Two roles: controller and processor
Under the GDPR, a SaaS company usually plays two roles at once:
- Controller for data you decide to collect yourself: sign-up details, billing information, product analytics, support conversations and your marketing site's visitors. Your privacy policy describes this data.
- Processor for the data your customers store in your product, such as their own users' records, files or messages. You handle it only on their instructions, and the terms for it belong in a data processing agreement (DPA) with each customer.
Your privacy policy should make this split clear. Say that you process customer content on behalf of your customers, and point to your DPA for the details, instead of trying to describe every customer's data in the policy.
What a SaaS privacy policy should cover
- Account and billing data: names, work emails, company details and payment records, with payments usually processed by a provider such as Stripe or Paddle
- Product usage data: logs, feature usage, device and browser details, and the analytics tools you use
- Marketing site data: cookies, analytics and ad pixels on your website, with a link to your cookie policy
- Communications: support tickets, onboarding emails and newsletters, and how to unsubscribe
- Legal bases: contract, legitimate interests and consent, for users in the EEA and the UK
- Security: the main measures you take, such as encryption and access controls
- Retention: how long you keep account data and customer content after a subscription ends
- Rights and contact: how people can access, correct or delete their data, and who to contact
Subprocessors
Every service that handles customer data for you, such as your cloud host, email provider and support tool, is a subprocessor. The GDPR requires processors to get their customers' authorization before using subprocessors, so SaaS companies usually publish a subprocessor list and notify customers before adding new ones. Link to that list from your privacy policy and your DPA. You can host it as a separate page on Legiflare.
International data transfers
If you or your subprocessors process personal data from the EEA or the UK outside those regions, you need a transfer mechanism. The most common are certification under the EU-US Data Privacy Framework, for US companies that join it, and the European Commission's Standard Contractual Clauses. Name the mechanism you rely on in your policy.
B2B data and the CCPA
Since January 1, 2023, the CCPA's temporary exemptions for business-to-business and employee data have expired. If the CCPA applies to your company, the contact details of people at your customers' companies are covered too, so your policy needs the California disclosures even if you only sell to businesses.
Checklist for a SaaS privacy policy
- The policy separates the data you control from customer content you process.
- Analytics, payment, email and support tools are named or described.
- There is a link to your DPA and subprocessor list.
- Your transfer mechanism is stated.
- Retention after cancellation is clear.
- The policy is linked from your sign-up page, app footer and website.
Frequently asked questions
Do I need a DPA as well as a privacy policy?
If your customers store personal data in your product and any of it is covered by the GDPR, yes. The GDPR requires a written contract between a controller and its processor, and a DPA is that contract.
Should my website and my app share one privacy policy?
Usually yes. One policy that covers both the marketing site and the product is easier to keep accurate. Use headings to separate website visitors from customers.
Do enterprise customers read the privacy policy?
Often, during security and procurement reviews. A clear policy, together with a DPA and a subprocessor list, makes those reviews faster.