MAINSYSTEMS is the controller for this website, commercial contacts and customer account administration. For reports and case data processed in a customer's UNOVOX environment, the customer is normally the controller and MAINSYSTEMS acts as processor, under that customer's documented instructions and the Data Processing Agreement. We do not sell personal data. The reporting portal can be used without identification and does not log the reporting person's IP address.
1. Scope
This policy applies to www.unovox.com, to contact and subscription forms, to commercial interactions regarding UNOVOX, to customer account administration and to the technical provision of the UNOVOX platform as software as a service. A customer must publish its own privacy notice on its whistleblowing channel; that notice governs the customer's processing and should be read together with this policy.
This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”). In the whistleblowing context, Directive (EU) 2019/1937 and the national transposition applicable to each customer are also relevant. On this global version of the site, no specific national law is asserted; country versions of this page describe the applicable national framework.
2. Who we are and our roles
UNOVOX is a product operated by MAINSYSTEMS, LDA., with contact address at Av. da República, 50, 2.º andar, 1050-196 Lisbon, Portugal (“MAINSYSTEMS”, “we” or “us”). Data protection questions can be sent to our privacy contact: dpo@mainsystems.pt.
- Controller: for website visits, demo or proposal requests, subscriptions, billing contacts, support and administration of customer and user accounts, MAINSYSTEMS determines the purposes and means of processing.
- Processor (Article 28 GDPR): for reports, messages, attachments, investigation records and other case content submitted or created in a customer's UNOVOX environment, it is normally the customer that determines the purposes and means; MAINSYSTEMS processes that data under documented instructions and the Data Processing Agreement.
- Customer responsibility: the organisation operating the channel must provide its own notice, identify the legal bases, define permissions and retention, keep the legally required register of reports and answer requests to exercise rights relating to its cases.
3. Data we may process
Website, commercial and contractual data
- professional identification and contact data, such as name, business email, phone, organisation, role and country;
- information included in demo, proposal, subscription, partnership or support requests;
- contract, subscription, billing and transaction records, excluding full card data where payment is handled by a specialised provider;
- communications and records needed to manage the commercial relationship and support.
Account and service usage data
- user name, business email, role, organisation, permissions and authentication information;
- technical and security logs of authorised users of the management area, such as access dates and times, browser and device information, IP address where needed for service and security logs, actions taken and incident records;
- configuration, usage, support and diagnostic information needed to operate and improve the service.
Report and case data
Depending on the customer's configuration and on what a reporting person or authorised user enters, a case may contain identity and contact data, employment or professional information, statements, messages, attachments, data about alleged conduct, special categories of data (Article 9 GDPR) and data relating to suspected offences (Article 10 GDPR). MAINSYSTEMS does not determine which reports a customer receives and does not use case content for advertising.
4. Anonymity on the reporting portal
UNOVOX can be configured to accept reports without requiring the reporting person's identity. To protect anonymity:
- the report submission portal does not log the IP address and does not build browsing profiles of reporting persons;
- the portal does not use analytics or marketing cookies;
- later communication with an anonymous reporting person happens through a follow-up code, with no identification required.
Anonymity can still be affected by factors outside our control: if the person identifies themselves in the description or attachments (including file metadata), if they use an organisational device or network monitored by third parties, or if they communicate through another channel.
5. Where data comes from
We obtain data directly from you, from the customer that creates or manages your account, from authorised users of the service, from reporting persons and other people mentioned in case content, from technical and security logs and from the providers used to run the website and platform. Where a subscription is made through an authorised partner, we may receive from that partner the contact and contractual data needed to provide the service. In case content, third-party data (for example, persons concerned by a report) is entered by reporting persons or by the customer, not by MAINSYSTEMS.
