Purple Post Privacy Policy

Last updated: February 2026

Please read this Privacy Policy carefully before downloading, accessing or using the Purple Post software.

Privacy Notice

This Privacy Policy explains how Made Purple Ltd collects, uses, stores and shares personal information when you use the Purple Post service. It also explains your rights under data protection law and how you can exercise them.

Made Purple Ltd is a company registered in England and Wales under company number 11151840. Made Purple Ltd operates Purple Post, a secure messaging service designed to help people in custody and their families maintain contact in line with safeguarding, security and legal requirements.

Purple Post is available to individual users and to organisations including solicitor firms, companies, charities and probation services. Organisation Accounts allow a single set of login credentials to be shared among authorised members of the organisation's team. This Privacy Policy applies to all users of the service including those using Organisation Accounts.

Data Controller and Law Enforcement Processing

For some personal data, Made Purple Ltd acts as a data controller.

For other personal data, particularly where processing is carried out for law enforcement purposes, the relevant prison, secure hospital or government authority acts as the data controller and Made Purple Ltd acts as a processor.

The role applied depends on the nature of the data and the purpose for which it is processed.

For Organisation Accounts, Made Purple Ltd acts as the data controller in respect of the operation of the Purple Post platform and the processing necessary to provide and secure the service. This includes the organisation's registration details and the Responsible Party's personal details.

Organisations using the service may act as independent data controllers in respect of the content and communications they choose to send through the service, as they determine the purpose and legal basis for those communications.

Where processing is carried out for law enforcement purposes, the relevant prison, secure hospital or government authority acts as the data controller and Made Purple Ltd acts as a processor.

Personal Data We Collect

The personal data we collect may include:

  • Full name
  • Email address
  • Date of birth
  • Postal address
  • Telephone number
  • Location information
  • Photographic identification documents
  • Profile image or verification selfie
  • Details of your approved contact including name, location and prison number
  • Items of Purple Post sent and received including text, images, GIFs and voice notes
  • Account activity and usage data
  • Technical and security related information associated with use of the service

Organisation Account Data

Where an organisation registers for an Organisation Account, we additionally collect:

  • Organisation name
  • Organisation type (solicitor firm, company, charity or probation service)
  • Registration or reference number (Companies House number, SRA number or Charity Commission number where applicable)
  • Organisation logo (where provided)
  • Verification status and source (whether the organisation was verified against an official registry)
  • Selected prison or establishment(s) the organisation wishes to communicate with
  • Responsible Party full name
  • Responsible Party job title or position
  • Responsible Party email address (which must be an organisation email address)
  • Responsible Party telephone number
  • Organisation address
  • Messages and content sent and received through the Organisation Account

We do not collect or process personal data about individual members of the organisation's team other than the named Responsible Party. Because Organisation Accounts use shared credentials, Made Purple Ltd cannot identify which individual within an organisation sent or accessed any particular message.

Purpose of Processing

We collect and process personal data to:

  • Provide, operate and secure the Purple Post service
  • Verify your identity and maintain account security
  • Enable prisons or secure hospitals to apply safeguarding and security controls
  • Prevent misuse of the platform and circumvention of safeguards
  • Detect and restrict prohibited content including inappropriate images
  • Investigate safeguarding, security or misuse concerns
  • Respond to support requests and user enquiries
  • Meet legal and regulatory obligations
  • Improve and develop the service
  • Support safeguarding through proportionate automated controls

When you send images through Purple Post, you confirm that you have the consent of any individual appearing in those images and accept responsibility for the content sent through your account.

Additional Purposes for Organisation Account Data

Where an organisation registers for an Organisation Account, we additionally process personal data to:

  • Verify the organisation's identity and registration status against official registries where available
  • Assess and process organisation account applications
  • Obtain approval from the relevant prison or establishment before activating the account
  • Enable organisations to communicate with prisoners through the Purple Post service
  • Contact the Responsible Party regarding account management, compliance matters or service updates
  • Maintain records of approved organisation accounts and their associated establishments
  • Investigate misuse or suspected non-compliance with the Terms and Conditions

Legal Basis for Processing

Contractual Processing

Personal data is processed under Article 6(1)(b) of the UK GDPR where necessary to perform the contract between you and Made Purple Ltd. This includes information such as your name, contact details and account credentials.

For Organisation Accounts, the contractual basis extends to the processing of the Responsible Party's personal data and the organisation's registration data, which is necessary to perform the contract between the organisation and Made Purple Ltd.

Made Purple Ltd is the data controller for this processing.

Legitimate Interests

Some processing is carried out under Article 6(1)(f) of the UK GDPR where it is necessary for legitimate interests, including service improvement, platform security and prevention of misuse.

For Organisation Accounts, legitimate interests also include verifying the organisation's identity and registration status against official registries, managing the ongoing relationship with the organisation, and ensuring organisations comply with the Terms and Conditions including the prohibition on legally privileged and Rule 39 communications.

Made Purple Ltd is the data controller for this processing.

Law Enforcement Processing

Where personal data is processed for law enforcement purposes, this is carried out in accordance with the Data Protection Act 2018 Part 3.

The relevant legal basis is DPA 2018 Part 3 Chapter 1 Section 35(2)(b) as the processing is necessary for the performance of a task carried out for a law enforcement purpose.

Some of this data may be classified as sensitive processing. The applicable condition is Schedule 8 paragraph 1 statutory purposes. This includes biometric data used for facial verification.

This processing may occur when:

  • A new user verifies their account using photographic identification and a selfie
  • Automated or security checks are applied before or during message sending

In these circumstances, the relevant prison, secure hospital or government authority is the data controller.

Automated Decision Making and Account Restrictions

Purple Post uses automated systems including image analysis and usage thresholds to help identify prohibited image content and potential misuse of the service.

