Privacy Policy

Last updated: Aug 30th, 2025

Effective date: August 6, 2026

This Privacy Policy explains how Volcanic Labs SLU, trading as PushFeedback (“PushFeedback”, “we”, “us”), processes personal data when it acts as a controller. It does not replace the privacy notice of a PushFeedback customer that uses our widget on its own site or application.

1. Who is responsible for your data

Volcanic Labs SLU is the controller for personal data processed through pushfeedback.com, PushFeedback accounts, billing, support, and our own communications. Our address is Plaza de Galicia, Local 7, 38612, Santa Cruz de Tenerife, Spain. Contact us at [email protected].

2. When we process data for customers

A PushFeedback customer that embeds our widget generally decides why and how end-user feedback is collected. In that situation, the customer is the controller and PushFeedback is its processor. We process submitted messages, screenshots, contact details, page URLs, IP addresses, session identifiers, and metadata only to provide, secure, and support the Services under the customer’s instructions and our Data Processing Agreement. If you submitted feedback through a customer’s site, contact that customer first to exercise rights over that feedback.

3. Data we process as controller

  • Account and contact data: name, work email, organisation, login details, and account settings.
  • Billing data: billing contact details, plan, invoices, and payment status. Card details are processed by our payment provider, not stored by PushFeedback.
  • Support and communications: messages, requests, and communication preferences.
  • Website and service usage data: technical logs, security events, device and browser information, pages viewed, and interaction data necessary to operate, secure, and improve the Services.
  • Cookie and attribution data: consent choices and, when you allow analytics cookies, pseudonymous analytics identifiers and first-touch campaign or referral information.

4. Why we use this data

We process account, billing, and support data to provide the Services and perform our contract with you. We process security logs and essential service data for our legitimate interests in protecting the Services, preventing abuse, and improving reliability. We process analytics cookies and related attribution data only with your consent. We may send service communications as necessary to provide the Services and marketing communications where permitted by law; you can unsubscribe from marketing at any time.

5. How long we keep data

We keep controller data for as long as needed for the purposes described above. Account data is kept while the account is active and then for a reasonable period to resolve requests, enforce agreements, or meet legal obligations. Billing records are retained for the legally required period. Cookie choices are retained for up to 24 months. Customer Content is handled under the DPA and the customer’s subscription; screenshots may also be subject to the plan retention settings.

6. Recipients and international transfers

We use carefully selected providers for hosting, storage, email, payments, error monitoring, analytics, and optional AI features. Some providers are located outside the European Economic Area. Where a transfer requires a safeguard, we use an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism. Current providers and optional integrations are listed in our provider documentation.

7. Cookies and similar technologies

We use essential local storage to remember your cookie choice. With your consent, we use Google Analytics and a 90-day first-touch attribution cookie to understand marketing performance. Analytics and attribution are not loaded or written until you accept. You can accept or reject analytics cookies from the cookie banner or change your choice at any time through “Cookie settings” in the site footer. Rejecting analytics cookies does not affect access to the website.

8. AI features

When an authorised account user requests an optional AI Report, we send the selected feedback data to the AI provider needed to generate that report. AI Reports can be disabled by a team administrator. We do not use Customer Content to train our own models, and our provider documentation describes the relevant providers.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data we process as controller. You may withdraw cookie consent at any time without affecting processing before withdrawal. To make a request, email [email protected]. You may also lodge a complaint with the Spanish Data Protection Agency or your local supervisory authority.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, logging, backups, and secure development practices. No system is completely secure, but we continually review and improve our safeguards. See our security overview for product details.

11. Changes to this policy

We may update this Policy from time to time. We will post the revised version and its effective date on this page. Where applicable law requires separate or advance notice, we will provide it.

12. Contact

Volcanic Labs SLU

Plaza de Galicia, Local 7, 38612, Santa Cruz de Tenerife, Spain

[email protected]