Legal readiness

Max AI legal and sales readiness

One visible DEV approval pack for the legal documents, self-serve acceptance flow and live billing decisions needed before Max AI can be sold publicly.

Last updated: June 29, 2026

Legal review required before PROD

Draft for DEV validation only. This is not legal advice. Requires review and acceptance by a qualified lawyer before any PROD publication, checkout, onboarding, sales proposal, App Store submission or customer contract use.

Company details used in drafts

MAXDATA APP LTD, company number 12078187.

Registered office: 280 King Street, London, W6 0SP, United Kingdom.

Company details checked against Companies House public records on 24 June 2026.

Before PROD

A qualified lawyer must approve the customer-facing text before it is published on production checkout, production onboarding, App Store metadata, paid ads, customer contracts or sales proposals.

This DEV package is intentionally visible and testable, but it is not legal advice and not a final contract.

Protection posture recommended for Max AI

Keep the PROD offer B2B-first unless consumer sales are deliberately enabled with consumer cancellation, cooling-off and subscription-renewal wording.

Make the customer responsible for data, permissions, connected accounts, end-user notices, agent instructions and review of AI-assisted outputs.

State that Max AI can suspend unsafe, unlawful, unpaid, abusive or security-risk activity, including automations and connected tools.

Avoid unapproved overage billing: charge extra usage only when checkout/order terms clearly explain it and the customer has accepted it.

Add a lawyer-approved liability cap, warranty disclaimer, indemnity and governing-law clause before production contracts are used.

Use a real DPA for business customers that upload customer data, connect inboxes/channels, use widgets or process personal data through agents.

Publish a concrete subprocessor list and transfer position before paid onboarding, especially for AI providers, hosting, auth, email, payments and support tooling.

Use a real cookie inventory and consent/withdrawal flow before analytics or marketing cookies are enabled.

Treat AI transparency as a product obligation: users and, where relevant, their end users should know when they interact with AI or receive AI-generated content.

Lawyer approval pack

Terms / regulaminNeeds lawyer

Draft covers workspace access, subscriptions, credits, customer responsibilities, acceptable use, AI output, suspension, cancellation, IP and support.

Approval needed: Approve final contract wording, liability cap, warranty disclaimer, indemnity, governing law, auto-renewal language and B2B/B2C carve-outs.

Privacy policyNeeds lawyer

Draft covers account, workspace, conversations, connected channels, AI providers, billing/support data, security, retention and data rights.

Approval needed: Confirm controller/processor roles, legal bases, Article 13/14 notices, retention windows, transfers, subprocessors and complaint routes.

CookiesNeeds business decision

Draft explains essential, analytics and future marketing cookies at policy level.

Approval needed: Approve real cookie inventory, consent banner, withdrawal route, analytics defaults, provider list and marketing-cookie gating.

DPA / GDPRNeeds lawyer

Draft summary explains processor/customer instructions, subprocessors, security, breach support, deletion, rights and transfer safeguards.

Approval needed: Prepare final Article 28 DPA, security appendix, subprocessor table, transfer mechanism, retention schedule and customer-signature route.

AI disclaimerNeeds lawyer

Draft explains that AI output may be wrong, needs human review and is not professional advice or a sole basis for high-impact decisions.

Approval needed: Approve exclusions for legal, financial, medical, employment, credit, insurance, education, biometric, safety and EU AI Act scenarios.

Payments and AI creditsNeeds business decision

Draft explains subscriptions, plan limits, credits, top-ups, overages, failed payments, billing records, taxes and invoice assumptions.

Approval needed: Confirm final prices, plan names, credit value, expiry/rollover, overage consent, Stripe live setup, VAT/tax treatment and invoice wording.

Refunds and cancellationNeeds lawyer

Draft covers cancellation, billing-cycle access, refund request handling, consumer-vs-business treatment, credits and failed payments.

Approval needed: Approve refund windows, cooling-off rights if B2C is enabled, renewal notices, unused credits, failed payments and cancellation mechanics.

Support / SLANeeds business decision

Draft gives a support route and explains billing, legal and data-deletion support expectations without a production SLA promise.

Approval needed: Decide support hours, response targets, incident escalation, paid-plan support tiers and whether any uptime or SLA commitment exists.

Data deletionNeeds lawyer

Draft explains support-led deletion, export, workspace-owner constraints, billing/security retention exceptions and subprocessors.

Approval needed: Approve identity verification, deletion/export SLA, backup retention, accounting retention, support-ticket retention and processor deletion route.

Acceptable useNeeds lawyer

Draft covers unlawful use, spam, harassment, privacy violations, credential abuse, unsafe automation, scraping and third-party platform rules.

Approval needed: Align prohibited-use list with Terms enforcement rights, suspension rights, AI-safety posture and third-party platform obligations.

Live billing blockers

VAT / podatki

DEV has draft tax language only; live tax treatment is not approved.

Decision needed: Decide sales countries, VAT registration/collection assumptions, net/gross pricing, tax IDs and reverse-charge handling.

PROD gate: No live billing until tax/VAT setup and checkout wording are approved.

B2B / B2C scope

Legal posture recommends B2B-first, but public checkout could technically be seen by consumers if not gated.

