Informativa sulla Privacy

Informativa sulla Privacy

English Version

Datenschutzerklärung

punku.ai | Last Updated: August 4, 2026

Scope: This Privacy Policy applies to punku.ai (the website) and the PUNKU SaaS platform (the Service). It covers personal data we process as a data controller. Where we process personal data on behalf of our B2B customers as a data processor, a separate Data Processing Agreement (Art. 28 GDPR) governs that processing (see Section 14).

1. Controller / Responsible Party

The controller within the meaning of the GDPR and other applicable data protection laws is:

PUNKU GmbH

c/o Campus Founders, Bildungscampus 1

74076 Heilbronn, Germany

Email: info@punku.ai

Website: www.punku.ai

2. Data Protection Officer

PUNKU GmbH has designated a Data Protection Officer. You can contact them at:

Data Protection Officer / Datenschutzbeauftragter

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1

74076 Heilbronn, Germany

Email: datenschutz@punku.ai

3. Overview and Legal Bases

We process personal data only to the extent necessary and on the basis of at least one of the following legal grounds under Art. 6(1) GDPR:

  • Art. 6(1)(a) - Consent: you have given clear, informed consent for a specific purpose (e.g. analytics cookies, marketing emails).
  • Art. 6(1)(b) - Contract performance: processing is necessary to provide the Service you have subscribed to (e.g. account management, billing).
  • Art. 6(1)(c) - Legal obligation: processing is required to comply with a statutory obligation (e.g. invoice retention under § 257 HGB / § 147 AO).
  • Art. 6(1)(f) - Legitimate interests: processing is necessary for our legitimate interests, balanced against your rights (e.g. security monitoring, fraud prevention, product analytics with PostHog). You have the right to object - see Section 20.

Where we rely on legitimate interests, we carry out a balancing test. You may request details of that test by writing to datenschutz@punku.ai.

4. Website Usage Data

When you visit punku.ai, our web server automatically records standard access log data.

Server / Access Logs

Data collectedIP address (anonymised after 7 days), browser type, operating system, referring URL, pages visited, date and time of access, HTTP status code
PurposeEnsure website security and stability; diagnose and fix technical errors
Legal basisArt. 6(1)(f) - legitimate interests in secure and stable website operation
Retention7 days for full IP; aggregated logs up to 90 days
RecipientsAWS (hosting infrastructure)

5. Contact and Inquiries

When you contact us via email, the contact form, or other channels, we process the data you provide to respond to your inquiry.

Contact / Support Inquiries

Data collectedName, email address, company name, message content, and any attachments you provide
PurposeRespond to and process your inquiry; maintain records of correspondence
Legal basisArt. 6(1)(b) for pre-contractual or contractual inquiries; Art. 6(1)(f) for general inquiries
Retention3 years from last contact, unless a longer period applies due to ongoing contract
RecipientsGoogle Workspace (email), HubSpot (CRM for business inquiries)

6. Account Registration and Subscription

To use the PUNKU Service, you must create an account. We process the data you provide during registration and throughout your subscription.

Account and Subscription Data

Data collectedName, business email address, company name, billing address, subscription plan, account settings, login timestamps, and usage metadata (e.g. number of agents created, API calls)
PurposeCreate and manage your account; deliver the Service; enforce usage limits; communicate service-related notices
Legal basisArt. 6(1)(b) - necessary for the performance of the contract
RetentionDuration of the contract plus 3 years after termination. Invoices retained for 10 years per § 257 HGB.
RecipientsAWS (hosting), Stripe (billing), Atlassian Jira (issue tracking), Slack (internal communications)

7. Payment Processing

We use Stripe to process all subscription payments. We do not store full payment card details on our servers.

Payment Data

Data collectedName, billing address, email, subscription amount and frequency, transaction IDs, and last-four digits of payment method (stored by Stripe)
PurposeProcess subscription payments, issue invoices, handle refunds and disputes
Legal basisArt. 6(1)(b) - contract performance; Art. 6(1)(c) - legal obligation for invoice retention
RetentionTransaction records and invoices: 10 years (§ 257 HGB / § 147 AO)
RecipientsStripe, Inc. (payment processor - USA, SCCs in place)

Stripe data processing: Stripe processes payment data in the USA. This transfer is governed by Standard Contractual Clauses (Art. 46(2)(c) GDPR). See stripe.com/privacy for details.

