This is a draft. The final text is still being written. It will replace this page under a new version.
Version 2026-09-09-draft of September 9, 2026.
This notice is for the people who use Puntjes for a business: the person who opens a workspace, the colleagues they invite, and the owner of a business that is a sole trader. It says what we collect about you and why, on which legal basis, who else receives it, how long we keep it, and what you can ask of us. It is the information GDPR Article 13 says you are owed.
Puntjes is the controller of the data this notice covers: we decide why it is collected and how. Our legal name, our registered office and our enterprise number are at the foot of this page.
We have no data protection officer. Every question about your data goes to one address, and a person reads it: info@puntjes.app.
The data your business keeps about its customers is not covered here. For that data your business is the controller, and Puntjes only processes it on your instructions. The data processing agreement says what we may and must do with it.
Are you a customer of a business that uses Puntjes? Then the notice that applies to you is the one that business gives you. Our documentation gives businesses a template for it.
Data processing agreementWhat your customers should be able to read
To open a workspace, you give the name of your business, your email address, your VAT number and a password. We store the password only as a hash, which nobody can turn back into the password.
Once you work in Puntjes, your account also holds your name, your role in the workspace, the language you read, and your two-factor authentication and passkeys if you turn them on. When you change your email address, we hold the new one until you confirm it. We record which version of the terms you accepted, and when. Google Maps Platform turns the address of your shop and your branches into map coordinates. Staying signed in takes cookies, which are listed on their own page.
Legal basis: for the person who opens the workspace, the contract between your business and us (GDPR Article 6(1)(b)). For a colleague invited into the workspace, the legitimate interest of your business and of us in giving your staff access to the service your business took (Article 6(1)(f)).
When an admin invites a colleague, the admin gives us that colleague's email address and the role they get. We use it to send the invitation, and to let the colleague create an account from it.
Legal basis: the legitimate interest of your business and of us in letting a business add its own staff (Article 6(1)(f)).
When you send us a support request, we keep what you typed, the files you attached, the page you were on and the plan of your workspace. We use it to answer you.
We copy the request to GitHub, where we track the work on what you reported. The copy holds the subject and the text you typed, the name of your business, your plan and the state of your subscription, and the page you were on. The files stay with us: the copy only says how many there are.
Legal basis: answering you is part of the contract (Article 6(1)(b)). Tracking the work on GitHub is our legitimate interest in solving problems reliably (Article 6(1)(f)).
For a paid plan we keep the legal name of your business, the invoice address, the enterprise and VAT number, the plan, the amounts and the invoices. Mollie takes the payment and issues the invoice, so it receives the legal name of your business, the invoice address, the VAT number and your contact email address.
We check your VAT number with VIES, the European Commission's service for VAT numbers. We keep its answer, with the name and address it returns, as the evidence for how we charged VAT.
Legal basis: charging for the plan is part of the contract (Article 6(1)(b)). Keeping the invoices and the VAT evidence behind them, and checking the VAT number, are obligations under Belgian VAT law (Article 6(1)(c)).
When someone in your workspace changes something, we record who did it, with which role, what changed and when. The application cannot edit or delete a line of that log. Only the scheduled clean-up removes old lines.
Legal basis: the legitimate interest of your business and of us in security, and in finding out afterwards what happened and who did it (Article 6(1)(f)).
When we announce a new release, we may send the admins of each workspace a short mail about it. For that we use your email address, your language, and a note of the release we last mailed you about.
Every one of those mails has a link to stop them. One click is enough, and we record the date you asked.
Legal basis: our legitimate interest in telling the people who use Puntjes what changed (Article 6(1)(f)). The link to stop is how you object.
When a request goes wrong, Laravel Nightwatch receives a report so we can find the fault and fix it. The report describes the request, and an email address can be part of it. We also keep the server's own logs.
To stop someone guessing passwords, we count the attempts to sign in, per internet address and per account. To stop someone opening workspaces in bulk, we count the attempts to open one, per internet address and per email domain, and how many workspaces were opened from one internet address.
