Purpl Privacy Policy
Controller: Purpl Tech Solutions Private Limited Licence number: CL13529 Registered address: Innovation One, Level 1, Dubai International Financial Centre, Dubai, U.A.E. Version: 2.1 Last Updated: 11 August 2026 Effective Date: 11 August 2026
Purpl Tech Solutions Private Limited ("Purpl", "we", "our" or "us") is committed to protecting the privacy and security of Personal Information entrusted to us.
This Privacy Policy explains how we collect, use, process, store, protect, disclose and otherwise handle Personal Information when you access or use the Purpl platform and related Services.
Contents
Part I — Privacy framework
- Introduction
- Scope
- Our privacy principles
- Definitions
Part II — Information we process
- Information we collect
- How we use Personal Information
- AI & automated processing
- Sharing Personal Information
- International data transfers
Part III — Protecting your information
- Information security
- Data retention
- Your privacy rights
- Cookies, mobile SDKs & similar technologies
- Marketing communications
Part IV — Legal & governance
- Controller and processor roles
- Children's privacy
- Security incidents & data breaches
- Changes to this Privacy Policy
- Contact us
- Governing law
Part I — Privacy framework
1. Introduction
Purpl Tech Solutions Private Limited ("Purpl", "we", "our" or "us") is committed to protecting the privacy and security of Personal Information entrusted to us.
This Privacy Policy explains how we collect, use, process, store, protect, disclose and otherwise handle Personal Information when you access or use the Purpl platform and related Services.
Purpl is an AI-powered Financial Operations Platform delivered as Software-as-a-Service (SaaS) that enables businesses to organise, manage, analyse and understand operational and financial information through intuitive software tools and AI-assisted capabilities.
This Privacy Policy applies to:
- the Purpl mobile applications;
- the Purpl web application;
- our websites;
- APIs;
- AI Features;
- customer support;
- integrations;
- communications;
- online services; and
- all related products and Services provided by Purpl.
By accessing or using the Services, you acknowledge that you have read this Privacy Policy.
This Privacy Policy should be read together with the Purpl Terms of Service.
2. Scope
This Privacy Policy applies whenever Purpl processes Personal Information relating to:
- Customers;
- prospective Customers;
- Authorised Users;
- business owners;
- directors;
- shareholders;
- employees;
- contractors;
- advisers;
- customers and suppliers whose information is uploaded by Customers;
- website visitors;
- customer support contacts;
- applicants for business relationships; and
- any other identifiable individual whose Personal Information is processed through the Services.
This Privacy Policy applies regardless of whether Personal Information is collected:
- directly from you;
- from your employer or organisation;
- from another authorised User;
- through integrations authorised by the Customer;
- automatically through your use of the Services;
- from authorised third-party service providers; or
- through future technologies incorporated into the Services.
3. Our privacy principles
Privacy is a core design principle of the Purpl platform. We are committed to the following principles.
3.1 Transparency
We aim to explain clearly:
- what information we collect;
- why we collect it;
- how we use it;
- who we share it with; and
- what choices are available to you.
3.2 Privacy by design
Privacy and security considerations are incorporated into the design, development and operation of our Services. Where reasonably practicable, new features are evaluated for privacy implications before release.
3.3 Data minimisation
We seek to collect only the Personal Information reasonably necessary to:
- provide the Services;
- maintain security;
- comply with Applicable Law;
- improve the platform; and
- fulfil our contractual obligations.
3.4 Customer control
Customers determine what information they upload into the Services. Where Purpl processes Customer Data on behalf of Customers, Customers remain responsible for ensuring that they have the appropriate legal basis for doing so.
3.5 Security
We implement technical, organisational and administrative safeguards designed to protect Personal Information against unauthorised access, disclosure, alteration or destruction.
3.6 Responsible artificial intelligence
Artificial Intelligence is an integral part of the Purpl platform. Where AI Features process Personal Information, we seek to do so responsibly, transparently and in accordance with applicable data protection laws.
