Shahi LegalFlowSuite

How to Generate a Privacy Policy

Overview

This guide shows how to generate a compliant privacy policy for your website using the Legal Document Generator.

Prerequisites

    1. Legal Documents module enabled
    2. Company profile completed
    3. Admin access to WordPress
    4. Step 1: Complete Company Profile

      Before generating documents, set up your company details:

    5. Go to SLOSLegal DocumentsCompany Profile
    6. Fill in all fields:
    7. Required Information:

    8. Company Name (legal name)
    9. Website URL
    10. Contact Email
    11. Business Address (street, city, state, zip, country)
    12. Phone Number
    13. Business Type (select from dropdown)
    14. Industry
    15. Optional Information:

    16. Data Protection Officer email
    17. Company logo
    18. Registration number
    19. Business hours
    20. Privacy Officer
    21. Click Save Profile
    22. Step 2: Generate New Privacy Policy

    23. Go to SLOSLegal DocumentsGenerate New
    24. Select Privacy Policy
    25. Choose template:
    26. Standard – Works for most sites
      E-Commerce – Includes payment data
      SaaS – Includes user accounts
      Agency/Consultant – Client data focus
      Publisher/Media – Content user data

    27. Choose language:
    28. – English (default)
      – Spanish
      – French
      – German
      – Portuguese
      – Italian
      – Dutch

    29. Click Generate
    30. Step 3: Review Generated Content

      The policy automatically includes:

      1. Introduction

    31. Company name and contact
    32. Policy effective date
    33. Last updated date
    34. Statement of commitment to privacy
    35. 2. Information We Collect

      Automatically Populated:

    36. Personal data types collected
    37. Collection methods (forms, cookies, tracking)
    38. Required vs optional data
    39. Special categories of data (if applicable)
    40. Includes:

    41. Contact information (name, email, phone)
    42. Account data (username, password)
    43. Device information (IP, browser, OS)
    44. Behavioral data (pages visited, time spent)
    45. Cookie data (types, purposes, vendors)
    46. 3. How We Use Your Data

      Auto-included Based on:

    47. Consent Management settings
    48. Cookie scanner results
    49. Analytics enabled
    50. Marketing tools
    51. Third-party integrations
    52. Common Sections:

    53. Providing services
    54. Improving website
    55. Marketing purposes
    56. Legal compliance
    57. Fraud prevention
    58. Analytics
    59. 4. Legal Basis for Processing

      Automatically Includes:

    60. Consent (cookie consent)
    61. Legitimate interest
    62. Contractual necessity
    63. Legal obligation
    64. Vital interests
    65. Public task
    66. 5. Data Retention

      Auto-filled with:

    67. Retention periods per data type
    68. Consent record retention
    69. Deletion procedures
    70. Archival practices
    71. Legal hold exceptions
    72. 6. Your Rights

      Based on Regulations Selected:

      GDPR (EU):

    73. Right of access
    74. Right to rectification
    75. Right to erasure
    76. Right to restrict
    77. Right to portability
    78. Right to object
    79. Rights related to automated processing
    80. CCPA (California):

    81. Right to know
    82. Right to delete
    83. Right to opt-out of sale
    84. Right to non-discrimination
    85. LGPD (Brazil):

    86. Right to access
    87. Right to correction
    88. Right to deletion
    89. Right to portability
    90. Right to revoke consent
    91. 7. Cookie Policy Section

      Auto-populated with:

    92. Cookie types detected by scanner
    93. Cookie vendors
    94. Cookie purposes
    95. Retention periods
    96. User controls
    97. 8. Third-Party Sharing

      Lists any third parties:

    98. Analytics providers
    99. Marketing platforms
    100. Payment processors
    101. Hosting providers
    102. Integrations
    103. Data processors
    104. 9. Data Security

      Describes:

    105. Encryption practices
    106. Access controls
    107. Security measures
    108. Breach notification
    109. Incident response
    110. 10. International Transfers

      If applicable:

    111. EU adequacy decisions
    112. Standard contractual clauses
    113. Binding corporate rules
    114. Consent for transfers
    115. 11. Contact Information

      Auto-filled:

    116. Contact email
    117. Mailing address
    118. Data Protection Officer (if provided)
    119. Response procedures
    120. SLA for responses
    121. 12. Cookie Consent Notice (if using Consent Management)

    122. Links to cookie banner
    123. Lists cookie types
    124. Explains purposes
    125. Links to preferences
    126. Step 4: Customize Policy

      Edit Sections

    127. Click Edit Policy
    128. Select section to edit:
    129. – Click section heading
      – Content becomes editable
      – Make changes
      – Save automatically

      Common Customizations

      Add Company-Specific Details:
      `
      Example: “We use analytics to understand how customers use our
      e-commerce platform to improve product recommendations.”
      `

      Add Internal Policies:
      `
      Example: “Our internal retention policy deletes inactive account data
      after 2 years of no login.”
      `

      Emphasize Security:
      `
      Example: “We use industry-standard 256-bit encryption for all
      personal data in transit and at rest.”
      `

      Special Categories:
      `
      If you process sensitive data:

    130. Health information
    131. Biometric data
    132. Racial or ethnic origin
    133. Political opinions
    134. Add to “Special Categories” section
    135. `

      Add Variables

      Use template variables:

    136. {company_name} – Auto-fills
    137. {website_url} – Auto-fills
    138. {contact_email} – Auto-fills
    139. {dpo_email} – DPO contact
    140. {effective_date} – Auto-fills
    141. {dataretentiondays} – Your number
    142. Example:
      `
      “As of {effectivedate}, {companyname} (www.{website_url})
      collects personal data to provide services. Contact us at {contact_email}.”
      `

