[TECHLAWG]
Services

What we do, and how an engagement works.

Scope, fee, revision allowance and delivery date are agreed in writing before work starts. We do not bill hourly for productised work, and we do not revise a fee mid-engagement unless you change the scope.

2.1 Packages

Packages.

Most companies should start here. A package covers a whole launch surface rather than one document, which is usually what the problem actually is.

Package A

Startup Launch Package

For a first software product going live with users in the US, UK or EU.

  • Terms of Service
  • Privacy Policy (GDPR, UK GDPR, CCPA)
  • Cookie Policy and banner wording
  • Acceptable use and disclaimers
  • Implementation memo
Fixed fee · 7–10 days
Package B · Most bought

SaaS Compliance Package

For B2B software vendors who keep losing time in enterprise procurement and security review.

  • SaaS subscription agreement and order form
  • Data Processing Agreement (Art. 28 compliant)
  • Sub-processor list and change process
  • Privacy Policy and Cookie Policy
  • Transfer mechanism assessment (SCCs / UK IDTA)
  • Implementation memo
Fixed fee · 7–10 days
Package C

AI Governance Package

For companies building AI products or embedding third-party models, ahead of EU AI Act deadlines.

  • Scope and role classification (provider / deployer)
  • Risk tiering against the Regulation
  • AI system inventory and risk register
  • Transparency and disclosure design
  • AI vendor review framework
  • Governance framework and board summary
Fixed fee · 10–14 days
Package D

Marketplace Legal Package

For two-sided platforms connecting buyers and sellers, or clients and providers.

  • Marketplace Terms of Use
  • Seller / provider agreement
  • Buyer terms and payments wording
  • Content, liability and intermediary positions
  • Privacy Policy and Cookie Policy
Fixed fee · 7–10 days
Package E

Enterprise Contract Package

For software companies moving upmarket and negotiating against real procurement teams.

  • Master Services Agreement
  • Order form and SOW templates
  • Service level and support schedule
  • Security schedule and DPA
  • Negotiation playbook with fallback positions
Fixed fee · 10–14 days
Package F

Compliance Audit

For companies who already have documents and want to know what is wrong with them.

  • Website and in-product compliance review
  • Document gap analysis against applicable regimes
  • Cookie and tracker scan
  • Prioritised remediation plan with effort estimates
Fixed fee · 5 days
2.2 Ongoing

Documents go stale quietly.

Regulation moves, your product ships, a vendor gets swapped, a new market opens. Nothing breaks visibly. It surfaces during a security questionnaire or a diligence request, at the worst possible moment.

The subscription exists so that never happens. We monitor the regimes that apply to you, update your documents when something changes, and tell you plainly what changed and why.

Ongoing · Monthly

Privacy Compliance Subscription

  • Regulatory monitoring for your applicable regimes
  • Document updates as law or product changes
  • Annual full review and rewrite
  • Named contact for privacy questions
  • Sub-processor register maintenance
  • Change log you can hand to a buyer
Monthly retainer · no lock-in
Ongoing · Monthly

Fractional Legal Department

  • Named lawyer, agreed monthly hours
  • Contract review and redlines
  • Security questionnaire support
  • Launch and market-entry reviews
  • Partner counsel coordination where needed
Monthly retainer · agreed hours
2.3 Individual documents

Single documents.

If you only need one thing. A package is more efficient once you need three or more.

Schedule 2 — Privacy and data protection
DocumentCoversTurnaround
Privacy PolicyWeb, mobile or bothGDPR, UK GDPR, CCPA / CPRA, and other US state laws as applicable3–5 days
Data Processing AgreementController to processorArticle 28 terms, sub-processor mechanics, SCCs and UK IDTA where needed3–5 days
Cookie Policy & consent reviewIncludes tracker scanePrivacy, consent architecture, banner wording, prior-consent check3–5 days
Record of Processing ActivitiesArticle 30 registerProcessing inventory, lawful bases, retention, recipients, transfers5–7 days
Data Protection Impact AssessmentArticle 35Necessity and proportionality analysis, risk and mitigation, sign-off pack7–10 days
Transfer Impact AssessmentPost-Schrems IITransfer mapping, mechanism selection, supplementary measures5–7 days
DSAR handling procedureOperationalIntake, verification, search, redaction and response templates5 days
Schedule 3 — Commercial contracts
DocumentCoversTurnaround
Terms of ServiceConsumer or businessLicence, acceptable use, payment, liability, termination, dispute resolution3–5 days
SaaS subscription agreementB2BSubscription mechanics, SLAs, data terms, IP, liability caps, renewal5–7 days
Master Services AgreementEnterpriseFramework terms with order form and SOW structure5–7 days
Software licence agreementOn-prem or embeddedGrant scope, restrictions, open source, audit, support5–7 days
Reseller / partner agreementChannelAppointment, territory, margin, branding, end-user flow-down5–7 days
Contractor / IP assignmentTeamWork product ownership, confidentiality, moral rights waiver3 days
Mutual NDAStandardDefinition scope, carveouts, term, residuals position2 days
Contract review & redlinesInbound agreementsTracked changes, risk memo, negotiation positions and fallbacks3–5 days
Schedule 4 — AI governance
DeliverableCoversTurnaround
EU AI Act applicability opinionScope and roleTerritorial scope, provider or deployer classification, risk tier, obligation map5 days
AI system inventory & risk registerFoundationalSystem catalogue, purpose, data, model, vendor, risk rating, owner7–10 days
AI governance frameworkPolicy layerAcceptable use, human oversight, review gates, incident handling, roles7–10 days
AI vendor review frameworkProcurementDiligence questionnaire, contract clause set, ongoing monitoring5–7 days
AI transparency & disclosure designProductUser-facing disclosure, synthetic content marking, in-product wording5 days
AI terms and user policyProduct termsInput and output rights, training use, hallucination and reliance positions3–5 days
2.4 Alternatives

When a generator is genuinely enough.

We would rather tell you honestly than sell you something you do not need.

Use a generator if

You have a simple marketing site, no accounts, no payments, analytics only, and no enterprise customers. A generated policy is a reasonable starting point and costs almost nothing.

Come to us if

  • You process personal data across borders or use sub-processors
  • You are selling to enterprise buyers who run security review
  • You are raising, and diligence is coming
  • You are building with or on AI models
  • You are a marketplace, a fintech, or handling health data
  • Someone has already sent you a DSAR, a complaint, or a regulator letter

The difference is not wording. It is that a generator cannot know your data flows, and every one of the situations above turns on exactly that.

Not sure which package fits?

Describe the product in two lines. We will tell you what you actually need, including if that is less than you thought.