8. Marketing and CRM (HubSpot)

We use HubSpot to manage our customer relationships and, where you have opted in, to send marketing communications.

Marketing / CRM Data

Data collectedName, business email address, company name, job title, interaction history (emails opened, links clicked, page visits via HubSpot tracking), notes from sales conversations
PurposeManage customer and prospect relationships; send service announcements; send marketing emails to opted-in contacts; track sales pipeline
Legal basisArt. 6(1)(b) for existing customers (service communications); Art. 6(1)(a) consent for marketing emails to non-customers; Art. 6(1)(f) for B2B prospect outreach
Opt-outUnsubscribe via the link in any email or by emailing hello@punku.ai
RetentionActive contacts: duration of relationship. Unsubscribed contacts: email retained on suppression list indefinitely to respect opt-out.
RecipientsHubSpot, Inc. (USA, SCCs in place)

9. Product Analytics (PostHog)

We use PostHog to understand how users interact with the Service, identify usability issues, and prioritise product improvements.

Product Analytics Data

Data collectedPseudonymous user ID, feature usage events, session duration, browser and device type, geographic region (country level), error events
PurposeUnderstand product usage patterns; improve the Service; identify and fix bugs; measure feature adoption
Legal basisArt. 6(1)(f) - legitimate interests in improving the Service. Data is pseudonymised and does not include message content.
Opt-outContact hello@punku.ai or adjust settings in your account
Retention90 days for individual session data; aggregated/anonymised analytics retained indefinitely
RecipientsPostHog, Inc. (EU-hosted instance, eu.posthog.com)

10. Website Analytics (Google Analytics)

We use Google Analytics 4 on the punku.ai website to measure traffic and marketing effectiveness.

Google Analytics Data

Data collectedAnonymised IP address, pages visited, session duration, traffic source, device/browser type. Stored via _ga and _ga_* cookies.
PurposeMeasure website traffic; evaluate marketing campaigns; identify popular content
Legal basisArt. 6(1)(a) - consent via cookie banner. Analytics cookies are only set after you accept them.
Opt-outDecline via cookie banner; or install the Google Analytics Opt-out Add-on: tools.google.com/dlpage/gaoptout
Retention14 months (Google Analytics default)
RecipientsGoogle LLC (USA, SCCs and EU-U.S. DPF certification)

11. Cookie Policy

Cookies are small text files stored on your device by your browser. We use cookies to ensure the website functions correctly, remember your preferences, and (with your consent) analyse usage.

11.1 Strictly Necessary Cookies

These cookies are required for the website to function and cannot be switched off. They include session management, authentication tokens, and your cookie consent preference. No consent is required for these.

11.2 Analytics Cookies (Consent Required)

CookieProviderDurationPurpose
_gaGoogle Analytics13 monthsIdentifies unique visitors for session and campaign tracking
_ga_*Google Analytics13 monthsStores and counts page views
ph_*PostHog1 yearPseudonymous product and website analytics. Set only with analytics consent; without it, analytics runs cookieless in page memory. Deleted on withdrawal.

11.3 Marketing Cookies and Conversion Measurement

If you reach punku.ai from a Google or Meta advertisement, we keep the initial click and campaign parameters only in the non-persistent memory of the current browser document while your marketing-cookie choice is undecided. This memory survives client-side navigation within the website, but it is not written to cookies, local storage, session storage, IndexedDB, or another persistent store.

Independently of your cookie choice, our own server relays cookieless measurement events (for example page views) to the conversion-measurement recipients listed in Section 22. These server-side events are derived from the individual request only (URL, page, IP address, browser user agent, and any click identifier present in the URL); nothing is read from or written to your device for them, and no persistent identifier is assigned to you. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our marketing); you may object at any time — see Section 20. Because these events access no information stored on your device, section 25 TDDDG does not require consent for them.

