Privacy Policy for the Blueprint AG Whistleblower Portal
This policy explains which personal data we process when you use the Blueprint AG whistleblower portal, for what purpose and on what legal basis, who has access, and what rights you have. Protecting your identity is our highest priority.
1. Controller
The controller within the meaning of the General Data Protection Regulation is Blueprint AG, Lindberghstraße 17, 80939 Munich, Germany, represented by its Management Board, Gerhard Meier and Roland Deffner. Contact details are set out in the portal's legal notice.
2. Data protection officer
The data protection officer of Blueprint AG is Sandor Ertl, reachable by phone at +49-89-450 80 69-21 and by email at S.Ertl@blueprint.de. For data protection matters concerning this portal you can also reach the operating reporting office using the contact details in section 18.
3. Operation of the reporting office and processing on behalf
The internal reporting office is operated by intelligent piXel GmbH, Enzianstraße 4a, 82319 Starnberg, Germany, as an independent external reporting office under Section 14 (1) HinSchG. In data protection terms, intelligent piXel GmbH acts as a processor for Blueprint AG under Article 28 GDPR. Your report is reviewed and handled with professional independence; within the scope of tasks defined by law and by contract, intelligent piXel GmbH acts autonomously. This does not affect its status as a processor under Article 28 GDPR. Blueprint AG has no administrative access to the platform or the servers.
4. Principles of processing
We process as little data as possible. You may submit a report without providing personal data. We do not link technical connection data such as IP addresses to the content of your report, to your case identifier or to your identity, and we use no techniques to identify you. For the technically necessary server log files, see section 6.
5. Purpose and general legal basis
The purpose of processing is to receive, review, handle, document and respond to reports under the German Whistleblower Protection Act and to take appropriate follow-up measures. The legal basis is Article 6 (1) (c) GDPR together with the obligations arising from that Act, in particular Sections 10 to 18 HinSchG. If the portal receives reports that do not fall directly within the scope of the Act, we process these on the basis of our legitimate interest under Article 6 (1) (f) GDPR. This legitimate interest lies in particular in detecting and preventing compliance, ethics and other operational rule violations.
6. Accessing the portal and server log files
When you access the portal, the transmission of technically necessary connection data is unavoidable. To protect the system, we process technically necessary server log files including the IP address. This data serves solely to defend against attacks and to maintain secure operation. It is not linked to the content of a report, to a case identifier or to the identity of a whistleblower. The logs are deleted automatically after 14 days. The legal basis is our legitimate interest in a secure and stable portal under Article 6 (1) (f) GDPR.
7. Written report
If you use the online form, we process the content of the report you enter, any details you provide voluntarily, a name you optionally provide, and any files you upload. A name is stored only if you provide it voluntarily. To access your case later, you receive a random case identifier and choose a password. We store the password solely as a non-reversible hash. The legal basis is Article 6 (1) (c) GDPR together with the Act.
8. Reporting by phone with a voice assistant
For reporting by phone we use an AI voice assistant that guides you through the call and responds in several languages, so that language barriers do not stand in the way. The assistant converts speech into text. This voice processing and transcription is carried out by X.AI LLC as a processor. Your caller number is not stored. The technical telephone connection is provided by Twilio Ireland Limited. The transcript of the call is transferred into the portal and handled confidentially in the same way as a written report. If instead you leave a message on the answering machine, technical measures ensure that your voice cannot be used to identify you. The message is converted into text and handled in the same way as a written report. The legal basis is Article 6 (1) (c) GDPR together with the Act.
9. In-person meeting
On request we hold an in-person meeting with you, including by video. For this we process the details you provide to arrange the appointment and the information shared during the meeting. Video calls are never recorded. The legal basis is Article 6 (1) (c) GDPR together with the Act.
10. Case access and communication
Using your case identifier and password, you can view the status of your case and communicate with the reporting office without disclosing your identity. For this we process the identifier, the password hash, the message history, and processing and deadline data.
11. Anonymous reporting
You may report anonymously. If you provide no details about yourself, we process no data that identifies you. We make no attempt to determine your identity.
12. Special categories of personal data
A report may contain special categories of personal data under Article 9 GDPR, such as information about health, if you or affected persons mention them. It may also contain personal data relating to criminal convictions and offences under Article 10 GDPR, such as criminal allegations. We process such data only where necessary to handle your report. The legal basis for data under Article 9 GDPR is Article 9 (2) (g) GDPR together with Section 10 HinSchG. The processing of data under Article 10 GDPR is based on Section 10 HinSchG as the legal authorisation.
