puntavia.
Português ▾
Experimentar 3 dias

Privacy policy

5 September 2026 · Golova Europe SL

Puntavia measures working time without reading what you type: this policy explains which data are processed, on what legal basis, and who each person should turn to.

1. Introduction

1.1. This Privacy Policy (the "Policy") describes how Golova Europe SL ("Golova", "we") collects, uses, discloses and protects personal data in connection with the website puntavia.com and with Puntavia, the cloud service that measures actual working time on a company's computers (together, the "Service").

1.2. This Policy is published in compliance with Regulation (EU) 2016/679 (the "GDPR") and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (the "LOPDGDD"), which apply to Golova as a company established in Spain.

1.3. Two distinct roles exist within the Service, and they determine who is answerable for the data and whom each person should address:

  • Golova Europe SL is the CONTROLLER for visitors of puntavia.com and for the people who register an account: the owner of the customer company's account, the administrators and the viewers with read-only access.
  • Golova Europe SL is only the PROCESSOR for the employees whose working time is measured. In that case the controller is the customer company itself, which decides what is measured and for how long it is kept; Golova acts on its documented instructions under the Data Processing Agreement available at https://puntavia.com/dpa.

1.4. Identification of the controller:

  • Company name: Golova Europe SL
  • Tax ID (CIF): B70717004
  • Registered office: Calle l'Hospital 95, Planta 1, Puerta 2, 08001 Barcelona, Spain
  • Email: privacy@puntavia.com
  • Telephone: +34 672 390 777
  • Supervisory authority: Spanish Data Protection Agency (AEPD), www.aepd.es

1.5. Golova has not appointed a Data Protection Officer, as the conditions requiring one under Article 37 GDPR are not met. All data protection matters are handled at privacy@puntavia.com.

1.6. This Policy does not apply to websites or services operated by third parties, even where they are reachable through links from the Service.

2. Definitions

2.1. For the purposes of this Policy:

  • Personal data: any information relating to an identified or identifiable natural person (Article 4(1) GDPR).
  • Processing: any operation performed on personal data (collection, recording, storage, retrieval, use, disclosure, erasure, and so on).
  • Data subject: the natural person to whom the personal data relate.
  • Controller: the entity that determines the purposes and means of the processing.
  • Processor: the entity that processes personal data on behalf of the controller and on its instructions.
  • Customer: the company or organisation that subscribes to the Service and registers an account in Puntavia.
  • Employee: the natural person whose working time is measured with the Service by decision of their employer, that is, of the Customer.
  • Agent: the program the Customer installs on work computers, which records the activity intervals described in section 3.
  • Dashboard: the Puntavia web interface where the Customer reviews hours, reports and the settings of its company.
  • Service: the website puntavia.com, the Dashboard and the Agent, taken together.

3. Categories of data subjects and personal data

3.1. We process personal data of the following categories of data subjects:

  • Visitors of the website puntavia.com (Golova is the controller).
  • People registered in an account: the owner, the administrators and the read-only viewers (Golova is the controller).
  • Employees of a customer company whose working time is measured with the Service: here the customer company is the controller and Golova is only the processor, as set out in section 12.

3.2. Account data we process as controller:

  • Identification and contact data: name and email address.
  • Sign-in data: password, stored only as a hash, and the chosen interface language.
  • Organisation data: company name and the person's role within the account (owner, administrator or viewer).
  • Sign-in log: date and time, IP address and browser user agent.
  • Billing data: processed by Stripe as our payment provider; Golova does not store card details.

3.3. Data the Service processes on behalf of the customer company, collected by the Agent in each measurement interval:

  • The name of the active application.
  • The title of the active window.
  • Whether there was keyboard or mouse input during the interval, recorded as a yes or a no, without storing what was pressed.
  • The time zone and the local time of the computer.
  • The computer name and the person it is assigned to.

3.4. Screenshots are switched off by default and are taken only if the customer company enables them. There is also a mode in which the screenshot is read on the employee's own computer and only the extracted text is sent: the image is deleted immediately and never reaches our servers.

3.5. The Service keeps a list of blocked words. If one of them appears in the application name or in the window title, the title is replaced with "[hidden]" and no screenshot is taken. Personal banking and password managers are on that list from day one.