When you open the signup application from this website, the link includes the current pseudonymous analytics identifier (ph_did) so that your signup can be connected to your website session for product-analytics purposes (Art. 6(1)(f)). Without analytics consent this identifier exists only in the memory of the current page and expires when you leave it; with analytics consent it is the identifier from the analytics cookie described in Section 11.2. It is shared only between punku.ai and app.punku.ai — never with third parties.

Only if you accept marketing cookies are the retained landing parameters written to the first-party cookies below, transmitted to the signup application, and used to link a later sign-up back to the campaign. If you later withdraw consent, the website immediately stops that cookie-based attribution, forgets the in-memory landing parameters, and deletes the cookies below, including both host-only and cross-subdomain variants; the cookieless server-side measurement described above continues on the basis of Art. 6(1)(f) unless you object.

CookieProviderDurationPurpose
_fbcPUNKU (first-party)90 daysStores the Meta ad click identifier (fbclid) from the link you arrived on, so a sign-up can be attributed to that ad
_fbpPUNKU (first-party) / Meta Pixel90 daysPseudonymous browser identifier used to de-duplicate Meta conversion events
_punku_gclPUNKU (first-party)90 daysStores the Google Ads click identifier (gclid, wbraid or gbraid) and the page you landed on
_punku_ltPUNKU (first-party)90 daysStores the campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) of the link you arrived on

Legal basis: for the cookies above and the browser-based Google Ads and Meta Pixel tags, Art. 6(1)(a) GDPR and section 25(1) TDDDG (consent). For the cookieless server-side measurement events described above, Art. 6(1)(f) GDPR (legitimate interest), with the right to object under Section 20.

11.4 Managing Cookie Preferences

You can update your cookie preferences at any time via the Cookie Settings button in the website footer. You may also manage cookies via your browser:

  • Chrome: Settings → Privacy and security → Cookies
  • Firefox: Settings → Privacy & Security
  • Safari: Preferences → Privacy
  • Edge: Settings → Cookies and site permissions

Cookie consent management is provided by CookieYes (Civic Technologies). See cookieyes.com/privacy-policy for their privacy policy.

12. AI Model Processing

The PUNKU Service enables you to build AI agents that call third-party language model APIs. When your AI agents run, input data (prompts) and output data (model responses) may be transmitted to our AI model provider partners.

AI Model API Data

Data transmittedPrompts and context you configure in your agents; output generated by the AI models. We do not intentionally transmit special categories of personal data to AI model providers.
PurposeProvide AI agent functionality as part of the Service
Legal basisArt. 6(1)(b) - necessary for contract performance
ProvidersAnthropic (Claude), OpenAI (GPT models), Google (Gemini). See anthropic.com/privacy, openai.com/privacy, cloud.google.com/privacy.
Your responsibilityAs a B2B customer and data controller, you are responsible for ensuring that data you instruct PUNKU to process through AI models complies with applicable law, including GDPR. You must have a lawful basis for any personal data included in prompts.
RetentionWe do not retain AI model inputs or outputs beyond what is necessary to deliver the response (typically the session duration). AI providers' own retention policies apply to their systems.

Important: Do not instruct AI agents to process special categories of personal data (health, financial, biometric, etc.) without first assessing compliance and obtaining appropriate consents from your end users.

13. Internal and External Communication Tools

We use the following tools for internal collaboration and external communications.

Communication Tools

ToolsGoogle Workspace (email), Slack (internal team), Twilio (messaging services)
Data processedEmail content and metadata; Slack messages; SMS/communication logs where applicable
Legal basisArt. 6(1)(b) - contract performance; Art. 6(1)(f) - legitimate interests in business operations
RetentionMax 3 years for routine correspondence, longer if required for legal or contractual reasons
RecipientsGoogle LLC, Salesforce/Slack Technologies, Twilio Inc. (all USA, SCCs in place)

14. Processing on Behalf of Our B2B Customers (Processor Role)

When our B2B customers use the PUNKU Service to process personal data of their own customers or end users, PUNKU GmbH acts as a data processor within the meaning of Art. 4(8) GDPR. In this capacity:

  • The B2B customer is the data controller and determines the purpose and means of processing.
  • PUNKU GmbH processes such data only on documented instructions from the customer.
  • This processing relationship is governed by a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR, which is available at punku.ai/privacy and is incorporated into our Terms of Service.
  • We implement appropriate technical and organisational measures to ensure the security of customer-controlled data.

