Legal
Purple Engage Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the Purple Engage Terms of Service or the applicable order form and master services agreement between Purple WiFi Limited (Purple, we, us) and the customer using Purple Engage (Customer, you).
It applies whenever Purple processes Customer Personal Data on Customer's behalf in providing Purple Engage.
1. Definitions and roles
Customer Personal Data means personal data that Purple processes on Customer's behalf in providing Engage.
Data Protection Laws means applicable data-protection and privacy laws, including the UK GDPR, EU GDPR and, where applicable, US state privacy laws.
Controller, processor, personal data breach, processing and related terms have the meanings given to them in applicable Data Protection Laws.
Customer is the controller, or business, of Customer Personal Data. Purple is the processor, or service provider. Purple is an independent controller for personal data about its own account users, billing contacts, visitors and representatives, as described in the Purple Engage Privacy Notice.
2. Processing instructions
Purple will process Customer Personal Data only on Customer's documented instructions, including the Terms of Service, this DPA, the applicable Subscription Details, Customer's documented use of Engage and Customer's API requests, unless Data Protection Laws require otherwise.
If we are required by law to process Customer Personal Data differently, we will inform Customer before doing so unless the law prohibits us from providing that information.
Customer is responsible for ensuring that its instructions and Customer Personal Data comply with Data Protection Laws.
3. Confidentiality and security
Purple will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
Purple will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking account of the risks of processing. These measures include:
- individual accounts, role-based permissions, authentication controls and removal of access when it is no longer required;
- logical customer-data segregation and controls designed to prevent cross-customer access;
- encryption in transit using current industry-standard protocols and appropriate protection for stored data, credentials and secrets;
- secure development, controlled deployment, vulnerability management and remediation appropriate to risk;
- backup, restoration, resilience and incident-management measures proportionate to the Service;
- security and administrative logging, monitoring for abuse and incident investigation;
- security training, confidentiality obligations and access reviews for personnel who may access Customer Personal Data; and
- periodic review of material security measures and service providers that process Customer Personal Data.
Purple may update these measures provided that the update does not materially reduce the overall level of protection.
4. Sub-processors
Customer gives Purple general written authorisation to use sub-processors to provide Engage.
Purple uses the following categories of sub-processor where required by the features Customer uses:
| Sub-processor | Purpose |
|---|---|
| Google Cloud | Cloud hosting, storage, database, encryption and operational logging |
| Twilio SendGrid | Email delivery and related delivery, open and click events |
| Anthropic | AI-assisted features that Customer chooses to use |
Purple will enter into a written agreement with each sub-processor that imposes data-protection obligations offering an equivalent level of protection to those required by this DPA. Purple remains responsible for its sub-processors' performance of those obligations.
Purple may appoint a new or replacement sub-processor by giving at least 30 days' notice to the account owner by email and by updating the current sub-processor list on this page. Customer may object during that notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If this is not reasonably possible, Customer may terminate the affected Service before the change takes effect and receive a refund of unused prepaid fees for that affected Service.
A provider chosen, contracted and controlled directly by Customer through an Engage integration is not Purple's sub-processor merely because Customer connects it to Engage.
5. Assistance
Taking account of the nature of the processing and the information available to Purple, Purple will provide reasonable assistance to Customer with:
- responding to data-subject requests;
- maintaining appropriate security;
- notifying and managing personal data breaches;
- carrying out data protection impact assessments; and
- consulting a supervisory authority where a data protection impact assessment indicates an unmitigated high risk.
Purple will not respond directly to a request about Customer Personal Data except to redirect the requester to Customer, unless required by law. Purple may charge reasonable fees for assistance that materially exceeds the self-service tools and standard support included in the applicable plan.
6. Personal data breaches
Purple will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to Purple so Customer can meet its notification obligations. Purple will provide updates as further information becomes available.
7. Audit and information rights
Purple will make available information reasonably necessary to demonstrate compliance with this DPA. Where that information is insufficient for Customer to meet a legal obligation, Customer may conduct or appoint an independent auditor to conduct an audit no more than once in any 12-month period, on at least 30 days' notice, during normal business hours, at Customer's cost and subject to reasonable confidentiality, security and non-disruption requirements.
Purple may satisfy an audit request by providing a current independent audit report, certification, security questionnaire or other evidence where this reasonably addresses the request.
8. International transfers
Purple will not make a restricted transfer of Customer Personal Data unless it has a valid transfer mechanism under applicable Data Protection Laws.
Where a restricted transfer is not covered by an adequacy decision or another permitted mechanism, Purple will use the appropriate transfer safeguards, including the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable. Purple will carry out any transfer assessment required by law and apply supplementary measures where appropriate.
9. Return and deletion
During the subscription, Customer can export Customer Personal Data through Engage or request reasonable assistance where an available export is insufficient.
When the Service ends, Customer may choose that Purple returns or deletes Customer Personal Data. Unless Customer gives another instruction, Purple will make the data available for export for 30 days and then delete it. Purple may retain Customer Personal Data only where required by law, and then only for the required period and purpose.
Where immediate deletion from backups is not technically feasible, Purple will put the data beyond active use, protect it under this DPA and delete it on the next applicable backup-deletion cycle.
10. US state privacy terms
To the extent applicable US state privacy law applies to Customer Personal Data, Purple is a service provider or processor and will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data outside the direct business relationship with Customer or other permitted purposes under applicable law;
- combine Customer Personal Data with personal data from another source except as permitted by law; or
- use Customer Personal Data for targeted advertising on Purple's own behalf.
Purple will notify Customer if it determines that it can no longer meet these obligations. Customer may take reasonable and appropriate steps to ensure Purple uses Customer Personal Data consistently with Customer's obligations, subject to the audit provisions in this DPA.
11. Liability
Each party will indemnify, keep indemnified and defend the other against costs, claims, damages and expenses incurred by the other because of that party's breach of this DPA or applicable Data Protection Laws. Each party's aggregate liability under this indemnity is limited to three times the fees paid or payable by Customer for the Service in the 12 months before the event giving rise to the claim, or £500 where Customer uses only a free plan, unless the applicable Subscription Details or master services agreement expressly states otherwise.
All other liability arising under this DPA is subject to the liability provisions in the Purple Engage Terms of Service or applicable master services agreement.
Annex: Processing details
| Item | Detail |
|---|---|
| Subject matter | Providing Purple Engage, including contact management, segmentation, communications, forms, surveys, automations, reporting, integrations and AI-assisted features selected by Customer. |
| Duration | The subscription term plus the return and deletion period in section 9. |
| Nature and purpose | Hosting, storing, organising, retrieving, transmitting, analysing and deleting Customer Personal Data as necessary to provide, secure and support Engage in accordance with Customer's instructions. |
| Data subjects | Customer's contacts, including customers, guests, visitors, prospects, members, loyalty participants, survey respondents, marketing recipients and Customer's authorised users. |
| Categories of personal data | Identity and contact details; preferences and consent records; venue, event, form, purchase, loyalty and survey data; message and engagement history; device or online identifiers where collected; custom fields Customer chooses to store; and integration data Customer chooses to connect. |
| Special-category data | Not intended. Customer must not upload special-category data unless it has a valid lawful basis, has given any required notices and has agreed the need with Purple in writing. |