical metadata collection is minimised or disabled as configured by the Customer
  • Communication data: messages exchanged between whistleblowers and Customer organisations through our secure messaging system
  • Uploaded files: documents, images, audio, video, or other files attached to reports

c) Données techniques

  • Fichiers journaux, statistiques d'utilisation et cookies (essentiels pour la fonctionnalité du site)
  • Données de sécurité et d'accès pour l'audit et la prévention de la fraude
  • Performance data: Service performance metrics, error logs, crash reports, load times
  • Cookie data: essential cookies for session management, authentication, and security (see Section 14)

d) Marketing and Communications Data (with consent)

  • Newsletter subscriptions: email address, communication preferences
  • Event registrations: name, email, company, job title for webinars or events
  • Website forms: information submitted through contact forms, demo requests, or quote requests

4. Comment nous utilisons les données personnelles

Nous utilisons les données personnelles aux fins suivantes:

  • Fournir, maintenir et améliorer le Service
  • Authentifier et gérer les comptes d'utilisateurs
  • Traiter les paiements d'abonnement
  • Assurer la sécurité et l'intégrité des rapports et des communications
  • Se conformer aux obligations légales et coopérer avec les autorités réglementaires
  • Pour l'analyse interne (sous forme anonymisée et agrégée uniquement)
  • Service Improvement: To analyse Service usage; identify trends and patterns; improve features and functionality; develop new services; conduct quality assurance; and optimise user experience (using anonymised and aggregated data only)
  • Communications: To send transactional emails (account confirmations, password resets, billing notices, security alerts); provide Service updates and announcements; and send marketing communications (with consent, which can be withdrawn at any time)
  • Research and Analytics: To conduct anonymised research; generate statistical reports; benchmark performance; and analyse compliance trends (personal data is always anonymised or aggregated for these purposes)
  • Business Operations: To manage internal operations; conduct audits; enforce our terms; protect our legal rights; and facilitate business transactions (mergers, acquisitions, asset sales)

5. Bases légales du traitement

Nous traitons les données personnelles sur les bases légales suivantes:

Nécessité contractuelle – pour fournir le Service auquel vous vous abonnez

Intérêts légitimes – pour améliorer le Service, maintenir la sécurité et prévenir la fraude

Obligations légales – pour se conformer aux lois et réglementations applicables

Consentement – lorsque vous fournissez volontairement des données sensibles ou facultatives

Vital Interests (Article 6(1)(d)) – Processing is necessary to protect vital interests, such as when a report involves imminent serious harm or threats to life

Public Interest and Legal Claims (Article 9(2)(f) and (g)) – For special category data in whistleblower reports, processing may be necessary for the establishment, exercise, or defence of legal claims, or when processing is necessary for reasons of substantial public interest (prevention of unlawful acts, protection of public interest in the area of employment law and social security)

Whistleblowing Legal Framework (Article 9(2)(g) and Directive 2019/1937) – Processing of personal data in whistleblower reports is explicitly permitted under the EU Whistleblowing Directive for the purposes of receiving, investigating, and following up on reports concerning breaches of EU law and serious misconduct

6. Hébergement et transferts de données

Data hosting: Customer Data is processed using infrastructure we configure with Supabase in the EEA (Ireland and, where used, Frankfurt). Data in transit is protected using TLS 1.3 (or equivalent). Stored content at rest is protected using AES-256-GCM (or an equivalent industry-standard algorithm).

Data residency: we configure primary storage and backups to remain within the EEA/UK unless we engage a subprocessor outside those regions with appropriate safeguards (see International transfers).

International transfers: we do not routinely transfer personal data outside the EEA/UK. If a transfer becomes necessary (for example to a subprocessor), we use mechanisms required by GDPR Chapter V where applicable, such as Standard Contractual Clauses or adequacy decisions, and we notify Customers where we are required to do so.

Subprocessors: we engage carefully selected subprocessors under written agreements. A current list of material subprocessors is available on request. We conduct proportionate due diligence and require appropriate confidentiality and security commitments.

7. Conservation des données

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are:

  • Customer Account Data: Retained for the duration of your active subscription plus six (6) years after account closure for accounting, tax, and legal purposes. Financial records are retained for seven (7) years to comply with UK tax law.
  • Whistleblower Reports and Customer Data: As Data Processor, we retain this data according to the Customer's instructions (the Customer, as Data Controller, determines retention periods). Upon account termination or Customer request, we will delete or return all Customer Data within thirty (30) days, unless longer retention is required by law. Customers must ensure their retention periods comply with the EU Whistleblowing Directive (which generally requires retention for the duration of investigations and legal proceedings, with a maximum recommended period of five years after case closure).
  • Technical Logs and Security Data: Retained for up to twelve (12) months for security monitoring, fraud prevention, and incident investigation purposes, then automatically deleted.
  • Marketing Data: Retained until you unsubscribe or withdraw consent, then deleted within thirty (30) days. We may retain a suppression list of unsubscribed email addresses to ensure we do not contact you again.
  • Anonymised Data: We may retain anonymised and aggregated data indefinitely for statistical analysis, research, and service improvement. This data cannot be used to identify individuals.
  • Legal Holds: In the event of litigation, investigation, or regulatory inquiry, we may suspend deletion of relevant data until the matter is resolved, as required by law.

