Privacy Policy

Privacy Policy

TEMPLATE — REVIEW BEFORE PUBLISHING This document is a generic boilerplate that ships with claudephpframework. It is not legal advice. Before publishing it on a real site, replace every [BRACKETED] placeholder, remove any sections that don't match what you actually do, add any sections specific to your operation, and have a qualified privacy lawyer review the result. Privacy laws differ by jurisdiction (GDPR, UK GDPR, CCPA/CPRA, PIPEDA, LGPD, APPI, etc.) and the specifics matter — generic boilerplate is a starting point, not a compliance guarantee.

Effective date: [EFFECTIVE DATE] Last updated: [DATE OF LAST UPDATE]

This Privacy Policy explains how [YOUR ORGANIZATION NAME] ("we", "us", or "our") collects, uses, and shares personal information about you when you use the website and services located at [WEBSITE URL] (the "Service").

1. Who is the data controller?

The data controller for personal information processed under this Policy is:

[YOUR ORGANIZATION LEGAL NAME] [REGISTERED ADDRESS] [COUNTRY]

You can contact us about privacy matters at [DPO OR PRIVACY CONTACT EMAIL].

2. What information we collect

2.1 Information you provide

the password you set (stored as a salted hash, never in plain text), and any name, username, or profile information you choose to provide.

details, or preferences you add to your profile.

submissions, and other content you create or upload through the Service.

and feedback.

enforce a minimum age at registration, we collect and store your date of birth to verify eligibility.

payment details are collected by our third-party payment processor. We do not store full card numbers ourselves; we receive only the truncated reference data needed to identify a transaction.

2.2 Information collected automatically

cookie and store the corresponding session record on the server, with your user identifier, the time of last activity, and a truncated record of your User-Agent and IP address.

password changes, two-factor changes, administrative actions) in an internal audit log. These logs include the actor's user identifier, the action, a timestamp, and limited request context (truncated User- Agent, source IP).

for the categories of cookies we use and how to control them.

including IP addresses, paths requested, response codes, and timing, for the purposes of operating, securing, and debugging the Service.

2.3 Information from third parties

(for example, Google, Microsoft, Apple, Facebook, or LinkedIn), we receive a subset of your profile information from that provider as authorised by you in their consent screen.

bounces and complaints back to us, which we use to maintain a suppression list (so we don't keep emailing addresses that don't receive successfully).

3. How we use information

We use personal information for the following purposes:

Service to you;

the Service;

confirmations, security alerts) and, where you have consented, marketing communications;

problems and detecting fraud or abuse;

purposes.

4. Legal bases for processing (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, we process personal information on the following legal bases:

any other processing for which we ask your consent. You can withdraw your consent at any time.

(for example, to prevent fraud, debug failures, and maintain audit logs). When we rely on legitimate interests, we balance them against your rights and interests.

tax, accounting, and law-enforcement requests.

5. How long we keep information

We retain personal information for as long as necessary for the purposes described in this Policy:

period afterwards for legal, accounting, and dispute-resolution purposes (typically up to [N] years).

data minimisation; configurable by site administrators and reviewed periodically.

retention.

primary system, after which they are overwritten.

Where retention is governed by a legal obligation (for example, financial records that must be retained for tax purposes), we keep information for the period that obligation requires, and may anonymise rather than delete records that we are not permitted to remove entirely.

6. How we share information

We share personal information only as described below. We do not sell your personal information for monetary consideration.

Service, deliver email and SMS, process payments, run analytics (where enabled), and provide other infrastructure. They process personal information on our behalf under contractual obligations.

posts, public profile fields) is visible to other users or to the public as appropriate to where you publish it.

in response to a valid legal process, or where we reasonably believe it necessary to protect rights, safety, or property.

or asset sale, personal information may be transferred as part of that transaction, subject to confidentiality obligations.

7. International transfers

We may transfer personal information to countries outside your country of residence, including to providers based in the United States or elsewhere. Where we transfer personal information out of the European Economic Area, the United Kingdom, or other regions with cross-border restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, equivalent UK transfer mechanisms, or another lawful basis recognized by applicable law.

8. Your rights

Depending on where you live, you may have some or all of the following rights regarding your personal information.

8.1 Rights under GDPR / UK GDPR

machine-readable format.

any direct-marketing processing.

You can exercise the access, portability, and erasure rights directly from your account at /account/data. For other rights, or if you have trouble using the in-product tools, contact us at [DPO OR PRIVACY CONTACT EMAIL].

8.2 California rights (CCPA / CPRA)

If you are a California resident, you have the right to:

used, disclosed, and shared;

We do not sell personal information for monetary consideration. To the extent that any of our processing constitutes "sharing" under the CPRA (for example, by sending information to certain analytics or advertising providers), you can opt out at /do-not-sell. We honor the Global Privacy Control (Sec-GPC) signal as an opt-out request.

We will not discriminate against you for exercising any of these rights.

8.3 Other jurisdictions

If you live in another jurisdiction with privacy rights (for example, Canada, Brazil, Australia, Japan, South Korea, India, or others), the rights described above apply to the extent your local law grants them, and additional rights may apply under your local law. Contact us at [DPO OR PRIVACY CONTACT EMAIL] for any privacy request.

9. Children

The Service is not directed to children under the age of [MINIMUM AGE, USUALLY 13 OR 16]. Where the Service is configured to enforce an age gate at registration, we will refuse the registration of any user who attests to a date of birth below the configured threshold and will not retain the date of birth they provided in connection with that refusal (only an audit record indicating that an under-age registration was attempted, with no personally identifying details).

If you believe a child has provided personal information to us in violation of this Policy, please contact us at [CONTACT EMAIL] and we will take appropriate steps to remove the information.

10. Security

We implement reasonable technical and organizational measures designed to protect personal information, including encrypted transport (TLS), hashed password storage, configurable two-factor authentication, session management with rotation on login, audit logging, infrastructure access controls, and routine security review. No system is perfectly secure, however, and we cannot guarantee the absolute security of personal information.

11. Cookies and tracking

See our separate Cookie Policy for full details on the cookies we use, what they do, and how to control them. The Service's cookie consent banner lets you choose which non-essential categories to enable; your choice is recorded with a timestamp and a record of which categories you accepted.

12. Automated decision-making

We do not engage in automated decision-making that produces legal or similarly significant effects on you without human involvement. If this changes, we will update this Policy and provide notice.

13. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or applicable law. Where the changes are material, we will notify you by email or by prominent notice on the Service before the changes take effect. The "Last updated" date at the top of this Policy indicates when it was last revised.

14. Contact us

If you have questions, complaints, or requests regarding this Policy or your personal information:

You also have the right to lodge a complaint with your local data protection authority. In the European Union, you can find your authority via the European Data Protection Board's directory; in the United Kingdom, the Information Commissioner's Office; in California, the California Privacy Protection Agency.