Skip to main content

Data Breach Notification Policy

Effective: July 11, 2026

Purpose

Push Start Go LLC (“Company,” “we,” or “us”) is committed to protecting your personal information. In the event of a data breach affecting your data, we will notify you and relevant authorities in accordance with applicable laws including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable U.S. state breach notification laws.

What Constitutes a Data Breach

A data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed by Push Start Go. Examples include:

  • Unauthorized access to our database or servers
  • Accidental exposure of personal data via a misconfiguration
  • Theft or loss of devices containing personal data
  • A third-party vendor breach affecting our users’ data

Internal Detection and Assessment

Upon discovery of a potential breach, our security team will:

  • Contain and mitigate the breach within 24 hours of discovery
  • Assess the scope, nature, and likely consequences of the breach
  • Determine which users and data categories are affected
  • Document all findings in an internal incident report

Regulatory Notification — GDPR (72-Hour Rule)

Where a data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. The notification will include:

  • The nature of the breach and approximate number of data subjects affected
  • Categories and approximate number of records affected
  • Contact details of our Data Protection contact
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

If a complete assessment is not possible within 72 hours, we will provide initial notification followed by supplementary information as it becomes available.

CCPA and U.S. State Breach Notification

In the event of a breach involving unencrypted personal information of California residents, we will notify affected individuals in the most expedient time possible and without unreasonable delay, as required by California Civil Code Section 1798.29. Similar timelines apply for residents of other U.S. states with breach notification laws (Colorado, Virginia, Texas, etc.).

User Notification

Where a breach is likely to result in a high risk to your rights and freedoms (e.g., exposure of passwords, financial data, or sensitive personal information), we will notify you without undue delay via:

  • Email to the address registered on your account
  • An in-app banner notification upon your next login
  • A public notice on our website if a large number of users are affected

The notification will describe in plain language:

  • What happened and what data was involved
  • What we are doing to address it
  • What you can do to protect yourself (e.g., change password, monitor accounts)
  • Contact information for further questions

Record Keeping

All data breaches, regardless of severity, are documented in our internal incident register in accordance with GDPR Article 33(5). This record includes the facts of the breach, its effects, and the remedial actions taken.

Contact Our Data Protection Team

To report a suspected breach or ask questions about this policy, contact us at: security@pushstartgo.com

For privacy-related requests, see our Privacy Policy and Privacy Request Form.