8. Divulgation de données personnelles

Nous ne vendons ni ne louons de données personnelles. Nous pouvons divulguer des données uniquement à:

  • Le Client (pour les rapports de lanceurs d'alerte)
  • Des prestataires de services de confiance (par exemple, hébergement, traitement des paiements) sous des accords de confidentialité stricts
  • Des organes réglementaires ou d'application de la loi si requis par la loi
  • Des conseillers professionnels (avocats, auditeurs) si nécessaire
  • Business Transfers: In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, personal data may be transferred to the successor entity. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
  • Professional Advisors: We may share personal data with lawyers, accountants, auditors, and other professional advisors under obligations of confidentiality when necessary for business operations or legal compliance.
  • With Your Consent: We may disclose personal data for purposes not described in this Privacy Policy with your explicit consent.

9. Sécurité

Nous mettons en œuvre des mesures techniques et organisationnelles pour protéger les données personnelles, notamment:

  • Cryptage (au repos et en transit)
  • Contrôles d'accès sécurisés et authentification
  • Audits et surveillance réguliers
  • Procédures de réponse aux incidents
  • Security Monitoring: 24/7 automated monitoring for security incidents and anomalous behaviour. Security logs are retained and regularly reviewed. Incident response procedures are in place and regularly tested.
  • Employee Training and Vetting: All employees with access to personal data undergo background checks and sign confidentiality agreements. Regular security awareness and data protection training is mandatory. Access is granted on a need-to-know basis and reviewed quarterly.
  • Physical security: our hosting providers operate facilities with controlled physical access, environmental safeguards, and monitoring appropriate to cloud SaaS workloads.
  • Backup and Recovery: Automated encrypted backups are performed daily and stored in geographically redundant locations. Disaster recovery and business continuity plans are tested regularly.
  • Secure Development: We follow secure coding practices and conduct code reviews. Security testing is integrated into our development lifecycle. Third-party dependencies are regularly updated and scanned for vulnerabilities.
  • Data Breach Response: We have documented procedures for detecting, investigating, and responding to personal data breaches. In the event of a breach affecting personal data, we will notify affected individuals and relevant supervisory authorities within 72 hours as required by GDPR.

While we apply appropriate technical and organisational measures, no online service can be guaranteed completely secure. Please use strong passwords, enable multi-factor authentication where offered, and follow your organisation's security guidance.

10. Vos droits

En fonction de votre rôle (Client ou Lanceur d'alerte) et de la loi applicable, vous pouvez avoir des droits à:

  • Accéder à vos données
  • Corriger des données inexactes ou incomplètes
  • Demander la suppression de vos données
  • Restreindre ou vous opposer au traitement
  • Porter vos données vers un autre fournisseur
  • Déposer une plainte auprès de votre autorité de contrôle (par exemple, l'ICO au Royaume-Uni)
  • Right Not to Be Subject to Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. You can withdraw consent by contacting privacy@disclosurely.com or using unsubscribe links in marketing emails.
  • Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State or UK country of your habitual residence, place of work, or place of the alleged infringement. In the UK, the supervisory authority is the Information Commissioner's Office (ICO): ico.org.uk, telephone: 0303 123 1113.

Si vous êtes un lanceur d'alerte, vous devez contacter le Client (votre organisation) pour exercer vos droits, car il est le Contrôleur de données.

Important Note for Whistleblowers: If you submitted a report to an organisation using our Service, that organisation is the Data Controller for the report content and your personal data contained therein. To exercise your rights regarding report data, you must contact the organisation directly. Disclosurely, as Data Processor, can only act on instructions from the Data Controller. However, we will assist the organisation in responding to your request where appropriate.

Verification: To protect your personal data, we may need to verify your identity before responding to requests. We may request additional information to confirm your identity.

11. Third-Party Services and Links

The Service may integrate with or contain links to third-party websites, applications, or services ("Third-Party Services") that are not operated by Disclosurely. This Privacy Policy does not apply to Third-Party Services.

We are not responsible for the privacy practices, content, or security of Third-Party Services. We encourage you to review the privacy policies of any Third-Party Services you access.

Third-Party Services we may use include: (a) Stripe for payment processing (Stripe Privacy Policy: stripe.com/privacy); (b) Google OAuth for authentication (Google Privacy Policy: policies.google.com/privacy); and (c) email service providers for transactional emails.

12. Children's Privacy

The Service is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you are under 16, you must not use the Service or provide any personal data to us.

If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information as soon as possible.

If you believe we have collected personal data from a child under 16, please contact us immediately at privacy@disclosurely.com.