AI infrastructure and sub-processors. Purpl's AI Features are powered by enterprise cloud artificial-intelligence infrastructure operated by Amazon Web Services, principally the Amazon Bedrock service, hosted within Purpl's own cloud environment. When you use an AI Feature, only the content required to fulfil that specific request — for example the prompt you enter together with the relevant business or document data you ask the assistant to work with — is transmitted to this infrastructure solely to generate the requested response, which is then returned to you.
What we send, and to whom. We transmit only the data necessary to perform the requested AI operation. That data is processed by our cloud AI sub-processor strictly as a service provider acting on Purpl's instructions under a contractual data-processing agreement. It is not sold, and it is not disclosed to independent third parties for their own purposes.
No third-party model training. Data sent to our AI infrastructure is not used to train, and is not retained to improve, any publicly available or third-party foundation models. Our AI sub-processor does not store your prompts or the AI-generated responses after your request has been served, and does not use them to train its models.
Your control. AI Features are used at your initiative — for example when you open the in-app assistant or expressly ask it to analyse your data. You can choose not to use AI Features, and the rest of the Services remains usable without submitting data to an AI Feature.
4. Definitions
Unless the context requires otherwise:
Account means the registered account used to access the Services.
Authorised User means an individual authorised by a Customer to access the Services.
Customer means the legal entity subscribing to or using the Services.
Customer Data means all information, records, documents, files, financial information, operational information, Personal Information, prompts, images, voice recordings, transactions and any other data uploaded, imported, generated, transmitted, created or stored by or on behalf of a Customer through the Services.
Personal Information means any information relating to an identified or identifiable natural person, including any equivalent concept recognised under applicable data protection legislation.
Processing means any operation performed on Personal Information including collection, recording, organisation, storage, use, disclosure, transfer, analysis, deletion or destruction.
Services means the Purpl platform, including its mobile applications, web applications, websites, APIs, Artificial Intelligence features, integrations, dashboards, reports, workflows, documentation and all related software, products and services provided by Purpl.
Part II — Information we process
5. Information we collect
The information we collect depends upon how the Services are used and the functionality selected by the Customer.
5.1 Information you provide
You or your organisation may provide information including:
Identity information. Examples include:
- full name;
- business name;
- job title;
- email address;
- telephone number;
- business registration details;
- trade licence information;
- authorised representative details;
- identity verification information where required.
Business information. Examples include:
- company profile;
- industry;
- business activities;
- reporting preferences;
- financial year settings;
- tax registration information;
- VAT information;
- business configuration settings.
Financial and operational information. Depending on how the Services are used, Customers may upload or create information including:
- quotations;
- invoices;
- receipts;
- purchase orders;
- bills;
- journal entries;
- chart of accounts;
- bank transaction information;
- budgets;
- forecasts;
- financial reports;
- business performance information;
- cash flow information;
- operational metrics.
Contact information. Customers may upload information relating to:
- employees;
- customers;
- suppliers;
- contractors;
- advisers;
- shareholders;
- directors; and
- other business contacts.
This information is uploaded solely for the Customer's own business purposes.
Documents. Customers may upload documents including:
- invoices;
- receipts;
- contracts;
- bank statements;
- trade licences;
- tax certificates;
- identity documents;
- spreadsheets;
- images;
- PDFs;
- supporting business records; and
- other files required to operate the Services.
Communications. Information contained within:
- customer support requests;
- emails;
- chat conversations;
- feature requests;
- surveys;
- meeting notes;
- feedback;
- support tickets.
5.2 Information collected automatically
When the Services are used, certain technical information may be collected automatically.
Device information. Examples include:
- browser type;
- operating system;
- application version;
- device identifiers;
- language preferences;
- time zone;
- device type.
