Privacy notice (privacy policy)

A privacy notice is the public statement in which a business tells the people who use its website and services what personal data it collects, why, who receives it, how long it is kept and what rights those people have.

Jurisdictions
California, England and Wales, Spain
Contract languages
English, Spanish

What it is and when it is used

A privacy notice (often called a privacy policy) is the document in which a business explains how it handles personal data. The Dealroom notice describes how the company collects, uses, shares and protects personal information when people use its website and related services. The skill is built to meet the transparency rules of the EU GDPR, the UK GDPR and the California CCPA and CPRA.

A business needs one as soon as it collects personal data through a website or online service. Under GDPR Articles 13 and 14 and CCPA §1798.100, people must be told what categories of personal data are collected about them, and the notice is where that information is given.

The notice opens with short definitions of Personal Data, Processing, Data Controller (the company) and Service Providers (third parties that process data on its behalf).

Who issues it and to whom it is addressed

Unlike a contract, the privacy notice is a one-party document. It is prepared in solo mode only: there is no counterparty, no negotiation and no signature.

  • Who publishes it: the business that runs the website or service. It speaks as "we" and names itself as the data controller, the party that decides why and how personal data is processed.
  • To whom it is addressed: the people who use the website and services, addressed as "you". The jurisdiction sections speak to specific groups: California residents, people located in the United Kingdom, and people located in Spain or the European Union.

The business fills in five facts: its company name, its website, a privacy contact email (where people send questions and rights requests), the effective date, and the jurisdictions where its users are located. The notice ends with the date it was last updated and the company's contact details.

Key clauses

Data collection scope

Three levels: essential data only (account, transaction and technical data), standard collection (adds identity, contact, usage and communication preference data) and comprehensive collection (adds financial data, precise geolocation, session recordings, profile data and inferred data).

GDPR Article 6 requires a lawful basis for each processing activity. The consent-based option relies mainly on consent, with contract and legal obligation as the other grounds. The balanced option combines consent (for marketing and non-essential cookies), contract, legitimate interests (service improvement, fraud prevention, internal analytics, personalisation) and legal obligation, and states that a balancing test is carried out for each legitimate interest.

Cookies and tracking technologies

Either strictly necessary cookies only, with a statement that no analytics, advertising or third-party tracking is used, or consent-based use of analytics and marketing cookies, with a consent banner on the first visit and a settings link in the website footer.

Third-party data sharing

Either no sharing except where the law requires it, to protect rights or safety, or with explicit consent (with a statement that all processing is done internally), or sharing only with service providers under contract, professional advisors and authorities when the law requires it. The second option states that all service providers are bound by data processing agreements, which is where a data processing agreement comes in.

International data transfers

Either no transfers outside the user's region, or transfers protected by adequacy decisions, Standard Contractual Clauses or the UK International Data Transfer Agreement, plus supplementary measures such as encryption. Users may ask for a copy of the safeguards.

Data retention

GDPR Article 5(1)(e) requires storage limitation and disclosed retention periods. The short option deletes account data within 30 days of closure and keeps transaction and usage data for about a year. The standard option keeps most data for up to 3 years (usage data up to 24 months) with an annual review. Both allow longer retention where the law requires it.

Individual rights

The standard option lists access, rectification, erasure, restriction, portability, objection and withdrawal of consent, with a reply within 30 days. The enhanced option adds a self-service privacy portal (download, correct, delete and export data in JSON or CSV), the right not to be subject to solely automated decisions, a possible 60-day extension for complex requests, and free handling unless a request is manifestly unfounded or excessive.

Children's privacy

GDPR Article 8 sets the age for a child's consent (16 in the EU, which member states may lower to 13; 14 in Spain), and COPPA protects children under 13 in the United States. The notice either states that the service is not directed at children under those ages, or describes age screening, verifiable parental consent, limited collection, no behavioural advertising and parental rights.

Security measures

GDPR Article 32 requires appropriate technical and organisational measures. The standard option lists encryption in transit (TLS 1.2 or higher) and at rest, access controls, regular testing, staff training and incident procedures. The enhanced option goes into detail: TLS 1.3, AES-256, multi-factor authentication for administrators, penetration testing, 72-hour notification to supervisory authorities, backups and disaster recovery.

Updates and notifications

Either changes are posted on the website with a new effective date, or material changes are emailed at least 30 days in advance, with a summary and renewed consent where needed.

Contact information and general provisions

A fixed section repeats the company's contact details; the notice is governed by the data protection laws where the company operates and its users are located.

What you decide instead of negotiating

With no other side, there is nothing to negotiate: every option is neutral and Dealroom does not propose a middle ground. Each choice describes what the business actually does, so the task is to pick the option that is true:

  • Minimal, standard or comprehensive collection, depending on the data really gathered.
  • Consent-based or a balanced mix of legal bases, depending on whether the business can manage consent or document balancing tests.
  • Essential cookies only, or analytics and marketing cookies with a consent banner.
  • No sharing or international transfers, or sharing with service providers and safeguarded transfers.
  • Standard rights handling, or a self-service portal that actually exists.
  • Not directed at children, or age-appropriate safeguards.

