Informativa sulla Privacy

Informativa sulla Privacy

English Version

Datenschutzerklärung

punku.ai | Last Updated: March 19, 2026

Scope: This Privacy Policy applies to punku.ai (the website) and the PUNKU SaaS platform (the Service). It covers personal data we process as a data controller. Where we process personal data on behalf of our B2B customers as a data processor, a separate Data Processing Agreement (Art. 28 GDPR) governs that processing (see Section 14).

1. Controller / Responsible Party

The controller within the meaning of the GDPR and other applicable data protection laws is:

PUNKU GmbH

c/o Campus Founders, Bildungscampus 1

74076 Heilbronn, Germany

Email: info@punku.ai

Website: www.punku.ai

2. Data Protection Officer

PUNKU GmbH has designated a Data Protection Officer. You can contact them at:

Data Protection Officer / Datenschutzbeauftragter

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1

74076 Heilbronn, Germany

Email: datenschutz@punku.ai

3. Overview and Legal Bases

We process personal data only to the extent necessary and on the basis of at least one of the following legal grounds under Art. 6(1) GDPR:

  • Art. 6(1)(a) - Consent: you have given clear, informed consent for a specific purpose (e.g. analytics cookies, marketing emails).
  • Art. 6(1)(b) - Contract performance: processing is necessary to provide the Service you have subscribed to (e.g. account management, billing).
  • Art. 6(1)(c) - Legal obligation: processing is required to comply with a statutory obligation (e.g. invoice retention under § 257 HGB / § 147 AO).
  • Art. 6(1)(f) - Legitimate interests: processing is necessary for our legitimate interests, balanced against your rights (e.g. security monitoring, fraud prevention, product analytics with PostHog). You have the right to object - see Section 20.

Where we rely on legitimate interests, we carry out a balancing test. You may request details of that test by writing to datenschutz@punku.ai.

4. Website Usage Data

When you visit punku.ai, our web server automatically records standard access log data.

Server / Access Logs

Data collectedIP address (anonymised after 7 days), browser type, operating system, referring URL, pages visited, date and time of access, HTTP status code
PurposeEnsure website security and stability; diagnose and fix technical errors
Legal basisArt. 6(1)(f) - legitimate interests in secure and stable website operation
Retention7 days for full IP; aggregated logs up to 90 days
RecipientsAWS (hosting infrastructure)

5. Contact and Inquiries

When you contact us via email, the contact form, or other channels, we process the data you provide to respond to your inquiry.

Contact / Support Inquiries

Data collectedName, email address, company name, message content, and any attachments you provide
PurposeRespond to and process your inquiry; maintain records of correspondence
Legal basisArt. 6(1)(b) for pre-contractual or contractual inquiries; Art. 6(1)(f) for general inquiries
Retention3 years from last contact, unless a longer period applies due to ongoing contract
RecipientsGoogle Workspace (email), HubSpot (CRM for business inquiries)

6. Account Registration and Subscription

To use the PUNKU Service, you must create an account. We process the data you provide during registration and throughout your subscription.

Account and Subscription Data

Data collectedName, business email address, company name, billing address, subscription plan, account settings, login timestamps, and usage metadata (e.g. number of agents created, API calls)
PurposeCreate and manage your account; deliver the Service; enforce usage limits; communicate service-related notices
Legal basisArt. 6(1)(b) - necessary for the performance of the contract
RetentionDuration of the contract plus 3 years after termination. Invoices retained for 10 years per § 257 HGB.
RecipientsAWS (hosting), Stripe (billing), Atlassian Jira (issue tracking), Slack (internal communications)

7. Payment Processing

We use Stripe to process all subscription payments. We do not store full payment card details on our servers.