Usage information. Examples include:
- login activity;
- feature usage;
- page views;
- navigation patterns;
- workflow completion;
- click activity;
- application performance;
- crash reports;
- diagnostic information.
Security information. Examples include:
- IP addresses;
- authentication logs;
- audit logs;
- failed login attempts;
- access history;
- security alerts;
- device security information where available.
Such information helps us protect the Services and detect fraudulent or unauthorised activity.
5.3 AI interaction information
Where Customers use AI Features, Purpl may process information including:
- prompts;
- questions;
- uploaded documents;
- images;
- spreadsheets;
- voice interactions;
- requests submitted to AI Features;
- AI-generated responses;
- user corrections;
- feedback regarding AI Outputs;
- interaction history.
This information is processed solely to:
- provide the requested AI functionality;
- improve service quality where permitted by Applicable Law;
- maintain platform security;
- troubleshoot technical issues;
- comply with legal obligations;
- improve the reliability and safety of AI Features.
Purpl does not intentionally use identifiable Customer Data or Personal Information to train publicly available artificial intelligence models without an appropriate legal basis or the Customer's explicit permission.
5.4 Information received from third parties
Where authorised by the Customer, Purpl may receive information from authorised third-party services including:
- banking integrations;
- payment service providers;
- identity verification providers;
- accounting or ERP systems;
- communication platforms;
- cloud storage providers;
- government or regulatory databases where lawfully available;
- other software integrated by the Customer.
The information received depends upon:
- the permissions granted by the Customer;
- the capabilities of the relevant integration;
- the settings configured by the Customer.
Purpl receives only the information necessary to provide the requested functionality.
6. How we use Personal Information
Purpl processes Personal Information only where there is an appropriate legal basis to do so and only for purposes consistent with this Privacy Policy, our contractual obligations and Applicable Law.
Depending on how the Services are used, we may process Personal Information for the following purposes.
6.1 Providing the Services
We use Personal Information to:
- create and administer Accounts;
- authenticate Users;
- provide access to the Services;
- configure Workspaces;
- process Customer Data;
- generate reports and dashboards;
- provide AI-assisted functionality;
- facilitate workflow approvals;
- manage subscriptions;
- process payments through authorised third-party providers;
- provide customer support;
- maintain audit logs;
- enable collaboration between Authorised Users; and
- deliver the functionality requested by the Customer.
6.2 Operating and improving the platform
We continually improve the Services by analysing information relating to:
- feature usage;
- platform performance;
- user feedback;
- support requests;
- application reliability;
- security events;
- anonymised usage trends;
- product quality; and
- customer experience.
Where reasonably practicable, product improvement activities are performed using aggregated, anonymised or de-identified information.
6.3 Platform security and fraud prevention
Personal Information may be processed to:
- authenticate Users;
- detect suspicious or fraudulent activity;
- prevent unauthorised access;
- investigate security incidents;
- monitor platform integrity;
- identify system vulnerabilities;
- maintain audit trails;
- enforce our Terms of Service;
- protect Customer Data; and
- comply with security obligations.
6.4 Customer communications
We may use your contact information to:
- respond to enquiries;
- provide customer support;
- communicate important account information;
- send security notifications;
- provide operational updates;
- notify Customers of material changes to our Services;
- notify Customers of changes to our legal documents;
- provide billing-related communications;
- respond to feedback and support requests.
Where permitted by Applicable Law, we may also send educational content, newsletters, product announcements and marketing communications. Recipients may opt out of marketing communications at any time.
6.5 Legal and regulatory compliance
We may process Personal Information where reasonably necessary to:
- comply with Applicable Law;
- respond to lawful requests from regulators, courts or government authorities;
- enforce our contractual rights;
- resolve disputes;
- investigate suspected unlawful activity;
- maintain legally required business records;
- protect the rights, property or safety of Purpl, our Customers or others.