6. Purposes and legal bases
| Purpose | Typical data | Legal basis (GDPR) |
|---|---|---|
| Answering contacts, preparing demos and proposals | Contact and request data | Art. 6(1)(b): pre-contractual steps; Art. 6(1)(f): legitimate interest in answering professional requests |
| Contracting, providing, administering and supporting UNOVOX | Account, contract, usage and support data | Art. 6(1)(b): performance of the contract; Art. 6(1)(f): service administration |
| Managing partner relationships and partner-sourced subscriptions | Contact and contractual data provided by the partner | Art. 6(1)(b): contract; Art. 6(1)(f): management of the partner channel |
| Billing, accounting and legal compliance | Contract records, invoices and transactions | Art. 6(1)(b) and (c): contract and legal obligations |
| Protecting the website and service, preventing abuse and investigating incidents | Technical, authentication and security log data | Art. 6(1)(f): legitimate interests; Art. 6(1)(c) where applicable |
| Measuring website performance and improving content | Cookie identifiers and aggregated browsing data | Art. 6(1)(a): consent for non-essential analytics technologies |
| Sending requested communications or marketing | Name, organisation, email and preferences | Art. 6(1)(a): consent where required; Art. 6(1)(f) for proportionate B2B communications, always with a simple opt-out |
| Establishing, exercising or defending legal claims | Contract, service and communication records | Art. 6(1)(f): legitimate interest; Art. 9(2)(f) where applicable |
| Processing customers' case data | Reports, messages, attachments and investigation records | The customer's documented instructions (Art. 28); the customer determines the applicable basis, typically Art. 6(1)(c) together with its national whistleblowing law |
Where processing is based on consent, you can withdraw it at any time, without affecting processing already carried out. Where we rely on legitimate interests, you can request information about the balancing performed and object under Article 21 GDPR.
7. Reports and confidential case data
Access to case data is limited to the users authorised by the customer and to the people who need access to provide or protect the service. MAINSYSTEMS teams may only access case information where needed for authorised support, security, incident response, legal compliance or maintenance, subject to confidentiality and access controls. Commercial partners have no access to customers' case data unless the customer itself grants it through the platform's permissions. We do not decide whether a report is founded, which investigation steps should be taken or whether anyone should be subject to a measure; those decisions belong to the customer.
The identity of the reporting person, and other information from which it can be deduced, is confidential under Article 16 of Directive (EU) 2019/1937 and the national transposition applicable to the customer, and may only be disclosed in the cases provided for there, notably under a legal obligation or judicial decision. Requests to exercise rights relating to a report should, as a rule, be addressed to the organisation operating the channel; we will assist the customer under the Data Processing Agreement. Data subject rights, including those of persons concerned, may be restricted where necessary to protect the reporting person's identity, the rights of third parties, an ongoing investigation, professional secrecy or another legally protected interest.
8. AI Agents and assisted processing
If a customer enables AI Agents, the customer chooses the categories and scope in which they may organise information and perform configured investigation tasks. Outputs may contain errors or require context. Final validation and material decisions remain the responsibility of an authorised human case manager; no decision with legal or similarly significant effects on a person is taken solely by automated processing through the platform. MAINSYSTEMS does not use customers' case content to train general-purpose models, except with the customer's express agreement and a valid legal basis. Any authorised AI subprocessor is bound by contractual confidentiality, security and data protection obligations.
9. Cookies, analytics and anti-abuse technology
On the commercial website we use strictly necessary technologies to run the site, remember consent preferences, protect forms and prevent automated abuse. Forms use Cloudflare Turnstile. We also use Cookiebot to manage consent and Google Tag Manager to manage measurement tags. Google Analytics 4 is only activated according to the choices made in the banner. We do not use website analytics data to identify the content of a report, and the reporting portal uses no analytics or advertising technologies.
You can change or withdraw consent for non-essential cookies at any time through the cookie settings available on the site. Blocking strictly necessary technologies may prevent forms or security checks from working.