Payment Data

Data collectedName, billing address, email, subscription amount and frequency, transaction IDs, and last-four digits of payment method (stored by Stripe)
PurposeProcess subscription payments, issue invoices, handle refunds and disputes
Legal basisArt. 6(1)(b) - contract performance; Art. 6(1)(c) - legal obligation for invoice retention
RetentionTransaction records and invoices: 10 years (§ 257 HGB / § 147 AO)
RecipientsStripe, Inc. (payment processor - USA, SCCs in place)

Stripe data processing: Stripe processes payment data in the USA. This transfer is governed by Standard Contractual Clauses (Art. 46(2)(c) GDPR). See stripe.com/privacy for details.

8. Marketing and CRM (HubSpot)

We use HubSpot to manage our customer relationships and, where you have opted in, to send marketing communications.

Marketing / CRM Data

Data collectedName, business email address, company name, job title, interaction history (emails opened, links clicked, page visits via HubSpot tracking), notes from sales conversations
PurposeManage customer and prospect relationships; send service announcements; send marketing emails to opted-in contacts; track sales pipeline
Legal basisArt. 6(1)(b) for existing customers (service communications); Art. 6(1)(a) consent for marketing emails to non-customers; Art. 6(1)(f) for B2B prospect outreach
Opt-outUnsubscribe via the link in any email or by emailing hello@punku.ai
RetentionActive contacts: duration of relationship. Unsubscribed contacts: email retained on suppression list indefinitely to respect opt-out.
RecipientsHubSpot, Inc. (USA, SCCs in place)

9. Product Analytics (PostHog)

We use PostHog to understand how users interact with the Service, identify usability issues, and prioritise product improvements.

Product Analytics Data

Data collectedPseudonymous user ID, feature usage events, session duration, browser and device type, geographic region (country level), error events
PurposeUnderstand product usage patterns; improve the Service; identify and fix bugs; measure feature adoption
Legal basisArt. 6(1)(f) - legitimate interests in improving the Service. Data is pseudonymised and does not include message content.
Opt-outContact hello@punku.ai or adjust settings in your account
Retention90 days for individual session data; aggregated/anonymised analytics retained indefinitely
RecipientsPostHog, Inc. (EU-hosted instance, eu.posthog.com)

10. Website Analytics (Google Analytics)

We use Google Analytics 4 on the punku.ai website to measure traffic and marketing effectiveness.

Google Analytics Data

Data collectedAnonymised IP address, pages visited, session duration, traffic source, device/browser type. Stored via _ga and _ga_* cookies.
PurposeMeasure website traffic; evaluate marketing campaigns; identify popular content
Legal basisArt. 6(1)(a) - consent via cookie banner. Analytics cookies are only set after you accept them.
Opt-outDecline via cookie banner; or install the Google Analytics Opt-out Add-on: tools.google.com/dlpage/gaoptout
Retention14 months (Google Analytics default)
RecipientsGoogle LLC (USA, SCCs and EU-U.S. DPF certification)

11. Cookie Policy

Cookies are small text files stored on your device by your browser. We use cookies to ensure the website functions correctly, remember your preferences, and (with your consent) analyse usage.

11.1 Strictly Necessary Cookies

These cookies are required for the website to function and cannot be switched off. They include session management, authentication tokens, and your cookie consent preference. No consent is required for these.

11.2 Analytics Cookies (Consent Required)

CookieProviderDurationPurpose
_gaGoogle Analytics13 monthsIdentifies unique visitors for session and campaign tracking
_ga_*Google Analytics13 monthsStores and counts page views
ph_*PostHog1 yearPseudonymous product analytics (Service users only)

11.3 Managing Cookie Preferences

You can update your cookie preferences at any time via the Cookie Settings button in the website footer. You may also manage cookies via your browser:

  • Chrome: Settings → Privacy and security → Cookies
  • Firefox: Settings → Privacy & Security
  • Safari: Preferences → Privacy
  • Edge: Settings → Cookies and site permissions

Cookie consent management is provided by CookieYes (Civic Technologies). See cookieyes.com/privacy-policy for their privacy policy.

