Legal readiness
Max AI legal and sales readiness
One visible DEV approval pack for the legal documents, self-serve acceptance flow and live billing decisions needed before Max AI can be sold publicly.
Last updated: June 29, 2026
Legal review required before PROD
Draft for DEV validation only. This is not legal advice. Requires review and acceptance by a qualified lawyer before any PROD publication, checkout, onboarding, sales proposal, App Store submission or customer contract use.
Company details used in drafts
MAXDATA APP LTD, company number 12078187.
Registered office: 280 King Street, London, W6 0SP, United Kingdom.
Company details checked against Companies House public records on 24 June 2026.
Before PROD
A qualified lawyer must approve the customer-facing text before it is published on production checkout, production onboarding, App Store metadata, paid ads, customer contracts or sales proposals.
This DEV package is intentionally visible and testable, but it is not legal advice and not a final contract.
Protection posture recommended for Max AI
Keep the PROD offer B2B-first unless consumer sales are deliberately enabled with consumer cancellation, cooling-off and subscription-renewal wording.
Make the customer responsible for data, permissions, connected accounts, end-user notices, agent instructions and review of AI-assisted outputs.
State that Max AI can suspend unsafe, unlawful, unpaid, abusive or security-risk activity, including automations and connected tools.
Avoid unapproved overage billing: charge extra usage only when checkout/order terms clearly explain it and the customer has accepted it.
Add a lawyer-approved liability cap, warranty disclaimer, indemnity and governing-law clause before production contracts are used.
Use a real DPA for business customers that upload customer data, connect inboxes/channels, use widgets or process personal data through agents.
Publish a concrete subprocessor list and transfer position before paid onboarding, especially for AI providers, hosting, auth, email, payments and support tooling.
Use a real cookie inventory and consent/withdrawal flow before analytics or marketing cookies are enabled.
Treat AI transparency as a product obligation: users and, where relevant, their end users should know when they interact with AI or receive AI-generated content.
Lawyer approval pack
Draft covers workspace access, subscriptions, credits, customer responsibilities, acceptable use, AI output, suspension, cancellation, IP and support.
Approval needed: Approve final contract wording, liability cap, warranty disclaimer, indemnity, governing law, auto-renewal language and B2B/B2C carve-outs.
Draft covers account, workspace, conversations, connected channels, AI providers, billing/support data, security, retention and data rights.
Approval needed: Confirm controller/processor roles, legal bases, Article 13/14 notices, retention windows, transfers, subprocessors and complaint routes.
Draft explains essential, analytics and future marketing cookies at policy level.
Approval needed: Approve real cookie inventory, consent banner, withdrawal route, analytics defaults, provider list and marketing-cookie gating.
Draft summary explains processor/customer instructions, subprocessors, security, breach support, deletion, rights and transfer safeguards.
Approval needed: Prepare final Article 28 DPA, security appendix, subprocessor table, transfer mechanism, retention schedule and customer-signature route.
Draft explains that AI output may be wrong, needs human review and is not professional advice or a sole basis for high-impact decisions.
Approval needed: Approve exclusions for legal, financial, medical, employment, credit, insurance, education, biometric, safety and EU AI Act scenarios.
Draft explains subscriptions, plan limits, credits, top-ups, overages, failed payments, billing records, taxes and invoice assumptions.
Approval needed: Confirm final prices, plan names, credit value, expiry/rollover, overage consent, Stripe live setup, VAT/tax treatment and invoice wording.
Draft covers cancellation, billing-cycle access, refund request handling, consumer-vs-business treatment, credits and failed payments.
Approval needed: Approve refund windows, cooling-off rights if B2C is enabled, renewal notices, unused credits, failed payments and cancellation mechanics.
Draft gives a support route and explains billing, legal and data-deletion support expectations without a production SLA promise.
Approval needed: Decide support hours, response targets, incident escalation, paid-plan support tiers and whether any uptime or SLA commitment exists.
Draft explains support-led deletion, export, workspace-owner constraints, billing/security retention exceptions and subprocessors.
Approval needed: Approve identity verification, deletion/export SLA, backup retention, accounting retention, support-ticket retention and processor deletion route.
Draft covers unlawful use, spam, harassment, privacy violations, credential abuse, unsafe automation, scraping and third-party platform rules.
Approval needed: Align prohibited-use list with Terms enforcement rights, suspension rights, AI-safety posture and third-party platform obligations.
Live billing blockers
DEV has draft tax language only; live tax treatment is not approved.
Decision needed: Decide sales countries, VAT registration/collection assumptions, net/gross pricing, tax IDs and reverse-charge handling.
PROD gate: No live billing until tax/VAT setup and checkout wording are approved.
Legal posture recommends B2B-first, but public checkout could technically be seen by consumers if not gated.
Decision needed: Decide whether Max AI sells B2B-only or also to consumers, and whether business confirmation is required during signup/checkout.
PROD gate: B2C needs separate consumer cancellation, renewal, cooling-off and refund treatment before PROD.
DEV mentions Stripe invoice access, but invoice entity, required buyer details and correction process are not final.
Decision needed: Confirm invoice issuer, numbering, buyer data fields, VAT line display, invoice emails, corrections and customer portal behavior.
PROD gate: Invoice workflow must match finance/legal approval before live charges.
Draft policy exists, but final refund windows and unused-credit treatment are not approved.
Decision needed: Approve refund eligibility, partial refunds, failed-payment handling, chargeback route, consumer exceptions and credit refunds.
