VooDooBox
Sign inSign up
Draft — not legally reviewed, not in effect.

The document below is a working draft, written to cover EU, North American, and ANZ markets. It has not been reviewed by a licensed professional in any jurisdiction, creates no binding obligations, and must not be relied on — see the “Legal surface” item in this project’s go-live runbook.

Privacy Policy

DRAFT — FOR TEST PURPOSES ONLY. NOT FOR PUBLICATION.

Last updated: [DATE] Effective date: [DATE]

This policy explains what personal information [PRODUCT/COMPANY NAME] ("we," "us") collects through our personal virtual assistant service (the "Service"), why we collect it, and the rights you have over it. It's written to meet our obligations under the EU General Data Protection Regulation (GDPR), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25, U.S. state privacy laws (including the CCPA/CPRA and the Virginia-model laws now in effect in 20+ states), the Australian Privacy Act 1988 and Australian Privacy Principles, and the New Zealand Privacy Act 2020 (including the indirect-collection notice requirement, IPP 3A, in force since May 1, 2026).

If you're a resident of one of these regions, section 9 tells you exactly which extra rights apply to you.


1. Who we are

[COMPANY NAME] ("we") is the data controller (EU/UK terms) / organization (Canada/NZ terms) / business (US/Australia terms) responsible for your personal information when you use the Service.

Contact: [PRIVACY EMAIL] · [MAILING ADDRESS] If required in your jurisdiction, our EU/UK representative is: [NAME/ADDRESS, IF APPLICABLE]

2. What we collect

We collect only what the Service needs to function:

  • Account data — name, email, password (hashed), account settings.
  • Connected service data — calendar entries, emails, contacts, or tasks, but only from the accounts you explicitly connect, and only the fields needed to perform the function you asked for.
  • Assistant interaction data — your requests to the assistant and its responses, so it can maintain context and improve.
  • Device and usage data — IP address, device type, app version, crash logs, general usage analytics.
  • Third-party information — if a calendar invite, shared contact, or email you connect includes information about someone else, we process that incidentally to deliver the Service to you. We do not use it for any other purpose. Where required by law, we take reasonable steps to make this notice available to that person too.

We do not knowingly collect biometric identifiers, precise health data, or financial account credentials unless you explicitly provide them for a feature that requires it, and we'll tell you at that point what it's for.

3. Why we use it (legal basis)

Purpose Legal basis
Running the assistant's core functions Performance of a contract with you
Improving reliability and safety Legitimate interest, balanced against your rights
Security, fraud, and abuse prevention Legitimate interest / legal obligation
Marketing communications Your consent, withdrawable anytime
Sensitive categories of data, where applicable Your explicit, opt-in consent

4. Automated processing

The assistant uses AI models to interpret your requests and generate responses. This is core to how the Service works, and no automated decision produces a legal or similarly significant effect on you without the option of human review. If this changes for any feature, we will disclose it specifically before you use that feature.

5. Who we share it with

We share personal information only with:

  • Service providers who process data on our behalf under contract (cloud hosting, AI model providers, customer support tools), bound to use it only for the purposes we specify.
  • The connected services you authorize (e.g., your calendar or email provider), to the extent necessary to perform the function.
  • Authorities, if legally required.

We do not sell personal information. We do not share it with advertisers.

6. International data transfers

Your data may be processed in a country other than the one you're in. Where we transfer personal information out of the EU/EEA, UK, Australia, Canada, or New Zealand, we use recognized safeguards (such as Standard Contractual Clauses or an applicable adequacy decision) and take reasonable steps to ensure comparable protection at the destination.

7. How long we keep it

We keep personal information only as long as needed for the purposes above, or as required by law. Account data is retained while your account is active and deleted within [X days] of account closure, except where we must retain it longer for legal, tax, or security-incident purposes.

8. Security

We use technical and organizational measures — encryption in transit and at rest, access controls, and regular review — appropriate to the sensitivity of the data. No system is perfectly secure; if a breach creates a real risk of harm to you, we will notify affected individuals and the relevant regulator within the timeframe required by law (as fast as 72 hours under some regimes).

9. Your rights, by region

If you're in the EU/EEA or UK (GDPR): You have the right to access, correct, delete, restrict, or port your data, to object to processing based on legitimate interest, and to withdraw consent at any time. You can lodge a complaint with your local supervisory authority.

If you're in Canada (PIPEDA / Quebec Law 25): You have the right to access and correct your personal information, to know how it's used, and to withdraw consent. Quebec residents additionally have the right to request deletion and data portability, and the right to be informed about automated decision-making.

If you're in the US: Depending on your state, you have rights to know what's collected, to access, correct, and delete it, to opt out of the sale or "sharing" of personal information (we don't sell data, but you can still exercise this right), and to opt out of targeted advertising and certain profiling. We honor recognized universal opt-out signals (e.g., Global Privacy Control) where required by your state's law.

If you're in Australia: Under the Australian Privacy Principles, you can access and correct your information and complain to us or to the Office of the Australian Information Commissioner if you believe we've mishandled it. Where our processing involves automated decision-making with a material effect on you, we will disclose this in line with the Privacy Act's phased-in requirements.

If you're in New Zealand: You have the right to access and correct your personal information under the Privacy Act 2020. Where we collect information about you indirectly — for example, from someone else's connected calendar — we will take reasonable steps to notify you as required under IPP 3A.

To exercise any of these rights, contact us at [PRIVACY EMAIL]. We will respond within the timeframe required by your local law (typically 30 days, up to 45 in parts of the US).

10. Children

The Service is not directed at children and we do not knowingly collect personal information from anyone under 16 (or the higher age of digital consent set by your local law). If we learn we've collected a child's data without appropriate consent, we will delete it.

11. Cookies and tracking

[Insert specifics once the product's actual tracking stack is known — session cookies, analytics, etc. Under current EU and incoming Australian rules, non-essential tracking requires active opt-in consent, not a pre-ticked box or a "continuing to browse" implied-consent notice.]

12. Changes to this policy

We'll update this policy as our practices or the law changes, and post the new effective date above. Material changes will be actively communicated, not just posted.

13. Contact us

[COMPANY NAME] [PRIVACY EMAIL] [MAILING ADDRESS]


This document is a compliance baseline, not a substitute for legal review. Data protection law is actively shifting in every jurisdiction covered here — Canada's Bill C-36, the EU's Digital Omnibus proposal, and Australia's automated-decision-making disclosure rule (effective December 2026) are all in motion. Have counsel licensed in each relevant market review before publishing, especially once you finalize what data the Service actually touches.