12. AI Model Processing

The PUNKU Service enables you to build AI agents that call third-party language model APIs. When your AI agents run, input data (prompts) and output data (model responses) may be transmitted to our AI model provider partners.

AI Model API Data

Data transmittedPrompts and context you configure in your agents; output generated by the AI models. We do not intentionally transmit special categories of personal data to AI model providers.
PurposeProvide AI agent functionality as part of the Service
Legal basisArt. 6(1)(b) - necessary for contract performance
ProvidersAnthropic (Claude), OpenAI (GPT models), Google (Gemini). See anthropic.com/privacy, openai.com/privacy, cloud.google.com/privacy.
Your responsibilityAs a B2B customer and data controller, you are responsible for ensuring that data you instruct PUNKU to process through AI models complies with applicable law, including GDPR. You must have a lawful basis for any personal data included in prompts.
RetentionWe do not retain AI model inputs or outputs beyond what is necessary to deliver the response (typically the session duration). AI providers' own retention policies apply to their systems.

Important: Do not instruct AI agents to process special categories of personal data (health, financial, biometric, etc.) without first assessing compliance and obtaining appropriate consents from your end users.

13. Internal and External Communication Tools

We use the following tools for internal collaboration and external communications.

Communication Tools

ToolsGoogle Workspace (email), Slack (internal team), Twilio (messaging services)
Data processedEmail content and metadata; Slack messages; SMS/communication logs where applicable
Legal basisArt. 6(1)(b) - contract performance; Art. 6(1)(f) - legitimate interests in business operations
RetentionMax 3 years for routine correspondence, longer if required for legal or contractual reasons
RecipientsGoogle LLC, Salesforce/Slack Technologies, Twilio Inc. (all USA, SCCs in place)

14. Processing on Behalf of Our B2B Customers (Processor Role)

When our B2B customers use the PUNKU Service to process personal data of their own customers or end users, PUNKU GmbH acts as a data processor within the meaning of Art. 4(8) GDPR. In this capacity:

  • The B2B customer is the data controller and determines the purpose and means of processing.
  • PUNKU GmbH processes such data only on documented instructions from the customer.
  • This processing relationship is governed by a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR, which is available at punku.ai/privacy and is incorporated into our Terms of Service.
  • We implement appropriate technical and organisational measures to ensure the security of customer-controlled data.

If you are an end user of a business that uses the PUNKU platform and wish to exercise your GDPR rights, please contact that business directly (they are the data controller for your data). We will assist the controller in fulfilling data subject requests as required by our DPA.

15. International Data Transfers

Several of our subprocessors are located in the United States. The transfer of personal data to these subprocessors is governed by Standard Contractual Clauses (SCCs) adopted under Art. 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), supplemented by a Transfer Impact Assessment (TIA) where required. Additionally, some providers participate in the EU-U.S. Data Privacy Framework (DPF).

SubprocessorServiceLocationTransfer Mechanism
Amazon Web ServicesAWS (Hosting)EU (Frankfurt)Data stored in EU-Central-1; no transfer outside EU
AtlassianJiraUSA / EUSCCs + DPF certification
Google LLCGoogle WorkspaceUSA / EUSCCs + DPF certification
Salesforce / SlackSlackUSA / EUSCCs + DPF certification
GitHub (Microsoft)GitHubUSA / EUSCCs + DPF certification
AnthropicClaude AIUSASCCs
OpenAIOpenAI APIUSASCCs + DPF certification
Google LLCGemini / Vertex AIUSA / EUSCCs + DPF certification
TwilioTwilioUSA / EUSCCs + DPF certification
PostHogPostHogEU (eu.posthog.com)EU-hosted instance; no transfer outside EU
HubSpotHubSpot CRMUSA / EUSCCs + DPF certification
StripePayment processingUSA / EUSCCs + DPF certification
Civic TechnologiesCookieYesUSA / EUSCCs

You can obtain copies of the applicable SCCs by contacting datenschutz@punku.ai. The EU-U.S. Data Privacy Framework list is publicly available at dataprivacyframework.gov.

