Privacy policy
This document is not published yet.
We would rather say that than put up something that reads like a policy and is not one. A document like this has to be written by a solicitor: it is enforceable, and getting it wrong is worse than not having it. This one is a legal requirement and not only a procurement one, so its absence is a gap rather than a roadmap item.
Who asks for it
Everyone, and UK and EU GDPR require it from the moment personal data is processed.
What it has to cover
- Who the controller is, and its registered details.
- Every category of personal data held, and the lawful basis for each.
- How long each category is kept, and why that period.
- The transfer mechanism for sending prompt content to model providers outside the UK.
- Data subject rights and the route to exercise them, which is built: see the account page.
- Who to complain to, including the ICO.
If this is blocking a decision, say so on the quote form. Meanwhile our sub-processors are listed in full, because that is a matter of fact rather than a legal opinion.