| Privacy Notice |
Baseline |
Explains controller identity, data categories, sources, purposes, legal bases, recipients, transfers, retention, rights, security, and contacts. |
User accounts, forms, analytics, logs, support, or any personal data collection. |
| Notice at collection |
Baseline |
Provides concise, just-in-time information before the user enters an email or other personal information. |
California CCPA when covered; GDPR transparency; good global practice. |
| Cookie and device-storage notice |
Baseline disclosure |
Describes cookies, local storage, session tokens, guest data, preference storage, vendors, and durations. |
Any browser or device storage. Consent layer depends on purpose and jurisdiction. |
| Cookie preference center |
Triggered |
Blocks nonessential technologies until valid consent and supports withdrawal. |
EU nonessential storage; behavioral analytics; advertising; session replay; embeds. |
| Terms of Use |
Baseline for accounts |
Defines eligibility, account rules, service scope, user content, IP, suspension, termination, disclaimers, liability, and change procedures. |
Login, saved data, interactive services, beta access, API access, or user content. |
| Acceptable Use Policy |
Baseline for accounts |
Defines prohibited conduct, security abuse, automation, malware, impersonation, illegal content, enforcement, and appeal. |
Accounts, APIs, uploads, shared resources, or platform interactions. |
Colombia Personal Data Processing Policy Política de Tratamiento de Datos Personales |
Jurisdictional |
Publishes controller duties, purposes, rights, channels, procedures, effective date, and database duration. |
Colombian controller or processing governed by Colombian law. |
Colombia Privacy Notice and authorization Aviso de Privacidad y autorización |
Jurisdictional |
Gives collection-time notice and records prior, express, informed authorization where no exception applies. |
Collection of personal data subject to Law 1581. |
| Legal / company notice |
Jurisdictional |
Identifies legal entity, address, email, registration, VAT, professional or supervisory details. |
EU business websites; Colombia e-commerce; regulated activities. |
| Accessibility statement |
Recommended floor |
States target standard, status, known limitations, testing date, feedback channel, and remediation process. |
EU e-commerce and covered services; U.S. public accommodations; public-sector rules. |
| Retention schedule |
Internal control |
Defines category-level retention and disposal. The public notice summarizes it. |
Any personal data system. |
| Data rights procedure |
Internal + public channel |
Identity verification, access, correction, deletion, portability, opt-outs, appeals, and statutory deadlines. |
GDPR, Colombia, California, and other state privacy laws. |
| Incident response and breach notice plan |
Internal control |
Maps detection, containment, investigation, legal analysis, notification, evidence preservation, and communications. |
Any personal data system; all U.S. states have breach-notification laws. |