Privacy policy and data protection compliance
We will work out which data protection regimes actually reach your users, write the privacy policy that matches what your product does, and set up the procedures behind it.
Breach report
Сообщить об утечке
72 hours
72 часа
Consumer request
Ответ на запрос
45 days
45 дней
Top fine band
Верхний штраф
€20m or 4% of turnover
20 млн € или 4% оборота
Agreeing alone
Соглашается сам
13, 14 or 16
13, 14 или 16 лет
When you need a privacy policy

You are opening a new market
Which law reaches you is decided by where your users sit; your own address decides nothing. One new country adds a whole set of duties.
A store rejected your listing
App stores ask for a working policy address before they publish. A broken link or a page that contradicts the app is enough to be sent back.
Children are using your product
The age at which a person may agree for themselves is different in every regime, and getting it wrong is the most expensive kind of mistake.
A customer sent a data questionnaire
Enterprise buyers ask where the data goes, who processes it and on what basis. Once signed, the answers bind you like a contract term.
Personal data leaked last week
A clock started the moment somebody in the company became aware of it, and it is counted in hours.
What you get
- The laws that reach you
- The policy and the notices
- A working request procedure
- A plan for a breach
- Contracts with your processors
What is required for a privacy policy

The question is never «which law do we follow». It is «which laws reach us at once», because these regimes are written to follow the person, and your users are in more than one place.
The European regulation says so in as many words: it applies to a controller or processor not established in the Union where the processing relates to offering goods or services to people who are in the Union.
The Emirati decree-law of 2021 reaches processing carried out inside or outside the country. Neither of them asks where your office is.
What the policy has to say
- What you collect, in categories a reader recognises, and what you do with each category.
- The ground you rely on for each purpose, and what changes if a person withdraws their agreement.
- Who else receives the data: the services you run on, and the countries those services sit in.
- How long each category is kept, and what happens to it at the end of that period.
- The rights a person has and the address that actually answers when one of them is used.
Privacy policy for app stores
A store checks two things: the address works, and the page matches what the app does. A policy naming a tracker the build dropped, or missing one it added, fails that comparison.
What a generator leaves out
A privacy policy generator writes a document from a questionnaire. What it cannot do is check the answers against your build, name the regimes that actually reach your users, or set up the procedure that answers a request inside the deadline.
The document is the visible part. The duties behind it are the expensive part, and they do not appear because a page was published.
Six regimes, one product
European Union
A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours. The top band of fines reaches 20 million euro or 4% of worldwide annual turnover, whichever is higher.
Cyprus
The same regulation applies, and the national law fills the gaps it leaves to member states. Where the regulation sets 16 as the age at which a child may agree alone to an online service, the Cypriot law sets 14.
United States
There is no single federal statute for everyone; duties come by sector and by state. The federal children's rule applies to services directed to children under 13 and requires verifiable parental consent before collection.
California
A business answers a verified consumer request within 45 days, extendable once by another 45. Administrative fines run to 2,500 dollars per violation and 7,500 dollars where it was intentional or involved a consumer under 16.
Brazil
The national authority may impose a fine of up to 2% of the revenue the business earned in the country in its last financial year, excluding taxes, capped at 50 million reais per infraction.
United Arab Emirates
The 2021 decree-law took effect on 2 January 2022 and covers processing inside or outside the country. Processing without the person's agreement is prohibited except in cases the law names.
Sources: the 72-hour report, the 4% band and the age of 16 are in the European regulation, the age of 14 in Cypriot law 125(I)/2018; 45 days and the two fines in the Californian code; under 13 in the children’s rule; 2% and 50 million in the Brazilian law.
Stages of work
Working out which laws reach you — 3–5 working days.
We will start from where your users are and where your data physically sits, and name the regimes that follow from both. That list decides everything else on this page.
Listing what you collect and why.
Every field the product asks for, every event it records, every service it sends something to. Each line gets a purpose and a ground, or a note that it has neither.
Writing the policy and the notices.
One document people can read, plus the short notices that appear at the moment of collection. We will write them against what the build actually does, and mark what has to change if the build changes.
Setting up the request procedure.
Access, correction, deletion and objection arrive by email and have to be answered inside a deadline that differs by regime. We will write who receives them, how identity is checked and what the answer looks like.
The breach plan and its clock.
The obligation starts when somebody in the company becomes aware, well before the investigation ends. We will write the steps, the decision on whether to notify, and the record kept either way.
Contracts with the services you use.
Analytics, hosting, support tools and payment providers all process data for you. We will paper that relationship and check what each already promises in its own terms.
Our work on licences and compliance sits in the Licensing & Compliance area.
FAQ
If your product collects anything about identifiable people, then yes. More than one regime can reach you at the same time, because they follow your users and not your company, so a document written for one of them can leave the others unanswered. App stores add a requirement of their own on top: a working address and a page that matches the build. The practical question is not whether you need one, but which regimes it has to satisfy.
It can, and the regulation says so directly. It applies to a controller or processor not established in the Union where the processing relates to offering goods or services to people who are in the Union, whether or not payment is required, or to monitoring their behaviour. So the test is who your product is aimed at, not where your servers or your company sit. The Emirati decree-law is built the same way: it reaches processing carried out inside or outside the country.
It will produce a document, and that is the easy half. A generator answers from a questionnaire: it cannot open your build to see which services actually receive data, it cannot decide which regimes reach your users, and it does not set up the procedure that has to answer a deletion request inside a deadline. The published page is what a regulator reads second. What it reads first is whether the page and the product agree.
It depends on the regime, and the three answers on this page are different. The European regulation sets 16 for online services offered directly to a child, and lets member states go lower but not below 13; Cyprus used that room and set 14. The federal rule in the United States works from the other end: a service directed to children under 13 needs verifiable parental consent before it collects anything. A product reaching all three has to satisfy all three.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
