01
Start with the real organisation and processing
Identify the legal controller, contact route, forms, accounts, payments, analytics, marketing, uploads, booking and communications. Do not describe features the service does not use.
02
Connect data, purpose and lawful basis
For each activity record the data involved, purpose and applicable lawful basis. Consent is not the only possible basis and should not be selected automatically.
03
Explain providers and transfers
List material processor categories and important named services where useful. Review hosting, email, payments, analytics, chat, AI and booking providers, including subprocessors and international transfer mechanisms.
04
Retention, security, rights and complaints
Give meaningful retention criteria, explain proportionate security without guarantees, and provide a usable rights and complaint route.
Practical next steps
Checklist
- 01Identify the controller
- 02Map collection points
- 03Record purposes and bases
- 04Review processors and transfers
- 05Set retention rules
- 06Explain rights and complaints
- 07Review after service changes
Common questions
Questions and answers
Is a template enough?
Only after it is tailored to actual processing and appropriately reviewed.
Is it the same as terms and conditions?
No. Terms govern the service relationship; privacy information explains personal-data processing.
Where should it be linked?
From a persistent footer and near relevant collection points where layered information is appropriate.
Need a considered recommendation?
Discuss the website, not just the symptom.
AHANIX reviews each requirement manually. Technical recommendations may depend on access to the website, hosting or DNS configuration.
Continue learning