Template version — last updated: July 2026
This is Meet Whenn Ltd's standard Data Processing Agreement template, compliant with Article 28 of the UK General Data Protection Regulation. Organisations wishing to enter into a countersigned copy should contact privacy@meetwhenn.com. Fields shown in [square brackets] will be completed upon execution.
This Data Processing Agreement ("Agreement") is entered into between:
Data Controller: [Customer Organisation Name], [registered address] ("Controller"); and
Data Processor: Meet Whenn Ltd, a company incorporated in England and Wales (Company No. 17342492), whose registered office is at [registered address] ("Processor").
This Agreement is incorporated into and forms part of the Whenn Terms of Service between the parties. In the event of any conflict between this Agreement and the Terms of Service with respect to the processing of personal data, this Agreement shall prevail.
In this Agreement:
The Processor will process Personal Data on behalf of the Controller for the following purposes:
The Processor shall, in relation to any Personal Data processed in connection with the performance of the Services:
4.1 Instructions
Process Personal Data only on the documented instructions of the Controller, unless required to do so by Applicable Data Protection Law, in which case the Processor shall inform the Controller of that legal requirement before processing (unless prohibited from doing so by law). For the purposes of this Agreement, the Terms of Service and the Controller's use of the Services constitute the Controller's documented instructions.
4.2 Confidentiality
Ensure that persons authorised to process Personal Data on behalf of the Processor are subject to appropriate confidentiality obligations (whether contractual or statutory) with respect to that Personal Data.
4.3 Security
Implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures include, without limitation: AES-256 encryption at rest; TLS 1.2 or higher for data in transit; row-level security at the database layer; multi-factor authentication for direct production access; and passwordless (magic-link) authentication for host accounts with no password database exposure. Further detail is available at meetwhenn.com/security.
4.4 Sub-processors
Not engage any Sub-processor without the prior written consent of the Controller, save that the Controller hereby provides general written consent to the engagement of the Sub-processors listed in Schedule 1 of this Agreement. The Processor shall: (i) impose on Sub-processors data protection obligations equivalent to those imposed on the Processor under this Agreement; (ii) remain fully liable to the Controller for the performance of each Sub-processor's obligations; and (iii) notify the Controller of any intended addition or replacement of Sub-processors with reasonable prior notice, giving the Controller the opportunity to object.
4.5 Data Subject Rights
Assist the Controller, by appropriate technical and organisational measures and to the extent possible, in fulfilling the Controller's obligations to respond to requests from data subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). Where a data subject makes a request directly to the Processor relating to Personal Data processed on behalf of the Controller, the Processor shall promptly forward that request to the Controller and shall not respond to the data subject except as instructed by the Controller or as required by law.
4.6 Assistance with Compliance
Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of UK GDPR (including security of processing, breach notification, data protection impact assessments, and prior consultation with the Supervisory Authority), taking into account the nature of processing and the information available to the Processor.
4.7 Deletion and Return
At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless retention is required under Applicable Data Protection Law. Account data will be deleted within 30 days of account closure. Meeting participation data will be deleted within 90 days of a meeting being confirmed or expiring. Calendar free/busy data is never stored persistently; it is queried, used to compute availability, and immediately discarded.
4.8 Audit
Make available to the Controller all information necessary to demonstrate compliance with this Agreement, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor may require reasonable advance notice (not less than 30 days) for such audits, and may require that the auditor enters into a confidentiality agreement. The costs of any audit shall be borne by the Controller unless the audit reveals a material breach of this Agreement.
4.9 Breach Notification
Notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a personal data breach affecting Personal Data processed under this Agreement. Such notification shall include, to the extent available: (i) a description of the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (ii) the likely consequences of the breach; and (iii) the measures taken or proposed to address the breach. Where full details are not available within 48 hours, the Processor may provide information in phases.
4.10 No Unauthorised Use
Not use Personal Data processed under this Agreement for any purpose other than providing the Services, including without limitation for advertising, profiling, machine learning model training, or transfer to third parties outside the scope of this Agreement.
The Controller warrants and represents that: (i) it has a lawful basis for processing the Personal Data and for instructing the Processor to process Personal Data on its behalf; (ii) it has provided all necessary notices to and obtained all necessary consents from data subjects as required by Applicable Data Protection Law; and (iii) its instructions to the Processor are lawful and will not cause the Processor to be in breach of Applicable Data Protection Law.
Some Sub-processors are located in the United States. All transfers of Personal Data to the United States are made under the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge), an adequacy regulation adopted under section 17A of the Data Protection Act 2018. The Processor shall notify the Controller if it becomes aware that any Sub-processor's certification lapses and shall implement appropriate alternative transfer mechanisms before continuing any transfer.
Supabase (the Processor's database provider) is hosted on AWS infrastructure in the EU (Ireland) and involves no international transfer of Personal Data. See Schedule 1 for the full Sub-processor list and applicable transfer mechanisms.
Each party's liability under this Agreement is subject to the limitations and exclusions set out in the Whenn Terms of Service. Nothing in this Agreement limits or excludes either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability which cannot be excluded or limited by law.
Where both parties are responsible for damage caused by a processing breach, liability shall be apportioned according to the extent to which each party is responsible for the damage, as determined under Applicable Data Protection Law.
This Agreement shall remain in force for the duration of the Controller's use of the Services and shall terminate automatically upon expiry or termination of the Terms of Service, save that clause 4.7 (deletion and return) and any other provisions necessary for its interpretation shall survive termination.
9.1 Governing law
This Agreement is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising out of or in connection with this Agreement.
9.2 Entire agreement
This Agreement, together with the Terms of Service, constitutes the entire agreement between the parties in relation to the processing of Personal Data and supersedes all prior representations, discussions, or agreements.
9.3 Amendments
The Processor may update this template periodically to reflect changes in Applicable Data Protection Law or the Services. Executed copies may only be amended by written agreement signed by both parties.
9.4 Severability
If any provision of this Agreement is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
The Controller hereby provides general written consent to the engagement of the following Sub-processors. The Processor will notify the Controller of any intended additions or replacements with reasonable prior notice.
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, and storage infrastructure | AWS EU (eu-west-1, Ireland) | No transfer — EU-resident |
| Vercel Inc. | Application hosting and serverless function execution | EU region (primary) | UK Extension to EU-US Data Privacy Framework |
| Resend Inc. | Transactional email delivery (scheduling invitations, magic-link authentication) | US | UK Extension to EU-US Data Privacy Framework |
| Google LLC | Google Calendar API and Google Meet link generation (hosts and participants who connect Google Calendar only) | Google infrastructure | ICO adequacy decision |
| Microsoft Corporation | Microsoft Graph API and Teams link generation (hosts and participants who connect Outlook only) | Microsoft infrastructure | ICO adequacy decision |
| Zoom Video Communications Inc. | Zoom meeting link generation (hosts who connect Zoom only) | US | UK Extension to EU-US Data Privacy Framework |
This Agreement is entered into as of the date of last signature below.
Data Controller
Signed: ____________________
Name: ____________________
Title: ____________________
Organisation: ____________________
Date: ____________________
Data Processor — Meet Whenn Ltd
Signed: ____________________
Name: ____________________
Title: ____________________
Company No.: 17342492
Date: ____________________
To enter into a signed DPA with Meet Whenn Ltd, contact privacy@meetwhenn.com with your organisation name and registered address. We will return a countersigned copy within 5 business days. For security documentation and compliance questions, contact security@meetwhenn.com.
Meet Whenn Ltd — Company No. 17342492 — ICO Reg. ZC199586