Whistleblowing Data Protection Information Gold Peg
The below notice sets out information about how you can make a whistleblowing report to Gold Peg, how our whistleblowing system operates, and how the report will be handled by Gold Peg and its related companies.
In summary:
We operate the whistleblowing system (the BKMS® System) to help us detect and prevent irregularities and to protect our company group, our employees and our customers.
Only Gold Peg has access to the data in the BKMS® System and can view reports and information you submit into the BKMS® System. The information is encrypted and stored with multi-level password protection.
Submitting a report is voluntary. You can submit a report anonymously, but you can also choose to reveal your identity if you prefer. We will also collect information about whether you are employed at Gold Peg, and the names and other information about any persons you name in your report.
When submitting a report, you can also add attachments. If you do, be careful to remove hidden personal data from such files (such as "author" data in Word documents). The below notice describes steps you can take if you are unsure or unable to remove such data.
When we receive a report, we evaluate each matter and perform any further required investigation and action. We may need to share reports with other Gold Peg employees or employees of other group companies, if the report involves them. Those employees or companies may be located (and therefore your personal information may be disclosed) around the world, outside of Australia, including in Germany and other countries from time to time.
We may also need to use, process or disclose the report to protect our rights or if required by law, including disclosure to government agencies, law enforcement, administrative authorities or courts.
We may be required to inform accused persons that we have received a report about them. As far as legally possible, in doing so we will not reveal your identity as a whistle-blower.
We will keep personal information for as long as necessary to complete our evaluation of the report, as long as required by law, or as long as we have a legitimate interest in doing so. After such period, we will delete the data as required by law.
You may have the right to access, correct, or complain about, your personal information held by Gold Peg. Further information is set out in the notice below.
You can contact us using the details set out below at any time to ask about our management of personal information submitted via the BKMS® System.
Data protection notice
We take the issue of data protection and confidentiality very seriously and follow the provisions of the EU Data Protection Basic Regulation (EU-DSGVO) and applicable national data protection regulations. Please read this data protection information carefully before you submit a report.
Purpose of the whistleblowing system and legal basis
The whistleblowing system (BKMS® System) is used to receive, process and administer notifications of violations of the compliance requirement of Gold Peg International Pty Ltd (hereinafter: "Gold Peg) in a secure and confidential manner. The processing of personal data within the framework of the BKMS® System is based on the justified interest of our company in the detection and prevention of irregularities and thus in averting damage to Gold Peg, its employees and customers. The legal basis under the EU-DSGVO for this processing of personal data is Article 6 Paragraph 1 lit. f EU-DSGVO.
Data Controller
To the extent the GDPR applies to a report submitted via the BKMS® System to Gold Peg, the data controller in the terms of GDPR in the whistleblowing system is:
Gold Peg International Pty Ltd77 Malcolm Rd
Braeside Victoria 3195
Australia
Tel: +613 8531 2999
Website: goldpeg.com
Further information can be found in the imprint of the website.
You can contact Gold Peg in respect of any queries, requests or complaints about your personal information in the whistleblowing system, at the following contact details:
Gold Peg International Pty Ltd
russell@natec-network.com
77 Malcolm Rd Braeside Vic 3195 Australia
The whistleblowing system is operated by a company specialized in this field, EQS Group GmbH, Bayreuther Str. 35, 10789 Berlin in Germany, in the name and on behalf of Hochland SE. Hochland SE, as the parent company of the group, in turn provides Gold Peg with the system for receiving and processing notices concerning them. Personal data and information entered the whistleblowing system are stored in a database operated by EQS Group GmbH in a high-security data centre. The data can only be viewed by Gold Peg. EQS Group GmbH and other third parties have no access to the data. This is guaranteed in the certified procedure by comprehensive technical and organizational measures.
All data is encrypted and stored with multi-level password protection and is subject to an authorization concept so that access is restricted to a very narrow circle of recipients expressly authorized by Gold Peg.
Gold Peg Inquiries about data protection at Gold Peg can be sent using the contact details listed above.
Type of the collected personal data
Use of the reporting system takes place on a voluntary basis. If you submit a report via the whistleblowing system, we collect the following personal data and information:
- your name, if you choose to reveal your identity,
- whether you are employed at Gold Peg, and
- the names of persons and other personal data of persons that you name in your report.
Confidential handling of reports
Incoming reports are received by a small selection of expressly authorized and specially trained employees of Gold Peg and are always handled confidentially. These Gold Peg employees will evaluate the matter and perform any further investigation required by the specific case.
During the processing of a report or the conduction of a special investigation it may become necessary to share reports with other Gold Peg employees or employees of other Group companies, e.g. if the reports refer to incidents in other Group companies. Such employees or other Group companies may be based in countries (and therefore your personal information may be disclosed) outside of Australia (including Germany and other countries from time to time) or outside of the European Union or the European Economic Area, with different regulations concerning the privacy of personal data. We always ensure that the applicable data privacy regulations are complied with when sharing reports.
All persons who receive access to the data are obligated to maintain confidentiality.
If it proves necessary to process your report or if it is required by law, state authorities, including law enforcement agencies, administrative authorities or courts, may also have access to this data.
Information of the accused person
As a basic principle we are bound by law to inform the accused persons that we have received a report concerning them, unless this threatens further investigations into the report. In doing so, your identity as whistle-blower is not revealed as far as is legally possible.
Rights of data subjects
To extent the European GDPR applies: According to European data protection law, you and the persons named in the report have the right to inquiry, rectification, erasure, restriction of processing and the right to object to processing of personal data concerning you/them. If the right of objection is claimed, we will immediately examine to what extent the stored data is still necessary for the processing of a report. Data that is no longer required will be deleted immediately. In addition, you also have the right of lodge a complaint with a supervisory authority.
For personal information collected in Australia by Gold Peg: Our Privacy Policy available at https://www.goldpeg.com/policy/ contains information about how you (and the persons named in the report) may access and seek correction of your respective personal information, how you may complain about a breach of your privacy, and how we will deal with that complaint.
Retention period of personal data
Personal data is retained for as long as necessary to clarify the situation and perform an evaluation of the report or a legitimate interest of the company exists, or it is required by law. After the report processing is concluded, this data will be deleted in accordance with the statutory requirements.
Automated decision-making including profiling
Your personal data will not be used for automatic decision-making including profiling.
Use of the reporting portal
Communication between your computer and the reporting system takes place over an encrypted connection (SSL). Your IP address will not be stored during your use of the reporting portal. In order to maintain the connection between your computer and the BKMS® System, a cookie is stored on your computer that merely contains the session ID (a so-called null cookie). This cookie is only valid until the end of your session and expires when you close your browser.
It is possible of set up a postbox within the reporting system that is secured with an individually chosen pseudonym/username and password. This allows you to send reports to the responsible Gold Peg employee either by name or in an anonymous, safe way. This system only stores data inside the reporting system, which makes it particularly secure. It is not a form of regular e-mail communication.
Notes on sending attachments
When submitting a report or an addition, you can simultaneously send attachments to the responsible Gold Peg employee. If you wish to submit an anonymous report, please take note of the following security advice: Files may contain hidden personal data that could compromise your anonymity. Please remove this data before sending. If you are unable to remove this data or are unsure how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the reporting process.
Version: 30 October 2020