Skip to main content

Legal

PurpletGo Privacy Policy

Last updated: May 2026

1. Who we are

PurpletGo ("we", "us", or "our") operates the employee offboarding platform available at purpletgo.com. For the purposes of the General Data Protection Regulation (GDPR) and applicable European data protection law, PurpletGo acts as a data processor on behalf of its business customers (controllers) with respect to employee offboarding data, and as a data controller for data relating to its own customers and website visitors.

Data protection enquiries: privacy@purpletgo.com

2. What data we collect and why

CategoryExamplesLawful basis
Account dataName, email, hashed password, organisation nameContract (Art. 6(1)(b))
Usage dataAudit log actions, feature usage, IP addressLegitimate interests (Art. 6(1)(f))
Employee offboarding dataDeparting employee name, email, role, exit dateContract / legal obligation on behalf of controller
Payment dataBilling email, Stripe customer ID (card data held by Stripe)Contract (Art. 6(1)(b))
Support communicationsEmail content when contacting usLegitimate interests (Art. 6(1)(f))

3. Your rights under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of access (Art. 15) - Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) - Correct inaccurate personal data directly from your account settings, or by contacting us.
  • Right to erasure (Art. 17) - Request deletion of your account and all associated personal data. Exercisable from Settings → Account, or by email.
  • Right to data portability (Art. 20) - Request a structured, machine-readable export of your data via Settings → Account → Export My Data.
  • Right to restrict processing (Art. 18) - Ask us to pause processing of your data in certain circumstances.
  • Right to object (Art. 21) - Object to processing based on legitimate interests.
  • Right to lodge a complaint - You may lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or the relevant DPA in your EU member state).

To exercise any right, email privacy@purpletgo.com. We will respond within 30 days.

4. Data retention

We retain account data for as long as your account is active. Offboarding records are subject to the retention policy configured by your organisation (minimum 30 days, configurable on Team and Enterprise plans). When an account is deleted, personal data is anonymised or hard-deleted within 30 days, except where retention is required by law (e.g. financial records for tax purposes).

5. Data transfers outside the EEA

Our infrastructure currently operates in Google Cloud Platform and may include regions outside the EEA (e.g. us-central1). Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (2021/914) to ensure an adequate level of protection. Enterprise customers may request an EU-region deployment. Contact dpa@purpletgo.com for a Data Processing Agreement (DPA).

6. Cookies

We use strictly necessary cookies only - specifically a single HttpOnly session cookie (access_token) used to authenticate you to the platform. This cookie is essential for the service to function and does not require separate consent under ePrivacy rules. We do not use advertising, analytics, or third-party tracking cookies.

7. Sub-processors

We use the following sub-processors to deliver our service:

  • StripePayment processing - USA (SCCs)
  • Google Cloud PlatformInfrastructure, storage, compute - USA/EU (SCCs / EU regions available)
  • Resend / SMTP providerTransactional email - Varies (SCCs)
  • GroqAI inference (exit interview sentiment, AI assistant) - USA (SCCs)

8. Security

We protect your data with TLS encryption in transit, bcrypt password hashing (cost factor 12), TOTP two-factor authentication, HttpOnly session cookies, row-level tenant isolation in PostgreSQL, and signed short-lived URLs for all stored files. We conduct regular security reviews and maintain a tamper-evident audit log of all data access and modification events.

9. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33) and affected individuals without undue delay (GDPR Art. 34) where required.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to registered account holders at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

Contact us

Privacy enquiries: privacy@purpletgo.com
Data Processing Agreements: dpa@purpletgo.com