Home  ›  Privacy Policy Builder
Privacy Policy Builder

A privacy policy that is actually about your business.

Some privacy policy builders only take five minutes. Ours can’t. We ask 126 questions (what you collect, who else sees it, what runs on your website, whether your meetings get recorded). It is your promise to your customers, and it is worth the time making sure it is right.

$59
One-off · AUD · one business · regenerate free for 30 days
126 questions · every one explained in plain English · PDF, Word or HTML

It takes 126 questions. That is the point.

We could ask you three and hand back a template with your business name dropped into it. That is what a five-minute generator does, and the result reads the same for a florist as it does for a physiotherapy clinic, because it was never about either of them.

If you want a quick generic template, this is not the right product. This will take about 10 to 15 minutes to complete, because we make sure it covers every privacy aspect of your business.

Your privacy policy is often the first place a customer looks to decide whether you can be trusted with their details. Getting it right is how you protect that trust, and keep it.

What your policy actually covers

Every question exists because something in the law, or in how your business runs, turns on the answer. What comes out is built from those answers: not assembled from a template and renamed.

You can regenerate it free for 30 days, in PDF, Word or HTML. It is built from a template written by AegorIQ, not by a law firm, and no lawyer has reviewed it, if your situation is unusual, have one read it before you publish.

Read more

AegorIQ is not a law firm and no lawyer has reviewed this template. It is a starting document built from your answers, not legal advice. If your situation is unusual, have it reviewed before you publish it.

What the policy is built against

Every clause in the library records the provision it exists for. There are 109 clauses carrying 77 distinct citations, and your policy is assembled only from the ones your answers call for. The questionnaire covers all thirteen Australian Privacy Principles of the Privacy Act 1988 (Cth), read alongside the OAIC's APP Guidelines.

Australian Privacy Principles

And the rules that sit outside the Principles

Which of these reach you depends entirely on your answers. A business with no premises, no staff and no overseas tools is asked about none of them, and its policy says nothing about them. This is a list of what the questionnaire can ask, not a list of what your policy will claim.

Common questions

How long does the privacy policy builder take?

It is 126 questions, and it is not a five-minute form. That is deliberate: a policy that is actually about your business has to ask how your business works. A full run takes about 15 to 20 minutes, longer if you need to check on something. If you want a quick generic template, this is not the right product for you.

What does the privacy policy cover?

The Australian Privacy Principles, including what personal information you collect and why, who you disclose it to, whether anything goes overseas and to which countries, how long you keep it, how someone asks for access or correction, and how to make a complaint. It also covers cookies, analytics and tracking, and the Notifiable Data Breaches scheme where it applies to you.

What formats can I download the privacy policy in?

PDF, Word (.docx), Word (.doc) and HTML. The HTML is the one to give a web developer to publish on your site.

Can I change my answers after I generate the policy?

Yes. For 30 days after purchase you can reopen your builder link, change any answer and generate the policy again. A link to your builder is emailed to you at purchase so you do not have to keep the tab open.

Is this legal advice?

No. AegorIQ is not a law practice and this is not legal advice. The builder produces a document from the answers you give about your own business. If your circumstances are unusual or you are unsure, a lawyer can review it.

How much does an Australian privacy policy cost?

The AegorIQ Privacy Policy Builder is AUD $59, paid once. There is no subscription.

Does the privacy policy builder cover the automated decision-making disclosure?

Yes, and it scopes it rather than assuming it. APP 1.7 and APP 1.8 commence on 10 December 2026, and APP 1.7 is a three-limb test: personal information used in a computer program, the program playing a material role in a decision, and the decision being one that could reasonably be expected to significantly affect someone’s rights or interests.

The builder asks all three. That matters in both directions, a business whose only decision software is a spam filter should not publish a formal automated-decision disclosure it does not owe, and a business whose staff rubber-stamp a system’s recommendation does not escape one. If all three are met, the policy sets out the three things APP 1.8 requires: the kinds of information those programs use, the decisions made solely by the program, and the decisions where the program does something materially relevant to a person’s decision.

Does it include the AML/CTF privacy disclosure for AUSTRAC reporting entities?

Yes. On 1 July 2026 the anti-money-laundering regime took in new designated services, real estate agency work, conveyancing, professional services that set up or administer companies and trusts, and dealing in precious metals and stones.

The builder does not ask you whether you are a reporting entity, because that is the legal conclusion and it is the thing people get wrong. It asks which services you actually provide, in the words you would use for your own work, and separately whether those services are provided from Australia or to customers in Australia: the geographical link in section 6(6) of the AML/CTF Act. If both are there, the disclosure is included: the identity documents you collect, that the service cannot be provided without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent.

It is a privacy disclosure only. Your AUSTRAC obligations (enrolment, customer due diligence, reporting) are a separate regime, and this does not discharge any of them.

Does the policy cover notifiable data breaches?

Yes. If the Notifiable Data Breaches scheme in Part IIIC applies to you, the policy says that you assess a suspected eligible breach promptly and within 30 days, that if serious harm is likely you will notify both the person and the Office of the Australian Information Commissioner as soon as practicable, and that if you can prevent the harm before it happens notification may not be required.

That last part is in the scheme and is usually left out, which makes a policy promise more than the business can keep.