Purple Giraffe โ† Terms of service
Legal

Privacy Policy

๐Ÿ“… Effective date: 1 April 2026 ๐Ÿข Purple Giraffe Studio ๐Ÿ“ง hello@purplegiraffe.cc

Contents

  • 1. Who we are
  • 2. What we collect
  • 3. How we use it
  • 4. Email communications
  • 5. Third parties
  • 6. Data retention
  • 7. Your rights
  • 8. Cookies
  • 9. Children
  • 10. Changes
  • 11. Contact

Plain English summary: We collect your email address and the website URL you scan. We use this to deliver your report and send follow-up emails. We do not sell your data. We use Paddle for payments (they process your card โ€” we never see it). You can ask us to delete your data at any time.

1 Who we are

Purple Giraffe Studio ("we", "us", "our") operates the website purplegiraffe.cc and the EU greenwashing compliance audit tool at purplegiraffe.cc/audit. We are based in Nairobi, Kenya.

This Privacy Policy explains how we collect, use, and protect personal data in connection with our services. We are committed to handling your data responsibly and transparently.

For users in the European Economic Area (EEA), we process your personal data in accordance with the General Data Protection Regulation (GDPR) where applicable, even as a non-EEA business processing data of EEA residents.

2 What data we collect

2.1 Data you provide

  • Email address โ€” provided voluntarily when you request a full report or contact us
  • Website URL โ€” the URL you submit for compliance scanning
  • Content you paste โ€” if you use the manual paste feature, the text content you submit
  • Communications โ€” emails and messages you send us

2.2 Data collected automatically

  • Scan results โ€” compliance scores, violations found, and report data associated with each scan
  • IP address and browser information โ€” collected by our hosting provider for security and performance purposes
  • Usage data โ€” pages visited, scan events, and general usage patterns

2.3 Payment data

We do not collect or store payment card details. All payment processing is handled by Paddle.com Market Limited. Paddle may share your email address and transaction reference with us for order fulfilment. See Paddle's privacy policy at paddle.com/legal/privacy.

3 How we use your data

We use the data we collect for the following purposes:

  • Service delivery โ€” generating your compliance report, delivering it by email, and making it available for download
  • Email communications โ€” sending your report, follow-up emails about your scan, and responses to your enquiries (see Section 4)
  • Service improvement โ€” analysing scan data in aggregate to improve the accuracy of our compliance analysis
  • Security โ€” detecting fraud, abuse, and unauthorised access
  • Legal obligations โ€” complying with applicable laws, responding to lawful requests

Our legal basis for processing under GDPR is:

  • Contract performance (Article 6(1)(b)) โ€” processing necessary to deliver the service you purchased
  • Legitimate interests (Article 6(1)(f)) โ€” improving our service, security, and fraud prevention
  • Consent (Article 6(1)(a)) โ€” for marketing emails where we seek your consent

4 Email communications

If you provide your email address during the upgrade flow, we will send you:

  • Your compliance report (immediately after payment confirmation)
  • A follow-up email 48 hours after a free scan if you have not purchased
  • A value email 7 days after a free scan with a free fix you can implement
  • A follow-up 5 days after purchase asking if the report was useful

You can opt out of follow-up emails at any time by replying "unsubscribe" or contacting hello@purplegiraffe.cc. Transactional emails (report delivery, payment confirmation) cannot be opted out of as they are necessary for service delivery.

We do not send unsolicited marketing emails. We do not add your email to any third-party mailing list without your explicit consent.

5 Third parties we share data with

We share personal data with the following third parties only as necessary to deliver our services:

  • Paddle.com Market Limited โ€” payment processing and invoicing. Paddle acts as our Merchant of Record.
  • Anthropic, PBC โ€” AI analysis of website content submitted for scanning. Content submitted through our tool is processed by Anthropic's API. See Anthropic's privacy policy at anthropic.com/privacy.
  • Mailtrap / transactional email provider โ€” sending compliance report emails. We use a transactional email service to deliver reports.
  • Hosting provider โ€” our website and application are hosted on a third-party server. Server logs may include your IP address.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

6 Data retention

We retain your data for the following periods:

  • Scan records and reports โ€” 24 months from the date of scan, after which they are anonymised or deleted
  • Email address โ€” retained for as long as your scan record exists, or until you request deletion
  • Payment records โ€” retained for 7 years as required for tax and accounting purposes (held by Paddle)

You may request deletion of your personal data at any time (see Section 7). Deletion of scan records will also remove access to the associated full report.

7 Your rights

Depending on your country of residence, you may have the following rights regarding your personal data:

  • Access โ€” request a copy of the personal data we hold about you
  • Correction โ€” request correction of inaccurate data
  • Deletion โ€” request deletion of your personal data ("right to be forgotten")
  • Portability โ€” request your data in a machine-readable format
  • Objection โ€” object to processing based on legitimate interests
  • Restriction โ€” request that we restrict processing in certain circumstances
  • Withdraw consent โ€” withdraw consent for processing where consent is the legal basis

To exercise any of these rights, contact us at hello@purplegiraffe.cc. We will respond within 30 days. We may need to verify your identity before acting on your request.

If you are in the EEA and believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection supervisory authority.

8 Cookies

Our website uses minimal cookies necessary for the operation of the service, including session cookies to maintain your scan state. We do not use advertising cookies or third-party tracking cookies.

Your browser settings allow you to control or delete cookies. Disabling session cookies may affect the functionality of the audit tool.

9 Children

Our services are intended for business users only and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at hello@purplegiraffe.cc.

10 Changes to this policy

We may update this Privacy Policy from time to time. The effective date at the top of this page reflects the most recent revision. We will notify you by email of material changes where we hold your email address.

11 Contact

For any privacy-related questions, data access requests, or deletion requests:

Purple Giraffe Studio

๐Ÿ“ง hello@purplegiraffe.cc

Subject line: Privacy request โ€” [your name]

We aim to respond to all privacy requests within 5 business days.

Purple Giraffe Studio ยท hello@purplegiraffe.cc

Pricing Terms Refund policy