Policy type
Select the type of policy you need to generate.
92 policies
Privacy Policy
Legally required in 100+ countries. Discloses exactly how you collect, use, store, and protect personal data - covering GDPR, CCPA, UK GDPR, and more.
Cookie Policy
Required under EU ePrivacy Directive and UK PECR. Lists every cookie and tracker on your site, explains their purpose, and documents your consent mechanism.
GDPR Compliance Policy
Comprehensive framework documenting all GDPR obligations - lawful basis mapping, data subject rights procedures, breach response, and DPO requirements.
CCPA Privacy Notice
Required for businesses serving California residents that meet CCPA thresholds. Covers the right to know, right to delete, and opt-out of data sales - updated for CPRA 2023.
Data Processing Agreement
Mandatory under GDPR Article 28 for any B2B data relationship. A legally binding contract between data controllers and processors specifying security measures and sub-processor rules.
Data Retention Policy
Documents how long each category of data is kept and how it is securely deleted. Required under GDPR's storage limitation principle - protects against over-retention fines.
Data Breach Response Policy
A step-by-step incident response plan for data security breaches. Covers detection, containment, authority notification (72-hour GDPR window), and affected-user communication.
HIPAA Privacy Policy
Federally mandated for US healthcare providers and Business Associates handling PHI. Covers patient rights, minimum necessary standard, breach notification, and BAA requirements.
COPPA Policy
Required by US law for any service directed at children under 13. Covers verifiable parental consent, data minimisation, prohibition on behavioural advertising, and safe harbour provisions.
Data Subject Access Request Policy
Defines how individuals can exercise their data rights under GDPR, CCPA, and UK GDPR - covering request submission, identity verification, response timelines (30 days GDPR / 45 days CCPA), and appeal procedures.
Data Transfer Agreement
Required for international transfers of personal data outside the EEA/UK. Incorporates EU Standard Contractual Clauses (SCCs), UK International Data Transfer Agreement (IDTA), and supplementary security measures.
Privacy Impact Assessment
DPIA template required under GDPR Article 35 for high-risk processing - covering data flows, necessity assessment, risk evaluation, and mitigation measures.
Consent Management Policy
Framework for collecting, recording, and managing user consent - covering opt-in mechanisms, granular consent options, withdrawal procedures, and audit trails.
Mobile App Privacy Policy
Privacy policy tailored for mobile applications - covering device permissions, push notifications, location data, app analytics, and app store compliance requirements.
Terms of Service
The foundational contract between your business and users. Defines acceptable use, limits your liability, protects your IP, and sets rules for account suspension.
Acceptable Use Policy
Specifies what users can and cannot do on your platform. Protects against abuse, illegal content, and misuse - essential for SaaS, hosting, and community platforms.
End User Licence Agreement
Grants end users a limited licence to use your software while prohibiting reverse engineering, copying, or redistribution. Required by Apple App Store and Google Play.
SaaS Agreement
Master subscription agreement for software-as-a-service - covering access rights, uptime guarantees, data ownership, support tiers, security obligations, and termination terms.
API Terms of Service
Governs how third-party developers can access and use your API. Covers rate limits, data caching rules, prohibited uses, authentication requirements, and API key revocation.
Subscription Terms
Covers auto-renewal billing, cancellation rights, price change notice periods, and proration rules. Ensures compliance with consumer protection laws on recurring charges in EU/UK/US.
Free Trial Terms
Sets clear boundaries for free trial access - trial duration, feature limitations, what happens at trial end, and whether a payment method is required upfront. Reduces chargeback risk.
Beta Testing Agreement
Governs access to pre-release software - covering confidentiality of unreleased features, feedback ownership, disclaimer of warranties, and no-liability for beta instability.
Community Guidelines
Sets behavioural standards for community platforms - covering prohibited content, harassment, hate speech, spam, and moderation procedures. Needed for Digital Services Act compliance.
Forum Rules
Specific rules of engagement for discussion boards and forums - covering post formatting, prohibited topics, spam, self-promotion, account bans, and moderator authority.
Intellectual Property Policy
Documents ownership of trademarks, patents, copyright, and trade secrets. Covers employee and contractor IP assignment, permitted use of third-party materials, and brand usage guidelines.
Referral Program Terms
Governs how users earn and redeem referral rewards - covering eligibility, reward conditions, anti-fraud provisions, tax disclosure, and program modification/termination rights.
Refund & Returns Policy
Legally required for e-commerce in the EU (14-day cooling off) and UK. Clearly defines return windows, refund timelines, conditions, and digital goods exceptions.
