Legal
Privacy policy
This policy explains what data we process on this website and, at a general level, in our products. It covers why we process it, how long we keep it, who we share it with, and the rights you have.
Last updated: 4 August 2026
Who we are and what this covers
Punfyre BV is the controllerThe organisation that decides why and how personal data gets used, and is answerable for it. for the personal data we process as a company. This privacy policy explains which data we process, why we do so, who we share it with, how long we keep it and which rights you have.
- Controller
- Punfyre BV, Vlamingstraat 4, 8560 Wevelgem, Belgium
- Company number
- KBO 0749.930.853, RPR Gent, division Kortrijk
- VAT number
- BE 0749.930.853
- Privacy questions
- privacy@punfyre.be
This is Punfyre's umbrella privacy policy. It covers three things: the company itself, this website, and at a general level the products we build and offer, such as Alarmira and Routeez.
A product may have its own privacy statement that goes into further detail, for instance on the precise data the app needs, the retention periodsHow long data is kept before it is deleted, decided in advance rather than left open. that apply there or the parties involved. Where such a product statement exists, it adds to this text and prevails for that product. Where it is silent, what is written here applies.
Definitions
Privacy texts are full of jargon. These are the words you will meet below, explained in plain language.
- Personal data
- Any information that makes you identifiable as a person, directly or indirectly. Your name and email address count, but so do an IP address or a device identifier.
- Processing
- Just about anything you can do with data: collecting, storing, viewing, using, sending on, changing, anonymising or deleting it.
- Controller
- Whoever decides why and how data is processed. For the processing in this policy that is Punfyre BV.
- Processor
- A party that processes data on our behalf and according to our instructions, for instance a hosting provider. A processor may not use the data for its own purposes.
- Data subject
- The person the data is about. If you are reading this text about your own data, that is you.
- Personal data breach
- A security incident in which data is lost, changed without intent or reaches someone who should not have it. In everyday language: a data leak.
- Special categories of personal data
- Extra sensitive data for which the law sets stricter rules, such as data about health, biometric data that identifies someone, or data about beliefs or sexual orientation.
- Consent
- A free, clear and informed choice to allow a particular processing activity. You can always withdraw consent, and refusing has no consequences beyond the feature itself.
Who the data is about
Which data we hold about you depends on the relationship we have with you. Someone who asks a single question through the website leaves something very different behind than someone who uses one of our products every day. That is why we distinguish four roles below.
Visitors and people who contact us
If you only visit the website or send us a message, it stays at the strict minimum: what you fill in yourself, the standard technical logs of our servers and a few preferences in your own browser. We build no visitor profile and we do not follow you from page to page.
Customers and contract contacts
If we work together under an agreement, we also process business contact details, the correspondence about the project or service, and the administration that goes with it: orders, invoices, payment status and agreed arrangements. If you send something back or invoke the guarantee, we also process the data in that file; how a return works in practice is on our returns page.
Users of a product
If you use one of our products, we process the data that product needs to do what it promises. What that means varies a great deal: an app that can send an alarm in an emergency needs more than an app that only shows an overview.
Third parties whose data a user gives us
Sometimes a user gives us data about someone else, for instance the name and phone number of an emergency contact. That person gave us nothing themselves and may not even know we exist.
Even so, that person has exactly the same rights as everyone else in this policy, and an email to privacy@punfyre.be is enough to exercise them.
What data we process
The part about the website is complete: if it is not listed there, we do not do it. The part about products is written conditionally, because not every product has the same features. If your product does not process a particular kind of data, that part does not apply to you.
Contact and support forms
When you send us a message through the contact or support form, we process the data you fill in yourself:
- your name
- your email address
- the topic you choose
- the content of your message
Your message reaches us as an email and is handled as business correspondence. We use it solely to answer your question and follow up on it. We do not add your address to a mailing list and we do not use your message for any other purpose.
To keep spam and abuse out, the forms are protected by a hidden honeypot field, a signed timestamp, rate limiting and optionally a cookieless proof-of-work check called Altcha. These measures work without tracking: no profile is built about you and no cookies are set for them.
If you email us directly instead of using the form, exactly the same applies: we treat your message as business correspondence and use it only to reply to you.
Planning a meeting
When you plan a meeting through the agenda on this website, we process your name, email address, chosen time and timezone, your choice of Google Meet or phone, your phone number where applicable, and any optional note you provide. We use those details only to schedule the meeting, send the calendar invitation and hold the conversation.
The Cal.com scheduling software runs on our own infrastructure. The appointment is added to our Google Workspace calendar; if you choose Google Meet, Google Workspace also creates the meeting link. Confirmations and cancellation or rescheduling links are sent by email.
