Plain-language summary

MAINSYSTEMS is the controller for this website, commercial contacts and customer-account administration. For reports and case data processed in a customer's UNOVOX environment, the customer is normally the controller and MAINSYSTEMS acts as a processor under that customer's instructions. We do not sell personal data.

1. Scope

This policy applies to www.unovox.com, contact and contracting forms, commercial interactions concerning UNOVOX, customer-account administration and the technical provision of the UNOVOX software-as-a-service platform. A customer may publish an additional privacy notice in its own whistleblowing channel. That notice governs the processing carried out by the customer and should be read together with this policy.

2. Who we are and our roles

UNOVOX is a product operated by MAINSYSTEMS, LDA., with a contact address at Av. da República, 50, 2nd floor, 1050-196 Lisbon, Portugal (“MAINSYSTEMS”, “we”, “us” or “our”).

  • Controller: for website visits, demo or proposal requests, contracting, billing contacts, support and the administration of customer and user accounts, MAINSYSTEMS determines the purposes and means of processing.
  • Processor: for reports, messages, attachments, investigation records and other case content submitted to or created in a customer's UNOVOX environment, the customer normally determines the purposes and means. MAINSYSTEMS processes that data under documented instructions and a data processing agreement.
  • Customer responsibility: the organisation operating the channel must provide its own notice, identify the applicable lawful bases, define permissions and retention, and respond to data-subject requests concerning its cases.

3. Data we may process

Website, commercial and contractual data

  • professional identification and contact data, such as name, business email, telephone, organisation, role and country;
  • information included in requests for demonstrations, proposals, subscriptions, partnerships or support;
  • contract, subscription, billing and transaction records, excluding full card details where payment is handled by a specialist provider;
  • communications and records required to manage the commercial relationship and support.

Account and service-usage data

  • user name, business email, role, organisation, permissions and authentication information;
  • technical and security records, such as access dates and times, browser and device information, IP address where required for service and security logs, actions performed and incident records;
  • configuration, usage, support and diagnostic information required to operate and improve the service.

Report and case data

Depending on the customer's configuration and what a reporting person or authorised user enters, a case may contain identity and contact data, employment or professional information, statements, messages, attachments, information about alleged conduct, special-category data and data concerning suspected offences. MAINSYSTEMS does not determine which reports a customer receives and does not use case content for advertising.

UNOVOX can be configured to accept a report without requiring the reporting person's identity. Anonymity may nevertheless be affected if the person voluntarily identifies themselves in the description or attachments, uses organisational equipment or a network monitored by third parties, or communicates through another channel.

4. Sources of data

We obtain data directly from you, from the customer that creates or administers your account, from authorised service users, from reporting persons and other people mentioned in case content, from technical and security logs, and from providers used to deliver the website and platform.

5. Purposes and lawful bases

PurposeTypical dataBasis
Respond to enquiries and prepare demonstrations and proposalsContact and request dataPre-contractual steps and legitimate interests in responding to professional enquiries
Contract, provide, administer and support UNOVOXAccount, contract, usage and support dataPerformance of a contract and legitimate interests in service administration
Billing, accounting and legal complianceContract, invoice and transaction recordsContract and legal obligations
Protect the website and service, prevent abuse and investigate incidentsTechnical, authentication and security dataLegitimate interests and, where applicable, legal obligations
Measure website performance and improve contentCookie identifiers and aggregated browsing dataConsent for non-essential analytics technologies
Send requested communications or marketingName, organisation, email and preferencesConsent where required; legitimate interests may apply to proportionate B2B communications, always with a simple opt-out
Process customer case dataReports, messages, attachments and investigation recordsThe customer's documented instructions; the customer determines the applicable lawful basis

Where processing relies on consent, you may withdraw it at any time without affecting processing already carried out. Where we rely on legitimate interests, you may request information about the balancing assessment and object to the processing.

6. Reports and confidential case data

Access to case data is limited to users authorised by the customer and people who require access to provide or protect the service. MAINSYSTEMS teams may access case information only where necessary for authorised support, security, incident response, legal compliance or maintenance, subject to confidentiality and access controls. We do not decide whether a report is substantiated, which investigative steps should be taken or whether any person should be subject to a measure; those decisions belong to the customer.

Requests to exercise rights concerning a report should normally be addressed to the organisation operating the channel. We assist the customer under the data processing agreement. Rights may be restricted where necessary to protect the identity of a reporting person, the rights of third parties, an investigation, professional secrecy or another legally protected interest.