13. Recipients and processors
To provide the service we use the following processors: Hetzner Online GmbH for hosting, X.AI LLC for the voice assistant and transcription, and Twilio Ireland Limited for the telephone connection. All are bound by contract under Article 28 GDPR and pass the same data protection obligations on to their own sub-processors. The current sub-processors of these providers can be found in their respective publicly maintained lists. The telecommunications providers involved process connection data within their own data protection responsibility. Information is passed to Blueprint AG only insofar as this is necessary to carry out legally required follow-up measures. The identity of whistleblowers remains protected under Sections 8 and 9 HinSchG.
14. Processing in third countries
Hosting takes place on servers in Germany. X.AI LLC is a company based in the United States. Even where data is held primarily in the European Union, processing in the United States cannot be entirely ruled out. For these transfers, appropriate safeguards under Articles 44 et seq. GDPR are in place. For X.AI LLC, safeguards are provided by the Standard Contractual Clauses of the European Commission; for Twilio Ireland Limited, by Binding Corporate Rules, additional Standard Contractual Clauses and the Data Privacy Framework. We are aware that, despite these safeguards, a residual risk of access by authorities in third countries cannot be entirely ruled out. We selected the providers with this in mind and limited the processing to what is necessary.
15. Retention period and deletion
Your report and the related documentation are deleted three years after the procedure has been concluded (Section 11 (5) HinSchG). For the X.AI LLC voice assistant, zero data retention is enabled, no content is stored after processing is complete, and your data is not used to train AI models. The authoritative record is kept solely within the portal. After the retention period ends, the data is deleted automatically.
16. Confidentiality of your identity
Your identity is treated confidentially under Section 8 HinSchG, including towards Blueprint AG. intelligent piXel GmbH is an external, independent office that protects your confidentiality by all necessary means. Blueprint AG has no administrative access to the platform or the servers and does not learn your identity. Information is passed to Blueprint AG only insofar as this is necessary for legally required follow-up measures. Your identity is protected under Sections 8 and 9 HinSchG and may be disclosed only in the statutory exceptions.
17. Data security
All transmission is encrypted end to end via TLS. Access to reports is reserved exclusively to the independent external reporting office and secured by two-factor authentication. Passwords are stored solely as a hash. Technically necessary server log files are kept separately from the report data and deleted after 14 days (see section 6). Operation takes place on a secured server within the European Union.
18. Your rights
Within the limits provided by law, you have the following rights, insofar as their conditions are met and insofar as this is compatible with confidentiality under Section 8 HinSchG:
- right of access (Article 15 GDPR),
- right to rectification (Article 16 GDPR),
- right to erasure (Article 17 GDPR). As long as and to the extent that we are legally required to document and retain the report (Section 11 HinSchG, Article 17 (3) (b) GDPR), we delete it only once that obligation no longer applies, at the latest three years after the procedure has been concluded,
- right to restriction of processing (Article 18 GDPR),
- right to data portability (Article 20 GDPR), where its conditions are met. As the processing is based on a legal obligation, this right is generally not applicable here,
- right to object (Article 21 GDPR), where processing is based on a legitimate interest,
- right to withdraw any consent given, with effect for the future, where processing is based on consent.
You can in principle exercise your data subject rights vis-à-vis Blueprint AG as the controller, whose contact details are set out in the legal notice. In addition, the operating reporting office is available as a point of contact: intelligent piXel GmbH, Enzianstraße 4a, 82319 Starnberg, Germany, my@intelligent-pixel.com (encrypted via Proton Mail).
You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.
19. No automated decision-making
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place. The voice assistant receives your report and converts it into text; it does not decide on your case. Review and handling are carried out by the responsible person at the reporting office.
20. Protection against reprisals
As a whistleblower you are protected against reprisals under Section 36 HinSchG, including a reversal of the burden of proof in your favour. Further details are set out in the reprisal protection notice on this portal.
21. Cookies and analytics
We do not use any analytics or tracking services. We use only a technically necessary session that is required to access your case. The legal basis for storing this technically necessary information is Section 25 (2) no. 2 TDDDG; no consent is required for this.
22. Fonts and icons
The fonts (Google Fonts) and icons (Lucide) used on this portal are served locally from our own server. Loading the site does not establish any connection to Google or other third-party servers, and no data, in particular no IP addresses, is transmitted to third parties.
23. Changes to this privacy policy
We update this privacy policy when the processing or the legal situation changes. The version published on this portal at the relevant time applies. This version is dated 17 July 2026.
24. Governing language
This page is also provided in English translation. In the event of any discrepancy, only the German version applies.