Trust Center
Everything your
IT department will ask.
Answered in public, before the meeting. Documents, sub-processors, retention, security and the company behind them, in one place.
The short answers
Where data lives
European Union, Ireland
Live location of a child
Never collected
Ads, resale, model training
None, on any content
Breach notice to you
Within 24 hours
Safety audit trail
30 days, rolling
Sub-processors
Five, all named
Documents
Sixteen, all readable without a form, all versioned and dated.
Agreements
Data
Where a byte actually goes
Tap a box to see what it holds and what it will never hold.
On the device
European Union
Outside the EU, under SCCs
Everything about a participant stays inside the two European boxes.
Sub-processors
Last updated: 2026-07-24
Every third party that can touch partner data, with 30 days' notice before this list changes.
| Provider | Role | Region | Since |
|---|---|---|---|
| Supabase | database, authentication, file storage | EU (AWS eu-west-1, Ireland) | 2026-01-01 |
| Apple | push notifications through APNs | Global (Apple infrastructure) | 2026-01-01 |
| Stripe | card payments | EU and US (SCC-backed) | 2026-05-01 |
| Vercel | hosting for findndo.app and the web cabinet | EU (Dublin, dub1) | 2026-05-01 |
| Resend | transactional email: receipts, cabinet credentials, booking confirmations | EU and US (SCC-backed) | 2026-05-01 |
Vendor assessment pack
The twenty-one questions a procurement questionnaire asks, answered. Print this page and attach it, or send the link.
| Question | Answer |
|---|---|
| Who is the controller and who is the processor? | Your organization is the controller of participant data; FND is the processor. Roles are set out in /dpa, clause 1. |
| Is there a GDPR Art. 28 agreement? | Yes, published at /dpa and part of the Terms. A countersigned copy with your details is generated at /dpa/sign. |
| Where is the data hosted? | European Union: Supabase on AWS in Ireland. Details in /dpa, clause 8. |
| Are there transfers outside the EEA? | No participant data. Payment and transactional email involve US-operating providers under Standard Contractual Clauses, and neither receives participant data. See /subprocessors. |
| Who are the sub-processors? | Supabase, Apple, Stripe, Vercel and Resend. The full registry with regions and dates is at /subprocessors. |
| How are we told about a new sub-processor? | Email, at least 30 days before it takes effect, with a right to object. /subprocessors, clause 2. |
| What personal data is processed? | The exhaustive category table is at /dpa, clause 4, and /privacy, clause 2. |
| Is location of minors tracked? | No. Presence comes from zone check-in events only; a live location is never collected or stored. /privacy, clause 3. |
| How long is data kept? | Every category has a published period at /retention. Safety records roll on 30 days; an organization's world is deleted 90 days after its term. |
| How is data deleted? | Revoking a participant deletes in full cascade; an organization can require immediate deletion at any time, confirmed in writing. /dpa, clause 11. |
| What are the security measures? | Row-level security, TLS, encryption at rest, MFA on production, daily backups with tested restores. Full list at /security. |
| What happens after a breach? | You are told within 24 hours of us becoming aware, with scope and measures, so your own 72-hour duty is workable. /dpa, clause 10. |
| Do you hold SOC 2 or ISO 27001? | No, and we say so rather than imply it. What exists instead is at /security, clause 9. |
| How do data subject requests work? | Most are handled by your director in the cabinet immediately; we assist within two business days. Procedure at /rights. |
| Are minors' rules documented? | Yes, in a document of their own at /children, including consent, contact rules, photos and moderation. |
| Is the product accessible? | Target WCAG 2.2 AA, self-assessed, with known gaps listed at /accessibility. |
| Do you keep an Art. 30 record? | Yes, published in full at /ropa. Your own Art. 30(1) record can copy from it. |
| Have you assessed the transfers after Schrems II? | Yes, the transfer impact assessment is at /transfers, per recipient, with the supplementary measures. |
| Is there a DPIA we can use? | A DPIA starter written from the processor side is at /dpia, with a risk and measure table to adapt. |
| What if your company stops or you are unavailable? | Full export on request within five business days, 90 days' notice on wind-down, and a custodian arrangement. All of it at /continuity. |
| Are there rules for the participants themselves? | Yes, in plain language at /participants, which doubles as the end-user terms in the app. |
Parental consent text
The paragraph promised in /children, ready to paste into the registration form you already send to parents. Edit it freely; it is yours.
During the session, [ORGANIZATION] uses FND, an app reserved for our verified participants and staff. Participants see the activities running right now and can join them. There is no public registration, no contact from outside the group, and no advertising. FND never collects or shows the live location of a child: the app displays activities, not people, and photos taken in an activity stay inside our group. We are responsible for the data of your child within FND; the details are at findndo.app/children and findndo.app/privacy. You can ask us at any time to see, correct or delete your child's data, or to withdraw this consent, in which case the account is revoked the same day. I consent to [CHILD'S NAME] taking part in [ORGANIZATION]'s FND group during the session. Name of parent or guardian: ______________ Date: ____________ Signature: ______________
Availability
We target 99.5% monthly availability outside announced maintenance, announce downtime 48 hours ahead, and publish incidents to affected organizations with a written post-mortem. There is no status-page theatre: with one operator, a mail from a human is faster and more honest than a dashboard.
Who to write to
One person answers all three, on Belgian business days, within one day.
Issued by
FND (Find 'n Do)
Belgium
Supervisory authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Write to us