VERSION 3.0 · UAE-BASED B2B SAAS · LAST UPDATED: JULY 27, 2026

Privacy Policy

1. Scope

This policy explains how Pushouse L.L.C-FZ ("Pushouse", "we"), a company established in the United Arab Emirates, processes personal data for its own purposes through www.pushouse.com and the Pushouse B2B SaaS platform. The UAE PDPL and, where applicable, the GDPR, Türkiye's Law No. 6698 (KVKK) and other mandatory privacy laws are considered together.

Pushouse services are offered to businesses. The customer relationship is formed through online registration, subscription and electronic acceptance; the absence of a separate wet-ink or external agreement does not change the data roles explained in this policy.

This policy primarily covers:

  • Website visitors
  • Business contacts who submit a demo, contact or meeting request
  • Customer account representatives, employees and support users
  • Newsletter subscribers and representatives of partners or suppliers

End-user data from our customers' stores

When a customer sends its e-commerce store end-user data to Pushouse, the customer generally determines the purposes and legal bases. The customer is the controller and Pushouse acts as its processor under documented instructions. End users should first consult the relevant store's privacy notice; this policy does not replace the store's own transparency obligations.

2. Our Identity and Data Roles

Legal name: Pushouse L.L.C-FZ

Licence number: 2540189.01

Tax registration number: 105300073100001

Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

Privacy contact: [email protected]

Our role depends on the processing context:

  • Pushouse is a controller for website, demo/contact, our own newsletter, billing and business account administration data.
  • For a customer's store, order, campaign, messaging and end-user data, Pushouse acts as a processor/service provider for that customer; limited processing for security, legal compliance or prevention of service abuse may be described separately.

3. Data, Purposes and Legal Bases

CategoryExamplesPurposesPrimary basis
Identity and business detailsName, company, role and countryEstablish the business relationship, authorize users and communicate with the organizationContract/pre-contract steps, legitimate interests and legal obligations where required
Contact and request dataBusiness email, phone, message, demo or meeting detailsRespond to requests, schedule demos, and manage sales and support follow-upSteps at your request, contract performance and legitimate interests
Account and service useAccount ID, session, integration, API and support recordsProvide the SaaS service, secure accounts, troubleshoot and prevent abuseContract performance and legitimate interests in network and service security
Technical and online useIP, browser, device, browser language/locale, page/event data and cookie choicesDeliver and localize the site, security, performance and permitted analyticsLegitimate interests for necessary processing; consent where required for non-essential cookies/analytics
Marketing preferencesChannel preference, consent/opt-out time and related recordsSend requested newsletters and marketing and demonstrate respect for choicesSeparate optional consent/permission or legitimate interests only where the applicable law permits
Commercial, billing and transactionPlan, subscription, invoice and payment references; correspondence and audit recordsSubscription management, accounting, disputes and complianceContract performance, legal obligation and establishment, exercise or defense of legal claims

4. Data Sources and Legal Framework

We may obtain data:

  • Directly from you through forms, registration, subscription, support, email or meetings
  • From your employer, an account administrator at your company or an authorized partner
  • Automatically from your device, server logs, cookies and similar technologies when you use the site or platform
  • From e-commerce, messaging and other integrations enabled by the customer, only to the extent needed for the relevant service

Depending on the applicable law, our primary legal grounds are:

  • Performance of a contract or steps taken at your request before entering a contract
  • Legitimate interests such as preventing fraud and abuse, network security, managing B2B relationships and improving services, where not overridden by your rights
  • Accounting, tax, lawful authority requests and other legal obligations
  • Establishment, exercise or defense of legal claims
  • Freely given, specific, informed and withdrawable consent/permission where the law requires it

The lawful basis is determined separately for each data flow and applicable regime. GDPR Article 6, KVKK Article 5 and UAE PDPL conditions are not interchangeable even when similar labels are used; a basis valid under one regime does not automatically satisfy another.

5. Service Providers, Recipients and Transfers

Data may be disclosed, only as needed for the stated purposes, to the following categories acting in their relevant processor/service provider roles:

  • Google/Gmail: form responses and business email communications
  • Odoo and Pushouse service systems: lead, business account, support and operations management
  • Brevo: newsletter, preference and message delivery processes only for relevant subscribers
  • Cal.com: meeting scheduling initiated by the user
  • Vercel: site delivery and performance/analytics measurement only after analytics permission
  • Google tags and web resources: delivery of site resources and tag/analytics processing only when the relevant permission is given
  • AWS, hosting, network, security and backup providers and Pushouse service infrastructure
  • Stripe and PayTR: payment, refund, fraud-prevention and transaction-reference processes in the payment flow selected by the Customer; Pushouse does not store full card data in its own systems
  • Authorities, auditors, professional advisers and parties to corporate transactions where legally necessary

International transfers

Pushouse is a foreign company headquartered in the UAE. Website, form and account data may therefore be transferred to the UAE and, depending on the provider's configuration, processed in or accessed from other service regions. Exact provider locations and subprocessors may change over time.

