Privacy policy & Cookie policy

Legal IT Group
Contact
We create privacy policies and cookie policies for websites and apps
legal it group

Why us?

Separate privacy practice since 2018

We developed hundreds of privacy documents for websites and apps
  • Team of three FIP

    Global privacy experts are in our team
    sircles
  • Privacy ambassadors

    Frequent live and online privacy events
    about_icon2
  • Experts in CCPA (CPRA), GDPR, PIPEDA

    We have longstanding experience in creating policies for different markets
    about_icon3
  • We work with all stakeholders

    Businesses, controllers, processors, service providers, and more
    about_icon4
Send a request
decor

How is a privacy policy created? How is a privacy policy created? How is a privacy policy created? How is a privacy policy created?

  • 01

    We study your product

    We analyze which personal data is collected and how it is used
  • 02

    We review the current policy

    We assess its compliance with current legal requirements, completeness, and relevance to the product
  • 03

    We create a new policy

    If the current privacy policy doesn’t meet legal standards, we draft a new version
  • 04

    We review cookies

    We examine your cookie banner design and cookie policy text — and update them if needed
  • 05

    We review consent texts

    For cookies, newsletter sign-ups, application forms, and more
  • 06

    We add a DPA

    An optional step for companies looking to streamline B2B sales and operate in specific markets

What user rights does it use? What user rights does it use? What user rights does it use? What user rights does it use?

red-folder EU
USA
  • Right to access personal data

    Find out whether data is being processed and receive a specially formatted archive or document with that data
  • Right to rectification of inaccurate data

    Data processing systems must include functionality for correcting user records
  • Right to erasure (“right to be forgotten”)

    This right does not always apply, so it’s important to understand which data your company must delete upon request
  • Right to restrict data processing

    Systems should be configured to, for example, isolate such data in a separate table or make records read-only in response to this request
  • Right to data portability

    Affects data format choices, processing systems, protocols, data architecture, and third-party vendors involved
  • Right to object to data processing

    The user has an absolute right to opt out of marketing, so clear links and mechanisms must be provided to exercise this right
  • Right not to be subject to automated decision-making, including profiling

    Important for AI systems — there must be a way for human intervention and the ability to override decisions
  • Right to know

    What categories and specific pieces of personal data are collected, disclosed to third parties, or sold — and for what purposes
  • Right to delete personal information

    Similar to the GDPR, but with jurisdiction-specific nuances
  • Right to opt-out of the sale or sharing

    Applies to businesses that profit (or benefit in other ways) from selling or disclosing data to third parties upon request
  • Right of non-retaliation

    Guarantees that submitting a request cannot be used by the company to discriminate against the individual
  • Right to limit use of sensitive personal information

    For example, limiting the duration of use, restricting storage within company systems, or disclosure to certain third parties
  • Right to correct personal information

    Similar to the GDPR — requires both architectural and procedural updates, such as enabling databases to modify user data or records
  • Right to opt-out of automated decision-making technology

    Relevant for AI and other automated systems — especially when data is collected directly from the data subject
  • Right to refuse targeting / cross-context behavioral advertising (CCBA)

    Specific requirements for companies acting as data brokers or using advertising in their business models
implementation_icon

We can help with the following:

  • Privacy Policy

    implementation_icon1
    We review your current privacy policy or create a new one
  • Cookie Policy

    implementation_icon2
    We help you draft a new cookie policy or configure a cookie management tool
  • “Do not sell/share my PII” page

    implementation_icon3
    We help ensure compliance with California’s data protection laws
  • Data Processing Agreement

    implementation_icon4
    We create annexes to public offers and EULAs to simplify data processing for your B2B clients
  • Imprint або Impressum

    A dedicated page required under telecom laws in certain EU countries
  • Cookie Management Platforms (CMPs)

    icon
    We support the selection and configuration of the right tool
  • Forms for GDPR/CCPA requests

    We assist in designing and implementing request forms for data subject rights

How much does it cost?

€100/hour
Depends on the complexity of data flows and processing mechanisms
Send a request
Команда

Team

  • Катерина Дубас Legal IT Group

    Kateryna Dubas

    Head of Privacy Practice at Legal IT Group
  • Антон Тарасюк Legal IT Group

    Anton Tarasiuk

    Managing partner at Legal IT Group
  • Антон Демчук Legal IT Group

    Anton Demchuk

    Junior IT/Privacy Lawyer at Legal IT Group
  • Дмитро Нефьодов Legal IT Group

    Dmytro Nefodov

    Junior AI/privacy lawyer at Legal IT Group

Certified GDPR experts

We hold 10+ certifications in the field of privacy

Our expertise is internationally recognized

Snov.io

Smart automation of cold sales
  • we are honored to act as DPO for Snovio.io

  • we help them with other legal tasks

Odeeo

Innovative in-game audio advertising platform
  • we were glad to enhance the product by developing a Compliance Rollout Programme

  • we act as a DPO

Readdle

Product IT company engaged in application development
  • we worked with the Readdle team on their data flow mapping

  • we helped them to add even more transparency to the relationship between Readdle and their customers

Multisearch.io

Smart search for the website
  • we helped with Privacy Policy and Terms of Use

blackthorn.ai

Service company, AI expertise to create business solutions
  • we developed IT contracts

BUKI

Free resource for finding a tutor
  • we have provided consultations on legal issues

  • we helped with the Terms of Use and Privacy documents preparation

blog_iconCurrent and practical articles

  • Data protection officer
  • AI compliance officer
  • Data privacy compliance
  • Дія.City
  • Digital Millennium copyright Act
  • Торгова марка в IT
Go to Blog

We write about what we practice

IP, GDPR, contracts and disputes, as well as the legal aspects of implementing technologies like artificial intelligence or sharing best practices for delivering practical legal solutions.