Subject matter and duration
The Customer is the data controller for the personal data of its end users. Bildirim.io service operator is the data processor, processing that data solely on the Customer’s instruction for the purpose of providing the service. This agreement remains in force for as long as the Customer’s account is open.
Nature and scope of processing
| Item | Detail |
|---|---|
| Purpose of processing | Providing web and mobile push notification infrastructure |
| Processing activities | Collection, storage, audience computation, delivery to the push service, recording delivery and click events, reporting, deletion |
| Data categories | Push endpoint and encryption keys, tags and external identifier defined by the Customer, browser/operating system/language/country/time zone, subscription and interaction timestamps |
| Categories of data subjects | Users of the Customer’s website and app |
| Special categories of data | Not processed. The Customer must not enter special categories of personal data into the service. |
Processing on instruction
- We process data only on the Customer’s documented instruction (use of the service constitutes that instruction).
- If processing is legally required, we inform the Customer beforehand unless that is prohibited.
- We do not use the data for our own purposes, for advertising, or to train models.
Confidentiality and access
Staff with access to the data are bound by confidentiality, and access is limited on a least-privilege basis to what the role requires.
Technical and organisational measures
- TLS in transit; Argon2id for passwords; AES-256-GCM encrypted storage for signing and provider keys.
- Tenant isolation: every query is scoped by project and account identity, and that isolation is verified by automated tests.
- API keys are stored hashed and can be revoked; a revoked key stops working immediately.
- Rate limiting and progressive account lockout on sign-in.
- SSRF protection on all outbound requests; timestamped HMAC signatures on outgoing webhooks.
- Encrypted database backups.
Sub-processors
The Customer gives general authorisation for the sub-processors listed below. We undertake to update this page and give reasonable prior notice before adding a new sub-processor; if the Customer objects, it may end its subscription.
| Sub-processor | Purpose | Data transferred | Location |
|---|---|---|---|
| Google LLC (Firebase Cloud Messaging / Google Push Service) | Delivering notifications to Chrome and Android devices | Push endpoint address, encrypted notification payload | USA / global |
| Mozilla Corporation (autopush) | Delivering notifications to Firefox browsers | Push endpoint address, encrypted notification payload | USA / global |
| Apple Inc. (APNs / Safari Push) | Delivering notifications to Safari and iOS devices | Push endpoint address or device token, encrypted notification payload | USA / global |
| Microsoft Corporation (WNS) | Delivering notifications to Edge browsers | Push endpoint address, encrypted notification payload | USA / global |
| Paddle.com Market Ltd. | Taking payments, invoicing and subscription management (as merchant of record) | Account email, billing and payment details | United Kingdom / EU |
| Brevo (Sendinblue SAS) | Transactional email: address verification, password reset, system and quota alerts | Account email address, email content | EU (France) |
| Google Ireland Ltd. / Google LLC (Google Analytics 4) | Measuring visits to the marketing site — in cookieless mode unless consent is given; advertising and personalisation signals are off in every case | Truncated IP address, browser/device details, pages visited; plus a cookie identifier only if consent is given | EU / USA |
Transfer to push services is technically necessary for a notification to reach a device. Notification content is delivered to them end-to-end encrypted (RFC 8291); the service cannot decrypt it and sees only the destination endpoint.
Data subject requests
If an end user comes to us directly, we do not act on the request but refer it to the Customer. We give the Customer reasonable assistance in meeting such requests; for operations not available in the panel we take requests through the support channel.
Data breach notification
When we learn of a personal data breach we notify the Customer without undue delay and in any event within 72 hours. The notice covers the nature of the breach, the categories of data affected, the estimated impact and the measures taken. The process is detailed on the Data Breach Procedure page.
Return and deletion
When the service ends we return or delete the data as the Customer requests. If no request is made, data is deleted automatically as its retention period expires, per the table below.
| Data | Retention period |
|---|---|
| Account record (name, email, password hash) | Until the account is deleted; within 30 days of a deletion request |
| Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone) | Until the subscription ends or the project is deleted |
| Campaign content and send records | Until the project is deleted |
| Delivery and click events | 12 months (deleted automatically as monthly partitions) |
| Outgoing webhook delivery records | 90 days (deleted automatically) |
| Session refresh tokens | 30 days (invalid once expired) |
| Invoice and payment records | The period required by financial legislation (10 years) |
Copies remaining in encrypted backups fall away once the backup rotation completes (within 30 days at most). During that period backups may be used only for disaster recovery.
Audit
To verify compliance with this agreement the Customer may request information once a year, within a reasonable scope and subject to the protection of trade secrets. On-site audits take place by prior written agreement and with reasonable notice.