If you are an end user of a business that uses the PUNKU platform and wish to exercise your GDPR rights, please contact that business directly (they are the data controller for your data). We will assist the controller in fulfilling data subject requests as required by our DPA.

15. International Data Transfers

Several of our subprocessors are located in the United States. The transfer of personal data to these subprocessors is governed by Standard Contractual Clauses (SCCs) adopted under Art. 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), supplemented by a Transfer Impact Assessment (TIA) where required. Additionally, some providers participate in the EU-U.S. Data Privacy Framework (DPF).

SubprocessorServiceLocationTransfer Mechanism
Amazon Web ServicesAWS (Hosting)EU (Frankfurt)Data stored in EU-Central-1; no transfer outside EU
AtlassianJiraUSA / EUSCCs + DPF certification
Google LLCGoogle Workspace and consented Analytics measurementUSA / EUSCCs + DPF certification
Meta Platforms Ireland / Meta Platforms, Inc.Consented advertising and conversion measurementEU / USASCCs + DPF certification
Salesforce / SlackSlackUSA / EUSCCs + DPF certification
GitHub (Microsoft)GitHubUSA / EUSCCs + DPF certification
AnthropicClaude AIUSASCCs
OpenAIOpenAI APIUSASCCs + DPF certification
Google LLCGemini / Vertex AIUSA / EUSCCs + DPF certification
TwilioTwilioUSA / EUSCCs + DPF certification
PostHogPostHogEU (eu.posthog.com)EU-hosted instance; no transfer outside EU
HubSpotHubSpot CRMUSA / EUSCCs + DPF certification
StripePayment processingUSA / EUSCCs + DPF certification
Civic TechnologiesCookieYesUSA / EUSCCs
Layers AI IncConversion measurement (Layers)USASCCs (pseudonymous data only)

You can obtain copies of the applicable SCCs by contacting datenschutz@punku.ai. The EU-U.S. Data Privacy Framework list is publicly available at dataprivacyframework.gov.

Last updated: June 15, 2026. This list is reviewed quarterly.

16. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, or as required by applicable law.

Data CategoryRetention PeriodLegal Basis / Reason
Website server logs7 days (full IP); 90 days (aggregated)Art. 6(1)(f) - security
Contact / support emails3 years from last contactArt. 6(1)(b)/(f)
Account / subscription dataContract term + 3 yearsArt. 6(1)(b) - warranty/disputes
Invoices & billing records10 years§ 257 HGB / § 147 AO - Art. 6(1)(c)
Payment transaction data10 years§ 257 HGB / Art. 6(1)(c)
Marketing contacts (opted-in)Until opt-out + 3 yearsArt. 6(1)(a) consent
Unsubscribe / opt-out recordsIndefinite (suppression list)Art. 6(1)(c) - comply with opt-out
Product analytics (PostHog)90 days session data; aggregated indefinitelyArt. 6(1)(f)
GA analytics cookies13 monthsArt. 6(1)(a) consent
AI model API data (prompts/responses)Session only (not stored beyond delivery)Art. 6(1)(b)
User Content (data export)30 days post-cancellationArt. 6(1)(b) - contract
Security / fraud prevention logs1 yearArt. 6(1)(f)

When a retention period expires, data is securely deleted or irreversibly anonymised.

17. Security Measures (Technical and Organisational Measures)

We implement appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These include:

  • Encryption in transit: all connections use TLS 1.2 or higher.
  • Encryption at rest: all data stored on AWS (eu-central-1) is encrypted using AES-256.
  • Access controls: role-based access control (RBAC); least-privilege principle; mandatory multi-factor authentication for all infrastructure access.
  • Network security: VPC isolation; firewall rules; intrusion detection monitoring.
  • Vulnerability management: automated dependency scanning (Dependabot / GitHub); regular penetration testing; responsible disclosure programme (security@punku.ai).
  • Data minimisation: we collect only the data necessary for each processing purpose.
  • Subprocessor due diligence: all subprocessors are contractually bound to maintain equivalent security standards.
  • Incident response: documented breach notification procedure; GDPR Art. 33/34 72-hour supervisory authority notification capability.

