AlmightyPushРусская версия

Data Processing Agreement

Last updated: October 5, 2026

This Data Processing Agreement (the “Agreement”) forms part of the Terms of Use of the AlmightyPush service (the “Service”) and applies from the moment a customer connects the Service to its website until the customer’s data is finally deleted. It governs the processing of personal data that we carry out on behalf of the customer, in accordance with Art. 28 GDPR.

1. Parties and roles

The customer — the owner of a project in the Service — is the controller. The processor is a private individual developing the AlmightyPush Service, based in Ukraine (“we”). Processor contact: support@pushmyinfo.site.

2. Description of processing

Subject matter and purposeCollecting browser push notification subscriptions on the customer’s websites, sending notifications, selecting recipients by the customer’s criteria, recording impressions, clicks and visits, statistics.
Nature of processingCollection, recording, storage, organisation, use, transmission to browser push services for delivery, erasure.
Data subjectsVisitors and subscribers of the customer’s websites.
Categories of dataListed in section 4 of the Privacy Policy: identifiers and subscription address, subscription source, IP-based location and last IP address, browser and device details, language and time zone, notification events.
Special categoriesNot processed. The customer does not submit them to the Service, including in labels and notification texts.
DurationFor as long as the customer uses the Service, with the retention periods in section 4.3 of the Privacy Policy.

3. Customer instructions

We process data only on the customer’s documented instructions. Instructions consist of the Terms of Use, this Agreement, and the customer’s settings and actions in the dashboard and via the API. If, in our opinion, an instruction infringes applicable data protection law, we will inform the customer. If the law requires us to process data otherwise, we will inform the customer in advance unless the law prohibits it.

4. Confidentiality

Access to customer data is limited to persons who need it to operate the Service and who are bound by confidentiality obligations.

5. Security

We apply measures appropriate to the risk (Art. 32 GDPR): encryption in transit, encryption of sending keys and secrets, secure password storage, access control within a project, isolation of data between projects, activity logging, two-factor authentication for dashboard users and regular backups.

6. Sub-processors

The customer grants a general authorisation to engage sub-processors. Their list, processing locations and transfer mechanisms are set out in section 5 of the Privacy Policy. We will notify the customer of a new sub-processor by email at least 30 days in advance. If the customer has reasonable grounds to object, it may stop using the Service before the change takes effect. Each sub-processor is bound by a contract with data protection obligations no less protective than this Agreement, and we remain liable to the customer for its performance.

7. Assistance

We assist the customer in responding to data subject requests: the dashboard provides a subscriber card, and we delete a specific subscriber’s data at the customer’s request. If a data subject contacts us directly, we will forward the request to the customer. Within reason, we assist the customer with data protection impact assessments and prior consultations with a supervisory authority.

8. Incidents

We will notify the customer of a personal data breach affecting its data without undue delay and no later than 48 hours after becoming aware of it, and provide the information known to us that the customer needs to notify the supervisory authority and data subjects.

9. Deletion

When the customer deletes a project, processing stops immediately. For 30 days the project can be restored at the customer’s request, after which the data is deleted; it disappears from backups within 14 days. The Service does not disclose subscription addresses or encryption keys, so returning data in that form is not provided; statistics available to the customer remain in the dashboard until the project is deleted.

10. Audits

We make available to the customer the information necessary to demonstrate compliance with this Agreement. Where that information is insufficient, the customer may conduct an on-site audit upon a reasoned request, no more than once a year, with at least 30 days’ notice, at its own cost and subject to confidentiality.

11. Transfers from the EEA

The processor is based in Ukraine. Where the customer is established in the European Economic Area or is subject to the GDPR, transfers are governed by the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this Agreement by reference. The customer is the data exporter and we are the data importer; their annexes are completed with the information in sections 2, 5 and 6 of this Agreement; the law and courts of the EU Member State where the customer is established apply. Onward transfers to sub-processors rely on the mechanisms set out in the Privacy Policy.

12. Order of precedence

In case of conflict, the standard contractual clauses prevail over this Agreement, and this Agreement prevails over the Terms of Use as regards data protection.