6.6 Business operations
Personal Information may also be processed for legitimate operational purposes including:
- internal administration;
- financial management;
- business continuity;
- corporate governance;
- risk management;
- internal reporting;
- audit activities;
- merger, acquisition or corporate restructuring activities;
- insurance and legal matters.
Where possible, these activities rely upon anonymised or aggregated information.
7. AI & automated processing
Artificial Intelligence is integrated throughout the Purpl platform to improve productivity, automate repetitive activities and assist Customers in managing their businesses. This section explains how Personal Information may be processed when AI Features are used.
7.1 AI-assisted processing
Depending upon the functionality used, AI Features may assist with:
- document extraction;
- OCR;
- invoice interpretation;
- receipt processing;
- transaction categorisation;
- report generation;
- financial summaries;
- forecasting;
- business insights;
- workflow recommendations;
- conversational assistance;
- multilingual translation;
- natural language search;
- voice interactions;
- image understanding;
- future AI-powered functionality introduced by Purpl.
AI Features are intended to support Customers rather than replace human judgement.
7.2 AI inputs
Where Customers voluntarily use AI Features, information submitted for AI processing may include:
- prompts;
- questions;
- uploaded documents;
- spreadsheets;
- images;
- voice recordings;
- Customer Data;
- business records;
- financial information;
- operational information;
- user instructions.
Customers should submit only information that they are authorised to process and upload through the Services.
7.3 AI outputs
AI-generated Outputs may include:
- summaries;
- recommendations;
- classifications;
- explanations;
- forecasts;
- suggested accounting categories;
- draft communications;
- business insights;
- generated reports;
- workflow suggestions.
AI-generated Outputs are produced using probabilistic technologies and may contain inaccuracies, omissions or inconsistencies. Customers remain responsible for reviewing AI-generated Outputs before relying upon them.
7.4 Human oversight
Purpl designs AI Features to support human decision-making. Unless expressly stated otherwise, Purpl does not make legally binding decisions on behalf of Customers using Artificial Intelligence.
Customers remain responsible for:
- reviewing AI Outputs;
- approving transactions;
- making business decisions;
- determining tax treatments;
- complying with Applicable Law;
- obtaining professional advice where appropriate.
7.5 AI model training
Purpl does not intentionally use identifiable Customer Data or Personal Information to train publicly available Artificial Intelligence models without an appropriate legal basis or the Customer's explicit permission.
Where permitted by Applicable Law, Purpl may use:
- anonymised information;
- aggregated information;
- de-identified information;
- statistical information; and
- operational metrics
for purposes including:
- improving the Services;
- evaluating AI performance;
- enhancing security;
- improving product quality;
- research and development.
Such information will not be used to identify individual Customers or individuals.
7.6 AI service providers
Purpl may use authorised third-party AI technologies to provide AI Features. Such providers are contractually required, where appropriate, to:
- process information only for authorised purposes;
- maintain appropriate confidentiality;
- implement reasonable security safeguards; and
- comply with applicable legal obligations.
Purpl may change AI providers from time to time as technology evolves.
7.7 Automated decision-making
Purpl may use automated technologies to:
- detect fraud;
- identify unusual activity;
- recommend workflow improvements;
- categorise transactions;
- prioritise support requests;
- improve application performance.
However, Purpl does not intentionally use solely automated processing to make decisions that produce legally binding or similarly significant effects on individuals without appropriate human involvement, except where permitted by Applicable Law.
8. Sharing Personal Information
Purpl does not sell Personal Information.
We share Personal Information only where reasonably necessary to provide the Services, comply with Applicable Law or operate our business. Information may be shared with the following categories of recipients.
8.1 Service providers
We may share information with authorised service providers supporting:
- cloud infrastructure;
- hosting;
- authentication;
- communications;
- payment processing;
- customer support;
- analytics;
- document processing;
- Artificial Intelligence;
- identity verification;
- application monitoring;
- security services.
Service providers process information only for authorised purposes and under appropriate contractual obligations.
