Data processing addendum
Reviewed for the current release
This addendum forms part of the agreement between the subscriber (controller) and PerformancePoint LLC (processor) and reflects the requirements of GDPR Article 28 and comparable regimes.
Subject matter and duration
We process personal data solely to provide the Heard Hotline service for the term of the subscription, plus the 30-day export window described in the terms of service.
Nature and purpose
Receipt, storage, routing, and case management of whistleblower reports; anonymous messaging between reporters and investigators; SLA and reminder processing; audit logging; reporting and export.
Categories of data subject and data
- Reporters — narrative content and, where they elect to identify themselves, name and contact details.
- Individuals named in reports — identity and allegation details, which may include special-category data.
- Subscriber personnel — console account name, email, role, and activity records.
Controller instructions
We process personal data only on the controller’s documented instructions, which are given through the configuration and use of the service, unless required otherwise by law — in which case we notify the controller unless the law forbids it.
Confidentiality and personnel
Personnel with access to personal data are bound by confidentiality obligations and receive training appropriate to whistleblower data. Access is granted on least-privilege terms and logged.
Security measures
- Encryption in transit (TLS) and at rest.
- Row-level tenant isolation enforced in the database, not only in application code.
- Private evidence vault with short-lived signed access links.
- Metadata scrubbing on upload; one-way hashing of passphrases and abuse-prevention identifiers.
- Append-only, hash-chained audit ledger with an on-demand integrity verification report.
- Two-factor authentication available for all console accounts and enforceable for administrators.
- Automated backups with restoration testing, and documented retention and purge routines.
Sub-processors
We use a small set of sub-processors for cloud hosting and database services, transactional email delivery, and — only where a subscriber enables the phone channel — telephony and transcription. Report content is never sent in notification emails; alerts contain only a case reference and a link to the console. We give notice of new sub-processors and the controller may object on reasonable data protection grounds.
Assistance to the controller
We assist the controller in responding to data subject requests, in carrying out data protection impact assessments, and in consulting supervisory authorities, taking into account the nature of processing and the information available to us.
Personal data breach
We notify the controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting their data, with the information required for the controller to meet its own notification obligations.
International transfers
Where personal data is transferred outside the EEA or UK, transfers are made under Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary measures. Data residency in a specific region can be arranged on request.
Deletion, return and audit
On termination the controller may export all data; we then delete it, subject to legal holds. We make available the information necessary to demonstrate compliance with this addendum and allow audits, including inspections, conducted on reasonable notice and subject to confidentiality.