Why Your Online Course Needs a Privacy Policy and More
Creating an online education platform? Legalities like Privacy Policy, Terms of Service, and a Disclaimer can help you avoid fines, reduce liability, and answer customer questions. Termageddon solves this for you.
Privacy Policy, Terms Of Service, And Disclaimer Requirements For Online Courses
Any course website that collects a name, an email address, or a payment needs a privacy policy, because privacy laws regulate what you collect, how you use it, and who you share it with. Most course sites also need a terms of service, and some need a disclaimer. In this training, two privacy attorneys from Termageddon walk through what each document does, which laws reach your business, and where to get policies that stay current.
What You’ll Learn
- What personally identifiable information is, and the four places a typical course website collects it without the owner noticing
- Which privacy laws reach your business based on where your students live rather than where you are located
- What a terms of service actually does for a course creator, from refund questions to protecting your course content as intellectual property
- When a course needs a disclaimer, covering health and fitness advice, affiliate links, and income claims
- The trade-offs between hiring a privacy attorney, using a policy generator, and copying a free template
Key Takeaways
- Treat a contact form, a newsletter signup, a survey, or a checkout as the trigger for a privacy policy. If your site has any of them, you are collecting personally identifiable information.
- Stop asking whether a law applies to your state. Privacy laws protect the residents of a state or country regardless of where your business sits, so your students’ locations decide your obligations.
- Build a plan to keep policies current instead of writing them once. Laws change, and a policy that was correct at launch can go stale within weeks.
- Keep your privacy policy and your terms of service on separate pages, because combining them makes consent ambiguous and courts have found the combination confusing to consumers.
- Collect the minimum information you actually need. Every extra field you ask for widens your exposure in a privacy complaint or a data breach.
- Publish a disclaimer if you give health, fitness, financial, or business advice, promote affiliate links, or show income results, and pair it with a no-warranty clause in your terms.
Frequently Asked Questions
Readership is not the point. A privacy policy is a legal requirement in many jurisdictions, so a missing one can expose you to fines or, where a private right of action exists, to a lawsuit. Consumer habits are also shifting. More visitors now glance at policies before handing over an email address, and some leave sites that do not have one.
No. The usual recommendation is one privacy policy that carries the disclosures required across every state where you have students. Per-state policies confuse visitors, especially anyone traveling, and they create heavy administrative work deciding who sees what. Within that single policy you can either break rights down by state or extend the same rights to everyone.
Two documents working together. Your terms of service should state that there is no warranty on the exercises, products, or services offered on the site. Alongside it, publish a health and fitness disclaimer telling students to stop if they feel unwell and to consult a doctor before starting, which is the same protection those old workout videos opened with.
It can, and that changes what you need. HIPAA protects patient health information and imposes strict obligations on healthcare providers. Termageddon does not cover HIPAA compliance, so anyone offering regulated health services should work with an attorney who specializes in it rather than relying on a general policy generator.
It turns on what you collect and whether your state licenses you to provide health services. Generic meal plans that are the same for everybody generally sit outside HIPAA. Asking students about diabetes, pre-existing conditions, medications, or psychiatric history pushes you toward regulated territory. Check the government resources for your profession, and ask a lawyer if you are unsure.
A privacy policy and a terms of service, almost always. Course sites collect information, register users, and usually take payment, and each of those is a clear indicator that both documents are needed. A disclaimer depends on your content. You need one if you give health, fitness, financial, or legal-sounding advice, or if you run affiliate links.
Avoid it. Multiple laws and court decisions have found the combination confusing for consumers, and it breaks consent, because you cannot tell whether someone agreed to the privacy policy or to the terms of service. Give each document its own page and link to both from your checkout and your signup forms.
State plainly that results are not guaranteed or typical, and note that a standout result is not representative. Back any claim with records you actually hold. Add a no-warranty clause to your terms, because a promise of a specific income can be read as a warranty. Disclose any testimonial you compensated, since an undisclosed paid endorsement is treated as misleading.
Full Webinar Transcript
Meet The Privacy Attorneys Behind Termageddon
Chris Badgett: Hello and welcome to another webinar training. I’m joined by Donata and Hans from Termageddon, which is over at termageddon.com, that’s t-e-r-m-a-g-e-d-d-o-n.com. Their policies for your websites automatically update whenever the law changes, and it’s written by real attorneys, not robots. I’m really excited to have Donata and Hans here today.
You know, for the LMS industry, for people building online courses and membership sites, the website is the business. It’s not just a marketing brochure for an offline business. So having everything above board and legal without breaking the bank is important, and it’s a question I get asked. I’ve been asked for probably five and a half years, since the beginning of LifterLMS, like how do I, where do I go to get the terms and conditions of my website? I’m not a lawyer, I don’t play one on the internet. And people want it without spending a lot of money on legal fees, and I’ve hired lawyers for work and they’re really expensive if they’re doing custom work for you. So I’m really excited to get into it with you. But first let me just say, Hans and Donata, welcome to this webinar.
Hans Skillrud: Thank you, thank you so much for having us.
Why Legal Compliance Feels Intimidating To Course Creators
Chris Badgett: I’m excited to get into it. Please ask questions, we are going to do a Q&A at the end after we get into this. So if you have any questions about making your terms and conditions, your privacy policy, keeping it at a level of legal compliance, just ask away. And I’m going to hand it over to Donata and Hans. Take us home. How can the course creators, the people building training based membership sites, people building online coaching and education businesses, level up their legal compliance?
Hans Skillrud: Absolutely, thank you for having us. I have to admit, anyone listening to this, any discussion about privacy policy and terms, I’m already impressed that you’re listening. And we will try to keep it as entertaining as possible.
What we’re trying to do today is kind of remove the barrier that I think everyone feels, which is like, this stuff is intimidating, therefore I’m not going to look at it and pretend it doesn’t exist. And what you’ll see shortly here is that that is unfortunately not going to be reality very soon here. Businesses of any size will need to not only have a privacy policy in place, most likely terms and conditions in place too, but they’re also going to need a strategy to keep it up to date when the laws change. And hopefully we can speak to that, why that exists, why that problem exists, and how Termageddon is a potential solution, as well as other potential solutions as well.
Why Online Learning Makes This Urgent
Donata Stroink-Skillrud: Yeah, absolutely. And I think now more than ever people are turning online to learn, whether it’s to learn something that will improve their business or something that will improve their life, or maybe just something that will relax them. I think right now online learning is really having a boom and people are searching for it. And so we’re hoping to make this webinar accessible and easier to understand for anybody who creates online courses of any kind, just how to protect yourself and how to protect your business and protect your course. So that’s really our hope with this.
What This Training Covers
Donata Stroink-Skillrud: So a couple things that we’re going to be talking about. We’ll talk about me, Hans, and I. What is collecting personally identifiable information. What courses need a privacy policy and why. What is the terms of service, what are its benefits, why do you need one. What is the disclaimer, what are the benefits of having a disclaimer, and where you can get policies so you can get all set up.
So we’re hoping for this to be like an all-encompassing class with hopefully a very minimal amount of legal jargon and confusing things. We’ll try to make this as easy to understand as possible, but if you do have any questions, let us know and we’d be happy to answer them throughout as well.
Donata’s Background In Privacy Law
Donata Stroink-Skillrud: So a little bit about me. My name is Donata and I’m the president of Termageddon. I’m an attorney, I’m licensed in Illinois. I’m also a certified information privacy professional. I’m the engineer behind all of the policy questions and text and the different variations in Termageddon. And so we create privacy policies, and I’m the one who has written all the questions, written all the text, and I also make sure that our policies are up to date with the law. So I spend a lot of my time tracking laws, which I’m sure everybody knows is very exciting.
