punkolink
L7 Cloud Solutions Blog Sign In to Console Join Us

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains what personal data we collect when you use the Punkolink service (the websites punkolink.com and cloud.punkolink.com — together, the "Service"), for what purposes and on what legal basis we process it, with whom we share it, and what rights you have as a data subject. Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR).


1. Who is responsible for processing your data (Controller)

The controller of your personal data is:

  • Controller: Strizhkov Hlib (individual)
  • Address: 61022, Kharkiv, Svobody Square, 5, Ukraine
  • Privacy contact: support@punkolink.com

We have not appointed a Data Protection Officer (DPO), as we do not carry out large-scale systematic monitoring and do not process special categories of data. For any questions relating to the processing of your data or the exercise of your rights, please contact us at the address above.


2. What data we collect, for what purpose, and on what legal basis

We process the minimum set of data necessary to operate your account.

2.1. Email address

  • What it is: your real email address. Stored in plain text.
  • Purpose: creating your account, signing in, identifying you as a user, and sending service-related messages.
  • Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract (providing you access to the Service).
  • Requirement: providing an email address is mandatory. Without it, creating an account and using the Service is not possible.

2.2. Password

  • What it is: we do not store your password. Only its cryptographic hash (bcrypt algorithm) is stored in the database, from which the original password cannot be recovered.
  • Purpose: authentication — verifying that it is indeed you accessing the account.
  • Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

2.3. Email verification token (email_verification_token)

  • What it is: a temporary technical token sent to you to confirm ownership of the specified address.
  • Lifetime: no more than 24 hours; deleted immediately after the address is confirmed.
  • Purpose: confirming that the email address belongs to you and preventing registrations using other people's addresses.
  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract) — address confirmation is part of the registration process.

2.4. IP address

  • What it is: the IP address from which your requests to the Service are made.
  • Purpose: security of the Service and protection against abuse (for example, defence against brute-force attempts and other malicious activity).
  • Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the Service secure.
  • Retention: security logs containing IP addresses are retained for up to 90 days and then deleted.
  • We do not use IP addresses for tracking, profiling, analytics, or advertising, and we do not share them with third parties.
  • Right to object: because this processing is based on legitimate interest, you have the right to object to it under Art. 21 GDPR.

2.5. Data from Google sign-in (optional)

If you choose to sign in with Google, we receive from Google your email address and a Google account identifier, and we use them to create or access your account. Your email is treated as verified by Google.

  • This happens only if you choose Google sign-in; it is not required to use the Service (you may register with email and password instead).
  • Legal basis: performance of the contract — to authenticate you and provide access to your account.
  • We store the Google account identifier to link your account to your Google sign-in.
  • Google may also provide your name; we do not store it.

3. What data we do NOT collect

In line with the data minimisation principle (Art. 5(1)(c) GDPR), we deliberately do not collect or store:

  • full name;
  • phone number;
  • postal or physical address;
  • payment data (card number, payment details, etc.).

4. With whom we share data

We do not sell your data and share it with third parties only to the extent necessary to operate the Service.

4.1. Brevo.com (SENDINBLUE) — processor. Hereinafter referred to as Brevo

We use Brevo to send emails (in particular, the registration confirmation email).

  • What is shared: your email (as the recipient address) and a link containing the confirmation token in the body of the email.
  • Role: Brevo acts as a processor on our behalf and in accordance with our instructions. A Data Processing Agreement has been concluded with Brevo in accordance with Art. 28 GDPR.
  • Where data is processed: within the European Union.
  • More information: Brevo Privacy Policy — https://www.brevo.com/legal/privacypolicy/

4.2. Stripe — payment processing

We use Stripe to process payments. It is important to understand the separation of roles:

  • What we share: when you initiate a purchase, our server creates a payment session with Stripe and associates it with an internal user identifier (a pseudonymous technical identifier). This identifier does not contain your email or payment data.
  • What Stripe collects itself: Stripe collects your email and payment data (card details, etc.) directly from you at the time of payment. We neither receive nor store your payment-card data.
  • Role: with respect to the payment data it collects, Stripe acts as an independent controller and processes it under its own privacy policy.
  • More information: Stripe Privacy Policy — https://stripe.com/privacy

4.3. Google — sign-in

If you choose to sign in with Google, authentication is performed by Google. In that process Google acts as an independent controller and processes your data under its own privacy policy. We receive from Google only your email address and a Google account identifier, used to create or access your account. We do not grant Google access to your data within the Service, and we do not use Google sign-in for tracking, profiling, or advertising.

