Plain English summary: We collect your email address and the website URL you scan. We use this to deliver your report and send follow-up emails. We do not sell your data. We use Paddle for payments (they process your card โ we never see it). You can ask us to delete your data at any time.
Purple Giraffe Studio ("we", "us", "our") operates the website purplegiraffe.cc and the EU greenwashing compliance audit tool at purplegiraffe.cc/audit. We are based in Nairobi, Kenya.
This Privacy Policy explains how we collect, use, and protect personal data in connection with our services. We are committed to handling your data responsibly and transparently.
For users in the European Economic Area (EEA), we process your personal data in accordance with the General Data Protection Regulation (GDPR) where applicable, even as a non-EEA business processing data of EEA residents.
We do not collect or store payment card details. All payment processing is handled by Paddle.com Market Limited. Paddle may share your email address and transaction reference with us for order fulfilment. See Paddle's privacy policy at paddle.com/legal/privacy.
We use the data we collect for the following purposes:
Our legal basis for processing under GDPR is:
If you provide your email address during the upgrade flow, we will send you:
You can opt out of follow-up emails at any time by replying "unsubscribe" or contacting hello@purplegiraffe.cc. Transactional emails (report delivery, payment confirmation) cannot be opted out of as they are necessary for service delivery.
We do not send unsolicited marketing emails. We do not add your email to any third-party mailing list without your explicit consent.
We share personal data with the following third parties only as necessary to deliver our services:
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
We retain your data for the following periods:
You may request deletion of your personal data at any time (see Section 7). Deletion of scan records will also remove access to the associated full report.
Depending on your country of residence, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at hello@purplegiraffe.cc. We will respond within 30 days. We may need to verify your identity before acting on your request.
If you are in the EEA and believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection supervisory authority.
Our website uses minimal cookies necessary for the operation of the service, including session cookies to maintain your scan state. We do not use advertising cookies or third-party tracking cookies.
Your browser settings allow you to control or delete cookies. Disabling session cookies may affect the functionality of the audit tool.
Our services are intended for business users only and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at hello@purplegiraffe.cc.
We may update this Privacy Policy from time to time. The effective date at the top of this page reflects the most recent revision. We will notify you by email of material changes where we hold your email address.
For any privacy-related questions, data access requests, or deletion requests:
Purple Giraffe Studio
Subject line: Privacy request โ [your name]
We aim to respond to all privacy requests within 5 business days.