7. AI Agents and assisted processing

If a customer activates AI Agents, the customer selects the categories and scope in which they may organise information and perform configured investigation tasks. Outputs may contain errors or require context. Final validation and material decisions remain the responsibility of an authorised human manager. MAINSYSTEMS does not use customer case content to train general-purpose models unless expressly agreed with the customer and supported by a valid lawful basis. Any authorised AI subprocessor is subject to contractual confidentiality, security and data-protection obligations.

8. Cookies, analytics and abuse-prevention technologies

We use strictly necessary technologies to provide the website, remember consent preferences, protect forms and prevent automated abuse. Forms use Cloudflare Turnstile. We use Cookiebot to manage consent and Google Tag Manager to manage measurement tags. Google Analytics 4 is activated for analytics only in accordance with the choices made in the consent banner. We do not use website analytics data to identify the content of a report.

You may change or withdraw consent for non-essential cookies at any time through the cookie settings available on the website. Blocking strictly necessary technologies may prevent forms or security checks from working.

9. Recipients and subprocessors

On a need-to-know basis, data may be made available to MAINSYSTEMS teams, the customer and its authorised users, hosting and infrastructure providers, email and communications providers, security and abuse-prevention providers, analytics and consent-management providers, payment and billing providers, professional advisers, auditors and public authorities where disclosure is legally required. Providers are subject to contractual obligations appropriate to their role. We do not sell or rent personal data.

Customers may request information about subprocessors relevant to their service and will be informed of material changes where required by the applicable contract.

10. International transfers

We prioritise processing in the European Economic Area. Where a provider or support operation involves a country outside the EEA, we use a lawful transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses and supplementary measures where appropriate. Customers may request further information about safeguards relevant to their service.

11. Retention

We retain data only for as long as necessary for the stated purpose, taking account of contractual obligations, statutory limitation periods, security requirements and the need to establish, exercise or defend legal claims.

  • commercial enquiries and related correspondence are generally retained for up to 24 months after the last relevant interaction, unless a contract is entered into or a longer period is justified;
  • customer, contract, billing and accounting records are retained during the relationship and for mandatory legal periods;
  • account and support records are retained while the account is active and for the period required to close, audit and defend the relationship;
  • technical and security logs are retained for a proportionate period and may be kept longer where associated with an incident;
  • customer case data is retained according to the customer's instructions, applicable law and the data processing agreement. Under the EU whistleblowing framework, records should be kept no longer than necessary and proportionate, subject to national transposition rules and other legal proceedings.

At the end of the service, customer data is returned or deleted in accordance with the contract, applicable law and the customer's documented instructions, subject to secure backup cycles and legal preservation obligations.

12. Security

We apply technical and organisational measures appropriate to the risk, including access controls, role-based permissions, authentication protection, encryption in transit, protected infrastructure, logging, backups, vulnerability management and incident-response procedures. No internet service can guarantee absolute security. Customers must configure permissions carefully, keep credentials confidential and notify us promptly of any suspected compromise.

13. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction or portability, or object to processing. You may withdraw consent and may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

For data controlled by MAINSYSTEMS, contact dpo@mainsystems.pt. We may request information needed to confirm your identity and locate the data. For data held in a customer's reporting channel, contact that customer; if you contact us, we will route or assist with the request without improperly disclosing confidential case information.

You may lodge a complaint with the supervisory authority in your habitual place of residence or work, or with the Portuguese Comissão Nacional de Proteção de Dados (CNPD). The European Data Protection Board lists EU and EEA supervisory authorities.

14. Children

The commercial UNOVOX website and customer administration area are intended for professional use and are not directed at children. A customer's whistleblowing channel may be made available to younger people where the customer's context requires it; in that case, the customer is responsible for appropriate information, a lawful basis and suitable safeguards.

15. Changes to this policy

We may update this policy to reflect changes to the service, providers, law or regulation. The current version and effective date are published on this page. Material changes affecting existing customers will be communicated through an appropriate channel where required.

16. Contact

MAINSYSTEMS, LDA. — UNOVOX
Av. da República, 50, 2nd floor, 1050-196 Lisbon, Portugal
Privacy: dpo@mainsystems.pt
General enquiries: info@mainsystems.pt
Telephone: +351 211 245 202