Some privacy policy builders only take five minutes. Ours can’t. We ask 115 questions (what you collect, who else sees it, what runs on your website, whether your meetings get recorded). It is your promise to your customers, and it is worth the time making sure it is right.
We could ask you three and hand back a template with your business name dropped into it. That is what a five-minute generator does, and the result reads the same for a florist as it does for a physiotherapy clinic, because it was never about either of them.
If you want a quick generic template, this is not the right product. This will take about 10 to 15 minutes to complete, because we make sure it covers every privacy aspect of your business.
Your privacy policy is often the first place a customer looks to decide whether you can be trusted with their details. Getting it right is how you protect that trust, and keep it.
Every question exists because something in the law, or in how your business runs, turns on the answer. What comes out is built from those answers: not assembled from a template and renamed.
You can regenerate it free for 30 days, in PDF, Word or HTML. It is built from a template written by AegorIQ, not by a law firm, and no lawyer has reviewed it, if your situation is unusual, have one read it before you publish.
AegorIQ is not a law firm and no lawyer has reviewed this template. It is a starting document built from your answers, not legal advice. If your situation is unusual, have it reviewed before you publish it.
Every clause in the library records the provision it exists for. There are 98 clauses carrying 67 distinct citations, and your policy is assembled only from the ones your answers call for. The questionnaire covers all thirteen Australian Privacy Principles of the Privacy Act 1988 (Cth), read alongside the OAIC's APP Guidelines.
Which of these reach you depends entirely on your answers. A business with no premises, no staff and no overseas tools is asked about none of them, and its policy says nothing about them. This is a list of what the questionnaire can ask, not a list of what your policy will claim.
It is 115 questions, and it is not a five-minute form. That is deliberate: a policy that is actually about your business has to ask how your business works. A full run takes about 15 to 20 minutes, longer if you need to check on something. If you want a quick generic template, this is not the right product for you.
The Australian Privacy Principles, including what personal information you collect and why, who you disclose it to, whether anything goes overseas and to which countries, how long you keep it, how someone asks for access or correction, and how to make a complaint. It also covers cookies, analytics and tracking, and the Notifiable Data Breaches scheme where it applies to you.
PDF, Word (.docx), Word (.doc) and HTML. The HTML is the one to give a web developer to publish on your site.
Yes. For 30 days after purchase you can reopen your builder link, change any answer and generate the policy again. A link to your builder is emailed to you at purchase so you do not have to keep the tab open.
No. AegorIQ is not a law practice and this is not legal advice. The builder produces a document from the answers you give about your own business. If your circumstances are unusual or you are unsure, a lawyer can review it.
The AegorIQ Privacy Policy Builder is AUD $59, paid once. There is no subscription.
Yes, and it scopes it rather than assuming it. APP 1.7 and APP 1.8 commence on 10 December 2026, and APP 1.7 is a three-limb test: personal information used in a computer program, the program playing a material role in a decision, and the decision being one that could reasonably be expected to significantly affect someone’s rights or interests.
The builder asks all three. That matters in both directions, a business whose only decision software is a spam filter should not publish a formal automated-decision disclosure it does not owe, and a business whose staff rubber-stamp a system’s recommendation does not escape one. If all three are met, the policy sets out the three things APP 1.8 requires: the kinds of information those programs use, the decisions made solely by the program, and the decisions where the program does something materially relevant to a person’s decision.
Yes. On 1 July 2026 the anti-money-laundering regime took in new designated services, real estate agency work, conveyancing, professional services that set up or administer companies and trusts, and dealing in precious metals and stones.
The builder does not ask you whether you are a reporting entity, because that is the legal conclusion and it is the thing people get wrong. It asks which services you actually provide, in the words you would use for your own work, and separately whether those services are provided from Australia or to customers in Australia: the geographical link in section 6(6) of the AML/CTF Act. If both are there, the disclosure is included: the identity documents you collect, that the service cannot be provided without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent.
It is a privacy disclosure only. Your AUSTRAC obligations (enrolment, customer due diligence, reporting) are a separate regime, and this does not discharge any of them.
Yes. If the Notifiable Data Breaches scheme in Part IIIC applies to you, the policy says that you assess a suspected eligible breach promptly and within 30 days, that if serious harm is likely you will notify both the person and the Office of the Australian Information Commissioner as soon as practicable, and that if you can prevent the harm before it happens notification may not be required.
That last part is in the scheme and is usually left out, which makes a policy promise more than the business can keep.