Data processing addendum
Effective 5 September 2026
This Addendum forms part of the Pushferry Terms of service and applies where you (“Customer”, the controller) use the Service to process personal data of third parties — typically the phone numbers and message content of people who message your phone — and the GDPR, the UK GDPR or similar law applies. Pushferry (“Processor”) processes that data only on your behalf.
About the operator. Pushferry is currently operated as an independent service reachable at hello@pushferry.com, with its servers in Frankfurt, Germany. The registered company details and the governing law for paid subscriptions are being finalised and will be published on this page, with the effective date, before paid plans open. Until then this document describes how the service actually handles your data and what we undertake to do — which is the part that binds our behaviour today.
1. Subject matter, duration, nature and purpose
Processing consists of receiving message metadata and, transiently, message content from the Customer's Android phone and delivering it to destinations the Customer configured; and sending SMS on the Customer's instruction. It lasts for the term of the Customer's account. The purpose is the operation of the Service as described in the Terms.
2. Categories of data and data subjects
- Data subjects: people who send messages to, or receive messages from, the Customer's phone; the Customer's staff who use the dashboard.
- Data: phone numbers and sender identifiers; message timestamps and delivery outcome; message text, transiently only, for messages sent through the API, received, or forwarded (the Customer's own dashboard Send page is the one exception — text composed and sent there is stored, since the Customer typed it directly into the Service's own website rather than through the API or the Customer's phone); destination identifiers configured by the Customer.
3. Processor obligations (Art. 28(3) GDPR)
The Processor shall:
- process personal data only on the Customer's documented instructions, which are given through the Customer's configuration of the Service;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex 1;
- engage sub-processors only under §4;
- assist the Customer in responding to data-subject requests, taking into account the nature of the processing;
- assist with the Customer's security, breach-notification and impact-assessment obligations, to the extent information is available to the Processor;
- delete or return personal data at the end of the Service, at the Customer's choice, and delete existing copies unless law requires retention;
- make available the information necessary to demonstrate compliance and allow audits, by way of written responses and, where reasonably required, on-site review at the Customer's expense with 30 days' notice, no more than once a year.
4. Sub-processors
The Customer authorises the sub-processors listed in the Privacy policy. The Processor will notify the Customer of any intended addition or replacement at least 14 days in advance; the Customer may object on reasonable grounds, in which case the parties will work in good faith to resolve the objection, failing which the Customer may terminate the affected part of the Service.
5. International transfers
Primary processing takes place in the European Union (Germany). Where a sub-processor is outside the EU/EEA, transfers rely on the EU Standard Contractual Clauses (Decision 2021/914) or another valid mechanism.
6. Personal data breach
The Processor will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, with the information reasonably available at that time.
7. Liability
Each party's liability under this Addendum is subject to the limitations in the Terms, except where the law does not allow such limitation.
Annex 1 — Technical and organisational measures
- No persistent storage of message content sent through the API, received, or forwarded. Text is held in memory only for delivery and is never written to database, disk logs or backups for that traffic. This is the single most important measure and is enforced by design. The one exception is the Customer's own dashboard Send page, described above.
- Encryption in transit (TLS 1.2+) for all connections: phone ↔ server, server ↔ destinations, dashboard.
- Encryption at rest for the database volume.
- Access to production restricted to named individuals with key-based authentication; no shared passwords.
- Separate production environment for EU customers; no mixing with other products' data.
- Daily encrypted database backups (metadata only), retained 14 days.
- Server logs exclude message content and are retained 30 days.
- Secrets held in environment configuration, not in code.
Annex 2 — Sub-processors
As listed in the Privacy policy at the date of this Addendum.