Skip to content

Compliance hub

Just visiting? Most people only need three documents:PrivacyCookiesTerms

Enforced in the product, not just written down

The documents below describe commitments; these are the mechanisms that keep them. Each one runs in every Whistle deployment, automatically.

Live trust panel, per client

Every client portal includes a live compliance snapshot generated from that deployment's own config and audit log: consents recorded, AI decisions logged, human overrides, DSAR activity and the last retention purge. Real numbers, not authored copy.

Audit trail on every AI decision

Each qualification outcome the AI proposes is logged, visible to your team, and reversible. Overrides are recorded, so human oversight is demonstrable, not asserted.

Retention that purges itself

Per-client retention periods are enforced by a daily automated purge, and the audit log itself has a bounded lifetime. Storage limitation as a cron job, not a policy PDF.

Data-subject rights, built in

Export and erasure run as first-class operations with a public rights page for visitors, so DSARs are fulfilled from tooling rather than improvised from backups.

Consent, versioned

Every consent is stamped with the exact consent-notice version the visitor saw, so you can evidence what was agreed to and when, even after the wording evolves.

Clean exits, certified

Offboarding revokes access, deletes configuration and data on schedule, and ends with a signed certificate of deletion. Self-serve account deletion carries a 30-day grace period.

For your DPO

The review pack: processor terms, transfer analysis and templates pre-filled with Whistle's details.

For the managing partner

What you are agreeing to and what happens if something goes wrong.

For IT and security

The technical posture, pre-answered for your vendor review.

Please note. These are GDPR-aligned templates and must be reviewed by a qualified data-protection lawyer or DPO before commercial reliance. Not legal advice.

The full pack: all 21 documents, versioned and published in full. Open a section, or search the page.

Legal agreements(4 documents)

The contractual stack. The DPA applies automatically with every plan; a signable client-specific copy comes with onboarding.

Privacy(5 documents)

How personal data is handled across the Amaigo site and every Whistle deployment.

AI and transparency(3 documents)

Built for EU AI Act Article 50 and for professional confidentiality duties.

Security(3 documents)

EU-hosted, privacy by design, and pre-answered due diligence for your vendor review.

For your DPO(5 documents)

Templates your organisation can complete for its own records, pre-filled with Whistle's details.

Stay informed of changes

Every document is versioned; the change log is the canonical record, and clients get 30 days' advance email notice of sub-processor changes.

Subscribe to sub-processor updates

Certification roadmap

We do not yet hold SOC 2, ISO 27001 or Cyber Essentials; they are on the roadmap as the platform matures. In the meantime the security questionnaire pre-answers the due-diligence questions those reports cover. Every document here prints cleanly to PDF for your records.