Hans Skillrud: But it is actually exciting. You actually like it.
Donata Stroink-Skillrud: I actually love it so much, and I hate how much I love it.
I am the chair of the International Association of Privacy Professionals Chicago chapter. I am also the editor of the e-privacy committee newsletter of the American Bar Association. I’ve also held courses about the General Data Protection Regulation at the Illinois State Bar Association, and we’ll talk about GDPR a little bit later, but it’s European Union law that protects the personal information of EU residents. And so I really enjoyed my time at the ABA, at the IAPP and ISBA, just kind of teaching other lawyers and other professionals on what privacy is, why it’s important, and if they are writing privacy policies, what those policies should contain.
Hans’s Background Running A Web Agency
Hans Skillrud: I like how my background’s like a sentence larger. So my name is Hans, I’m the vice president of Termageddon. I handle sales and marketing for the company. Prior to Termageddon I ran a 12-person web agency for seven years in downtown Chicago, and almost a year to date I sold my agency, made the decision to go full-time Termageddon, which has been awesome. Donata and I are engaged, we’re gonna get married in October, and being able to work with my soon-to-be wife has been an amazing experience.
Donata Stroink-Skillrud: Congratulations.
Hans Skillrud: Yeah, thank you. I’m looking for a raise.
Donata Stroink-Skillrud: His salary is contingent upon the joy of working with me.
Hans Skillrud: But yeah, no, I handle sales and marketing, I do a lot of client communications, just helping them understand things. I’ll tell you what, a year ago I was so intimidated by privacy policies and terms and conditions, and I think like two weeks in I’m like, okay, this is really not that difficult. Just like anything else in life, you have to learn what’s going on, and then you just need to act on it. And that’s what I’m really proud of Termageddon, and I think we’ve done a pretty good job at demystifying what all these privacy laws are about and enabling people to protect their business, which we believe is extremely important for small business owners.
What Personally Identifiable Information Means
Donata Stroink-Skillrud: So maybe let’s get started with privacy policies, who needs them and why. We’re gonna try to keep definitions and terms to an absolute minimum, but I personally thought that this one was really important to understand, and it kind of builds the foundation of what we’re going to be talking about.
So personally identifiable information, or PII, is any data that could identify an individual. So for example somebody’s name, email, phone number, or physical address.
Where Your Course Website Collects Student Data
Donata Stroink-Skillrud: And any website that has a contact form is collecting PII. So if your online course has a contact form where people can contact you, you are collecting PII. If it has a place where people can sign up for newsletter updates, for your upcoming launches, and you ask for their name and email, that’s also collecting PII. Same thing with surveys, for example, that you’re creating for your courses, that could collect PII. And then also billing portals where people purchase your courses. And so all of those different areas are where your website or where your course collects PII.
For our first and most important takeaway from this webinar, any website that collects PII should have a privacy policy. So if your website has a contact form, a newsletter form, a billing portal, surveys, stuff like that, that should be your first kind of light bulb going off saying, I need to have a privacy policy.
Why The Collection Of Personal Data Matters
Donata Stroink-Skillrud: Now when I was a kid I would always ask why. I really wouldn’t do anything unless I understood why I had to do it. So for people like me, why does the collection of PII matter? Why does that light bulb need to be going off? Why should I have a privacy policy even though some of my competitors might not, or some of the other businesses that I know don’t have one?
So really you should have a privacy policy because privacy laws regulate the collection, use, and disclosure of PII. So privacy laws are laws that have been implemented to protect consumers or residents or citizens of a particular state or country, and privacy laws really require certain websites to disclose what PII you collect, what is done with that PII, and who that PII is shared with.
Now just to be clear, privacy laws require you to disclose a lot more than that, but this is really just the meat and potatoes of what a privacy policy should have. And the required disclosures are usually made in the privacy policy. So when a user goes onto your website and they’re giving you their personal information, they really need to know what you do with that information, who you share it with, and other disclosures, and usually they will go to a privacy policy to find that out.
How GDPR Reaches Course Creators Outside Europe
Donata Stroink-Skillrud: So we have certain laws that protect PII, and the ones that are kind of the main laws in the US and the EU are the General Data Protection Regulation, or GDPR. I know most people have probably heard of this one just because of the freakout that was going on in 2018. I don’t know if anybody remembers the thousands of emails that we got from every single vendor saying they’ve updated their privacy policy, but that’s kind of what that was for.
So a little bit about who the GDPR applies to. It applies to businesses that are located in the European Union, businesses that offer goods or services to European Union residents regardless of that business’s location, or businesses that monitor the behavior of European Union residents, again regardless of that business’s location. So if you are selling your course to people in Germany, to people in France, you need to make sure that you are GDPR compliant even though you yourself are physically located in the US.
The California Online Privacy Protection Act
Donata Stroink-Skillrud: In terms of what laws we have in the United States, we have the California Online Privacy Protection Act of 2003, which applies to websites that collect the PII of consumers located in California regardless of that business’s location. So if your course’s website could be accessed by somebody from California and they could submit their personal information on your site, you need to make sure that you’re CalOPPA compliant.
The California Consumer Privacy Act
Donata Stroink-Skillrud: Next we have the California Consumer Privacy Act, or the CCPA. That one went into effect January 1st, and it applies to any for-profit business that has annual revenues of 25 million annually, buys, receives, sells, or shares the PII of 50,000 or more California residents, or derives 50 percent or more of its annual revenue from selling the PII of California residents as well.
This one kind of has a large business exception. So if you’re a smaller business that doesn’t deal with a lot of data you might not need to worry about the CCPA, but if you are working with larger companies they could require you to be CCPA compliant by contract. So just make sure and see whether or not any of your contracts with your customers have changed or your vendors have changed, because they will say whether or not you need to comply with that by contract.
Nevada’s Revised Statute 603A
Donata Stroink-Skillrud: And then finally we have Nevada’s Revised Statute 603A, which applies to commercial websites that collect the personal information of Nevada residents and enter into a transaction with a Nevada consumer, has nexus with Nevada, or purposely directs its activities towards Nevada. Now that one’s a little bit more confusing as to who it applies to, but if you have any Nevada customers, that one definitely applies to you.
Why Privacy Laws Ignore Where Your Business Is Located
Donata Stroink-Skillrud: So I think one thing that a lot of these privacy laws have in common is that they protect the consumers of a particular state and not the businesses. So maybe Hans could speak a little bit about that.
Hans Skillrud: Yeah, so it is really important to remember, like fact number one which Donata showed earlier, if you are collecting personal information you should have a privacy policy, and you should also have a strategy to keep it up to date when the laws change. And we’ll speak to that shortly here.
But the second biggest thing to take away is privacy laws do not care about where your business is located. This is a common misconception we hear all the time. Oh, I’m not located in California, therefore I don’t need to comply with the CCPA. This is false. That is not the reason. Now CCPA does have some business limit restrictions, maybe you don’t have to comply with CCPA for a different reason, but you need to understand privacy laws do not care about where businesses are located. They’re only out to protect the citizens of that state or country.
It’s really important to remember that where your business is located does not matter at all. What matters is, are you offering your services and do you have customers in other areas outside of your state?
Privacy Laws Outside The United States And Europe
Donata Stroink-Skillrud: And for anybody who’s listening that is outside of the US or the EU, there’s also different privacy laws in Canada and Australia. So that’s something to keep in mind as well. And some of those might be a little bit more narrowly defined, but again, if you are doing business in those areas you need to be cognizant of the fact that you might need to have a privacy policy that has very specific disclosures.
