# Legal, Privacy, And Cookie Requirements

## Purpose

This document lists requirements before launching AgentReady paid self-service sales from France to an international B2B audience.

It is not legal advice. Professional legal validation is required before activating real payments.

## Required Company Information

Do not invent missing company information.

Use `TO_BE_COMPLETED` until verified:

| Requirement | Current value |
| --- | --- |
| Publisher legal identity | TO_BE_COMPLETED |
| Legal form or EI identity | TO_BE_COMPLETED |
| Professional address | TO_BE_COMPLETED |
| SIREN/SIRET | TO_BE_COMPLETED |
| VAT number if applicable | TO_BE_COMPLETED |
| Publication director | TO_BE_COMPLETED |
| Hosting provider | TO_BE_COMPLETED |
| Contact email | TO_BE_COMPLETED |

## Required Public Legal Pages

Before real payment activation, the public site should include:

- legal notice;
- terms of use;
- B2B terms of sale;
- privacy policy;
- refund policy;
- cookie policy or cookie notice;
- responsible disclosure / security policy;
- subprocessor list;
- DPA if required by product scope.

Do not update public legal HTML in this PR.

## Legal Notice Checklist

Required or expected items:

- identity of publisher;
- legal form;
- professional address;
- SIREN/SIRET;
- VAT number if applicable;
- publication director;
- hosting provider identity;
- hosting provider address/contact;
- contact email;
- intellectual property notice;
- applicable law;
- limitation of liability compatible with product claims.

## Terms Of Use Checklist

Must cover:

- product purpose;
- Community usage;
- paid plan access;
- account rules;
- acceptable use;
- API/MCP content responsibility;
- no live execution by AgentReady static scans;
- no guarantee of absolute safety;
- suspension and termination;
- intellectual property;
- liability limits;
- dispute handling;
- applicable law.

## B2B Terms Of Sale Checklist

Must cover:

- B2B-only purchase at launch;
- plan descriptions;
- monthly and annual billing;
- HT / excluding tax prices;
- tax calculation;
- payment methods;
- invoice delivery;
- renewal;
- upgrade;
- downgrade;
- cancellation;
- refund policy;
- failed payment consequences;
- license access;
- no manual quotes for Community, Pro, Team, or Agency at launch.

## Privacy Policy Checklist

Must cover:

- data controller identity;
- contact email;
- categories of personal data;
- billing data;
- account data;
- license validation metadata;
- support data;
- technical logs;
- cookies if any;
- legal bases;
- retention periods;
- recipients/subprocessors;
- international transfers;
- GDPR rights;
- deletion process;
- incident process;
- complaint authority;
- data security measures.

## Legal Bases

Likely legal bases to validate:

- contract performance for account, subscription, invoice, and license management;
- legal obligation for accounting and tax records;
- legitimate interest for security logs, abuse prevention, and product integrity;
- consent for non-essential cookies if ever introduced.

Final legal basis wording requires professional validation.

## Retention Periods

Define retention for:

- account records;
- subscription records;
- invoices and accounting records;
- license validation logs;
- support tickets;
- security logs;
- deleted account backups;
- marketing consent if ever used.

Use `TO_BE_COMPLETED` until retention periods are legally validated.

## Subprocessors

Maintain a public subprocessor list.

Expected categories:

- hosting provider;
- payment processor;
- transactional email provider;
- error monitoring provider if used;
- support/helpdesk provider if used;
- analytics provider only if introduced with proper consent handling.

Current concrete vendors:

- TO_BE_COMPLETED.

## International Transfers

If subprocessors process data outside the EU/EEA, document:

- vendor;
- country;
- transfer mechanism;
- safeguards;
- link to vendor DPA if applicable.

Use `TO_BE_COMPLETED` until vendors are chosen.

## GDPR Rights

Document procedures for:

- access;
- rectification;
- deletion;
- restriction;
- portability;
- objection;
- withdrawal of consent where applicable;
- complaint to a supervisory authority.

## Incident Procedure

Before launch, define:

- internal incident contact;
- detection path;
- severity classification;
- user notification criteria;
- regulator notification criteria;
- evidence retention;
- post-incident review.

## Deletion Procedure

Account deletion should define:

- cancellation relationship;
- immediate data removed;
- retained legal/accounting records;
- backup deletion window;
- license revocation;
- support contact for deletion issues.

## DPA And Subprocessor Future

A DPA may be required if paid Team/Agency features process customer account, team, client, or CI history data on behalf of customers.

Before Team or Agency launch:

- decide processor/controller roles;
- draft DPA;
- publish subprocessor list;
- define security measures;
- define audit/support process.

## Responsible Disclosure

Publish a responsible disclosure policy covering:

- scope;
- safe harbor statement where appropriate;
- reporting email;
- expected response times;
- prohibited testing;
- treatment of customer data;
- no extortion or public disclosure before coordination.

## Official Cookie Strategy At Launch

Launch cookie strategy:

- no advertising tracker;
- no Meta Pixel;
- no Hotjar;
- no session replay;
- no non-essential analytics cookie by default;
- no unnecessary banner if no non-essential cookie is used;
- if non-essential cookies are added, they must be blocked before consent;
- "Accept", "Reject", and "Manage preferences" must be offered at the same level;
- provide a permanent "Cookie settings" link.

## Cookie Checklist

Before adding cookies:

- identify cookie name;
- purpose;
- provider;
- duration;
- category;
- legal basis;
- whether it is essential;
- consent requirement;
- withdrawal mechanism.

## Payment Activation Blocker

Real payments must not be activated until:

- company identity is complete;
- terms of sale are complete;
- privacy policy is complete;
- refund policy is complete;
- cookie strategy is implemented;
- subprocessors are listed;
- professional legal validation is complete.

## Non-Guarantee

TimeProofs AgentReady does not guarantee that an AI agent will never fail.
It identifies structural risks that may cause AI agents to misuse APIs, tools or MCP servers.
