Legal
Privacy policy.
This Privacy Policy (hereinafter referred to only as the “Policy”) defines the privacy practices employed by Hello.Purple, a platform operated by Purple Technology s.r.o., with its registered seat at Masarykova 410/28, Brno-city, 602 00 Brno, Czech Republic, reg. no.: 29364973 (hereinafter referred to only as the “Company”) in providing and/or receiving the Service (as defined in the Terms and Conditions) to its customers and/or from providers such as vendors, affiliates and marketing services providers, where provided by natural persons and/or through a corporate structure, in which case the Company processes personal data of their directors, shareholders and/or employees where necessary (hereinafter referred to collectively as the “Subjects” or specifically as “Client” / “Provider”), and shall be read in the light of the legal agreements and policies provided by the Company.
The Company is not a bank, investment firm, broker or payment institution and does not provide any investment service or payment service. Where the Subject holds a trading account with any broker, that account and the personal data relating to it are governed by the privacy policy of that broker and not by this Policy. See Article VIII below.
IPurpose of this privacy policy
This Policy defines how the Company collects and processes personal data of the Subjects through the use of hello-purple.com and its services, or within the scope of a contractual relationship between the Company and a Provider (hereinafter referred to only as the “Website” or “Service”), including any data the Subject may provide through the Website when signing up thereto.
The Services are not intended for minors (persons below 18 years of age) and no data related to minors may be collected.
IIData controller
The Company is the controller and the entity responsible for the Subject’s personal data. It is important that the personal data the Company holds about the Subject is accurate and up to date. The Subject is obliged to inform the Company of any changes in his or her personal data.
Contact details:
- Business name
- Purple Technology s.r.o.
- reg. no.
- 29364973
- reg. office
- Masarykova 410/28, Brno-city, 602 00 Brno, Czech Republic
- e-mail address
- hello@hello-purple.com
The Company has not appointed a data protection officer, as it is not a public authority, its core activities do not consist of processing operations which by virtue of their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, and it does not carry out large-scale processing of special categories of personal data. All requests relating to personal data, including requests to exercise the legal rights described in Article XXV, should be addressed to the contact e-mail stated above. Should the Company appoint a data protection officer in the future, it will update this Policy and publish the officer’s contact details.
IIIData collected
Personal data means any information about an individual which may be used to identify that person. It does not include data where the identity has been removed (anonymous data).
The Company may collect, use, store and transfer different kinds of personal data about the Subject. For the purposes of this Policy the data is divided into the following groups:
- Identity Data includes first name, maiden name, last name, username or similar identifier.
- Contact Data includes residential address, e-mail address and telephone numbers.
- Financial Data includes billing details and payment card or other payment instrument identifiers processed by the Company’s payment provider.
- Transaction Data includes details about subscription payments to and refunds from the Company.
- Technical Data includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices the Subject uses to access the Services.
- Profile Data includes the username and password of the Subject, his or her interests, preferences, feedback and survey responses.
- Usage Data includes information about how the Subject uses the Website and the Services.
- Marketing and Communications Data includes the Subject’s preferences in receiving marketing from the Company and its third parties, and the Subject’s communication preferences.
- Content Data includes any text, prompt, instruction, comment or other content which the Subject submits to the Website or the Services.
The Company does not collect any special categories of personal data and does not collect any data relating to criminal convictions or offences.
IVIf the subject does not provide personal data
Where the Company is required to collect personal data by law, or under the terms of the respective agreement with the Subject, and the Subject does not provide such data after being requested to do so, the Company may not be able to perform the agreement with the Subject. In such case the Company may have to terminate the agreement, with the obligation to notify the Subject thereof.
VSubscription and content services
The Company’s primary purpose in processing personal data is the operation of the Website and the provision of its subscription and content services. Where the Subject subscribes to the Website, to a newsletter or to any content service, the Company processes the following further categories of personal data:
- Authentication data – e-mail address and authentication identifiers used to sign in. Where the Subject signs in via a single sign-on provider, the Company receives the e-mail address and the relevant unique identifier from that provider.
- Subscription data – the subscription selected, its status, its term, the date of commencement and renewal, and the history of payments and refunds.
- Engagement data – which content the Subject has opened, read or downloaded, whether an e-mail has been delivered and opened, and which links have been followed.
- Communications data – the content of any enquiry, comment or support request submitted by the Subject and the Company’s response to it.
The legal bases of this processing are performance of the contract with the Subject, the Company’s legitimate interests in operating, securing and improving the Website, and, in respect of marketing communications, the Subject’s consent where required.
