Looking for examples is the right instinct and it usually goes wrong in the same way: the examples found are long, written for a larger organisation, and copied whole. What is worth taking from an example is its STRUCTURE, because every workable policy has the same four parts and most published ones bury them under a page of preamble nobody reads.
Part one: who it binds, stated first
Scope belongs at the top, in one sentence, and it should name people rather than systems: all employees and contractors, or everyone with access to customer data, or the four people who can approve a payment. A policy whose scope is discovered on page two is a policy half its readers assume is not about them, and that assumption is the failure mode nobody notices until it matters.
Part two: the rule, in the fewest words that survive an argument
State what must happen and what must not, in the present tense, without hedging. The test is whether two people reading it independently would agree on whether a given action broke it. If they would not, the rule is not written yet, however many words are in it. Most bad policies fail this test on their central sentence while passing it easily on the parts nobody disputes.
Part three: an owner and a review date
A name and a date, on the document. This is the part that turns a file into a living rule: somebody is accountable for it being right, and there is a moment at which somebody has to look. Without both, a policy is only as current as the last person who happened to open it, which for most documents on most shared drives is a long time ago.
Part four: the record that it was agreed
Who has seen this version, and when. Not who was sent it. The distinction is the whole reason this site exists: a distribution list proves an email left, and an acknowledgement record proves a person read and agreed. When somebody asks whether an employee knew the rule, only one of those two answers the question.
Questions people ask about policy examples
Can we copy a published policy?
Take the structure, not the words. A copied policy names practices you do not have and omits the ones you do, and the first person to notice will be the one you least want noticing.
How many policies does a small company need?
Fewer than most start with. Acceptable use, information security, data retention, and whatever your industry actually requires. Add one when a real decision keeps being made twice.
What makes a policy enforceable?
That it is clear, that it was communicated, and that you can show the person agreed to the version in force at the time. The third is the one that is usually missing.