Technical website data
Like almost every website, our servers and hosting environment keep standard log files. These contain, among other things, your IP address and technical data about your request, such as the page requested and the time.
We use these logs only to keep the website secure and running: detecting attacks, investigating incidents and preventing abuse. We do not use them to analyse your browsing behaviour.
Browser storage
We set a cookie that remembers your language choice and store a few preferences locally in your browser, such as your theme choice and optionally a remembered email address. That remembered email address stays in your own browser and is never sent to us.
The full details, with the name and retention period of each item, are in our cookie policy. You manage your choices for non-essential storage through the cookie banner, and you can change them there at any time.
Account and profile data
If a product works with accounts, we process what is needed to create, secure and manage that account: your name or a username, your email address, possibly your phone number, your language and notification preferences and the status of your subscription.
We never store passwords in readable form. We store only an encrypted derivation that lets us verify your sign-in, without us knowing or being able to recover your password.
Order, billing and payment data
If a product sells something, for instance a device or a subscription, we process your order, your billing details and where needed a delivery or installation address.
The payment itself runs through a payment provider. It receives the data needed to carry out the payment and processes it under its own privacy policy for what it has to do itself. We see the result of the payment and the details on your invoice, not your full card details.
Invoices and the accounting records that go with them must be kept by law. That means we cannot erase this data while that retention duty runs, not even on request.
Device and technical data in a product
An app or service exchanges technical data in order to work: the device type and operating system, the app version, a technical identifier for the installation, error reports and connection data.
Where a product works together with an accessory, for instance an alarm button over Bluetooth, that also includes pairing status, signal and battery status.
We use this data to find faults, watch over reliability and prevent abuse. Not to analyse your behaviour or to build profiles.
Location data
If a product offers location features, we process your location only where the feature you are using needs it, and only after you have granted the permission on your device. You can withdraw that permission at any time in your phone settings.
With a safety product, location can be the difference between being found and not being found. Such a product may therefore send your location along when you start an alarm or when it detects an incident. If you withdraw the permission, the product keeps working, but without the features that need location.
Audio and camera recordings
If a product records sound or images during an incident, it does so in a targeted and limited way: around the moment of the incident, so the situation can be assessed and answered appropriately. Such a recording is not continuous surveillance and does not serve to follow you.
Where a product has this feature, that product's own statement explains when a recording starts, who may view or listen to it and how long it is kept.
Health and other sensitive data
Some safety features only work if sensitive information is available, for instance a medical note that responders need to know or a detail about medication. Where a product offers this, you fill that information in yourself, and only if you want to.
We ask for your explicit consent for it and use the information solely for the safety purpose you gave it for. The next part sets out exactly which rules apply.
Emergency contact data
If a product lets you choose who gets alerted, we process the name and contact details you fill in for that person, plus the role you give them, for instance first contact or second contact.
We use that data only to reach that person in the situation you added them for, and to show you whether that worked.
Support conversations
If you contact support from within a product, we process the conversation itself and the technical context you send along, such as log files or a screenshot.
We use that to solve your problem and, in aggregated or anonymised form, to fix recurring problems at the root.
Special categories of personal data
Data about health, biometric data that identifies someone and comparably sensitive data fall under a stricter regime. Our starting point is that we do not process them, unless a product needs them for a safety purpose.
Where that is the case, we do so only on the basis of your explicit consent or another valid ground under Article 9 of the GDPR, for instance the protection of vital interests when someone is in danger and can no longer give consent themselves.
You can withdraw your consent at any time. That has a clear consequence: the feature resting on that data will no longer work, and information you had stored for responders will no longer be passed on during a future incident. What we lawfully processed before the withdrawal stays lawful.
Only fill in sensitive data you actually want shared in an emergency. If you are in doubt, leave the field empty.
Data about other people you give us
If you give us data about someone else, for instance an emergency contact or a colleague as a contact person, we assume you are allowed to share it. We ask you to make that genuinely true: tell that person you have added them, and what for.
We use that data solely for the purpose you gave it for. We do not add it to a mailing list and do not build a separate profile with it.
The person concerned has the same rights as you: access, correction, erasure and objection. An email to privacy@punfyre.be is enough. If someone asks us to remove them as a contact, we do so and let you know that the feature will no longer work in full.
Why we process data and on what legal basis
Every processing activity has a purpose and a legal basis under the General Data Protection Regulation. They are listed together below, so you can see per basis what we use data for.
- Performance of a contract
- Creating and securing an account, delivering a product and keeping it working, managing an order and a subscription with the payments that go with it, and providing support during use.
- Pre-contractual steps and answering questions
- Handling your question through the contact or support form or by email, preparing a quote or a demo, and the conversations that go with it.
