Template — not yet valid
A privacy policy must describe what you actually do with data. Copying a generic one is itself a UK GDPR breach. Before publishing, list every tool that touches customer data — payment processor, hosting, email, analytics, live chat, CRM — and make sure each appears in section 5 below.
If you monitor viewing behaviour, or you handle data for people outside the UK, take advice: those raise obligations this skeleton does not cover. Delete this notice block when the page is ready.
Privacy Policy
1. Who we are
[LEGAL COMPANY NAME] ("we", "us") is the data controller for the personal data described in this policy. We are registered in [JURISDICTION] under company number [COMPANY NUMBER], at [REGISTERED ADDRESS].
[IF YOU ARE UK-BASED AND PROCESS PERSONAL DATA, YOU LIKELY NEED TO PAY THE ICO DATA PROTECTION FEE AND STATE YOUR REGISTRATION NUMBER HERE: ICO registration [NUMBER].]
For any privacy question, contact [PRIVACY EMAIL].
2. What we collect
- Account data — name, email address, and the credentials issued to you.
- Purchase data — plan purchased, amount, date, and a payment reference. [WE DO NOT STORE FULL CARD DETAILS — CONFIRM THIS IS TRUE OF YOUR SETUP.]
- Technical data — IP address, device type, browser, and connection logs generated when you use the service.
- Support data — the content of messages you send us.
- [ANY OTHER CATEGORY YOU ACTUALLY COLLECT.]
3. Why we use it, and our lawful basis
- To provide the service you bought — lawful basis: performance of a contract.
- To take payment and prevent fraud — contract, and our legitimate interests in preventing abuse.
- To provide support — contract and legitimate interests.
- To meet legal and accounting obligations — legal obligation.
- To send marketing — consent, which you may withdraw at any time. [DELETE IF YOU DO NOT MARKET.]
4. Cookies
[DESCRIBE EVERY COOKIE THE SITE SETS. If you add analytics, advertising pixels or live chat, UK law requires informed consent before those cookies are set — which means a real consent banner, not a notice bar. The site as delivered sets no cookies and loads no analytics; if that stays true, say so here plainly.]
5. Who we share it with
We share personal data only with the providers we rely on to run the service:
- [PAYMENT PROCESSOR] — to take and reconcile payments.
- [HOSTING PROVIDER] — to host this website and our systems.
- [EMAIL PROVIDER] — to send account and support email.
- [ANY OTHER PROCESSOR — ANALYTICS, LIVE CHAT, CRM, CDN.]
We do not sell your personal data. We may disclose data where required by law or to establish or defend legal claims.
6. International transfers
[IF ANY PROVIDER ABOVE STORES DATA OUTSIDE THE UK, SAY SO HERE AND NAME THE SAFEGUARD RELIED ON — adequacy regulations or the International Data Transfer Agreement.]
7. How long we keep it
We keep account and purchase records for [PERIOD], which reflects [REASON — commonly six years for tax and accounting]. Technical logs are kept for [PERIOD]. Support messages are kept for [PERIOD]. After that, data is deleted or anonymised.
8. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- receive your data in a portable format; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these, email [PRIVACY EMAIL]. We will respond within one month.
9. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.
10. Changes
We may update this policy. The current version is always published on this page, with the date it took effect shown at the top.