Yes. The platform is GDPR-compliant, and Pushwoosh acts as a data processor for the data you send us.
Where your data is hosted
Pushwoosh operates its own enterprise-grade infrastructure in more than one region:
- EU region — Germany (Nuremberg, with Frankfurt used for backup). Customers who require EU data residency are provisioned here, and their data stays in the EU.
- US region — Washington DC area, USA. Used for accounts provisioned in the US region.
Your account lives in one region. If EU-only hosting is a contractual requirement for you, confirm your region with Pushwoosh support or your account manager rather than assuming it.
Certifications and transfer mechanisms
- ISO/IEC 27001:2022
- SOC 2 Type 1
- GDPR compliant; HIPAA and OWASP practices
- Pushwoosh, Inc. is certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF — the lawful basis for any transfer of personal data to the US. Standard Contractual Clauses are also available.
Collecting consent before any data leaves the device
To strictly meet data protection requirements, you can configure the SDK so that communication with Pushwoosh servers is disabled by default. No tracking or data collection occurs until you have received explicit consent from the user and enabled communication in code.
For the current certification list and a Data Processing Agreement, see Pushwoosh data safety and Data Privacy Frameworks.
Comments
0 comments
Please sign in to leave a comment.