puntavia.
Nederlands ▾
3 dagen proberen

Data Processing Agreement

5 September 2026 · Golova Europe SL

How Golova Europe SL processes, on behalf of the customer company and on its instructions, the personal data that Puntavia records on its employees’ work computers.

1. Parties and scope

1.1. This Data Processing Agreement (the “DPA”) is entered into between:

  • Golova Europe SL, Tax ID B70717004, with registered office at Calle l’Hospital 95, Planta 1, Puerta 2, 08001 Barcelona, Spain, operator of the Puntavia service (the “Processor”); and
  • the customer company that signs up for Puntavia (the “Controller”) — together, the “Parties”.

1.2. This DPA is accepted together with the terms of service published at https://puntavia.com/terms, of which it forms part, and applies for as long as the Controller uses the service.

1.3. This DPA gives effect to Article 28 of Regulation (EU) 2016/679 (GDPR) and to the equivalent provisions of Spanish Organic Law 3/2018 (LOPDGDD), and governs the Processor’s processing of personal data on behalf of the Controller in the provision of the service.

1.4. In case of conflict between this DPA and the terms of service, this DPA prevails in everything relating to the processing of personal data by the Processor.

1.5. Capitalised terms used and not defined here have the meaning given to them by the GDPR or by the terms of service.

1.6. Communications concerning this DPA are addressed to privacy@puntavia.com.

2. Subject matter, duration, nature and purpose

2.1. Subject matter. The Processor measures the working time of the Controller’s employees on their work computers and, from that measurement, produces the daily record, the summaries and the reports the Controller receives.

2.2. Duration. This DPA applies for as long as the Controller uses the service and survives termination to the extent necessary for the return or deletion of personal data (section 11).

2.3. Nature of the processing. It comprises the collection, recording, organisation, storage, retrieval, use, computation, disclosure to authorised sub-processors, restriction, and erasure or destruction of personal data.

2.4. Purpose. The processing is carried out for the sole purpose of providing the service to the Controller in accordance with the terms of service and the Controller’s documented instructions.

2.5. Categories of data subjects:

  • the Controller’s employees and contractors who work on the computers where the program is installed;
  • the Controller’s own staff who use the dashboard.

2.6. Categories of personal data:

  • identification data: the name given by the employer and the company email address of dashboard users;
  • the computer name and its time zone;
  • the name of the active application and the window title;
  • whether there was keyboard or mouse input in each interval;
  • the working time and breaks computed from the above;
  • the one-sentence summary produced by AI;
  • and, only if the Controller enables it, screenshots of the work computer’s screen — or, in text mode, only the text read from the screenshot on the employee’s own machine.

2.7. Special categories of data. The service requests no special category of data under Article 9 GDPR and is not designed to process any. Keeping such data out of the service is the Controller’s responsibility: the blocked-word list exists for exactly this, and personal banking and password managers are on it from day one.

3. Controller’s instructions

3.1. The Processor processes personal data only on the Controller’s documented instructions, including as regards international transfers, unless required to do otherwise by Union or Member State law; in that case the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.2. The following, taken together, constitute the Controller’s documented instructions: the terms of service, this DPA, the settings the Controller chooses in the dashboard — screenshots on or off, the blocked-word list, the retention period, whether the AI analyses — and any specific instruction sent in writing to privacy@puntavia.com.

3.3. If the Processor considers that an instruction infringes the GDPR or other applicable data protection law, it will tell the Controller and may hold that instruction until the point is clarified.

4. Confidentiality

4.1. The Processor ensures that every person authorised to process personal data under this DPA — staff, contractors and authorised sub-processors — is bound by appropriate contractual or statutory confidentiality obligations.

4.2. Access is granted on a need-to-know basis. Within the service, access to a company’s data is limited to that company’s own members and depends on each member’s role.

5. Security of processing

5.1. The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR), taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

5.2. The measures in force are described in Annex II. The Processor may update them over time, provided the level of security is not reduced.

5.3. The Processor claims no third-party certification and no external security audit: Annex II describes only what is actually in place.

