Whistleblower System
We use the Trusty whistleblower system to securely and confidentially receive and process information about suspected violations that could harm our organization.
Go to the whistleblower system at dc.trusty.report
Go to the whistleblower system at dc.trusty.report
Information Obligation for the Whistleblower System
The following section provides details on the collection, processing, and use of personal data in connection with the whistleblower system. The processing of personal data within Trusty is based on the legitimate interest of the organization in detecting and preventing violations and avoiding related damages and liability risks. If a report concerns an employee, processing also serves to prevent crimes or other legal violations in connection with the employment relationship.
Data Privacy Information according to Art. 13, 14 GDPR
According to Art. 4 No. 1 GDPR, your personal data includes all information that relates to you or can be linked to you. The following information explains how your data is processed as part of our whistleblower management.
1. Name and Contact Details of the Responsible Entity
The responsible party under data protection law is dc AG, Von-Linde-Str. 11, 95326 Kulmbach. You can find more information about our company, authorized representatives, and additional contact options in our Legal Notice on our website: www.dc.ag/en/legal-notice2. Our Data Protection Officer
We have appointed a data protection officer for our company.You can reach them at the following contact details:
ITs Hein GmbH
Andreas Hein
Kulmbacher Str. 27b
95460 Bad Berneck
Email: info@dc.ag
3. Collection and Storage of Personal Data; Type, Purpose, and Use
3.1 Categories of Personal DataIn general, you can use the whistleblower system – as far as legally permitted – without providing personal data. However, you may voluntarily provide personal data during the reporting process, especially:
- Identity information
- First and last name
- Residence
- Contact details such as phone number or email address
- Content data
- Meta/communication data
- any other data you provide
Your report may also contain personal data of third parties you refer to. Affected individuals will have the opportunity to comment on the report. In this case, we will inform them about the report. Your confidentiality will still be maintained, as – as far as legally possible – no information about your identity will be shared, and your report will be used in a way that does not compromise your anonymity.
3.2 Source of Personal Data
We collect personal data directly from the whistleblower (by submission) and from the accused person. The data is provided via an online form through the whistleblower system.
3.3 Purpose and Legal Basis
The whistleblower system allows you to contact us and report compliance and legal violations. We process your personal data to review the report you submit and to investigate suspected compliance and legal violations. We may need to follow up with you. For this, we use only the communication channel within the whistleblower system. Confidentiality of your information is our top priority.
We process your personal data based on your consent given when submitting a report through the whistleblower system (Art. 6 para. 1a GDPR).
We also process your personal data as necessary to fulfill legal obligations. This includes, in particular, reports of criminal, competition, and labor law matters (Art. 6 para. 1c GDPR).
Finally, we process your personal data if required to protect the legitimate interests of the company or a third party (Art. 6 para. 1f GDPR). We have a legitimate interest in processing personal data to prevent and detect violations within the company, review internal processes for legal compliance, and maintain the integrity of the company.
If you provide us with special categories of personal data, we process these based on your consent (Art. 9 para. 2 lit. a GDPR).
We also use your personal data in anonymized form for statistical purposes.
We do not intend to use your personal data for purposes other than those listed above. If this changes, we will obtain your consent in advance.
3.4 Technical Implementation and Data Security
The whistleblower system enables anonymous communication via an encrypted connection. After submitting a report, you will receive access data for the whistleblower system mailbox, allowing you to continue communicating with us securely and, if desired, anonymously.To ensure data privacy and confidentiality, we implement appropriate technical measures. The data you provide is stored in a specially secured database by the whistleblower system provider. All data stored in the database is encrypted according to the latest standards.
3.5 Retention Period
Collected data is stored as long as required by statutory retention periods (according to § 11 HinSchG-E: Documentation is deleted two years after the procedure is completed).4. Disclosure of Personal Data
Only specially authorized individuals within the company can access stored data. If necessary to fulfill the above purpose, specially authorized individuals from our affiliated companies may also be granted access. This is especially the case if the investigation of your report is conducted in the relevant country. All authorized persons are expressly bound to confidentiality.We only transfer your personal data for the purposes described above. In particular, your data may be shared with:
- Authorities: e.g. courts, law enforcement agencies
- External reporting offices
- Service providers we use as data processors
- Joint controllers
5. Your Rights as a Data Subject
As a data subject, you have various rights regarding the processing of your personal data:Right to Withdraw Consent: You can withdraw any consent you have given us at any time. Data processing based on withdrawn consent may not continue in the future.
Right of Access: You can request information about your personal data processed by us. This includes the purposes of processing, categories of personal data, recipients (if any), retention periods, the origin of your data (if applicable), and the existence of automated decision-making including profiling (if applicable) and meaningful information about its details.
Right to Rectification: You can request the correction of incorrect or completion of your personal data stored by us.
Right to Erasure: You can request the deletion of your personal data stored by us, unless processing is required for exercising the right to freedom of expression and information, fulfilling a legal obligation, reasons of public interest, or for the establishment, exercise, or defense of legal claims.
Right to Restrict Processing: You can request the restriction of processing your personal data if you dispute the accuracy of the data, processing is unlawful but you oppose deletion, we no longer need the data but you require it for legal claims, or you have objected to processing.
Right to Data Portability: You can request that we provide your personal data, which you have given us, in a structured, commonly used, and machine-readable format. Alternatively, you can request direct transfer of your data to another controller, where technically feasible.
Right to Lodge a Complaint: You have the right to complain to a supervisory authority for data protection about our processing of your personal data, e.g. if you believe we are processing your data unlawfully.
Our responsible data protection supervisory authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach
Phone: +49 (0) 981 180093-0
Email: poststelle@lda.bayern.de