Legal basis: our legitimate interest in keeping Puntjes secure and working for everyone who uses it (Article 6(1)(f)).
Most of the companies that process data for us do so inside the European Economic Area. Two parts of what this notice covers go to the United States.
GitHub receives the copy of a support request. Google Maps Platform receives the address of your shop and your branches.
Both take part in the EU-US Data Privacy Framework, which the European Commission decided gives your data the same protection there as here. Every company involved, what each one gets and where each one runs is on its own page.
Your account stays while your workspace exists. Delete your account yourself and we erase it at once. A colleague an admin removes can be restored for 90 days, and after that we erase their account. An accepted invitation is part of the account it created and is deleted with it.
An invitation nobody accepted is deleted 90 days after it expires.
A workspace that never had a paid plan is cleared out 2 years after the last thing that happened in it, and we mail everyone on the account a warning 30 days before. A workspace that had a paid plan is cleared out 2 years after its subscription ended, with a warning 30 days before. A warning only goes out while the account is still open.
Clearing out a workspace erases the account of everyone in it, and the contact email address and phone number of the business. The legal name, the VAT number and the invoice address stay until 7 years after the last invoice that names them. A workspace that never had an invoice loses those at the clear-out too.
We keep invoices and the VAT evidence behind them as long as Belgian VAT law requires, which today is 7 years after the invoice.
A support request and its files are deleted 12 months after the request is closed. On GitHub we then delete the subject, the text you typed, the name of your business and the page you were on, and we close the copy. What stays there points to nobody: the kind of request, your plan and the state of your subscription at the time.
When one of your customers puts their loyalty card in the wallet on their phone, that phone registers with us so we can keep the card up to date. That registration and the messages Google Wallet sends us about the card are deleted 90 days after the card in the wallet expires. The identifier of the phone goes once we hold no card for that phone any more.
A line in the activity log stays for 365 days. The note of the release we last mailed you about, and of whether you stopped those mails, goes with your account.
A sign-in counter forgets an attempt after one minute. A counter of attempts to open a workspace forgets them after 60 minutes, and the count of workspaces opened from one internet address after 24 hours. We keep error reports and server logs only as long as we need them to find and fix a fault, and the services that hold them delete them after the period our plan with them sets.
You can ask which data we hold about you, and get a copy of it. You can ask us to correct data that is wrong, and to erase data we no longer need or have no basis for.
You can ask us to restrict the processing while we look into a complaint of yours. You can ask for the data you gave us in a form a computer can read, so you can take it somewhere else.
You can object at any time to processing that rests on our legitimate interest. We then stop, unless we have compelling reasons that outweigh your interests, or need the data to bring or defend a legal claim.
Write to info@puntjes.app. We answer within one month. If a request is complex or we get many at once, we can take two months more, and we tell you so within the first month.
Some of this you can do yourself, on your account page: change your details, export your workspace and delete your account.
Nothing in this notice rests on your consent, so there is no consent to withdraw. If you do not want something we do on the basis of our legitimate interest, you object to it, as the previous article explains. For the mail about new releases, the link in every mail is enough.
If you think we handle your data wrongly, feel free to tell us first: we would rather put it right. You can always complain to the Belgian supervisory authority, the Data Protection Authority (Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels. You can also complain in the EU country where you live or work.
To open a workspace you have to give the name of your business, an email address, a VAT number and a password. Without them we cannot set up an account, and you cannot use Puntjes.
For a paid plan, Belgian VAT law requires the legal name, the address and the VAT number on the invoice. Without them we cannot sell you a paid plan.
The rest is your choice: two-factor authentication, passkeys and support requests.
Puntjes takes no decision about you that rests only on automated processing and has legal or similarly significant effects on you, in the sense of GDPR Article 22.
Some things do happen automatically, by rules the terms of service announce in advance: a workspace nobody uses is cleared out after the periods above, and a workspace whose payment fails is paused and then ends. The terms say when, and which mails come first.