WhiteBox
WhiteBox
Grievance mechanism

Policies

The documents that govern how WhiteBox is used and how data is protected. Plain-language summaries are below.

Terms of Service

The rules for using WhiteBox, for reporters and organisations alike.

Last updated: —

Privacy Policy

What information we collect, why, and the choices you have.

Last updated: —

Data Processing Addendum

How WhiteBox processes data on behalf of organisations.

Last updated: —

Terms of Service

Last updated: —

Using WhiteBox

WhiteBox is a secure channel for raising and handling grievance reports. By using it, you agree to provide truthful information and to use the service only for legitimate reporting and case-handling purposes.

Your responsibilities

Reporters are asked to describe concerns honestly and to the best of their knowledge. Organisations agree to handle reports fairly, to protect reporter identities, and to follow their own grievance procedures.

Availability

We aim to keep the service available and secure at all times. Planned maintenance and service updates may occasionally affect access.

Privacy Policy

Last updated: —

What we collect

We only collect what is needed to handle a report. If you report anonymously, we do not ask for your identity. Any contact details you share are stored securely and shown only where you have allowed it.

How your report is used

Your report is shared with the team responsible for handling it, and translated where needed. Sensitive details can be redacted, and visibility is limited to those who need it to act.

Your choices

You decide whether to stay anonymous and whether to share contact details. You can ask about the information held about you in line with applicable data-protection law.

Data Processing Addendum

Last updated: —

Roles

When an organisation uses WhiteBox to handle reports, the organisation is the data controller and WhiteBox acts as a data processor, processing personal data only on documented instructions.

Security and location

Data is encrypted in transit and at rest and hosted within the EU. Access is restricted, logged, and limited to what each role needs.

Retention

Reports are retained according to the organisation's settings and applicable law. Archived cases are kept for a defined period and then securely removed.

Questions about these documents? Get in touch.