Loading
Loading
Trust and security
Most vendors make you sit through a call before they will tell you where your data lives or which certifications they actually hold. Here is the whole picture, including the parts that do not flatter us. If you are running a security review, you should be able to finish most of it on this page.
Where we actually stand
This is the section where wellbeing vendors usually write “enterprise-grade security” and move on. Four of the six rows below are things we do not have.
UK GDPR compliance
Whole Technologies Group Ltd is the data controller for its own users and the processor for organisation data. A data processing agreement is available before contract, not after.
SOC 2 Type II (infrastructure)
Our infrastructure providers hold current SOC 2 Type II reports. This is their certification, not ours, and we do not present it as ours.
SOC 2 Type II (Whole)
We do not hold SOC 2. Pursuing it before we have the customer base to justify the audit cost would be theatre. We will commit to a timeline contractually where a customer needs one.
ISO 27001
Not held. On the roadmap alongside SOC 2, driven by enterprise demand rather than a fixed date we would then miss.
Penetration test
No third-party penetration test has been completed to date. We will commission one as a condition of an enterprise agreement, and share the report and remediation plan.
Security questionnaire response
We complete standard questionnaires, including CAIQ-Lite and bespoke enterprise formats, and will get on a call with your security team rather than returning a document and disappearing.
If your procurement process has a hard requirement for SOC 2 or ISO 27001 today, we will not pass it, and we would rather tell you on this page than three weeks into an evaluation. Where a certification timeline can be a contractual commitment instead of a precondition, we are happy to sign one.
Privacy architecture
Aggregation happens in the query layer, before data reaches any interface. There is no dashboard view that resolves to a person and no setting that creates one.
| Data | HR admin | Manager | Whole staff |
|---|---|---|---|
| An individual wellbeing score | No | No | No |
| An individual check-in or reflection | No | No | No |
| Connected wearable or health data | No | No | No |
| Team aggregate, 5 or more participants | Yes | Partial | Yes |
| Team aggregate, under 5 participants | No | No | No |
| Whether a named person is enrolled | Yes | Yes | Yes |
| Whether a named person is active this week | No | No | Yes |
Managers see aggregates for their own reporting line only, and only when that line has five or more participants. Whole staff access to organisation aggregates is limited to named support and engineering staff, requires an authenticated admin session, and is written to an append-only audit log. Nobody at Whole, at any level, can read an individual’s check-ins or health data through the product.
Sub-processors
We notify customers of additions at least 30 days before they take effect, which gives you a window to object. The definitive list forms part of the DPA.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All application and health data | EU (Ireland) |
| Vercel | Application hosting and edge delivery | Request metadata, IP addresses | Global edge, EU primary |
| Stripe | Subscription billing | Billing contact and payment metadata. Card details never reach us. | EU and US |
| Resend | Transactional email | Name and email address | EU and US |
| Sentry | Error and performance monitoring | Error traces, user identifier. Health data is scrubbed before send. | US |
| Anthropic | Plan generation and reflective insight | De-identified wellbeing signals. No name, email or organisation identifier. | US |
| OpenAI | Plan generation and reflective insight | De-identified wellbeing signals. No name, email or organisation identifier. | US |
| Apple (APNs) | Push notifications | Device token and notification body | Global |
| Daily | Video sessions with coaches, where used | Session media, not recorded by default | Global |
Data handling
Primary storage and processing run in EU (Ireland) data centres. Model inference and error monitoring involve US providers under standard contractual clauses; the payloads sent to them carry no name, email or organisation identifier. Contractual EU-only residency is available on Company and Enterprise terms.
Health and check-in data is retained while the account is active and for 30 days after deletion is requested, at which point it is purged from primary storage. Backups roll off within a further 30 days. Aggregated, non-identifying organisation metrics may be retained for reporting continuity.
TLS 1.2 or better in transit, AES-256 at rest. Row-level security policies scope every table to its owner, and the aggregation layer runs under a separate role that cannot read individual rows.
Export and deletion are self-service inside the app for every employee, independent of their employer. An employee leaving your organisation keeps their personal account and history; you lose access to their contribution to the aggregate, as you should.
SAML and OIDC single sign-on, SCIM 2.0 provisioning and group sync. Administrative actions inside your organisation are recorded in an append-only audit log that you can export.
We notify affected customers within 72 hours of confirming a personal data breach, with what we know, what we do not yet know, and what we are doing. Report a vulnerability to security@joinwhole.app.
Documents
One request returns the whole set. We do not drip-feed documents to keep you on a call schedule.
Data processing agreement
Our DPA including standard contractual clauses, to sign or to redline.
Security questionnaire
CAIQ-Lite, or a response in your own format.
Architecture overview
How the aggregation layer works and where the privacy thresholds are enforced.
Records of processing
Article 30 record covering organisation data.