  • More information: Google Privacy Policy — https://policies.google.com/privacy

5. International data transfers

  • Brevo processes data within the European Union, so there is no cross-border transfer of personal data outside the EU/EEA in this respect.
  • Stripe is a US-based payment services provider. Where payment data is processed by Stripe outside the EU/EEA, such transfers rely on the safeguards described in Stripe's privacy policy (for example, Standard Contractual Clauses). See the Stripe Privacy Policy for details.
  • Google is a US-based provider. Where data is processed by Google outside the EU/EEA in connection with Google sign-in, such transfers rely on the safeguards described in Google's privacy policy (for example, Standard Contractual Clauses). See the Google Privacy Policy for details.

6. Retention periods

  • Email and password hash — stored for the entire duration of your account. After the account is deleted, the data is removed within a reasonable period, except where longer retention is required by law.
  • Email verification token — no more than 24 hours; deleted immediately after the address is confirmed.

7. Your rights

Under the GDPR (Arts. 15–21), you have the right:

  • of access — to obtain confirmation of processing and a copy of your data;
  • to rectification — to correct inaccurate or incomplete data;
  • to erasure ("right to be forgotten") — to request the deletion of your data;
  • to restriction of processing — in the cases provided for by law;
  • to data portability — to receive your data in a structured, machine-readable format;
  • to object to processing in the applicable cases.

To exercise any of these rights, write to us at support@punkolink.com. We will respond within one month of receiving your request (this period may be extended in the cases provided for by the GDPR, of which we will notify you).


8. Right to lodge a complaint

If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with a data protection supervisory authority — in particular, with the supervisory authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available on the website of the European Data Protection Board (EDPB).


9. Automated decision-making and profiling

We do not carry out automated decision-making producing legal effects concerning you, and we do not carry out profiling within the meaning of Art. 22 GDPR.


10. Cookies and tracking

We use only strictly necessary (technical) cookies required to operate the Service and to sign in to your account. We do not use analytics, advertising, or any other trackers. Since strictly necessary cookies do not require consent under the ePrivacy Directive, no cookie banner is used.


11. Additional information for UK users

If you are in the United Kingdom, your personal data is processed in accordance with the UK GDPR and the Data Protection Act 2018. The rights described in this Policy apply equally. You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).


12. Additional information for California residents

We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), including disclosure for advertising purposes. Accordingly, we do not provide a "Do Not Sell or Share My Personal Information" link, as it is not applicable.

We do not use tracking, analytics, advertising, or profiling.

Categories of personal information we collect: identifiers (email address), provided by you at registration. We process an IP address for security as described in Section 2.4.

California rights: you have the right to know what personal information we hold, to request its deletion, to request correction, and not to be discriminated against for exercising these rights. To exercise these rights, contact support@punkolink.com.


13. Additional information for Canadian users

If you are in Canada, your personal data is processed in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect the minimum necessary, do not sell your data, and do not use tracking or profiling. You may address concerns to the Office of the Privacy Commissioner of Canada.


14. Security and changes to this policy

Security. We apply technical and organisational measures to protect data (Art. 32 GDPR), including password hashing (bcrypt) and encryption of the data transmission channel (HTTPS/TLS).

Changes. We may update this Policy from time to time. The current version is always available on this page; the date of the last revision is indicated at the top of the document. In the event of material changes, we will notify you by an available means.

punkolink
L7 Solutions Pricing Blog
Legal Terms of Use Refund Policy Privacy Policy Pricing Policy
© 2026 Punkolink — L7 routing. Full stop.