( Legal )
Legal register
Everything this company needs to publish, and where each item stands. 25 items across 5 groups.
This is not legal advice. It is a checklist assembled from what this site already claims and what the product already integrates with — a starting point for counsel, not a substitute for it. Which items apply, and what each must say, depends on the legal entity, where it is registered, where its customers are, and where its data physically sits.
Publish before launch
The set a visitor is entitled to find before they hand over anything at all.
Terms of Service
OutstandingThe contract between the company and whoever uses the product.
Without it there is no agreed limit of liability, no stated governing law, and no basis for suspending an account.
Privacy Policy
OutstandingWhat personal data is collected, why, on what legal basis, and who it is shared with.
Required almost everywhere the site claims to operate, and it has to name the sub-processors rather than gesture at them.
Cookie Policy and consent
OutstandingWhat is stored on the visitor's device, and a real choice about the non-essential parts.
Consent has to be collected before the cookie is set, not after — a banner that only informs is not consent.
Acceptable Use Policy
OutstandingWhat customers may not do with the platform.
This is what makes it possible to terminate an abusive account without breaching the contract.
Refund and cancellation terms
OutstandingHow to cancel, what is refundable, and over what period.
The company takes payments; consumer law in most markets requires this to be stated up front.
Company identity and contact
OutstandingRegistered name, registration number, registered address, and a contact route.
Several jurisdictions require a trading website to identify the legal entity behind it. It also has to match the entity named in the Terms.
Because customers are worldwide
Serving EU or UK residents brings these in wherever the company itself is registered.
Data Processing Agreement
OutstandingThe terms under which the company handles data on a customer's behalf.
Business customers will ask for it during procurement, and GDPR requires a written agreement between controller and processor.
Sub-processor list
OutstandingEvery third party that touches customer data, kept current.
AWS, Google Cloud and the Meta platforms are all sub-processors. Customers are usually entitled to notice before the list changes.
Data subject request process
OutstandingHow someone asks for their data, corrects it, or has it deleted — and how fast that is answered.
The right exists whether or not there is a process; without one the deadlines get missed.
Breach notification commitment
OutstandingWho gets told, and within how long, if data is exposed.
Regulator deadlines are measured in hours. The decision tree has to exist before the incident, not during it.
International transfer basis
OutstandingThe mechanism relied on when data leaves the region it was collected in.
Cloud regions and support access both move data across borders, often without anyone deciding to.
Data retention schedule
OutstandingHow long each category is kept, and what happens at the end.
“Until we feel like deleting it” is not a retention period, and it is the first thing an audit asks for.
Because of the integrations
Obligations that arrive through the platforms and networks the product connects to.
PCI DSS attestation
OutstandingEvidence that cardholder data is handled to the card networks' standard.
Mastercard and the banks enforce this through the acquirer. The required level depends on volume and on whether card data ever touches your systems.
Platform terms compliance
OutstandingThe developer terms for WhatsApp Business, Facebook, Instagram, AWS and Google Cloud.
Each flows down its own privacy and data-use requirements, and the Meta platforms audit against them.
Trademark attribution
OutstandingA note that third-party names and marks belong to their owners, and that listing them is not a claim of endorsement.
The credentials belt (NU-32) displays other companies' marks. See the warnings in claims.ts and public/media/logos/LICENCE.txt.
Certification substantiation
OutstandingProof for each certification named on the site, and wording matching what each programme actually grants.
“Certified by” is looser than most partner programmes permit, and the programmes police it themselves.
Open-source attributions
OutstandingLicences and notices for the third-party code and assets shipped in the product.
This site alone carries Next.js, GSAP, Three.js, Lenis, simple-icons and two Google Fonts, several of which require notice.
Because of what the site says
Every superlative already on these pages is a representation someone can be asked to prove.
Substantiation file
OutstandingThe evidence behind each marketing claim, held before the claim goes live.
“Fastest growing SaaS in Iraq”, “most secure servers” and “trusted by companies worldwide” are all superlatives. See claims.ts.
Service Level Agreement
OutstandingThe uptime actually committed to, and what happens when it is missed.
The site implies reliability. An SLA turns that from a mood into a number with a remedy.
Security statement
OutstandingHow data is encrypted, who can reach it internally, and how that is reviewed.
It is what a security questionnaire asks for, and it is the evidence behind the security claims on the site.
Accessibility statement
OutstandingThe standard targeted, known gaps, and how to report a barrier.
Public-sector and enterprise buyers ask for it, and in several markets it is a procurement requirement.
As the company grows
Not day-one items, but the ones that arrive with headcount, funding or public contracts.
Employment and contractor templates
OutstandingContracts, IP assignment, and confidentiality.
Without written IP assignment, work produced by contractors may not belong to the company.
Anti-bribery and sanctions policy
OutstandingControls on who the company may transact with.
Cross-border payments and public-sector customers both raise screening obligations.
Insurance
OutstandingProfessional indemnity and cyber cover.
Enterprise contracts frequently require minimum cover as a condition of signing.
Dispute resolution and governing law
OutstandingWhich country's law applies and where a dispute is heard.
It belongs in the Terms, but it is a commercial decision rather than a drafting one.