- Legitimate interests
- Keeping the website and our products secure and available, preventing abuse and fraud, investigating faults, improving our services on the basis of aggregated information, and keeping a record of arrangements and reports.
- Consent
- Special categories of data, optional features such as location, recordings or emergency contacts, non-essential browser storage, and any communication you explicitly signed up for.
- Legal obligations
- Accounting and tax obligations, consumer protection duties, and answering lawful requests from competent authorities.
- Vital interests
- Sharing the strictly necessary data when someone's life, health or safety is at risk and there is no time or possibility to ask for consent.
Legitimate interestA legal ground for using data when you have a genuine need for it and it does not override someone's privacy. means that we have a real and concrete interest in the processing, that the processing is necessary for it, and that we have weighed up whether it does not weigh too heavily on you. We make that assessment up front and you can ask us for it.
Where a processing activity rests on our legitimate interestA legal ground for using data when you have a genuine need for it and it does not override someone's privacy., you can object to it. We then stop that processing, unless there are compelling reasons to continue, and in that case we explain what those reasons are.
Do you have to give us data? For an order or a contract you have no real choice: without the data we need to deliver, invoice and reach you, we cannot conclude or perform the contract. For an account, the fields marked as required in the form apply. Where a legal obligation applies, an invoice for instance, the law itself prescribes what it must contain. Everything else is voluntary, and leaving it blank has no consequence other than that we cannot offer that one function.
No analytics, no tracking, no advertising
No analytics or tracking software runs on this website. We show no advertising, build no profiles and make no automated decisions about you. There are no pixels, no fingerprinting and no social media trackers.
We never sell or rent your data to third parties. Our fonts are self-hosted too, so your browser sends no requests to external font services when you visit the site.
The same starting point holds for our products: no advertising, no selling of data and no tracking for commercial purposes. Were a product ever to use a measurement tool, that product's own statement will say so, and we will ask for your consent first wherever the law requires it.
Emergency situations
Where a product exists to call for help, acting fast is the whole point. If you start an alarm or the product detects an incident, we may share the data needed to help you with the party handling the follow-up, for instance a licensed monitoring partner, and with emergency services or the contacts you designated yourself.
That means whatever is relevant at that moment: who you are and how you can be reached, your location where it is available, the information you stored for responders, and what the product established about the incident.
This processing rests on the performance of the contract and, where sensitive data or acute danger is involved, on the protection of vital interests. We share no more than needed and we do not use that data afterwards for purposes other than handling the incident and being able to account for it.
Disclosures required by law
We may be obliged to disclose data, for instance following a court order, a demand from an investigating authority or a lawful request from a supervisory authority.
We do not follow such a request blindly. We check whether it comes from a competent authority, whether it has a valid legal basis and whether the scope requested is reasonable. We then disclose only what is actually asked for, and no more.
Where we are allowed to, we inform the person concerned. If the law or the order forbids us from doing so, we stay silent for as long as that prohibition lasts and inform you as soon as we can.
Transfers outside the EEA
We prefer to keep our processing inside the European Economic Area, and that is also what we ask of our service providers.
If for a specific service we do work with a party that processes data outside the EEA, we base that transfer on a valid mechanism: an adequacy decision of the European Commission, or the standard contractual clauses approved by the European Commission, supplemented with additional measures where those are needed.
Want to know which parties and which safeguards apply to your situation? Email privacy@punfyre.be and we will send you an overview.
How long we keep data
We keep data as long as we need it for the purpose we received it for, and after that only where the law obliges us to retain it. As a guideline, per kind of record:
- Correspondence
- As long as needed to handle your request and for reasonable follow-up afterwards. After that it is deleted, or archived where the law obliges us to keep certain correspondence longer.
- Contracts and billing
- For the duration of the collaboration and after that for the statutory retention period applying to accounting and tax records.
- Account and profile data
- As long as your account exists. If you close it, we delete it or make it irreversibly anonymous, except for what we are legally required to keep.
- Technical logs
- At most 30 days. They serve only security and correct operation, so we keep them no longer than that requires.
- Incident data
- As long as needed to handle the incident and to be able to account for it afterwards, for instance if there is a discussion about the follow-up.
- Consent records
- As long as needed to demonstrate which choice you made and when, including after you withdraw the consent.
- Cookies and browser storage
- According to the periods listed per item in our cookie policy.
Where a product needs different or stricter periods, those are set out in that product's own statement. What we do not do is keep data because it might come in handy some day.
Your rights
The GDPREuropean privacy law: personal data may only be collected, used and kept for a clear and limited reason. gives you a set of rights over your personal data. You can exercise all of them with us:
- Access
- Ask which data we hold about you and receive a copy of it.
- Rectification
- Have inaccurate or incomplete data corrected.