Non-Disclosure Agreement
Legally binding contract preventing parties from sharing your trade secrets, product plans, or sensitive business data. Essential before any partnership conversation.
Service Level Agreement
Defines guaranteed uptime (e.g. 99.9%), support response times, severity classifications, service credit formulas, and maintenance windows. Expected by enterprise buyers.
Contractor Agreement
Clearly establishes an independent contractor (not employee) relationship - covering deliverables, IP assignment, payment terms, confidentiality, and right to substitute.
Partnership Agreement
Defines profit sharing, decision-making authority, capital contributions, buy-out provisions, and dissolution procedures for business partnerships and joint ventures.
Affiliate Disclosure
FTC and ASA required disclosure that you earn commission from product recommendations. Must appear before affiliate links - required even for free products and gifted items.
Shipping Policy
Required before checkout under EU/UK consumer law. Covers carrier partners, estimated delivery timescales, international shipping zones, customs duties, and lost parcel procedures.
Ecommerce Terms & Conditions
Comprehensive legal framework for online retail - covering order acceptance, payment processing, price errors, VAT, warranty limitations, and statutory consumer rights.
Marketplace Policy
Governs the relationship between your marketplace platform and its sellers/buyers - covering seller verification, listing rules, escrow, dispute resolution, and fee structures.
White Label Agreement
Agreement for reselling or rebranding products/services under a different brand name, covering IP licensing, quality standards, and revenue sharing.
Terms of Sale
Terms governing the sale of goods or digital products, including pricing, payment terms, delivery, risk transfer, and warranty.
Influencer Agreement
Contract governing influencer partnerships - covering deliverables, content approval, usage rights, FTC/ASA disclosure requirements, exclusivity, and payment terms.
Employee Handbook
Your primary staff reference document - covering working hours, PTO, disciplinary procedures, equal opportunities, IT use, and benefits. Reduces employment tribunal risk significantly.
Remote Work Policy
Defines expectations for home and hybrid workers - covering equipment stipends, cybersecurity requirements, working hours across time zones, and working-abroad tax implications.
Social Media Policy
Governs how employees represent your brand online - covering personal vs professional accounts, confidentiality obligations, prohibited content, and FCA promotion rules.
Equal Opportunity Policy
Documents your commitment to non-discriminatory hiring and workplace practices across all protected characteristics. Required for public sector contracts and many enterprise suppliers.
Whistleblower Policy
Provides protected reporting channels for employees to raise concerns about wrongdoing - covering anonymity guarantees, non-retaliation protections, and investigation procedures.
Code of Conduct
Sets ethical standards for all staff - covering professional behaviour, anti-harassment, conflict of interest, gifts and entertainment, and consequences for violations.
Conflict of Interest Policy
Requires staff and directors to disclose personal interests that could influence business decisions - covering recusal procedures, disclosure registers, and enforcement.
Anti-Harassment Policy
Workplace policy prohibiting harassment, bullying, and intimidation - covering definitions, reporting procedures, investigation process, and disciplinary actions.
Employee Privacy Notice
Privacy notice specifically for employees and job applicants, covering HR data processing, monitoring, background checks, and data subject rights.
Bring Your Own Device (BYOD) Policy
Governs employee use of personal devices for work - covering permitted device types, MDM enrollment, acceptable use, data segregation, security requirements, and remote-wipe rights upon termination.
Grievance & Complaints Policy
Provides a formal procedure for employees to raise workplace concerns - covering informal resolution, formal grievance stages, investigation timelines, appeal rights, and anti-retaliation protections.
AI Usage Policy
Governs employee use of generative AI tools - covering prohibited inputs (confidential data, PII), output review requirements, approved tools list, and IP ownership of AI-generated content.
Anti-Bribery Policy
Required for compliance with UK Bribery Act 2010 and US FCPA. Covers prohibited facilitation payments, gift and hospitality registers, due diligence on agents, and training obligations.
Modern Slavery Statement
Annual statement required for UK businesses with £36M+ turnover under Modern Slavery Act 2015. Covers supply chain due diligence, risk areas, and remediation actions taken.
Cybersecurity Policy
Sets organisation-wide information security standards - covering access controls, encryption requirements, patch management, network security, and employee security training.
Password Policy
Defines minimum password complexity, rotation schedules, MFA requirements, password manager use, and prohibited practices - aligned with NIST 800-63B guidelines.
Incident Response Policy
Defines how your team detects, classifies, contains, and recovers from all security incidents - covering severity levels, escalation paths, communication templates, and post-incident reviews.
Accessibility Statement
Demonstrates your commitment to digital accessibility under ADA (US), EAA (EU 2025), and WCAG 2.2 AA standards. Documents conformance level, known limitations, feedback channels, and remediation timeline.
