Privacy policy
Internal Reporting System · Whistleblowing Channel of RAO SOCIAL, SL
Purpose of this document
To inform, clearly and transparently, how RAO SOCIAL, SL processes the personal data associated with the reports received through its Internal Reporting System, as well as the guarantees of confidentiality, restricted access, retention and exercise of rights.
1. Introduction and legal framework
This Privacy Policy governs the processing of personal data carried out by RAO SOCIAL, SL (hereinafter, «RAO SOCIAL») when receiving, handling, analysing and, where applicable, investigating the reports submitted through its Internal Reporting System (hereinafter, the «System»), commonly known as the whistleblowing or alert channel.
The System has been set up in accordance with the applicable data protection and whistleblower protection rules, in particular:
- Regulation (EU) 2016/679 of 27 April 2016, the General Data Protection Regulation (GDPR).
- Organic Law 3/2018 of 5 December on the protection of personal data and the guarantee of digital rights (LOPDGDD).
- Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and on the fight against corruption.
The interpretive criteria of the Spanish Data Protection Agency (AEPD) on internal reporting systems and the defence of the reporting person are also taken into account.
2. Identity of the data controller
| Data controller | RAO SOCIAL, SL |
| Tax ID (NIF) | B55334106 |
| Address | C/BHFUIS FHIS |
| Telephone | 972 65984648 |
| Commercial Register | RMN GIRONA HF UISHFIUSF |
| Whistleblowing channel | https://codifosc3.canaletic-test.protecdatus.com |
| System Manager | Maria puig |
The technology platform of the Channel is provided and maintained by PROTECDATUS Consultors, SL (Tax ID B55334106, C/ Pla de Dalt, 5 · 17840 Sarrià de Ter, Girona), which acts as data processor on behalf of RAO SOCIAL, SL, in accordance with Article 28 of the GDPR.
3. Purposes and legal basis of the processing
The personal data collected through the System are processed exclusively to receive and handle reports, assess their admissibility, keep in contact with the reporting person where possible and, where applicable, carry out or channel the investigation of the reported facts and adopt the appropriate measures.
The System of RAO SOCIAL is established as an internal compliance and integrity mechanism. In internal systems implemented voluntarily, Law 2/2023 presumes that the processing is covered by Article 6.1.e of the GDPR, as it is necessary for the performance of a task carried out in the public interest. If the processing arose from a legal obligation to have the System, the legal basis would be Article 6.1.c of the GDPR, in accordance with Article 30 of Law 2/2023.
Where a report includes special categories of data that are necessary for the investigation, the processing will be based on Article 9.2.g of the GDPR, in accordance with Article 30.5 of Law 2/2023. Data that are not necessary will be deleted immediately.
3.1. Categories of data and source
The data come from the report itself and from the handling and investigation activities, and may relate to the reporting person, the person concerned by the facts and third parties mentioned in them. The following categories of data may be processed:
- identification and contact details, when the reporting person decides to identify themselves;
- professional or employment data linked to the reported facts;
- the description of the facts and the documents, images or voice recordings provided; and
- the data generated during the handling and, where applicable, the investigation.
Reports may be submitted anonymously. In that case, no identifying data of the reporting person will be processed and no attempt will be made to find out their identity.
Scope of the protection under Law 2/2023
The System may also be used to report internal breaches. However, the specific protection status of the reporting person under Law 2/2023 applies when the reported information falls within its material scope.
4. Data retention
Data will be kept within the System only for the time strictly necessary to decide whether an investigation of the reported facts should be started.
- If three months pass from receipt of the report without any investigation having started, the data must be deleted from the System, unless the only purpose of keeping them is to leave evidence of how the System works. Reports that have not been followed up may only be kept in anonymised form.
- In these cases the blocking obligation provided for in Article 32 of the LOPDGDD does not apply.
- If it is proven that the information provided, or part of it, is not truthful, it will be deleted immediately from the moment this becomes known, unless the lack of truthfulness may constitute a criminal offence. In that case, the information will be kept for as long as necessary for the court proceedings.
- Data that are not necessary to know and investigate the facts, or that refer to conduct not covered by the System, will be deleted immediately.
- If an investigation is started, the necessary information may continue to be processed outside the System, in the corresponding file or management environment, for the time needed for the investigation and to meet any resulting legal responsibilities.
- RAO SOCIAL will keep, where required, a register of the information received and of the internal investigations, with confidentiality guarantees. The personal data recorded in it will be kept only for the necessary and proportionate period and, in no case, for more than ten years.
