This page is intended for IT administrators, security teams, and data protection officers evaluating Whenn for organisational use. It covers our technical controls, data practices, and compliance posture.
Whenn uses the following third-party processors. All US-based processors are certified under the UK Extension to the EU-US Data Privacy Framework, providing a lawful transfer mechanism under UK GDPR.
| Processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication, storage | AWS EU (eu-west-1, Ireland) | No transfer — EU-resident |
| Vercel | Application hosting, serverless functions | EU region (primary deployment) | UK Extension to EU-US DPF |
| Resend | Transactional email delivery | US (DPF certified) | UK Extension to EU-US DPF |
| Google (OAuth) | Calendar integration (optional) | Google infrastructure | ICO adequacy decision |
| Microsoft (OAuth) | Calendar integration (optional) | Microsoft infrastructure | ICO adequacy decision |
| Zoom (OAuth) | Video conferencing link generation (optional) | Zoom infrastructure | UK Extension to EU-US DPF |
If you are evaluating Whenn for organisational use and need additional documentation — including a Data Processing Agreement, subprocessor DPAs, or answers to specific security questions — contact us:
Last updated: July 2026