Last updated: March 12, 2026. This list is reviewed quarterly.

16. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, or as required by applicable law.

Data CategoryRetention PeriodLegal Basis / Reason
Website server logs7 days (full IP); 90 days (aggregated)Art. 6(1)(f) - security
Contact / support emails3 years from last contactArt. 6(1)(b)/(f)
Account / subscription dataContract term + 3 yearsArt. 6(1)(b) - warranty/disputes
Invoices & billing records10 years§ 257 HGB / § 147 AO - Art. 6(1)(c)
Payment transaction data10 years§ 257 HGB / Art. 6(1)(c)
Marketing contacts (opted-in)Until opt-out + 3 yearsArt. 6(1)(a) consent
Unsubscribe / opt-out recordsIndefinite (suppression list)Art. 6(1)(c) - comply with opt-out
Product analytics (PostHog)90 days session data; aggregated indefinitelyArt. 6(1)(f)
GA analytics cookies13 monthsArt. 6(1)(a) consent
AI model API data (prompts/responses)Session only (not stored beyond delivery)Art. 6(1)(b)
User Content (data export)30 days post-cancellationArt. 6(1)(b) - contract
Security / fraud prevention logs1 yearArt. 6(1)(f)

When a retention period expires, data is securely deleted or irreversibly anonymised.

17. Security Measures (Technical and Organisational Measures)

We implement appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These include:

  • Encryption in transit: all connections use TLS 1.2 or higher.
  • Encryption at rest: all data stored on AWS (eu-central-1) is encrypted using AES-256.
  • Access controls: role-based access control (RBAC); least-privilege principle; mandatory multi-factor authentication for all infrastructure access.
  • Network security: VPC isolation; firewall rules; intrusion detection monitoring.
  • Vulnerability management: automated dependency scanning (Dependabot / GitHub); regular penetration testing; responsible disclosure programme (security@punku.ai).
  • Data minimisation: we collect only the data necessary for each processing purpose.
  • Subprocessor due diligence: all subprocessors are contractually bound to maintain equivalent security standards.
  • Incident response: documented breach notification procedure; GDPR Art. 33/34 72-hour supervisory authority notification capability.

To report a security vulnerability, contact security@punku.ai. We will acknowledge within 48 hours.

18. Automated Decision-Making and Profiling

We do not make decisions about you based solely on automated processing (including profiling) that would produce legal or similarly significant effects, within the meaning of Art. 22 GDPR. Product analytics and usage data are used only to improve the Service and are reviewed by humans before any business decisions are made.

19. Children's Data

The Service is directed exclusively at businesses and professionals (B2B). We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe we hold data about a minor, please contact datenschutz@punku.ai.

20. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data. To exercise any right, contact datenschutz@punku.ai. We will respond within one calendar month (with a possible extension of two further months for complex requests, of which we will notify you).

Right of Access (Art. 15 GDPR)

You may request confirmation of whether we process your personal data, and if so, a copy of that data together with information about the processing (purposes, categories, recipients, retention periods, rights).

Right to Rectification (Art. 16 GDPR)

You may request correction of inaccurate personal data or completion of incomplete data. Many details can be updated directly in your account settings.

Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR)

You may request deletion of your personal data where: (a) it is no longer necessary for the purpose for which it was collected; (b) you withdraw consent and there is no other legal basis; (c) you object and we have no overriding legitimate interest; or (d) the data was processed unlawfully. This right does not apply where retention is required by law (e.g. 10-year invoice retention under HGB) or where the data is necessary for legal claims.

Right to Restriction of Processing (Art. 18 GDPR)

You may request that we restrict processing (i.e. store but not use) your data while we verify accuracy, consider your objection, or if processing was unlawful but you prefer restriction over erasure.