- Erasure
- Ask us to delete your data when we no longer need it.
- Restriction
- Ask us to put processing on hold, for example while we look into an objection.
- Objection
- Object to processing that rests on our legitimate interest.
- Portability
- Receive the data you gave us in a commonly used format.
- Withdrawing consent
- Withdraw previously given consent at any time, without affecting the lawfulness of earlier processing.
Want to exercise one of these rights? Email privacy@punfyre.be with a short description of what you are asking for. There is no form to fill in and you do not have to give a reason.
We may ask you to confirm your identity, so we are certain we are not handing your data to someone else. We ask no more than necessary for that: if a check via your known email address is enough, we will not demand a copy of your ID card.
You will receive a reply within the legal timeframe of one month. If your request is complex, or if many requests come in at once, we may extend that period by 2 months, and we will tell you why within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessively repetitive. In that case we explain why and what we can do instead.
With a product, erasure can mean you are no longer able to use it, because without an account or without certain data there is no service left. We say so in advance, so you can decide for yourself.
No automated decision-making
We do not make decisions about you by purely automated means that have legal effects or otherwise significantly affect you. We also do not build profiles to predict what you will do, buy or need.
Some features are technically automated, for instance a detection that proposes an alarm. That is a signal, not a decision about you: a person assesses the follow-up, and you keep control to confirm or cancel the alarm.
Were this ever to change for a product, that product's own statement will say so, we will explain the logic behind it and what the consequences are, and we will inform the users concerned before it happens.
How we protect your data
We take appropriate technical and organisational measures to protect your data: encrypted connections (TLS), access control following the principle of least privilege, separate environments for development and production, systems we update and harden, and passwords stored only as an encrypted derivation.
If we do detect a personal data breach, we investigate it, close the gap and document what happened. Where the breach is notifiable, we inform the Belgian Data Protection Authority within 72 hours of becoming aware of it. Where there is a high risk to the people concerned, we inform them too, in plain language and with what they can do themselves.
No system is perfect, but our most important security measure is the simplest one: we collect very little. What is not there cannot leak.
What we expect from you
If a product works with an account, your access is partly your responsibility too. Keep your sign-in details to yourself, do not share them with others, use a unique password and turn on two-step verification where the product offers it.
Suspect that someone else can get into your account? Report it as soon as possible via privacy@punfyre.be. The sooner we know, the more we can do.
Also make sure the data you enter is accurate and up to date, certainly for a safety feature. An old phone number for an emergency contact helps nobody at the moment it counts.
We do what can reasonably be expected of us to protect your data, and we stand behind that. If something nevertheless goes wrong purely because of a third party's unlawful acts or because sign-in details were shared beyond our control, we cannot be held liable for that damage.
Children
This website is not aimed at children and we do not knowingly process children's personal data through the website.
Where a product may be used by or for a minor, for instance because a parent sets up a safety feature for a child, a parent or legal guardian must do the setup and give the necessary consent. We handle that data with extra care: only what the feature needs, never for commercial purposes, and with the same rights for the child as for anyone else.
Do you believe we process a child's data without that consent? Email privacy@punfyre.be and we will look into it and delete whatever should not be there.
Filing a complaint
Not happy with how we handle your data? Tell us first via privacy@punfyre.be and we will look for a solution together. That is usually the fastest route, but it is not a mandatory step.
You always have the right to lodge a complaint with the Belgian supervisory authority: the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit).
A complaint with the supervisory authority rules nothing out. You can also go to court, and if you suffered damage from unlawful processing you can claim compensation. That right remains, even if you come to us or to the supervisory authority first.
Changes to this policy
We may update this privacy policy, for instance when the website, a product or the law changes. The version published on this page, with the date at the top, is the version that applies.
For significant changes we will make that clearly visible on the website. Where a change concerns a product you use, we will also notify you inside that product where that is appropriate.
Contact and applicable law
- Privacy questions and requests
- privacy@punfyre.be
- Post
- Punfyre BV, Vlamingstraat 4, 8560 Wevelgem, Belgium
This privacy policy and the processing it describes are governed by Belgian law, together with the General Data Protection Regulation and the Belgian implementing legislation. The courts of Kortrijk have jurisdiction over disputes, without prejudice to your right to bring a case before the court the law assigns to you when you act as a consumer.
Contact
Questions about your data?
You have the right to know what we hold about you, and to have it corrected or erased. One email is enough, and you do not need to give a reason.
-
Privacy and your data
Access, correction or deletion of your data, and any other privacy question.
privacy@punfyre.be -
Legal and contracts
Questions about these documents, contracts, invoices or formal notices.
legal@punfyre.be -
Not sure?
Unsure where your question belongs? Send it here and we will sort it out.
support@punfyre.be