6. Sub-processors

6.1. The Controller grants the Processor a general written authorisation to engage sub-processors in the provision of the service, subject to the safeguards in this section.

6.2. The list of authorised sub-processors is set out in Annex I and published, kept up to date, at https://puntavia.com/subprocessors, stating the name, purpose, data location and applicable transfer safeguard.

6.3. Before engaging a new sub-processor or replacing an existing one, the Processor will announce the change at least thirty (30) days in advance by publishing it on that page and notifying the Controller. The Controller may object on reasonable and demonstrable data protection grounds; if the Parties find no solution, the Controller may terminate the service.

6.4. The Processor enters into a written contract with each sub-processor imposing on it the same data protection obligations set out in this DPA, in particular sufficient guarantees that appropriate technical and organisational measures will be implemented (Article 28(4) GDPR).

6.5. The Processor remains fully liable to the Controller for the sub-processor’s performance of its obligations.

7. International transfers

7.1. The data are hosted in the European Union: the service runs on Hetzner Online GmbH servers located in Finland. The payment and email sub-processors handle data within the European Economic Area (EEA).

7.2. The only transfer outside the EEA is the one made to Anthropic PBC (United States) while the Controller keeps AI analysis enabled. That transfer is covered by the European Commission’s standard contractual clauses included in Anthropic’s data processing addendum. Customer data is not used to train models.

7.3. If the Controller turns AI analysis off in the dashboard, nothing is sent to Anthropic and no transfer outside the EEA takes place.

7.4. By accepting this DPA, the Controller authorises the Processor to enter into standard contractual clauses with sub-processors to the extent necessary to provide the service.

8. Data subject requests

8.1. Where the Processor receives a request from a data subject exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection) that relates to data processed on behalf of the Controller, the Processor:

  • will not answer the request itself, unless required by law;
  • will forward it to the Controller without undue delay;
  • will give the Controller, taking into account the nature of the processing, the reasonable assistance it needs to reply.

8.2. The dashboard itself lets the Controller satisfy those rights without involving the Processor: view an employee’s record, export all the data as a single file, and delete it permanently.

9. Assistance to the Controller

9.1. Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with its obligations under:

  • Article 32 (security of processing), by maintaining the measures in Annex II;
  • Articles 33 and 34 (personal data breach notification), in accordance with section 10;
  • Articles 35 and 36 (impact assessment and prior consultation), by providing information on what the service records, how often, and what settings are available.

9.2. This assistance is provided at no extra cost where it consists of the documentation the Processor publishes as a matter of course. For work beyond that, the Processor may charge a reasonable fee, notified in advance.

10. Personal data breach

10.1. On becoming aware of a security breach affecting personal data processed on behalf of the Controller, the Processor will notify the Controller without undue delay, with the information available at that moment.

10.2. The notification will include, so far as known:

  • the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address the breach and mitigate its effects;
  • the point of contact for further information: privacy@puntavia.com.

10.3. Where the information is not all available at once, the Processor will provide it in phases as it is obtained, and will cooperate reasonably with the Controller in the notifications the Controller must make to the supervisory authority (Article 33) or to data subjects (Article 34).

11. Return or deletion

11.1. At any time, from the dashboard itself, the Controller can export everything the service holds for its company — database, settings and screenshots — as a single file.

11.2. The Controller can also delete all of its company’s data permanently. Deletion removes the company’s whole folder; it does not merely flag a row as deleted.

11.3. On termination the data is deleted. Any copy remaining in backups disappears with the normal backup rotation.

11.4. The Processor will retain personal data after termination only where Union or Member State law requires it.

12. Audits and inspections

12.1. The Processor makes available to the Controller the information needed to demonstrate compliance with the obligations of Article 28 GDPR and of this DPA, and answers the Controller’s security questionnaires with the information available to it.

12.2. The Controller may carry out an on-site inspection on the following conditions, which the Parties consider proportionate:

  • on reasonable written notice;
  • at most once a year, unless a competent supervisory authority requires otherwise;
  • during business hours and without unreasonably interfering with the Processor’s operations;
  • at the Controller’s cost, with the auditor bound by confidentiality.