Why States Keep Proposing Their Own Privacy Bills
Hans Skillrud: Just to reiterate point number one, if you’re collecting personal information you should have a privacy policy. Point number two, privacy laws do not care about where a business is located, they’re only out to protect the citizens of that state or country, or continent technically with the EU.
So what is happening in America is really really interesting. We do not have a federal law for privacy, and what we have are individual states proposing their own privacy laws. And we provide a list here. It is crazy how often this gets updated, to say the least. But we have individual states proposing their own privacy laws to protect their citizens.
The problem with this is that each of these bills are unique. New York for example is proposing a bill that will enable their citizens to sue businesses of any size located anywhere for having as little as a contact form without a privacy policy.
Why You Need A Strategy To Keep Policies Up To Date
Hans Skillrud: This is really important to know, and this is the third thing I want to share with everyone. You need to have a strategy to keep your policies up to date. You need to have either a privacy attorney in place, or use a company like Termageddon that monitors the privacy laws for you. You need to have a strategy to have someone somewhere monitoring these privacy laws for you so they can push the appropriate new disclosures that are required by these new laws. Otherwise you could face privacy related fines or lawsuits.
How Privacy Fines Are Counted Per Website Visitor
Hans Skillrud: And the fines currently in place range from twenty five hundred dollars to seventy five hundred dollars per infringement. That does not mean you get a seventy five hundred dollar fee if you screw up. That means you have a seventy five hundred dollar fee per website visitor that you’ve not obeyed the laws by. So that is really important.
Now what we discussed here in this visual, and if anyone does want to link to this, it’s in our blog and we can provide it to Chris to provide to everyone. We have columns here with what each and every section requires, and as you’ll see, privacy policy changes, the first column, shows that every single one of these laws once enacted will require updates to your privacy policy most likely.
Why Each Bill Demands Different Disclosures
Donata Stroink-Skillrud: In terms of privacy policy changes, I think what’s really interesting is that a lot of people might think that here’s a privacy law and it just requires you to disclose what information I collect, how I use it, and who I share it with. But everybody has to justify their existence, so our wonderful legislatures have come up with very very specific things that a privacy policy needs to include.
So for example, one of the things that California has to include is whether or not your website responds to do not track signals. Nevada is requiring websites to say whether or not they sell personal information and how users can opt out of that sale. So there’s very different requirements with each of these bills and they need to be read very carefully just to make sure that your privacy policy is compliant.
Business Size Limits In Proposed Privacy Bills
Donata Stroink-Skillrud: In terms of business size limits, some states have decided that the laws would apply to large businesses only. So for example annual revenue of 25 million or more.
What A Private Right Of Action Would Change
Donata Stroink-Skillrud: Consumers can sue. This would allow consumers to have a direct right to sue a business instead of going through a state’s attorney general. Most of the privacy laws right now are being enforced by state’s attorneys general and by the Federal Trade Commission. But if consumers can sue businesses directly, obviously we’ll see a big uptake in litigation, just like we’ve seen with the Americans with Disabilities Act and websites. I’m sure some people are aware of that. So once consumers can sue, that really increases the risk of litigation.
The Right To Access And Delete Your Data
Donata Stroink-Skillrud: The right to access data would basically mean that as a consumer I have a right to ask your company to show me what data you have on me, and you would have to show me all of the data that you have on me from all of the different sources where you keep that data.
Right to delete data, this one’s really popular. As a consumer I would have the ability to ask a business to delete my data, and there are exceptions to this, but in most instances a business would have to just delete that data.
The Right To Correct Data And Restrict Processing
Donata Stroink-Skillrud: Right to correct data. So if you have my name as Donut instead of Donata in your CRM, I would be able to ask you to correct that and to change it into the correct spelling.
Right to restrict processing. You can use my data for certain processes but not for others. So for example I could say you can use my data to process my order, but you can’t use my data for direct marketing. So all of a sudden you can’t send me email newsletters. And I think that that’s something that’s really important for course creators as well, because a lot of that marketing is done through emails of new courses, new launches, new content. So the right to restrict processing would kind of disable the ability to send emails or process data in other ways.
The Right To Opt Out Of Data Sales
Donata Stroink-Skillrud: Right to opt out. Every single bill has this right, and it’s the right to opt out of sales of data. So I’m not sure if anybody’s seen on some websites at the bottom you’ll see, please do not sell my information, and that basically means that that company is selling your information, and if you’re a California resident you have the right to tell them no. In other words, if you’re not a California resident you currently have no right to tell companies not to sell your data, which when you say it the reverse way it kind of, wow, you know, it’s interesting.
I can’t wait till that right comes to Illinois. I’m going to be exercising my rights everywhere.
Consent, Portability, And Automated Decision Making
Donata Stroink-Skillrud: This one’s really popular in Europe with GDPR. Basically you have to get the user’s consent to take their data in the first place. And unfortunately we don’t have that in the US, and none of the proposed bills have that, but maybe someday.
Right to portability means that as a consumer I would have the right to ask a business to take my data and give it to me in a machine readable format so I can transport it to your competitor. So for example if I’m using Facebook and I don’t really like it that much, I don’t like the privacy concerns that come with it, Facebook would have to give me all of my data and I could take it to another platform similar to that.
Against automated decision making. Automated decision making is making decisions by a computer or machine only, without any human intervention, that has legal consequences. Some of these laws allow consumers to stop that practice, so you’d have to have human intervention when making big decisions.
Fiduciary Duty And Protection From Discrimination
Donata Stroink-Skillrud: Imposes fiduciary duty. That basically means that the business would have to act in the best interest of the consumer and their data. This is kind of a remnant of financial law, and New York has that duty that they would impose if the law were to pass. And I think that’s pretty appropriate considering that they have spent so much time in finance there.
And then prohibits discrimination, which basically means that you can’t discriminate against somebody that has exercised their privacy rights. So if I ask you to access my data, you all of a sudden can’t charge me a hundred dollars more for that particular service just because I exercised my privacy rights.
Hans Skillrud: Or you can’t give them a different user experience as well on the website, right?
Donata Stroink-Skillrud: Yeah, exactly.
Why A Privacy Policy Is Never Write It And Forget It
Donata Stroink-Skillrud: So as more and more consumers are more interested in their privacy online, more and more bills get proposed and passed, and more and more restrictions go into businesses. So that’s something that’s very important to keep in mind, is that your privacy policy is not just a document where you can write it and then forget about it for the next 10 years. It’s really like a constantly updating thing.
Hans Skillrud: Now we spent a lot of time on this slide, but I think just to reiterate for anyone who kind of started to be like, oh this is so intimidating, this is reality. And I don’t mean it in a joking manner. This is what’s happening with privacy, this is what we see on the privacy side of things, and it’s super important for people with online courses especially to really take it all in, that each and every one of these states has their own set of rules to protect their own citizens. This can become a scalability issue if not addressed.
What Happens When You Ignore Privacy Laws
Donata Stroink-Skillrud: In terms of people saying, okay, that’s a lot and I’m just gonna ignore it, there are penalties that come with not complying with privacy laws. And those penalties can range from 2500 dollars per violation to 5000 per violation to 20 million euros in total. And per violation doesn’t mean per day, per month, per year. It means per website visitor whose privacy rights you infringed on. So for example, even if you have a hundred visitors from California to your website per month, that can really add up to a very very large sum.
Why Small Companies Do Get Fined
Donata Stroink-Skillrud: And I know that there’s a very common misconception in our industry that small companies are not getting fined, and unfortunately that’s just not true. Especially in the European Union for GDPR violations, we’ve seen fines being imposed on one-person marketing companies, on small grocery stores. And these fines can be large, and you don’t need to have millions of customers. We’ve seen fines where businesses have been fined for not respecting the privacy rights of one person. So it doesn’t have to be consistent violations of many different provisions or many different consumers, it can be just one.