3.6. The Service never processes the following, not even when the Customer enables every available feature:

  • Keystrokes (the Service does not record what is typed).
  • The contents of messages or documents.
  • Location data.
  • Camera.
  • Microphone.
  • Personal files on the computer.

4. Purposes and legal bases of processing

4.1. We process personal data solely for the purposes set out in this section and on the basis of one or more of the legal bases in Article 6(1) GDPR.

4.2. Performance of the contract (Article 6(1)(b) GDPR). Creation and management of your account, provision of access to the Dashboard, operation of the Agent, calculation of hours, technical support and Service-related communications.

4.3. Legitimate interest (Article 6(1)(f) GDPR). Security of the Service, prevention of fraud and abuse, and keeping the Service working, including the sign-in log and error diagnostics. You may object to this processing at any time as set out in section 9.

4.4. Legal obligation (Article 6(1)(c) GDPR). Issuing and keeping invoices and complying with Spanish accounting and tax obligations.

4.5. Employee data. The legal basis for processing the data measured by the Agent is determined by the customer company as controller, and is usually its own legal obligation to keep a daily record of working time, together with its legitimate interest in organising and verifying work. It is for the customer company to inform its employees and to ensure that this legal basis is valid; Golova neither chooses it nor replaces it.

4.6. Summary of purposes:

  • Account and authentication: legal basis, performance of the contract; data, identification, sign-in and organisation; retention, for as long as the account exists.
  • Working-time measurement and reports: legal basis, as determined by the customer company; data, those listed in section 3.3; retention, as set by the customer company within the periods in section 8.
  • Security and access logs: legal basis, legitimate interest; data, IP address, user agent and sign-in time.
  • Payments and invoicing: legal basis, performance of the contract and legal obligation; data, billing data; retention, six years.

5. How we collect personal data

5.1. Directly from you, when you register an account, configure your company, write to us or make a payment.

5.2. Automatically, through the Agent installed by the customer company on its work computers, which collects the data listed in section 3.3, and through server logs, which record sign-ins with the IP address and user agent.

5.3. From third parties, in a single case: from Stripe we receive the outcome of a transaction and the data needed to issue the invoice.

6. Recipients of personal data and processors

6.1. We do not sell, rent or trade personal data, and we never share it for advertising purposes.

6.2. We use the following processors, bound by contracts compliant with Article 28 GDPR:

  • Anthropic PBC (United States): AI analysis of application names, window titles and, if the customer company has enabled them, screenshots. Customer data is not used to train models.
  • Hetzner Online GmbH (Germany, with its data centre in Finland, EU): hosting of the Service.
  • Stripe Payments Europe, Limited (Ireland): payment processing and invoicing.
  • Resend: email delivery, with the sending region in the EU on Amazon SES.

6.3. No other third party receives the data processed in the Service.

6.4. As regards employee data, these providers are sub-processors: Golova engages them in its capacity as processor for the customer company and on the terms of the Data Processing Agreement published at https://puntavia.com/dpa.

7. International transfers

7.1. The hosting, databases, backups and email delivery of the Service remain within the European Union.

7.2. The only transfer of personal data outside the European Economic Area is the one made to Anthropic PBC, in the United States, for the AI analysis described in section 6.

7.3. That transfer is covered by the standard contractual clauses adopted by the European Commission and by the supplementary measures set out in Anthropic's data processing addendum.

7.4. You may request information about the safeguards applied to this transfer by writing to privacy@puntavia.com.

8. Retention periods

8.1. Each customer company has its own database file, separate from every other company's, and the periods below apply within that file.

8.2. Applicable periods:

  • Screenshots: deleted after 60 days.
  • Activity records and measured intervals: deleted after one year, unless the customer company sets a different period in its account settings.
  • Deletion of a company from the Dashboard: the company's whole folder, with its database and its files, is removed; it is not flagged as deleted or kept out of sight.
  • Account data: kept for as long as the account exists and deleted when it ceases to exist.
  • Invoices and accounting records: kept for the period required by Spanish tax law, six years.

8.3. The customer company may shorten the periods in section 8.2 that concern its employees' data and may delete any record earlier from its Dashboard.