8.2 Professional advisers
Where reasonably necessary, information may be shared with:
- legal advisers;
- auditors;
- insurers;
- accountants;
- consultants; and
- other professional advisers
who are subject to appropriate confidentiality obligations.
8.3 Corporate transactions
If Purpl is involved in:
- a merger;
- acquisition;
- investment transaction;
- financing;
- sale of assets;
- restructuring; or
- other corporate reorganisation,
Personal Information may be transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.
8.4 Legal requirements
We may disclose Personal Information where reasonably necessary to:
- comply with Applicable Law;
- respond to lawful requests from courts or regulators;
- protect legal rights;
- investigate unlawful activity;
- prevent fraud;
- protect the safety of Customers or others.
8.5 Customer instructions
Where the Customer instructs or authorises Purpl to disclose information to another party, we may do so in accordance with those instructions. Examples include:
- external accountants;
- auditors;
- banking partners;
- lenders;
- investors;
- advisers;
- integration partners.
9. International data transfers
Purpl operates as a cloud-based software platform. Accordingly, Personal Information may be processed or stored in jurisdictions outside the country in which it was originally collected.
Where Personal Information is transferred internationally, Purpl seeks to implement appropriate safeguards designed to protect Personal Information in accordance with Applicable Law. Such safeguards may include:
- contractual protections;
- recognised adequacy mechanisms;
- encryption;
- organisational security measures;
- access controls;
- transfer impact assessments where appropriate.
Customers acknowledge that cloud-based software services may involve processing across multiple jurisdictions in order to provide secure, resilient and reliable Services.
Regardless of where Personal Information is processed, Purpl seeks to apply consistent privacy and security standards across its operations.
Part III — Protecting your information
10. Information security
Protecting Customer Data and Personal Information is fundamental to the design and operation of the Services.
Purpl implements technical, organisational and administrative measures designed to protect information against unauthorised access, disclosure, alteration, destruction and other unlawful processing. Our security programme is designed to evolve alongside changes in technology, cyber threats and regulatory expectations.
10.1 Security measures
Depending on the nature of the Services, security measures may include:
- encryption of data in transit;
- encryption of data at rest where appropriate;
- role-based access controls;
- authentication and identity management;
- multi-factor authentication where available;
- audit logging;
- infrastructure monitoring;
- vulnerability management;
- secure software development practices;
- backup and disaster recovery procedures;
- incident response processes;
- access management controls;
- employee confidentiality obligations; and
- periodic security reviews.
The security measures implemented may evolve over time as technology and security practices develop.
10.2 Customer responsibilities
Security is a shared responsibility. Customers are responsible for:
- protecting usernames and passwords;
- enabling multi-factor authentication where available;
- assigning appropriate User permissions;
- removing Users who no longer require access;
- securing devices used to access the Services;
- maintaining appropriate internal security procedures;
- promptly notifying Purpl of suspected security incidents.
10.3 No absolute security
While Purpl seeks to implement appropriate security measures, no internet-connected platform or technology can guarantee absolute security. Accordingly, Purpl cannot guarantee that unauthorised access, cyberattacks or security incidents will never occur.
11. Data retention
Purpl retains Personal Information only for as long as reasonably necessary to:
- provide the Services;
- fulfil contractual obligations;
- comply with Applicable Law;
- resolve disputes;
- enforce legal rights;
- maintain platform security;
- protect legitimate business interests.
Retention periods depend upon factors including:
- the nature of the information;
- legal and regulatory obligations;
- contractual commitments;
- operational requirements;
- the Customer's Subscription status.
Following expiry of the applicable retention period, Personal Information may be:
- securely deleted;
- anonymised;
- aggregated; or
- archived where required by Applicable Law.
Customers should export any Customer Data they require before terminating their Subscription.
12. Your privacy rights
Privacy rights vary depending on the jurisdiction in which an individual resides and the data protection laws applicable to the relevant processing activity.