I know of a one-person company, I think a one-person marketing company, that was fined 60,000 euro for changing the email address of one of their subscribers without consent.
Hans Skillrud: So let that sink in for a second. When I heard that I was like, oh my gosh, am I handling my subscriptions correctly? 60,000 euros. They’re really making statements, and Europe is about a year and a half ahead of America I would say, like maybe two years.
Why Enforcement Deadlines Do Not Get Postponed
Donata Stroink-Skillrud: What’s interesting too is that the CCPA will be enforced July 1st, and with the COVID-19 going on and all of that, a lot of industries are asking the California attorney general to postpone that enforcement until later in the year or maybe even next year. But the California attorney general has said no. They said that they’re still going to enforce that law starting July 1st, and they actually said potentially even earlier.
So just because bad things are happening out in the world right now does not mean that this is just going to be swept under the rug. And whether or not that’s the right decision, that’s up to the attorney general, but that’s something to keep in mind too.
The Business Benefits Of Getting Privacy Right
Hans Skillrud: So other reasons why you should consider having a privacy policy. More than 70 percent of organizations say they receive significant business benefits from privacy. I think you could expand on that better than I could, because this is the study you watched, right?
Donata Stroink-Skillrud: Yeah, so it was a study done by Cisco of a lot of different organizations in the US and around the world, and basically 70 percent of organizations said that they received significant business benefits from privacy, which would mean reduced breaches, reduced costs of breaches, and reduced customer complaints, things like that.
Whether A Privacy Policy Helps Your SEO
Hans Skillrud: Some other reasons outside of the fact that privacy is becoming a bigger and bigger discussion. A lot of people say that there’s an SEO benefit to having a privacy policy and terms and conditions in place. Google has trust being a ranking factor, and a lot of people believe having a privacy policy helps your SEO.
Standing On The Right Side Of History
Hans Skillrud: That’s another thing that I think is super important to remember, outside of the fact that there’s these concerns, I want to avoid fines and lawsuits, blah blah. The fact is, what we’re sharing here on this slide, concerns are growing. And rather than this looking as a reactionary thing to avoid fines and lawsuits, look at it also as a pro thing.
As a human being I don’t think it’s the worst thing that we as humans can tell companies, get rid of my data, and they have to. Don’t sell my data, and they have to. They have to listen to you. So I think there’s something profound about just standing on the right side of history too, like thinking, you know what, I’m going to be proactive about this and disclose to people this is what I do with your data.
Why You Are Sharing Data Without Realizing It
Hans Skillrud: Even if you’re not selling it, the fact is you’re most likely sharing it. So many companies I helped set up their policies for, saying well I don’t share my information with anyone, and I’m like, well, do you have an email newsletter subscription? Yeah. Okay, so you’re sharing that information with MailChimp or ActiveCampaign or whatever it may be. Do you have an e-commerce system? Yes. Okay, are you sharing your data with Stripe or PayPal? And it always is yes. So sharing data is something that happens more than I think most small businesses even realize.
How Privacy Concerns Change Consumer Behavior
Donata Stroink-Skillrud: So a different study found that privacy concerns are having a major impact on the behavior of consumers online. So that basically means that some consumers will not use certain platforms due to privacy concerns, they will just leave those platforms. So that’s something that any small business does not want happening to them, because each customer is really important, and you want to make sure that people are having a good experience, that they don’t leave or they don’t go to a competitor. So having a privacy policy will help curb that.
58 percent of US-based respondents are concerned about the privacy and security of their personal information. Now what that means is that 58 percent of the US population are pressing their congressmen, pressing their representatives to pass these privacy laws, and that’s really what’s driving all of these privacy laws as well, is consumer interest. And after the Cambridge Analytica scandal, consumer interest in their privacy and security went through the roof, and that’s why we have all of these privacy bills.
Why A Privacy Policy Answers The Question Buyers Are Asking
Donata Stroink-Skillrud: And 79 percent of Americans are very or somewhat concerned about how companies use the data that they collect. Now having a privacy policy is a wonderful way to answer that question, because it will literally say how you use the data that you collect.
So 79 percent of the consumers that visit your website, they might be concerned about that. They look at your privacy policy and here you go, it says how you use the data, who you share it with, and that alleviates a lot of that concern. It stops customer questions, it kind of moves them along the purchasing path.
How Privacy Concerns Slow Down Your Sales Cycle
Donata Stroink-Skillrud: And even though I didn’t put it on the slide, there was a study by Cisco that found that privacy concerns can slow down the sales cycle by an average of 7.8 weeks, which is a really really long time if you are in a small business environment. You don’t want to delay your sales by eight weeks, that’s crazy, just over something that’s having a privacy policy or having privacy information.
So that’s really our wrap up on the privacy policy side of things. We’re also going to talk about terms of service and disclaimers.
Why A Privacy Policy Matters Even If Nobody Reads It
Chris Badgett: The concern is about what is the importance of a privacy policy page if most people don’t look at it?
Hans Skillrud: So I’ll be the first to admit, I don’t read every single terms and conditions that I agree to when I go and update my app. Now that being said, I have noticed myself more so looking at privacy policies, at least glancing. Glancing is infinitely more than not looking at them, which is what I used to do. Now I kind of like, all right, what do I got, let me just take a quick look and see what they’re doing here.
And actually I can confirm that there is a business that I did not do business with because they had the do not sell my information page, and I saw that at the bottom of their site, and then I looked further into it and it’s like, oh my gosh, if I submitted my information here they’re going to sell my information to a bunch of people and I was about to get like 25 phone calls.
So I think you’re right, I’m not going to ignore the fact that there’s many many people that just don’t read it. But the fact is, let’s just say that trend continues, which I disagree with, I don’t think it will continue, but let’s just say theoretically it does. It doesn’t stop people from the private right of action, the ability to sue businesses for not having a privacy policy. It does not stop governments from pushing fines. The fact is if complaints come in you will get pursued, and that’s what really needs to be taken into consideration as well.
Donata Stroink-Skillrud: I think maybe two or three years ago nobody did read the privacy policies and nobody looked at them, but I think now that is really changing. And one thing that I’ve seen myself that I’ve been pretty surprised about is all of these studies that say that consumers are interested and that they are reading them. Because honestly I thought it was just me with a tinfoil hat sitting in my basement reading all of these, but turns out that that’s just not the case anymore. More and more consumers are reading them, more consumers are leaving sites that don’t have a privacy policy on them.
Why Privacy Policies Are Following The Same Path As SSL Certificates
Donata Stroink-Skillrud: And I think maybe a good analogy here would be the SSL certificate.
Hans Skillrud: That’s a great call. So back when I was running my agency, maybe it was like five years ago, where having an SSL certificate to secure your website, I’m like okay yeah, you need that for e-commerce websites and that’s about it. It’s kind of nice to have beyond that, but who cares. Well that changed. So SSL certificates kind of became a big deal.
And I think that’s such a good analogy, because nowadays we look at websites that are not secure and we’re like, I don’t feel safe on this website. There’s like an inner, oh my, this is unsafe, why am I even on this website. And I would say I really would strongly suggest taking that into consideration when considering the fact that privacy is becoming more important, not less important over time.
In the past I’m the first to admit, yeah I ignored it, and I would say that nowadays I’m kind of in the middle, I will look at them a little bit more closely. In the future I think it’s all about asking what’s going to happen in the future, and I think without a doubt it’s going to become a bigger and bigger and bigger deal based on trends, based on everything that’s happening. But even if it isn’t, it doesn’t mean that there aren’t laws saying you have to have it and you could be fined or sued. So I think those are two really good things to consider.
