Data processing agreement
Last updated 8 October 2026.
This agreement is between the organisation that uses Whisk (the "Customer", "you") and Whisk (the "Processor", "we"). It is part of the Terms of service and applies whenever we process personal data on your behalf, meaning the data inside your apps, their databases, files, logs and the people your apps sign in. It is written in the shape of Article 28 of the GDPR and applies in the same way wherever you are.
You accept it when you accept the Terms of service. No signature is needed, and we will sign a copy on request at support@whisk.run if your own compliance requires one.
1. Words used here
"Personal data", "controller", "processor", "processing", "data subject", "personal data breach" and "supervisory authority" mean what the GDPR says they mean. "Data protection law" means the GDPR, the UK GDPR, the Swiss FADP, the New Zealand Privacy Act 2020, the CCPA as amended, and any other privacy law that applies to the processing. "Customer Personal Data" is the personal data we process for you under this agreement. "Standard contractual clauses" means the clauses the European Commission adopted in its decision of 4 June 2021.
2. Roles
You are the controller (or, where you act for a client, a processor for that client) of Customer Personal Data. We are your processor, and where you are a processor we are your subprocessor and this agreement binds us to your client's terms as though they were yours. You decide what is collected and why; we run the apps and the services they use, on your instructions and no others.
Under the CCPA we are your service provider. We do not sell or share Customer Personal Data, do not keep, use or disclose it outside our direct business relationship with you or for any purpose other than performing the Service, and do not combine it with personal information from another source. We certify that we understand and will comply with this.
You are responsible for having a lawful basis to collect the data, for telling the people it is about what you do with it, and for the accuracy of what you put into the Service.
3. Subject matter, duration, nature and purpose
We process Customer Personal Data for as long as your organisation exists on the Service and until it is shredded under section 11, for the purpose of providing the Service: hosting and running your apps; storing, backing up and restoring their databases, files and workflow state; signing in the people your apps serve; delivering jobs, workflow runs, webhooks and email on their behalf; keeping logs and an audit trail; and everything else the Service does as described in the Terms and the documentation. Annex 1 sets this out in the form the standard contractual clauses ask for.
4. Types of personal data and data subjects
Whatever your apps hold. Typically: names, email addresses, roles and group memberships of your team; names, email addresses and account records of your customers; and the business records your apps keep, which may contain personal data about employees, customers, suppliers and contacts. You are responsible for not putting special-category data (health, biometrics, criminal records and the like) into apps on a plan that does not commit to the measures such data needs; ask us before you do. Annex 1 lists the categories in full.
5. Your instructions
- We process Customer Personal Data only on your documented instructions. These Terms, your organisation's settings, your apps' manifests and the actions you and your agents take in the dashboard and the CLI are your instructions.
- If we believe an instruction breaks data protection law we tell you and may pause it.
- If the law of the EU, a member state, or another law we are subject to requires us to process the data otherwise, we tell you before we do, unless that law forbids telling you.
- An instruction outside what the Service does may cost us time. We will tell you before we charge for it, and we may decline an instruction the Service cannot carry out.
6. Confidentiality
Everyone at Whisk with access to Customer Personal Data is bound by confidentiality that outlasts their engagement, and gets only the access their job needs. Our staff access Customer Personal Data only at your request, and that access is logged.
7. Security
We take the technical and organisational measures in Annex 2, keep them current, and tell you through the trust page and the changelog when they change materially. We will not make a change that materially weakens them. They cover isolation of every app in its own sandboxed container and network; encryption in transit; envelope encryption of secrets with a key per organisation and a master key we never hold on our servers; continuous backup; weekly restore drills with a report you can read; vulnerability scanning of every image; an audit log of every sign-in, permission change and secret access.
Some of the Service's security is yours to configure: roles and permissions, whether your people sign in with passkeys, what your app logs, and what your app does with the data it holds. We give you the controls; you decide how to use them.
8. Subprocessors
- You give general authorisation for the subprocessors in Annex 3. Each is bound by a written contract with data protection obligations no weaker than these.
- We add or replace a subprocessor that will process Customer Personal Data only after it has been listed in Annex 3 for at least 30 days. On the Business and Enterprise plans we also tell your owners by email when it is listed. You have those 30 days to object on reasonable data protection grounds. We will try to resolve it with a different provider, a different configuration, or by leaving the feature out for you. If we cannot, you may terminate the affected service, or the whole agreement, and export your data. There is no refund of fees already paid.
- We may appoint a subprocessor without notice where an emergency demands it, and we tell you as soon as we can afterwards.
- We remain responsible to you for what a subprocessor does as if we had done it ourselves.
9. Assistance
- Data subject requests. The Service lets you answer most requests yourself: the data is in your databases, which you can query, export and restore; customer accounts can be listed, blocked and removed. Where a request reaches us about data in your apps we pass it to you within 5 business days and do not answer it ourselves, except to tell the person we have passed it on. Where you need our help beyond the Service's own tools, we help at a reasonable cost, and at no cost where the request arises from something we got wrong.
