This policy explains what data Punt (apunt.ie) (“we”, “us”) collects, why we collect it, and how we handle it.
Who is responsible for your data
For the Punt platform, Punt is the data controller. Your account, module progress, saved calculations and survey responses are ours to look after. We decide what is collected and why, and this policy explains how.
Some services are provided through your college. If your institution offers additional services through Punt, your college is the data controller for those, and Punt acts only as its data processor — handling information on its written instructions under a data processing agreement. A separate privacy notice covering those services is provided within your institution’s own section of the site, and requests about that data go to your college’s Data Protection Officer rather than to us.
What we collect
Account data: When you create an account, we collect your email address and password (stored securely by Supabase). You may optionally provide your first name and institution.
Usage data: We store your module progress (which steps you’ve completed) and any calculations you choose to save. This is used to provide the service — showing your progress and saved calculations when you return.
Survey responses: If you complete the Punt financial literacy survey, your responses are stored anonymously. If you optionally provide your email at the end of the survey, it is stored separately from your responses and is not linked to them.
Services provided through your college: If you use a service your institution offers through Punt, the information you submit is processed on your college’s behalf and is covered by the separate notice in your institution’s section of the site.
Cookies and local storage
We do not use analytics, advertising, or tracking cookies. There is no Google Analytics, no advertising pixel, and no third-party tracker anywhere on this site. We do not build a profile of you, and we share no device identifier with anyone.
Because of this, there is no cookie consent banner — there is nothing to consent to. The only things stored on your device are:
- Authentication cookies, set by our authentication provider (Supabase), which keep you signed in as you move between pages. These are strictly necessary to provide a service you have asked for, and are exempt from the consent requirement under the ePrivacy Regulations (S.I. 336/2011).
- An article rating identifier. If you rate a news article as helpful or not, we store a random identifier in your browser’s local storage so you are not asked the same question twice. It is created only when you choose to rate something, contains no personal information, and is never linked to your account.
You can clear both at any time through your browser settings. Clearing the authentication cookie will sign you out.
The fonts used on this site are served from our own servers, not from Google or any other third party, so viewing a page sends no data to a font provider.
Why we collect it
Account data — to provide the service you signed up for. Lawful basis: performance of a contract (Article 6(1)(b)).
Module progress and saved calculations — to deliver the features themselves and to improve the platform. Lawful basis: performance of a contract, and our legitimate interests in maintaining and improving the service (Article 6(1)(b) and (f)).
Survey emails — only with your consent, to send you the published research report (Article 6(1)(a)). You may withdraw that consent at any time.
Services provided through your college — the lawful basis is determined by your institution as controller, and is set out in the separate notice within your institution’s section of the site. Punt acts solely on its instructions.
Who we share it with
We do not sell your data. We do not share your data with advertisers or third parties for marketing purposes.
We use the following processors to operate the service:
- Supabase (database, authentication and document storage) — EU region
- Vercel (website hosting) — EU region
- Resend (transactional email) — account and service notifications
All processors operate under GDPR-compliant data processing agreements. Where a processor operates outside the European Economic Area, transfers are covered by Standard Contractual Clauses.
Where a service is provided on behalf of your college, these providers act as sub-processors to your institution, and it is notified of any change to this list.
How long we keep it
- Account and usage data — retained while your account is active, and for 24 months after your last sign-in.
- Data processed on behalf of your college — retained for the period set out in your institution’s own notice, then permanently deleted.
- Survey emails — deleted after the research report is sent.
- Survey responses — retained indefinitely in anonymous form, with no way to link them back to you.
How we protect it
- All traffic is encrypted in transit (HTTPS), and data is encrypted at rest.
- Database access is governed by row-level security, so records are only readable by the account they belong to or by staff explicitly authorised for that institution.
- Uploaded documents are held in private storage with per-user and per-institution access rules.
- Staff actions on an application — status changes, notes, decisions — are recorded in an audit log.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours and, where the risk is high, notify you directly without undue delay. Where we act as processor for your university, we notify them immediately so they can meet the same obligation.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Article 15)
- Correct data that is inaccurate or incomplete (Article 16)
- Erase your data in certain circumstances (Article 17)
- Restrict how we process your data (Article 18)
- Portability — receive your data in a machine-readable format, or have it transmitted to another provider (Article 20)
- Object to processing based on our legitimate interests (Article 21)
- Withdraw consent at any time, where we rely on consent
For your Punt account — email admin@apunt.ie. We will respond within one month, which may be extended by up to two further months for complex requests. We will tell you if that happens.
For a service provided through your college — your institution is the controller, so contact its Data Protection Officer. The address is given in the privacy notice within your institution’s section of the site. If you contact us instead, we will pass your request on promptly and tell you we have done so.
You also have the right to lodge a complaint with the Data Protection Commission (dataprotection.ie).
Changes to this policy
If we make a material change to how we handle your data, we will update this page and change the date at the top. Where a change affects data we process on behalf of a college, that institution is notified in advance.