Donata Stroink-Skillrud: I wonder if one day it’s going to be something similar to the SSL certificate on Google, where it says this website is unsafe. Maybe it’ll be, this website does not provide you privacy protections or something like that.
Hans Skillrud: And then you’re gonna have to go into advanced settings. Or Google just admitting, hey, we rank this for SEO as an incentive to push it. I mean I could see that happening first, and then I could just say it’s required by law. I could totally see that.
Which Countries A Policy Generator Can Cover
Chris Badgett: Does your service Termageddon provide policies compatible with all US states and with the European Union?
Hans Skillrud: Yes, we are compatible with all US businesses, meaning that we ask questions like what state were you formed in, what county do you want to resolve disputes in. We provide compliance like GDPR with the European Union, but compatibility, we are only compatible with US businesses right now. That being said, over the coming weeks, because of our growth, we’ve decided to expand into Canada compatibility, UK compatibility, and Australia compatibility. So over the following weeks we’ll be launching our services to allow businesses located in those countries to also sign up with Termageddon. But we already provide the compliance for GDPR and stuff.
Terms Of Service, Terms Of Use, And Terms And Conditions
Hans Skillrud: All right, terms of service. Just real quick, this blew my mind. Terms of service, terms of use, terms and conditions, they all mean the same thing. Okay, that’s what I wanted to share.
Donata Stroink-Skillrud: Now that we’ve had that valuable insight.
What A Terms Of Service Actually Is
Donata Stroink-Skillrud: So most websites will have terms of service on there, but a lot of people don’t actually know what it is. So terms of service, terms of use, terms and conditions, TOS, it’s an agreement between the operator of a website and the visitor or user of that website that spells out the rules of using that website.
So if you were to come to my house and I tell you please take your shoes off, that would be a terms of service for my home. It’s kind of similar with your website.
So there are some benefits to having a terms of service, and a terms of service really does a lot of different things, and it’s kind of a catch-all to all of the rules that come with visiting your website.
Answering Refund And Cancellation Questions Up Front
Donata Stroink-Skillrud: First, in the terms of service you could answer frequently asked customer questions. So for example, what is your refund policy, and whether a user can cancel their purchase.
So if I’m running an online course and I have some downloadable guides, let’s say one of the users downloaded those guides and they’re unable to view them on their computer due to software error or something like that. As a user, can I get a refund for that? The terms of service will explain that. It will also say when you can get a refund, so like incompatible, didn’t like it, decided I didn’t want it, only with a receipt, things like that.
And also if a user can cancel their purchase. So if they’ve bought your course, never accessed it, and then decided to change their mind, can they cancel their purchase, would they get their money back, things like that.
Spelling Out The Warranty On Your Courses
Donata Stroink-Skillrud: They can also spell out the warranty that you offer on your courses. This can help reduce disputes and mitigate damages.
So for example, if you are teaching a course on Facebook marketing and the user uses your Facebook course for marketing and gets really bad results, or gets flagged by Facebook because they wrote something in that they weren’t supposed to write in, or they’re advertising products or services that are banned off of Facebook, you can spell out the warranty that you offer. So you could say, this is really up to you to decide what the best course of action is for your business, what I’m telling you in my course might not work for everybody.
So that’s something to keep in mind too, is that the lesser the warranty you have, the less likely it is that you’re going to be liable for damages. And obviously none of us want that. So your terms of service can make sure that you are protected.
Protecting Your Course Content As Intellectual Property
Donata Stroink-Skillrud: You can also protect your intellectual property by saying that all courses and course materials on your website belong to you. I’m sure this has happened to a lot of people on this course, but many people will take worksheets and ebooks and content and full-on courses and completely copy them and say that they created them when in reality they didn’t.
If somebody steals all your stuff, it’s a great way to point back and say, look, in my terms of service I said that all of this belongs to me. Or if you’re selling worksheets or something like that, you obviously don’t want people to copy them and give them to their friends, because then they won’t buy the course from you, they’ll just take this copyrighted thing and use it instead of purchasing your course, purchasing the worksheets.
So really the terms of service will say, you can’t copy the materials given to you, you can’t resell them, stuff like that, and everything that’s on this website including the course, including the worksheets, including everything else, is our intellectual property, you can’t take it.
Avoiding Copyright Suits With A DMCA Safe Harbor
Donata Stroink-Skillrud: Terms of service can help also avoid copyright infringement suits by helping place you in a Digital Millennium Copyright Act safe harbor. So the DMCA has a way to create a safe harbor for people who upload stuff onto their website, maybe not necessarily knowing that that item is copyrighted. It basically provides users with your email and address and a phone number where they can contact you to ask you to take the stuff down instead of going to sue you automatically.
So that’s something that’s really helpful too, especially if you’re uploading graphics or pictures or content. You make sure that you avoid copyright infringement suits by providing your information in there in the right format, which could help provide you with a safe harbor.
Choosing Where You Resolve Disputes
Donata Stroink-Skillrud: So it can choose where you would like to resolve disputes. Let’s say I’m located in Chicago, I’m in the suburbs, and I sell my services all over the world, and somebody from California purchases my service, doesn’t like it, and I get into trouble with that and they sue me. My terms of service can say that I would like to resolve all disputes in Illinois, because that’s obviously going to be a lot cheaper for me than flying myself out, and my evidence and everything else, into California. So you can really choose where you would like to resolve disputes, which would save you time and money.
Limiting The Damages You Are Responsible For
Donata Stroink-Skillrud: It can lessen the amount of damages that you may be responsible for in case something goes wrong. So this is a bunch of lawyer boilerplate that we always add, but for example, let’s say you’re selling a course for embroidering, and they end up injuring themselves while embroidering. You can lessen the amount of damages to the actual cost of the embroidering course instead of the entire damages of them going to the hospital, which obviously can save thousands and thousands of dollars.
Protecting Yourself When You Link To Other Websites
Donata Stroink-Skillrud: Protecting yourself in case of third-party websites having viruses. So I know a lot of websites will link to Facebook, Twitter, different blogs, stuff like that. If that website has a virus and somebody went from your website to that website and got a virus, you could potentially be held liable for that, and a terms of service will help protect you.
Keeping Your Course Community A Welcoming Place
Donata Stroink-Skillrud: And then lastly, keep your website a welcoming place for everybody. So I know a lot of courses will have comment sections, or will have roundtable discussions where people can share ideas and share their successes or their failures. And anybody who’s ever been on the internet knows there’s some jerks on here, and having a terms of service can help you kick those jerks out, delete their comments, stuff like that. So you can keep your website a wholesome and good place where everybody can have a good experience, and terminate accounts, delete comments, stuff like that, of people who are not abiding by that.
Whether To Write One Policy Or One Per State
Chris Badgett: If I offer services for all US states, then do I need to generate different content for the policies and terms depending upon the location of the user, or do you provide one content template compatible with all regulations in all states?
Donata Stroink-Skillrud: So you would have one that’s compatible with all regulations in all states. There have been some companies that will have a different privacy policy for let’s say California residents only, but that can be really confusing to users, especially if they’re traveling. Let’s say I’m a California resident but I’m in New York right now, that can be really confusing for people. So usually what’s been recommended is to have one that kind of has all the relevant things for every resident of every state that has a law.
Now the rights that consumers get on your website would be broken down by different states, because different states have different rights, or you can choose to give those rights to everybody. So that’s something that we have chosen to do at Termageddon, is we give GDPR rights to every visitor regardless of where they’re located. But regardless of the ethics of all of that, you can choose whether or not you want to provide the rights to that state’s resident or to everybody. But usually you’d have one privacy policy for everyone.
