[TECHLAWG]
Selected work

The problem, not the document count.

Engagements described by what was actually wrong and what changed. Client identities and identifying details are withheld or altered. We do not name clients without written permission, and we do not publish anything that would let one be identified.

5.1 Engagements

Six representative engagements.

Engagement 01AI · Series A · United States

The classification nobody had done

Situation
An AI scheduling product assumed it was a deployer under the EU AI Act because it had trained no models of its own. It was licensing a third-party model and shipping it under its own brand, which on the facts pointed to provider status.
Why it mattered
The provider obligation set is an order of magnitude heavier. An investor questionnaire had already asked the question and the company had answered it wrongly, in writing.
Work
Territorial scope assessment, role reclassification across four systems, risk tiering, an AI system inventory, redesigned in-product transparency, and rewritten model vendor terms with flow-down obligations.
Outcome
A defensible written classification, a corrected position with the investor, and a governance pack that closed the diligence item rather than reopening it.
Duration
14 business days
Engagement 02B2B SaaS · Enterprise motion · UK and EU

Losing deals in security review, not in the pitch

Situation
A B2B analytics vendor kept reaching verbal agreement and then stalling six to ten weeks in procurement. No DPA, no sub-processor list, no documented transfer position, and a subscription agreement borrowed from a consumer app.
Why it mattered
Every enterprise buyer runs the same review. The company was failing it repeatedly and reading the delay as a sales problem.
Work
SaaS subscription agreement and order form, Article 28 DPA, sub-processor register with a change-notification process, transfer mechanism assessment with SCCs and the UK Addendum, security schedule, and a negotiation playbook with fallback positions per clause.
Outcome
Procurement stopped being the bottleneck, and the sales team stopped escalating every redline to the founder.
Duration
10 business days
Engagement 03Marketplace · Pre-launch · Three jurisdictions

Two-sided terms, borrowed from a one-sided business

Situation
A services marketplace preparing to launch in three countries had adopted a competitor’s terms wholesale. Those terms described a single-party seller model. The business was an intermediary holding funds in escrow.
Why it mattered
The liability, refund and payout provisions described obligations the company had not undertaken and could not perform, and the intermediary position was undocumented in all three markets.
Work
Platform terms of use, separate buyer and seller agreements, payments and payout terms aligned to the escrow flow, content and liability positions, prohibited-use policy, and a privacy suite covering all three jurisdictions.
Outcome
Launched on documents that matched the actual money flow, with the intermediary position stated rather than assumed.
Duration
12 business days
Engagement 04HR technology · Growth · EU

A high-risk system, discovered late

Situation
A hiring platform had built candidate ranking as a product feature. Under the EU AI Act, AI used in employment and recruitment sits within the listed high-risk areas. Nobody internally had connected the two.
Why it mattered
High-risk obligations are a programme, not a document. Discovering the classification close to a deadline leaves no room to build one.
Work
Applicability opinion, risk tiering across the product surface, gap analysis against the provider obligation set, a phased remediation plan with owners and effort estimates, and a board-level summary of exposure and sequencing.
Outcome
A realistic, sequenced programme with a defensible paper trail showing when the company knew and what it did about it.
Duration
15 business days
Engagement 05Mobile app · Consumer · US multi-state

A generated policy that described a different app

Situation
A consumer app with several hundred thousand users was running a generated privacy policy written before it added an SDK-heavy analytics stack, in-app purchases and a referral programme.
Why it mattered
The policy omitted categories of data actually collected and named none of the recipients. A single user complaint would have surfaced the gap immediately.
Work
Full SDK and tracker audit, data flow mapping, a rewritten privacy policy covering CCPA and CPRA and the newer state regimes, in-app disclosure wording, consent architecture review, and a DSAR handling procedure.
Outcome
Documentation that described the app as it actually existed, and an operational process for handling requests rather than a page promising one.
Duration
9 business days
Engagement 06Agency · White label · Ongoing

A legal service line, without hiring a lawyer

Situation
A product studio building SaaS for clients was repeatedly asked for legal documentation and repeatedly declining, sending the work and sometimes the whole client relationship elsewhere.
Why it mattered
Every declined request was margin walking out of the door, and a handover point where the client met another supplier.
Work
A white-label arrangement: standard intake folded into the studio’s onboarding, defined turnaround, deliverables issued under the studio’s brand, and a fixed wholesale rate so they could price it into their own proposals.
Outcome
A new service line for the studio with no headcount, and a repeatable delivery channel on our side.
Duration
Ongoing

Yours is probably one of these.

Describe the situation in two lines. If it is a problem we have solved before, we will tell you how it went and what it took.