Purpl is committed to respecting and responding to privacy rights in accordance with Applicable Law. Depending on the circumstances, individuals may have one or more of the following rights regarding their Personal Information.
The availability and scope of these rights may vary under different privacy laws, including those applicable within the United Arab Emirates, the Dubai International Financial Centre (DIFC), the European Economic Area, the United Kingdom, Singapore and other jurisdictions in which Purpl operates or provides its Services.
12.1 Right of access
You may request confirmation of whether Purpl processes your Personal Information and, where applicable, request access to that information.
12.2 Right to correction
You may request correction of inaccurate, incomplete or outdated Personal Information. Where functionality is available, certain information may also be updated directly through your Account.
12.3 Right to erasure
You may request deletion of your Personal Information where:
- the information is no longer required;
- consent has been withdrawn where processing is based solely on consent;
- processing is unlawful; or
- Applicable Law requires deletion.
This right remains subject to legal, contractual and regulatory retention obligations.
12.4 Right to restrict processing
Where permitted by Applicable Law, you may request that Purpl temporarily restrict certain processing activities relating to your Personal Information.
12.5 Right to object
Where processing is based upon legitimate interests, you may object to that processing where permitted by Applicable Law. Purpl will consider each request in accordance with applicable legal requirements.
12.6 Right to data portability
Where Applicable Law provides such a right, you may request a copy of certain Personal Information in a structured, commonly used and machine-readable format.
12.7 Withdrawal of consent
Where processing is based solely upon consent, you may withdraw that consent at any time. Withdrawal does not affect processing undertaken before consent was withdrawn.
12.8 Exercising your rights
Privacy requests may be submitted through:
- Account settings where available;
- customer support;
- the contact details provided within this Privacy Policy.
Purpl may request reasonable information to verify the identity of the individual making the request before responding.
13. Cookies, mobile SDKs and similar technologies
Purpl uses cookies and similar technologies to support the operation, security and performance of the Services. For simplicity, this Privacy Policy refers to these technologies collectively as "Cookies".
These technologies may include:
- browser cookies;
- local storage;
- session storage;
- mobile Software Development Kits (SDKs);
- application identifiers;
- web beacons;
- pixels;
- similar technologies used to store or retrieve information from a device.
13.1 Why we use Cookies
We use Cookies to:
- authenticate Users;
- maintain secure login sessions;
- remember preferences;
- improve platform performance;
- protect against fraud;
- analyse platform usage;
- improve customer experience;
- maintain platform reliability;
- support security monitoring.
13.2 Categories of Cookies
Essential Cookies support:
- authentication;
- session management;
- security;
- fraud prevention;
- application settings;
- load balancing.
These Cookies are necessary for the operation of the Services.
Functional Cookies help remember User preferences including:
- language settings;
- display preferences;
- dashboard configuration;
- recently used features;
- interface customisation.
Analytics and performance technologies help Purpl understand:
- feature usage;
- platform reliability;
- application performance;
- navigation patterns;
- error rates;
- customer experience.
Where reasonably practicable, analytics are performed using aggregated or de-identified information.
Mobile applications. The Purpl mobile applications may use technologies functionally similar to Cookies, including application identifiers and mobile SDKs. These technologies support:
- authentication;
- security;
- analytics;
- application performance;
- crash diagnostics.
The same privacy principles described in this Privacy Policy apply to these technologies.
13.3 Managing Cookies
Most web browsers allow Users to:
- view Cookies;
- delete Cookies;
- block Cookies;
- configure Cookie preferences.
Disabling essential Cookies may affect the availability or functionality of certain features of the Services.
Where required by Applicable Law, Purpl will obtain consent before using non-essential Cookies.
14. Marketing communications
Where permitted by Applicable Law, Purpl may send communications relating to:
- new product features;
- educational content;
- newsletters;
- webinars;
- events;
- product announcements;
- promotional offers.
