Legal documents

Data Processing Agreement (DPA)

A supplementary agreement in which the Customer acts as data controller and Bildirim.io as data processor. It forms an integral part of the Terms of Service.

Last updated: 28 July 2026 · Data controller / service provider: Bildirim.io service operator

This English text is an informational translation. The agreement is concluded in Turkish and governed by Turkish law; in case of any discrepancy, the Turkish version prevails.
This text applies automatically alongside the Terms of Service for every customer with an account; it does not need to be signed separately. If you want a wet-signed or electronically signed copy, write to [email protected].

Subject matter and duration

The Customer is the data controller for the personal data of its end users. Bildirim.io service operator is the data processor, processing that data solely on the Customer’s instruction for the purpose of providing the service. This agreement remains in force for as long as the Customer’s account is open.

Nature and scope of processing

ItemDetail
Purpose of processingProviding web and mobile push notification infrastructure
Processing activitiesCollection, storage, audience computation, delivery to the push service, recording delivery and click events, reporting, deletion
Data categoriesPush endpoint and encryption keys, tags and external identifier defined by the Customer, browser/operating system/language/country/time zone, subscription and interaction timestamps
Categories of data subjectsUsers of the Customer’s website and app
Special categories of dataNot processed. The Customer must not enter special categories of personal data into the service.

Processing on instruction

Confidentiality and access

Staff with access to the data are bound by confidentiality, and access is limited on a least-privilege basis to what the role requires.

Technical and organisational measures

We also state the measures not yet in place: two-factor authentication (MFA), a customer-visible audit log and an independent security audit report are not offered yet. They are on the roadmap.

Sub-processors

The Customer gives general authorisation for the sub-processors listed below. We undertake to update this page and give reasonable prior notice before adding a new sub-processor; if the Customer objects, it may end its subscription.

Sub-processorPurposeData transferredLocation
Google LLC (Firebase Cloud Messaging / Google Push Service)Delivering notifications to Chrome and Android devicesPush endpoint address, encrypted notification payloadUSA / global
Mozilla Corporation (autopush)Delivering notifications to Firefox browsersPush endpoint address, encrypted notification payloadUSA / global
Apple Inc. (APNs / Safari Push)Delivering notifications to Safari and iOS devicesPush endpoint address or device token, encrypted notification payloadUSA / global
Microsoft Corporation (WNS)Delivering notifications to Edge browsersPush endpoint address, encrypted notification payloadUSA / global
Paddle.com Market Ltd.Taking payments, invoicing and subscription management (as merchant of record)Account email, billing and payment detailsUnited Kingdom / EU
Brevo (Sendinblue SAS)Transactional email: address verification, password reset, system and quota alertsAccount email address, email contentEU (France)
Google Ireland Ltd. / Google LLC (Google Analytics 4)Measuring visits to the marketing site — in cookieless mode unless consent is given; advertising and personalisation signals are off in every caseTruncated IP address, browser/device details, pages visited; plus a cookie identifier only if consent is givenEU / USA

Transfer to push services is technically necessary for a notification to reach a device. Notification content is delivered to them end-to-end encrypted (RFC 8291); the service cannot decrypt it and sees only the destination endpoint.

Data subject requests

If an end user comes to us directly, we do not act on the request but refer it to the Customer. We give the Customer reasonable assistance in meeting such requests; for operations not available in the panel we take requests through the support channel.

Data breach notification

When we learn of a personal data breach we notify the Customer without undue delay and in any event within 72 hours. The notice covers the nature of the breach, the categories of data affected, the estimated impact and the measures taken. The process is detailed on the Data Breach Procedure page.

Return and deletion

When the service ends we return or delete the data as the Customer requests. If no request is made, data is deleted automatically as its retention period expires, per the table below.

DataRetention period
Account record (name, email, password hash)Until the account is deleted; within 30 days of a deletion request
Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone)Until the subscription ends or the project is deleted
Campaign content and send recordsUntil the project is deleted
Delivery and click events12 months (deleted automatically as monthly partitions)
Outgoing webhook delivery records90 days (deleted automatically)
Session refresh tokens30 days (invalid once expired)
Invoice and payment recordsThe period required by financial legislation (10 years)

Copies remaining in encrypted backups fall away once the backup rotation completes (within 30 days at most). During that period backups may be used only for disaster recovery.

Audit

To verify compliance with this agreement the Customer may request information once a year, within a reasonable scope and subject to the protection of trade secrets. On-site audits take place by prior written agreement and with reasonable notice.

Bildirim

For questions about this document, write to [email protected] .

All legal documents