Legal

Privacy Policy

Last updated: July 2026

What We Collect

When you use Whenn, we collect your name, email address, and calendar availability (free/busy status only). We never access event titles, descriptions, attendees, or any other calendar details beyond free/busy status.

How We Use It

Your data is used solely to find mutually agreeable meeting times. We do not sell, share, or use your data for advertising, profiling, or any purpose other than the scheduling service you have requested. Calendar free/busy data accessed via Google or Microsoft OAuth is never used to train machine learning models and is never transferred to third parties.

Legal Basis for Processing

We process personal data under the following legal bases under UK GDPR:

  • Hosts (users who create meetings): Processing is necessary for the performance of the contract to provide the Whenn scheduling service (Article 6(1)(b) UK GDPR). This covers account management, calendar connections, and meeting management.
  • Participants (people invited to meetings): Processing is based on the legitimate interests of the host in scheduling meetings efficiently and the participant's own interest in attending meetings they have been invited to (Article 6(1)(f) UK GDPR). We have assessed that these interests are not overridden by participants' rights and freedoms, given the limited nature of data processed and the direct benefit to participants.
  • Service improvement: Processing is based on our legitimate interests in understanding how the service is used in order to improve it (Article 6(1)(f) UK GDPR).

Calendar Access and OAuth Scopes

When you connect your calendar or video platform, Whenn requests the minimum permissions necessary to deliver the service:

Google Calendar (host): We request three scopes:

  • calendar.freebusy — read-only access to determine when you are free or busy. We never read event titles, descriptions, or attendee details.
  • calendar.events — used solely to create one calendar event on your behalf when a meeting is confirmed. This is required by Google's API to generate a Google Meet link. We never read, modify, or delete your existing calendar events.
  • openid, email, profile — standard authentication scopes used to identify your account.

Microsoft Outlook / Microsoft 365 (host): We request four scopes:

  • Calendars.ReadWrite — used to read your free/busy availability via the Microsoft Graph getSchedule endpoint. Write access is required by Microsoft's API for this call.
  • OnlineMeetings.ReadWrite — used solely to create a Microsoft Teams meeting link when a meeting is confirmed.
  • User.Read — reads basic profile information required for authentication context.
  • offline_access — maintains the connection without requiring you to reconnect each time.

We never read, modify, or delete your calendar events or any calendar content beyond free/busy windows.

Google Calendar (participant): We request one scope:

  • calendar.freebusy — read-only access to determine when you are free or busy during the meeting's proposed date range.

Microsoft Outlook (participant): We request two scopes:

  • Calendars.Read — read-only access to check your availability during the meeting's proposed date range.
  • offline_access — maintains the connection for the duration of the scheduling process.

Zoom (host): We request one scope:

  • meeting:write:meeting — used solely to create a Zoom meeting link when a meeting is confirmed with Zoom selected as the video platform. We do not access existing meetings, recordings, contacts, or any other Zoom data.

Google API Services User Data Policy

Whenn's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained through Google OAuth is used exclusively to identify participant availability for scheduling purposes. It is not used for any other purpose, shared with third parties, used for advertising, or used to train machine learning models.

Data Retention

  • Calendar free/busy data — never stored persistently. Retrieved in real-time and discarded immediately after availability computation.
  • OAuth access tokens — retained only while a calendar connection is active. Deleted immediately upon disconnection or revocation.
  • Meeting participation data (availability responses, slot selections) — deleted within 90 days of a meeting being confirmed or expiring.
  • Account data (name and email address) — retained for as long as the account is active. Accounts with no activity for 12 months will receive a deletion notice and will be permanently deleted 30 days later if no action is taken.
  • Meeting core data (title, confirmed time, host details) — retained for 90 days after confirmation, then deleted.
  • Server and application logs — retained for 30 days, then automatically purged.

You can request immediate deletion of your account and all associated data at any time by contacting privacy@meetwhenn.com. We will action this within 30 days.

Third-Party Services (Sub-processors)

Whenn uses the following sub-processors. Each is bound by their own privacy policies and data protection terms:

  • Supabase — database and authentication infrastructure, hosted on AWS in the EU region (Ireland)
  • Vercel — application hosting and serverless functions
  • Resend — transactional email delivery
  • Google LLC — Google Calendar API, used only when you explicitly connect your Google Calendar
  • Microsoft Corporation — Microsoft Graph API, used only when you explicitly connect your Outlook calendar
  • Zoom Video Communications — Zoom API, used only when you connect Zoom for meeting link generation

We do not sell data to third parties and do not use advertising or analytics services that receive personal data.

International Transfers

Some sub-processors are based in the United States. All such transfers are made under the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge), an adequacy regulation under UK GDPR:

  • Vercel — certified under the UK Extension to the EU-US Data Privacy Framework
  • Resend — certified under the UK Extension to the EU-US Data Privacy Framework
  • Zoom — certified under the UK Extension to the EU-US Data Privacy Framework

Supabase is hosted on AWS in the EU (Ireland) and involves no international transfer. Google and Microsoft data is processed under the respective adequacy decisions applicable to those platforms.

We periodically verify that US-based sub-processors maintain active certification. If certification lapses, we will implement appropriate alternative safeguards before continuing any transfer.

Organisational Use and Data Processing

Organisations using Whenn to schedule meetings on behalf of their teams act as data controllers in respect of their participants' data. In this context, Whenn acts as a data processor. Organisations requiring a Data Processing Agreement (as required under Article 28 UK GDPR) may request one by contacting privacy@meetwhenn.com. Further information on our security practices and compliance posture is available at meetwhenn.com/security.

Your Rights (UK GDPR)

Under UK GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to its processing. To exercise any of these rights, contact privacy@meetwhenn.com. We will respond within 30 days.

Data portability (Article 20): Hosts can download a copy of their meeting data at any time without contacting us — go to Settings → Data & Privacy → Export CSV. The export includes meeting titles, statuses, confirmed times, and scheduling history. Participant personal data is not included in the export.

Cookies and Analytics

Whenn uses a single session cookie (whenn_session) to maintain your authenticated session. This cookie is httpOnly, Secure (HTTPS only), and expires after 30 days.

We use Google Analytics 4 (GA4) to understand how the service is used in aggregate. GA4 is configured with client_storage set to 'none', which disables all GA4 cookies including _ga and _ga_*. No analytics cookies are set on your device. The data collected is anonymised usage data (pages visited, feature interactions) and does not include personal data or calendar content.

We do not use advertising cookies, retargeting cookies, or any third-party tracking cookies.

Contact

Whenn is operated by Meet Whenn Ltd, a company incorporated in England and Wales (Company No. 17342492), registered as a data controller with the Information Commissioner's Office (ICO Registration No. ZC199586). For questions about this policy or to exercise your data rights, contact privacy@meetwhenn.com.

For security enquiries or to request a Data Processing Agreement, contact security@meetwhenn.com. Our full security and compliance documentation is available at meetwhenn.com/security.

Last updated: July 2026

Terms of useSecurity