VIDeveloper access and technical documentation
This Article applies from the moment the Company makes available developer access to technical documentation, software development kits, a developer portal or comparable developer resources. Until that time, no processing described in this Article takes place.
Where the Subject registers for developer access, the Company processes: registration and authentication data; the identifier and configuration of any application which the Subject registers; credentials issued to the Subject for the purpose of accessing the documentation and the developer portal; records of the Subject’s use of those resources, including requests made, errors returned and volumes consumed; and any content which the Subject submits to the developer portal.
The Company does not, under this Policy, process any data relating to any trading account. Where the Subject connects an application to a trading account held with a broker, the authorisation, the credentials relating to that account and any data retrieved from it are processed by that broker as controller under its own privacy policy, and the Company is not a party to that processing. Where the Company acts as a technical service provider to a broker in respect of such processing, it does so on that broker’s instructions and as its processor, and not as an independent controller.
The legal bases of this processing are performance of the contract with the Subject and the Company’s legitimate interests in operating, securing and improving the developer resources and in preventing their misuse.
VIIArtificial intelligence
The Website and the Services may include functions which use artificial intelligence, including generative models, in order to generate, summarise, classify or otherwise process content, and in order to respond to enquiries submitted through the Company’s support channels.
Where such a function is used, Content Data and related Technical Data may be transmitted to and processed by third-party model providers acting as processors of the Company and solely for the purpose of delivering the requested functionality, subject to appropriate contractual, technical and organisational safeguards. The identity of those providers is stated on the Website and is updated as it changes.
The Company does not use Content Data submitted by Subjects to train its own artificial intelligence models. Should the Company intend to change this practice, it will update this Policy in advance and, where required by applicable law, obtain consent or establish another lawful basis. Where an output is generated by artificial intelligence, the Company discloses that fact in accordance with applicable law.
Artificial intelligence is not used to take any decision based solely on automated processing which produces legal effects concerning the Subject or which similarly significantly affects the Subject; see also Article XXII.
VIIIRelationship to other Purple Group companies
Purple Group is not a legal entity. It is a brand representing a group of independent companies. Each service is provided by a specific company within the group, on its own account and under its own authorisations where required. The Company is the controller only in respect of the processing described in this Policy.
Where the Company shares personal data with another company within the group, it does so on the basis of its legitimate interests in the internal administration, security and support of the group, or on the basis of a written arrangement under which the recipient acts as processor. Where another company within the group provides a service to the Subject on its own account, that company is the controller of the personal data processed for that purpose and its own privacy policy applies. The fact that a company within the group holds an authorisation for a particular service does not mean that the Company holds it, and no such authorisation should be assumed in respect of the Company.
IXHow is the subject’s personal data collected
The Company uses different methods to collect data from and about the Subject, including the following:
- Direct interactions. The Subject may provide personal data to the Company by filling in forms or by communicating with the Company by post, telephone, e-mail or otherwise. This includes personal data the Subject provides if he or she:
- registers on the Website or subscribes to any content service;
- subscribes to a newsletter or completes any marketing form or landing page;
- registers for developer access as described in Article VI;
- contacts the Company’s representatives; or
- submits an enquiry, comment or support request.
- Introducing Brokers and other affiliates. The Company may be provided with the Subject’s personal data through the Company’s Introducing Brokers and/or other affiliates.
- Automated technologies or interactions. As the Subject interacts with the Website, and in accordance with the Cookies Policy, technical data about his or her equipment, browsing actions and patterns may be collected automatically by means of cookies, server logs and similar technologies.
- Third parties or publicly available sources. The Company may receive personal data about the Subject from third parties and public sources, such as analytics providers and advertising networks based within and outside the European Union.
XHow the company uses personal data of the subjects
The Subject’s personal data will be used only where the law allows the Company to do so. Most commonly the Company will use the Subject’s personal data in the following circumstances:
- where it is necessary to perform the agreement concluded, or in the process of conclusion, with the Subject;
- where it is necessary for the Company’s legitimate interests, or those of a third party, unless those interests are overridden by the interests or fundamental rights and freedoms of the Subject;
- where the Company must comply with a legal or regulatory obligation;
- where freely given, specific, informed and unambiguous consent has been granted by the Subject.
In cases not covered by the above legal grounds, the consent of the Subject is required. This applies in particular where personal data is used for the purposes of direct marketing communications by e-mail or text message. The Subject has the right to withdraw consent to processing for marketing purposes at any time by contacting the Company at hello@hello-purple.com.