Depending on applicable law, transfers use adequacy decisions, contractual and technical safeguards, GDPR Chapter V standard contractual clauses, the post-2024 safeguards under KVKK Article 9, or statutory derogations only when their conditions are met. This policy is not itself a transfer consent or standard contract.

6. Customer Data and Retention

We process Customer Data under the online service and data processing terms, the customer's configuration and documented instructions. The absence of a separate wet-ink agreement does not remove the customer's controller obligations or Pushouse's duty to follow instructions as processor.

  • The customer is responsible for informing end users and establishing the necessary legal basis and communication permissions.
  • Pushouse processes Customer Data to provide and secure the service and operate features enabled by the customer.
  • If AI-assisted analytics or campaign features are enabled, the customer determines their scope and purpose and must separately assess profiling and automated-decision rules.
  • If an end-user request reaches us, we may direct it to the relevant customer and provide reasonable assistance unless applicable law requires us to respond directly.

Our retention approach

We retain data only for the stated purposes, the online service relationship, security needs and applicable legal periods. A single fixed period does not apply to every record.

  • Demo and contact records: for handling the request, reasonable B2B follow-up and applicable dispute limitation periods
  • Account, subscription, invoice and support records: during the service relationship and for applicable accounting, tax and limitation periods afterward
  • Marketing data: until permission is withdrawn or the purpose ends; consent/opt-out evidence for the legally required period
  • Technical logs, cookies and backups: for security and operations and for periods stated in the Cookie Policy, then deleted, anonymized or overwritten in the backup cycle

7. Security, Children and AI

We apply technical and organizational measures proportionate to risk, data type and service context. Where appropriate, these include:

  • Transmission security and appropriate storage protections
  • Role- and need-based access restrictions and authentication controls
  • Logging, monitoring, backup and change management
  • Supplier review, confidentiality obligations and personnel awareness
  • Incident response, business continuity and required notification processes

No internet transmission or storage method is completely secure. This policy does not claim that we hold a particular certification or that a security incident can never occur.

Children

Our website and business accounts are not directed to children, and we do not intend to knowingly collect children's data through these channels. If a customer sends children's data to the service, that customer is responsible for the appropriate legal basis, notice and age-related rules.

AI and automated assessment

Some SaaS features may support analysis, segmentation or content under a customer's instructions. We do not envisage making decisions about website visitors, demo contacts or account representatives that produce legal or similarly significant effects based solely on automated processing. We will provide further information on scope, legal basis and rights before any materially different use.

8. Your Rights

Depending on your location and the processing context, some or all of the following rights may apply under the UAE PDPL, GDPR, KVKK or other mandatory law:

  • Ask whether we process your data and request access
  • Request information about purposes, sources, recipients and transfer safeguards
  • Correct inaccurate or incomplete data
  • Request deletion or restriction where the legal conditions are met
  • Object to legitimate-interest processing and direct marketing
  • Withdraw consent prospectively; withdrawal does not affect prior lawful processing
  • Data portability and protections relating to solely automated decisions where applicable

If your request concerns data held in a Pushouse customer's store, contacting that store as controller is usually the fastest route. We will coordinate with the customer when required.

9. Privacy Requests and Complaints

Send your request from the email address registered to your account or previously provided to us to [email protected], by securely electronically signed document, or in writing to the Dubai address above. Any published local representative or additional statutory channel may also be used.

To prevent unauthorized disclosure, we may request identity and authority information proportionate to your request. Do not send a full identity-document copy unless specifically requested; redact unrelated fields when appropriate.

We respond within applicable periods: requests under KVKK within no more than 30 days, and requests under the GDPR generally within one month, subject to lawful extension conditions. Requests are free unless an exceptional fee is permitted by law.

Where available, you may complain to Türkiye's Personal Data Protection Authority, the relevant EEA supervisory authority or the competent UAE data protection authority if you are dissatisfied with our response.

10. Policy Changes

We may update this policy when our services, providers or laws change. The current version is published on this page with its effective date.

For changes that materially affect your rights or use of data, we will use additional notice such as an account message or email where reasonable and practicable.

Effective and last updated: July 27, 2026.