Free Privacy Policy Generator for UK Small Business Websites

Generate a plain-English privacy policy covering UK GDPR essentials: what you collect, why, how long you keep it, and users' rights.

Free plan includes 30 credits, no card required

Documents are AI-generated drafts for you to review before use. Vizivo doesn't provide legal, financial or other professional advice.

Covers UK GDPR + PECR cookie basics
Plain English your customers can read
Remembers your business details

What the generator produces

A UK GDPR privacy policy in plain English, covering what the regulation actually requires you to tell people:

SectionWhat it covers
Who we areYour business as data controller, and how to contact you
What we collectThe categories of personal data, tied to how your site collects them
Why, and our lawful basisUK GDPR requires a lawful basis for each purpose, not simply a reason
Who we share it withYour processors: email tools, analytics, payment providers, hosting
How long we keep itRetention periods, rather than "as long as necessary"
Your rightsAccess, correction, erasure, portability, objection, and how to exercise them
CookiesWhat you set and how visitors control them, which is PECR rather than UK GDPR
ComplaintsThe right to complain to the ICO, with their details

What it asks you

What your website does, what it collects (contact forms, mailing list, orders, accounts), which third-party tools you use, whether you run analytics or advertising cookies, and how long you keep records. Your business details come from your Business Memory.

The third-party question is the one people underestimate. Every tool that touches personal data, from your email provider to your analytics, is a processor you are expected to disclose.

What comes out

A formatted policy you can publish, export as PDF or Word, and revisit whenever you add a tool that collects something new. It costs 5 credits, and the free plan includes 30 a month.

What it does not do

It does not give legal advice, and it does not replace a professional review if you process special category data, children's data, or personal data at scale.

It also does not build your cookie banner. A policy explains what you collect; the banner is how you obtain consent before non-essential cookies are set. Most UK sites running analytics need both.

The ICO publishes plain-English guidance and runs a small business helpline, and it is genuinely good. If you want to work out whether you need a policy at all, our guide on UK privacy policies covers that.

Questions

Is this legal advice?
No. It is a strong, well-structured first draft. Have a professional review it if your data processing is complex.
Does it cover cookies?
Yes, a cookies section is included when you tell it your site uses them. The policy is not the same as a cookie banner though: most UK sites running analytics need both.
Does a small UK website really need a privacy policy?
If it collects any personal data, yes. A contact form, an email signup or analytics cookies all count as processing personal data under UK GDPR, which requires you to tell people what you collect and why.
Can I copy a privacy policy from another website?
It is a poor idea. The policy has to describe what your site actually collects, which tools you use and how long you keep data. A copied policy describes someone else's processing, which is worse than useless if a customer or the ICO asks.
How often should I update it?
Whenever you add something that collects or shares personal data: a booking widget, a chat box, a new email tool. The policy is meant to describe what you do now, not what you did at launch.
How long does it take?
A few minutes. The generator asks what your site collects and which tools you use, and takes your business details from your profile.