Key retention criterion
Three months is the general limit for data to remain in the System when no investigation has started. The ten-year maximum applies to the register regulated in Article 26 of Law 2/2023, not to the ordinary retention of the report within the channel.
5. Recipients and disclosure of data
Data will not be disclosed to third parties, unless necessary to handle the report, adopt corrective measures or conduct disciplinary, sanctioning or criminal proceedings, or where there is a legal obligation.
- External professionals who provide support in handling, preparing or investigating a case may be involved, always subject to confidentiality duties and, where appropriate, to a data processing agreement under Article 28 of the GDPR.
- The provider of the technology platform of the Channel, PROTECDATUS Consultors, SL, acts as data processor on behalf of RAO SOCIAL.
- The identity of the reporting person may only be disclosed to the judicial authority, the Public Prosecutor's Office or the competent administrative authority in the context of a criminal, disciplinary or sanctioning investigation, with the legally established safeguards. Before disclosing it, the reporting person will be informed, unless this could jeopardise the investigation or the court proceedings.
- No international transfers of data are foreseen.
- Regarding the protection of reporting persons, it is possible to go to the Independent Authority for Whistleblower Protection (AIPI) and to the competent supervisory authority: Oficina Antifrau de Catalunya.
6. Exercise of rights
Data subjects may exercise, under Articles 15 to 22 of the GDPR and with the limitations necessary to preserve the identity of the reporting person, the rights of access, rectification, erasure, restriction of processing and objection, as well as any other rights that apply in each case.
- The person concerned by the reported facts will in no case be told the identity of the reporting person, nor may they obtain it by exercising the right of access.
- When the person concerned exercises the right to object, it will be presumed —unless proven otherwise— that there are compelling legitimate grounds that justify continuing the processing.
To exercise their rights, data subjects can contact RAO SOCIAL by the following means:
- Postal mail: RAO SOCIAL, SL · C/BHFUIS FHIS.
- Telephone: 972 65984648.
The request must allow the data subject to be identified and specify the right they wish to exercise. RAO SOCIAL will only ask for additional information to verify identity where there are reasonable doubts about who is making the request.
If they consider that the processing does not comply with the rules, data subjects may lodge a complaint with the Spanish Data Protection Agency (AEPD), through www.aepd.es or the other officially available channels.
7. Data minimisation and quality
RAO SOCIAL applies the principles of minimisation, accuracy and purpose limitation. Accordingly, the data processed:
- will be limited to what is strictly necessary to assess and handle a specific report;
- will not be used for purposes incompatible with the operation of the System;
- will be deleted without undue delay when their relevance is not evident or they were collected accidentally without being necessary; and
- will be processed only by authorised persons and for the applicable periods.
8. Restricted access to the information
Access to the personal data held in the System is limited, within their respective powers and functions, to the persons or functions expressly provided for in Law 2/2023:
- the System Manager (Maria puig) and the person or entity directly handling it;
- the person in charge of human resources, only where disciplinary measures against an employee may be taken;
- the person in charge of legal services, where legal measures may be taken;
- any data processors that may be appointed; and
- the data protection officer, where there is one.
Access or disclosure to other persons will also be lawful when strictly necessary to adopt corrective measures or conduct sanctioning or criminal proceedings.
9. Security, confidentiality and protection of identity
RAO SOCIAL applies appropriate technical and organisational measures to preserve the confidentiality, integrity and availability of the information, prevent unauthorised access and ensure the traceability of the management of the System. Reports received through the web channel are transmitted and stored encrypted.
- The identity of the reporting person is confidential and will not be disclosed to the persons to whom the reported facts refer.
- Confidentiality also extends to the persons concerned and to any third party mentioned in the report.
- Persons with access to the System are subject to a reinforced duty of secrecy, discretion and confidentiality.
Confidentiality commitment
Protecting the identity of the reporting person is a core guarantee of the System. Any disclosure of their identity is limited to the cases and authorities expressly provided for by Law 2/2023.
Version control
| Implementation | 8 October 2026 |
| Last review of the documentation | 8 October 2026 |
| Review basis | GDPR · LOPDGDD · Law 2/2023 · AEPD criteria |
This document explains how personal data are processed in the Internal Reporting System of RAO SOCIAL, SL and does not constitute individual legal advice. Rights may be exercised before RAO SOCIAL and, where applicable, a complaint may be lodged with the Spanish Data Protection Agency (AEPD). The current version will be identified and accessible.