How it applies

This Data Processing Agreement (“DPA”) forms part of the contractual framework between MAINSYSTEMS, LDA. and each UNOVOX Customer, together with the Terms of Service and the applicable Order. For personal data processed on the Customer's behalf, the DPA prevails over the Terms. A signable version can be requested from dpo@mainsystems.pt.

1. Subject matter and roles

This DPA governs the processing of personal data by MAINSYSTEMS, LDA. (“Processor”) on behalf of the Customer (“Controller”) in connection with the UNOVOX platform, under Article 28 of Regulation (EU) 2016/679 (“GDPR”). The Customer determines the purposes and means of processing its case data; MAINSYSTEMS processes that data only on the Customer's documented instructions, including the configurations made in the platform, unless required to do so by Union or Member State law; in that case, it will inform the Customer before processing, unless the law prohibits such information.

2. Description of the processing

  • Subject matter: hosting and provision of the UNOVOX platform, including the reporting portal, case management, communications, reporting, technical support and, where enabled by the Customer, AI Agents.
  • Duration: the subscription term, plus the recovery and deletion period in section 10.
  • Nature and purpose: collection, storage, organisation, consultation, disclosure to the Customer and erasure of data, exclusively to operate the Customer's protected disclosure channel and case management.
  • Categories of data subjects: reporting persons, persons concerned, witnesses and third parties mentioned; the Customer's authorised users.
  • Categories of data: identification and contact data, professional information, report content, messages and attachments, case management records; these may include special categories of data (Article 9 GDPR) and data relating to offences (Article 10 GDPR), depending on what is submitted.

3. Customer instructions

MAINSYSTEMS will inform the Customer immediately if, in its view, an instruction infringes the GDPR or other data protection provisions, and may suspend execution of that instruction until it is confirmed or amended. The Customer warrants that its instructions are lawful and that it has a legal basis for the processing it determines.

4. Confidentiality

MAINSYSTEMS ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is strictly necessary to provide, protect and support the service. In the whistleblowing context, confidentiality covers in particular the identity of reporting persons and any information from which that identity may be directly or indirectly deduced, in line with section 16 of the Protected Disclosures Act 2014 (No. 14 of 2014), as amended by the Protected Disclosures (Amendment) Act 2022 (No. 27 of 2022), and with Article 16 of Directive (EU) 2019/1937. Where the Customer is established in Ireland, MAINSYSTEMS supports the Customer in operating channels that meet the confidentiality requirement in section 6A(1)(a) of that Act.

5. Security measures

MAINSYSTEMS applies the technical and organisational measures appropriate to the risk required by Article 32 GDPR, including, as at this version: access controls and role-based permissions defined by the Customer; authentication with encrypted password storage; access to the platform over HTTPS connections; logical segregation of each customer's environment; no logging of reporting persons' IP addresses on the reporting portal; activity logs in the management area; periodic backups; vulnerability management and incident response procedures. An updated description of the measures is available on request and may evolve, provided the overall level of protection is not materially reduced.

6. Subprocessors

The Customer gives general authorisation for the use of subprocessors for hosting and infrastructure, communications, security and, where enabled, AI services. MAINSYSTEMS keeps a list of the relevant subprocessors, available to the Customer on request, and informs the Customer with reasonable advance notice of any material change, giving the opportunity to object on legitimate grounds; failing a reasonable solution, the Customer may terminate the affected service. MAINSYSTEMS imposes on each subprocessor, by contract, data protection obligations equivalent to those in this DPA and remains liable to the Customer for their performance.

7. Assistance to the Customer

Taking into account the nature of the processing, MAINSYSTEMS provides reasonable assistance to the Customer, through appropriate technical and organisational measures and the platform's functions, to: respond to data subject requests; comply with the obligations in Articles 32 to 36 GDPR, including security, breach notification, impact assessments and prior consultations. If a data subject contacts MAINSYSTEMS directly about data processed on the Customer's behalf, MAINSYSTEMS will forward the request to the Customer without undue delay and will not respond on the merits without the Customer's instruction, except where legally required. Assistance exceeding what is reasonable within the service may be charged at reasonable rates.

8. Personal data breaches

MAINSYSTEMS notifies the Customer without undue delay after becoming aware of a personal data breach affecting data processed on the Customer's behalf, providing the reasonably available information on the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, and supplementing the information as it becomes available. Notification to the supervisory authority, which for a customer established in Ireland is the Data Protection Commission, and to data subjects is the decision and responsibility of the Customer as controller; MAINSYSTEMS cooperates reasonably.

9. International transfers

Data is processed in the European Economic Area. Any transfer outside the EEA only takes place with a valid Chapter V GDPR mechanism (an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where appropriate, or another legally recognised instrument) and will be reflected in the subprocessor information.

10. Return and deletion

Upon termination of the service, and at the Customer's choice, MAINSYSTEMS returns the personal data through the available export functions during the 30-day recovery period, unless the Order states a different period, and then deletes the existing data and copies, except to the extent Union or Member State law requires their retention. Deletion from backups occurs within secure rotation cycles. The Customer is responsible for exporting, before the end of the recovery period, the records of reports it must keep under section 16C of the Protected Disclosures Act 2014, as amended. Under that section, the person to whom a report is made or transmitted must keep a record of every report, and reports and the records of anonymous reports are to be retained for no longer than is necessary and proportionate to comply with the provisions of that Act or any other enactment. Irish law does not set a fixed number of years; defining, documenting and applying a proportionate retention period is the Customer's responsibility as controller.

11. Information and audits

MAINSYSTEMS makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including responses to security questionnaires and documentation of the measures applied. The Customer may conduct, or mandate an independent auditor bound by confidentiality to conduct, an audit of the relevant processing operations, with reasonable prior notice, at most once per year except where required by a supervisory authority or after a material breach, during business hours and without access to other customers' data. Audit costs are borne by the Customer.

12. Liability and term

The parties' liability under this DPA follows Article 82 GDPR and the limitations in the Terms of Service, to the extent they can lawfully apply. This DPA remains in force for as long as MAINSYSTEMS processes personal data on the Customer's behalf and prevails over conflicting provisions of the Terms in personal data processing matters. It is governed by Portuguese law, and the courts of Lisbon, Portugal, have jurisdiction. Versions in other languages are provided for convenience; in case of divergence, the Portuguese version prevails.

13. Contact

MAINSYSTEMS, LDA. (UNOVOX)
Av. da República, 50, 2.º andar, 1050-196 Lisbon, Portugal
Privacy: dpo@mainsystems.pt
General: info@mainsystems.pt
Phone: +351 211 245 202