Draft starting structure — replace all bracketed placeholders, verify the actual operation of your website, and obtain an appropriate legal review before publishing. This draft is not legal advice.
Last updated: [DATE]
1. Introduction
[COMPANY NAME] is operated by [LEGAL COMPANY NAME], established at [ADDRESS], [COUNTRY]. This policy explains how we handle personal information connected with this website and direct communications with our business. For privacy questions, contact [EMAIL].
2. Information We Collect
When you contact us directly, we may receive your name, professional contact details, organisation and the information you choose to share. Our hosting provider may process technical information, such as an IP address, browser information and security logs, to operate the website.
[Describe the information actually collected, its sources, the hosting provider, and any analytics or other services in use. Remove anything that does not apply.]
3. How We Use Information
We use relevant information to respond to enquiries, discuss potential engagements, maintain professional communications and protect the operation of the website. We limit the use of personal information to the purposes described in the final version of this policy.
[Identify each processing purpose and its applicable legal basis, including how any consent can be withdrawn.]
4. Cookies
[Describe any cookies and similar technologies actually used, their providers, purposes and duration. Explain the choices available to visitors and implement consent controls where applicable. Verify this section after adding any plugins, embeds or analytics.]
5. Third-Party Services
We may use service providers for hosting, email and business administration. External links, including links to social platforms, lead to websites operated by their respective providers and governed by their own privacy policies.
[List relevant service providers, categories of recipients, processing locations, and any applicable international-transfer safeguards.]
6. Data Retention
[Specify retention periods or the criteria used to determine them for enquiries, client communications, security logs and other relevant records. Describe deletion or anonymisation practices and applicable record-keeping obligations.]
7. Data Security
We aim to use appropriate organisational and technical measures to protect personal information. No transmission or storage system can be guaranteed completely secure. Please avoid sending sensitive information in an initial, unsolicited email.
[Confirm the safeguards that accurately reflect your business practices.]
8. Your Rights
Depending on the law that applies to you, you may have rights concerning access, correction, deletion, restriction, objection, portability or withdrawal of consent. To ask about exercising a right, contact [EMAIL]. We may need to verify your identity before responding.
[Confirm the rights, response periods, exceptions and relevant supervisory authority for your jurisdiction, including how to raise a complaint.]
9. Changes to This Policy
We may update this policy as our practices or legal requirements change. The latest published version will be available on this page with its revision date. [Describe any additional notification process where applicable.]
10. Contact
[LEGAL COMPANY NAME]
[ADDRESS]
[COUNTRY]
Email: [EMAIL]