To report a security vulnerability, contact security@punku.ai. We will acknowledge within 48 hours.

18. Automated Decision-Making and Profiling

We do not make decisions about you based solely on automated processing (including profiling) that would produce legal or similarly significant effects, within the meaning of Art. 22 GDPR. Product analytics and usage data are used only to improve the Service and are reviewed by humans before any business decisions are made.

19. Children's Data

The Service is directed exclusively at businesses and professionals (B2B). We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe we hold data about a minor, please contact datenschutz@punku.ai.

20. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data. To exercise any right, contact datenschutz@punku.ai. We will respond within one calendar month (with a possible extension of two further months for complex requests, of which we will notify you).

Right of Access (Art. 15 GDPR)

You may request confirmation of whether we process your personal data, and if so, a copy of that data together with information about the processing (purposes, categories, recipients, retention periods, rights).

Right to Rectification (Art. 16 GDPR)

You may request correction of inaccurate personal data or completion of incomplete data. Many details can be updated directly in your account settings.

Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR)

You may request deletion of your personal data where: (a) it is no longer necessary for the purpose for which it was collected; (b) you withdraw consent and there is no other legal basis; (c) you object and we have no overriding legitimate interest; or (d) the data was processed unlawfully. This right does not apply where retention is required by law (e.g. 10-year invoice retention under HGB) or where the data is necessary for legal claims.

Right to Restriction of Processing (Art. 18 GDPR)

You may request that we restrict processing (i.e. store but not use) your data while we verify accuracy, consider your objection, or if processing was unlawful but you prefer restriction over erasure.

Right to Data Portability (Art. 20 GDPR)

Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and have it transmitted to another controller where technically feasible. Applies to data you actively provided (account data, usage data).

Right to Object (Art. 21 GDPR)

You may object at any time to processing based on Art. 6(1)(f) legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is needed for legal claims. You have an absolute right to object to direct marketing (including profiling for marketing). We will stop immediately on receipt of your objection.

Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. Use the unsubscribe link in marketing emails, adjust cookie settings via the cookie banner, or email datenschutz@punku.ai.

Identity verification: To protect your personal data, we may need to verify your identity before processing a rights request. We will not charge a fee for reasonable requests, but may charge a reasonable fee or refuse manifestly unfounded or excessive requests (Art. 12(5) GDPR).

21. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data violates the GDPR (Art. 77 GDPR).

As PUNKU GmbH is established in Baden-Württemberg, the competent supervisory authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)

Heilbronner Straße 35

70191 Stuttgart, Germany

Phone: +49 (0) 711 615541-0

Email: poststelle@lfdi.bwl.de

Website: www.baden-wuerttemberg.datenschutz.de

You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work.

22. Advertising and Conversion Measurement

The punku.ai website relays measurement events through a first-party server endpoint to the enabled measurement recipients below. As described in Section 11.3, these server-side events run cookieless for every visitor on the basis of Art. 6(1)(f) GDPR (legitimate interest), carrying only request-derived data. Identifiers stored in cookies (advertising click IDs, the Google Analytics client ID) and the signup-URL attribution parameters are added to these events only after you accept marketing cookies; if consent is absent or withdrawn, those identifiers are not read or transmitted and the stored cookies are deleted. You may object to the cookieless measurement at any time — see Section 20.

