Legal

Whistleblowing

Last updated: September 2026

If you believe something at SkyLink API is unlawful, unsafe, or seriously wrong, we want to hear about it, and we want you to be able to tell us without fear of the consequences. This page explains how to report a concern, what happens after you do, and how you are protected.

SkyLink is a small business and offers this channel voluntarily. We follow the standards of EU Directive 2019/1937 and Italian Legislative Decree 24/2023 as good practice. Whether their statutory protections apply to you depends on your situation; the commitments on this page apply in every case.

1

Who can report

Anyone who has come across a concern through their dealings with SkyLink, including:

  • Customers and their developers
  • Contractors, freelancers, and consultants
  • Suppliers, data providers, and business partners
  • Job applicants, and anyone whose working relationship with us has ended
2

What you can report

2.1 Concerns this channel is for

  • Fraud, bribery, corruption, or false accounting
  • Breaches of data protection law, including misuse of customer or personal data
  • Breaches of consumer protection, tax, or competition law
  • Breaches of sanctions or export control law, including supplying the Service to sanctioned parties
  • Use of third-party data in breach of its licence terms
  • The Service being marketed or supplied for navigational or safety-critical use, contrary to §11 of our Terms of Use
  • Security incidents affecting customer data that have been concealed or not properly handled
  • Retaliation against someone for raising a concern
  • Any attempt to hide any of the above

You do not need proof. A reasonable belief, based on what you have seen or been told, is enough.

2.2 Where to go for other matters

These are handled faster through our normal channels than as a whistleblowing report:

Support, billing, refunds[email protected] or the contact form
Security vulnerabilitiesOur good-faith research process in Terms §5.5
Privacy rights requestsPrivacy Policy §8
3

How to report

Email [email protected]. This mailbox is separate from our support inbox, and only the person responsible for handling reports can read it.

It helps if your report includes:

  • What happened, and when and where it happened
  • Who was involved, if you know
  • How you came to know about it
  • Any documents or other evidence you have, if you can share them lawfully
  • Whether you have reported it anywhere else

Reporting anonymously

You do not have to give your name. If you want to stay anonymous, write from an email address that does not identify you, and we will use that address to acknowledge and follow up. We will not try to find out who you are. Anonymous reports can be harder to investigate, because we cannot ask you questions any other way.

4

What happens after you report

Within 7 daysWe acknowledge receipt of your report.
AssessmentWe check whether the report falls within this policy and decide how to look into it. If it does not, we tell you and point you to the right channel.
InvestigationWe look into the facts, which may include asking you for more information. Where needed, we may involve an external adviser bound by confidentiality.
Within 3 monthsWe tell you what we have done or plan to do about your report, and why, as far as the law and the rights of others allow.
5

Confidentiality

We will not disclose your identity, or anything that could reveal it, without your express consent, except where the law requires us to, for example to a court or a public authority. If we are ever required to disclose it, we will tell you first and explain why, unless doing so would compromise the related investigation or legal proceedings.

We also protect the identity of the people named in a report, and of anyone who helps you make one, until the matter is resolved.

6

Protection from retaliation

We will not retaliate against anyone who reports a concern in good faith, or who helps someone else to report one, even if the concern turns out to be mistaken.

Retaliation includes, among other things:

Ending or not renewing a contract, account, or working relationship because of the report
Withholding payments, work, or business that would otherwise have been given
Threats, harassment, or damage to your reputation
Blacklisting, or discouraging others from working with you

If you believe you have suffered retaliation for a report, tell us through the same channel. Where Legislative Decree 24/2023 applies to you, you can also report retaliation to ANAC (§7).

7

Reporting outside SkyLink

You can always report to the competent public authorities instead of, or as well as, to us. In Italy, the Autorità Nazionale Anticorruzione (ANAC) runs the national external reporting channel, available where the conditions set by Legislative Decree 24/2023 are met. Depending on the subject, other authorities, such as data protection or consumer protection authorities, and the institutions of the European Union may also receive reports.

If your concern involves the person who handles reports to this channel, or you fear it would not be dealt with impartially, we encourage you to report to an external authority.

8

Good faith

The protections on this page cover anyone who reports in good faith, with reasonable grounds to believe the information is true when they report it. They do not cover someone who knowingly makes a false report. A report that turns out to be wrong but was made honestly is never treated as false.

9

How we handle your personal data

Reports are processed by the controller named in our Privacy Policy, which applies alongside this section.

PurposeReceiving, assessing, investigating and following up reports, and protecting the people involved
Legal basisOur legitimate interest in detecting and dealing with wrongdoing (Art. 6(1)(f) GDPR) and, where it applies, compliance with a legal obligation (Art. 6(1)(c) GDPR)
DataThe content of the report and the personal data in it. Data that is clearly irrelevant to the report is not collected or, if received, is deleted without delay
RecipientsOnly the person handling the report, advisers bound by confidentiality where needed, and authorities where the law requires
RetentionAs long as needed to handle the report, and no more than 5 years from its final outcome

Your rights under the GDPR are described in Privacy Policy §8. The rights of a person named in a report may be delayed or restricted, to the extent the law allows, where exercising them would reveal the reporter's identity or compromise the investigation.

10

Contact

To make a report, or to ask a question about this policy before you do:

[email protected]