Data Processing Addendum.
For customers who are controllers of their own end-users' data. It sets out what we may do with that data — which is only what you tell us to.
Effective 10 October 2026. These terms take effect when OpenPush opens to the public. They are published now so you can read them before deciding whether to sign up, and so any change between now and then is visible rather than sprung on you. If you need contractual certainty sooner, email legal@openpush.ai and we will deal with you directly.
Who is who
When you use OpenPush to reach your users, you are the controller of your users' personal data and SuperTuned Inc is your processor. You decide who gets a notification and why; we operate the machinery that delivers it. This addendum forms part of the Terms of Service.
Separately, we are a controller of your own account and usage data — the person who signed up, billing details, how you use the dashboard. That is covered by the Privacy Policy, not by this addendum. Keeping those two roles apart is the whole point of this document.
What we process for you
| Subject matter | Detail |
|---|---|
| Categories of data subject | Your end users — the people who installed your app or subscribed on your site. |
| Categories of personal data | Push tokens and device identifiers, the external ID or alias you assign, tags and attributes you set, language and timezone, subscription status, and delivery events. |
| Special category data | None. OpenPush is not designed for it and you should not put it in tags or payloads. |
| Nature and purpose | Storing subscriptions, evaluating the segments you define, delivering notifications via APNs and FCM, and reporting on what happened. |
| Duration | For as long as your account is active, plus the deletion window below. |
We act on your instructions
We process your users' personal data only to provide the service and only as you instruct us — through your configuration, your API calls, and this agreement. We do not use it for our own purposes.
In particular: we do not move your end users' personal data into our other products. Where we build features across our product line, they are built on our own account and usage data, or on data that is aggregated and stripped of identifiers, or on data you have specifically instructed us to use. Nothing in our other agreements grants us a blanket right over data you control.
If we ever believe an instruction from you would breach data protection law, we will tell you rather than quietly comply.
Security
We keep appropriate technical and organisational measures in place, and describe our practices on the security page. Everyone with access to your data is bound by confidentiality.
Subprocessors
We use other vendors to run the service, and they are listed by name on the subprocessors page. You authorise those listed there. We will give notice before adding a new one, and you will have a window to object.
Notably, delivery itself depends on Apple's APNs and Google's FCM. Sending a push means handing the token and payload to one of them; that is inherent to push notifications on any platform, ours included.
International transfers — read this before you sign up
Our infrastructure is in the United States. For transfers out of the EEA we rely on the EU Standard Contractual Clauses, and those are the only mechanism we currently operate.
We are not currently suitable for you if you need a UK IDTA, a Swiss addendum, or the EU–US Data Privacy Framework. We do not have any of the three. If your transfers depend on one of them, OpenPush is not the right choice for you today, and we would rather say so now than have you find out during a data protection review. Email legal@openpush.ai and we will tell you honestly whether that is likely to change on a timescale that suits you.
This costs us sign-ups. We think the honest version is better than the surprise.
Helping you meet your obligations
- Data subject requests. The API lets you find, export and delete an individual subscriber yourself. If you need help, ask and we will help.
- Breach notification. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and with enough detail for you to meet your own reporting deadlines.
- Audits and assessments. We will provide the information you reasonably need for a data protection impact assessment or to demonstrate our compliance.
Deletion and return
On termination you can export everything. After that we delete your data within a defined window, except where we are legally required to keep something — in which case we keep only that, only for as long as required.
Signing this
If your procurement process needs a countersigned DPA, email legal@openpush.ai. We would rather sign your paper than make you argue with ours.
SuperTuned Inc
1 Sansome Street, San Francisco, CA 94104, USA
Privacy: privacy@openpush.ai · Legal: legal@openpush.ai · Security: security@openpush.ai