10. Recipients and subprocessors
Data may be made available, on a need-to-know basis, to MAINSYSTEMS teams, to the customer and its authorised users, to authorised partners involved in the subscription or in commercial support for the customer's service, to providers of hosting and infrastructure, email and communications, security and abuse prevention, analytics and consent management, payments and billing, to professional advisers, auditors and public authorities where disclosure is legally required. Providers and partners are bound by contractual obligations appropriate to their role. We do not sell or rent personal data.
Customers can request the list of subprocessors relevant to their service and will be informed of material changes under the Data Processing Agreement.
11. International transfers
Data is hosted and processed in the European Economic Area. Where a provider or support operation involves a country outside the EEA, we rely on a legal transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses and supplementary measures where appropriate. Customers can request further information about the safeguards relevant to their service.
12. Retention
We keep data only for as long as needed for the stated purpose, taking into account contractual obligations, statutory limitation periods, security requirements and the need to establish, exercise or defend legal claims.
- commercial requests and related correspondence are, as a rule, kept for up to 24 months after the last relevant interaction, unless a contract is concluded or a longer period is justified;
- customer, contract, billing and accounting records are kept for the duration of the relationship and for the mandatory statutory periods, including applicable tax periods;
- account and support records are kept while the account is active and for the period needed to close, audit and defend the relationship;
- technical and security logs are kept for a proportionate period and may be kept longer when linked to an incident;
- customers' case data is kept according to the customer's instructions, the law applicable to the customer and the Data Processing Agreement. National transpositions of Directive (EU) 2019/1937 typically require the customer to keep a register of reports for a legally defined period, which varies by country.
At the end of the service, customer data is returned or deleted under the contract, applicable law and the customer's documented instructions, without prejudice to secure backup cycles and legal preservation obligations.
13. Security
We apply technical and organisational measures appropriate to the risk, including access controls and role-based permissions, protected authentication with encrypted password storage, access to the website and platform over HTTPS connections, segregation of each customer's environment, activity logs, backups, vulnerability management and incident response procedures. No Internet service can guarantee absolute security. Customers should configure permissions carefully, keep credentials confidential and promptly report any suspected compromise.
In the event of a personal data breach that we process as controller, MAINSYSTEMS assesses the risk and notifies the supervisory authority within the statutory 72 hours where required by Article 33 GDPR, and the data subjects where there is a high risk (Article 34). Where acting as processor, MAINSYSTEMS notifies the customer without undue delay after becoming aware of the breach, as set out in the Data Processing Agreement.
14. Your rights
Under the conditions of applicable law, you can request access, rectification, erasure, restriction, portability or object to processing (Articles 15 to 21 GDPR). You can withdraw consent and may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22).
For data controlled by MAINSYSTEMS, contact dpo@mainsystems.pt. We reply within one month, extendable as legally permitted, and may request information needed to confirm identity and locate the data. For data held in a customer's channel, contact that customer; if you contact us, we will forward or support the request without improperly disclosing confidential case information. In the whistleblowing context, the exercise of rights may be restricted to the extent necessary to protect the confidentiality of the reporting person's identity and the integrity of the follow-up, under the law applicable to the customer.
You can lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), which oversees MAINSYSTEMS, or with the supervisory authority of your habitual residence or place of work in the EEA.
15. Children
The UNOVOX commercial website and the customer administration area are intended for professional use and are not directed at children. A customer's whistleblowing channel may be made available to younger people where that customer's context requires it; in that case, the customer must ensure appropriate information, legal basis and safeguards.
16. Changes to this policy
We may update this policy to reflect changes to the service, providers, law or regulation. The current version and effective date are published on this page. Material changes affecting existing customers will be communicated by appropriate means where required.
17. Contact
MAINSYSTEMS, LDA. (UNOVOX)
Av. da República, 50, 2.º andar, 1050-196 Lisbon, Portugal
Privacy: dpo@mainsystems.pt
General: info@mainsystems.pt
Phone: +351 211 245 202