Impressum
Legally required in Germany, Austria, and Switzerland under TMG §5 and ECG §5. Discloses business identity, registered address, contact details, VAT number, trade register entry, and responsible editor.
EU AI Act Compliance Policy
Compliance policy for the EU AI Act (2024/1689) - risk classification, transparency obligations, prohibited practices, and human oversight requirements for AI systems.
Digital Services Act (DSA) Policy
Policy for EU Digital Services Act compliance - content moderation transparency, notice-and-action mechanisms, recommender system disclosure, and annual reporting.
UK Online Safety Act Policy
Compliance with the UK Online Safety Act 2023 - illegal content duties, child safety obligations, age verification, and Ofcom transparency reporting.
AI/ML Ethics Policy
Governs responsible AI use across the organisation - covering bias prevention, algorithmic transparency, accountability frameworks, human oversight requirements, and ethical review processes.
Records Retention Policy
Policy defining how long different categories of business records must be retained, archived, or destroyed, per regulatory requirements.
Financial Services Privacy Policy
Privacy policy tailored for regulated financial services - covering Gramm-Leach-Bliley Act (GLBA), FCA data requirements, MiFID II record-keeping, and consumer financial data rights.
Disclaimer
Limits your liability for the accuracy of content on your site. Critical for blogs, health/finance/legal sites - protects against negligence claims from readers acting on your content.
Copyright Policy
Declares ownership of your original content, defines permitted uses and attribution requirements, and details your process for handling infringement - includes DMCA contact information.
DMCA Policy
Required for "safe harbour" protection under US law. Designates a DMCA agent, sets out your takedown notice process, counter-notice procedure, and repeat infringer termination policy.
Anti-Spam Policy
Ensures all marketing emails comply with CAN-SPAM, CASL, and GDPR - covering opt-in consent standards, unsubscribe mechanisms, sender identification, and prohibited practices.
Environmental & Sustainability Policy
Documents your organisation's commitment to environmental responsibility - covering carbon reduction targets, supply chain sustainability standards, waste management, energy efficiency, and compliance with UK SECR, EU CSRD, and SEC climate disclosure rules.
Photo & Video Release Policy
Obtains consent to photograph, record, and publish images of individuals - covering model release rights, usage scope (commercial, editorial, social media), moral rights waivers, and GDPR biometric data considerations.
Event & Conference Terms
Terms and conditions for ticketed events - covering registration, cancellation and refund rights, force majeure, photography consent, code of conduct, liability limitations, and venue-specific rules.
Information Security Policy
Your organisation-wide security rules: access control, classification, acceptable use of systems, and incident escalation.
IT Acceptable Use Policy
What staff may and may not do with company devices, networks, email and accounts.
Data Classification Policy
Defines your data tiers (public, internal, confidential, restricted) and the handling rules for each.
Transfer Impact Assessment
Documents the Schrems II style assessment behind an international transfer of personal data.
Backup & Recovery Policy
Backup scope, frequency, retention and restore testing for your systems and data.
Disaster Recovery Policy
Recovery objectives, roles and step-by-step restoration procedure after a major outage.
Business Continuity Policy
How the business keeps operating through disruption - critical functions, dependencies and fallbacks.
Change Management Policy
How changes to production systems are requested, reviewed, approved and rolled back.
Acceptable Encryption Policy
Approved algorithms, key lengths, key management and where encryption is mandatory.
Third-Party Risk Policy
How you assess, approve and monitor the security and privacy posture of suppliers.
Vendor Management Policy
Vendor onboarding, contract requirements, review cadence and offboarding.
Supply Chain Transparency Statement
Discloses your supply chain, due-diligence steps and labour standards expectations.
AI Transparency Policy
Tells users where AI is used in your product, what it does, and how human oversight works.
Billing Policy
Billing cycles, payment methods, failed payments, dunning and invoice terms.
Expense Policy
What staff can claim, approval limits, receipts and reimbursement timelines.
Disciplinary Policy
The formal stages, evidence and appeal rights in a disciplinary process.
Maternity & Paternity Policy
Leave entitlements, notice, pay and return-to-work arrangements for new parents.
Volunteer Agreement
Sets expectations, confidentiality and boundaries for unpaid volunteers.
Student Data Privacy Policy
How an education provider or edtech product handles student records and parental rights.
Franchise Agreement
Territory, fees, brand standards, training and termination terms for a franchise.
Guest Post Agreement
Rights, originality warranties, disclosure and editing terms for contributed content.
Ad Network Privacy Disclosure
The advertising and personalisation disclosures ad networks require publishers to display.