Back to Tools
PushPushGo logo

PushPushGo

Partially Compliant

Polish web and mobile push notification platform from PushPushGo sp. z o.o. in Kraków, founded 2017, hosted on OVH with a named Data Protection Officer and a published sub-processor list.

🇵🇱Poland🇪🇺EU Hosted🇪🇺 European

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paidfrom 49 €/month
PushPushGo website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryPoland
OwnershipEuropean-owned
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
European Union"Who we share your data with: OVH - our server provider" (pushpushgo.com/en/company/gdpr, read raw 2026-09-07). No specific OVH data center region is named, but OVH's core infrastructure is French/EU.
EU Servers Available
Data Processing AgreementOffered on request, not published
Sub-processor ListView sub-processors
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified7 September 2026

How we reached this

Polish legal entity: PushPushGo sp. z o.o., registered office Quattro Business Park, Aleja Generała Tadeusza Bora-Komorowskiego 25C, 31-476 Kraków, KRS 0000688693, NIP 6751601766, REGON 367877285, per pushpushgo.com/en/company/regulations and /en/company/gdpr, both read raw 2026-09-07. A named Data Protection Officer, Katarzyna Krzywicka, is given with a direct email. PARTIAL rather than COMPLIANT: the GDPR page names its sub-processors explicitly by name, which is rare and valuable in this category, but that same list includes several US companies (Google/Gmail/Drive, Stripe, PayPal, Microsoft Clarity) alongside OVH for server hosting, so extraterritorialExposure is US_CLOUD_ACT despite EU server hosting, and schremsIIRisk is MEDIUM because no SCC or other transfer safeguard is named for those US sub-processors anywhere in the reviewed pages, so sccInPlace is false. dpaEvidence is ON_REQUEST: the GDPR FAQ states a signed 'entrustment agreement for the processing of personal data...is an integral part of our documentation' and is required of every customer, which is functionally a DPA, but no document was found published at a standalone public URL during this review.

About PushPushGo

A Named DPO and a Published Sub-Processor List, Which Is Rare Here

Push notification vendors in this directory tend to be thin on documentation: a privacy policy, sometimes a DPA reference, rarely more. PushPushGo's GDPR page is a useful counter-example. It names its Data Protection Officer (Katarzyna Krzywicka), states plainly who it shares data with, and lists them by name rather than by category:

Who we share your data with: OVH - our server provider. Gmail, Slack, Livespace, YouTrack, Google (Gmail, Drive) - our communication platforms. Fakturownia, Stripe, PayPal, PayU, ING Bank - our payment platforms. Google Analytics, Microsoft Clarity, Mixpanel - services that help us improve our online site. Mailerlite - email marketing. CookieHub - cookie consent management. Ycode - the platform we built our website on.

That is an unusually specific list, and it cuts both ways: it's the kind of transparency almost no competitor in this category offers, and it also makes plain that several of those named sub-processors, Google, Stripe, PayPal and Microsoft Clarity among them, are American companies.

What the Platform Does

  • Web push, mobile push and transactional push notifications
  • Onsite and pop-up notifications, plus in-app messages
  • WhatsApp channels on higher tiers
  • Multi-channel personalization and automation

Pricing is published: Basic runs 49 €/month for the first six months (59 € regularly) for one channel; Pro is 109 €/month initially (149 € regularly) covering two channels and 35,000 push subscribers; Business and Enterprise move to custom annual pricing with five to six channels, up to unlimited subscribers, and dedicated support.

The Kraków Entity

PushPushGo sp. z o.o., registered office at Quattro Business Park, Aleja Generała Tadeusza Bora-Komorowskiego 25C, 31-476 Kraków, entered in the National Court Register under KRS 0000688693, tax number NIP 6751601766, business register number REGON 367877285.

A DPA Exists, But Isn't Published at a URL

PushPushGo's GDPR FAQ states that customers must sign what it calls an "entrustment agreement": "it is necessary that you entrust us with the processing of your subscribers' personal data, to the extent and for the purpose specified in the entrustment agreement for the processing of personal data...The entrustment agreement is an integral part of our documentation." That is functionally a DPA and appears to be standard practice, but no document was found published at a public URL during this review, so it's recorded as available on request rather than published.

Where It Fits

Against OneSignal, PushPushGo is a Polish entity with an OVH-hosted product and a named DPO, trading a free tier for published starting prices and named sub-processor transparency. See also Batch.com and Frizbit in push notifications.

Key Features

Web push, mobile push and transactional push notifications
Onsite and pop-up notifications, plus in-app messages
WhatsApp channels on higher tiers
Multi-channel personalization and automation
Named sub-processor list published on the GDPR page
Named Data Protection Officer with direct contact

Pros & Cons

Publishes named sub-processors rather than vague categories, unusually transparent for this category
Names a Data Protection Officer with a direct email address
Published starting prices (49 €/month) rather than quote-only
Founded 2017 with an established Polish legal entity and full registration numbers public
OVH server hosting keeps the core infrastructure European
Named sub-processor list includes several US companies (Google, Stripe, PayPal, Microsoft Clarity), so US_CLOUD_ACT exposure applies despite EU server hosting
No SCC or other international-transfer safeguard named for those US sub-processors
The DPA (entrustment agreement) is required but not published at a public URL
Entry Basic plan covers only one communication channel
Business and Enterprise tiers require a custom quote, so full pricing isn't transparent

Replaces

PushPushGo GDPR & data protection: common questions

Is PushPushGo GDPR compliant?

Partly. PushPushGo meets some of the requirements, with caveats worth reading before you commit. PushPushGo is a European company headquartered in Poland, data is hosted within the European Union.

Where does PushPushGo store data?

PushPushGo states: ""Who we share your data with: OVH - our server provider" (pushpushgo.com/en/company/gdpr, read raw 2026-09-07). No specific OVH data center region is named, but OVH's core infrastructure is French/EU.". Data is hosted within the European Union.

Does PushPushGo offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for PushPushGo. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover

Is PushPushGo a European company?

Yes. PushPushGo is headquartered in Poland and, as far as we can establish, European-owned.

Is PushPushGo subject to the US CLOUD Act?

Indirectly. PushPushGo itself is European-owned and headquartered in Poland, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.

Schrems II compliance checklist

Who are PushPushGo's sub-processors?

PushPushGo publishes its sub-processor list at https://pushpushgo.com/en/company/gdpr. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at PushPushGo and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.