Why One Policy Scales Better Than Fifty
Hans Skillrud: And just to add my two cents here, it’s a great question, it’s something I actually asked Donata a year ago. Should we have a different policy for each and every citizen of each and every state? And she provided her feedback as to why that probably is not ideal. And we’re certainly monitoring it, seeing if that’s ever done the other way, but I’ve really come over to the side of having one policy because of the scalability issue.
The fact is if you have different citizens that you’re giving different rights to, you’re going to have a lot of back end work of who gets what. Whereas through the Termageddon questionnaire for example, we say, do you want to extend these rights to all of your users? And at first you’re like, oh I don’t know if I want to do that, but all of a sudden it makes a lot of sense, because if you just have it one simple way, now you as a business owner have way less of, who’s this person, where’s this person from, what rights do they have. You try to standardize as much as possible.
Donata Stroink-Skillrud: Also if we were to have a different privacy policy for each state, you would end up with like 50 of them, which would be really confusing and very cluttered and very hard to find. So we definitely recommend having one if you can.
What Health And Fitness Courses Need In Their Terms
Chris Badgett: We have people in the health and fitness niche. So if let’s say there’s a yoga course or a dancing course, and somebody breaks their leg or has a knee injury and they want to go after the website owner who was teaching dance or yoga online, what type of thing could they have in their terms and conditions for that sort of medical related thing?
Donata Stroink-Skillrud: So it’s two different things that you would have if selling health coaching or a workout. So first you would have a terms of service that says that there’s no warranty on any of the exercises or any of the products or services listed on the site. But then you would also have a disclaimer, and we’ll talk about that next.
So if you’ve ever seen those workout videos from the 90s, at the very start it comes in and it’s like, do not continue if you feel like you’re gonna die. So you would have a specific health or fitness products or services disclaimer on your website, which would help protect you in that sense.
Whether HIPAA Applies To Counseling Services
Chris Badgett: Does Termageddon support also mental health related services like psychological counseling?
Donata Stroink-Skillrud: So it really depends on whether or not HIPAA would apply to you at that point. So if HIPAA does apply to the services, then we don’t cover HIPAA.
What HIPAA Protects
Chris Badgett: Can you explain what HIPAA is?
Donata Stroink-Skillrud: Yeah, so HIPAA is a law that protects the health information of patients. And so for example, if I go to the emergency room right now because I broke my foot, all of the information that they collect about me, like my name, my health history, my prescriptions, my x-rays, what treatment they gave me, would be protected by HIPAA. Which is basically a very stringent law in the United States that protects the health information of patients, which makes sense because patient information is a lot more sensitive. It’s a lot more sensitive to know that somebody’s gotten counseling for depression than it is that they bought juice the other day.
So if HIPAA applies to you, if you are a medical provider, if you’re a psychiatrist, it might also even apply to psychologists and their services, you need very specialized compliance, and at that point we would recommend that you go to an attorney. Because we’re a generator, we try to keep costs low for most of our clients, so we don’t undertake certain industries, for example HIPAA compliance, or websites that collect information from children under the age of 13. And that just helps us keep costs reasonable. But if you are providing those types of services that are covered under HIPAA, you would need to speak to an attorney about that, because it’s a very highly regulated field.
Where A Health Coach Ends And A Provider Begins
Chris Badgett: Since we’re on the topic, could you just expand a little bit more, because we do get this question a lot. If somebody’s a health coach versus a doctor or whatever, so like health coach, maybe some videos that you follow along with, maybe a meal plan, maybe some workout plans. If I have a website that’s like Chris’s six weeks to six pack abs or whatever, at what line do we cross the HIPAA? What’s the difference between a health coach and a doctor? I just see people get hung up on this a lot, especially if they’re trying to help people with health related issues. Like when do they cross the line, or where should they go to find out if HIPAA is in play or not?
Donata Stroink-Skillrud: So there’s a lot of different government websites that will talk about HIPAA, so you can just search that on Google. But it really applies to health services providers. So I would say that if you have a very generic meal plan that’s the same for everybody, like let’s say I want to lose weight I get meal plan A, let’s say I want to gain muscles I get meal plan B, you’re probably fine. But if you’re asking people their health backgrounds, like do you have diabetes, pre-existing conditions, stuff like that can really kind of push you into that realm.
If you are providing health services like acupuncture or something like that, the information that you collect might be under HIPAA. Chiropractor, same thing. But if you’re just running a yoga class where Jane Doe at Jane Doe gmail.com signs up and gets the class and you don’t ask her for any other information, then you’re probably fine. But it really depends on whether or not you’re licensed by your state to provide those health services, stuff like that.
And I know the government has a lot of resources on this, so I’d really just search Google, what the profession is that you’re in, and then just ask whether or not HIPAA applies to you, because the government does have resources on that. But you should be really careful anytime you’re collecting very sensitive information, like what is your psychiatric history, what medication do you take. Asking somebody about an allergy to a food is different than saying, have you had depression in the past, if that makes sense.
Whether HIPAA Applies Outside The United States
Chris Badgett: Does HIPAA only apply to businesses that are located in the United States?
Donata Stroink-Skillrud: Hmm, that’s a good one. I think so, yes. Or to businesses that treat American patients maybe. I’m not an expert on HIPAA I have to say, but I do think it would be at least healthcare providers that are located in the US, and then possibly healthcare providers that are collecting the information of US patients.
Hans Skillrud: Yeah, that would be where the biggest indicator would be, are you collecting. I think it’s US only, but I wouldn’t be surprised to hear that other countries have their own versions of HIPAA.
Donata Stroink-Skillrud: I would definitely say that that is most likely the case, especially in first world countries. I know under GDPR collecting health information is considered sensitive information, which brings in a lot more different considerations and requirements to keep in mind.
Hans Skillrud: Yeah, it’s all about what are you collecting. And if you’re collecting questions like, do you have diabetes, have you suffered from a stroke, these are questions that are health related, that are red flags. I think asking for a name and a credit card is not.
Collect The Minimum Information You Actually Need
Donata Stroink-Skillrud: I would also throw in a little tidbit here, a tip for anybody. Make sure that you collect the minimum amount of information that you actually need. So I was on a website the other day that was asking me for my birth date to sign up for a newsletter. I’m like, no, that’s not happening. So if you don’t need certain information, don’t collect it just to have it. I think that really opens people up to privacy violations and to data breaches too.
When A Doctor’s Website Does Not Need HIPAA Compliance
Chris Badgett: Adding to the conversation, from research, HIPAA applies to psychotherapy and psychological counseling but not to coaching.
Hans Skillrud: Yeah, we’ve had some conversations with some HIPAA experts, and they confirmed that even if you have a doctor’s website but you don’t have patient intake forms, you just have a generic contact form with Google Analytics, you do not need HIPAA compliance for your website. Now that doctor needs to be HIPAA compliant obviously with the doctor’s practice. Beyond that, it’s fine.
Donata Stroink-Skillrud: But if you’re doing anything like that, I would definitely first talk to a lawyer that specializes in that area just to be safe. There’s nothing wrong with getting a second opinion, whether it’s health care or law. So I would definitely say if you are in that area, talk to a lawyer even for just 10 minutes and just make sure that you’re getting what you need.