Recipients may unsubscribe from marketing communications at any time.
Even where marketing communications are disabled, Purpl may continue sending service-related communications including:
- security alerts;
- billing notices;
- account notifications;
- legal updates;
- operational communications.
Part IV — Legal & governance
15. Controller and processor roles
Purpl's role under applicable data protection legislation depends upon the circumstances in which Personal Information is processed.
15.1 When Purpl acts as controller
Purpl generally acts as a data controller when processing Personal Information relating to:
- Account administration;
- subscription management;
- billing;
- customer support;
- website visitors;
- marketing communications;
- platform security;
- fraud prevention;
- legal compliance.
In these circumstances, Purpl determines the purposes and means of processing.
15.2 When Purpl acts as processor
Purpl generally acts as a data processor when processing Customer Data on behalf of Customers through the Services. Examples include Personal Information relating to:
- employees;
- customers;
- suppliers;
- contractors;
- directors;
- shareholders;
- financial transactions;
- uploaded business documents.
In these circumstances, Customers determine the purposes and means of processing and remain responsible for ensuring that such processing complies with Applicable Law.
Enterprise Customers may enter into a separate Data Processing Agreement where appropriate.
16. Children's privacy
The Services are designed for businesses and business users. Purpl does not knowingly provide Services directly to children or intentionally collect Personal Information from individuals below the minimum age permitted under Applicable Law.
If Purpl becomes aware that such information has been collected inappropriately, reasonable steps will be taken to delete it where required by Applicable Law.
17. Security incidents & data breaches
Purpl maintains procedures designed to identify, investigate, manage and respond to security incidents affecting Personal Information.
Where required by Applicable Law, Purpl will:
- investigate suspected incidents;
- take reasonable steps to contain the incident;
- notify affected Customers where legally required;
- notify relevant regulatory authorities where applicable;
- implement corrective measures designed to reduce the likelihood of recurrence.
Customers also play an important role in protecting Personal Information and should promptly notify Purpl if they become aware of:
- unauthorised access;
- compromised credentials;
- suspected data breaches;
- suspicious activity affecting their Account.
18. Changes to this Privacy Policy
Purpl may update this Privacy Policy from time to time to reflect:
- changes to the Services;
- legal or regulatory developments;
- technological improvements;
- security enhancements;
- operational requirements;
- new platform capabilities.
The most current version will always be made available through the Services.
Where changes materially affect the processing of Personal Information, Purpl will provide reasonable notice through appropriate communication channels.
Continued use of the Services after the effective date of the updated Privacy Policy constitutes acknowledgement of the revised Privacy Policy.
19. Contact us
Questions regarding this Privacy Policy or requests relating to Personal Information may be submitted using the contact channels published within the Services or on Purpl's official website.
Privacy requests should include sufficient information to enable Purpl to:
- verify the identity of the requester where appropriate;
- understand the nature of the request;
- respond within the timeframes required by Applicable Law.
20. Governing law
This Privacy Policy shall be governed by and interpreted in accordance with the laws of the Dubai International Financial Centre (DIFC), United Arab Emirates, except to the extent that mandatory privacy or data protection legislation applicable to the processing of Personal Information requires otherwise.
Nothing in this Privacy Policy limits any rights that individuals may have under applicable privacy or data protection laws.
Version history
- 2.0 — 31 July 2026 — Consolidated Privacy Policy for production release.
- Pilot v1.0 — 24 June 2026 — Pilot-phase policy, superseded by 2.0.
Related documents
This Privacy Policy should be read together with the:
- Purpl Terms of Service; and
- any applicable Data Processing Agreement entered into between Purpl and an enterprise Customer.
Where there is any inconsistency between this Privacy Policy and a separately executed Data Processing Agreement, the Data Processing Agreement shall prevail to the extent of that inconsistency in relation to Personal Information processed under that agreement.