Understand your data rights under UK GDPR: how to access your data, delete your account and how Purple Visits protects your privacy and personal information.
We’re committed to protecting your privacy and being transparent about how we collect, use and protect your personal information. This page explains your rights under UK data protection law (UK GDPR) and how Purple Visits handles your data responsibly.
Purple Visits data rights include UK GDPR rights to access personal data, delete Purple Visits account, understand data protection practices and submit DSAR requests for prison video calling services. Purple Visits complies with UK GDPR and Data Protection Act 2018, offering right to erasure, data subject access requests, secure data storage in UK data centers and transparent data retention periods including call recording retention requirements and identity verification document storage policies for prison video calling data protection.
We understand that trust is essential when sharing personal information, especially in the context of staying connected with loved ones in custody. Here’s everything you need to know about your data rights and our privacy practices.
Under UK data protection law, you have important rights regarding your personal information. We’ve simplified this section to focus on the two most relevant rights for Purple Visits users.
You have the right to know what personal data we hold about you. This is called a Data Subject Access Request (DSAR).
What you can request: You can ask for a copy of all personal data we hold about you, details about how we use your data, who we share it with and how long we keep it.
How to request your data: Visit our Data Subject Access Request form, complete it with your details and we’ll verify your identity to protect your privacy. You’ll receive your data within 30 days and this service is completely free.
What you’ll receive: We’ll provide your account information (name, email, phone, address), the identity verification documents you provided, contact details (prisoner names and relationships), call history and metadata (dates, times, durations), any correspondence with our support team and information about how your data has been used.
We may need to verify your identity before fulfiling your request - this protects your privacy by ensuring we only share your data with you.
You have the right to request that we delete your account and personal information.
How to delete your account:
Option 1: Through the App (Quickest)
Option 2: Contact Support
Important considerations before deleting:
⚠️ What happens when you delete your account: Your account will be permanently deleted, you won’t be able to book new video calls, your contact information will be removed and you won’t be able to undo this action.
⚠️ What we must keep (legal requirements): Call recordings are kept for a minimum of 93 days from the call date due to establishment security requirements. Financial records are kept for 6 years as required by tax law. Identity verification documents and account records may be kept up to 6 years due to legal and safeguarding requirements.
These retention periods are required by law and establishment security policies. We cannot delete this information earlier, even if you request it.
When deletion may be delayed: Your deletion request may be delayed if there’s an ongoing investigation involving your account, if there are outstanding payments or refunds or if we’re required to keep records by law or court order.
We only collect data that’s necessary to provide you with secure video calling services and comply with legal requirements.
We collect basic details including your name, date of birth, email address, phone number and postal address. We need this information to create and manage your account, verify your identity and contact you about your bookings.
We collect photo ID such as your passport, driving licence or other government-issued ID, along with verification selfies. This is required by prison security - establishments need to verify the identity of everyone who communicates with prisoners. Children under 18 don’t need to provide ID verification.
We collect the names and prison numbers of people you want to call, along with your relationship to them. This helps us connect you with the right person and comply with establishment safeguarding requirements.
We record video and audio of all calls, along with call metadata like date, time, duration, participants and establishment. We also collect security data including face recognition scans during calls and security selfies. Establishments require call recordings for security monitoring with a minimum 93-day retention period.
We collect information about how you use the app, device information, IP addresses, browser type and technical logs. This helps us improve the service, troubleshoot technical issues and ensure security.
We collect payment method details, which are processed securely by our payment provider, to process payments for paid video calls. We don’t store your full card details - these are handled by PCI-compliant payment processors.
We only use your personal data for specific, legitimate purposes:
We use your data to create and manage your account, process your video call bookings, connect you with people in custody and provide technical support when you need it.
We’re legally required to verify your identity (prison security requirement), record and monitor calls (establishment safeguarding requirement), comply with court orders or law enforcement requests and meet data protection and tax obligations.
Your data helps us fix technical issues and bugs, improve app functionality and user experience, develop new features and ensure security while preventing fraud.
We use your contact details to send booking confirmations and reminders, notify you about schedule changes, provide important service updates and respond to your support inquiries.
We will never sell your personal data to third parties, use your data for purposes you haven’t agreed to or share your data unnecessarily.
We limit access to your personal information to only those who need it to provide or support the service.
Only limited employees in technical, support and security roles have access to your data. They have role-based access, meaning staff only see what they need for their job. They access your data to provide technical support, troubleshoot issues and ensure service quality.
Security teams, safeguarding officers and authorised staff at the facility can see your identity, contact relationships, call recordings and metadata. They need this access for security monitoring, safeguarding prisoners and visitors and investigating incidents. This is a legal requirement - establishments must monitor communications with prisoners.
We work with carefully selected partners who help us provide the service. Our cloud hosting partner AWS (Amazon Web Services) stores data securely in UK data centers. PCI-compliant payment providers handle payments securely. Trusted verification services confirm your identity and email and SMS providers send you notifications. Third party calendar providers and other services used within prisons and secure hospitals may also have limited access to some data as listed within our Privacy Policy.
All third-party providers are GDPR-compliant, have signed data processing agreements with us, only access data necessary for their specific service and are required to protect your data to the same standards we do.
We only share data with law enforcement when legally required through court orders, warrants or legal investigations. We only provide the specific information requested by legal authority and we verify all requests are legally valid before sharing any data. We do not provide data to law enforcement without proper legal authority.
We only keep your personal data as long as necessary to provide the service and comply with legal requirements.
All account data is kept while you maintain an active account. Call recordings are kept for a minimum of 93 days from the call date due to establishment requirements. Identity documents are kept while your account is active and up to 6 years after closure.