Right to Data Portability (Art. 20 GDPR)

Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and have it transmitted to another controller where technically feasible. Applies to data you actively provided (account data, usage data).

Right to Object (Art. 21 GDPR)

You may object at any time to processing based on Art. 6(1)(f) legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is needed for legal claims. You have an absolute right to object to direct marketing (including profiling for marketing). We will stop immediately on receipt of your objection.

Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. Use the unsubscribe link in marketing emails, adjust cookie settings via the cookie banner, or email datenschutz@punku.ai.

Identity verification: To protect your personal data, we may need to verify your identity before processing a rights request. We will not charge a fee for reasonable requests, but may charge a reasonable fee or refuse manifestly unfounded or excessive requests (Art. 12(5) GDPR).

21. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data violates the GDPR (Art. 77 GDPR).

As PUNKU GmbH is established in Baden-Württemberg, the competent supervisory authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)

Königstraße 10a

70173 Stuttgart, Germany

Phone: +49 (0) 711 615541-0

Email: poststelle@lfdi.bwl.de

Website: www.baden-wuerttemberg.datenschutz.de

You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes (e.g. new processing purposes, new categories of data, or new international transfers), we will:

  • Update the “Last Updated” date at the top of this page;
  • Notify registered users by email at least 30 days before the change takes effect; and
  • Where required by law, obtain fresh consent for new consent-based processing activities.

The current version is always available at punku.ai/privacy.

23. Contact

Privacy / Data Protection Queries

Email: datenschutz@punku.ai

General: info@punku.ai

Security vulnerabilities: security@punku.ai

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn, Germany

Last updated: March 19, 2026

Deutsche Version

Die vollständige Datenschutzerklärung ist die englische Fassung oben. Die folgende Kurzfassung gibt die wesentlichen Informationen gemäß Art. 13/14 DSGVO wieder.

I. Verantwortlicher

PUNKU GmbH, c/o Campus Founders, Bildungscampus 1, 74076 Heilbronn.

E-Mail: info@punku.ai

II. Datenschutzbeauftragter

III. Verarbeitungszwecke und Rechtsgrundlagen

Wir verarbeiten Ihre personenbezogenen Daten auf folgenden Rechtsgrundlagen:

  • Art. 6 Abs. 1 lit. a DSGVO - Einwilligung (z.B. Cookies, Newsletter)
  • Art. 6 Abs. 1 lit. b DSGVO - Vertragserfüllung (Kontoführung, Zahlungsabwicklung)
  • Art. 6 Abs. 1 lit. c DSGVO - Rechtliche Verpflichtung (Buchführung nach HGB)
  • Art. 6 Abs. 1 lit. f DSGVO - Berechtigte Interessen (Sicherheit, Produktanalyse)

IV. Empfänger und Drittlandübermittlungen

Wir setzen Auftragsverarbeiter ein (AWS, Google, Stripe, HubSpot, PostHog, OpenAI, Anthropic u.a.). Drittlandübermittlungen in die USA erfolgen auf Grundlage von Standardvertragsklauseln (Art. 46 Abs. 2 lit. c DSGVO). Die vollständige Liste finden Sie in Abschnitt 15 der englischen Fassung.

V. Ihre Rechte (Art. 15–21 DSGVO)

Sie haben das Recht auf: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch (Art. 21) und Widerruf einer Einwilligung (Art. 7 Abs. 3). Anfragen richten Sie bitte an datenschutz@punku.ai.

VI. Beschwerderecht

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)

Königstraße 10a, 70173 Stuttgart

www.baden-wuerttemberg.datenschutz.de

VII. Automatisierte Entscheidungsfindung

Wir setzen keine automatisierte Entscheidungsfindung einschließlich Profiling im Sinne von Art. 22 DSGVO ein, die rechtliche oder ähnlich erhebliche Auswirkungen auf Sie hätte.

© 2026 PUNKU GmbH. All rights reserved.