1. Legal
  2. Subprocessors

Drafted in-house and not reviewed by a lawyer. It is accurate about what the system does and about what each vendor publishes; it is not legal advice.

Last reviewed 2026-09-14.

WhooshBang uses the subprocessors below to provide the service. Each one processes personal data on our behalf, under a written agreement imposing data protection obligations no less protective than those in our data processing agreement.

We do not use any other subprocessor, and we do not sell or share personal data with anyone for their own purposes.

​
The list

SubprocessorLegal entityWhat it does for usWhat it processesWhere it durably stores itTransfer basisCertifications it holds
Tiger DataTimescale, Inc., d/b/a Tiger Data (United States), operating the instance on AWSThe database. Everything durableEvery category below: organization and membership identifiers, credentials, subscriber identifiers, channel bindings, message content, interaction answers, delivery diagnostics, audit eventsaws:eu-west-1 — IrelandNo transfer of stored data out of the EEA. Where the US company processes it, its DPA incorporates the EU standard contractual clauses (Decision 2021/914) and the UK AddendumSOC 2 Type 2; HIPAA on its Enterprise plan (security). The annual SOC 2 report is available to its Scale and Enterprise customers
CloudflareCloudflare, Inc. (United States)Compute, queues, key-value storage, logs, networkRequest traffic; OAuth grants and consent state; delivery and provider-ingress queue jobs; structured log lines carrying pseudonymous identifiersCompute is pinned to aws:eu-west-1 in production. Key-value storage replicates globally. Queues and Workers Logs have no stated regionEU-U.S. Data Privacy Framework, with the EU standard contractual clauses in its DPA applying automatically if that certification lapses — a commitment Cloudflare makes expresslyPublished on Cloudflare’s trust hub; we do not restate them
ClerkClerk, Inc. (United States)Customer sign-in and authenticationThe sign-in identity of a customer’s own users — email address, name, authentication factorsClerk’s infrastructure, in the United StatesEU-U.S. Data Privacy Framework, with the EU standard contractual clauses (Modules One, Two and Three) in its DPA as a standing fallbackPublished on Clerk’s trust centre; we do not restate them
ResendPlus Five Five, Inc. (United States)Sending email from WhooshBang’s shared pool and reporting delivery outcomesRecipient email address, notification content, delivery metadata, events and logsUnited States. Resend states that selecting a sending region does not change storage locationResend’s DPA incorporates the EU standard contractual clauses and its GDPR statement states that it participates in the EU-U.S. Data Privacy FrameworkPublished on Resend’s security page; we do not restate them
TelegramTelegram Messenger Inc., with group companies in the British Virgin Islands and DubaiDelivering a notification to a recipient who chose TelegramThe routing identity we create for that recipient, and the notification we sendTelegram states that data for an account signed up from the UK or EEA is stored in data centres in the NetherlandsSee belowNone published
SlackSlack Technologies Limited (Ireland) for workspaces outside the US and Canada; Slack Technologies, LLC (United States) otherwise — both Salesforce companiesDelivering a notification into your own Slack workspaceThe sameYour workspace. Slack stores it in the United States unless you have bought Slack data residencyYour own agreement with Slack governs your workspace. Where your workspace is outside the US and Canada, the entity we disclose to is in Ireland. Slack covers the onward leg to its US company with the standard contractual clauses its own privacy policy leads with, and Slack Technologies, LLC is separately covered by the EU-U.S. Data Privacy Framework through Salesforce’s certificationPublished on Salesforce’s compliance site; we do not restate them

​
Telegram and Slack are not ordinary subprocessors

Both are on this list because your users’ data reaches them, and a compliance team is entitled to see them named. But the relationship is not the one the word “subprocessor” usually describes, and pretending otherwise would be misleading.

A recipient already has that account. They held it, under that provider’s terms, before you invited them, and they chose to receive notifications there by acting on a single-use link. Their account, their chat history and their reading of a message belong to that provider under its own terms. Telegram says so in its own privacy policy, where it calls itself “the data controller responsible for your personal data” for users in the European Economic Area.

On Slack it is your workspace, not ours. What a notification becomes once it is delivered is Customer Data in your own Slack workspace, held by Slack as your processor under your Slack agreement. Slack’s privacy policy, in its own words and its own hedge: “In general, Customer is the controller of Customer Data. In general, Slack is the processor of Customer Data and the controller of Other Information.” The hedge matters — Slack is a controller of what it calls Other Information, meaning the account and device data it generates about a person, as distinct from what is in your channels. We are not a party to that agreement, and nothing we do changes it.

What is genuinely ours in both cases is narrower: the routing identity we create so that a message can reach that person, and the fact of disclosing it to the provider. That is what our data processing agreement covers.

​
Resend retention and account ownership

Resend states that email content, metadata, delivery events, logs and metrics are stored for 30 days on its Free, Pro and Scale plans; Enterprise customers can configure retention. It also states that backups are retained for seven days. Its optional control that disables message-content storage is arranged through support, costs extra and has plan, account-age, volume, website and bounce-rate requirements; WhooshBang cannot promise it as an onboarding option or determine its state through a documented API. These are vendor facts, not WhooshBang retention settings. See Resend’s GDPR statement, security page, and content-storage requirements.

The table’s Resend relationship applies when WhooshBang sends from its dedicated shared Resend account. For a customer-owned email connection, the customer authorizes its own Resend team and its own agreement, billing, retention and content-storage controls apply. WhooshBang remains responsible under this DPA for its handling of the OAuth grant and any copy held in WhooshBang.

Resend publishes its current downstream provider list at resend.com/legal/subprocessors.

​
Where a sending identity is your own

WhooshBang offers customer-owned sending identities through customer_byok and customer_managed on Telegram, customer_managed on Slack, and customer_managed email through an authorized Resend team. In those modes the bot, app or email domain that speaks to your recipient belongs to you. You have chosen the provider authority, and its agreement is yours rather than ours.

​
Changes to this list

We will publish an addition or replacement here at least thirty days before that subprocessor begins processing personal data on our behalf. If you object on reasonable data protection grounds within ten days of publication, we will work with you in good faith; if we cannot resolve it, you may terminate the affected service.

To be told when this list changes, write to privacy@flowxo.com.