XIPurposes for which the company uses personal data
The table below describes the ways in which the Company uses personal data and the legal bases relied upon, including the Company’s legitimate interests where relevant. Personal data may be processed on more than one lawful ground depending on the specific purpose.
| Purpose | Type of data | Lawful basis |
|---|---|---|
| To register the Subject as a new client and to create and administer the account | Identity, Contact, Profile, Technical | Performance of a contract with the Subject |
| To provide the subscription and content services, including delivery of content and newsletters to subscribers | Identity, Contact, Profile, Subscription, Engagement, Usage | Performance of a contract; legitimate interests in operating and improving the Services |
| To process and collect subscription payments and to issue invoices and refunds | Identity, Contact, Financial, Transaction | Performance of a contract; compliance with a legal obligation (accounting and tax) |
| To provide developer access, to issue and administer credentials and to monitor and prevent misuse of the developer resources | Identity, Contact, Technical, Usage, Content | Performance of a contract; legitimate interests in the security and integrity of the Services |
| To provide artificial-intelligence functions requested by the Subject and to respond to support enquiries | Content, Technical, Contact | Performance of a contract; legitimate interests in providing support |
| To manage the relationship with the Subject, including notifying about changes to terms or to this Policy | Identity, Contact, Profile, Marketing and Communications | Performance of a contract; compliance with a legal obligation; legitimate interests in keeping records updated |
| To deliver relevant content and advertising and to measure its effectiveness | Identity, Contact, Profile, Usage, Marketing and Communications, Technical | Consent, where required; otherwise legitimate interests in developing the Services and growing the business |
| To administer and protect the business and the Website, including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data | Identity, Contact, Technical | Legitimate interests in running the business, providing administration and IT services, network security and preventing fraud; compliance with a legal obligation |
| To use data analytics to improve the Website, the Services, marketing and Subject relationships | Technical, Usage | Legitimate interests in defining types of Subject for the Services, keeping the Website updated and relevant, and developing the business |
XIIMarketing
The Company strives to provide the Subject with choices regarding certain uses of personal data, particularly around marketing and advertising. The Company may use Identity, Contact, Technical, Usage and Profile Data to form a view of what the Subject may want or need, or what may be of interest.
XIIIPromotional offers
The Subject may receive marketing communications from the Company if he or she has requested information from the Company, has subscribed to a newsletter or content service, or has otherwise provided the Company with details in the course of registration, and has not opted out of receiving such communications. Where consent is required by applicable law, marketing communications are sent only on the basis of consent.
XIVThird-party marketing
The Company will obtain the Subject’s express opt-in consent before it shares personal data with any third party for that third party’s own marketing purposes.
XVOpting out
The Subject may ask the Company to stop sending marketing messages at any time by following the opt-out links in any marketing message or by contacting the Company at hello@hello-purple.com. Opting out of marketing does not affect processing carried out on any other lawful basis.
XVICookies
The Website uses cookies and similar technologies. Detailed information is set out in the Cookies Policy available on the Website. Cookies which are not strictly necessary for the operation of the Website are placed only with the Subject’s consent, which may be withdrawn at any time through the cookie settings on the Website.
XVIIChange of purpose
The Company will use the Subject’s personal data only for the purposes for which it was collected, unless it reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. Where the Company needs to use personal data for an unrelated purpose, it will notify the Subject and explain the legal basis which permits it to do so.
XVIIIDisclosure of the subject’s personal data to third parties
The Company may share the Subject’s personal data with the following categories of recipients:
- hosting, infrastructure and cloud providers;
- authentication providers;
- payment providers and payment service providers processing subscription payments;
- analytics, marketing automation and CRM providers;
- artificial-intelligence model providers, as described in Article VII;
- other companies within the Purple Group, as described in Article VIII;
- professional advisers, including lawyers, auditors and insurers;
- public authorities, regulators and courts, where required by law.
The Company requires all third parties to respect the security of personal data and to treat it in accordance with the law. The Company does not allow its third-party service providers to use personal data for their own purposes and permits them to process personal data only for specified purposes and in accordance with the Company’s instructions.
XIXData security
The Company has put in place appropriate technical and organisational measures to prevent personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Access to personal data is limited to those employees, agents, contractors and other third parties who have a business need to know, and they are subject to a duty of confidentiality.
The Company has put in place procedures to deal with any suspected personal data breach and will notify the Subject and any applicable supervisory authority of a breach where legally required to do so.
