Privacy Policy (definition)
The privacy policy of a website is a legal document, published on websites, which specifies the way in which the website stores, processes and handles the data of its users or customers.
In other words, a website’s privacy policy is a contract in which the site owners commit to keeping the personal information of their visitors and users safe.
1. What is the privacy policy for?
The purpose of a privacy policy is to inform a website’s users how the site collects their data during their visit and how the collected data will be used.
Likewise, it must give users the option to update, modify or even delete their data.
Although reading the privacy policy is something all of us users should do, we don’t, even though in it we consent to the processing of our data by the administrators of the website whose privacy policy we accept.
2. What should a privacy policy include?
The privacy policy should clearly indicate, avoiding technicalities, the type of data that will be collected in the visits we receive, as well as the use that will be made of such data.
It has to be written in the most detailed and understandable way possible. A correct privacy policy should detail at least the following points:
- Set a retention period for the data.
- Type of information collected (name, emails, phone numbers, IP, etc.)
- Use that will be made of the information (statistics, improving the user experience, email marketing, etc.)
- If the data will be transferred to third parties and how it will be used in such case.
- It should state that it can be updated in the future.
- It must include a real and quick way to get in touch, so users can modify, update or delete the data collected.
- It should indicate the responsibilities and limitations of the users during the visit to the Website.
- Include information on the cookies policy.
- Any relevant information on how the data will be protected.
This policy varies depending on the country. In the case of Spain, after creating the document, you must register with the Spanish Data Protection Agency (AEPD), where you declare the files involved in the collection of data.
At the same time, it is a very good idea for a company to publish its social responsibility, generally large companies do it and this can help us to differentiate ourselves.