Compliance hub
Enforced in the product, not just written down
The documents below describe commitments; these are the mechanisms that keep them. Each one runs in every Whistle deployment, automatically.
Live trust panel, per client
Every client portal includes a live compliance snapshot generated from that deployment's own config and audit log: consents recorded, AI decisions logged, human overrides, DSAR activity and the last retention purge. Real numbers, not authored copy.
Audit trail on every AI decision
Each qualification outcome the AI proposes is logged, visible to your team, and reversible. Overrides are recorded, so human oversight is demonstrable, not asserted.
Retention that purges itself
Per-client retention periods are enforced by a daily automated purge, and the audit log itself has a bounded lifetime. Storage limitation as a cron job, not a policy PDF.
Data-subject rights, built in
Export and erasure run as first-class operations with a public rights page for visitors, so DSARs are fulfilled from tooling rather than improvised from backups.
Consent, versioned
Every consent is stamped with the exact consent-notice version the visitor saw, so you can evidence what was agreed to and when, even after the wording evolves.
Clean exits, certified
Offboarding revokes access, deletes configuration and data on schedule, and ends with a signed certificate of deletion. Self-serve account deletion carries a 30-day grace period.
For your DPO
The review pack: processor terms, transfer analysis and templates pre-filled with Whistle's details.
For the managing partner
What you are agreeing to and what happens if something goes wrong.
For IT and security
The technical posture, pre-answered for your vendor review.
The full pack: all 21 documents, versioned and published in full. Open a section, or search the page.
Legal agreements(4 documents)
The contractual stack. The DPA applies automatically with every plan; a signable client-specific copy comes with onboarding.
Terms of Service
v2.0Commercial terms, incorporating the DPA, AUP, SLA and AI Transparency Notice.
Updated 2026-07-08
Data Processing Agreement
v2.1Article 28 controller-processor terms with processing, security and UK Addendum annexes.
Updated 2026-07-18
Acceptable Use Policy
v1.0Prohibited uses, including AI-specific rules that keep deployments out of high-risk territory.
Updated 2026-07-08
Service Level Agreement
v1.099.5% monthly availability target, exclusions, credits and claim procedure.
Updated 2026-07-08
Privacy(5 documents)
How personal data is handled across the Amaigo site and every Whistle deployment.
Privacy Policy
v2.2Lawful bases, the controller-processor split, transfers, retention and your rights.
Updated 2026-07-18
Cookie Notice
v2.2No tracking cookies; every widget storage key listed with purpose and lifetime.
Updated 2026-07-18
Consent Notice
v2.4The exact consent wording visitors see in the widget, tier by tier.
Updated 2026-07-19
Data Subject Requests
v2.1How data-subject requests are routed, verified and fulfilled.
Updated 2026-07-18
Data Retention Policy
v2.1Retention periods per record type, enforced by automated purge.
Updated 2026-07-18
AI and transparency(3 documents)
Built for EU AI Act Article 50 and for professional confidentiality duties.
AI Transparency Notice
v1.5What the AI does and does not do, AI disclosure, provider terms, and privilege positioning for law firms.
Updated 2026-08-27
Sub-processors
v3.1Every sub-processor with location, data involved and transfer mechanism. AI providers flagged.
Updated 2026-07-11
Subprocessor Change Notification Policy
v2.030 days' advance notice of sub-processor changes, with an objection right.
Updated 2026-07-08
Security(3 documents)
EU-hosted, privacy by design, and pre-answered due diligence for your vendor review.
Security Overview
v2.2Hosting map, encryption, application security and operations, on one page.
Updated 2026-07-18
Security Questionnaire
v1.2Around 40 pre-answered questions mapped to legal-ethics vendor vetting.
Updated 2026-07-18
Breach Response
v2.0Incident runbook with a 48-hour controller notification commitment.
Updated 2026-07-08
For your DPO(5 documents)
Templates your organisation can complete for its own records, pre-filled with Whistle's details.
DPIA Template
v2.0DPIA template with AI-specific risks and mitigations pre-filled.
Updated 2026-07-08
Transfer Risk Assessment (TRA)
v2.0Transfer risk assessment for the AI sub-processor, six-step EDPB structure.
Updated 2026-07-08
Records of Processing (ROPA)
v2.0Article 30 records template, controller and processor rows.
Updated 2026-07-08
Client Onboarding SOP
v1.0Exactly how new clients are onboarded, compliance step by step.
Updated 2026-07-08
Client Offboarding SOP
v1.0How an engagement ends: revocations, deletion and a signed certificate of deletion.
Updated 2026-07-12
Stay informed of changes
Every document is versioned; the change log is the canonical record, and clients get 30 days' advance email notice of sub-processor changes.
Subscribe to sub-processor updatesCertification roadmap
We do not yet hold SOC 2, ISO 27001 or Cyber Essentials; they are on the roadmap as the platform matures. In the meantime the security questionnaire pre-answers the due-diligence questions those reports cover. Every document here prints cleanly to PDF for your records.