12.3. The Processor holds no third-party certification (such as ISO/IEC 27001 or SOC 2) and no external audit report, and does not offer any as a substitute for what this section provides.

13. Liability

13.1. Liability under this DPA is governed by the terms of service published at https://puntavia.com/terms.

13.2. Each Party bears the consequences of its own infringement. The allocation of liability between the Parties towards data subjects follows Article 82 GDPR.

14. Miscellaneous

14.1. This DPA is governed by Spanish law. Disputes are submitted to the courts of Barcelona.

14.2. This DPA is published in Spanish and English. The Spanish version prevails in the event of any discrepancy between them.

14.3. The version in force is the one published with the terms of service; the date in the heading identifies that version.

14.4. Any question about this DPA can be sent to privacy@puntavia.com or to Golova Europe SL, Calle l’Hospital 95, Planta 1, Puerta 2, 08001 Barcelona, Spain.

Annex I — Details of the processing and list of authorised sub-processors

A. Details of the processing:

  • Controller: the customer company that signs up for Puntavia.
  • Processor: Golova Europe SL, Tax ID B70717004, Calle l’Hospital 95, Planta 1, Puerta 2, 08001 Barcelona, Spain — privacy@puntavia.com.
  • Subject matter and purpose: measuring the working time of the Controller’s employees on their work computers and producing the daily record, the summaries and the reports the Controller receives.
  • Categories of data subjects: the Controller’s employees and contractors who work on the computers where the program is installed; the Controller’s staff who use the dashboard.
  • Categories of data: identification (name given by the employer, company email of dashboard users), computer name and time zone, name of the active application, window title, whether there was keyboard or mouse input in each interval, computed working time and breaks, the one-sentence AI summary and, only if the Controller enables it, screenshots — or, in text mode, only the text read from the screenshot on the employee’s machine.
  • Special categories: none requested; the Controller keeps them out by means of the blocked-word list.
  • Duration: for as long as the Controller uses the service, plus the time needed for deletion.

B. Authorised sub-processors:

  • Anthropic PBC (United States) — AI analysis of application names, window titles and, if enabled, screenshots. Safeguard: the European Commission’s standard contractual clauses included in Anthropic’s data processing addendum. Customer data is not used to train models.
  • Hetzner Online GmbH (Germany) — hosting. The servers used are in Finland (European Union). Safeguard: no transfer outside the EEA.
  • Stripe Payments Europe, Limited (Ireland) — payments and invoices. Processes the Controller’s billing data, not employee data. Safeguard: no transfer outside the EEA.
  • Resend (email delivery; sending region European Union, on Amazon SES) — delivery of reports, confirmation codes and password resets. Processes the recipient’s email address and the message body. Safeguard: no transfer outside the EEA.

The current list is published at https://puntavia.com/subprocessors. Any change is announced at least thirty (30) days in advance, in accordance with section 6.

Annex II — Technical and organisational measures

The Processor applies the following measures. They are described as implemented; no certification and no penetration test is claimed.

A. Separation of each customer’s data:

  • each customer company has its own separate database file, apart from every other company’s; there is no shared table with a company column;
  • deleting a company removes its whole folder rather than flagging a row.

B. Encryption and credentials:

  • all traffic between the computers, the dashboard and the server is encrypted with TLS;
  • passwords are stored derived with PBKDF2 and 600,000 iterations.

C. Access control:

  • access to a company’s data is limited to its own members and according to each member’s role;
  • screenshots are served privately and are never stored in public caches.

D. Server hardening:

  • the service runs as an unprivileged user, with a read-only file system and no additional system capabilities;
  • container memory and process limits.

E. Minimisation at source:

  • a list of blocked words that prevents the capture of sensitive windows, with personal banking and password managers on it from day one;
  • text mode: where the Controller chooses it, the screenshot is read on the employee’s own machine and only the resulting text is sent;
  • screenshots stay off unless the Controller turns them on.

F. Availability and integrity:

  • daily backups of the database, with an integrity check;
  • older copies disappear with the normal backup rotation.
Taal van het document: Español English