Compliance, explained
without the jargon.
Compliance means your documents say what the law requires them to say. A privacy policy has to explain what you do with people's data. A cookie banner has to ask before anything tracks them. A contract has to hold up if someone later disputes it.
Most founders meet the word for the first time in a customer's security questionnaire, or in a clause an investor's lawyer has flagged. This page explains what it means for a company your size, what we check, and what we honestly cannot do.
Does any of this apply to me?
Almost certainly yes, and earlier than most people expect. These are the four situations that pull a startup into scope. One line of each pair is probably already true of you.
Your website has a contact form, an email signup, or analytics.
You are handling personal data. You need a privacy policy that says what you collect, why, and how long you keep it.
You have a single user, customer, or employee in the UK or the EU.
UK GDPR or EU GDPR applies to you, at any size. There is no exemption for being small or early.
You use cookies, or you send marketing email in the UK.
PECR applies: ask before you track anyone, and put an unsubscribe link in every marketing email.
You sell to companies bigger than you.
Their security review will ask for written policies, a data processing agreement, and often a SOC 2 report before they sign.
Getting this wrong is rarely dramatic. It usually shows up as a deal that stalls in procurement, a customer asking for a document you do not have, or a complaint that turns into a regulator's letter.
A rulepack is a checklist of one law.
We turn a law into a list of things a document has to say, and keep that list up to date. Running a rulepack reads your document against every item on it. Here is every pack we ship today, and what each one actually is.
GDPR
General Data Protection Regulation
The EU's data protection law, and the reason every website suddenly grew a cookie banner in 2018. It applies to any company handling personal data about people in the EU, wherever the company itself is based.
UK DPA 2018
Data Protection Act 2018 and UK GDPR
Britain's version of the same law, kept after Brexit. If you have UK users, this is the one that applies to you.
PECR
Privacy and Electronic Communications Regulations
The UK rules covering cookies, tracking, and marketing email. Consent before you track, and a way out of every mailing list.
CCPA
California Consumer Privacy Act, as amended by the CPRA
California's privacy law. It starts to matter the moment you have California customers, which for most startups is sooner than expected.
EU AI Act
EU Artificial Intelligence Act
The EU's rules for products that use AI: what you have to disclose to users, and what you have to write down about how your system works.
SOC 2 policies
Not a law: a security standard customers ask about
SOC 2 is an audit that enterprise buyers ask for. We draft and maintain the written policies an auditor will request. We do not run the audit, collect evidence, or issue a report, and nobody can make you audit-ready by reading your documents.
Templates themselves are drafted for England & Wales, and that is the only jurisdiction we claim for drafting today. EU and US template coverage is in progress.
What happens when you press check.
01
You pick a document and a rulepack
02
It is read against every item in that pack
03
You get findings, in plain language
04
Each finding comes with a proposed fix
05
You accept or reject, one by one
06
Later, you run it again
What we will never claim.
A tool that reads your documents can tell you what they are missing. It cannot sign anything off. We would rather say that here than let you find out later.
- This is not legal advice, and we are not a law firm. For anything unusual, contested, or high-value, have a solicitor review the final document.
- We do not issue certificates. No SOC 2 report, no ISO 27001, no audit, no evidence collection.
- We do not guarantee compliance in any jurisdiction. Every automated finding is shown to you for review, and the judgement stays yours.
- We do not file anything with Companies House or HMRC on your behalf.
- We do not train AI models on your documents. Edits and checks are sent to third-party model providers solely to produce the response you asked for.
If you are starting from nothing.
You do not have to solve compliance. You have to do the first five things, in this order.
- 01Write a privacy policy. It is the document you need first, and the first one a customer or investor looks for.
- 02Add terms of service if people can sign up to anything.
- 03Add a cookie policy if you run analytics or any third-party script.
- 04Run the GDPR and UK DPA rulepacks across all three.
- 05Accept the fixes that make sense, then re-run the checks until they come back clean.
That is an afternoon of work, and it covers what most early customers and investors ask to see. Everything after that is maintenance, which is the part this product is really for. For the complete picture beyond these five, the startup documents checklist runs stage by stage from incorporation to due diligence.
Three more questions.
What does the product actually do?
The three panes, the editing loop, and every capability, with a picture of the app.
What templates are in the library?
Privacy policy to founders' agreement: every template, what it covers, and the settings you control.
What does it cost?
Three plans from £19 a month, 7 days free, five documents in week one or every penny back, and what each one includes.
Start with the privacy policy.
It is the first of the five documents the free week covers. Pay and not have them? One email within 30 days refunds every penny, and every export stays yours.