Terms of use
Internal Reporting System · Whistleblowing Channel of RAO SOCIAL, SL
Purpose of this document
To set out the conditions of access and proper use of the Channel, explain what can be reported, how reports are handled and what guarantees apply to the reporting person and to the persons concerned.
This document supplements the applicable Internal Reporting System Policy, Report Management Procedure, Code of Ethics and Privacy Policy. In case of discrepancy, the legislation in force and the internal documents formally approved by RAO SOCIAL, SL will prevail.
1. Purpose and legal framework
The Whistleblowing Channel, accessed through https://codifosc3.canaletic-test.protecdatus.com, is the main route into the Internal Reporting System of RAO SOCIAL, SL (hereinafter, «RAO SOCIAL»). The Whistleblowing Channel is therefore a part of the Internal Reporting System and does not replace the System Policy, the System Manager or the Report Management Procedure.
Its purpose is to provide a safe route for persons who have obtained information in an employment or professional context to report possible infringements, with guarantees of confidentiality, data protection, independence in handling and a ban on retaliation.
The main legal framework of reference is:
- Directive (EU) 2019/1937 of 23 October 2019 on the protection of persons who report breaches of Union law.
- Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and on the fight against corruption.
- Regulation (EU) 2016/679 of 27 April 2016, the General Data Protection Regulation (GDPR).
- Organic Law 3/2018 of 5 December on the protection of personal data and the guarantee of digital rights (LOPDGDD).
- Criminal, administrative, employment, sector-specific and data protection rules applicable to the reported facts.
Terminology
This document preferably uses the expressions «reporting person» and «report». The expression «Whistleblowing Channel» is kept as an informative name that is easy for users to understand.
2. Who can use the Channel and what can be reported
2.1. Persons who can report
Natural persons who have obtained information about possible infringements in an employment or professional context may use the System. This includes, among others, employees, self-employed persons, shareholders or participants, members of administrative, management or supervisory bodies, persons working for contractors, subcontractors or suppliers, as well as persons whose relationship has ended, volunteers, trainees, persons in training and candidates in selection or pre-contractual negotiation processes.
The protection measures provided for in Law 2/2023 also extend, where appropriate, to the following persons:
- the legal representatives of employees when exercising their functions of advising and supporting the reporting person;
- natural persons who, within the organisation where the reporting person works, assist them in the process;
- natural persons related to the reporting person who may suffer retaliation, such as colleagues or relatives; and
- legal entities for which the reporting person works, or with which they have any other kind of relationship in an employment context or in which they hold a significant interest.
RAO SOCIAL may accept other reports related to ethics, compliance or internal rules. This does not mean, however, that all such reports are automatically protected by the specific regime of Law 2/2023; their content and the applicable legal scope will have to be assessed.
2.2. Facts that may be reported
The Channel is mainly intended for reporting:
- Acts or omissions falling within the material scope of Law 2/2023, especially certain infringements of European Union law.
- Facts that may constitute a criminal offence.
- Facts that may constitute a serious or very serious administrative infringement, including those involving economic loss to the Public Treasury or Social Security under the terms of the law.
- Other breaches of the Code of Ethics or of the internal rules that RAO SOCIAL has decided to channel through the same System.
2.3. Reports that may require another channel
Strictly interpersonal complaints, ordinary management disagreements or conflicts affecting exclusively private interests are not, as a general rule, covered by the protection regime of Law 2/2023. Where there is a specific channel for human resources, prevention, harassment, consumer matters, data protection or customer service, the report may be redirected to the corresponding procedure, without prejudice to an analysis of the case determining that the facts also fall within the scope of Law 2/2023.
3. Principles of use: voluntariness, good faith and reasonable truthfulness
Use of the Channel is voluntary. The reporting person does not have to provide conclusive evidence to be protected, but must have reasonable grounds to believe that the information is true at the time of reporting and that the facts may fall within the scope of legal protection.
