You answer questions about how your business actually handles personal information. The policy is assembled from your answers, nothing in it that you did not tell us, and nothing left out because a shorter form never asked.
Around 71 questions for a simple business, and up to 126 if all of it applies to you. Questions you do not need are never shown: answering “no” to one often closes several others, so the form gets shorter as you go.
They cover what you collect and why, who else sees it, what runs on your website, whether meetings get recorded, what you publish about your customers, how long you keep things, and what happens when someone asks to see their file.
Every question has a plain-English explanation of what it means and why we are asking, one click away. If you are not sure what something is, that is the normal case and the explanation is written for it.
A finished policy built from a library of 91 sections, of which you get only the ones your answers call for. A business with no premises, no website and no staff gets a short policy. One that records meetings, runs advertising pixels, holds identity documents and publishes customer stories gets all of it.
Three of those sections are the ones generic templates do not have, and they are the reason the questionnaire is as long as it is:
Download it as a PDF, a Word document or HTML. Each section also comes with a short note explaining why it is there and which of your answers put it in, useful months later, when someone asks.
One payment, no subscription, one business. We email you a link to your builder so closing the tab does not lose it, and for 30 days you can change your answers and generate a fresh policy as often as you need, useful when you spot a typo, or when something about the business changes.
After 30 days the policy you downloaded is yours to keep and does not stop working; only the ability to rebuild it here finishes. If you build policies for clients, each business needs its own.
AegorIQ is not a law firm and no lawyer has reviewed this template. It is a starting document built from your answers, not legal advice.
Your builder opens straight away on the confirmation page, and the link is emailed to you as well so you can finish it later or come back to make changes.
Yes. Your answers are saved as you go, so you can close the builder and pick it up from the same emailed link. They are encrypted in your browser before they reach us, with a key that is part of your link and nothing else, so what we store is a block of characters we cannot read. That also means we cannot recover your answers if you lose the email, and anyone you forward the link to gets your saved answers with it. Everything is deleted when your 30-day window closes.
No. The finished policy is emailed to you and written nowhere else: not to our database, not to a log, not to disk. The only copies that exist afterwards are yours.
All three are in the library of 91 sections, and each is reached by its own questions rather than being included by default.
The automated-decision section is the APP 1.7 and 1.8 disclosure commencing 10 December 2026, scoped against all three limbs of the test. The AML/CTF section is the privacy disclosure for the designated services that entered the regime on 1 July 2026, reached by asking which services you provide and whether they have an Australian link. The notifiable data breach section covers how you assess a suspected breach, the 30-day window, and who you tell. Your AUSTRAC obligations are a separate regime and the AML section does not discharge them.