Skip to the main content
Whenabouts Whenabouts
CreatePricingSign in

Data processing

If you're an organization, you are the controller of what your people submit and we are the processor. This page is the addendum.

Last updated 18 September 2026.

What's on this page

  • Who we are
  • What we process, and why
  • Sub-processors
  • What we promise
  • Transfers
  • How long we keep it
  • Questions a legal team asks

It applies from the moment you use the service; there is nothing to sign, though we will sign your paperwork instead if you need us to.

Who we are

Whenabouts. Privacy questions go to privacy@whenabouts.me, and a person reads them.

What we process, and why

  • Names and, where given, email addresses of the people who respond to what you put up — so they can be shown to you and so we can send them their own link.
  • What they said they can do. Times, choices, and a note if they wrote one.
  • Busy intervals from a connected calendar, where somebody connected one. A start and an end, and nothing else — no titles, no locations, no attendees, not in the database, not in a log, not in a cache.

We process it to provide the service and for nothing else. Not to build a profile, not to sell, not to train anything, and not for our own analytics.

Sub-processors

Who else handles data, and what for
WhoWhat forWhere
CloudflareHosting, the database, and the network in front of itGlobal edge
ResendSending emailUnited States
PaddlePayments, as merchant of recordUnited Kingdom and United States

We'll tell you before we add one. If you object, you can stop using the service and take your data with you.

What we promise

  • We act only on your instructions, which for this service means the settings you set.
  • Everybody with access is under confidentiality, and access is limited to what the job needs.
  • Encrypted in transit and at rest. Credentials are sealed with a rotatable key.
  • We'll help you answer a request from one of your people — export and deletion are self-service, so usually you won't need us.
  • Breach notification within 72 hours of us becoming aware, with what we know at the time rather than a polished version a week later.
  • On request, we delete or return everything at the end.

Transfers

Data may be processed outside Canada and the EEA by the sub-processors above. Standard contractual clauses apply where they need to. We are a Canadian business and PIPEDA applies to us throughout; Quebec's Law 25 applies to Quebec residents' data.

How long we keep it

As set out on the privacy page, which is the single source for retention and is not different for an organization.

Questions a legal team asks

The six that come up every time, answered the way we would answer them on a call.

  • Do you have a privacy impact assessment? Yes — what is collected, the risks, and what prevents each, written because Quebec's Law 25 asks for one on a project like this. Ask and we'll send it.
  • Who handles privacy? A person at the address above, who is also the person who writes the code. Small enough that your question reaches whoever can answer it.
  • Do you have an EU representative? We're a Canadian business under PIPEDA. If your use puts EU residents' data in scope and your process needs one named, tell us and we'll arrange it.
  • What covers transfers? The standard contractual clauses our sub-processors already operate under, which we'll point you at. We'll also execute your own set if that is what your process needs.
  • Can we audit you? We'll answer your questionnaire and hand over everything on these pages, which is built to be checkable from outside.
  • Will you tell us about a new sub-processor? Yes, before we add one. Tell us the notice period your contract needs and we'll agree it with you.
© WhenaboutsPrivacyTermsSecurityAccessibilityContact