- Legal
- Subprocessors
Legal
Subprocessors
Every company that processes data on our behalf, what it does and where.
Drafted in-house and not reviewed by a lawyer. It is accurate about what the system does and about what each vendor publishes; it is not legal advice.
Last reviewed 2026-09-14.
WhooshBang uses the subprocessors below to provide the service. Each one processes personal data on our behalf, under a written agreement imposing data protection obligations no less protective than those in our data processing agreement.
We do not use any other subprocessor, and we do not sell or share personal data with anyone for their own purposes.
The list
| Subprocessor | Legal entity | What it does for us | What it processes | Where it durably stores it | Transfer basis | Certifications it holds |
|---|---|---|---|---|---|---|
| Tiger Data | Timescale, Inc., d/b/a Tiger Data (United States), operating the instance on AWS | The database. Everything durable | Every category below: organization and membership identifiers, credentials, subscriber identifiers, channel bindings, message content, interaction answers, delivery diagnostics, audit events | aws:eu-west-1 — Ireland | No transfer of stored data out of the EEA. Where the US company processes it, its DPA incorporates the EU standard contractual clauses (Decision 2021/914) and the UK Addendum | SOC 2 Type 2; HIPAA on its Enterprise plan (security). The annual SOC 2 report is available to its Scale and Enterprise customers |
| Cloudflare | Cloudflare, Inc. (United States) | Compute, queues, key-value storage, logs, network | Request traffic; OAuth grants and consent state; delivery and provider-ingress queue jobs; structured log lines carrying pseudonymous identifiers | Compute is pinned to aws:eu-west-1 in production. Key-value storage replicates globally. Queues and Workers Logs have no stated region | EU-U.S. Data Privacy Framework, with the EU standard contractual clauses in its DPA applying automatically if that certification lapses — a commitment Cloudflare makes expressly | Published on Cloudflare’s trust hub; we do not restate them |
| Clerk | Clerk, Inc. (United States) | Customer sign-in and authentication | The sign-in identity of a customer’s own users — email address, name, authentication factors | Clerk’s infrastructure, in the United States | EU-U.S. Data Privacy Framework, with the EU standard contractual clauses (Modules One, Two and Three) in its DPA as a standing fallback | Published on Clerk’s trust centre; we do not restate them |
| Resend | Plus Five Five, Inc. (United States) | Sending email from WhooshBang’s shared pool and reporting delivery outcomes | Recipient email address, notification content, delivery metadata, events and logs | United States. Resend states that selecting a sending region does not change storage location | Resend’s DPA incorporates the EU standard contractual clauses and its GDPR statement states that it participates in the EU-U.S. Data Privacy Framework | Published on Resend’s security page; we do not restate them |
| Telegram | Telegram Messenger Inc., with group companies in the British Virgin Islands and Dubai | Delivering a notification to a recipient who chose Telegram | The routing identity we create for that recipient, and the notification we send | Telegram states that data for an account signed up from the UK or EEA is stored in data centres in the Netherlands | See below | None published |
| Slack | Slack Technologies Limited (Ireland) for workspaces outside the US and Canada; Slack Technologies, LLC (United States) otherwise — both Salesforce companies | Delivering a notification into your own Slack workspace | The same | Your workspace. Slack stores it in the United States unless you have bought Slack data residency | Your own agreement with Slack governs your workspace. Where your workspace is outside the US and Canada, the entity we disclose to is in Ireland. Slack covers the onward leg to its US company with the standard contractual clauses its own privacy policy leads with, and Slack Technologies, LLC is separately covered by the EU-U.S. Data Privacy Framework through Salesforce’s certification | Published on Salesforce’s compliance site; we do not restate them |
Telegram and Slack are not ordinary subprocessors
Both are on this list because your users’ data reaches them, and a compliance team is entitled to see them named. But the relationship is not the one the word “subprocessor” usually describes, and pretending otherwise would be misleading.
A recipient already has that account. They held it, under that provider’s terms, before you invited them, and they chose to receive notifications there by acting on a single-use link. Their account, their chat history and their reading of a message belong to that provider under its own terms. Telegram says so in its own privacy policy, where it calls itself “the data controller responsible for your personal data” for users in the European Economic Area.
On Slack it is your workspace, not ours. What a notification becomes once it is delivered is Customer Data in your own Slack workspace, held by Slack as your processor under your Slack agreement. Slack’s privacy policy, in its own words and its own hedge: “In general, Customer is the controller of Customer Data. In general, Slack is the processor of Customer Data and the controller of Other Information.” The hedge matters — Slack is a controller of what it calls Other Information, meaning the account and device data it generates about a person, as distinct from what is in your channels. We are not a party to that agreement, and nothing we do changes it.
What is genuinely ours in both cases is narrower: the routing identity we create so that a message can reach that person, and the fact of disclosing it to the provider. That is what our data processing agreement covers.
Resend retention and account ownership
Resend states that email content, metadata, delivery events, logs and metrics are stored for 30 days on its Free, Pro and Scale plans; Enterprise customers can configure retention. It also states that backups are retained for seven days. Its optional control that disables message-content storage is arranged through support, costs extra and has plan, account-age, volume, website and bounce-rate requirements; WhooshBang cannot promise it as an onboarding option or determine its state through a documented API. These are vendor facts, not WhooshBang retention settings. See Resend’s GDPR statement, security page, and content-storage requirements.
The table’s Resend relationship applies when WhooshBang sends from its dedicated shared Resend account. For a customer-owned email connection, the customer authorizes its own Resend team and its own agreement, billing, retention and content-storage controls apply. WhooshBang remains responsible under this DPA for its handling of the OAuth grant and any copy held in WhooshBang.
Resend publishes its current downstream provider list at resend.com/legal/subprocessors.
Where a sending identity is your own
WhooshBang offers customer-owned sending identities through customer_byok and
customer_managed on Telegram, customer_managed on Slack, and
customer_managed email through an authorized Resend team. In those modes the
bot, app or email domain that speaks to your recipient belongs to you. You have
chosen the provider authority, and its agreement is yours rather than ours.
Changes to this list
We will publish an addition or replacement here at least thirty days before that subprocessor begins processing personal data on our behalf. If you object on reasonable data protection grounds within ten days of publication, we will work with you in good faith; if we cannot resolve it, you may terminate the affected service.
To be told when this list changes, write to privacy@flowxo.com.