Data Processing Agreement
Last updated: October 5, 2026
This Data Processing Agreement (the “Agreement”) forms part of the Terms of Use of the AlmightyPush service (the “Service”) and applies from the moment a customer connects the Service to its website until the customer’s data is finally deleted. It governs the processing of personal data that we carry out on behalf of the customer, in accordance with Art. 28 GDPR.
1. Parties and roles
The customer — the owner of a project in the Service — is the controller. The processor is a private individual developing the AlmightyPush Service, based in Ukraine (“we”). Processor contact: support@pushmyinfo.site.
2. Description of processing
| Subject matter and purpose | Collecting browser push notification subscriptions on the customer’s websites, sending notifications, selecting recipients by the customer’s criteria, recording impressions, clicks and visits, statistics. |
|---|---|
| Nature of processing | Collection, recording, storage, organisation, use, transmission to browser push services for delivery, erasure. |
| Data subjects | Visitors and subscribers of the customer’s websites. |
| Categories of data | Listed in section 4 of the Privacy Policy: identifiers and subscription address, subscription source, IP-based location and last IP address, browser and device details, language and time zone, notification events. |
| Special categories | Not processed. The customer does not submit them to the Service, including in labels and notification texts. |
| Duration | For as long as the customer uses the Service, with the retention periods in section 4.3 of the Privacy Policy. |
3. Customer instructions
We process data only on the customer’s documented instructions. Instructions consist of the Terms of Use, this Agreement, and the customer’s settings and actions in the dashboard and via the API. If, in our opinion, an instruction infringes applicable data protection law, we will inform the customer. If the law requires us to process data otherwise, we will inform the customer in advance unless the law prohibits it.
4. Confidentiality
Access to customer data is limited to persons who need it to operate the Service and who are bound by confidentiality obligations.
5. Security
We apply measures appropriate to the risk (Art. 32 GDPR): encryption in transit, encryption of sending keys and secrets, secure password storage, access control within a project, isolation of data between projects, activity logging, two-factor authentication for dashboard users and regular backups.
6. Sub-processors
The customer grants a general authorisation to engage sub-processors. Their list, processing locations and transfer mechanisms are set out in section 5 of the Privacy Policy. We will notify the customer of a new sub-processor by email at least 30 days in advance. If the customer has reasonable grounds to object, it may stop using the Service before the change takes effect. Each sub-processor is bound by a contract with data protection obligations no less protective than this Agreement, and we remain liable to the customer for its performance.
7. Assistance
We assist the customer in responding to data subject requests: the dashboard provides a subscriber card, and we delete a specific subscriber’s data at the customer’s request. If a data subject contacts us directly, we will forward the request to the customer. Within reason, we assist the customer with data protection impact assessments and prior consultations with a supervisory authority.
8. Incidents
We will notify the customer of a personal data breach affecting its data without undue delay and no later than 48 hours after becoming aware of it, and provide the information known to us that the customer needs to notify the supervisory authority and data subjects.
9. Deletion
When the customer deletes a project, processing stops immediately. For 30 days the project can be restored at the customer’s request, after which the data is deleted; it disappears from backups within 14 days. The Service does not disclose subscription addresses or encryption keys, so returning data in that form is not provided; statistics available to the customer remain in the dashboard until the project is deleted.
10. Audits
We make available to the customer the information necessary to demonstrate compliance with this Agreement. Where that information is insufficient, the customer may conduct an on-site audit upon a reasoned request, no more than once a year, with at least 30 days’ notice, at its own cost and subject to confidentiality.
11. Transfers from the EEA
The processor is based in Ukraine. Where the customer is established in the European Economic Area or is subject to the GDPR, transfers are governed by the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this Agreement by reference. The customer is the data exporter and we are the data importer; their annexes are completed with the information in sections 2, 5 and 6 of this Agreement; the law and courts of the EU Member State where the customer is established apply. Onward transfers to sub-processors rely on the mechanisms set out in the Privacy Policy.
12. Order of precedence
In case of conflict, the standard contractual clauses prevail over this Agreement, and this Agreement prevails over the Terms of Use as regards data protection.