How A Lawyer Can Override Generated Policy Sections
Hans Skillrud: One of the features we have at Termageddon is we’re very lawyer friendly. I think that’s why we have so many law firms using our platform, because we have an override feature where your lawyer can review the policies and then even edit sections if they may so choose. And what’s cool about it is those sections will remain intact, whatever you overrode remains untouched. But when new laws go into effect that maybe require an update to that section, we notify you via email and in your dashboard saying, hey, a new law has passed, we think you have an overridden section that’s now allowing us to push an update, do you want to review what the new suggested copy says, giving you the ability to change it out and so forth.
What A Disclaimer Does
Donata Stroink-Skillrud: So let’s talk about disclaimers, and who needs them and why. So a disclaimer is a statement that makes certain disclosures and helps reduce your liability. So like I said earlier, those 90s exercise videos that say, if you’re short of breath, if you’re about to die, stop exercising, that’s a disclaimer. And there are a variety of different disclaimers that apply to different situations.
When You Need A Disclaimer For Third-Party Products
Donata Stroink-Skillrud: So when does somebody need a disclaimer? You should always have a disclaimer if you advertise third-party products or services. A disclaimer in that sense would say that you’re not necessarily endorsing those products or services, you have no control over those products or services, and you don’t operate the website that shows that product or service.
So if somebody clicks on an ad on your website, you’re not liable for anything that happens. You’re not liable for that product or that service, you’re not the one making sure that it’s okay for the consumer to use, or that it doesn’t cause injury or something like that. It’s just an ad.
Disclaimers For Health Products You Sell Or Display
Donata Stroink-Skillrud: Sell or display health products. That one’s very popular when it comes to things like vitamins or supplements or nutritional shakes and stuff like that. That disclaimer would say something along the lines of, make sure you speak to your doctor before you take any of these products, they’re not intended to diagnose, treat, or cure any particular disease.
We see those on vitamin bottles all the time, but if a consumer is shopping online they might not necessarily see the back of that label just by the way that pictures are created, or they might not be able to read it because it’s too far away or something like that. So a disclaimer will make sure to take care of that.
Disclosing Affiliate Links And Paid Promotions
Donata Stroink-Skillrud: Whenever you participate in an affiliate program. So if you are participating in Amazon Affiliates, let’s say you have a yoga course and people can purchase a yoga mat through your website by going to Amazon and it’s an affiliate link and you get a cut of that purchase, you need to make sure that you disclose that on your website.
And that’s something that the Federal Trade Commission is cracking down on pretty frequently, because consumers should know whether or not you’re getting paid to promote a particular product. Also most affiliate programs that you’ll end up participating in have this in their terms of service and require you to have a disclaimer.
Disclaimers For Health And Fitness Advice
Donata Stroink-Skillrud: Provide health and fitness advice, that one we already spoke to. If you don’t feel good, don’t continue this fitness program. That one’s definitely very important, especially with people that have pre-existing conditions and stuff like that. If they do certain exercises they might get worse, and you want to make sure that you’re not liable for that. Just because it’s the internet, you don’t know exactly who you’re providing this advice to, and it just might not be the best advice for their situation.
Disclaimers For Advice That Could Look Like Legal Advice
Donata Stroink-Skillrud: And then lastly, provide information that could be seen as legal advice. So if you have a business coaching course, if you are giving advice on stocks, if you are giving advice on purchasing a car or even negotiating contracts, you want to make sure that people know that this is not necessarily legal advice. Just because advice on websites is very general, it might be correct for 99 percent of people, but there’s always going to be that one person that it doesn’t really work for, and you just want to make sure that you don’t get in trouble with that one person.
Where To Get Your Policies
Hans Skillrud: So we discussed the three really important, very popular sets of policies that are used on websites. Well now the question is, where do I get one? There’s really two main ways to do it that I think are worth suggesting, which would be attorneys or generators.
Why Free Templates Are A Mistake
Hans Skillrud: You’ll notice there’s a third one, templates, which we did not include. We don’t suggest using a template, and if you haven’t drawn the conclusions, it’s why, I’ll just share them.
Templates do not auto update when the laws change. With those free templates online you don’t even know what you’re getting. I would say if anything it’s hurting you more than it’s helping you, because it makes you think, oh, I have my solution now, I don’t have to look at the law anymore, which I think is a very big mistake.
As I shared those three things around the privacy policies. If you’re collecting personal information you need a privacy policy. Privacy laws do not care about where your business is located. And you need to have a strategy to keep it up to date. Attorneys and generators are the way to do that.
What To Ask A Privacy Attorney Before You Hire One
Hans Skillrud: Hiring a privacy attorney, nothing beats it, that’s the best way to do it. And I want to be clear, I’m saying a specialized attorney, not just a general business attorney, an actual privacy attorney.
And if you have an attorney in place, I would suggest asking them, hey, are you comfortable not only providing me a privacy policy, but also what is your strategy to keep it up to date when a new privacy law has gone into effect? And hopefully after watching this presentation today you have enough ammunition to know that, are they monitoring all those privacy laws, can they speak to those privacy laws.
Really make sure you hire a good privacy attorney, not just a general attorney. And I say this very seriously, we have so many law firms using our platform, and I’ve reached out to some of them being like, hey, you’re an attorney, why did you sign up with us? And they’re like, I know this stuff is important but I don’t want to deal with the privacy law stuff. I’ve had that happen so many times.
So again, make sure it’s a privacy attorney that you work with, make sure you establish a strategy to keep it up to date whenever the laws change. Now the fact is, not everyone has ten grand a year to do that. It’s an expensive endeavor working with privacy attorneys.
What A Policy Generator Is And How It Differs From A Template
Hans Skillrud: And the second option would be generators. So the pros, generators, you can typically generate a set of policies very quickly. And the other pro is you can do it at a fraction of the cost of hiring an attorney. Termageddon is a generator.
Donata Stroink-Skillrud: Maybe if we can just kind of backtrack just a tiny bit and talk about what a generator is, because some people might not know.
Hans Skillrud: Yeah.
Donata Stroink-Skillrud: So a generator is basically a software where you go in and you answer some questions about your business and your website. So for example you would answer, what information do you collect, how do you use that information, who do you share it with. And then your answers are used to create a customized privacy policy that fits exactly what your business and your website does.
So that’s really a generator, versus a template, which is a document that’s already written with no input from you, that is not specific to what your website or your business does.
Hans Skillrud: Right, so that’s a great call. I’m so used to generators, I just kind of skipped through it. Great point.
How An Embed Code Keeps Your Policies Current
Hans Skillrud: And what’s cool about our generator with Termageddon is that you answer all the questions to generate the custom policy for your website, but at the end you click submit, and in addition to getting your policies you get a piece of embed code. And that’s what you copy and paste into the body of your privacy policy page, for example. And that embed code, whenever someone visits that website, the embed code fires and boom, there’s your policy.
What’s cool about it, because it’s an embed code, we at Termageddon can control what that copy says, and that’s what allows us to monitor privacy laws and then push updates to your policies automatically when these new laws go into effect. That’s why I like our program, that’s why we built our program. Our job is to monitor privacy laws for you so you don’t have to. That is our vision behind why we think a generator is a phenomenal move for people who can’t pay privacy attorneys tens of thousands of dollars every year to keep their policies up to date.
Which Policies Every Course Website Needs
Chris Badgett: Should all websites, especially in this niche, really have at least the three that we discussed today? Should all websites have a privacy policy, a separate terms and conditions, then a separate disclaimer? Is that almost the case for all of them?
Hans Skillrud: The first two for sure, privacy policy and terms and conditions. You guys are in the act of collecting money.
Donata Stroink-Skillrud: Yeah, you fundamentally have to. Users are registering on the site.
Hans Skillrud: Yes, exactly, the users are registering, they’re using your platform. I guess you’re right, I made an assumption that people are charging for that service, but they aren’t necessarily. They’re going through coursework, but information is being collected, there’s a login portal usually. Those are complete indicators that a privacy policy and terms and conditions need to be established.