Conversion Signal Data

Data collectedConversion event type (for example page view, lead, or sign-up), a per-event id, page URL and title, consented campaign parameters, and available pseudonymous advertising or analytics identifiers. The server receives the IP address and user agent as part of the web request. The website tracker does not add a name or email address to these events.
PurposeAttribute sign-ups and other conversion steps to marketing campaigns, de-duplicate browser and server events, and measure campaign effectiveness
Legal basisCookie-based attribution: Art. 6(1)(a) GDPR and section 25(1) TDDDG (marketing consent). Cookieless server-side measurement events: Art. 6(1)(f) GDPR (legitimate interest), see Section 11.3
WithdrawalWithdraw marketing consent at any time through Cookie Settings in the footer. Cookie-based attribution stops immediately and the advertising cookies listed in Section 11.3 are deleted. Cookieless server-side measurement continues under Art. 6(1)(f); object at any time as described in Section 20.
RecipientsMeta Platforms (Conversions API), Google (Analytics Measurement Protocol), PostHog (server-side conversion analytics), and Layers AI Inc (conversion measurement), only when each destination is enabled
Data minimisationLayers does not receive the visitor IP address. The other recipients receive only the fields needed for the enabled measurement path. Retention is governed by the recipient settings and agreements listed in this policy.

International transfers: Some recipients process data in the United States. The safeguards for each recipient, including Standard Contractual Clauses and applicable Data Privacy Framework participation, are listed in Section 15. Layers receives pseudonymous conversion signals without a name, email address, or visitor IP address. See layers.com/privacy for its policy.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes (e.g. new processing purposes, new categories of data, or new international transfers), we will:

  • Update the “Last Updated” date at the top of this page;
  • Notify registered users by email at least 30 days before the change takes effect; and
  • Where required by law, obtain fresh consent for new consent-based processing activities.

The current version is always available at punku.ai/privacy.

24. Contact

Privacy / Data Protection Queries

Email: datenschutz@punku.ai

General: info@punku.ai

Security vulnerabilities: security@punku.ai

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn, Germany

Last updated: August 4, 2026

Deutsche Version

Die vollständige Datenschutzerklärung ist die englische Fassung oben. Die folgende Kurzfassung gibt die wesentlichen Informationen gemäß Art. 13/14 DSGVO wieder.

I. Verantwortlicher

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn.

E-Mail: info@punku.ai

II. Datenschutzbeauftragter

III. Verarbeitungszwecke und Rechtsgrundlagen

Wir verarbeiten Ihre personenbezogenen Daten auf folgenden Rechtsgrundlagen:

  • Art. 6 Abs. 1 lit. a DSGVO - Einwilligung (z.B. Cookies, Newsletter)
  • Art. 6 Abs. 1 lit. b DSGVO - Vertragserfüllung (Kontoführung, Zahlungsabwicklung)
  • Art. 6 Abs. 1 lit. c DSGVO - Rechtliche Verpflichtung (Buchführung nach HGB)
  • Art. 6 Abs. 1 lit. f DSGVO - Berechtigte Interessen (Sicherheit, Produktanalyse)

IV. Empfänger und Drittlandübermittlungen

Wir setzen Auftragsverarbeiter ein (AWS, Google, Meta, Stripe, HubSpot, PostHog, OpenAI, Anthropic, Layers u.a.). Werbe-Cookies und die cookie-basierte Kampagnen-Zuordnung erfolgen nur nach Ihrer Einwilligung und werden bei Widerruf sofort gestoppt bzw. gelöscht; daneben übermittelt unser Server cookielose Messereignisse (ohne Zugriff auf Ihr Endgerät) auf Grundlage von Art. 6 Abs. 1 lit. f DSGVO — Widerspruch jederzeit möglich, siehe Abschnitt 20. Drittlandübermittlungen in die USA erfolgen auf Grundlage der in Abschnitt 15 genannten Garantien. Die vollständige Beschreibung finden Sie in den Abschnitten 11.3, 15 und 22 der englischen Fassung.

V. Ihre Rechte (Art. 15–21 DSGVO)

Sie haben das Recht auf: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch (Art. 21) und Widerruf einer Einwilligung (Art. 7 Abs. 3). Anfragen richten Sie bitte an datenschutz@punku.ai.

VI. Beschwerderecht

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)

Heilbronner Straße 35, 70191 Stuttgart

www.baden-wuerttemberg.datenschutz.de

VII. Automatisierte Entscheidungsfindung

Wir setzen keine automatisierte Entscheidungsfindung einschließlich Profiling im Sinne von Art. 22 DSGVO ein, die rechtliche oder ähnlich erhebliche Auswirkungen auf Sie hätte.

© 2026 PUNKU GmbH. All rights reserved.