Privacy Policy

WhisTrust Privacy Policy

Compliance with Data Protection Laws

This Privacy Policy is designed to comply with applicable data protection and privacy laws in your jurisdiction. WhisTrust is committed to protecting your privacy and handling your personal data in accordance with industry best practices and legal requirements.

1. Introduction

WhisTrust ("we," "us," or "our") operates a secure whistleblowing platform that enables anonymous reporting of misconduct, fraud, and policy violations within organizations. This Privacy Policy explains how we collect, use, protect, and disclose personal information in compliance with Saudi Arabian law.

By using WhisTrust, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Data Controller Information

WhisTrust acts as the data controller for personal information processed through our platform. For inquiries regarding your personal data:

Contact Information:

  • Email: info@aisar.sa
  • Data Protection Officer: info@aisar.sa
  • Website: www.whistrust.com
3. Information We Collect

3.1 Information from Anonymous Reporters

We collect minimal information to maintain anonymity:

  • Report details (category, description, incident information)
  • Optional contact information (if you choose to provide it)
  • File attachments (automatically stripped of metadata)
  • Encrypted messages exchanged through the platform
  • Unique tracking code (for case follow-up)

3.2 Information from Admin Users

For authenticated administrators:

  • Name and email address
  • Job title and department
  • Login credentials (encrypted)
  • Role and permission level
  • Audit trail of actions performed

3.3 Technical Information

  • IP addresses (anonymized where possible)
  • Browser type and version
  • Device information
  • Usage analytics and system logs
4. How We Use Your Information

In accordance with data protection principles, we process personal data only for specified, explicit, and legitimate purposes:

  • To facilitate anonymous reporting and case management
  • To enable secure communication between reporters and administrators
  • To maintain audit logs for compliance and security purposes
  • To improve our services and user experience
  • To comply with legal obligations under applicable law
  • To prevent fraud and ensure platform security
  • To provide technical support when requested
5. Data Localization and Storage

In compliance with data protection regulations:

Data Storage Location

Personal data is stored in secure, compliant data centers. We offer data localization options to meet regional regulatory requirements.

Data Transfers

We implement appropriate safeguards for international data transfers, including standard contractual clauses and encryption, in accordance with applicable regulations.

Cloud Infrastructure

Our cloud services are hosted in certified, secure data centers that meet industry standards and regulatory requirements.

6. Data Security

We implement comprehensive security measures in accordance with industry best practices and cybersecurity standards:

  • End-to-end encryption for all messages and file uploads
  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Automatic metadata removal from uploaded files
  • Role-based access control (RBAC) with audit logging
  • Regular security assessments and penetration testing
  • Multi-factor authentication for admin users
  • Incident response and breach notification procedures
7. Your Data Protection Rights

Under applicable data protection laws, you have the following rights:

Right to Access

Request access to your personal data we hold

Right to Rectification

Request correction of inaccurate personal data

Right to Deletion

Request deletion of your personal data (subject to legal obligations)

Right to Withdraw Consent

Withdraw consent for data processing at any time

Right to Object

Object to certain types of data processing

Right to File a Complaint

Lodge a complaint with the relevant Data Protection Authority in your jurisdiction

To exercise these rights, contact us at info@aisar.sa

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by applicable law:

  • Case reports: Retained for 7 years after case closure (or as required by applicable regulations)
  • Admin account data: Retained during employment + 2 years
  • Audit logs: Retained for 5 years for compliance purposes
  • Anonymous tracking codes: Retained for 1 year after case closure
9. Data Breach Notification

In the event of a data breach affecting personal data, we will:

  • Notify relevant Data Protection Authorities as required by law
  • Notify affected individuals without undue delay if the breach poses a high risk
  • Implement immediate remediation measures
  • Document all breach incidents and response actions
10. Third-Party Sharing

We do not sell personal data. We may share information only in the following circumstances:

  • With your organization's authorized administrators (for case management)
  • With cloud infrastructure providers (under data processing agreements)
  • When required by applicable law or court order
  • To protect our rights, safety, or property

All third parties are contractually obligated to protect your data in accordance with applicable data protection laws.

11. Cookies and Tracking

We use essential cookies to ensure platform functionality. We do not use advertising or third-party tracking cookies. You can control cookie settings through your browser.

12. Children's Privacy

WhisTrust is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If you become aware that a child has provided us with personal data, please contact us immediately.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of WhisTrust after changes constitutes acceptance of the revised policy.

14. Contact Us

For questions about this Privacy Policy or our data practices:

Email: info@aisar.sa

Data Protection Officer: info@aisar.sa

This Privacy Policy is governed by applicable laws in your jurisdiction