Subject: Notice of Privacy Policy Update for [Company/Product Name]
Effective date: [YYYY-MM-DD]
Version: [Policy Version Number]
Link to full Privacy Policy: [URL]
Overview
We have updated our Privacy Policy to improve transparency about how we collect, use, disclose, retain, and protect personal data in connection with our cloud collaboration services. This notice summarizes the key changes. Please review the full policy at the link above.
Summary of key changes
- Data categories: Expanded descriptions of the personal data processed, including account identifiers, workspace/project metadata, collaborator role and activity logs, device and network information (e.g., IP address, browser type), and customer support records.
- Purposes of processing: Clarified purposes for service delivery, account administration, security and fraud prevention, service analytics and performance, product improvement, and compliance with legal obligations.
- Legal bases (EU/UK GDPR): Specified the legal bases for each processing purpose, including contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), consent for optional features/marketing/cookies where required (Art. 6(1)(a)), and legal obligations (Art. 6(1)(c)).
- Retention: Updated retention schedules and criteria for different data categories, including how we determine retention periods and when data is anonymized or deleted.
- Subprocessors: Updated the list of third-party service providers that support our services and the functions they perform. We will provide advance notice of material subprocessor changes via [URL or in-product notice].
- International data transfers: Clarified transfer mechanisms and safeguards (e.g., Standard Contractual Clauses, UK IDTA, or other applicable measures) for transfers to countries outside the EU/EEA/UK.
- Cookies and similar technologies: Consolidated cookie categories and provided enhanced controls to manage preferences. The policy explains consent requirements in applicable jurisdictions.
- “Sale”/“Sharing” under CCPA/CPRA: Clarified whether and how we “sell” or “share” personal information for cross-context behavioral advertising. The policy includes an opt-out mechanism and information on how we honor applicable opt-out signals (e.g., Global Privacy Control).
- Sensitive personal information: Defined any sensitive personal information we process and the limited purposes for its use. Included instructions to exercise the right to limit use/disclosure where applicable.
- Children’s data: Restated our service is not directed to children under applicable age thresholds and our approach to parental consent where required.
- Automated decision-making: Described any automated processing that produces legal or similarly significant effects and how to exercise related rights.
- Contact points: Updated Data Protection Officer (DPO) and regional contact details for privacy inquiries and complaints.
Your rights and choices
EU/EEA and UK (GDPR/UK GDPR)
- You may request access, rectification, erasure, restriction, data portability, and object to processing, and withdraw consent where processing is based on consent.
- You have the right to lodge a complaint with a supervisory authority. Contact details are provided in the Privacy Policy.
- Submit requests via: [Self-service portal URL], [DPO email], or [postal address].
California (CCPA/CPRA)
- You may request to know/access the categories and specific pieces of personal information we collect, delete personal information, correct inaccuracies, opt out of “sale” or “sharing,” and limit use/disclosure of sensitive personal information. We will not discriminate for exercising these rights.
- Exercise rights via: [Web form URL], [toll-free number], or the “Do Not Sell or Share My Personal Information” link: [URL].
- We honor applicable opt-out preference signals as required by law. See the Privacy Policy for details.
Other jurisdictions
- Rights under other privacy laws are described in the Privacy Policy, including available appeals processes where required.
Security and data protection
- We have reaffirmed technical and organizational measures to protect personal data, including access controls, encryption in transit and at rest (where implemented), logging/monitoring, vulnerability management, and incident response procedures. Details are outlined in the Privacy Policy and supporting documentation: [Security page URL].
International data transfers
- Where data is transferred internationally, we use appropriate safeguards recognized by applicable law. The Privacy Policy explains the mechanisms in use and provides links to relevant documentation and FAQs.
Subprocessors
- An updated list of subprocessors is available at: [Subprocessor list URL]. We will notify users of material changes according to the process described in the Privacy Policy.
Action required
- No immediate action is required to continue using the service. If a change requires consent (e.g., certain cookies or optional features), we will request it through in-product prompts or settings.
- Please review and update your privacy preferences in: [Account settings URL].
Questions or contact
- Data Protection Officer: [DPO Name], [DPO email]
- EU/UK representative (if applicable): [Representative Name/Company, contact details]
- Privacy inquiries: [Privacy email], [Postal address]
- For California consumers: [toll-free number], [web form URL]
This notice is a summary. The full Privacy Policy governs and provides comprehensive information about our data practices. Continued use of the service after the effective date constitutes acknowledgment of these updates, subject to applicable law and any required consent.