      Step 5: Verify Compliance

      GDPR Checklist

      If targeting EU visitors:

    143. ✓ Identifies company (controller)
    144. ✓ Lists lawful bases for processing
    145. ✓ Explains data subject rights
    146. ✓ Specifies retention periods
    147. ✓ Mentions data processor agreements
    148. ✓ Covers international transfers
    149. ✓ Includes breach notification process
    150. ✓ Mentions data protection authority
    151. ✓ Notes right to lodge complaints
    152. CCPA Checklist

      If California visitors:

    153. ✓ States collection of personal information
    154. ✓ Lists business purposes
    155. ✓ Explains do not sell option
    156. ✓ Describes consumer rights
    157. ✓ Includes contact for requests
    158. ✓ References privacy practices
    159. ✓ Mentions shine the light compliance
    160. LGPD Checklist

      If Brazilian visitors:

    161. ✓ Identifies data controller
    162. ✓ Specifies processing purposes
    163. ✓ Lists lawful bases
    164. ✓ Explains data subject rights
    165. ✓ Mentions data protection authority
    166. ✓ References retention period
    167. ✓ Covers international transfers
    168. Step 6: Get Legal Review

      IMPORTANT: Before publishing:

    169. Download draft (see Step 7)
    170. Send to legal counsel
    171. Have lawyer review for:
    172. – Jurisdiction compliance
      – Business accuracy
      – Completeness
      – Risk areas

    173. Incorporate feedback
    174. Get approval
    175. Step 7: Export or Publish

      Export Options

      Option 1: PDF Export

    176. Click Export as PDF
    177. File downloads to computer
    178. Share with legal team
    179. Print if needed
    180. Option 2: HTML Export

    181. Click Export as HTML
    182. Get HTML code
    183. Paste into page editor
    184. Customize formatting
    185. Option 3: Word Document

    186. Click Export as DOCX
    187. Opens in Microsoft Word
    188. Edit in Word
    189. Add company branding
    190. Print or PDF
    191. Publish to Website

      Option A: Auto-Create Page

    192. Click Publish to Website
    193. Creates new page: “Privacy Policy”
    194. Policy auto-published as draft
    195. Review in page editor
    196. Click Publish when ready
    197. Option B: Manual Page Creation

    198. Export as HTML
    199. Create new WordPress page
    200. Go to PagesAdd New
    201. Title: “Privacy Policy”
    202. Paste HTML into editor
    203. Customize formatting
    204. Publish
    205. Step 8: Create Privacy Policy Page

      Page Setup

    206. Page Title: “Privacy Policy”
    207. URL Slug: “/privacy-policy/”
    208. Status: Published
    209. Visibility: Public
    210. Menu: Add to footer menu (optional)
    211. Page Content

    212. Add policy content
    213. Format with headings
    214. Add company logo (optional)
    215. Add last updated date
    216. Add contact info
    217. Save and publish
    218. Link from Banner

    219. Go to Consent ManagementSettings
    220. In banner links section:
    221. – Privacy Policy URL: /privacy-policy/

    222. Save settings
    223. Banner now links to page
    224. Step 9: Keep Policy Current

      Set Reminders

    225. Go to Legal DocumentsPoliciesEdit
    226. Set Review Date: Annually
    227. Reminders sent to admin email
    228. Review and update as needed
    229. Version Control

      Track changes:

    230. Major Update – Change in practices
    231. – Increment major version
      – Mark as new “effective date”
      – Send notification to users

    232. Minor Update – Clarification
    233. – Increment minor version
      – Update in place
      – Note change

      Documentation

      Keep change log:
      `
      Version 1.2 – Dec 31, 2025

    234. Added CCPA section for California visitors
    235. Expanded cookie descriptions
    236. Added DSR request process
    237. Version 1.1 – Jan 15, 2025

    238. Added AI/ML processing disclosure
    239. Clarified third-party sharing
    240. Updated security practices
    241. Version 1.0 – Jan 1, 2025

    242. Initial policy creation
    243. `

      Step 10: Notify Users (Optional)

      For Major Changes

    244. If material changes made:
    245. – Send email to users
      – Post banner on site
      – Add notification in privacy settings

    246. Timing:
    247. – Notify 15-30 days before effective
      – Request re-consent if using cookies
      – Document acknowledgment

      Troubleshooting

      Policy Missing Sections

      Solution:

    248. Verify all company profile fields completed
    249. Re-generate policy
    250. Manually add missing sections
    251. Update company profile
    252. Formatting Issues

      Solution:

    253. Export as HTML
    254. Check in page editor
    255. Fix formatting manually
    256. Re-save page
    257. Compliance Questions

      Solution:

    258. Use verification checklists
    259. Consult legal resources
    260. Contact lawyer if uncertain
    261. Get professional review
    262. Best Practices

    263. Legal Review First – Have lawyer review before publishing
    264. Keep Current – Update annually minimum
    265. Version Control – Track all changes
    266. Communicate Changes – Notify users of major updates
    267. Archive Old Versions – Keep historical copies
    268. Mobile Friendly – Ensure readable on mobile
    269. Accessible – Follow WCAG guidelines
    270. Plain Language – Avoid legal jargon
    271. Next Steps

    272. Complete company profile
    273. Generate privacy policy
    274. Customize for your business
    275. Get legal review
    276. Publish to website
    277. Link from consent banner
    278. Set annual review reminder
    279. Related Articles

    280. Generate Cookie Policy
    281. Create Terms of Service
    282. Accessibility Statement Generation

Share this article

Was this article helpful?

Help us improve our documentation

Still need help?

Our support team is ready to assist you with personalized guidance for your workspace.

Submit a support ticket