PROD gate: No PROD checkout until refund policy matches Stripe operation and customer-facing terms.
Trial labels exist in billing status, but public offer does not define whether trial is available.
Decision needed: Choose no trial, free trial without card, card-required trial, trial length, reminders and what happens at trial end.
PROD gate: Checkout copy and Stripe products must match the approved trial policy.
Draft says customers should manage cancellation, but final access-after-cancel and portal behavior are not approved.
Decision needed: Decide whether access continues to period end, whether downgrade is instant, how automations pause and how cancellation confirmation is sent.
PROD gate: Portal and policy must agree before PROD live billing.
DEV displays credit concepts and plan allowances, but commercial credit rules are not final legal terms.
Decision needed: Approve monthly allowance, expiry, rollover, top-ups, throttling, no-unapproved-overage rule, abuse limits and customer notifications.
PROD gate: No automatic overage billing until explicit checkout acceptance exists.
DEV/test billing can be visible, but live products, prices, tax, invoices, portal, webhooks and emails are separate PROD gates.
Decision needed: Approve live product catalogue, price IDs, webhook routing, customer portal settings, tax integration and email receipts.
PROD gate: Requires explicit Julian approval for PROD/live keys and separate verification.
Self-serve acceptance flow
Required consent checkboxes for core legal documents and commercial/payment documents before account creation.
Approval needed: Lawyer should approve the exact consent text and document-version capture before PROD.
DEV legal gate that lists required policies, checkout facts and billing blockers before live payment launch.
Approval needed: Business/legal must approve final price, tax, invoice, trial, cancellation, refund and AI-credit wording.
Workspace-owner responsibilities for data, connected services, AI review, end-user notices and accepted policy versions.
Approval needed: Lawyer should approve workspace-owner responsibility language and audit trail requirements.
DEV-safe plan/payment UI, plan status, credit usage and decisions still required before live billing.
Approval needed: Finance/legal must approve live billing decisions before real PROD charging is enabled.
Gap list
Expanded Terms now cover B2B workspace access, authority to accept terms, subscriptions, credits, acceptable use, AI output, connected services, support, suspension, cancellation, IP/confidentiality themes and legal-review status.
Next: Lawyer should approve liability cap, warranty disclaimers, indemnity, governing law, consumer carve-outs, auto-renewal wording and paid-plan obligations before PROD.
Expanded Privacy Policy now covers account, workspace, conversation, connected-channel, AI-provider, billing/support, cookies, retention, security, data-rights and international-transfer themes.
Next: Lawyer / DPO should confirm controller/processor roles, legal bases, Article 13/14 notices, subprocessor list, retention periods, transfer mechanisms and complaint routes.
Cookie notice now explains essential, analytics and future marketing cookies at a policy level and flags that consent cannot be hidden only inside a privacy policy.
Next: Confirm real cookie inventory, categories, retention, provider list, consent banner/withdrawal flow and analytics/marketing defaults before paid traffic or PROD launch.
Draft policy explains subscription cancellation, billing-cycle access, refund request handling, consumer-vs-business treatment and AI-credit handling.
Next: Confirm refund windows, statutory consumer cooling-off rules if B2C is enabled, trial/renewal notices, Stripe mechanics, taxes and whether unused credits are refundable.
Draft policy covers unlawful use, spam, abuse, unsafe automation, protected data and third-party services.
Next: Lawyer should align this with enforcement rights in the Terms.
Draft disclaimer explains that AI output can be wrong, needs human review, is not professional advice and must not be used for high-risk regulated decisions without separate approval.
Next: Confirm language for financial, legal, medical, employment, credit, insurance, education, biometric, safety and EU AI Act transparency scenarios.
Draft DPA/GDPR summary explains controller/processor intent, customer instructions, subprocessors, security, breach support, exports, deletion, data subject rights and transfer safeguards.
Next: Prepare lawyer-approved DPA, Article 28 schedule, UK/EU transfer mechanism, subprocessor table, security appendix, retention schedule and support process.
Support page explains support routes, billing/credits help, response expectations and legal-review status, but it does not promise a production SLA.
Next: Decide support hours, incident route, enterprise SLA promises, escalation owner, refund tie-ins and whether any uptime or response-time commitment is offered.
Draft deletion article explains support-led deletion, exports, workspace admin constraints and retention exceptions.
Next: Connect the final policy to an in-product request flow once approved.
Draft page explains planned subscriptions, plan limits, AI credits, top-ups, overage handling, failed payments and no-unapproved-overage position, but live checkout is not final in this package.
Next: Confirm Stripe setup, invoice entity, tax/VAT handling, plan names, renewal reminders, credit expiry/rollover/refund rules, usage metering and overage consent.
Official reference points used
Company number, active status and registered office used in these drafts.
Privacy notices should be clear, concise and cover Articles 13/14 UK GDPR information.
Cookie consent must be specific, informed and based on an unambiguous positive action where required.
Controller/processor relationships need a written contract covering required processing terms.
Deletion rights exist but are not absolute and should be handled through a verified process.
Subscription cancellation, renewal and refund handling must be checked before consumer or mixed B2B/B2C sales.
Invoice wording, VAT display and buyer details should be checked against the final tax position.
Live plans, trials, renewal behavior, invoices and customer portal settings must match customer-facing terms.
Stripe Tax setup is a product/finance decision and does not replace legal or tax advice.
AI transparency and high-risk-use assumptions should be reviewed if Max AI serves EU users or affected people.