Data Processing Agreement
1. The parties
This agreement governs the processing of personal data that studiosongear (the «Processor») carries out on behalf of the company using Puntual (the «Controller»).
- The customer company is the Controller. It decides what data is collected and why, it holds the legal duty to record working time, and it answers to its workers and to the supervisory authority.
- We are the Processor. We process that data solely to provide the service, on the Controller's instructions.
This agreement does not apply to Puntual's local mode: there the data never leaves the device and we process nothing.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Puntual working-time recording service.
Nature and purpose: storing the clock-in records sent by devices, sealing their time of receipt, aggregating them so the Controller can consult them, and allowing their export. No other processing takes place.
Duration: for as long as the Controller uses the service, plus the retention period described in section 7.
3. Data processed and data subjects
Categories of data subjects: the Controller's workers and whoever administers the account.
Categories of data:
- Identifying: name and email address.
- Working activity: clock-in, clock-out and break records with date and time; on-site or remote mode; issues; justified absences; monthly agreement with the recorded hours.
- Technical: device identifier, platform, app version and integrity-verification markers.
- Location, only if the Controller enables it: coordinates of the exact moment of each clock-in or clock-out. It is off by default. There is no continuous or background tracking.
- Shared-terminal PIN, if used: only a cryptographic derivation is stored, never the PIN itself.
No special categories of data (Art. 9 GDPR) and no biometric data are processed. The Controller undertakes not to introduce them into the service.
4. Processor obligations
The Processor undertakes to:
- Process the data only on the Controller's documented instructions, including this agreement, and never for its own purposes nor disclose it to third parties.
- Ensure that anyone with access to the data is bound by confidentiality.
- Apply the security measures in section 6.
- Assist the Controller where a worker exercises rights of access, rectification, erasure, restriction, portability or objection, insofar as possible given the nature of the service.
- Notify the Controller without undue delay of any personal data breach it becomes aware of, with the information needed for the Controller to meet its own notification duty.
- Assist the Controller with its obligations on security, breach notification and impact assessment (Arts. 32–36 GDPR).
- Make available the information needed to demonstrate compliance with these obligations and allow for audits, including inspections, by the Controller or an auditor it mandates.
- Immediately inform the Controller if, in its opinion, an instruction infringes data protection law.
5. Sub-processors
The Controller authorises the following sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Supabase | Database, authentication and server functions | European Union (Ireland) |
As the data is hosted in the European Union, no international transfers requiring additional safeguards take place.
Should the Processor wish to add or replace a sub-processor, it will give reasonable prior notice and the Controller may object; in that case it may terminate this agreement without penalty.
The Processor will impose on any sub-processor the same obligations it assumes here, and remains liable to the Controller for their performance.
6. Security measures
The service applies, among others:
- Isolation between companies at database level, so that no query can return another company's data.
- Role-based access control (worker, manager, administrator).
- Encryption in transit for all communications.
- Non-modifiable records: clock-ins are never edited or deleted; a correction is added as a new entry alongside the original, recording who approved it.
- Integrity verification: each record is chained to the previous one with a cryptographic fingerprint, and exports include an annex allowing independent verification that the data has not been altered.
- Server-side time sealing on receipt of each record.
7. Retention and return of data
The server does not keep records for the full statutory period. It acts as an intermediary that seals and aggregates, with limited retention depending on the plan. This is a characteristic of the service, not a defect, and the Controller must be aware of it.
The legal duty to retain records — four years in Spain, and a different period in each country — lies with the Controller as employer. Puntual therefore lets it download its full history at any time, in a readable and independently verifiable format, and reminds it periodically to do so.
On termination of the service, the Processor will delete the data unless legally required to retain it. The Controller is responsible for having downloaded its copies beforehand.
8. Controller instructions
The Controller's documented instructions are those contained in this agreement and those resulting from the use of the application's configuration features, such as enabling or disabling location at clock-in, adding or deactivating people, or exporting records.
If the Controller enables location at clock-in, it accepts that it is for the Controller to inform its workers in advance and, where applicable, their legal representatives, and to assess the proportionality of the measure.
9. Acceptance
This agreement is accepted when registering the company in Puntual. The date of acceptance and the version accepted are recorded. The version in force is always published on this page.
10. Contact
For any question about this agreement or about data processing: contacto@puntualpro.com.
See also the privacy policy.