XXGoogle reCAPTCHA
The Website may use the reCAPTCHA service provided by Google in order to distinguish human users from automated access and to protect the Website against abuse. This involves the transmission of the IP address and possibly other data required by Google for the reCAPTCHA service. The legal basis is the Company’s legitimate interest in the security of the Website. Further information is available in Google’s privacy policy and terms of use.
XXIInternational transfers
Some of the Company’s external third parties are based outside the European Economic Area, so their processing of personal data may involve a transfer of data outside the EEA. Where the Company transfers personal data outside the EEA, it ensures a similar degree of protection by implementing at least one of the following safeguards: transfer to a country which has been deemed by the European Commission to provide an adequate level of protection; use of standard contractual clauses approved by the European Commission, together with any supplementary measures identified as necessary; or reliance on a specific derogation permitted by applicable law. The Subject may request a copy of the relevant safeguards by contacting the Company.
XXIIAutomated decision-making and profiling
The Company does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning the Subject or which similarly significantly affect the Subject. Where the Company carries out profiling for the purposes of marketing or of improving the Services, the Subject has the right to object to such processing at any time.
XXIIIPersonal data breaches
In the event of a personal data breach, the Company will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the Company will also notify the affected Subjects without undue delay.
XXIVData retention
The Company will retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements. In determining the appropriate retention period the Company considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, whether those purposes can be achieved by other means, and the applicable legal requirements.
By way of guidance: registration and account data are retained for the duration of the account and for three (3) years following its closure; subscription, payment and invoicing data are retained for ten (10) years as required by accounting and tax legislation; marketing consents and opt-outs are retained for the duration of the consent and for three (3) years thereafter; server logs and technical data are retained for fourteen (14) months; and Content Data is retained for the duration of the account unless deleted earlier by the Subject. Where a longer retention period is required by law or is necessary for the establishment, exercise or defence of legal claims, the data is retained for that period.
Account deletion. The Subject may request deletion of the account and the related personal data by e-mail to the contact address stated in Article II. The Company verifies identity, typically by a confirmation link sent to the registered e-mail address, and completes the deletion within thirty (30) days of verification, save in respect of data which the Company is required to retain by law.
XXVLegal rights of the subjects
Under data protection law the Subject has the following rights in relation to his or her personal data:
- Right of access – to request a copy of the personal data the Company holds about the Subject.
- Right to rectification – to request correction of incomplete or inaccurate data.
- Right to erasure – to request deletion of personal data where there is no good reason for the Company to continue processing it.
- Right to object – to object to processing based on legitimate interests, and to object at any time to processing for direct marketing purposes.
- Right to restriction – to request the suspension of processing in defined circumstances.
- Right to data portability – to receive personal data provided by the Subject in a structured, commonly used, machine-readable format, or to have it transmitted to another controller.
- Right to withdraw consent – to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights the Subject may contact the Company at hello@hello-purple.com.
No fee usually required. The Subject will not have to pay a fee to access personal data or to exercise any of the other rights. The Company may charge a reasonable fee, or refuse to comply, where a request is manifestly unfounded or excessive, in particular because of its repetitive character.
What the Company may need. The Company may need to request specific information in order to confirm the Subject’s identity and to ensure the right to access personal data, or to exercise any other right, is not exercised by a person who has no right to do so. The Company may also contact the Subject for further information in relation to the request in order to speed up the response.
Time limit to respond. The Company tries to respond to all legitimate requests within one (1) month. Occasionally it may take longer if the request is particularly complex or a number of requests have been made, in which case the Company will notify the Subject and keep him or her updated.
XXVIChildren’s privacy
The Services are not directed at persons below 18 years of age and the Company does not knowingly collect personal data from such persons. Should the Company become aware that it has collected personal data from a person below 18 years of age, it will delete that data without undue delay.
XXVIIRight to lodge a complaint with a supervisory authority
The Subject has the right to lodge a complaint at any time with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz. The Company would, however, appreciate the opportunity to deal with the Subject’s concerns before the Subject approaches the supervisory authority, and asks the Subject to contact it in the first instance. A Subject resident in another Member State of the European Union may also lodge a complaint with the supervisory authority of that Member State.
XXVIIIChanges to this policy and effective date
The Company may amend this Policy from time to time, in particular where the Services change, where the Company begins to provide the developer access described in Article VI, where the categories of recipients change, or where required by law. The Company will publish the amended Policy on the Website and, where the amendment is material, will notify the Subject by e-mail or by notification within the Service in advance of it taking effect.
This Policy comes into force and effect on 18th September 2026. Version 1.0.