A privacy policy that matches what your product really does.
A privacy attorney drafts your policy and terms from your real data flows — your forms, your vendors, your tracking — not from a generator template that nobody read. We start with a free written audit of your live site, then write the documents backwards from reality so they hold up to a regulator and to enterprise procurement. Tailored to GDPR, CCPA and US state law, and India's DPDP Act.
From $495 — a flat fee per document set, quoted after a free audit, before any work begins.
Send your name, email, company, and website. Within two business days we send back a written audit of your live site — the data you collect, the trackers and vendors you run, and where your current policy (if any) misstates what the product does. No payment, no obligation, and the audit is yours to keep.
2
Discovery and drafting
A thirty-minute call to map your real data flows, vendor list, and user base across the jurisdictions you operate in. We then draft a privacy policy, terms of service, and cookie policy from that reality, with a plain-English summary of every section so you understand what each clause does and why.
3
Deliver and implement
We deliver the document set, help you publish and version it, and align the cookie disclosures with your consent banner. We set an annual review reminder so the documents stay current as your product, vendors, and the law change.
What it costs
Quoted by document set and scope
Privacy Policy & Terms Drafting starts from $495. Every engagement is quoted up front, in writing, after a free audit of your live site and a short discovery call — once your data flows, jurisdictions, and the document set are known. The fee is scoped to the work: a single privacy policy, or a full policy, terms of service, and cookie policy set across multiple jurisdictions and an AI feature set. Compliance is ongoing rather than a one-time outcome, so an annual review and refresh option is available.
What's included
Free written privacy audit of your live website, yours to keep
Custom privacy policy drafted from your actual data flows
Custom terms of service or EULA
Cookie policy aligned with your consent-banner disclosures
Rights language for GDPR, CCPA, CPRA, US state laws, and India's DPDP Act
AI and ML disclosures, and children's-privacy clauses, where they apply
Plain-English summary of every section
Annual review reminder, with a retainer option to keep documents current
Privacy policy only
Quoted by scope
Policy + terms + cookie policy set
Quoted by scope
Multi-jurisdiction or AI-product add-ons
Quoted by scope
Annual review and refresh retainer
Quoted by scope
No GTC fee is committed until the free audit is done, the scope is confirmed, and you have approved the quote in writing. Any third-party translation is arranged through trusted legal-translation partners and passed through at cost.
Get started
Get your privacy policy & terms
Tell us about your product and the website it runs on, and a GTC attorney will send a free written audit and a flat-fee quote — no payment, no obligation.
No payment required Reply within 1 business dayA GTC attorney reviews it & sends a flat-fee quote.
01Your request
02Documents
03Your details
Include your live website URL — the free audit reads your actual forms, trackers, and vendors so the quote and the draft start from reality.
Your request
1
Legal name of the entity.
2
Pick all that apply.
3
Drives standard provisions.
4
E.g. 'email, name, IP address, device info, payment info via Stripe, analytics via GA'.
5
Where are your users located? Drives which laws apply (GDPR / CCPA / etc.).
Why GTC
What lawyer-drafted documents buy you.
Handled by
GTC's privacy team
Data-protection counsel
Attorney-led
Built from your real data flows
A regulator checks three things first: does the policy describe the data you collect, does it give a real legal basis under GDPR or a business purpose under CCPA for each collection, and does it explain users' rights and how to exercise them. We write from your forms, vendors, and tracking, so the document answers all three accurately.
Survives enterprise diligence
Enterprise procurement and security questionnaires can spot a generated policy quickly. A document that matches your actual practices — and a plain-English summary you can speak to — is what gets you through a customer's vendor review rather than stalling the deal.
Multi-jurisdiction by design
One policy, written to GDPR, CCPA, CPRA, and the major US state privacy laws, with India's DPDP Act and children's-privacy clauses (COPPA, GDPR-K) added where they apply. We disclose only the rights and obligations that genuinely apply to where you operate.
Terms that protect you
Your terms of service limit your liability, protect your IP, and give you a clean way to suspend or terminate problem users — with governing law, venue, and dispute-resolution clauses drafted to be enforceable in your jurisdiction, not padded with copied clauses that are not.
Your Customer Success Team
A dedicated team that owns your matter from start to finish.
Every GTC client gets a dedicated Account Manager and a Senior Account Manager who learn your business and stay with you from first email to final filing. They are named people who pick up the phone and already know your matter, so every step moves forward without delay.
Your Account Manager
Your day-to-day point of contact, who coordinates every matter, keeps things moving, and already knows your file. They have your full history, so you start every conversation where the last one left off.
Your Senior Account Manager
Senior oversight on strategy and escalations, stepping in as your needs grow, so every important detail stays on track.
A named person, on email or a call, at every step.
How we compare
How GTC drafting compares to a generator template and a big consultancy.
What you get
GTC
Online filing services
Doing it yourself
Drafted by a privacy attorney from your real data flows
Free written audit of your live site before any work begins
Plain-English summary of every section
Covers GDPR, CCPA, US state law, and India's DPDP Act in one document set
AI and cookie disclosures included where they apply
Annual review reminder so the documents stay current
Drafted by a privacy attorney from your real data flows
GTC
Online filing services
Doing it yourself
Free written audit of your live site before any work begins
GTC
Online filing services
Doing it yourself
Plain-English summary of every section
GTC
Online filing services
Doing it yourself
Covers GDPR, CCPA, US state law, and India's DPDP Act in one document set
GTC
Online filing services
Doing it yourself
AI and cookie disclosures included where they apply
GTC
Online filing services
Doing it yourself
Annual review reminder so the documents stay current
GTC
Online filing services
Doing it yourself
The timeline
From first call to documents you can publish.
Drafting is quick once we understand your data flows. Here is the path from the free audit to a published policy and terms.
Days 1–2
Free audit
You send your details and we return a written audit of your live site — the data collected, the vendors and trackers running, and where your current documents misstate the product.
Day 3
Discovery call
A thirty-minute call to map your real data flows, vendor list, user base, and the jurisdictions you operate in, so the drafting starts from reality rather than a checklist.
Days 4–10
Drafting
We draft the privacy policy, terms of service, and cookie policy from your data flows, with a plain-English summary of every section, and share them for your review.
Ongoing
Publish and review
We help you publish and version the documents, align the cookie disclosures with your consent banner, and set an annual review reminder so they stay current as the product and the law change.
In their words
All your legal, in one place.
One accountable team across every practice, operating since 2016.
A generator produces a generic policy from a checklist, with no idea what your product does. If the result names data you do not collect, vendors you do not use, or rights that do not exist where you operate — and generated policies routinely do — the document misleads your users and hands a regulator a first finding. We start from a free written audit of your live site and draft from your real data flows, then explain in plain English what each clause does. Regulators and enterprise procurement can tell the difference.
Drafting the documents is the start. Most clients pair it with a full compliance programme for the jurisdictions they operate in. Here is the related lineup.
Send your name, email, company, and website. We will return a free written audit of your live site within two business days, confirm the scope on a short call, and quote a flat fee in writing before any work begins.
We use cookies to improve your experience.We use cookies to improve your experience, analyze site traffic, and personalize content.Learn more about cookies