Skip to content
01AboutAbout02WorkWork03LabsLabs04BlogBlog05ContactContact

( Legal )

Legal register

Everything this company needs to publish, and where each item stands. 25 items across 5 groups.

This is not legal advice. It is a checklist assembled from what this site already claims and what the product already integrates with — a starting point for counsel, not a substitute for it. Which items apply, and what each must say, depends on the legal entity, where it is registered, where its customers are, and where its data physically sits.

Publish before launch

The set a visitor is entitled to find before they hand over anything at all.

  • Terms of Service

    Outstanding

    The contract between the company and whoever uses the product.

    Without it there is no agreed limit of liability, no stated governing law, and no basis for suspending an account.

  • Privacy Policy

    Outstanding

    What personal data is collected, why, on what legal basis, and who it is shared with.

    Required almost everywhere the site claims to operate, and it has to name the sub-processors rather than gesture at them.

  • Cookie Policy and consent

    Outstanding

    What is stored on the visitor's device, and a real choice about the non-essential parts.

    Consent has to be collected before the cookie is set, not after — a banner that only informs is not consent.

  • Acceptable Use Policy

    Outstanding

    What customers may not do with the platform.

    This is what makes it possible to terminate an abusive account without breaching the contract.

  • Refund and cancellation terms

    Outstanding

    How to cancel, what is refundable, and over what period.

    The company takes payments; consumer law in most markets requires this to be stated up front.

  • Company identity and contact

    Outstanding

    Registered name, registration number, registered address, and a contact route.

    Several jurisdictions require a trading website to identify the legal entity behind it. It also has to match the entity named in the Terms.

Because customers are worldwide

Serving EU or UK residents brings these in wherever the company itself is registered.

  • Data Processing Agreement

    Outstanding

    The terms under which the company handles data on a customer's behalf.

    Business customers will ask for it during procurement, and GDPR requires a written agreement between controller and processor.

  • Sub-processor list

    Outstanding

    Every third party that touches customer data, kept current.

    AWS, Google Cloud and the Meta platforms are all sub-processors. Customers are usually entitled to notice before the list changes.

  • Data subject request process

    Outstanding

    How someone asks for their data, corrects it, or has it deleted — and how fast that is answered.

    The right exists whether or not there is a process; without one the deadlines get missed.

  • Breach notification commitment

    Outstanding

    Who gets told, and within how long, if data is exposed.

    Regulator deadlines are measured in hours. The decision tree has to exist before the incident, not during it.

  • International transfer basis

    Outstanding

    The mechanism relied on when data leaves the region it was collected in.

    Cloud regions and support access both move data across borders, often without anyone deciding to.

  • Data retention schedule

    Outstanding

    How long each category is kept, and what happens at the end.

    “Until we feel like deleting it” is not a retention period, and it is the first thing an audit asks for.

Because of the integrations

Obligations that arrive through the platforms and networks the product connects to.

  • PCI DSS attestation

    Outstanding

    Evidence that cardholder data is handled to the card networks' standard.

    Mastercard and the banks enforce this through the acquirer. The required level depends on volume and on whether card data ever touches your systems.

  • Platform terms compliance

    Outstanding

    The developer terms for WhatsApp Business, Facebook, Instagram, AWS and Google Cloud.

    Each flows down its own privacy and data-use requirements, and the Meta platforms audit against them.

  • Trademark attribution

    Outstanding

    A note that third-party names and marks belong to their owners, and that listing them is not a claim of endorsement.

    The credentials belt (NU-32) displays other companies' marks. See the warnings in claims.ts and public/media/logos/LICENCE.txt.

  • Certification substantiation

    Outstanding

    Proof for each certification named on the site, and wording matching what each programme actually grants.

    “Certified by” is looser than most partner programmes permit, and the programmes police it themselves.

  • Open-source attributions

    Outstanding

    Licences and notices for the third-party code and assets shipped in the product.

    This site alone carries Next.js, GSAP, Three.js, Lenis, simple-icons and two Google Fonts, several of which require notice.

Because of what the site says

Every superlative already on these pages is a representation someone can be asked to prove.

  • Substantiation file

    Outstanding

    The evidence behind each marketing claim, held before the claim goes live.

    “Fastest growing SaaS in Iraq”, “most secure servers” and “trusted by companies worldwide” are all superlatives. See claims.ts.

  • Service Level Agreement

    Outstanding

    The uptime actually committed to, and what happens when it is missed.

    The site implies reliability. An SLA turns that from a mood into a number with a remedy.

  • Security statement

    Outstanding

    How data is encrypted, who can reach it internally, and how that is reviewed.

    It is what a security questionnaire asks for, and it is the evidence behind the security claims on the site.

  • Accessibility statement

    Outstanding

    The standard targeted, known gaps, and how to report a barrier.

    Public-sector and enterprise buyers ask for it, and in several markets it is a procurement requirement.

As the company grows

Not day-one items, but the ones that arrive with headcount, funding or public contracts.

  • Employment and contractor templates

    Outstanding

    Contracts, IP assignment, and confidentiality.

    Without written IP assignment, work produced by contractors may not belong to the company.

  • Anti-bribery and sanctions policy

    Outstanding

    Controls on who the company may transact with.

    Cross-border payments and public-sector customers both raise screening obligations.

  • Insurance

    Outstanding

    Professional indemnity and cyber cover.

    Enterprise contracts frequently require minimum cover as a condition of signing.

  • Dispute resolution and governing law

    Outstanding

    Which country's law applies and where a dispute is heard.

    It belongs in the Terms, but it is a commercial decision rather than a drafting one.

BLCK