Loading
Loading
Trust and security
The whole picture, including the parts that do not flatter us. A security review should be able to finish most of its work on this page.
Where we actually stand
Four of the six rows below are things we do not have.
2
YesHeld
1
PartialHeld by our providers
3
NoNot held
Whole Technologies Group Ltd is the data controller for its own users and the processor for organisation data. A data processing agreement is available before contract, not after.
Our infrastructure providers hold current SOC 2 Type II reports. This is their certification, not ours, and we do not present it as ours.
We do not hold SOC 2. Pursuing it before we have the customer base to justify the audit cost would be theatre. We will commit to a timeline contractually where a customer needs one.
Not held. On the roadmap alongside SOC 2, driven by enterprise demand rather than a fixed date we would then miss.
No third-party penetration test has been completed to date. We will commission one as a condition of an enterprise agreement, and share the report and remediation plan.
We complete standard questionnaires, including CAIQ-Lite and bespoke enterprise formats, and will get on a call with your security team rather than returning a document and disappearing.
If your procurement process has a hard requirement for SOC 2 or ISO 27001 today, we will not pass it, and we would rather tell you on this page than three weeks into an evaluation. Where a certification timeline can be a contractual commitment instead of a precondition, we are happy to sign one.
Privacy architecture
Aggregation happens in the query layer, before data reaches any interface. There is no dashboard view that resolves to a person and no setting that creates one.
Your people
Personal, and theirs
Your organisation
Aggregates, by team
| Data | HR admin | Manager | Whole staff |
|---|---|---|---|
| An individual wellbeing score | No | No | No |
| An individual check-in or reflection | No | No | No |
| An individual post-practice reflection | No | No | No |
| Aggregate post-practice reflection sentiment, any cohort sizeUnlike check-ins, reflections have no aggregate path at all, not even above the cohort floor. | No | No | No |
| An individual streak, badge, or practice history | No | No | No |
| Connected wearable or health data | No | No | No |
| Team aggregate, 5 or more participants | Yes | Partial | Yes |
| Team aggregate practice participation, 5 or more members | Yes | Partial | Yes |
| Team aggregate, under 5 participants | No | No | No |
| Whether a named person is enrolled | Yes | Yes | Yes |
| Whether a named person is active this week | No | No | Yes |
| An individual challenge submission or scoreEmployers see team totals only, for teams of 5 or more taking part. | No | No | Yes |
| Names of people meeting the check-in threshold, via an audited requestOff by default. Only possible where Whole has switched on the duty-of-care review for the organisation. See the conditions below. | Partial | No | Yes |
The one exception
Where Whole has switched it on for an organisation, an organisation admin can request the names of employees who meet a fixed threshold on their own check-ins: average energy at or below 2.0 and average mood at or below 2.5 over 30 days, from at least 5 check-ins. It is a deterministic rule applied to self-reported numbers, not a model or a prediction.
An employer with a genuine duty of care may need some way to act, and a system with no path at all invites a worse one outside the product. So the path exists, it is off unless deliberately switched on, it is narrow, and it is never silent: nobody is named without being told.
Managers see aggregates for their own reporting line only, and only when that line has five or more participants. Whole staff access to organisation aggregates is limited to named support and engineering staff, requires an authenticated admin session, and is written to an append-only audit log. Nobody at Whole, at any level, can read an individual’s check-ins or health data through the product.
Sub-processors
We notify customers of additions at least 30 days before they take effect, which gives you a window to object. The definitive list forms part of the DPA.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All application and health data | EU (Ireland) |
| Vercel | Application hosting and edge delivery | Request metadata, IP addresses | Global edge, EU primary |
| Stripe | Subscription billing | Billing contact and payment metadata. Card details never reach us. | EU and US |
| Resend | Transactional email | Name and email address | EU and US |
| Sentry | Error and performance monitoring | Error traces, user identifier. Health data is scrubbed before send. | US |
| Anthropic | Plan generation and reflective insight | De-identified wellbeing signals. No name, email or organisation identifier. | US |
| OpenAI | Plan generation and reflective insight | De-identified wellbeing signals. No name, email or organisation identifier. | US |
| Apple (APNs) | Push notifications | Device token and notification body | Global |
| Daily | Video sessions with coaches, where used | Session media, not recorded by default | Global |
Data handling
Primary storage and processing run in EU (Ireland) data centres. Model inference and error monitoring involve US providers under standard contractual clauses; the payloads sent to them carry no name, email or organisation identifier. Contractual EU-only residency is available on Company and Enterprise terms.
Health and check-in data is retained while the account is active and for 30 days after deletion is requested, at which point it is purged from primary storage. Backups roll off within a further 30 days. Aggregated, non-identifying organisation metrics may be retained for reporting continuity.
TLS 1.2 or better in transit, AES-256 at rest. Row-level security policies scope every table to its owner, and the aggregation layer runs under a separate role that cannot read individual rows.
Export and deletion are self-service inside the app for every employee, independent of their employer. An employee leaving your organisation keeps their personal account and history; you lose access to their contribution to the aggregate, as you should.
SAML and OIDC single sign-on, SCIM 2.0 provisioning and group sync. Administrative actions inside your organisation are recorded in an append-only audit log that you can export.
We notify affected customers within 72 hours of confirming a personal data breach, with what we know, what we do not yet know, and what we are doing. Report a vulnerability to security@joinwhole.app.
Documents
Data processing agreement
Our DPA including standard contractual clauses, to sign or to redline.
Security questionnaire
CAIQ-Lite, or a response in your own format.
Architecture overview
How the aggregation layer works and where the privacy thresholds are enforced.
Records of processing
Article 30 record covering organisation data.