Privacy policy generator

A GDPR (and Swiss FADP) privacy notice covering what you collect, why, who receives it and which rights visitors have.

Fill in the form, read the draft as it writes itself, copy it. No account, no e-mail address, nothing stored on our side.

As registered, e.g. Muster AG

Street, number, postcode, town, country

example.com

What an account adds

This draft is a text file. The paid platform makes it a live document: hosted at a stable URL you can link from your footer, versioned every time it changes, published in English, German, French and Italian at once, with a cookie list that updates itself from a real scan of your site, a consent banner in front of it and an audit trail behind it.

Live draft updating…

Privacy policy

Automatically generated draft — no legal validity
This text was generated automatically from the details you entered. It has not been checked by a lawyer, is not legal advice and has no legal validity. Read it in full, adapt it to what your business actually does, and have it reviewed before you publish or rely on it.


Introduction and data controller

This cookie and privacy policy explains how Your company (example.com) uses cookies and similar technologies when you visit our website. It describes what these technologies are, which categories we use, the legal basis for their use, and the choices available to you.

The data controller responsible for the processing of personal data described in this policy is Your company.

What are cookies

Cookies are small text files that a website stores on your device when you visit it. They allow the site to recognise your browser and to remember certain information between requests or visits. Similar technologies, such as local storage (localStorage and sessionStorage) and comparable identifiers, fulfil the same purpose and are covered by this policy.

A distinction is made between first-party cookies, which are set by example.com itself, and third-party cookies, which are set by external providers whose services are embedded on our website. Cookies are also classified by their lifespan: session cookies are deleted when you close your browser, whereas persistent cookies remain stored for a defined period or until you delete them.

How we use cookies

We group cookies and similar technologies into categories according to their purpose:

  • Strictly necessary and functional cookies are required for the website to operate and to provide functions you have explicitly requested, such as maintaining your session, ensuring security, or remembering your preferences. These cookies do not require your consent.

Consent and withdrawing consent

Before any non-essential cookies are set, we ask for your consent through the cookie banner displayed when you first visit the website. You may accept or decline each consent-based category, and no cookies in these categories are placed until you have given your consent.

You can change or withdraw your consent at any time. cookie settings

Withdrawing your consent does not affect the lawfulness of any processing carried out on the basis of your consent before its withdrawal.

Cookies we use

The list below is generated automatically and always reflects the cookies currently in use on this website.

Legal basis

The legal basis for setting non-essential cookies and processing the related personal data is your consent pursuant to Article 6(1)(a) of the General Data Protection Regulation (GDPR). For strictly necessary cookies, the legal basis is our legitimate interest in providing a secure and functional website pursuant to Article 6(1)(f) GDPR. The requirement to obtain consent for the storage of and access to information on your device also follows from the ePrivacy Directive (Directive 2002/58/EC) and its national implementations.

Third-party cookies and data transfers

Some cookies are set by third-party providers whose services are integrated into our website, such as analytics or media services. These providers may process personal data on their own responsibility and may transfer data to countries outside the European Union or the European Economic Area, including countries whose level of data protection has not been recognised as adequate.

Where such transfers take place, they are based on appropriate safeguards, such as an adequacy decision of the European Commission or standard contractual clauses. For details on the processing carried out by each provider, please refer to the respective privacy policies, which are linked in the cookie list above.

Your rights

Subject to the conditions set out in the GDPR, you have the right to access your personal data, to have inaccurate data rectified, to have your data erased, to restrict processing, to data portability, and to object to processing. Where processing is based on your consent, you may withdraw that consent at any time. You also have the right to lodge a complaint with a competent data protection supervisory authority.

Changes to this policy

The cookie list in this policy is updated automatically as the cookies used on this website change. We may also revise the remaining content of this policy from time to time. In the event of material changes affecting consent-based cookies, we will ask for your consent again through the cookie banner.

Contact

If you have any questions about this policy or about how we use cookies, please contact Your company.

Swiss data protection (FADP)

In addition to the provisions set out above, the processing of personal data described in this policy also complies with the Swiss Federal Act on Data Protection (FADP). The revised FADP has been in force since 1 September 2023 and applies wherever the processing of personal data has an effect in Switzerland, alongside the GDPR where the latter is applicable.

If you are located in Switzerland, you enjoy rights equivalent to those described above under the FADP. In particular, you have the right to request information about the personal data we process concerning you, to have inaccurate data rectified, to request the deletion of your data, and to object to particular processing. Where processing relies on your consent, you may withdraw that consent at any time using the cookie settings referred to above.

The supervisory authority responsible for data protection in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC), to whom you may address concerns regarding the processing of your personal data.

Where personal data is disclosed abroad, such disclosure takes place in accordance with Articles 16 et seq. FADP. Data may be transferred to countries that the Federal Council has recognised as providing an adequate level of data protection. In the absence of such recognition, we ensure that appropriate safeguards, such as standard contractual clauses, are in place before any transfer.


Automatically generated draft — no legal validity
This text was generated automatically from the details you entered. It has not been checked by a lawyer, is not legal advice and has no legal validity. Read it in full, adapt it to what your business actually does, and have it reviewed before you publish or rely on it.

Questions people actually ask

Is a generated privacy policy GDPR compliant?
It gives you the structure and the standard wording that Articles 13 and 14 GDPR require, but compliance depends on what your site actually does. If you run analytics, ads, embedded video, a CRM or a payment provider, each of those has to be named with its purpose, legal basis and retention period. Our draft covers the common ground; the paid platform fills in the rest from a real scan of your site.
Which law applies to me, GDPR or the Swiss FADP?
Both can apply at once. The revised Swiss FADP covers processing that has an effect in Switzerland; the GDPR covers offering goods or services to people in the EU or monitoring their behaviour. A Swiss company with EU customers is normally subject to both, which is why choosing Switzerland here produces a combined text.
How often does a privacy policy need updating?
Whenever your processing changes: a new tool, a new purpose, a new recipient, a new retention period. In practice most sites drift out of date within months because a marketing tag is added and nobody tells the person who owns the policy. That is the problem the paid platform solves by rescanning and reissuing the text automatically.

Other free generators