pushouse

VERSION 3.0 · UAE-BASED B2B SAAS · LAST UPDATED: JULY 27, 2026

Website, Lead and Business Account Data Notice

1. Controller

Legal name: Pushouse L.L.C-FZ

Licence number: 2540189.01

Tax registration number: 105300073100001

Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

Privacy contact: [email protected]

Pushouse is a foreign B2B SaaS company established in the United Arab Emirates. It acts as controller for the direct website, lead and business-account processing described in this notice. Mandatory local laws, including the GDPR and Türkiye's KVKK where their territorial requirements are met, may also apply.

2. Scope, Purposes and Data Roles

This notice covers the following direct Pushouse processes:

  • Delivering and securing the website, country/language localization and permitted performance analytics
  • Receiving, responding to and following up B2B demo, contact and meeting requests
  • Creating and authorizing business accounts and providing, supporting and billing for the SaaS service
  • Sending newsletters or marketing and managing choices only where separate optional permission has been given

Controller and processor distinction

Pushouse is controller for website visitors, demo/contact persons, newsletter subscribers and customer account representatives in the direct processes above.

For end-user order, contact, behavior and campaign data from a customer's e-commerce store, the customer is controller and Pushouse acts as its processor. The customer relationship is formed through online subscription and electronic acceptance; no separate wet-ink agreement is required for this role allocation.

This is not the privacy notice for our customers' store end users. End users should consult the relevant store's privacy notice for that store's purposes, legal bases and rights process.

3. Data Categories

CategoryExamplesProcessing purposes
Identity and businessName, company, role/title and countryManage the request and business relationship and verify account authority
Contact and requestBusiness email, phone, message, demo and meeting detailsRespond, schedule meetings and manage sales/support follow-up
Account and customer transactionAccount ID, subscription/plan, invoice and payment references, support historyProvide the SaaS service, billing, account management and legal records
Technical and securityIP, browser/device, session, server and error logsDeliver the site/service, security, troubleshooting and abuse prevention
Locale and online useBrowser language/locale, page/event data, cookies and preferencesAdaptation to browser locale, cookie choices, and permitted performance/analytics
Marketing preferenceSelected channel, consent/opt-out time and evidenceNewsletter/marketing delivery, honoring preferences and demonstrating permission

4. Collection and Legal Bases

Collection methods

  • Electronically through contact, demo, meeting, newsletter, registration, account and support forms
  • Through email, online meetings and support communications
  • Automatically from the device, server logs, cookies and similar technologies during website/platform use
  • From your employer, company account administrator or authorized partner

Primary legal bases under applicable law

  • Contract performance or steps at your request: accounts, subscription, support and pre-contract requests
  • Legal obligation: accounting, tax, lawful authority and compliance records
  • Establishment, exercise or defense of legal claims: dispute, request and audit records
  • Legitimate interests not overridden by your rights: B2B follow-up, site/network security, fraud and abuse prevention
  • Consent/permission where required: non-essential analytics/cookies and optional marketing

Providing this notice or confirming that it was read is not consent. Where consent or marketing permission is required, it is requested as a separate, specific and optional choice and must not be made a condition of submitting a demo or contact request.

5. Recipients and International Transfers

Data may be transferred, only as needed for the stated purposes, to these recipient/service provider categories:

  • Google/Gmail: form responses and business email communications
  • Odoo and Pushouse service systems: lead, account, sales, support and operations management
  • Brevo: subscription, preference and delivery operations only for relevant newsletter subscribers
  • Cal.com: meeting scheduling initiated by you
  • Vercel: site delivery and performance/analytics measurement only after analytics permission
  • Google tags and web resources: delivery of site resources and tag/analytics processing only when the relevant permission is given
  • AWS, hosting, network, security and backup providers and Pushouse service infrastructure
  • Stripe and PayTR: payment, refund, fraud-prevention and transaction-reference processes in the payment flow selected by the Customer; Pushouse does not store full card data in its own systems
  • Authorities, courts, auditors and professional advisers where legally required

Nature of international transfers

Pushouse is headquartered in the UAE, so data in this notice may be transmitted to the UAE and, depending on provider configuration, processed in other service regions. A provider's name alone does not mean all its processing occurs in one country.

