Pushferry

Data processing addendum

Effective 5 September 2026

This Addendum forms part of the Pushferry Terms of service and applies where you (“Customer”, the controller) use the Service to process personal data of third parties — typically the phone numbers and message content of people who message your phone — and the GDPR, the UK GDPR or similar law applies. Pushferry (“Processor”) processes that data only on your behalf.

About the operator. Pushferry is currently operated as an independent service reachable at hello@pushferry.com, with its servers in Frankfurt, Germany. The registered company details and the governing law for paid subscriptions are being finalised and will be published on this page, with the effective date, before paid plans open. Until then this document describes how the service actually handles your data and what we undertake to do — which is the part that binds our behaviour today.

1. Subject matter, duration, nature and purpose

Processing consists of receiving message metadata and, transiently, message content from the Customer's Android phone and delivering it to destinations the Customer configured; and sending SMS on the Customer's instruction. It lasts for the term of the Customer's account. The purpose is the operation of the Service as described in the Terms.

2. Categories of data and data subjects

3. Processor obligations (Art. 28(3) GDPR)

The Processor shall:

4. Sub-processors

The Customer authorises the sub-processors listed in the Privacy policy. The Processor will notify the Customer of any intended addition or replacement at least 14 days in advance; the Customer may object on reasonable grounds, in which case the parties will work in good faith to resolve the objection, failing which the Customer may terminate the affected part of the Service.

5. International transfers

Primary processing takes place in the European Union (Germany). Where a sub-processor is outside the EU/EEA, transfers rely on the EU Standard Contractual Clauses (Decision 2021/914) or another valid mechanism.

6. Personal data breach

The Processor will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, with the information reasonably available at that time.

7. Liability

Each party's liability under this Addendum is subject to the limitations in the Terms, except where the law does not allow such limitation.

Annex 1 — Technical and organisational measures

Annex 2 — Sub-processors

As listed in the Privacy policy at the date of this Addendum.