Create an editable SaaS privacy-policy draft with guided questions for accounts, customer data, sub-processors, APIs, transfers, retention, GDPR, and CCPA/CPRA topics.
A generic website privacy policy won't cut it for SaaS. Multi-tenant data, sub-processors, DPAs, and API access create unique compliance requirements that standard templates completely miss.
Your platform hosts data for multiple customers in shared infrastructure. Your privacy policy must explain data isolation, access controls, and how you prevent cross-tenant data leaks.
As a data processor under GDPR, you have specific legal obligations. You process data on behalf of your customers, not for your own purposes — this distinction changes everything about your privacy policy.
Your APIs enable data to flow between your platform and third-party tools. OAuth tokens, webhooks, and integrations create complex data flows that must be documented.
Your SaaS relies on AWS, Stripe, SendGrid, and dozens of other services. Each one is a sub-processor that your customers have the right to know about under GDPR.
Controller-processor relationships may require Article 28 contract terms. Use this section as a requirements checklist; a standard PolicyForge DPA and signature workflow remain on the delivery backlog.
Define exactly what data you process, why, and how long you retain it. Must distinguish between data you process as a controller (account data) and as a processor (customer data).
Document your technical and organizational measures: encryption at rest and in transit, access controls, audit logging, vulnerability management, and incident response procedures.
Document sub-processors, locations, processing roles, and the notice or objection process promised in the governing contract.
Define how you assist customers in responding to data subject access requests (DSARs), deletion requests, data portability, and correction requests from their end users.
Document all international data transfers and the legal mechanisms used: Standard Contractual Clauses (SCCs), adequacy decisions, or binding corporate rules.
Grant customers the right to audit your data processing. Define breach notification timelines (GDPR requires 72 hours) and the process for communicating incidents.
A SaaS product may rely on third-party services that act as sub-processors or other recipients. Build the inventory from contracts, configuration, and current vendor documentation.
Hosts application data, user uploads, databases, and CDN content
Processes billing info, subscription data, invoices, and payment methods
Sends transactional emails, notifications, in-app messages, and SMS
Tracks user behavior, feature usage, funnels, and product metrics
Captures error logs, performance data, session replays, and alerts
PolicyForge can use questionnaire answers and MCP stack manifests to draft an inventory. You verify the roles, data flows, locations, and notice duties.
Privacy-policy drafting, DPA requirement guidance, and a reviewable sub-processor inventory in one workflow.
No credit card required. Standard Enterprise DPA workflow is on the delivery backlog.
From verified SaaS facts to a reviewed privacy-policy draft in three steps.
Tell us about your data architecture, integrations, and target markets. The workflow organizes the services and data flows you provide into a draft inventory for review.
PolicyForge generates an editable privacy-policy draft and organizes DPA requirements and sub-processor facts for review. It does not currently issue a standard executed DPA.
Publish through the API, embed code, or hosted URL. Scheduled monitoring can create alerts and draft suggestions for supported changes; you review them before publishing. Version history records prior policy content.
Everything SaaS founders and legal teams need to know.
Create a privacy-policy draft, DPA requirements checklist, and sub-processor inventory for review. Use verified operational evidence—not generated wording—to support audits and enterprise diligence.
Free to start • No credit card required