Privacy Policy – Whistleblowing Channel
The purpose of this Privacy Policy is to inform about the processing of personal data carried out for the management and investigation of reports or queries submitted through Proasur’s Whistleblowing Channel.
To ensure the proper configuration and design of the Whistleblowing Channel, Proasur fully complies with applicable data protection regulations, in particular: Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights, Spanish Law 2/2023 on the protection of persons reporting regulatory infringements, Spanish Organic Law 10/1995 on the Criminal Code, and other applicable European and Spanish regulations.
1.- Who is responsible for the processing of your personal data?
Proasur’s Compliance Officer.
2. Category and source of the data
This Whistleblowing Channel may process personal information of the reporting person and the person reported, as well as of third parties involved in the facts (for example, possible witnesses). It is not possible to define in advance which categories of personal data will be processed, as this depends on the information freely provided by the reporting person, the reported person, or witnesses. In all cases, only data strictly and objectively necessary to process the reports will be processed.
Proasur may receive such personal data directly from the data subject, or indirectly, from any person involved in the investigation or from the Group’s companies. Reporting persons who wish to disclose their identity must provide current and accurate personal data so that the information held is properly updated.
3. For what purpose and on what legal basis do we process your personal data?
Compliance with Law 2/2023, on the Protection of Whistleblowers: we will process the information collected for the purpose of managing and investigating reports submitted, and adopting the protective measures legally established to prevent retaliation.
Handling and responding to queries: if a query is submitted rather than a report, Proasur will process the information to handle, manage and respond to it, based on the legitimate interest of both Proasur and the person submitting the query.
Prevention of criminal risks, as a task carried out in the public interest: data may also be processed for the prevention, detection and discovery of possible breaches that could give rise to criminal liability for Proasur.
Evidence of the proper functioning of the Criminal Risk Prevention Model: based on Proasur’s legitimate interest in having such evidence available.
Other legally required uses: in certain cases, data may also be processed to comply with legal obligations (for example, if requested by a Court).
4. How long will we keep your data?
Data will be kept for the time strictly necessary to decide whether to initiate an investigation, during the course of the investigation itself, and, where applicable, during the exercise of any corresponding legal actions. If three months have elapsed since receipt of the report without any investigation having been initiated, the data will be deleted, unless retention is necessary as evidence of the channel’s operation.
Data may subsequently be retained, duly blocked, to address possible claims or liabilities, for a maximum period of ten years.
5. Who will your data be shared with?
As a general rule, Proasur will not disclose data collected through the Whistleblowing Channel to any third party. Only duly and previously authorised personnel may access it.
If, as a result of the investigation, legal or disciplinary measures are agreed against the reported person, Proasur will forward the strictly necessary information to the relevant entity. Data may also be provided to third parties when legally required (Courts, Law Enforcement Authorities).
Proasur may work with service providers (legal advisory, technology services) who process data on its behalf, under the corresponding data processing agreement.
6. Rights of data subjects
Affected persons (reporting person, reported person and witnesses) may exercise their rights of access, rectification, erasure, restriction and objection to the processing of their data, under the legally established terms, in a manner that does not allow the reported person to identify the reporting person.
These rights may be exercised at Proasur’s registered address (Pg. Ind. de Olloniego, Parcela B-41, 33660 Oviedo, Asturias, Spain) or by email to canaletico@proasur.com.
If you do not receive a satisfactory response, you may contact the Spanish Data Protection Agency (www.aepd.es).
7. How do we ensure the security of your data?
Proasur applies and maintains appropriate technical and organisational measures to ensure an adequate level of security, preventing loss, misuse, alteration, unauthorised access to, and theft of the data provided. Proasur has carried out a risk analysis and the corresponding Data Protection Impact Assessments.
8. Information provided to the parties involved
Each time a report or query is submitted, Proasur will individually inform the persons involved about the processing of their data: the reporting person, in the acknowledgement of receipt of their report; the reported person, within a maximum of 30 days from admission of the report (unless doing so would compromise the investigation, a decision which will be duly documented); and any other interested party, prior to their participation in the process.
9. Security and confidentiality measures. Anonymity of the reporting person
Reporting persons may decide whether or not to identify themselves when submitting a report — anonymous reports are accepted. The identity of those who choose to identify themselves will be treated with the utmost confidentiality, and the exercise of the right of access by the reported person will not, under any circumstances, grant automatic access to that identity.
All persons who, due to their duties, become aware of reports submitted are required to maintain confidentiality regarding all information they access.