acib GmbH is committed to a corporate culture of integrity, transparency and compliance with the law. To ensure adherence to the highest ethical standards and to identify potential legal violations, we have established an internal reporting system in accordance with the Whistleblower Protection Act (HSchG). This whistleblowing system serves to identify and address legally relevant breaches and serious misconduct at an early stage. It is available to all employees, applicants, interns, former employees and external partners
Who can submit a report?
- Current employees
- Former employees
- Applicants and interns
- Students in cooperation with acib
- External partners, contractors and service providers
- Research partners and academic cooperation partners
Reporting channels
- Digital reporting (written & voice message): Reports can be submitted securely, encrypted and, if desired, completely anonymously via our Integrity Line platform. This platform allows for both written submissions and the transmission of voice messages.
- Verbal reporting: Verbal reporting is possible via the aforementioned portal (voice message function) or by appointment.
- Face-to-face meeting: At the whistleblower’s request, a physical or virtual meeting with a designated trusted representative from our Compliance Board must be arranged within a reasonable timeframe.
What can be reported?
- Public procurement
- Financial services, prevention of money laundering and corruption
- Product safety and environmental protection
- Public health
- Data protection and security of network and information systems
- Breaches of the financial interests of the Union
- Breaches of product safety and compliance
- Certain criminal offences under Sections 302–309 of the German Criminal Code (StGB) (e.g. corruption, breach of trust)
Important note: General complaints, suggestions or personal conflicts in the workplace that do not constitute a legal violation within the meaning of the Whistleblower Protection Act (HSchG) should be addressed via the regular channels of communication (line managers, HR department or compliance@acib.at).
Procedure following a report
- Report: You submit your report – either completely anonymously or by name – via our Integrity Line or by email.
- Confirmation (max. 7 days): You will receive a formal acknowledgement of receipt from us no later than seven days after submission.
- Investigation: The Compliance Board examines the reported matter carefully, impartially and with the strictest confidentiality. If necessary, we will contact you via the secure platform to ask for further details.
- Feedback (max. 3 months): Within three months of the confirmation at the latest, we will inform you of the outcome of the investigation and of any follow-up measures already taken or planned.
You can rest assured in all cases:
If reported breaches are confirmed
Protection of whistleblowers
Comprehensive protection against reprisals:
Strict confidentiality (protection of identity):
Prohibition of malicious reports:
Data protection, data security and retention
- Encryption & Anonymity: Our reporting platform (“Integrity Line”) is hosted by a specialised, market-leading external service provider acting as a data processor (EQS Integrity Line). The system is ISO 27001-certified and uses state-of-the-art encryption technologies. Neither IP addresses nor location or device information relating to the reporting person are stored. Even the platform operator has no access to the content of your report.
- Access restriction: Internally, only expressly authorised members of the Compliance Board have access to the reports received and the personal data contained therein.
- Retention periods: In accordance with Section 8(11) of the HSchG, personal data is generally retained for five years following the last processing or transmission of the report. Data is retained for a longer period only if this is strictly necessary for the conduct of administrative, judicial or criminal investigations that have already been initiated. Once these retention obligations cease to apply, the data is irrevocably deleted.