No one cares about this kind of stuff till you're big. So get big and then worry about it.
Your users agree to certain obligations as part of the contract; you should too. Make privacy a contractual obligation on your part, not just a policy.
If someone breaks into the datacenter and physically steals the server (a more realistic scenario than the server being hacked) I don't think that would count as "disclosing". But I'm in Massachusetts where courts seem to have a higher-than-average degree of common sense.
It might even be riskier post copy/paste legal documents. Because you're not a lawyer you don't know what ramifications it could have on any future litigation.
(IANAL, I could be wrong and often am, this is not legal advice, etc. etc.)
Then we talked about to a local long-time entrepreneur, who said that is exactly what his lawyer did, and charged him thousands for it; in fact, it didn't turn out that great. So, save some money and write them yourself.