Security & Trust

How Whenn protects your data

This page is intended for IT administrators, security teams, and data protection officers evaluating Whenn for organisational use. It covers our technical controls, data practices, and compliance posture.

Infrastructure security

Encryption in transit
All data transmitted between users and Whenn is encrypted using TLS 1.2 or higher. This applies to all API calls, web traffic, and calendar OAuth flows.
Encryption at rest
All data stored in Whenn's database (Supabase on AWS EU infrastructure) is encrypted at rest using AES-256. This includes participant names, email addresses, meeting details, and session tokens.
Authentication
Whenn uses passwordless magic-link authentication for host accounts. There is no password database. Session tokens are issued as cryptographically random strings, stored as httpOnly, Secure, SameSite=Lax cookies with a 30-day expiry. Magic links expire after 15 minutes and are single-use.
Calendar access
Whenn requests read-only OAuth access to calendar free/busy information only. We request the minimum scopes necessary: free/busy availability data, and the ability to create calendar events at the point a meeting is confirmed (with explicit host authorisation). We never read, store, or transmit event titles, attendees, meeting descriptions, or any other calendar content.
Service availability
We target 99.9% uptime for the Whenn web application and API. Current status, uptime history, and incident reports are published at meetwhenn.com/status.

Data we collect and retain

Host accounts
Name, email address, session token. Calendar OAuth tokens (encrypted) when a calendar is connected. Deleted on account deletion or after 12 months of inactivity.
Participants
Name, email address, availability data (time slots or free/busy status). Availability data is deleted 30 days after a meeting concludes. Names and emails are deleted 90 days after meeting conclusion. Participants do not need a Whenn account.
Calendar data
Free/busy status is read at the point of response only. Calendar data is not stored persistently — it is queried, used to identify available slots, and discarded. Raw calendar event data is never stored.
Meeting data
Title, date range, duration, confirmed time (if applicable), video conferencing link (if applicable). Meeting records are deleted 90 days after conclusion.

Access controls

Production access
Access to production data is restricted to authorised personnel only. Database access is controlled via Supabase's row-level security (RLS), meaning each host can only access their own meetings and participants at the application layer. Direct database access requires multi-factor authentication and is logged.
No third-party advertising or tracking
Whenn does not share personal data with advertising networks. We do not use third-party tracking cookies. The only cookies set are a session authentication cookie and standard analytics identifiers.
OAuth token security
Google and Microsoft OAuth tokens are stored encrypted. Token refresh is handled server-side. Tokens are never exposed to the client. Revocation is supported — participants and hosts can disconnect their calendar at any time from the Settings page, and Whenn will immediately cease reading their calendar data.

Subprocessors

Whenn uses the following third-party processors. All US-based processors are certified under the UK Extension to the EU-US Data Privacy Framework, providing a lawful transfer mechanism under UK GDPR.

ProcessorPurposeData locationTransfer mechanism
SupabaseDatabase, authentication, storageAWS EU (eu-west-1, Ireland)No transfer — EU-resident
VercelApplication hosting, serverless functionsEU region (primary deployment)UK Extension to EU-US DPF
ResendTransactional email deliveryUS (DPF certified)UK Extension to EU-US DPF
Google (OAuth)Calendar integration (optional)Google infrastructureICO adequacy decision
Microsoft (OAuth)Calendar integration (optional)Microsoft infrastructureICO adequacy decision
Zoom (OAuth)Video conferencing link generation (optional)Zoom infrastructureUK Extension to EU-US DPF

Compliance and certifications

UK GDPR
Whenn is operated by Meet Whenn Ltd (Company No. 17342492), a UK-based service that processes personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. Meet Whenn Ltd is registered as a data controller with the Information Commissioner's Office (ICO Registration No. ZC199586).
Google API Services User Data Policy
Whenn's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained through Google OAuth is used solely to identify participant availability for scheduling purposes and is not used for any other purpose, shared with third parties, or used for advertising.
OAuth verification
Whenn's Google OAuth application is verified by Google. Microsoft OAuth publisher verification is in progress.
Data Processing Agreements
Whenn maintains Data Processing Agreements with all subprocessors. A template DPA (compliant with Article 28 UK GDPR) is available to review at meetwhenn.com/dpa. Organisations wishing to enter into a countersigned DPA with Whenn as data processor may contact privacy@meetwhenn.com.
Subprocessor DPAs
All subprocessors are engaged under Article 28-compliant agreements. Supabase, Vercel, and Resend each publish their own Data Processing Agreements, available via their respective privacy documentation. Google and Microsoft are engaged under their standard API terms which include data processing provisions compliant with UK GDPR.

Incident response

Breach notification
In the event of a personal data breach, Whenn will notify affected data controllers within 72 hours of becoming aware, in accordance with our obligations under UK GDPR Article 33. Notification will be made to the contact email associated with the affected account.
Vulnerability disclosure
We welcome responsible disclosure of security vulnerabilities. To report a vulnerability, email security@meetwhenn.com with a description of the issue, steps to reproduce, and any relevant technical detail. We will acknowledge receipt within 48 hours and provide a status update within 7 days. We request that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it. We will not pursue legal action against researchers who act in good faith, provide sufficient detail to reproduce the issue, and do not access or exfiltrate data beyond what is necessary to demonstrate the vulnerability.

Questions for IT or legal teams

If you are evaluating Whenn for organisational use and need additional documentation — including a Data Processing Agreement, subprocessor DPAs, or answers to specific security questions — contact us:

General enquirieshello@meetwhenn.com
Privacy and data protectionprivacy@meetwhenn.com
Security enquiriessecurity@meetwhenn.com
Supportsupport@meetwhenn.com

Last updated: July 2026

Data Processing AgreementPrivacy policyTerms of use