Privacy notice for a SaaS product

A privacy notice and cookie notice for a SaaS product, drafted for the provider to sit alongside its customer terms and data processing agreement, for a fixed fee of £595 in five working days.

Share

Privacy notice for a SaaS product

Buy now, £595

A SaaS provider is a controller for the data it collects about its account holders, users and website visitors, and a processor for the data its customers put into the product, and the privacy notice covers the first while the data processing agreement covers the second; a notice that confuses the two tells customers that the provider decides what happens to their data, which is the opposite of what the provider has promised in its terms. The notice has to describe the account, user, billing and usage data the provider controls, name the sub-processors and the transfers, deal with cookies and product analytics, and say what happens to data when the subscription ends. I draft the privacy notice and the cookie notice for the provider, with guidance on the consent mechanism, for a fixed fee of £595, delivered in five working days; the data processing agreement is a separate document.

Who this is for

SaaS and software providers in England and Wales with business customers, consumer users or both, from a product preparing to launch to one whose notice was written before its stack changed.

What matters in a SaaS privacy notice

The two roles a SaaS provider plays and the notice that covers one of them

For the data the provider collects for its own purposes (account registration, billing, support, marketing, website analytics, product usage data it analyses to improve the service) the provider is a controller under the UK GDPR and the privacy notice under Article 13 covers it; for the content and personal data its customers upload into the product (their own customers' records, their staff's data, the documents they store) the customer is the controller and the provider is a processor acting on instructions under Article 28, which the data processing agreement governs; the notice should say this in its first section, because a business customer's own privacy notice to its users depends on the provider having got the roles right.

Account holders, users and the data the provider controls

The notice should set out the data the provider controls and the lawful basis for each use: account and billing data on the basis of the contract under Article 6(1)(b); security logs, fraud prevention and service improvement on the basis of legitimate interests under Article 6(1)(f) with the interest stated; support correspondence on the contract or legitimate interests; marketing to account holders on the basis of consent or the soft opt-in under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003; and the position of users invited by a customer (whose account data the provider controls but whose use of the product the customer directs); a notice that treats every user as the provider's own customer has not understood who the users are.

Customer content and the data the provider processes for its customers

The notice should state that content and personal data uploaded by customers are processed on the customer's instructions under the data processing agreement, that the customer is responsible for its own privacy notice to the individuals whose data it uploads, that the provider accesses customer content only to provide the service, for support with the customer's permission and as the law requires, and that requests from individuals about customer content are referred to the customer; the notice should also say what the provider does with aggregated or anonymised usage data derived from customer content (which the customer terms should permit), because that is where providers and customers disagree.

Sub-processors, hosting and international transfers

The notice should describe the categories of recipient for the data the provider controls (hosting and infrastructure, payment processing, email and support tools, analytics, authentication providers), should refer to the sub-processor list the data processing agreement maintains for customer content, and should state the international transfers (to a hosting region or a provider outside the United Kingdom) and the safeguards under Article 46 of the UK GDPR (the international data transfer agreement, the addendum to the EU standard contractual clauses, or an adequacy regulation) the provider relies on; a provider that hosts in the United States and says nothing about transfers has a notice its enterprise customers' procurement teams will reject.

Cookies, analytics and product usage data

The provider's website and the product itself set cookies and similar technologies, and regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 requires consent before any that are not strictly necessary (analytics, session replay, advertising, in-product tracking that is not needed to provide the service) are placed, with the consent mechanism doing the work the notice cannot; the pack includes a cookie notice listing the cookies and the technologies in the product by category and purpose and guidance on the consent mechanism, and the notice should explain product usage analytics (what is collected, whether it is identifiable, how it is used) separately from website cookies, because the regulator treats in-product tracking as it treats cookies.

Retention, deletion and the end of the subscription

The notice should state the retention periods for the data the provider controls (account data while the account is active and for a stated period after, billing records for the period tax law requires, logs for a stated period, marketing data until consent is withdrawn), the position on customer content at the end of the subscription (returned or deleted within the period the customer terms and the data processing agreement set, with backups overwritten on the provider's cycle), the individual's rights (access, rectification, erasure, restriction, portability, objection) and how to exercise them, the one-month time limit, the right to complain to the Information Commissioner's Office, and the provider's registration under the Data Protection (Charges and Information) Regulations 2018; the deletion at the end of the subscription is the question enterprise customers ask, and the notice and the terms should give the same answer.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Our customers upload their own customers' data into our product. Does our privacy notice cover it?

It does not. For that data the customer is the controller and the provider is a processor under the data processing agreement; the privacy notice covers the data the provider controls (accounts, billing, support, usage). The notice says so in its first section.

For any tracking that is not strictly necessary to provide the service, yes. The regulator treats in-product analytics as it treats cookies. The pack includes the cookie notice and guidance on the consent mechanism.

We host on US servers. What does the notice need to say?

That the provider transfers data outside the United Kingdom and the safeguard it relies on, which is also in the data processing agreement. Enterprise customers' procurement teams check for it.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.