- Personal data breaches. If we become aware of a personal data breach affecting Customer Personal Data we tell your owners without undue delay and in any event within 48 hours, by email. We tell you what happened and when, which categories of data and roughly how many people and records are involved, the likely consequences, what we have done to contain and fix it, and what we recommend you do. We update you as we learn more, and keep a record of the breach and our response. Telling you is not an admission of fault. Notifying a supervisory authority or the people affected is yours to decide and to do; we give you what you need to do it.
- Impact assessments and consultation. We give you the information about the Service you reasonably need for a data protection impact assessment or a consultation with a supervisory authority, and we help with the parts only we can answer.
10. Audits
- The trust page, the restore drill reports, the audit log with export, the changelog and the security disclosure policy are the standing evidence of how we meet this agreement, and we make them available to you as our first answer to an audit request.
- Once a year, or after a breach affecting your data, you may ask us written questions about our measures and we answer within 30 days.
- Where data protection law gives you a right to an on-site audit or inspection, you may exercise it with 30 days' notice, during business hours, at your cost, no more than once a year unless a breach or an authority requires otherwise, through an independent auditor bound by confidentiality who is not a competitor of ours and who does not disturb other tenants or see their data.
- We hold no SOC 2 report and no ISO 27001 certificate, and we commit to no date for either. An independent penetration test is carried out at least once a year. The trust page shows publicly how the platform is running. The weekly restore drill is run and its report is published there. That is what you may rely on instead.
11. Deletion and return
- You can export everything at any time, on every plan and in every status: repositories, database dumps, manifests, secret names and the audit log, as one archive.
- When your organisation is deleted, or ends under the Terms, it enters shredding and is shredded 30 days later, or sooner on request. Shredding destroys the organisation's encryption key, which makes every secret, credential and connection token that was sealed under it unreadable in every copy and every backup, and removes its apps, databases, caches, files and customer sign-in pools. Backups of databases and files roll out of retention within a further 30 days.
- The 30 days before shredding are your window to export. We will shred sooner if you ask at support@whisk.run, and we will confirm in writing when it is done.
- We keep after shredding only what the law requires (billing records) and the audit log, which records that things happened and who did them but not the content of your data. What we keep stays protected by this agreement for as long as we hold it.
12. International transfers
Backups are stored with Backblaze, a United States company, and platform email and key operations go through Amazon Web Services. Email the platform and your apps send goes through Resend, in the United States, and a hostname's public traffic goes through Bunny, in the EEA, only when you turn on its CDN. For any transfer of personal data out of the EEA, the United Kingdom or Switzerland, we rely on the subprocessor's standard contractual clauses, on its certification under the EU-US Data Privacy Framework, or on an adequacy decision that covers it, as listed in Annex 3, and we carry out a transfer impact assessment where one is required.
Where the law requires the clauses between you and us, they are incorporated into this agreement:
| Clause | How it is set |
|---|---|
| Module | Module two (controller to processor), or module three (processor to processor) where you are yourself a processor |
| Parties | You as data exporter, Whisk as data importer |
| Clause 7, docking | Included |
| Clause 9, subprocessors | Option 2, general written authorisation, with 30 days' notice through Annex 3 (and by email on the Business and Enterprise plans) |
| Clause 11, redress | The optional independent dispute resolution language is not included |
| Clause 17, governing law | The law of Ireland |
| Clause 18, forum | The courts of Ireland |
| Annexes I, II and III | Annexes 1, 2 and 3 below |
The clauses, and disputes about them, are the only part of this agreement under Irish law and before the Irish courts. Everything else, including the rest of this agreement and the Terms of service, stays under the law of New Zealand and goes to the New Zealand courts.
For transfers out of the United Kingdom, the clauses apply as modified by the Information Commissioner's International Data Transfer Addendum, with the annexes below as its tables and neither party able to end the addendum under its section 19. For transfers out of Switzerland, references to the GDPR read as references to the FADP, the Federal Data Protection and Information Commissioner is the supervisory authority, and the clauses protect data about legal entities as well as individuals.
13. Liability, precedence and term
- Liability under this agreement is subject to the limits in the Terms of service, counted together with liability under the Terms rather than in addition to it, except that neither party limits its liability to data subjects where the law does not allow it, and except where the standard contractual clauses say otherwise.
- If this agreement conflicts with the Terms of service, this agreement wins for anything about personal data. If the standard contractual clauses conflict with either, the clauses win.
- This agreement runs until shredding is complete and nothing of yours is left to protect. It is governed by the law that governs the Terms of service, except where data protection law or the clauses require otherwise.
