// privacy notice

Privacy Notice

/privacy-notice

If your business collects personal data — even just names and emails — UK GDPR requires you to tell people how you use it in a clear privacy notice: what you collect, why, your lawful basis, who you share it with, how long you keep it, and the rights people have. PrivacyReady assembles a structured privacy notice from a few answers for you to tailor to your actual processing and publish on your site.

not legal advice. For use in the United Kingdom only. A standard template; a knowledgeable person must tailor it to how you actually use data.

// inputs00/05 set

Secure one-off payment via Stripe. No account needed.

preview · privacy-notice
watermarked

// privacy-notice

Privacy Notice

Privacy Notice

[Business name] ("we", "us") is responsible for the personal data described in this notice.

Questions about your data: [contact].

1. What we collect

[the personal data you collect].

We collect this information directly from you when you contact us, buy from us, or use our services, and in some cases from third parties such as our suppliers or publicly available sources. [Add any special category data, such as health information, only if you actually collect it, and identify the additional condition you rely on.]

2. Why we use it, and our lawful basis

[your purposes].

For each purpose above we rely on a lawful basis under UK GDPR, which will be one of: your consent; the performance of a contract with you; compliance with a legal obligation; or our legitimate interests in running and improving our business (where these are not overridden by your rights). [Map each purpose above to the specific basis you rely on.]

3. How long we keep it

[retention periods].

We keep personal data only for as long as we need it for the purposes set out above, or for as long as the law requires (for example, tax and accounting records are generally kept for six years). When we no longer need it, we securely delete or anonymise it.

4. Sharing

We share personal data only where necessary: with service providers who process it on our behalf (for example payment, hosting, IT and email providers) under written contracts that require them to protect it; with professional advisers; and with authorities where we are required to do so by law. We do not sell your personal data.

If we transfer personal data outside the UK, we make sure it is protected by an approved safeguard, such as UK adequacy regulations or the International Data Transfer Agreement (or UK Addendum). [Delete this line if you do not transfer data abroad, or name the countries and safeguard if you do.]

5. Your rights

You have rights over your data, including access, correction, and erasure. To exercise them, contact us using the details above. You can also complain to the ICO.

Depending on the circumstances, you have the right to: access a copy of your data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and, where we rely on consent, to withdraw that consent at any time without affecting processing carried out before you withdrew it. We will not usually charge for these requests and will respond within one month.

You can complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, though we would welcome the chance to resolve any concern first.

draft generated by privacyready — Sample content — review with a qualified person. Not legal advice.

// frequently asked

Questions, answered.

01
Do I really need a privacy notice?
If you process any personal data, you must provide clear information about how you use it. A published privacy notice is the standard way to meet that transparency requirement. Tailor it to what you actually do.
02
What's a lawful basis?
UK GDPR requires a lawful basis for each processing purpose (for example consent, contract, or legitimate interests). Identify the right basis for each use — confirm with ICO guidance if unsure.
03
Is this legal advice or a guarantee of compliance?
No. PrivacyReady helps you draft and organise your data-protection paperwork. The wording is a standard template that must be tailored to how your business actually uses personal data. It is not legal advice and does not guarantee UK GDPR compliance. Follow ICO guidance.