Privacy Policy
Last updated: 17 July 2026
1. Who we are
Whistleblowing.services ("WBS", "we", "us") provides secure whistleblowing intake, case management, training and related compliance services. This Privacy Policy explains how we collect, use, store and disclose personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Information we collect
Depending on how you interact with us, we may collect:
- Website visitors: contact details you submit through our contact, newsletter or sign-up forms, and limited technical data needed to operate the site.
- Clients and their users: names, work email addresses, organisation details, billing information and account activity.
- Learners: name, email address, course enrolments, progress, quiz results and certificates.
- Whistleblowers and report participants: only the information you choose to provide. Our reporting platform supports fully anonymous reporting; where a reporter chooses anonymity, identifying details are stripped and never stored.
3. Whistleblower confidentiality
Protecting reporter identity is the foundation of our service. Disclosures made through our reporting platform are handled under strict confidentiality and, where applicable, statutory protections including Part 9.4AAA of the Corporations Act 2001 (Cth). We never disclose a whistleblower's identity without lawful basis or consent, and our systems are engineered to minimise identifying metadata. Audit records reference case identifiers only — never personal details of reporters.
4. How we use personal information
- To provide, operate and secure our reporting, case-management, portal and training services.
- To administer accounts, subscriptions, payments and invoicing.
- To issue training certificates and maintain course records.
- To respond to enquiries and provide support.
- To send service notifications and, with consent, newsletters (you can unsubscribe at any time).
- To comply with our legal and regulatory obligations.
We do not sell personal information, and we do not use whistleblowing report content for marketing or analytics.
5. Disclosure to third parties
We share personal information only with service providers necessary to run the platform, under contractual confidentiality obligations:
- Secure cloud hosting and object storage providers.
- Payment processing (Stripe) — we never store full card details.
- Email delivery services for transactional messages.
We may disclose information where required by law, court order or regulator. Where a client's whistleblowing program requires cross-border reporting, data is handled in line with the applicable legal frameworks disclosed to that client.
6. Security
We apply layered technical and organisational safeguards including encryption in transit, hardened access controls, role-based permissions, ringfenced client data, tamper-evident audit trails and time-limited access links for documents. Access to report content is restricted to authorised case handlers.
7. Data retention
We retain personal information only as long as needed for the purposes above, to meet the record-keeping requirements agreed with our clients, or as required by law. When information is no longer required it is securely deleted or de-identified.
8. Your rights
You may request access to, or correction of, the personal information we hold about you. Where the GDPR applies you may also have rights to erasure, restriction, portability and objection. Requests can be made using the contact details below; note that whistleblower confidentiality obligations may limit what we can disclose about report content.
9. Cookies
We use strictly necessary cookies for authentication and session security. We do not use third-party advertising cookies.
10. Complaints and contact
If you have a question or complaint about how we handle personal information, please contact us via our contact page. We will respond within a reasonable period. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be published on this page with its "last updated" date.
