Puntjes

Data processing agreement

This is a draft. The final text is still being written. It will replace this page under a new version.

Version 2026-09-09-draft of September 9, 2026.

Your customers' data is yours. You decide what happens to it, and Puntjes only does what you ask. This agreement writes that down: what we may do with the data, what we must do to protect it, and what you can hold us to. It is the contract GDPR Article 28 requires between the two of us, and you accept it together with the terms of service.

1. Who this is between

You are the controller of your customers' data. You decide which customers you record, what you record about them and what you use it for. Puntjes is the processor: we hold that data and act on it for you.

This agreement is part of the terms of service, and you accept both with the same tick box. Where the two disagree about your customers' data, this agreement wins.

Our legal name, our registered office and our enterprise number are at the foot of this page.

Terms of service

2. What we process, about whom, and for how long

The subject is your loyalty programme, and nothing else. We store the data it needs, we read it back when you or your customers use it, and we use it to work out points, rewards and the emails you send. That is the whole nature and purpose of the processing.

The people whose data this is: the customers of your business, and the people you invite into your workspace.

About a customer we hold a name, an email address, a phone number, a date of birth, the language they read, the loyalty card and any other identifier you give them, what they bought and when, the points that earned and what they traded them for, and whether they said yes to your marketing mail. About someone you invite we hold a name, an email address and what they did in the workspace.

We hold it for as long as your workspace is open. Article 10 says what happens after that.

3. We only do what you tell us

We process your customers' data on your instructions and on nothing else. Working in the portal is an instruction. Calling the API is an instruction. This agreement and the terms of service are instructions.

Sending data outside the European Economic Area is an instruction too, and article 6 is where you give it: it names the parties involved and what makes each transfer lawful.

The one thing that overrides your instructions is a law we are bound by. If Union or Belgian law makes us process or hand over your customers' data, we do it, and we tell you before we do unless that same law forbids us to.

If we believe an instruction of yours breaks data protection law, we tell you and we may hold off until you confirm or change it.

We never use your customers' data for our own ends. We do not sell it, we do not rent it, and we do not build anything of ours on top of it.

4. The people who can reach it

Everyone at Puntjes who can reach your data is bound to keep it confidential, in writing, and that duty outlives their time with us.

Only the people who need the data for their work can reach it. When one of us has to look inside your workspace to help you, we enter it as an operator, and our audit log records who went in, and when they went in and came out. That log is ours rather than yours, so ask us and we tell you every time somebody entered your workspace and why.

5. How we protect it

We take the measures GDPR Article 32 asks for, weighed against what could go wrong and how bad it would be. Annex 1 lists what those measures are today.

We keep looking at them, and we may swap one for another. We will not swap one for a weaker one.

6. The other companies that help us

Running Puntjes takes other companies: one to run the servers, one to hold the database, one to send the mail. You agree that we may use them, and the page below is the full list, with what each one gets and where each one runs. That page is part of this agreement.

We tell you at least 30 days before we add a party to that list or replace one. You can tell us you object. If we cannot resolve your objection, you can end this agreement and the terms of service before the change takes effect, and article 10 says what happens to your data then.

Every party on that list is bound by a contract that puts the same duties on it that this agreement puts on us. If one of them gets it wrong, you come to us: we stay fully liable to you for what they do.

Where your data is processed

7. When one of your customers exercises a right

Your customer asks you, not us, because you are the controller. Our job is to put you in a position to answer, and we do it within the month that GDPR Article 12(3) gives you.

What you can use today. The customer page shows everything we hold about one person. Exporting your workspace hands you your customer base in a file you can read anywhere, and you can ask us for an export of every category. Anonymising a customer erases the name, the email address and the phone number for good while leaving the counts behind, so your figures stay right. The consent record shows what a customer agreed to, when, and through which channel.

If a request from one of your customers reaches us directly, we do not answer it. We pass it to you and tell you we did.

Export your workspace

8. When something goes wrong with the data

If your customers' data is lost, changed or seen by someone who should not have seen it, we tell you without undue delay once we know. You have 72 hours to tell the supervisory authority, and our notice is what starts your clock, so we do not wait to have the full picture before we send it.

The notice says what happened, which kinds of data and roughly how many people are involved, what we think the consequences are, and what we have done and are doing about it. We add what we learn as we learn it.

We help you make your report to the supervisory authority, and we help you tell the people affected where the law asks you to.

9. Assessments and questions to the authority

If you have to write a data protection impact assessment, we give you what we know about the processing we run for you: what we hold, where it goes, and how it is protected. Annex 1 and the sub-processor page already answer most of it.

If that assessment sends you to the supervisory authority before you start, we help you there too.

10. When this agreement ends

Before it ends, take your data. Exporting your workspace gives you every category in a file that other systems can read, and nothing stops you doing it while your workspace is still open.

After it ends we delete your customers' data, unless you ask us in writing to hand it back first. A workspace that had a paid plan is kept for 2 years after your subscription ends so you can still ask for that export, and a workspace that never had a paid plan goes after 2 years without a sign of life. We warn the people in the workspace before either deletion happens.

The only thing we keep after that is what the law makes us keep. Invoices are the case that comes up: Belgian tax law sets how long we hold them, and we hold them for that and for nothing else.

Export your workspaceTerms of service

11. Checking that we do all this

We give you what you need to show that Article 28 is met. This page, the sub-processor list and Annex 1 are part of that, and they are public, so you can point an auditor at them without asking us first.

You may audit us once a year, with reasonable notice and at a reasonable time, or accept a report from an independent auditor if we hold one. You carry the cost of your own audit, unless it finds that we broke this agreement.

An audit must not reach another workspace's data. Where a check would, we answer it with evidence instead of access.

12. Annex 1: what protects the data today

Everything travels encrypted. The site tells your browser never to connect over plain HTTP again, so an address typed without the s is upgraded before anything leaves the machine.

Passwords are stored as hashes, never as passwords. Anyone on our side with access to the platform has to pass two-factor authentication before they reach the portal at all.

Your session lives in a signed cookie, so a stolen one cannot be edited into somebody else's. Reading your customers is bound to your workspace, so one workspace does not see another's rows. Where a lookup has to run outside that boundary, it names the workspace itself and we test that it does.

The activity log is append-only. A row cannot be edited or deleted once written, and the only thing that removes one is the nightly clean-up after 365 days.

Logging in, two-factor and the API are all rate limited, so guessing at a password or a code stops being worth trying.

Our hosting and database providers encrypt what sits on their disks. Article 6 names them and says where they run.

Data that has reached the end of its retention is deleted by a job that runs every day, not by somebody remembering.

13. Annex 2: the parties that process data for us

The list lives on its own page so that it is always the current one. It names each party, what it gets, which country it runs in, and, for a party outside the European Economic Area, what makes sending data there lawful. The same page carries our statement about which country's law our infrastructure answers to and what we do when an authority outside the Union asks for data.

Where your data is processed

14. What else applies

This agreement runs for as long as the terms of service do, and it ends with them.

Belgian law applies to it, and a dispute goes to the courts the terms of service name.

If a court finds one clause here void, the rest stands, and the void clause is read as the closest lawful thing to what it meant.

Terms of service