Cookie Policy Generator for SaaS
Written for the controller/processor split, sub-processor lists, DPAs and enterprise security review.
SaaS cookie policies have a split personality: the marketing site runs advertising and analytics that need consent, while the authenticated app runs functional and product-analytics cookies under a different rationale. Treating them as one surface produces a banner that either breaks the app or under-protects the marketing site.
A SaaS company wears two hats simultaneously, and the single biggest failure in SaaS privacy documentation is not separating them. For your own marketing site, billing and support you are a controller. For the customer data your users push into the product you are a processor, acting on their instructions - and the disclosures, the rights, and the deletion obligations are completely different in each role.
That distinction is not academic. It determines who answers a data subject access request, who notifies a regulator after a breach, who signs which contract, and what your policy is allowed to promise. A privacy policy that describes customer-uploaded data as "your data that we use to improve our services" is describing processor data in controller language, and enterprise security reviewers will catch it.
The commercial layer matters as much as the legal one. Every enterprise deal now runs through a security questionnaire that asks for a data processing agreement, a published sub-processor list with change notification, a defined breach notification window, and a sub-processor change-objection right. Having those documents ready shortens sales cycles; not having them stalls deals at procurement.
What a cookie policy for a SaaS product has to cover
Marketing site versus in-app cookies, separated and categorised differently
Product analytics and session recording inside the authenticated app, with what they capture
Advertising and attribution tags on the marketing site
How consent is captured on the marketing site and what happens on login
Third-party embeds - chat, docs, status page, demo booking - and their cookies
How a SaaS product actually moves personal data
Customer-uploaded content (processor role)
Whatever your users put into the product, including personal data about their own customers and staff. You process it on instruction, you do not decide its purposes, and you cannot use it for your own ends without a separate basis.
Account, billing and usage data (controller role)
Names, work emails, plan, invoices, feature usage and login history. This is yours to decide about, and your privacy policy is the notice for it.
Product analytics and session recording
Tools like Amplitude, PostHog or a session recorder capture in-app behaviour - which frequently means capturing customer data as a side effect, turning an analytics decision into a processor problem.
Support tickets and screenshots
The fastest route by which processor data ends up in a controller system. A screenshot attached to a ticket lands in a helpdesk with a different retention policy.
AI features processing customer content
If your product sends customer data to a model provider, that provider is a sub-processor, and whether the data is used for training is the first question every enterprise reviewer asks.
Sales and marketing enrichment
Buying contact data and enriching leads is controller processing with a legitimate interests analysis and a notification duty under Article 14 to people whose data you did not collect from them.
Third parties the draft will ask you about
AWS or Google Cloud · Stripe · Twilio and SendGrid · Intercom or Zendesk · Amplitude or PostHog · Datadog or Sentry · HubSpot or Salesforce · OpenAI or Anthropic · Snowflake
The rules that apply
GDPR Article 28
Processor obligations: process only on documented instructions, confidentiality, security, sub-processor authorisation, assistance with rights and breaches, deletion or return at the end, and audit rights.
Sub-processor transparency
Not a statutory list requirement in itself, but the practical standard: a published list, and advance notice with an objection window before adding to it.
Transfer mechanisms in the contract chain
SCCs and the UK Addendum have to flow down to sub-processors, not just sit in the top-level agreement.
Breach notification, contractual and statutory
As a processor you notify your customer without undue delay; as a controller you notify the regulator within 72 hours in the UK and EU.
US state law service-provider terms
CCPA requires specific contract language for a recipient to count as a service provider rather than a sale.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
The SaaS compliance document set
Separate the privacy policy from the DPA
The policy covers you as controller. The DPA covers you as processor. Different audiences, different content, different signatures.
Publish a sub-processor list with a subscribe option
Name, purpose, location. Offer email notification of changes and an objection window.
Write the security page procurement actually asks for
Encryption, access control, testing cadence, incident response, and whatever certification you hold - or an honest statement that you hold none yet.
Define the breach notification window in the DPA
A stated number of hours, and an internal process that can meet it.
Decide and document your AI data position
Whether customer content reaches a model provider, whether it is used for training, and how long the provider retains it.
Build deletion and export that actually work
Article 28 requires deletion or return at the end of the relationship, and enterprise contracts require proof.
Where this usually goes wrong
One document covering both roles
The privacy policy describes controller processing. Processor obligations belong in the DPA. Merging them produces a document that over-promises about customer data and under-explains your own.
Training on customer data without saying so
The single fastest way to lose an enterprise deal, and depending on your terms, a breach of the instruction limitation in Article 28.
A sub-processor list that is out of date
If the contract promises notice before adding a sub-processor, adding one silently is a breach of contract as well as a transparency failure.
Support tooling that copies processor data into controller systems
Screenshots, exported CSVs and debug logs move data out of the environment your DPA describes.
No defined breach notification window
"Without undue delay" is the statutory phrase, but enterprise contracts want a number. Not having one is a negotiation cost on every deal.
Free-tier and trial data treated casually
Trial accounts contain real customer data far more often than teams assume, and the same obligations apply.
Frequently asked questions
Is my SaaS company a controller or a processor?
Both, in different respects. You are a controller for your own account, billing, marketing and support data, and a processor for the data your customers put into the product. The documents you publish should make the boundary obvious.
Do I need a data processing agreement?
If you process personal data on behalf of business customers subject to GDPR or UK GDPR, yes - Article 28 requires it in writing. In practice enterprise customers will require one regardless of jurisdiction.
Do I have to publish a sub-processor list?
There is no free-standing statutory duty to publish one, but almost every enterprise DPA requires notice before you add a sub-processor, and a public list is the standard way to meet that.
Can I use customer data to train AI models?
Only with a lawful basis and, where you are a processor, only if your customer has instructed or permitted it. Doing it silently breaches the instruction limitation and, for most enterprise contracts, the agreement itself.
What breach notification window should I commit to?
Common commitments run from 24 to 72 hours from confirmation. Pick one your incident process can actually meet, because a missed contractual deadline is a breach of contract on top of the incident.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for SaaS
Answer a short questionnaire and get a draft written for a SaaS product. Free to start, no card required.
Generate your cookie policyOther documents a SaaS product needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.