Informativa sulla Privacy
Datenschutzerklärung
punku.ai | Last Updated: March 19, 2026
Scope: This Privacy Policy applies to punku.ai (the website) and the PUNKU SaaS platform (the Service). It covers personal data we process as a data controller. Where we process personal data on behalf of our B2B customers as a data processor, a separate Data Processing Agreement (Art. 28 GDPR) governs that processing (see Section 14).
The controller within the meaning of the GDPR and other applicable data protection laws is:
PUNKU GmbH
c/o Campus Founders, Bildungscampus 1
74076 Heilbronn, Germany
Email: info@punku.ai
Website: www.punku.ai
PUNKU GmbH has designated a Data Protection Officer. You can contact them at:
Data Protection Officer / Datenschutzbeauftragter
PUNKU GmbH, c/o Campus Founders, Bildungscampus 1
74076 Heilbronn, Germany
Email: datenschutz@punku.ai
We process personal data only to the extent necessary and on the basis of at least one of the following legal grounds under Art. 6(1) GDPR:
Where we rely on legitimate interests, we carry out a balancing test. You may request details of that test by writing to datenschutz@punku.ai.
When you visit punku.ai, our web server automatically records standard access log data.
| Data collected | IP address (anonymised after 7 days), browser type, operating system, referring URL, pages visited, date and time of access, HTTP status code |
| Purpose | Ensure website security and stability; diagnose and fix technical errors |
| Legal basis | Art. 6(1)(f) - legitimate interests in secure and stable website operation |
| Retention | 7 days for full IP; aggregated logs up to 90 days |
| Recipients | AWS (hosting infrastructure) |
When you contact us via email, the contact form, or other channels, we process the data you provide to respond to your inquiry.
| Data collected | Name, email address, company name, message content, and any attachments you provide |
| Purpose | Respond to and process your inquiry; maintain records of correspondence |
| Legal basis | Art. 6(1)(b) for pre-contractual or contractual inquiries; Art. 6(1)(f) for general inquiries |
| Retention | 3 years from last contact, unless a longer period applies due to ongoing contract |
| Recipients | Google Workspace (email), HubSpot (CRM for business inquiries) |
To use the PUNKU Service, you must create an account. We process the data you provide during registration and throughout your subscription.
| Data collected | Name, business email address, company name, billing address, subscription plan, account settings, login timestamps, and usage metadata (e.g. number of agents created, API calls) |
| Purpose | Create and manage your account; deliver the Service; enforce usage limits; communicate service-related notices |
| Legal basis | Art. 6(1)(b) - necessary for the performance of the contract |
| Retention | Duration of the contract plus 3 years after termination. Invoices retained for 10 years per § 257 HGB. |
| Recipients | AWS (hosting), Stripe (billing), Atlassian Jira (issue tracking), Slack (internal communications) |
We use Stripe to process all subscription payments. We do not store full payment card details on our servers.
| Data collected | Name, billing address, email, subscription amount and frequency, transaction IDs, and last-four digits of payment method (stored by Stripe) |
| Purpose | Process subscription payments, issue invoices, handle refunds and disputes |
| Legal basis | Art. 6(1)(b) - contract performance; Art. 6(1)(c) - legal obligation for invoice retention |
| Retention | Transaction records and invoices: 10 years (§ 257 HGB / § 147 AO) |
| Recipients | Stripe, Inc. (payment processor - USA, SCCs in place) |
Stripe data processing: Stripe processes payment data in the USA. This transfer is governed by Standard Contractual Clauses (Art. 46(2)(c) GDPR). See stripe.com/privacy for details.
