Generate legally compliant privacy policies, terms of service, HIPAA documentation, and compliance pages for healthcare SaaS platforms. Ensures Google Play/App Store approval and GDPR/HIPAA compliance.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Generate legally compliant privacy policies, terms of service, HIPAA documentation, and compliance pages for healthcare SaaS platforms. Ensures Google Play/App Store approval and GDPR/HIPAA compliance.
Business Associate Agreements (BAA) (HIPAA requirement)
All documentation is written to meet Google Play Store, Apple App Store, and Google API Services User Data Policy requirements.
Compliance Standards
1. GDPR Compliance (EU/UK)
Required Elements:
Legal basis for data processing (consent, legitimate interest)
Data subject rights (access, deletion, portability, rectification)
Data retention periods (specific durations)
International data transfers (adequacy decisions, SCCs)
Contact information (DPO or privacy officer)
Right to lodge complaint with supervisory authority
Automated decision-making disclosure
User Rights Under GDPR:
Right to access personal data
Right to rectification (correction)
Right to erasure ("right to be forgotten")
Right to restrict processing
Right to data portability
Right to object to processing
Rights related to automated decision-making
2. HIPAA Compliance (US Healthcare)
Required Elements:
PHI (Protected Health Information) definition
Security measures (encryption, access controls)
Breach notification procedures (within 60 days)
Business Associate Agreement (BAA) availability
Patient rights (access, amendment, accounting of disclosures)
Minimum necessary standard
Workforce training requirements
Technical Safeguards:
AES-256 encryption at rest
TLS 1.3 encryption in transit
Multi-factor authentication (MFA)
Role-based access control (RBAC)
Audit logging (immutable, 7+ years)
Automatic session timeout
Intrusion detection systems
3. Google API Services User Data Policy
Critical Requirements:
Limited Use: Only use Google user data for providing/improving the app's user-facing features
No Selling Data: Explicit statement that Google user data is NOT sold to third parties
No AI Training: Do not use Google Workspace data for training generalized AI models without explicit consent
Secure Transmission: All data transmitted via modern cryptography (TLS 1.2+)
Privacy Policy Link: Must be easily accessible from app (footer, settings)
Scope Justification: Only request minimum necessary scopes
Example Compliant Statement:
"We access your Google Calendar data solely to check availability and book appointments on your behalf. We do not sell your Google user data to third parties. We do not use your Google Workspace data for training generalized AI models without your explicit consent. All data is transmitted using industry-standard encryption (TLS 1.3)."
4. Google Play Store Requirements
Privacy Policy Must Include:
Developer/company name and contact information
Types of data collected (personal, sensitive, device)
How data is used and shared
Data retention and deletion policies
Security measures
User rights and choices
Third-party service providers (with links to their privacy policies)
Children's privacy (COPPA compliance if applicable)
Active account data: Retained while account is active
Inactive accounts: 30 days after last login, then flagged for deletion
Deleted account data: 90 days (soft delete), then permanent deletion
Call recordings: 30 days (adjustable per organization, max 7 years)
Transcripts: 90 days (adjustable per organization)
Audit logs: 7 years (HIPAA requirement)
Payment records: 7 years (tax/legal requirement)
Support tickets: 3 years
Legal Hold: Data subject to legal proceedings is retained until matter is resolved.
Security Measures to Document
Encryption:
AES-256 encryption for data at rest
TLS 1.3 for data in transit
End-to-end encryption for voice calls (where applicable)
Access Controls:
Role-based access control (RBAC)
Multi-factor authentication (MFA) for admin accounts
Principle of least privilege
Automatic session timeout (15 minutes)
Monitoring:
24/7 security monitoring
Intrusion detection systems (IDS)
Automated vulnerability scanning
Penetration testing (annually)
Backup & Disaster Recovery:
Daily encrypted backups
30-day backup retention
Multi-region redundancy
Disaster recovery plan (RTO: <1 hour, RPO: <24 hours)
Incident Response:
Dedicated security team
24-hour breach notification to affected users
Forensic investigation procedures
Post-incident review and remediation
Usage Examples
Example 1: Generate Privacy Policy
Generate a GDPR-compliant privacy policy for Voxanne AI with the following:
- Company: Voxanne AI (Call Waiting AI Ltd.)
- Address: Collage House, 2nd Floor, 17 King Edward Road, Ruislip, London HA4 7AE
- Services: AI voice receptionist for healthcare providers
- Data collected: Name, email, phone, clinic info, call recordings, transcripts, Google Calendar data
- Third parties: Vapi, Twilio, Supabase, Google Calendar API, Stripe
- Retention: 30 days inactive, 90 days soft delete, 7 years audit logs
- Contact: privacy@voxanne.ai
- Google API compliance: Yes (Calendar access)
- Target length: 500+ lines
Example 2: Generate HIPAA Compliance Page
Generate a comprehensive HIPAA compliance page for Voxanne AI:
- Audience: Healthcare providers (dental, medical clinics)
- PHI handled: Patient names, phone numbers, appointment details, medical queries
- Encryption: AES-256 at rest, TLS 1.3 in transit
- BAA: Available for enterprise clients (contact sales@voxanne.ai)
- Security contact: security@voxanne.ai
- Certifications: SOC 2 Type II (in progress)
- Target length: 400+ lines
Example 3: Review Existing Policy for Google API Compliance
Review this privacy policy for Google API Services User Data Policy compliance:
[paste existing policy]
Check for:
- Limited use statement
- No selling data statement
- No AI training statement
- Secure transmission mention
- Calendar data specific disclosures
- Easy-to-find location in app
Best Practices
1. Plain Language
Avoid legalese where possible
Use short sentences (15-20 words)
Define technical terms (e.g., "PHI" = Protected Health Information)
Use examples (e.g., "call recordings may contain PHI such as...")
2. Transparency
Be specific about data collection ("we collect your email address" vs. "we collect information")
Explain WHY data is collected (not just what)
Disclose all third parties (with links to their privacy policies)
3. User-Friendly Formatting
Use headings and subheadings
Use bullet points for lists
Highlight key information (bold or colored text)
Provide table of contents for long documents
4. Regular Updates
Review policies every 6 months
Update "Last Updated" date whenever changes are made
Notify users of material changes (email + in-app banner)
5. Legal Review
All generated documents should be reviewed by a qualified attorney
Especially important for healthcare (HIPAA) and EU markets (GDPR)
Consider hiring specialized privacy counsel
Compliance Checklist
Use this checklist to verify compliance before publishing: