Privacy notice
We take data protection and confidentiality very seriously and adhere to the provisions of the EU General Data Protection Regulation (GDPR) as well as current national data protection regulations. Please read this information on data protection law carefully before submitting a report.
Name and contact details of the controller
Wiener ArbeitnehmerInnen Förderungsfonds (waff), Lassallestrasse 1, 1020 Vienna; Telephone: 01/ 217 48 – 0, www.waff.at;
Data protection officer: Mag. David Klein
Contact: datenschutz@waff.at
The whistleblowing system is operated by a specialised company, EQS Group GmbH, Bayreuther Str. 35, 10789 Berlin, Germany, on behalf of waff. EQS Group GmbH and other third parties do not have access to the data. This is ensured in the certified procedure through extensive technical and organisational measures. All data are stored encrypted with multiple levels of password protection according to a system of permissions so that access is restricted to a very small selection of expressly authorised persons at waff.
Data and categories of data that are processed
Use of the whistleblowing system is voluntary. If you submit a report via the whistleblowing system, we collect the following personal data and information:
- Your name, if you choose to reveal your identity
- Whether you are employed at waff
- The names and other personal data of persons whom you list in your report, if applicable
- Where applicable, special categories of data according to Article 9 GDPR or personal data concerning criminal convictions and crimes according to Article 10 GDPR
Sources from which the data are obtained
The personal data are collected directly from the person who submits the report. In the course of further processing, personal data may also be collected from the employer and other sources arising from the descriptions of the situation.
Legal basis
Personal data are processed on the basis of the Viennese Whistleblower Protection Act (W-HSchG) where the report falls within the scope of application of this law.
Reports which do not fall within the scope of application of the W-HSchG are processed on the basis of the legitimate interests of the controller pursuant to Article 6(1)(f) GDPR where the interests of the data subject do not outweigh such interests. waff has a legitimate interest in discovering and preventing abuses and thereby averting damage to waff, its employees and stakeholders.
Purpose of data collection
The data processing serves to protect against image damage for the controller, to protect the employees, to protect the organisation, to process the complaint, to process the information on procedures, to assist the associated investigations and to aid in clarification of the case.
Recipients
Incoming reports are received by a small selection of expressly authorised and specially trained employees at waff (internal reporting office) and always handled in confidence. The employees at the internal reporting office evaluate the matter and carry out any further investigation that may be required by the specific case. In some circumstances, personal data may be shared with decision-makers at waff, with authorities or with courts.
All persons who receive access to the data are obligated to maintain the strictest confidentiality.
Personal data and information entered into the whistleblowing system are stored in a database operated by EQS Group GmbH in a high-security data centre. Only waff can view the data. EQS Group GmbH and other third parties do not have access to the data. This is ensured in the certified procedure through extensive technical and organisational measures.
All data are stored encrypted with multiple levels of password protection according to a system of permissions so that access is restricted to a very small selection of expressly authorised persons at waff.
Note on the use of the whistleblowing system
Communication between your computer and the whistleblowing system takes place over an encrypted connection (SSL). Your IP address will not be stored during your use of the whistleblowing system. In order to maintain the connection between your computer and BKMS® System, a cookie is stored on your computer that merely contains the session ID (a session cookie). This cookie is only valid until the end of your session and expires when you close your browser.
It is possible to set up a secured postbox within the whistleblowing system with an individually chosen pseudonym/ user name and password. This allows you to send reports to the internal reporting office at waff either by name or in an anonymous, secure way. This system only stores data inside the whistleblowing system, which makes it particularly secure. It is not a form of regular e-mail communication.
Note on sending attachments
When submitting a report or an addition, you can simultaneously send attachments. If you wish to submit an anonymous report, please take note of the following security advice: Files may contain hidden personal data that could jeopardise your anonymity. Please remove all such information before sending a file. If you are unable to remove this information or are uncertain about how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the reporting process.
Storage period
The personal data are stored for a period of up to one year if the report does not lead to a sufficiently justified suspicion of a legal violation and / or has not led to the initiation or continuation or suspension of an investigation process.
Personal data which have been processed or transmitted based on sound reports shall be stored for up to five years and beyond for the period which is necessary and proportionate for carrying out official administrative or court procedures or to protect an individual.
Rights of the data subjects
You have the right of access, rectification, erasure, restriction of processing of the stored data concerning and a right of objection, as a well as a right to data portability, pursuant to the provisions of the General Data Protection Regulation (EU) 2016 / 679 (GDPR).
These rights may be restricted insofar as this is necessary to protect the identity of a whistleblower or for the purpose of taking follow-up measures.
If you believe that the processing of your personal data violates the provisions of data protection law or that your legal data protection rights have been otherwise violated, you can also register a complaint with the supervisory authority which is responsible for you. In Austria, the competent authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna (Telephone: +43 1 52 152-0, E-mail: dsb@dsb.gv.at).
Version: 3 April 2023