VERSION 3.0 · UAE-BASED B2B SAAS · LAST UPDATED: JULY 27, 2026
This policy explains how Pushouse L.L.C-FZ ("Pushouse", "we"), a company established in the United Arab Emirates, processes personal data for its own purposes through www.pushouse.com and the Pushouse B2B SaaS platform. The UAE PDPL and, where applicable, the GDPR, Türkiye's Law No. 6698 (KVKK) and other mandatory privacy laws are considered together.
Pushouse services are offered to businesses. The customer relationship is formed through online registration, subscription and electronic acceptance; the absence of a separate wet-ink or external agreement does not change the data roles explained in this policy.
This policy primarily covers:
End-user data from our customers' stores
When a customer sends its e-commerce store end-user data to Pushouse, the customer generally determines the purposes and legal bases. The customer is the controller and Pushouse acts as its processor under documented instructions. End users should first consult the relevant store's privacy notice; this policy does not replace the store's own transparency obligations.
Legal name: Pushouse L.L.C-FZ
Licence number: 2540189.01
Tax registration number: 105300073100001
Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Privacy contact: [email protected]
Our role depends on the processing context:
| Category | Examples | Purposes | Primary basis |
|---|---|---|---|
| Identity and business details | Name, company, role and country | Establish the business relationship, authorize users and communicate with the organization | Contract/pre-contract steps, legitimate interests and legal obligations where required |
| Contact and request data | Business email, phone, message, demo or meeting details | Respond to requests, schedule demos, and manage sales and support follow-up | Steps at your request, contract performance and legitimate interests |
| Account and service use | Account ID, session, integration, API and support records | Provide the SaaS service, secure accounts, troubleshoot and prevent abuse | Contract performance and legitimate interests in network and service security |
| Technical and online use | IP, browser, device, browser language/locale, page/event data and cookie choices | Deliver and localize the site, security, performance and permitted analytics | Legitimate interests for necessary processing; consent where required for non-essential cookies/analytics |
| Marketing preferences | Channel preference, consent/opt-out time and related records | Send requested newsletters and marketing and demonstrate respect for choices | Separate optional consent/permission or legitimate interests only where the applicable law permits |
| Commercial, billing and transaction | Plan, subscription, invoice and payment references; correspondence and audit records | Subscription management, accounting, disputes and compliance | Contract performance, legal obligation and establishment, exercise or defense of legal claims |
The lawful basis is determined separately for each data flow and applicable regime. GDPR Article 6, KVKK Article 5 and UAE PDPL conditions are not interchangeable even when similar labels are used; a basis valid under one regime does not automatically satisfy another.
Data may be disclosed, only as needed for the stated purposes, to the following categories acting in their relevant processor/service provider roles:
Pushouse is a foreign company headquartered in the UAE. Website, form and account data may therefore be transferred to the UAE and, depending on the provider's configuration, processed in or accessed from other service regions. Exact provider locations and subprocessors may change over time.
Depending on applicable law, transfers use adequacy decisions, contractual and technical safeguards, GDPR Chapter V standard contractual clauses, the post-2024 safeguards under KVKK Article 9, or statutory derogations only when their conditions are met. This policy is not itself a transfer consent or standard contract.
We process Customer Data under the online service and data processing terms, the customer's configuration and documented instructions. The absence of a separate wet-ink agreement does not remove the customer's controller obligations or Pushouse's duty to follow instructions as processor.
We retain data only for the stated purposes, the online service relationship, security needs and applicable legal periods. A single fixed period does not apply to every record.
We apply technical and organizational measures proportionate to risk, data type and service context. Where appropriate, these include:
No internet transmission or storage method is completely secure. This policy does not claim that we hold a particular certification or that a security incident can never occur.
Our website and business accounts are not directed to children, and we do not intend to knowingly collect children's data through these channels. If a customer sends children's data to the service, that customer is responsible for the appropriate legal basis, notice and age-related rules.
Some SaaS features may support analysis, segmentation or content under a customer's instructions. We do not envisage making decisions about website visitors, demo contacts or account representatives that produce legal or similarly significant effects based solely on automated processing. We will provide further information on scope, legal basis and rights before any materially different use.
Depending on your location and the processing context, some or all of the following rights may apply under the UAE PDPL, GDPR, KVKK or other mandatory law:
If your request concerns data held in a Pushouse customer's store, contacting that store as controller is usually the fastest route. We will coordinate with the customer when required.
Send your request from the email address registered to your account or previously provided to us to [email protected], by securely electronically signed document, or in writing to the Dubai address above. Any published local representative or additional statutory channel may also be used.
To prevent unauthorized disclosure, we may request identity and authority information proportionate to your request. Do not send a full identity-document copy unless specifically requested; redact unrelated fields when appropriate.
We respond within applicable periods: requests under KVKK within no more than 30 days, and requests under the GDPR generally within one month, subject to lawful extension conditions. Requests are free unless an exceptional fee is permitted by law.
Where available, you may complain to Türkiye's Personal Data Protection Authority, the relevant EEA supervisory authority or the competent UAE data protection authority if you are dissatisfied with our response.
We may update this policy when our services, providers or laws change. The current version is published on this page with its effective date.
For changes that materially affect your rights or use of data, we will use additional notice such as an account message or email where reasonable and practicable.
Effective and last updated: July 27, 2026.