← Return to Menu
🎯
What type of business are you?
This helps us set sensible defaults for your privacy policy
This sets sensible defaults for data types, purposes, and security measures. All fields remain fully customisable.
🏢
What is your organization's name?
The legal name of your business or organization
📍
What is your registered address?
Your official business address including postcode
🌐
What is your website URL?
The website this privacy policy applies to
👤
Do you have a Data Protection Officer?
Required for public authorities and large-scale data processors
Most small businesses don't need a DPO. It's required if you're a public authority or process data on a large scale.
📊
What personal data do you collect?
Select all types that apply
➕
Any other types of data?
List any additional personal data you collect
⚠️
Do you process sensitive data?
Special category data under GDPR
Special category data includes: health, race/ethnicity, religion, politics, sexual orientation, trade union membership, genetics, biometrics
❌
No special
category data
🔒
Yes, we process
sensitive data
⚖️
Do you process criminal conviction data?
For example, DBS checks for employees
🔍
Yes, DBS checks
or similar
🎯
Why do you process personal data?
Select all purposes that apply
📝
Any other processing purposes?
Add any specific purposes not listed
🍪
What types of cookies do you use?
UK PECR requires consent for non-essential cookies
🎯
All types
including marketing
🔄
Who do you share data with?
Third parties and service providers
🌍
Do you transfer data internationally?
Outside the UK to other countries
Post-Brexit, transfers outside UK need safeguards. EU has adequacy for UK. US transfers need SCCs or Data Privacy Framework.
Select the safeguards you use:
⏰
How long do you keep data?
Your general retention period
UK law requires 6 years for financial records, 3 years for PAYE, 6 years for contracts
📅
3 years after
last interaction
📋
Any specific retention periods?
Different periods for different data types
👶
Are your services for children?
UK digital age of consent is 13
🔞
Not directed
at children
🔒
What security measures do you use?
Technical and organizational measures
⚡
How quickly will you respond to data requests?
GDPR requires response within 30 days
📝
Final policy details
When does this policy take effect?