Important
The fact that a report cannot later be proven does not, in itself, mean that it is false or that it was made in bad faith. Protection depends on the reasonableness and good faith present at the time the facts are reported.
A report or public disclosure made knowing that the information is false is not covered by legal protection. Law 2/2023 classifies this conduct as a very serious infringement and, where the person responsible is a natural person, provides for fines of €30,001 to €300,000, without prejudice to other responsibilities that may apply.
As regards how the information was obtained, legal protection does not exempt from liability where acquiring or accessing the information is itself a criminal offence. Nor does it cover other actions unrelated to the report that are not necessary to disclose an infringement.
The reporting person should try to provide specific, relevant and proportionate information, avoiding third-party personal data that are not necessary to understand or investigate the facts.
4. How to submit a report
A report can be submitted, identified or anonymously, through the secure form of the web channel (https://codifosc3.canaletic-test.protecdatus.com). Where the channel has it enabled, it can also be made by recording a voice message on the same channel or by postal mail to C/BHFUIS FHIS, for the attention of the System Manager. Anonymity does not prevent the report from being received or handled.
Each report submitted through the web channel receives a tracking code, shown at the moment of sending, which allows you to check its status, receive replies and provide additional information without having to identify yourself. Anyone wishing to report anonymously only has to avoid providing identifying data; if the report is sent by postal mail without a sender, RAO SOCIAL will not be able to contact you. RAO SOCIAL will in no case try to find out the identity of an anonymous reporting person.
When the reporting person identifies themselves, they may indicate an address, an email address or another safe place to receive notifications.
Queries about the use of the Channel or about the scope of the reporting person's protection can also be raised through the same route. Queries are not considered reports of an infringement.
If the reporting person requests an in-person meeting, the legally established guarantees will apply and the meeting must be arranged within a maximum of seven days. If a verbal report is recorded or transcribed, the reporting person will be informed beforehand and may check, correct and accept the transcript where applicable.
Practical recommendation
Keep the tracking code in a safe place: it is the only way to access your report and it cannot be recovered. Do not share it with third parties who do not need to be involved in the report.
5. Receipt, investigation and deadlines
The System Manager (Maria puig) is responsible for the diligent handling of reports and acts independently and autonomously in carrying out their duties.
As general rules of the procedure:
- An acknowledgement of receipt will be sent within seven calendar days of receipt, unless this could jeopardise the confidentiality of the report.
- Communication with the reporting person may be maintained and additional information requested when necessary.
- The ordinary maximum period to respond to the investigation is three months. In cases of special complexity, it may be extended by up to three additional months.
- The person concerned by the facts will be informed and heard at the time and in the manner that preserves the success of the investigation.
- If the facts could constitute a criminal offence, the matter will be referred to the Public Prosecutor's Office; if they affect the financial interests of the European Union, they will be sent to the European Public Prosecutor's Office.
The reply to the reporting person does not necessarily imply disclosing confidential information about internal investigations, third-party data, disciplinary measures or actions subject to confidentiality duties.
6. Guarantees for the reporting person
The System must be managed securely and with the following guarantees:
- Confidentiality of the identity of the reporting person and of any third party mentioned, as well as of the handling and investigation activities.
- Possibility to submit and process anonymous reports, without trying to identify the anonymous reporting person.
- Restricted access to legally authorised persons and application of technical and organisational security measures.
- Independence, impartiality and absence of conflicts of interest in handling.
- Ban on retaliation, including threats and attempted retaliation, where the legal conditions for protection are met.
The identity of a reporting person who has identified themselves will not be disclosed to the person to whom the facts refer. It may only be disclosed to the judicial authority, the Public Prosecutor's Office or the competent administrative authority in the context of a criminal, disciplinary or sanctioning investigation and with the legally established safeguards.
Protection against retaliation
Protection may cover, among other cases, unjustified dismissals or penalties, demotions, denial of promotion or training, intimidation, harassment, reputational damage, blacklisting, financial loss or any unfavourable treatment motivated by having reported information under the legally protected conditions.