Where the GDPR applies, transfers use adequacy decisions, standard contractual clauses or other Chapter V mechanisms. Where Türkiye's KVKK applies, the post-2024 Article 9 framework may require an adequacy decision, notified standard contract, binding corporate rules, an authorized undertaking or a statutory occasional-transfer condition. UAE PDPL cross-border requirements are applied where relevant. This notice is not itself consent or a transfer agreement.

6. Retention and Security

Retention criteria

We retain personal data while needed for the stated purpose, the online service relationship, or applicable legal, evidence and limitation periods. One fixed period does not apply to every category.

  • Demo/contact records: while handling the request, reasonable B2B follow-up and applicable dispute limitation periods
  • Account, subscription, invoice and support records: during the service relationship and required accounting, tax and limitation periods afterward
  • Marketing data: until permission is withdrawn or the purpose ends; permission/opt-out evidence for the legally required period
  • Technical logs, cookies and backups: for security and operational periods and the periods in the Cookie Policy, then deleted, anonymized or overwritten in the backup cycle

Security measures

We apply measures proportionate to the risk and data type. Where appropriate, these include:

  • Transmission and storage security and secure configuration
  • Role- and need-based access, authentication and access records
  • Logging, monitoring, backup, incident response and business continuity
  • Supplier review, confidentiality obligations and personnel awareness

No system can guarantee absolute security. This notice does not claim that Pushouse holds any particular ISO, SOC or other certification.

7. Rights and Requests

Depending on the law that applies to your circumstances, you may have rights to:

  • Ask whether we process your data and request access.
  • Learn the purposes, sources, recipients and use of your data.
  • Request correction of inaccurate or incomplete data.
  • Request deletion, destruction or restriction where legal conditions are met.
  • Object to legitimate-interest processing, direct marketing or qualifying automated decisions.
  • Withdraw consent prospectively and request portability where applicable.
  • Seek a remedy or compensation where provided by applicable law.

How to submit a request

Send your request from the email registered to your account or previously provided to us to [email protected], by securely electronically signed document, or in writing to the Dubai address above. Any later-published local representative or statutory channel may also be used.

State your name, contact details, request and any customer/account relationship. We may request proportionate identity or authority verification. Do not send a full identity-document copy unless specifically requested; redact unrelated fields where appropriate.

We respond within the period applicable to you: generally one month under the GDPR, no more than 30 days under KVKK, and the relevant period under UAE PDPL, subject to lawful extension or fee rules.

Where available, you may complain to the relevant EEA supervisory authority, Türkiye's Personal Data Protection Authority or the competent UAE data protection authority.

8. Special Topics

Notice and consent

This notice provides information; it is not a contract or consent declaration. Withdrawing consent does not affect processing lawfully completed before withdrawal or processing based on another valid legal ground.

Cookies and similar technologies

We seek a prior choice for non-essential analytics or marketing technologies where required. Provider, purpose and duration information is presented in the Cookie Policy, and category choices are presented in the preference center.

Children

The website, demo and business account processes are not directed to children, and we do not intend to knowingly collect children's data through these channels.

AI and profiling

We do not envisage decisions about website visitors, demo contacts or account representatives producing legal or similarly significant effects based solely on automated processing. For AI/segmentation features enabled by a customer, that customer must assess legal basis, notice and appropriate human oversight as controller.

9. Updates

We may update this notice when our data flows or applicable laws change. The current notice is published on this page with its effective date.

For changes that materially affect rights or use of data, we will provide additional notice where reasonable and practicable.

Effective and last updated: July 27, 2026.