13. Anonymous Whistleblower Reporting

The Service offers anonymous reporting functionality to protect whistleblower confidentiality in accordance with the EU Whistleblowing Directive. When anonymous reporting is enabled by a Customer:

We minimise data collection: IP addresses, device identifiers, and other metadata that could identify the whistleblower are not collected or are anonymised. Whistleblowers access their reports using a unique access code that does not require registration or authentication with personal information.

Anonymous messaging: where enabled, whistleblowers can communicate with the Customer organisation through messaging protected in transit and subject to access controls configured for the Service. It should not be assumed to provide end-to-end encryption in every deployment.

Customer Obligations: Customers are responsible for ensuring they do not attempt to identify anonymous whistleblowers. Customers must configure the Service in accordance with applicable law and their whistleblowing procedures.

Limitations: Complete anonymity cannot be guaranteed in all circumstances. For example, if a whistleblower includes identifying information in their report, or if disclosure is required by law, anonymity may be compromised. Whistleblowers are advised not to include personal information in reports if they wish to remain anonymous.

11. Cookies

The Service uses cookies and similar tracking technologies. A cookie is a small text file stored on your device that allows us to recognise your browser and capture certain information.

Types of Cookies We Use: We use only essential cookies that are strictly necessary for the Service to function. These include: (a) Session cookies: to authenticate users and maintain your logged-in state; (b) Security cookies: to detect authentication abuse and protect user accounts; (c) Functionality cookies: to remember your preferences (e.g., language settings).

We do not use: Advertising cookies, tracking cookies, analytics cookies (other than anonymised internal analytics), or third-party marketing cookies.

Cookie Duration: Most cookies are session cookies that expire when you close your browser. Some cookies persist for up to 30 days to maintain your login state.

Managing Cookies: You can control cookies through your browser settings. Most browsers allow you to refuse cookies or delete cookies. However, if you disable essential cookies, you may not be able to use certain features of the Service. For browser-specific instructions, see: Chrome: support.google.com/chrome/answer/95647; Firefox: support.mozilla.org/kb/enable-and-disable-cookies-website-preferences; Safari: support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac; Edge: support.microsoft.com/help/4027947/microsoft-edge-delete-cookies.

12. Modifications de cette politique

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes as follows:

For Customers: We will send email notification to the email address associated with your account at least thirty (30) days before material changes take effect. We will also post a notice on the Service dashboard.

For Whistleblowers: Material changes will be posted on the reporting portal, and the effective date at the top of this Privacy Policy will be updated.

For Website Visitors: We will post a notice on our website homepage for thirty (30) days.

Non-Material Changes: Minor changes, clarifications, or corrections may be made without advance notice. We encourage you to review this Privacy Policy periodically.

Continued Use: Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy. If you do not agree to changes, you must stop using the Service and may request deletion of your data.

13. Contactez-nous

Si vous avez des questions ou des préoccupations concernant cette politique de confidentialité, veuillez contacter:

Umbrella Rank Ltd

Londres, EC1V 2NX, Royaume-Uni

Email: privacy@disclosurely.com (for privacy and data protection inquiries) or support@disclosurely.com (for general support)

Data Protection Officer: We have appointed a Data Protection Officer (DPO) who can be contacted at: dpo@disclosurely.com

Response Time: We will respond to all inquiries within ten (10) business days and will resolve requests within one (1) month (or notify you of any extension).

17. EU Whistleblowing Directive Compliance

The Service is designed to support common requirements under the EU Whistleblowing Directive (Directive 2019/1937) and national implementing legislation. Key measures include:

Confidentiality and Anonymity: The Service provides secure channels that protect the confidentiality of whistleblowers, including anonymous reporting options. We implement technical and organisational measures to prevent unauthorised access to whistleblower identities.

Data Minimisation: Personal data in reports is processed only to the extent necessary for the purposes of receiving, investigating, and following up on reports. Customers are advised to limit data collection to what is necessary.

Security: We implement state-of-the-art encryption and security measures to protect the integrity and confidentiality of reports and communications.

Retention Limits: Customers are responsible for establishing retention periods for reports in accordance with the Directive and national law. The Directive generally requires deletion of data that is not necessary for follow-up actions.

Access Rights: Access to whistleblower identity and report content is restricted to authorised personnel designated by the Customer. We provide audit logs to track access.

Data Subject Rights: While the Directive requires protection of whistleblower confidentiality, data subjects (including persons mentioned in reports) retain their GDPR rights, which must be balanced against the need to protect whistleblowers. Customers are responsible for managing this balance.

Disclaimer: Customers are solely responsible for ensuring their use of the Service and their internal whistleblowing procedures comply with the EU Whistleblowing Directive and all applicable national laws. Disclosurely provides the technical platform but does not provide legal advice on compliance.

Dernière mise à jour: Mai 2025

Politique de confidentialité | Disclosurely