Annex 1: Details of the processing
| Item | Detail |
|---|---|
| Data exporter | The Customer: the organisation that uses Whisk, acting as controller, or as processor for its own client |
| Data importer | Whisk, Auckland, New Zealand, support@whisk.run, acting as processor |
| Categories of data subjects | The Customer's team members and guests; the customers and end users its apps sign in; the people whose records its apps hold, among them employees, customers, suppliers and contacts |
| Categories of personal data | Names, email addresses, roles and group memberships; authentication records and session metadata; the contents of the Customer's databases, files and uploads; application and workflow logs; email the Service sends on the Customer's behalf |
| Special-category data | Not permitted without our prior agreement (section 4). Where agreed, it is protected by the measures in Annex 2 and any further measures we agree in writing |
| Frequency of the transfer | Continuous, for as long as the apps run |
| Nature and purpose | Hosting and operating the Customer's apps and the platform services they use, as described in section 3 |
| Duration | The life of the organisation on the Service, plus the shredding and backup retention windows in section 11. Within that life, some records go sooner: webhook deliveries (headers and body) 30 days after they arrive, or 7 days if their signature did not verify; the app's customers' sessions 30 days after they end; edge and app logs after 14 days; traces after 7 days |
| Subprocessors | As Annex 3, for the purposes and durations stated there |
| Competent supervisory authority | The authority of the member state where the data exporter is established, or its EU representative, as the clauses determine |
Technical and organisational measures (Annex 2)
| Area | Measure |
|---|---|
| Isolation | Every app in its own container under a sandboxed kernel, non-root, read-only filesystem, on a network reaching only its own database and the platform's services. One database and one database role per app by default. |
| Encryption in transit | TLS on every hostname; the private network between the platform's machines is encrypted end to end. |
| Encryption at rest | Provider-level encryption of disks and object storage; backups encrypted before they leave the platform. |
| Encryption of secrets | Envelope encryption: a key per secret, wrapped by a key per organisation, wrapped by a master key in AWS KMS. Servers never hold the master key. Values are write-only in the dashboard and scrubbed from logs. |
| Access control | Sign-in by passkey, emailed code or password; multi-factor sign-in offered to everyone, with passkeys available to every owner and admin; roles with separate permissions for deploying and for reading secrets; per-app access grants; guests marked as external. |
| Agent access | Agents act with short-lived tokens scoped to one organisation and app, without the right to read secrets, revocable by the person who approved them. |
| Audit | Every sign-in, permission change, secret set or read and deploy is written to the organisation's audit log, kept indefinitely, exportable. The IP address on each entry is removed after 12 months. Signs of a stolen credential page the operator. |
| Backup | Continuous database archiving. Point-in-time recovery to any minute in the last 30 days. |
| Restore testing | A weekly automated restore drill; the report is on the trust page. |
| Resilience | A warm standby with failover in minutes; documented recovery point and recovery time targets on the trust page; runbooks for the failures we expect. |
| Vulnerability management | Images scanned on every build and rebuilt when a base image is patched; hosts patched automatically. |
| Edge protection | Security headers, CSRF protection and rate limits applied in front of every app; identity headers stripped from incoming traffic and set only by the platform. |
| Outbound port 25 blocked for every app; platform email through a provider that tracks reputation per tenant, with automatic pause on bounces and complaints. | |
| Staff access | Staff access customer data only at the customer's request, and that access is logged. Access ends when an engagement ends. |
| Personnel | Everyone with production access is bound by confidentiality and is given only the access their role needs. Access is reviewed and withdrawn when someone leaves. We make no commitment about background checks or security training. |
| Incident response | Signs of compromise, such as a container's one-time credential used twice, page the operator at once. A breach is contained, assessed and reported with the notification commitments in section 9.2, and a public post-incident note is posted on the status page. |
| Deletion | Crypto-shredding by destruction of the organisation's key, plus removal of apps, databases, files and sign-in pools, on the timeline in section 11. |
| Operations | Runbooks, monitoring with alerts to the operator, a public status page, and a changelog of material changes to these measures. |
| Subprocessor management | Written contracts with terms no weaker than these, a published list updated 30 days before a change (emailed on the Business and Enterprise plans) and an objection right. |
Subprocessors (Annex 3)
| Subprocessor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | EEA | Servers, object storage for tenant files | None needed (EEA) |
| Backblaze, Inc. | United States | Off-site backups (encrypted) | Standard contractual clauses |
| Amazon Web Services, Inc. (SES, KMS) | Region as configured for the platform | Platform email; master key operations | Standard contractual clauses, or the EU-US Data Privacy Framework, or adequacy, as applicable to the region |
| Resend, Inc. | United States | Email the platform and the Customer's apps send | Standard contractual clauses, or the EU-US Data Privacy Framework where Resend is certified |
| Stripe, Inc. | United States, Ireland | Payments and invoices (billing data only) | Standard contractual clauses |
| Cloudflare, Inc. | Global | DNS for the platform's domains | Standard contractual clauses |
| BunnyWay d.o.o. | Slovenia | CDN for a hostname, only when the Customer turns it on | None needed (EEA) |
This list is the current one; the page you are reading is the notice. A new subprocessor is listed here 30 days before it starts, owners on the Business and Enterprise plans are emailed when it is, and this page is the record of who they are. There is no feed or mailing list to subscribe to.
Contact: Whisk, Auckland, New Zealand, support@whisk.run.
See also: Terms of service · Acceptable use policy · Privacy policy · Takedown process · Security disclosure policy