Last updated: July 2026
When you use Whenn, we collect your name, email address, and calendar availability (free/busy status only). We never access event titles, descriptions, attendees, or any other calendar details beyond free/busy status.
Your data is used solely to find mutually agreeable meeting times. We do not sell, share, or use your data for advertising, profiling, or any purpose other than the scheduling service you have requested. Calendar free/busy data accessed via Google or Microsoft OAuth is never used to train machine learning models and is never transferred to third parties.
We process personal data under the following legal bases under UK GDPR:
When you connect your calendar or video platform, Whenn requests the minimum permissions necessary to deliver the service:
Google Calendar (host): We request three scopes:
Microsoft Outlook / Microsoft 365 (host): We request four scopes:
We never read, modify, or delete your calendar events or any calendar content beyond free/busy windows.
Google Calendar (participant): We request one scope:
Microsoft Outlook (participant): We request two scopes:
Zoom (host): We request one scope:
Whenn's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained through Google OAuth is used exclusively to identify participant availability for scheduling purposes. It is not used for any other purpose, shared with third parties, used for advertising, or used to train machine learning models.
You can request immediate deletion of your account and all associated data at any time by contacting privacy@meetwhenn.com. We will action this within 30 days.
Whenn uses the following sub-processors. Each is bound by their own privacy policies and data protection terms:
We do not sell data to third parties and do not use advertising or analytics services that receive personal data.
Some sub-processors are based in the United States. All such transfers are made under the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge), an adequacy regulation under UK GDPR:
Supabase is hosted on AWS in the EU (Ireland) and involves no international transfer. Google and Microsoft data is processed under the respective adequacy decisions applicable to those platforms.
We periodically verify that US-based sub-processors maintain active certification. If certification lapses, we will implement appropriate alternative safeguards before continuing any transfer.
Organisations using Whenn to schedule meetings on behalf of their teams act as data controllers in respect of their participants' data. In this context, Whenn acts as a data processor. Organisations requiring a Data Processing Agreement (as required under Article 28 UK GDPR) may request one by contacting privacy@meetwhenn.com. Further information on our security practices and compliance posture is available at meetwhenn.com/security.
Under UK GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to its processing. To exercise any of these rights, contact privacy@meetwhenn.com. We will respond within 30 days.
Data portability (Article 20): Hosts can download a copy of their meeting data at any time without contacting us — go to Settings → Data & Privacy → Export CSV. The export includes meeting titles, statuses, confirmed times, and scheduling history. Participant personal data is not included in the export.
Whenn uses a single session cookie (whenn_session) to maintain your authenticated session. This cookie is httpOnly, Secure (HTTPS only), and expires after 30 days.
We use Google Analytics 4 (GA4) to understand how the service is used in aggregate. GA4 is configured with client_storage set to 'none', which disables all GA4 cookies including _ga and _ga_*. No analytics cookies are set on your device. The data collected is anonymised usage data (pages visited, feature interactions) and does not include personal data or calendar content.
We do not use advertising cookies, retargeting cookies, or any third-party tracking cookies.
Whenn is operated by Meet Whenn Ltd, a company incorporated in England and Wales (Company No. 17342492), registered as a data controller with the Information Commissioner's Office (ICO Registration No. ZC199586). For questions about this policy or to exercise your data rights, contact privacy@meetwhenn.com.
For security enquiries or to request a Data Processing Agreement, contact security@meetwhenn.com. Our full security and compliance documentation is available at meetwhenn.com/security.
Last updated: July 2026