The skill's notes on each option weigh simplicity against capability: the simpler options lower the compliance burden but limit analytics, integrations or younger audiences; the fuller options support more activity but bring more obligations to keep the statements true.

Jurisdictions and languages Dealroom supports for it

The notice is available in English and Spanish and covers California, England and Wales and Spain. Unlike two-party contracts, it skips the single jurisdiction step: the business selects every jurisdiction where its users are located, and Dealroom adds one section for each:

  • California (CCPA/CPRA): rights to know, delete, correct, opt out of sale or sharing and limit use of sensitive information, plus non-discrimination, with a reply within 45 days of a verifiable request.
  • England and Wales (UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025): the company as controller, the lawful bases, the rights, transfer safeguards and the right to complain to the Information Commissioner's Office.
  • Spain (GDPR and LOPDGDD): lawful bases with their Article 6 references, rights under Articles 15 to 22, digital rights under Title X of the LOPDGDD and the right to complain to the Spanish data protection authority (AEPD).

Some options carry jurisdiction notes: comprehensive collection requires detailed disclosure under CCPA §1798.100 and must respect the GDPR proportionality principle in Spain, and the legitimate interest option points to Article 19 of the LOPDGDD.

Common mistakes

  • Choosing options that do not match practice. The no-sharing option says no outside service providers process data at all, and the essential-cookies option says no analytics are used. If the business uses cloud hosting or analytics, those statements are wrong.
  • Overlooking the fixed statements. The California section says the company does not sell personal information and lists the categories collected in the last 12 months; the UK section says no solely automated decisions with legal effects are made. Check that these are true before publishing.
  • Leaving out a jurisdiction. Only the jurisdictions selected receive their own section.
  • Retention that conflicts with the law. Short retention may clash with legal retention requirements such as tax records.
  • Consent without the means to manage it. Consent can be withdrawn at any time, so a consent management system is needed.
  • Promising what cannot be delivered. The enhanced rights option assumes a working self-service portal, and the enhanced security option describes specific controls (such as multi-factor authentication and third-party penetration testing) that must actually be in place and kept up to date.
  • Updating quietly. Website-only updates may go unnoticed and may not meet every regulatory expectation; material changes may require renewed consent.
  • An unmonitored contact email. Rights requests and children's data reports go to the privacy contact, with response deadlines.

Frequently asked questions

Is a privacy notice the same as a privacy policy?

Both names are used for the public document that explains how a business handles personal data. The Dealroom document is titled "Privacy Notice" and describes how the company collects, uses, shares and protects personal information when people use its website and related services.

Does a privacy notice need to be signed?

No. It is a one-sided statement, not an agreement, so it has no signature block. It closes with the date it was last updated, the company name, its website and its privacy contact email.

What must a GDPR privacy notice include?

The Dealroom notice covers the points the skill ties to the GDPR: the categories of data collected (Articles 13 and 14), the lawful basis for processing (Article 6), the recipients (Article 13(1)(e)), safeguards for international transfers (Chapter V), retention periods (Article 5(1)(e)), individual rights (Articles 15 to 22), security (Article 32) and how to complain to the supervisory authority.

Can one privacy notice cover the EU, the UK and California?

Yes. When creating the notice you select every jurisdiction where your users are located (California, England and Wales, Spain). Dealroom adds a separate section for each one: CCPA and CPRA rights, UK GDPR provisions, or GDPR and LOPDGDD provisions.

How should users be told when the privacy notice changes?

The skill offers two approaches: publish the revised notice on the website with a new effective date, or email users at least 30 days before material changes take effect, seeking renewed consent where the change affects processing based on consent.

Two ways to make it

Create it in Dealroom

Choose the jurisdiction and language, answer a few questions and negotiate each clause with the other side, or prepare it alone.

Start in Dealroom

Have your agent draft and negotiate it

Your AI agent can read the clause library and create the contract through the agent API or the MCP server. A short example:

MCP: list_templates (query: "PRIVACY_NOTICE"), get_template, create_playbook, initiate_negotiation.

Read the agent API guide
# 1. Read the clauses, options and the facts it needs
curl https://dealroom.todo.law/api/v1/agent/templates/PRIVACY_NOTICE \
  -H "Authorization: Bearer drk_YOUR_KEY"

# 2. Create the contract (clauses you leave out take the default option)
curl -X POST https://dealroom.todo.law/api/v1/agent/deals \
  -H "Authorization: Bearer drk_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
    "schema": "dealroom.solo-intake/1",
    "contractType": "PRIVACY_NOTICE",
    "governingLaw": "ENGLAND_WALES",
    "language": "en",
    "dealName": "Example PRIVACY_NOTICE",
    "selectionPolicy": "defaults"
  }'

Drafting and negotiating are free.

Related contracts

This page explains how the contract usually works. It is general information, not legal advice.

© Rindogatan LLC