B2B SaaS · Electronic agreement

Data Processing Addendum (DPA)

Version 3.0Effective: 27 July 2026

1. Parties, scope and electronic acceptance

This Data Processing Addendum (“DPA”) is between Pushouse L.L.C-FZ, licence no. 2540189.01, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates (“Pushouse”) and the customer that electronically accepts the Pushouse Terms of Service on behalf of a business (“Customer”).

This DPA forms an integral part of the Terms. Customer’s affirmative electronic acceptance of the Terms in the registration or subscription flow also accepts and executes this DPA as a written agreement. Silence or continued use alone does not replace that initial acceptance. No wet-ink, paper or separate side agreement is signed for routine SaaS use.

Any law that mandatorily requires a specific cross-border transfer instrument or regulatory filing remains applicable; electronic acceptance does not waive those official formalities.

2. Roles and processing instructions

“Customer Personal Data” means personal data included in Customer Data that Customer or its authorised users submit to, generate through or cause Pushouse to process through the Services on Customer’s behalf in Pushouse’s processor or subprocessor role. It excludes limited account, billing, security and compliance data for which Pushouse acts as an independent controller.

For Customer Personal Data, Customer is a controller or a processor acting for another controller, and Pushouse is a processor or subprocessor, as applicable. Pushouse processes that data only under the Terms, Customer’s Service configuration, support requests and legally binding documented instructions.

Pushouse may act as an independent controller for limited account administration, billing, fraud and abuse prevention, security of its own Services and compliance data. Those activities are described in the Privacy Policy.

3. Processing details

ItemDetails
Subject matter and purposeE-commerce integrations, messaging automation through WhatsApp and other enabled channels, segmentation, campaigns, analytics, reporting, support, security and Customer-enabled AI features.
DurationThe subscription term plus a limited transition period for export/deletion, mandatory retention and rolling backup overwrite.
Data subjectsCustomer personnel and users; Customer store visitors, buyers, prospects, message recipients and support users.
Data categoriesIdentity and contact data; order, transaction and product data; campaign, preference and consent records; message content and interactions; device, log and usage data; Customer-uploaded content.
OperationsCollection, recording, organisation, matching, segmentation, querying, analysis, message transmission, access, hosting, transfer, export, erasure and anonymisation.

Customer must not upload special-category/sensitive data, card verification codes, health data or children’s data unless the Service is expressly configured and approved for that purpose.

4. Customer obligations

  • Ensure that its data and instructions are lawful and provide all required notices, permissions and marketing-message consents.
  • Maintain evidence of the source, lawful basis and channel-specific consent for recipients and contact lists.
  • Transfer only necessary data and obtain Pushouse product approval before any special-category or high-risk processing.
  • Keep permissions current, use strong authentication and manage data-subject requests in its controller role.
  • Comply with WhatsApp/Meta and other enabled channel-provider rules.

5. Pushouse obligations

  • Process personal data only on documented instructions unless law requires otherwise, in which case Pushouse will notify Customer where permitted.
  • If Pushouse considers that a documented instruction infringes applicable data-protection law, it will immediately inform Customer unless legally prohibited and may suspend only the affected processing until the instruction is clarified or corrected.
  • Bind authorised personnel to confidentiality and limit access according to job need.
  • Apply technical and organisational measures appropriate to the nature and risk of processing.
  • Provide reasonable assistance with data-subject requests, impact assessments, regulator consultations and breach notifications.
  • Provide information necessary to demonstrate compliance and support reasonable audits within this DPA’s limits.

6. Security schedule and incident notice

This section is the DPA security schedule referenced in the Terms. Pushouse applies technical and organisational measures appropriate to the nature, scope, context and risk of processing and the enabled Service configuration across the control areas below.

After becoming aware of a personal data breach concerning Customer Personal Data, Pushouse will notify Customer without undue delay and provide available details about the nature, likely impact, mitigation and contact point. If all information is not available with the initial notice, Pushouse will provide further information without undue delay as it becomes available. Customer, as controller, decides on notifications to authorities or individuals; Pushouse provides reasonable assistance.

  • Role- and need-based access, authentication, access reviews and privileged-access restrictions.
  • Current industry-standard encryption in transit and, where appropriate, at rest.
  • Logical separation of Customer environments, data minimisation, retention lifecycle and controlled-deletion processes.
  • Logging and monitoring of security-relevant access and events, with protection against unauthorised alteration.
  • Backup, recovery, business-continuity and periodic review of restoration readiness.
  • Vulnerability, patch, change-management and secure-development processes.
  • Vendor-risk review; personnel confidentiality and need-to-know access; security-incident response processes.

7. Subprocessors

Customer grants general authorisation for subprocessors needed to provide the Services. The current list is published on the Subprocessors page. Pushouse will provide electronic notice at least 15 days before any subprocessor that will access Customer Personal Data is added or replaced, giving Customer an opportunity to object within that period.

Customer may object within that period only on documented data-protection grounds. The parties will seek a reasonable solution; if none is available, Customer may disable the affected feature or terminate under the Terms. Pushouse imposes materially equivalent protection obligations and remains responsible for its own obligations.

8. International transfers

The Services may use global infrastructure and providers. To the extent GDPR applies, Pushouse will rely on an applicable adequacy decision or appropriate safeguards such as the European Commission standard contractual clauses; to the extent Turkish Law No. 6698 applies, the current Article 9 adequacy, appropriate-safeguard or incidental-transfer conditions apply; and UAE PDPL transfer requirements apply where relevant.

Where required, the parties will reasonably cooperate to complete the official transfer instrument, correct role module, annexes and mandatory regulatory filing.

Where a Turkish KVKK standard contract is required, only the permitted selections in the official text are completed; the Turkish copy, authorised signatures, signature dates and authority documents are supplied, and the contract is notified to the Authority within five business days after signature. This statutory transfer instrument is not a customer-specific external commercial services agreement; it is a mandatory safeguard that the routine online DPA cannot waive.

9. Return, deletion and backups

On termination, Customer may choose return of Customer Personal Data in an available standard format or deletion. If Customer does not state a choice, Pushouse will delete the data. Except for records whose retention is legally required, Pushouse will implement that choice as technically practicable and in all cases within 90 days; if return is chosen, Pushouse will then delete existing copies. At Customer’s written request, Pushouse will certify completion of the return and/or deletion in writing or electronically. Copies in rolling backups remain isolated until ordinary overwrite, are not restored for production use and remain subject to the same protections.

10. Audit, precedence and liability

Pushouse will first demonstrate compliance through security documentation, available independent reports or questionnaire responses. Additional audits are ordinarily limited to once per year on reasonable notice and must protect continuity and other customers’ confidentiality. The annual limit does not apply following a personal data breach affecting Customer Personal Data, where required by a competent authority, or where Customer has documented reasonable grounds to suspect non-compliance with this DPA.

This DPA prevails over the Terms for personal-data processing. Liability and claim procedures remain governed by the Terms, subject to mandatory data-protection law.

11. Contact

Data-protection and DPA notices may be sent to [email protected]. Publishing this contact does not represent that a statutory data protection officer has been appointed.

This DPA is accepted electronically with the Terms; no separate external or wet-ink agreement is used for routine SaaS subscriptions.