Data Processing Agreement

Version 1.1 · 16 August 2026

Applies across the EU The GDPR is a Regulation, so Article 28 applies directly and identically in every member state. This agreement is not specific to Spain: it covers all thirteen countries where Puntual operates.

1. The parties

This agreement governs the processing of personal data that studiosongear (the «Processor») carries out on behalf of the company using Puntual (the «Controller»).

This agreement does not apply to Puntual's local mode: there the data never leaves the device and we process nothing.

2. Subject matter, duration, nature and purpose

Subject matter: provision of the Puntual working-time recording service.

Nature and purpose: storing the clock-in records sent by devices, sealing their time of receipt, aggregating them so the Controller can consult them, and allowing their export. No other processing takes place.

Duration: for as long as the Controller uses the service, plus the retention period described in section 7.

3. Data processed and data subjects

Categories of data subjects: the Controller's workers and whoever administers the account.

Categories of data:

No special categories of data (Art. 9 GDPR) and no biometric data are processed. The Controller undertakes not to introduce them into the service.

4. Processor obligations

The Processor undertakes to:

5. Sub-processors

The Controller authorises the following sub-processors:

Sub-processorServiceLocation
Supabase Database, authentication and server functions European Union (Ireland)

As the data is hosted in the European Union, no international transfers requiring additional safeguards take place.

Should the Processor wish to add or replace a sub-processor, it will give reasonable prior notice and the Controller may object; in that case it may terminate this agreement without penalty.

The Processor will impose on any sub-processor the same obligations it assumes here, and remains liable to the Controller for their performance.

6. Security measures

The service applies, among others:

What we do not promise No measure is infallible and we do not claim the system is impenetrable. The service runs on third-party infrastructure and without a service level agreement. The Controller should take this into account when assessing its own risk.

7. Retention and return of data

The server does not keep records for the full statutory period. It acts as an intermediary that seals and aggregates, with limited retention depending on the plan. This is a characteristic of the service, not a defect, and the Controller must be aware of it.

The legal duty to retain records — four years in Spain, and a different period in each country — lies with the Controller as employer. Puntual therefore lets it download its full history at any time, in a readable and independently verifiable format, and reminds it periodically to do so.

On termination of the service, the Processor will delete the data unless legally required to retain it. The Controller is responsible for having downloaded its copies beforehand.

8. Controller instructions

The Controller's documented instructions are those contained in this agreement and those resulting from the use of the application's configuration features, such as enabling or disabling location at clock-in, adding or deactivating people, or exporting records.

If the Controller enables location at clock-in, it accepts that it is for the Controller to inform its workers in advance and, where applicable, their legal representatives, and to assess the proportionality of the measure.

9. Acceptance

This agreement is accepted when registering the company in Puntual. The date of acceptance and the version accepted are recorded. The version in force is always published on this page.

10. Contact

For any question about this agreement or about data processing: contacto@puntualpro.com.

See also the privacy policy.