Startup Launch Package
For a first software product going live with users in the US, UK or EU.
- Terms of Service
- Privacy Policy (GDPR, UK GDPR, CCPA)
- Cookie Policy and banner wording
- Acceptable use and disclaimers
- Implementation memo
Scope, fee, revision allowance and delivery date are agreed in writing before work starts. We do not bill hourly for productised work, and we do not revise a fee mid-engagement unless you change the scope.
Most companies should start here. A package covers a whole launch surface rather than one document, which is usually what the problem actually is.
For a first software product going live with users in the US, UK or EU.
For B2B software vendors who keep losing time in enterprise procurement and security review.
For companies building AI products or embedding third-party models, ahead of EU AI Act deadlines.
For two-sided platforms connecting buyers and sellers, or clients and providers.
For software companies moving upmarket and negotiating against real procurement teams.
For companies who already have documents and want to know what is wrong with them.
Regulation moves, your product ships, a vendor gets swapped, a new market opens. Nothing breaks visibly. It surfaces during a security questionnaire or a diligence request, at the worst possible moment.
The subscription exists so that never happens. We monitor the regimes that apply to you, update your documents when something changes, and tell you plainly what changed and why.
If you only need one thing. A package is more efficient once you need three or more.
| Document | Covers | Turnaround |
|---|---|---|
| Privacy PolicyWeb, mobile or both | GDPR, UK GDPR, CCPA / CPRA, and other US state laws as applicable | 3–5 days |
| Data Processing AgreementController to processor | Article 28 terms, sub-processor mechanics, SCCs and UK IDTA where needed | 3–5 days |
| Cookie Policy & consent reviewIncludes tracker scan | ePrivacy, consent architecture, banner wording, prior-consent check | 3–5 days |
| Record of Processing ActivitiesArticle 30 register | Processing inventory, lawful bases, retention, recipients, transfers | 5–7 days |
| Data Protection Impact AssessmentArticle 35 | Necessity and proportionality analysis, risk and mitigation, sign-off pack | 7–10 days |
| Transfer Impact AssessmentPost-Schrems II | Transfer mapping, mechanism selection, supplementary measures | 5–7 days |
| DSAR handling procedureOperational | Intake, verification, search, redaction and response templates | 5 days |
| Document | Covers | Turnaround |
|---|---|---|
| Terms of ServiceConsumer or business | Licence, acceptable use, payment, liability, termination, dispute resolution | 3–5 days |
| SaaS subscription agreementB2B | Subscription mechanics, SLAs, data terms, IP, liability caps, renewal | 5–7 days |
| Master Services AgreementEnterprise | Framework terms with order form and SOW structure | 5–7 days |
| Software licence agreementOn-prem or embedded | Grant scope, restrictions, open source, audit, support | 5–7 days |
| Reseller / partner agreementChannel | Appointment, territory, margin, branding, end-user flow-down | 5–7 days |
| Contractor / IP assignmentTeam | Work product ownership, confidentiality, moral rights waiver | 3 days |
| Mutual NDAStandard | Definition scope, carveouts, term, residuals position | 2 days |
| Contract review & redlinesInbound agreements | Tracked changes, risk memo, negotiation positions and fallbacks | 3–5 days |
| Deliverable | Covers | Turnaround |
|---|---|---|
| EU AI Act applicability opinionScope and role | Territorial scope, provider or deployer classification, risk tier, obligation map | 5 days |
| AI system inventory & risk registerFoundational | System catalogue, purpose, data, model, vendor, risk rating, owner | 7–10 days |
| AI governance frameworkPolicy layer | Acceptable use, human oversight, review gates, incident handling, roles | 7–10 days |
| AI vendor review frameworkProcurement | Diligence questionnaire, contract clause set, ongoing monitoring | 5–7 days |
| AI transparency & disclosure designProduct | User-facing disclosure, synthetic content marking, in-product wording | 5 days |
| AI terms and user policyProduct terms | Input and output rights, training use, hallucination and reliance positions | 3–5 days |
We would rather tell you honestly than sell you something you do not need.
You have a simple marketing site, no accounts, no payments, analytics only, and no enterprise customers. A generated policy is a reasonable starting point and costs almost nothing.
The difference is not wording. It is that a generator cannot know your data flows, and every one of the situations above turns on exactly that.
Describe the product in two lines. We will tell you what you actually need, including if that is less than you thought.