Call recordings are kept for a minimum of 93 days from the call date, even after account deletion. Financial records are kept up to 6 years as required by tax law. Identity verification documents and account records may be kept up to 6 years for legal obligations and fraud prevention. Other personal data is deleted within 30 days of account closure.
Call recordings must be kept for 93 days due to prison security requirements for monitoring and investigations. UK law requires businesses to keep certain records (financial, identity, account records) for 6 years for tax, legal and safeguarding purposes. Records related to ongoing investigations must be kept until resolved.
We take data protection seriously and use multiple layers of security to keep your information safe.
All data is encrypted in transit and at rest (AES-256). Our UK-based data centers have physical security controls and we implement role-based access controls with multi-factor authentication for staff. We provide 24/7 security monitoring for suspicious activity and conduct regular independent security audits.
We hold Cyber Essentials Plus certification, a government-backed security standard. We’re fully compliant with UK data protection law (UK GDPR) and follow international security best practices including ISO standards.
For detailed information about our security measures, see our Security and Privacy guide.
We don’t store passwords in plain text (they’re encrypted), share data with unauthorised parties, access your data without valid reason or keep data longer than legally required.
When you use Purple Visits, certain information must be shared with the prison or custodial establishment.
Establishments receive your verified identity (name, photo ID, verification documents), contact relationship information (who you’re calling and your relationship), call recordings and metadata (dates, times, participants) and security incident reports if any issues occur.
This data sharing is a security requirement - establishments must know who is communicating with prisoners. It’s essential for safeguarding to protect both prisoners and visitors from harm. It’s a legal obligation required by prison regulations and security policies and it helps resolve any security incidents through investigation support.
You consent to this data sharing when you create an account. You can withdraw consent by deleting your account, though establishments handle your data under their own privacy policies. Contact the establishment’s data protection officer if you have questions about their data handling.
While we protect your data, you also have responsibilities:
Use unique, complex passwords and never share your account with others. Always log out on shared devices and contact us immediately if you suspect unauthorised access.
Provide genuine ID documents, keep your contact information up to date and accurately describe your relationship to contacts.
All calls are recorded and may be monitored. Prison staff may review your calls, so don’t expect complete privacy. Comply with establishment communication policies.
Don’t share call recordings - they’re for security purposes only. Don’t share prisoner details publicly and let us know if someone asks you to share sensitive information.
We’ve made it easy to access, update or delete your information.
Through the app: Log in, go to Settings → Account Information and update your email, phone or address as needed. Changes take effect immediately.
Contact details: Update your contacts in the Contacts section of the app. Changes must be verified before use.
Through the app: Go to Settings → Account Settings → Delete My Account.
Via email: Email [email protected] with “Delete My Account” in the subject line.
Remember: Some data must be kept for legal requirements (see “Right to Erasure” above)
For questions, concerns or to exercise your rights, email us at [email protected] with “Data Privacy Inquiry” in the subject line. Include your full name, the email address associated with your account, your specific question or request and any relevant reference numbers. We aim to respond to all privacy inquiries within 5 business days.
We use cookies and similar technologies to improve your experience on our website and app.
We use essential cookies that are required for the website to work (security, remembering your cookie choice), and – only with your consent – analytics cookies to help us understand how people use the website, marketing cookies and support cookies for live chat.
You can manage cookie preferences in your browser settings, though blocking essential cookies may prevent the service from working properly. For detailed information, see our Cookie Policy.
On this website we use Cloudflare’s cookieless analytics, which sets no cookies and collects no personal data. We use Google Analytics only if you accept analytics cookies, and the Meta pixel only if you accept marketing cookies. Live chat (Freshworks) loads only if you accept support cookies. We don’t sell your browsing data. You can change your choices at any time using the Cookie preferences link in the footer of this website.
We take extra care with information from young users.
Children under 18 don’t need to provide photo ID verification. Parental consent is required for users under 16 in line with UK law. We only collect what’s necessary for the service and don’t send marketing communications to children.
We ask for date of birth during registration and may verify age if there are concerns. We comply with the UK age-appropriate design code.
We may update our privacy practices from time to time.
For major changes, we’ll email you in advance. Minor updates are posted on this page with an updated “Last Updated” date. If you disagree with changes, you can delete your account.
Changes might include new features that require different data collection, changes in legal requirements, improvements to security measures or updates to third-party service providers.
Check this page periodically for updates, read emails from us about privacy changes and remember that our current Privacy Policy always has the most up-to-date information.
We’re here to help if you have questions about your data rights or privacy.
For general privacy questions: Email [email protected] with “Data Privacy Inquiry” in the subject line. We respond within 5 business days.
For data access requests: Use our Data Subject Access Request form. We respond within 30 days.
For urgent security concerns: Email [email protected] with “URGENT - Security Issue” in the subject line. We respond to security concerns within 24 hours.
If you’re not satisfied with how we handle your data, you have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO). You can reach them at ico.org.uk, by phone at 0303 123 1113 or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
We hope you’ll contact us first so we can resolve your concern, but you have the right to complain to the ICO at any time.
At Purple Visits, we believe transparency builds trust.
We explain data practices in plain English, tell you exactly what we do with your data, answer your privacy questions promptly and regularly review and enhance our privacy practices.
We will never sell your personal data to third parties, use your data in ways you haven’t agreed to, hide important information in complex legal language or ignore your privacy concerns or requests.
We will always protect your data with strong security measures, be transparent about how we use your information, respect your rights under data protection law, respond to your questions and concerns and keep improving our privacy practices.
Learn more about privacy and security:
Exercise your rights:
Your privacy matters to us. We’re committed to protecting your personal information and giving you control over your data. If you ever have questions or concerns, please don’t hesitate to contact us.