Privacy Policy

A Privacy Policy is a legal document that explains how an organisation handles personal data. For a UK business, this must be transparent, concise, and easily accessible.

1. Controller Identity

You must clearly state who is responsible for the data.

  • Company Name: Registered business name.
  • Contact Details: Email address, phone number, and physical office address.
  • Data Protection Officer (DPO): If the business is large or processes sensitive data on a large scale, contact details for the DPO must be included.

Categorise the data types you process:

  • Identity Data: Names, usernames, titles.
  • Contact Data: Billing addresses, delivery addresses, email addresses, phone numbers.
  • Technical Data: IP addresses, login data, browser types, operating systems (often related to cookies).
  • Financial Data: Bank account and payment card details.

3. Lawful Basis for Processing

Under UK GDPR, you must have a valid legal basis to process data. You should disclose which of these you rely on for different activities:

  • Consent: The user has given clear consent.
  • Contract: The data is necessary for a contract (e.g., fulfilling an order).
  • Legal Obligation: You are required to process the data by law (e.g., tax records).
  • Legitimate Interests: Processing is necessary for your legitimate interests (and these are not overridden by user rights).

4. How Data is Used

Explain the purpose of the collection in plain English (e.g., “to register you as a new customer,” “to process your order,” “to manage our relationship with you”).

5. Data Sharing (Third Parties)

You must disclose if you share data with:

  • Service providers (e.g., payment processors like Stripe, email marketing tools like Mailchimp).
  • Regulators or law enforcement if required by law.
  • External third parties (explain why).

6. International Transfers

If you transfer data outside the UK (e.g., using a US-based cloud host), you must explain the safeguards in place to protect that data (e.g., Standard Contractual Clauses or UK-US Data Bridge).

7. Data Retention

State clearly how long you keep the data. You must not keep personal data for longer than is necessary for the purposes for which it was collected.

8. User Rights

Your policy must inform users of their rights under the UK GDPR:

  • Right to Access: Request a copy of their personal data.
  • Right to Rectification: Request correction of inaccurate data.
  • Right to Erasure (Right to be Forgotten): Request deletion of data.
  • Right to Restrict Processing: Limit how you use their data.
  • Right to Data Portability: Request a transfer of data to another service.
  • Right to Object: Object to processing based on legitimate interests.

9. Cookies and Tracking

Even if you have a separate Cookie Policy, a summary or a link to it must be included within your Privacy Policy.

10. How to Complain

Users have the right to lodge a complaint with the Information Commissioner’s Office (ICO). Include a link to the ICO website.

Get A Fast Quote