Privacy Policy
Effective date: November 5, 2025
Last updated: November 5, 2025
1) Who we are
[Your Site Name] (“we,” “us,” “our”) operates [yourdomain.com]. We’re the data controller for personal data collected through this site. Contact: [privacy@yourdomain.com] | [postal address]. If you’re in the EEA/UK and we appoint an EU/UK representative or DPO, their details will appear here. (GDPR Art. 13/14 require these IDs and contacts.) GDPR+1
2) What this notice covers
This notice explains what we collect, why, the legal bases we rely on, who we share data with, international transfers, retention, and your rights. (GDPR “right to be informed” scope.) ICO+1
3) Personal data we collect
You provide: name, email, comments, messages, newsletter sign-ups, purchase/support info (if applicable).
Collected automatically: IP address, device/browser info, pages viewed, and interactions (via analytics, subject to your consent/opt-out).
From others: service providers (email/analytics), ad partners (only if you consent or have not opted out), social embeds (e.g., YouTube/Maps) per their policies.
We describe categories and sources because US laws require that clarity and GDPR expects transparency. California Privacy Protection Agency
4) Why we use your data (purposes)
Run and secure the site, moderate comments, prevent fraud.
Measure site performance and improve content.
Send newsletters you request; respond to messages.
Personalize/measure advertising only with consent in the EEA/UK and subject to opt-out rights elsewhere.
Include clear purpose statements—required in both GDPR and CPRA. GDPR+1
5) Legal bases (EEA/UK only)
Consent (e.g., analytics/ads cookies, email marketing).
Contract (providing content or services you request).
Legitimate interests (site security, minimal audience measurement with safeguards).
We also explain the right to withdraw consent and how to object to legitimate-interest processing. GDPR+1
6) Cookies & tracking
See our Cookie Policy for consent choices and a full cookie table. We only set non-essential cookies in the EEA/UK after opt-in, and we honor your Global Privacy Control (GPC) opt-out signal for sale/sharing where required in the US. [Link: /cookie-policy] ICO+1
7) Sharing your data
We share personal data with:
Service providers (processors): hosting/CDN, security, analytics, email service, payment processors.
Advertising/measurement partners: only if you consent (EEA/UK) or have not opted out (US).
Legal/safety: if required by law or to protect rights.
Your policy must list categories of third parties for CPRA and be specific enough for meaningful understanding. California Privacy Protection Agency
8) International data transfers
When data leaves your country (e.g., to the US), we use approved safeguards: EU Standard Contractual Clauses (2021/914) and, for the UK, the IDTA or UK Addendum. We’ll apply supplementary measures if needed. European Commission+2EUR-Lex+2
9) Retention
We keep personal data only as long as needed for the purposes above (or as required by law). For CPRA “notice at collection,” disclose retention by category or the criteria used. California Privacy Protection Agency
10) Your rights (EEA/UK)
You can request access, correction, deletion, restriction, portability, and objection, and withdraw consent anytime. You also have the right to lodge a complaint with your local authority (e.g., ICO in the UK). GDPR+1
11) California (CPRA/CCPA) rights
If you’re a California resident, you can:
Know/Access the categories and specific pieces of personal information we collected, sources, purposes, categories of recipients, and whether we sold/shared or disclosed for a business purpose in the last 12 months.
Delete personal information (with exceptions).
Correct inaccurate personal information.
Opt out of “sale” or “sharing” of personal information (and we honor GPC signals as a valid opt-out).
Limit the use/disclosure of Sensitive Personal Information to permitted purposes.
Non-discrimination for exercising rights.
Links: Do Not Sell or Share My Personal Information | Limit the Use of My Sensitive Personal Information (also available in our footer and banner). California Privacy Protection Agency
If we sell/share data of consumers under 16, we obtain opt-in authorization (parent/guardian for under 13). If we don’t sell/share, we will state that here. California Privacy Protection Agency
How to exercise your rights (US/EU/UK): Use [this request form/email]. We’ll verify your request and respond within the applicable timeframe.
12) Children
This site is not intended for children. We do not knowingly sell/share personal information of consumers under 16, and we obtain appropriate consent when required. California Privacy Protection Agency
13) How we secure your data
We use technical and organizational measures appropriate to the risk (encryption in transit, access controls, logging, staff/admin hygiene). No method is 100% secure.
14) Changes
We’ll update this notice when our practices or laws change. See “Last updated” at the top.