Trust Center

Everything your
IT department will ask.

Answered in public, before the meeting. Documents, sub-processors, retention, security and the company behind them, in one place.

The short answers

Where data lives

European Union, Ireland

Live location of a child

Never collected

Ads, resale, model training

None, on any content

Breach notice to you

Within 24 hours

Safety audit trail

30 days, rolling

Sub-processors

Five, all named

Documents

Sixteen, all readable without a form, all versioned and dated.

Where a byte actually goes

Tap a box to see what it holds and what it will never hold.

On the device

European Union

Outside the EU, under SCCs

Everything about a participant stays inside the two European boxes.

Sub-processors

Last updated: 2026-07-24

Every third party that can touch partner data, with 30 days' notice before this list changes.

ProviderRoleRegionSince
Supabasedatabase, authentication, file storageEU (AWS eu-west-1, Ireland)2026-01-01
Applepush notifications through APNsGlobal (Apple infrastructure)2026-01-01
Stripecard paymentsEU and US (SCC-backed)2026-05-01
Vercelhosting for findndo.app and the web cabinetEU (Dublin, dub1)2026-05-01
Resendtransactional email: receipts, cabinet credentials, booking confirmationsEU and US (SCC-backed)2026-05-01
Read it →

Vendor assessment pack

The twenty-one questions a procurement questionnaire asks, answered. Print this page and attach it, or send the link.

QuestionAnswer
Who is the controller and who is the processor?Your organization is the controller of participant data; FND is the processor. Roles are set out in /dpa, clause 1.
Is there a GDPR Art. 28 agreement?Yes, published at /dpa and part of the Terms. A countersigned copy with your details is generated at /dpa/sign.
Where is the data hosted?European Union: Supabase on AWS in Ireland. Details in /dpa, clause 8.
Are there transfers outside the EEA?No participant data. Payment and transactional email involve US-operating providers under Standard Contractual Clauses, and neither receives participant data. See /subprocessors.
Who are the sub-processors?Supabase, Apple, Stripe, Vercel and Resend. The full registry with regions and dates is at /subprocessors.
How are we told about a new sub-processor?Email, at least 30 days before it takes effect, with a right to object. /subprocessors, clause 2.
What personal data is processed?The exhaustive category table is at /dpa, clause 4, and /privacy, clause 2.
Is location of minors tracked?No. Presence comes from zone check-in events only; a live location is never collected or stored. /privacy, clause 3.
How long is data kept?Every category has a published period at /retention. Safety records roll on 30 days; an organization's world is deleted 90 days after its term.
How is data deleted?Revoking a participant deletes in full cascade; an organization can require immediate deletion at any time, confirmed in writing. /dpa, clause 11.
What are the security measures?Row-level security, TLS, encryption at rest, MFA on production, daily backups with tested restores. Full list at /security.
What happens after a breach?You are told within 24 hours of us becoming aware, with scope and measures, so your own 72-hour duty is workable. /dpa, clause 10.
Do you hold SOC 2 or ISO 27001?No, and we say so rather than imply it. What exists instead is at /security, clause 9.
How do data subject requests work?Most are handled by your director in the cabinet immediately; we assist within two business days. Procedure at /rights.
Are minors' rules documented?Yes, in a document of their own at /children, including consent, contact rules, photos and moderation.
Is the product accessible?Target WCAG 2.2 AA, self-assessed, with known gaps listed at /accessibility.
Do you keep an Art. 30 record?Yes, published in full at /ropa. Your own Art. 30(1) record can copy from it.
Have you assessed the transfers after Schrems II?Yes, the transfer impact assessment is at /transfers, per recipient, with the supplementary measures.
Is there a DPIA we can use?A DPIA starter written from the processor side is at /dpia, with a risk and measure table to adapt.
What if your company stops or you are unavailable?Full export on request within five business days, 90 days' notice on wind-down, and a custodian arrangement. All of it at /continuity.
Are there rules for the participants themselves?Yes, in plain language at /participants, which doubles as the end-user terms in the app.

Availability

We target 99.5% monthly availability outside announced maintenance, announce downtime 48 hours ahead, and publish incidents to affected organizations with a written post-mortem. There is no status-page theatre: with one operator, a mail from a human is faster and more honest than a dashboard.

Who to write to

One person answers all three, on Belgian business days, within one day.

Issued by

FND (Find 'n Do)

Belgium

Supervisory authority

Gegevensbeschermingsautoriteit / Autorité de protection des données

www.gegevensbeschermingsautoriteit.be

Write to us

fnd.meet@gmail.com