Decision needed: Decide whether Max AI sells B2B-only or also to consumers, and whether business confirmation is required during signup/checkout.

PROD gate: B2C needs separate consumer cancellation, renewal, cooling-off and refund treatment before PROD.

Invoices

DEV mentions Stripe invoice access, but invoice entity, required buyer details and correction process are not final.

Decision needed: Confirm invoice issuer, numbering, buyer data fields, VAT line display, invoice emails, corrections and customer portal behavior.

PROD gate: Invoice workflow must match finance/legal approval before live charges.

Refunds

Draft policy exists, but final refund windows and unused-credit treatment are not approved.

Decision needed: Approve refund eligibility, partial refunds, failed-payment handling, chargeback route, consumer exceptions and credit refunds.

PROD gate: No PROD checkout until refund policy matches Stripe operation and customer-facing terms.

Trial

Trial labels exist in billing status, but public offer does not define whether trial is available.

Decision needed: Choose no trial, free trial without card, card-required trial, trial length, reminders and what happens at trial end.

PROD gate: Checkout copy and Stripe products must match the approved trial policy.

Cancellation

Draft says customers should manage cancellation, but final access-after-cancel and portal behavior are not approved.

Decision needed: Decide whether access continues to period end, whether downgrade is instant, how automations pause and how cancellation confirmation is sent.

PROD gate: Portal and policy must agree before PROD live billing.

AI limits and credits

DEV displays credit concepts and plan allowances, but commercial credit rules are not final legal terms.

Decision needed: Approve monthly allowance, expiry, rollover, top-ups, throttling, no-unapproved-overage rule, abuse limits and customer notifications.

PROD gate: No automatic overage billing until explicit checkout acceptance exists.

Live Stripe configuration

DEV/test billing can be visible, but live products, prices, tax, invoices, portal, webhooks and emails are separate PROD gates.

Decision needed: Approve live product catalogue, price IDs, webhook routing, customer portal settings, tax integration and email receipts.

PROD gate: Requires explicit Julian approval for PROD/live keys and separate verification.

Self-serve acceptance flow

Gap list

Terms / regulaminDraft visible on DEV

Expanded Terms now cover B2B workspace access, authority to accept terms, subscriptions, credits, acceptable use, AI output, connected services, support, suspension, cancellation, IP/confidentiality themes and legal-review status.

Next: Lawyer should approve liability cap, warranty disclaimers, indemnity, governing law, consumer carve-outs, auto-renewal wording and paid-plan obligations before PROD.

Privacy policyDraft visible on DEV

Expanded Privacy Policy now covers account, workspace, conversation, connected-channel, AI-provider, billing/support, cookies, retention, security, data-rights and international-transfer themes.

Next: Lawyer / DPO should confirm controller/processor roles, legal bases, Article 13/14 notices, subprocessor list, retention periods, transfer mechanisms and complaint routes.

CookiesDraft visible on DEV

Cookie notice now explains essential, analytics and future marketing cookies at a policy level and flags that consent cannot be hidden only inside a privacy policy.

Next: Confirm real cookie inventory, categories, retention, provider list, consent banner/withdrawal flow and analytics/marketing defaults before paid traffic or PROD launch.

Refund / cancel policyDraft visible on DEV

Draft policy explains subscription cancellation, billing-cycle access, refund request handling, consumer-vs-business treatment and AI-credit handling.

Next: Confirm refund windows, statutory consumer cooling-off rules if B2C is enabled, trial/renewal notices, Stripe mechanics, taxes and whether unused credits are refundable.

Acceptable useDraft visible on DEV

Draft policy covers unlawful use, spam, abuse, unsafe automation, protected data and third-party services.

Next: Lawyer should align this with enforcement rights in the Terms.

AI disclaimerDraft visible on DEV

Draft disclaimer explains that AI output can be wrong, needs human review, is not professional advice and must not be used for high-risk regulated decisions without separate approval.

Next: Confirm language for financial, legal, medical, employment, credit, insurance, education, biometric, safety and EU AI Act transparency scenarios.

DPA / GDPRDraft visible on DEV

Draft DPA/GDPR summary explains controller/processor intent, customer instructions, subprocessors, security, breach support, exports, deletion, data subject rights and transfer safeguards.

Next: Prepare lawyer-approved DPA, Article 28 schedule, UK/EU transfer mechanism, subprocessor table, security appendix, retention schedule and support process.

Support / SLADraft visible on DEV

Support page explains support routes, billing/credits help, response expectations and legal-review status, but it does not promise a production SLA.

Next: Decide support hours, incident route, enterprise SLA promises, escalation owner, refund tie-ins and whether any uptime or response-time commitment is offered.

Account and data deletionDraft visible on DEV

Draft deletion article explains support-led deletion, exports, workspace admin constraints and retention exceptions.

Next: Connect the final policy to an in-product request flow once approved.

Payments and AI creditsNeeds product decision

Draft page explains planned subscriptions, plan limits, AI credits, top-ups, overage handling, failed payments and no-unapproved-overage position, but live checkout is not final in this package.

Next: Confirm Stripe setup, invoice entity, tax/VAT handling, plan names, renewal reminders, credit expiry/rollover/refund rules, usage metering and overage consent.

Official reference points used