Templates · Core pack

Privacy policy template for UK startups.

The privacy policy is the first legal document most startups need: the moment your site has a contact form, a signup box, or analytics, you are handling personal data and UK GDPR requires you to explain what you do with it.

This template drafts the full notice from settings you control, then checks it against the GDPR and UK DPA 2018 rulepacks, so what you publish actually says what the law requires it to say.

When you need it

The moments this document comes up.

  • Your website collects anything: a contact form, an email signup, analytics, or account registration.
  • A customer's procurement or security review asks for your privacy notice before signing.
  • You are adding a new tool (CRM, analytics, support desk) that touches personal data and the current policy does not mention it.
  • An investor's counsel asks for your data protection documents during due diligence.

What's inside

What the template covers.

The sections below mirror the document the generator drafts. Every template is a starting point, not legal advice, and says so on its face.

01

Who we are

The controller's identity: company, registration, registered office, and the contact for privacy questions.

02

What we collect

Account, billing, usage, and content data, each described in plain English rather than catch-all categories.

03

Why we process it

The lawful basis for each purpose: contract, legitimate interests, consent, and legal obligation, mapped the way UK GDPR expects.

04

How long we keep it

Retention periods for account data and billing records, with the statutory periods where the law sets them.

05

Who we share it with

Processors, the DPA that binds them, the no-selling commitment, and how international transfers are covered.

06

Your rights

Access, correction, deletion, restriction, portability, and objection, plus how to complain to the ICO.

Settings, not blanks

Drafted from choices you make.

A downloaded template hands you someone else's prose with holes in it. Here the document is generated from a settings sheet, so the wording follows your answers, and changing an answer later regenerates the parts it touches.

PRIVACY POLICY

SETTINGS
  • JurisdictionEngland & Wales
  • Analytics in useYes
  • Marketing emailOpt-in
  • Retention period30 days after deletion
Generate document

After generating, the document opens in the editor like any other: edits arrive as tracked changes you accept or reject, compliance checks run against real rulepacks, and exports come out as print-ready PDF or DOCX your lawyer can redline. What a compliance check actually does →

FAQ

Fair questions.

Does my startup actually need a privacy policy?

Almost certainly. UK GDPR applies from your first user, customer, or employee; there is no exemption for being small or pre-revenue. If your website has a form or analytics, you are processing personal data and must tell people what you do with it.

What must a UK privacy policy include?

UK GDPR (Articles 13 and 14) requires specifics: who the controller is, what you collect, the lawful basis for each purpose, how long you keep it, who you share it with, international transfers, and the rights people have, including the right to complain to the ICO.

The GDPR rulepack in StartupDocs checks your finished policy against that list item by item, so a missing lawful basis or an unmentioned processor shows up as a finding with a proposed fix.

Is one policy enough for both my website and my product?

Often yes at startup size, if the policy clearly covers both the site visitor data (analytics, cookies, forms) and the product data (accounts, billing, content). The template is structured to cover both; if your product processes customer data in an unusual way, that is the part to have a solicitor read.

Draft your privacy policy this week.

It is one of the first-week five: drafted, checked, and exported inside the 7-day free trial. Pay and not have your documents? One email within 30 days refunds every penny, and every export stays yours.