Home / Privacy Policy

Legal · GDPR

Privacy Policy

How puniq UG collects, uses and protects personal data, in line with the EU General Data Protection Regulation (GDPR).

GDPR-aligned We do not sell data Last updated 21 June 2026

Minimal by design

We collect only the data we need to run the site and answer your enquiry. Nothing speculative, nothing for sale.

Your rights, honoured

Access, correction, erasure and more, free of charge, within the timeframes the GDPR requires.

German rigor

The same engineering discipline we bring to buildings, applied to encryption, access control and retention.

Template wording for review by counsel.

Last updated: 21 June 2026. This policy explains what personal data we process when you visit puniq.de or contact us, why we process it, the legal basis under the GDPR, and the rights you hold over your data.

1. Who is responsible (Controller)

The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:

Full registered address and registration details are available on our Impressum. For any question about this policy or about how your data is handled, write to us at contact@puniq.de.

2. What data we collect

We keep data collection to the minimum needed to run our website and respond to enquiries. We process the following categories of personal data:

Contact-form and enquiry data

When you use our contact form, request an assessment, or email us, we process the details you choose to provide:

  • Name
  • Email address
  • Company (where given)
  • Phone number (optional)
  • The message and any project details you include, plus the type of project selected

Newsletter data

If you subscribe to our newsletter, we process the email address you submit so we can send you updates. You can unsubscribe at any time.

Technical data

When you visit the site, our hosting provider automatically processes standard server log data such as your IP address, browser type, the pages requested, and the date and time of access. This is needed to deliver the site securely and to detect and prevent abuse.

3. Why we use it and the legal basis

We process personal data only where the GDPR gives us a lawful basis to do so:

  • To respond to your enquiry and discuss a possible engagement. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering a contract) and Art. 6(1)(f) GDPR (our legitimate interest in answering business enquiries).
  • To send newsletter updates you asked for. Legal basis: Art. 6(1)(a) GDPR (your consent), which you may withdraw at any time.
  • To operate, secure and maintain the website. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a stable, secure service).
  • To comply with legal obligations, for example tax or commercial record-keeping. Legal basis: Art. 6(1)(c) GDPR.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to such processing as set out in section 7.

puniq does not sell, rent or trade your personal data, and we never use it for automated decision-making or profiling.

4. We do not sell your data

puniq does not sell, rent or trade your personal data. We do not use it for automated decision-making or profiling. We share data only with the service providers needed to run our business, as described in the next section, and only where they are bound to protect it.

5. Processors and hosting

We use carefully selected service providers (processors) to host and operate this website and to handle enquiries. Each acts only on our instructions under a data-processing agreement pursuant to Art. 28 GDPR. These include:

  • Website and database hosting, to deliver the site and store contact submissions.
  • Email and communication tools, to receive and reply to your messages.

Where a provider processes data outside the European Economic Area, we ensure an adequate level of protection through an EU adequacy decision or the EU Standard Contractual Clauses. We do not transfer personal data to third countries without such safeguards in place.

6. How long we keep it

We retain personal data only as long as needed for the purpose it was collected, or as required by law:

  • Enquiry data is kept for the duration of our correspondence and for a reasonable period afterward so we can follow up, then deleted unless it becomes part of a contractual relationship.
  • Newsletter data is kept until you unsubscribe.
  • Data subject to statutory retention (for example tax records) is kept for the legally required period, typically up to ten years under German commercial and tax law.
  • Server logs are kept for a short period for security purposes, then deleted or anonymised.

7. Your rights

Under the GDPR you have the following rights regarding your personal data. You can exercise any of them free of charge by contacting us:

  • Access (Art. 15) — a copy of the data we hold about you.
  • Rectification (Art. 16) — correction of inaccurate or incomplete data.
  • Erasure (Art. 17) — deletion of your data where there is no lawful reason to keep it.
  • Restriction (Art. 18) — limiting how we process your data in certain cases.
  • Data portability (Art. 20) — receiving your data in a structured, machine-readable format.
  • Objection (Art. 21) — objecting to processing based on legitimate interests.
  • Withdraw consent (Art. 7) — at any time, without affecting prior lawful processing.

You also have the right to lodge a complaint with a supervisory authority. In Germany, this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

8. Cookies and analytics

We aim to keep tracking to a minimum. We use only the cookies strictly necessary to operate the website. If we use analytics to understand how the site is used, we do so in a privacy-respecting way: analytics are configured to limit personal data, and any non-essential analytics or cookies are set only with your consent, which you can change or withdraw at any time. We do not use third-party advertising cookies.

9. Data security

We apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, including encrypted connections (TLS) for data in transit and access controls on the systems that store enquiry data. This reflects the same German engineering rigor we bring to the buildings we work on.

10. Changes to this policy

We may update this policy to reflect changes in our services or in the law. The current version is always published on this page with its effective date. Material changes will be made clear here.

11. How to contact us

To exercise your rights, ask a question, or raise a concern about your data, contact us at contact@puniq.de or through the . We respond within a reasonable timeframe and at the latest within the period required by the GDPR.

Template wording for review by counsel.

More legal

The rest of the small print

Questions about your data?

Reach the puniq team directly. We will answer clearly and act on any request within the timeframes the GDPR requires.

العربية