Required under the GDPR. We draft it from your actual data processing, not a generic template.
Most websites publish a document downloaded online or their CMS’s default template. These texts describe processing that does not exist, and stay silent on what actually does: contact forms, security tools, analytics, transfers outside the EU.
A document that does not match your actual processing does not fulfil your duty to inform. It mainly signals, to anyone who knows what to look for, that compliance has not been addressed.
Articles 13 and 14 of the GDPR. Informing data subjects is required from the first collection of personal data.
A breach exposes the company to a sanction from the competent supervisory authority.
Your privacy policy must cover your subcontractors (hosting, third-party tools, service providers) and the safeguards for any transfer outside the European Union.
A document that leaves this out is not compliant, even if it covers everything else.
Thirty minutes, no commitment, to identify what is missing from your compliance.