Whistleblowing, handled properly
A reporting channel people are willing to use
Kaja gives an organisation the internal reporting channel the EU Whistleblower Directive requires, and gives the person raising the concern a way to do it without putting themselves at risk.
There is no company picker on this page, by design. Each organisation publishes its own reporting address in its whistleblowing policy, its legal notices or its intranet, and that link is what connects your report to the right legal entity, in the right country, under the right law. If you mean to raise a concern, start from the link your organisation published. If you cannot find it, ask for the reporting channel by name; an organisation covered by the directive is required to have one.
How it works
- 1
Arrive through your organisation
You open the reporting link your organisation published, pick the entity your concern relates to, and see which law protects you before you write anything down.
- 2
Report named or anonymously
Choose whether to give your identity. Describe what happened, when, and whether it is still going on, and attach any evidence you hold.
- 3
Follow it with a code
You receive a private tracking code. It is shown once, it cannot be recovered, and it is the only way back to your case, including if you stayed anonymous.
What it does
Written around the directive
Directive (EU) 2019/1937 sets the floor: receipt acknowledged within seven days, feedback within three months, and confidentiality for the reporter's identity. The flow states the rules that apply to the entity being reported on, at the point they matter.
Anonymity that holds
An anonymous report carries no name and no contact details. The tracking code is the only link back, so a case handler can ask questions and the reporter can answer without ever identifying themselves.
In the reporter's language
The intake flow runs in English, French, Polish and Spanish, chosen by the person reporting rather than by the organisation.
Structured from the start
Concern categories, the reporter's relationship to the organisation, dates, whether the conduct is ongoing, who else was told, and attached evidence: the case arrives ready to assess instead of as a paragraph of free text.
A case view for handlers
Reports land in an administrator panel with status and priority, separated into identified and anonymous, so nothing sits unacknowledged past its deadline.
Confidential by default
Identity is shown only to the people handling the case, and the reporter is told exactly what is stored about them before they submit it.
Compliance
GDPR
A report is personal data, often about the reporter and about the people they name, so it is handled under Regulation (EU) 2016/679. Reporters are told what is collected and why before they submit, an anonymous report holds no identifying details at all, and identity is disclosed only to the people handling the case.
Privacy and security policyAnti-bribery and anti-corruption
Norn Labs operates under anti-bribery and anti-corruption rules, and does not offer, accept or facilitate improper payments in any form. Kaja is part of how an organisation meets the same standard: bribery, corruption and public procurement irregularities are first-class reporting categories, and every case carries a record of how it was handled.
For organisations
If you need a reporting channel for your own organisation, Kaja gives you one reporting address per entity, a case view for the people who handle what comes in, and a record of how each report was dealt with.
Talk to Norn LabsKaja provides a reporting channel and general information about Directive (EU) 2019/1937. It is not legal advice. Member states transpose the directive into national law, sometimes with stricter requirements, and an organisation should confirm its own obligations.