7. Rights and guarantees of the person concerned
Protection of the reporting person is compatible with the rights of the person to whom the facts are attributed. During the handling, the person concerned keeps the right to the presumption of innocence, the right of defence, the right to be heard, to honour and to the confidential treatment of their data.
Information about the facts must be provided at the right time and in the right way so as not to jeopardise the investigation or make it easier to conceal, destroy or alter evidence. In no case will the identity of the reporting person be disclosed to them.
8. External channels and freedom of choice
The existence of the internal Channel does not prevent going directly to the external channels of the competent authorities. Law 2/2023 provides for the external channel of the Independent Authority for Whistleblower Protection (AIPI), an independent administrative authority (A.A.I.), as well as the channels of the regional or sector-specific authorities that are competent (in Catalonia, the Anti-Fraud Office of Catalonia, within its powers) and, where appropriate, of the institutions, bodies or agencies of the European Union. The reference supervisory authority is: Oficina Antifrau de Catalunya.
RAO SOCIAL will provide clear and accessible information about these external channels within the public information of the Internal Reporting System.
9. Protection of personal data
RAO SOCIAL, SL, as the organisation that implements the Internal Reporting System, is the controller of the personal data associated with the reports, without prejudice to the processing agreements or other roles that apply to technology providers according to the services actually provided and the contracts signed.
Providers that process personal data on behalf of RAO SOCIAL must act as data processors under Article 28 of the GDPR and only on documented instructions, with confidentiality and security obligations.
Access to the data in the System is limited, within their functions, to legally authorised persons, which may include:
- the System Manager and the person directly handling it;
- the human resources function or the competent body, only where disciplinary measures may be taken;
- the legal services, where legal measures may be taken;
- any data processors that have been appointed;
- the Data Protection Officer, where applicable.
Personal data that are not necessary to know and investigate the facts must not be processed. Unnecessary data must be deleted without delay and the specific rules provided by law for special categories of data will apply.
Data will be kept in the receiving system only for the time strictly necessary to decide whether to start an investigation. If three months pass from receipt without any investigation having started, they must be deleted from the system, except to keep anonymised evidence of its operation. Data from investigations that have started may be kept outside the system for the necessary and proportionate time, and the register may not keep personal data for more than ten years.
Full information on purposes, legal bases, recipients, retention and exercise of rights is set out in the Privacy Policy of the Internal Reporting System of RAO SOCIAL, SL.
10. Ownership and technical support of the software
The Channel runs on the free software GlobaLeaks, deployed and maintained by PROTECDATUS Consultors, SL, which provides the technical support of the Channel and acts as data processor on behalf of RAO SOCIAL, SL.
RAO SOCIAL will keep this information up to date in the event of a change of provider, platform or support service.
11. Cookies, security and availability of the portal
The portal does not use cookies. If cookies or similar technologies requiring information or consent were introduced in the future, RAO SOCIAL will update this notice before using them.
RAO SOCIAL and its providers will apply the technical and organisational measures necessary to preserve the confidentiality, integrity and availability of the information, although this does not allow absolute, uninterrupted availability to be guaranteed in the face of technical incidents, maintenance or force majeure.
12. Acceptance, updates and precedence
Accessing and using the Channel means that the user has had the opportunity to read these terms. These terms cannot limit the rights and guarantees recognised by Law 2/2023, the GDPR or other applicable legislation.
RAO SOCIAL may update this document to adapt it to legal changes, criteria of the competent authorities, changes to the Management Procedure or technical changes to the platform. The current version must be identified and easily accessible from the Channel.
Version control
| Implementation | 8 October 2026 |
| Last review of the documentation | 8 October 2026 |
This document is informative and does not constitute individual legal advice. These terms cannot limit the rights and guarantees recognised by Law 2/2023, the GDPR or other applicable legislation. The current version will be identified and accessible from the Channel.