Privacy notice
Reviewed for the current release
Heard Hotline is operated by PerformancePoint LLC as a processor on behalf of the organization that publishes each reporting portal. This notice explains what we collect, what we deliberately do not collect, and how long anything survives.
What we do not collect
The web intake form does not record your IP address, browser fingerprint, device identifiers, or geolocation. No advertising or analytics trackers run on the reporting or status pages. We do not require an account, an email address, or a phone number to file a report.
For abuse prevention only, we derive a salted one-way hash of coarse connection characteristics to rate-limit submissions and passphrase guessing. That hash cannot be reversed to an IP address and is discarded on a rolling window.
What we collect
- The content you type into the report, including any identities you choose to name.
- Files you attach. These are re-encoded on our servers under a sanitised filename, which removes camera GPS coordinates, device serials, and document authorship metadata before storage.
- Your name and contact details only if you select the “identified” option.
- A one-way hash of your case passphrase. The passphrase itself is never stored.
- An append-only audit record of case activity: status changes, messages, file access, and exports.
Anonymity levels
Anonymous — no identity is captured. Contact is only possible through the passphrase-protected status portal.
Semi-anonymous — your identity is held by the independent intake team and withheld from the employer’s staff unless you consent to release it.
Identified — your name and contact details are visible to the assigned investigation team.
If a phone channel is enabled for an organization, it is described as confidential rather than anonymous: telecommunications carriers create their own call records outside our control. Caller numbers are hashed on receipt and are not stored in readable form.
Who can see a report
Access is restricted to the designated recipients and investigators of the organization that owns the portal, enforced at the database level. If a report names a designated recipient, that person’s access is revoked automatically and the case is routed to an independent alternate. Every view, message, download, and export is written to the immutable ledger.
Retention and deletion
Each organization configures a retention window (five years by default). When the window elapses, the case is either anonymised — narrative and personal data destroyed, statistics retained — or purged entirely, according to that organization’s policy. Cases placed under legal hold are excluded from both until the hold is released.
Your rights
Where GDPR, UK GDPR, or comparable law applies, data subjects may request access, correction, erasure, restriction, or portability of their personal data. Because Heard Hotline acts as a processor, requests are directed to the organization that published the portal; we assist them in responding. Requests that would unmask an anonymous reporter, or prejudice an active investigation, may be lawfully refused.
Security
Data is encrypted in transit and at rest. Evidence files live in a private vault reachable only through short-lived signed links issued to authorised investigators. Administrator accounts can be required to use two-factor authentication. The audit ledger is hash-chained, so altering or deleting a past entry invalidates every subsequent hash.
Contact
PerformancePoint LLC · performancepointllc.com. Privacy questions concerning a specific portal should be addressed to the publishing organization’s compliance officer.