Privacy Policy
Effective Date: April 28, 2026
Flying Dynamite Sp. z o.o. (“Push0”, “we”, “us” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our website (push0.com), dashboard, API, SDK, and related services (collectively, the “Services”).
1. Controller and Contact Details
The controller of your personal data is:
Flying Dynamite Sp. z o.o.
ul. Andersa 15/306a, 41-200 Sosnowiec, Poland
KRS: 0001090841
Email: [email protected]
We have appointed a Data Protection Officer (DPO), who can be contacted at: [email protected]
2. Categories of Personal Data We Process
We process the following categories of personal data:
A. Customer Account Data (you as our client):
- Name, email address, company name, billing information
- Account credentials and usage logs
- Payment information (processed by our payment provider)
B. End-User Data (processed on behalf of our customers):
- Device tokens / registration tokens
- Push notification content and metadata
- Interaction data (e.g., delivery status, opens, clicks – if tracking enabled)
- IP addresses and technical data necessary for delivery and analytics
C. Website and Service Usage Data:
- IP address, browser type, device information
- Cookies and similar tracking technologies
- Usage statistics and analytics
3. Purposes and Legal Basis for Processing
We process personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing and managing the Services (including sending push notifications) | Contract performance (Art. 6(1)(b) GDPR) |
| Account creation, authentication and support | Contract performance |
| Billing and payment processing | Contract performance + Legal obligation |
| Improving our Services and analytics | Legitimate interests (Art. 6(1)(f) GDPR) |
| Sending marketing communications | Consent or Legitimate interests |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Establishing, exercising or defending legal claims | Legitimate interests |
When we act as a Processor (processing end-user data on behalf of our customers), we process such data solely on the documented instructions of the customer (Controller) and in accordance with our Data Processing Agreement (DPA).
4. Sharing and Disclosure of Personal Data
We may share personal data with:
- Sub-processors: Our trusted service providers who process data on our behalf (e.g., cloud hosting providers, payment processors like Stripe, analytics tools, email service providers). A current list of sub-processors is available upon request.
- Legal obligations: When required by law, court order, or governmental authority.
- Business transfers: In the event of a merger, acquisition, or sale of assets.
We do not sell personal data to third parties.
5. International Data Transfers
Some of our sub-processors are located outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, primarily through the EU Standard Contractual Clauses (SCCs) or other valid transfer mechanisms approved by the European Commission.
6. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected:
- Account data: for the duration of the contractual relationship + up to 6 years for legal claims (or longer if required by law).
- Device tokens and notification data: for the duration of the Service + a limited period after termination (usually up to 90 days), unless longer retention is instructed by the customer.
- Marketing data: until consent is withdrawn.
7. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object to processing (including for direct marketing and profiling)
- Right to withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, please contact us at [email protected] or [email protected].
You also have the right to lodge a complaint with the Polish supervisory authority (President of the Personal Data Protection Office – UODO).
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the website, analyze usage, and improve our Services. For detailed information, please see our Cookie Policy [link – do dodania].
9. Children’s Privacy
Our Services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the “Effective Date”.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
DPO: [email protected]
Flying Dynamite Sp. z o.o.
ul. Andersa 15/306a, 41-200 Sosnowiec, Poland