These systems may result in:

  • Blocking individual images
  • Restricting image sending features on an account
  • Withdrawing access to image functionality or the platform in cases of continued misuse

Automated systems do not make decisions producing legal or similarly significant effects without appropriate human oversight and the opportunity for review.

Automated controls are designed to be proportionate to the custodial environment to which Purple Post is being sent.

Where automated restrictions are applied, users may contact the Purple Post support team if they believe a restriction has been applied in error. A member of the Made Purple Ltd team will review the account and may amend or remove the restriction where appropriate.

Access to Data and Monitoring

Access to personal data is restricted and controlled.

Authorised access may include:

  • Designated staff within the relevant prison or secure hospital
  • Prison management organisations and government authorities with lawful oversight
  • Law enforcement agencies acting under lawful authority
  • Authorised members of the Made Purple Ltd team

Made Purple Ltd staff may access specific messages, images or account activity where necessary to:

  • Operate and maintain the service
  • Investigate safeguarding or security concerns
  • Prevent misuse of the platform
  • Respond to support or technical requests
  • Comply with legal obligations

Such access is limited, logged and proportionate and restricted to what is necessary for the relevant purpose. Made Purple Ltd staff do not make custodial or disciplinary decisions.

Organisation Accounts and Shared Access

Organisation Accounts allow a single set of login credentials to be shared among authorised members of the organisation's team. Made Purple Ltd does not track or identify individual users within an Organisation Account. All activity on an Organisation Account is associated with the organisation as a whole. Made Purple Ltd does not create profiles of individual users within an Organisation Account.

Prisoners communicating with an Organisation Account should be informed that the account belongs to an organisation and that messages sent to or received from the account may be viewed by multiple authorised members of the organisation's staff. The organisation's name and logo (where provided) may be displayed to the prisoner.

The personal data of the Responsible Party (including name, job title, email address, telephone number and address) is retained as part of the Organisation Account record. The Responsible Party's data is processed for account management, compliance and communication purposes. This information is not provided to the prisoner or secure patient but will be shared with prison staff during the vetting process and if requested by the authority for any reason.

Organisations using the service may have their own data protection obligations under the UK General Data Protection Regulation or the Data Protection Act 2018 in connection with personal data they handle through or in connection with the service. For example, an organisation may need to inform its own staff about how their use of Purple Post is managed, or inform prisoners about the organisation's own data processing activities. These obligations are the responsibility of the organisation and are separate from the obligations of Made Purple Ltd described in this Privacy Policy.

Third Party Services

Some third party service providers may process personal data on our behalf, including:

  • Email and communication service providers
  • Hosting and infrastructure providers

Data Retention

We may retain personal account details for up to six years after account closure for legal, regulatory and audit purposes. After this period, data will be anonymised unless you have opted in to receive ongoing communications.

Messages sent via Purple Post are retained by Made Purple Ltd for up to 93 days after they have been deleted by both parties. Prisons, secure hospitals and relevant authorities may retain copies of messages in accordance with their own policies and legal obligations which may extend beyond this period.

Disabling your account will result in identity documents and verification images being deleted by Made Purple Ltd after 93 days.

Your account status does not affect the retention periods applied by custodial authorities.

The Ministry of Justice retains data in line with Prison Rule 35D and PSI 04/2016.

For Organisation Accounts, registration data including the organisation's name, type, reference number and the Responsible Party's details is retained for as long as the Organisation Account remains active, and for up to six years following account closure for legal, regulatory and audit purposes. Messages sent and received through Organisation Accounts are subject to the same retention periods as individual accounts.

International Transfers

All data held by Made Purple Ltd is stored within the United Kingdom unless the establishment receiving Purple Post is located outside the UK.

Primary data storage is in London, England. Disaster recovery backups may be stored temporarily in Cardiff, Wales.

Cookies

Our website uses temporary cookies to enable ordering and account functionality. Cookies used by Purple Post do not identify individual visitors. Further details are available in our Cookies Policy.

Your Rights

Depending on the purpose of processing, you may have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request completion of incomplete data
  • Request restriction of processing
  • Request erasure of personal data where applicable
  • Request portability of data provided under contract

These rights are subject to statutory exemptions, particularly where data is processed for law enforcement purposes.

Where personal data has been collected in connection with an Organisation Account, the Responsible Party may exercise data subject rights in respect of their own personal data. Requests relating to organisation data such as the organisation's registration details should be made by the Responsible Party or an authorised representative of the organisation. Rights requests do not affect data retained by custodial authorities or data that Made Purple Ltd is required to retain for legal or regulatory purposes.

How to Exercise Your Rights

Requests can be made by contacting our Data Protection Officer at dpo@madepurple.com. You may be required to provide proof of identity.

For data controlled by a prison or government authority, you should contact the relevant organisation directly.

Contact Details

Made Purple Ltd
Keystone Innovation Centre
Croxton Road
Thetford
Norfolk
IP24 1JD
Email: support@madepurple.com

Government Data Protection Officers

Ministry of Justice
Email: data.compliance@justice.gov.uk or DPO@justice.gov.uk
Address: 5th Floor, 102 Petty France, Westminster, London, SW1H 9AJ

States of Jersey
Email: dataprotection@gov.je

States of Guernsey
Email: data.protection@gov.gg

Northern Ireland Prison Service
https://www.justice-ni.gov.uk/contact

Scottish Prison Service
Calton House
5 Redheughs Rigg
Edinburgh
EH12 9HW

Complaints

If you believe your personal data has been mishandled, you may complain to the Information Commissioner's Office.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Email: casework@ico.org.uk

Review of This Policy

This Privacy Policy is reviewed regularly and may be updated from time to time. This version was last updated in February 2026.