A disclaimer, maybe, it depends. Are you providing information that could be seen as health advice, are you providing affiliate links, are you providing information that can be seen as legal advice? The disclaimers are more optional. So pretty much everyone should have a privacy policy and a terms of service, but not everyone might need a disclaimer.
Why Your Privacy Policy And Terms Need Separate Pages
Donata Stroink-Skillrud: And I think one question that I get all of the time is people that want to combine their privacy policy and terms of service into one page. I feel like I see this at least a few times a week, and that’s really not a good idea, because multiple laws and multiple courts have found that when you combine a privacy policy and a terms of service into one page it’s really confusing for the consumer as to what exactly is happening.
And then you actually can’t get consent when both of those are on the same page, because you don’t know if the customer is consenting to the privacy policy or if they’re consenting to the terms of service. So I would definitely recommend that everybody has a separate page for the privacy policy and a separate page for the terms of service.
Making Income Claims Without Creating A Warranty
Chris Badgett: We talked about health and fitness. Another big industry in this community or niche is business, and sometimes that often involves something that’s going to help you make more money. If we even use our own software like LifterLMS as an example, people make money with it. But can you tell us what area we should be thinking about when it comes to income claims, or showing testimonials of people that made money, or making statements about making money, or specific amounts of money that have happened in the past, or what we think you might be able to achieve?
Donata Stroink-Skillrud: Yeah, I think the Federal Trade Commission has really good guidelines, misleading claims for example. So one thing that I would definitely make sure that I do is number one, say results are not guaranteed or typical. Or if you’re highlighting somebody who did really well, like yeah, this person made a million dollars, but that’s not typical. Or you can also say, you might not get the same results as this first person.
I’d also have a terms of service that has a warranty on it that says we do not warrant anything. So if I say that you will make a million dollars from this course, that could be potentially seen by a consumer as a warranty, like I will make a million dollars, and when I don’t make a million dollars you have breached that warranty and I can sue you. So a terms of service that says there is no warranty on the products or services sold on this website is definitely a good place to start as well, just to make sure that people understand that this is not a warranty, this is just an example.
Disclosing Paid Testimonials And Endorsements
Hans Skillrud: And also it’s not an excuse now to say you’re going to make a bazillion dollars if you use my course. It doesn’t give you the right to just start spamming people and misleading people. You gotta have a good head on your shoulders too. And if somebody, their testimonial, like if I’ll give you 10 bucks if you leave a testimonial, make sure you disclose that as well. That’s something that can be seen as misleading to a lot of consumers if you’re not disclosing that that person was paid for their testimonial.
Donata Stroink-Skillrud: So that’s a paid endorsement or something, right? Yeah.
And if you are providing business coaching on how to make money, also make sure to have a disclaimer that says that this stuff is not legal advice. So for example if I say, take a second mortgage on your home and invest it into a timeshare business, maybe that could be seen as legal advice by some consumers, like oh, it’s okay for me to take out a second mortgage and use it for this purpose, even though it might not be. So just make sure you have a disclaimer that says that this is not legal advice.
Backing Up Your Income Claims With Real Records
Donata Stroink-Skillrud: And then lastly I would say, from what I’ve gleaned from Federal Trade Commission guidelines, and by the way I’ve got to throw praise out to them because they have one of the best websites and blogs I’ve ever read. It’s actually super funny, they have awesome jokes. The Federal Trade Commission is where it’s at for this kind of application.
But one of the things that I would say I have gleaned from their expertise and their advice is, make sure that you’re honest with your subscribers, make sure that you’re honest with the people that are interested in purchasing your course or are purchasing your course. If you’ve never seen a single one of your students make a million dollars, don’t make those claims. But if you see ninety percent of your students make ten thousand dollars, that’s a valid claim, but you have to make sure that you can back this up.
So if you’ve never had any person ever tell you how much money they’ve made, and all of a sudden now everybody can make fifty thousand dollars, that’s not a claim that you can back up. So make sure that you keep those records of people that have told you that they’ve made this much money, and make sure that you have a valid basis for making those claims.
Why Chris Recommends A Generator Over Custom Legal Fees
Chris Badgett: Super solid, thank you for that advice. At some point every WordPress LMS website builder needs to put a quality terms and conditions and privacy policy page on their website, ideally before they launch, as part of their go live process. It’s a mission critical piece.
And I love what you all have done in terms of using a generator. I’ve paid those big legal fees for these custom privacy policy handwritten deals and it’s super expensive. So when I heard about what you all have going on here, and how it’s customized and it’s automatically updating in real time. Anytime I call my lawyer, boom, there goes 500 bucks just for a quick question or whatever. It’s expensive.
So I’m really excited with what you all have built to help people level up as course creators, as membership site builders, as coaches, as professionals, in whatever it is that you do that are watching this, on the legal standpoint, because it’s not something you can ignore.
Why Termageddon Was Built
Donata Stroink-Skillrud: I appreciate that Chris. That’s one of the reasons why we started Termageddon, is I used to write these policies for my clients as a lawyer, and I would charge a lot of money for it, and it was actually really monotonous. And I noticed that I was asking a lot of my clients the same questions, I was writing similar language, and I kind of don’t feel okay charging this much money for it, because I feel like I can reuse a lot of my work. And it was getting kind of monotonous. So that was my reasoning behind Termageddon, is those crazy legal fees don’t need to be like that.
Hans Skillrud: And it was crazy because we created Termageddon before GDPR even was enacted.
Donata Stroink-Skillrud: Yeah, we just, we would have never guessed.
Hans Skillrud: Now we have 12 states with proposed bills, the number’s growing. It’s a nightmare. So I think we’re in the right place at the right time. The fact that we can help small business owners get up to speed with privacy laws and stay up to speed, I cannot emphasize that enough, staying up to speed.
How Quickly A Privacy Policy Goes Out Of Date
Hans Skillrud: Because if you have a privacy policy that you paid two grand for an attorney, and you got your privacy policy, well, did you get it in the last 45 days? Because if you didn’t, 45 days ago the UK left the EU. Have you updated for that? 65 days ago the CCPA went into effect, has it been updated since then? Six months ago Nevada’s update went into effect.
So how old is your privacy policy? Because it could have gone extinct the very next day from keeping you protected. So what’s the point of having it if it doesn’t work?
Why The Default WordPress Privacy Policy Is Not Enough
Hans Skillrud: And that brings me into one thing I did want to note real quick. On the generators page we were talking about generators versus templates, I think Donata did a really good job explaining the difference, but I get this question a lot. Why don’t I just use WordPress’s default privacy policy?
I think it’s a very fair question. I mean it’s right there in WordPress, why don’t I just use this? Let me be super clear on this. You can go to Slack and speak with the privacy group on Slack, the people who built that portion of WordPress, and ask them, hey, is this compliant with the law? They’ll be the first ones to tell you it’s not. They built the privacy policy page to create awareness of the importance of privacy policies, and the creators will be the first ones to tell you, no, you should absolutely have a strategy to keep it up to date over time.
Closing Thoughts
Chris Badgett: Donata and Hans are from Termageddon. Go check that out. I just want to thank you all for coming. This is a great service to this community and I’m excited to turn it into an evergreen resource for the hundreds of times I get asked about this, and I’ll be able to be like, just go watch this. So thank you, thank you very much for coming, and keep doing what you all do. Thanks everybody for coming, and I hope everybody has a great rest of your day.
Donata Stroink-Skillrud: Thank you so much.
Hans Skillrud: Thank you Chris.



