๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Privacy Policy addendum

Bring your privacy policy up to date with subprocessors, borders, and AI.

Your privacy policy was probably written before subprocessors, cross-border processing, and AI tools became the questions clients actually ask. Lavawall® drafts a drop-in addendum that covers all three, auto-filled from the vendors, data flows, and AI use already captured in your Business Impact Assessment records.

It uses data you already have, and it is written in plain language your clients can read. You get a current, honest addendum without rewriting your whole policy.

Start with the GRC Wizard See the full GRC platform

Auto-filled from your BIA · subprocessors · international processing · AI tool use

The gap in most privacy policies

Buyers, regulators, and their lawyers now expect a privacy policy to say who else handles the data, where it crosses borders, and whether AI is in the mix. Few older policies do. Rewriting one is a legal project most teams keep putting off. The addendum closes the gap without the rewrite.

Two themes run through it

First, it uses data you already have. Lavawall reads the subprocessors, data flows, and AI use in your BIA records and drafts each section for you. Second, it is written in plain language, so the addendum reads like a statement to clients, not a contract only a lawyer can parse.

Subprocessors, named and explained

The addendum sets out the subprocessors who help handle personal information and what they do, drawn from your BIA vendors, so clients can see who is in the chain and why.

International processing, stated plainly

Where data is processed in another country, the addendum says so and points to your Foreign Processing Disclosure for the detail, keeping your public statement consistent with your internal records.

AI tool use, out in the open

If your organisation uses AI tools that touch personal information, the addendum describes that use in plain language, the transparency clients and regulators increasingly look for.

Why an addendum beats a rewrite

Current in an afternoon

Because it is auto-filled from your BIA records, you review and confirm instead of drafting from scratch, so your public statement catches up fast.

Consistent with your other documents

The same subprocessors and data flows feed your Foreign Processing Disclosure and data flow register, so your public and internal records tell one story.

Answers the questions buyers ask

Subprocessors, borders, and AI are standard items on security questionnaires. Putting them in your policy answers them before they are raised.

Reconcile before you publish

This addendum is a starting draft generated from your records. Before it goes public, it must be reconciled with your main privacy policy so the two documents do not contradict each other on retention, contact details, or the rights you offer. It is not legal advice.

Check it against your existing policy

Make sure the addendum's language on subprocessors, borders, and AI lines up with what your main policy already says, and resolve any conflicts before publishing.

Have your counsel review it

A privacy lawyer or advisor should confirm the wording fits your obligations and your jurisdiction. Lavawall gets you most of the way; your advisor finalises it.

Part of the wider GRC platform

Foreign Processing Disclosure

The outside-Canada notice the addendum's international section points to.

Learn more →

Data Flow Documentation

The subprocessor register that keeps the addendum's vendor list accurate.

Learn more →

Business Impact Assessment

The records that fill every section, captured once in plain language.

Learn more →

Common questions

What is a privacy policy addendum?
A public add-on to your existing privacy policy covering three things people increasingly ask about: the subprocessors who help handle their data, the international processing it may go through, and how your organisation uses AI tools. Lavawall drafts it from the vendors, data flows, and AI use in your Business Impact Assessment records.
Why do I need one on top of my privacy policy?
Most privacy policies were written before subprocessors, cross-border processing, and AI tools became routine questions. Rather than rewrite the whole policy, the addendum drops in the current detail, auto-filled from data you already have, so your public statement matches how you operate today.
Where does the content come from?
From your BIA records. Lavawall reads the subprocessors, data flows, and AI tool use you have already captured and drafts each section in plain language. You review and adjust rather than write from a blank page.
Can I publish it as is?
No. It is a starting draft. It must be reconciled with your main privacy policy so the two do not contradict each other, and your legal counsel should review it before you publish. Lavawall gets you most of the way; your advisor finalises it.

Start with the GRC Wizard →See the full GRC platform