We use HubSpot to manage our customer relationships and, where you have opted in, to send marketing communications.
| Data collected | Name, business email address, company name, job title, interaction history (emails opened, links clicked, page visits via HubSpot tracking), notes from sales conversations |
| Purpose | Manage customer and prospect relationships; send service announcements; send marketing emails to opted-in contacts; track sales pipeline |
| Legal basis | Art. 6(1)(b) for existing customers (service communications); Art. 6(1)(a) consent for marketing emails to non-customers; Art. 6(1)(f) for B2B prospect outreach |
| Opt-out | Unsubscribe via the link in any email or by emailing hello@punku.ai |
| Retention | Active contacts: duration of relationship. Unsubscribed contacts: email retained on suppression list indefinitely to respect opt-out. |
| Recipients | HubSpot, Inc. (USA, SCCs in place) |
We use PostHog to understand how users interact with the Service, identify usability issues, and prioritise product improvements.
| Data collected | Pseudonymous user ID, feature usage events, session duration, browser and device type, geographic region (country level), error events |
| Purpose | Understand product usage patterns; improve the Service; identify and fix bugs; measure feature adoption |
| Legal basis | Art. 6(1)(f) - legitimate interests in improving the Service. Data is pseudonymised and does not include message content. |
| Opt-out | Contact hello@punku.ai or adjust settings in your account |
| Retention | 90 days for individual session data; aggregated/anonymised analytics retained indefinitely |
| Recipients | PostHog, Inc. (EU-hosted instance, eu.posthog.com) |
We use Google Analytics 4 on the punku.ai website to measure traffic and marketing effectiveness.
| Data collected | Anonymised IP address, pages visited, session duration, traffic source, device/browser type. Stored via _ga and _ga_* cookies. |
| Purpose | Measure website traffic; evaluate marketing campaigns; identify popular content |
| Legal basis | Art. 6(1)(a) - consent via cookie banner. Analytics cookies are only set after you accept them. |
| Opt-out | Decline via cookie banner; or install the Google Analytics Opt-out Add-on: tools.google.com/dlpage/gaoptout |
| Retention | 14 months (Google Analytics default) |
| Recipients | Google LLC (USA, SCCs and EU-U.S. DPF certification) |
Cookies are small text files stored on your device by your browser. We use cookies to ensure the website functions correctly, remember your preferences, and (with your consent) analyse usage.
These cookies are required for the website to function and cannot be switched off. They include session management, authentication tokens, and your cookie consent preference. No consent is required for these.
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
| _ga | Google Analytics | 13 months | Identifies unique visitors for session and campaign tracking |
| _ga_* | Google Analytics | 13 months | Stores and counts page views |
| ph_* | PostHog | 1 year | Pseudonymous product analytics (Service users only) |
You can update your cookie preferences at any time via the Cookie Settings button in the website footer. You may also manage cookies via your browser:
Cookie consent management is provided by CookieYes (Civic Technologies). See cookieyes.com/privacy-policy for their privacy policy.
The PUNKU Service enables you to build AI agents that call third-party language model APIs. When your AI agents run, input data (prompts) and output data (model responses) may be transmitted to our AI model provider partners.
| Data transmitted | Prompts and context you configure in your agents; output generated by the AI models. We do not intentionally transmit special categories of personal data to AI model providers. |
| Purpose | Provide AI agent functionality as part of the Service |
| Legal basis | Art. 6(1)(b) - necessary for contract performance |
| Providers | Anthropic (Claude), OpenAI (GPT models), Google (Gemini). See anthropic.com/privacy, openai.com/privacy, cloud.google.com/privacy. |
| Your responsibility | As a B2B customer and data controller, you are responsible for ensuring that data you instruct PUNKU to process through AI models complies with applicable law, including GDPR. You must have a lawful basis for any personal data included in prompts. |
| Retention | We do not retain AI model inputs or outputs beyond what is necessary to deliver the response (typically the session duration). AI providers' own retention policies apply to their systems. |
Important: Do not instruct AI agents to process special categories of personal data (health, financial, biometric, etc.) without first assessing compliance and obtaining appropriate consents from your end users.
We use the following tools for internal collaboration and external communications.
| Tools | Google Workspace (email), Slack (internal team), Twilio (messaging services) |
| Data processed | Email content and metadata; Slack messages; SMS/communication logs where applicable |
| Legal basis | Art. 6(1)(b) - contract performance; Art. 6(1)(f) - legitimate interests in business operations |
| Retention | Max 3 years for routine correspondence, longer if required for legal or contractual reasons |
| Recipients | Google LLC, Salesforce/Slack Technologies, Twilio Inc. (all USA, SCCs in place) |
When our B2B customers use the PUNKU Service to process personal data of their own customers or end users, PUNKU GmbH acts as a data processor within the meaning of Art. 4(8) GDPR. In this capacity:
If you are an end user of a business that uses the PUNKU platform and wish to exercise your GDPR rights, please contact that business directly (they are the data controller for your data). We will assist the controller in fulfilling data subject requests as required by our DPA.
Several of our subprocessors are located in the United States. The transfer of personal data to these subprocessors is governed by Standard Contractual Clauses (SCCs) adopted under Art. 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), supplemented by a Transfer Impact Assessment (TIA) where required. Additionally, some providers participate in the EU-U.S. Data Privacy Framework (DPF).
| Subprocessor | Service | Location | Transfer Mechanism |
|---|---|---|---|
| Amazon Web Services | AWS (Hosting) | EU (Frankfurt) | Data stored in EU-Central-1; no transfer outside EU |
| Atlassian | Jira | USA / EU | SCCs + DPF certification |
| Google LLC | Google Workspace | USA / EU | SCCs + DPF certification |
| Salesforce / Slack | Slack | USA / EU | SCCs + DPF certification |
| GitHub (Microsoft) | GitHub | USA / EU | SCCs + DPF certification |
| Anthropic | Claude AI | USA | SCCs |
| OpenAI | OpenAI API | USA | SCCs + DPF certification |
| Google LLC | Gemini / Vertex AI | USA / EU | SCCs + DPF certification |
| Twilio | Twilio | USA / EU | SCCs + DPF certification |
| PostHog | PostHog | EU (eu.posthog.com) | EU-hosted instance; no transfer outside EU |
| HubSpot | HubSpot CRM | USA / EU | SCCs + DPF certification |
| Stripe | Payment processing | USA / EU | SCCs + DPF certification |
| Civic Technologies | CookieYes | USA / EU | SCCs |
You can obtain copies of the applicable SCCs by contacting datenschutz@punku.ai. The EU-U.S. Data Privacy Framework list is publicly available at dataprivacyframework.gov.
Last updated: March 12, 2026. This list is reviewed quarterly.
We retain personal data only as long as necessary for the purposes described in this policy, or as required by applicable law.
| Data Category | Retention Period | Legal Basis / Reason |
|---|---|---|
| Website server logs | 7 days (full IP); 90 days (aggregated) | Art. 6(1)(f) - security |
| Contact / support emails | 3 years from last contact | Art. 6(1)(b)/(f) |
| Account / subscription data | Contract term + 3 years | Art. 6(1)(b) - warranty/disputes |
| Invoices & billing records | 10 years | § 257 HGB / § 147 AO - Art. 6(1)(c) |
| Payment transaction data | 10 years | § 257 HGB / Art. 6(1)(c) |
| Marketing contacts (opted-in) | Until opt-out + 3 years | Art. 6(1)(a) consent |
| Unsubscribe / opt-out records | Indefinite (suppression list) | Art. 6(1)(c) - comply with opt-out |
| Product analytics (PostHog) | 90 days session data; aggregated indefinitely | Art. 6(1)(f) |
| GA analytics cookies | 13 months | Art. 6(1)(a) consent |
| AI model API data (prompts/responses) | Session only (not stored beyond delivery) | Art. 6(1)(b) |
| User Content (data export) | 30 days post-cancellation | Art. 6(1)(b) - contract |
| Security / fraud prevention logs | 1 year | Art. 6(1)(f) |
When a retention period expires, data is securely deleted or irreversibly anonymised.
