Privacy Policy addendum
Bring your privacy policy up to date with subprocessors, borders, and AI.
Your privacy policy was probably written before subprocessors, cross-border processing, and AI tools became the questions clients actually ask. Lavawall® drafts a drop-in addendum that covers all three, auto-filled from the vendors, data flows, and AI use already captured in your Business Impact Assessment records.
It uses data you already have, and it is written in plain language your clients can read. You get a current, honest addendum without rewriting your whole policy.
Start with the GRC Wizard See the full GRC platform
Auto-filled from your BIA · subprocessors · international processing · AI tool use
The gap in most privacy policies
Buyers, regulators, and their lawyers now expect a privacy policy to say who else handles the data, where it crosses borders, and whether AI is in the mix. Few older policies do. Rewriting one is a legal project most teams keep putting off. The addendum closes the gap without the rewrite.
Two themes run through it
First, it uses data you already have. Lavawall reads the subprocessors, data flows, and AI use in your BIA records and drafts each section for you. Second, it is written in plain language, so the addendum reads like a statement to clients, not a contract only a lawyer can parse.
Subprocessors, named and explained
The addendum sets out the subprocessors who help handle personal information and what they do, drawn from your BIA vendors, so clients can see who is in the chain and why.
International processing, stated plainly
Where data is processed in another country, the addendum says so and points to your Foreign Processing Disclosure for the detail, keeping your public statement consistent with your internal records.
AI tool use, out in the open
If your organisation uses AI tools that touch personal information, the addendum describes that use in plain language, the transparency clients and regulators increasingly look for.
Why an addendum beats a rewrite
Current in an afternoon
Because it is auto-filled from your BIA records, you review and confirm instead of drafting from scratch, so your public statement catches up fast.
Consistent with your other documents
The same subprocessors and data flows feed your Foreign Processing Disclosure and data flow register, so your public and internal records tell one story.
Answers the questions buyers ask
Subprocessors, borders, and AI are standard items on security questionnaires. Putting them in your policy answers them before they are raised.
Reconcile before you publish
This addendum is a starting draft generated from your records. Before it goes public, it must be reconciled with your main privacy policy so the two documents do not contradict each other on retention, contact details, or the rights you offer. It is not legal advice.
Check it against your existing policy
Make sure the addendum's language on subprocessors, borders, and AI lines up with what your main policy already says, and resolve any conflicts before publishing.
Have your counsel review it
A privacy lawyer or advisor should confirm the wording fits your obligations and your jurisdiction. Lavawall gets you most of the way; your advisor finalises it.
Part of the wider GRC platform
Foreign Processing Disclosure
The outside-Canada notice the addendum's international section points to.
Learn more →Data Flow Documentation
The subprocessor register that keeps the addendum's vendor list accurate.
Learn more →Business Impact Assessment
The records that fill every section, captured once in plain language.
Learn more →Common questions
- What is a privacy policy addendum?
- A public add-on to your existing privacy policy covering three things people increasingly ask about: the subprocessors who help handle their data, the international processing it may go through, and how your organisation uses AI tools. Lavawall drafts it from the vendors, data flows, and AI use in your Business Impact Assessment records.
- Why do I need one on top of my privacy policy?
- Most privacy policies were written before subprocessors, cross-border processing, and AI tools became routine questions. Rather than rewrite the whole policy, the addendum drops in the current detail, auto-filled from data you already have, so your public statement matches how you operate today.
- Where does the content come from?
- From your BIA records. Lavawall reads the subprocessors, data flows, and AI tool use you have already captured and drafts each section in plain language. You review and adjust rather than write from a blank page.
- Can I publish it as is?
- No. It is a starting draft. It must be reconciled with your main privacy policy so the two do not contradict each other, and your legal counsel should review it before you publish. Lavawall gets you most of the way; your advisor finalises it.