9. Your rights as a data subject

9.1. Under Articles 15 to 22 GDPR, you have the right to:

  • Access: to know whether we process your data and to obtain a copy.
  • Rectification: to correct inaccurate or incomplete data.
  • Erasure: to request the deletion of your data.
  • Restriction of processing.
  • Portability: to receive your data in a structured, commonly used and machine-readable format.
  • Objection to processing based on our legitimate interest.
  • Lodging a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or with the supervisory authority of your habitual residence.

9.2. To exercise any of these rights, write to privacy@puntavia.com stating the right you wish to exercise and the information needed to identify you. Where there is reasonable doubt about your identity, we may ask for additional information.

9.3. We will answer within one month of receiving the request.

9.4. If you are an employee whose working time is measured with Puntavia, your employer is the controller: requests for access, deletion or an explanation must be addressed to it. If such a request reaches us directly, we forward it to the relevant customer company without undue delay and assist it in responding, as required by the Data Processing Agreement.

10. Security of personal data

10.1. We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), in particular:

  • A separate database for each customer company, in its own file.
  • Encrypted transport for all traffic between the Agent, the browser and the server.
  • Passwords stored with PBKDF2, never in clear text.
  • Access to a company's data reserved to its own members and limited by the role each of them holds in the account.
  • Regular backups of the Service data.
  • The server run by an unprivileged user with a read-only file system.

10.2. In the event of a personal data breach involving a risk to the rights and freedoms of natural persons, we will notify the AEPD without undue delay and, where feasible, within 72 hours, and will inform the affected data subjects where the risk is high (Articles 33 and 34 GDPR).

11. Automated decisions and AI features

11.1. The Service uses artificial intelligence to write a readable summary of the recorded activity from application names, window titles and, if the customer company has enabled them, screenshots.

11.2. The hours are not decided by the AI: they are computed by the server from the measured intervals, and the result is always visible in the Dashboard and can be exported.

11.3. We do not take decisions based solely on automated processing that produce legal effects or similarly significantly affect data subjects within the meaning of Article 22 GDPR. Any employment consequence drawn from the data is a decision of the customer company, taken by people.

11.4. Customer data is not used to train AI models.

12. Processing of employee data on behalf of Customers

12.1. Where a customer company installs the Agent and measures the working time of its employees, that company is the controller within the meaning of Article 4(7) GDPR and Golova acts solely as processor, on its documented instructions.

12.2. The conditions of this processing are governed by the Data Processing Agreement that forms part of the Customer's contract and is available at https://puntavia.com/dpa.

12.3. Within what the Service allows, the customer company decides whether screenshots are enabled, whether the mode that sends only the extracted text is used, which words are added to the blocked list, how long records are kept and who in its organisation may consult them.

12.4. An employee who wants access to their data, its deletion or an explanation must address their own employer. If such a request reaches us directly, we forward it to the customer company without undue delay.

12.5. It is for the customer company to inform its employees that their working time is measured, which data are collected and on what legal basis, before the measurement begins.

13. Privacy of minors

13.1. The Service is intended for professional use and is not aimed at people under 16 years of age. We do not knowingly process their personal data.

13.2. If you become aware that a minor has provided personal data to us, write to privacy@puntavia.com and we will delete it.

14. Updates to this Policy

14.1. We may update this Policy to reflect changes in the Service, in the providers we use or in the applicable legal requirements.

14.2. Where the change is material (for example, where it affects the categories of data processed, the purposes, the legal bases, the processors, the retention periods or the international transfers), we will notify registered Customers by email or by a visible notice in the Dashboard before it takes effect.

14.3. Minor changes, such as clarifications or wording corrections, take effect on publication. The current version always carries the date of the last update and is available at puntavia.com.

15. Final provisions

15.1. This Policy is published in Spanish and English. In the event of a discrepancy between the two versions, the Spanish version prevails, unless the Customer concluded the contract in English, in which case the English version prevails.

15.2. If any provision of this Policy is held invalid or unenforceable, the remaining provisions continue in full force and effect.

15.3. Enquiries, requests and complaints concerning this Policy may be addressed to privacy@puntavia.com or to Golova Europe SL, Calle l'Hospital 95, Planta 1, Puerta 2, 08001 Barcelona, Spain.

Idioma do documento: Español English