We implement appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These include:
To report a security vulnerability, contact security@punku.ai. We will acknowledge within 48 hours.
We do not make decisions about you based solely on automated processing (including profiling) that would produce legal or similarly significant effects, within the meaning of Art. 22 GDPR. Product analytics and usage data are used only to improve the Service and are reviewed by humans before any business decisions are made.
The Service is directed exclusively at businesses and professionals (B2B). We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe we hold data about a minor, please contact datenschutz@punku.ai.
Under the GDPR, you have the following rights regarding your personal data. To exercise any right, contact datenschutz@punku.ai. We will respond within one calendar month (with a possible extension of two further months for complex requests, of which we will notify you).
You may request confirmation of whether we process your personal data, and if so, a copy of that data together with information about the processing (purposes, categories, recipients, retention periods, rights).
You may request correction of inaccurate personal data or completion of incomplete data. Many details can be updated directly in your account settings.
You may request deletion of your personal data where: (a) it is no longer necessary for the purpose for which it was collected; (b) you withdraw consent and there is no other legal basis; (c) you object and we have no overriding legitimate interest; or (d) the data was processed unlawfully. This right does not apply where retention is required by law (e.g. 10-year invoice retention under HGB) or where the data is necessary for legal claims.
You may request that we restrict processing (i.e. store but not use) your data while we verify accuracy, consider your objection, or if processing was unlawful but you prefer restriction over erasure.
Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and have it transmitted to another controller where technically feasible. Applies to data you actively provided (account data, usage data).
You may object at any time to processing based on Art. 6(1)(f) legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is needed for legal claims. You have an absolute right to object to direct marketing (including profiling for marketing). We will stop immediately on receipt of your objection.
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. Use the unsubscribe link in marketing emails, adjust cookie settings via the cookie banner, or email datenschutz@punku.ai.
Identity verification: To protect your personal data, we may need to verify your identity before processing a rights request. We will not charge a fee for reasonable requests, but may charge a reasonable fee or refuse manifestly unfounded or excessive requests (Art. 12(5) GDPR).
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data violates the GDPR (Art. 77 GDPR).
As PUNKU GmbH is established in Baden-Württemberg, the competent supervisory authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Königstraße 10a
70173 Stuttgart, Germany
Phone: +49 (0) 711 615541-0
Email: poststelle@lfdi.bwl.de
You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work.
We may update this Privacy Policy from time to time. When we make material changes (e.g. new processing purposes, new categories of data, or new international transfers), we will:
The current version is always available at punku.ai/privacy.
Email: datenschutz@punku.ai
General: info@punku.ai
Security vulnerabilities: security@punku.ai
PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn, Germany
Last updated: March 19, 2026
Die vollständige Datenschutzerklärung ist die englische Fassung oben. Die folgende Kurzfassung gibt die wesentlichen Informationen gemäß Art. 13/14 DSGVO wieder.
PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn.
E-Mail: info@punku.ai
E-Mail: datenschutz@punku.ai
Wir verarbeiten Ihre personenbezogenen Daten auf folgenden Rechtsgrundlagen:
Wir setzen Auftragsverarbeiter ein (AWS, Google, Stripe, HubSpot, PostHog, OpenAI, Anthropic u.a.). Drittlandübermittlungen in die USA erfolgen auf Grundlage von Standardvertragsklauseln (Art. 46 Abs. 2 lit. c DSGVO). Die vollständige Liste finden Sie in Abschnitt 15 der englischen Fassung.
Sie haben das Recht auf: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch (Art. 21) und Widerruf einer Einwilligung (Art. 7 Abs. 3). Anfragen richten Sie bitte an datenschutz@punku.ai.
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Königstraße 10a, 70173 Stuttgart
Wir setzen keine automatisierte Entscheidungsfindung einschließlich Profiling im Sinne von Art. 22 DSGVO ein, die rechtliche oder ähnlich erhebliche Auswirkungen auf Sie hätte.
© 2026 PUNKU GmbH. All rights reserved.