BusinessSep 29, 2027·10 min read

Terms of Service and DPAs When You're an AI Startup

The paperwork that unblocks enterprise deals, keeps you out of trouble, and doesn't need to cost $10k in legal fees to get right.

Muhammad Qitmeer
Muhammad Qitmeer
Co-Founder & CEO, Augere Labs
Share
The paperwork that unblocks enterprise deals, keeps you out of trouble, and doesn't need to cost $10k in legal fees to get right.

The first time a serious customer asks for your DPA, you find out how much paperwork you skipped. Terms of service and data processing agreements aren't the fun part of building an AI startup, but they're the paperwork that lets you close deals larger than $10k and answer the questions procurement teams always ask.

Here's the practical version — what to have, what to skip, and how not to overpay for it.

What each document actually does

Your Terms of Service is the contract between you and the customer for using your product. It covers acceptable use, IP ownership, uptime, liability caps, and what happens when the relationship ends.

Your Privacy Policy tells end users what data you collect and what you do with it. Required in most jurisdictions.

Your Data Processing Agreement (DPA) is the contract customers ask for when they're regulated or GDPR-adjacent. It describes how you handle personal data on their behalf — what you do, what you don't do, who your subprocessors are.

All three are separate. Bundling them into one giant document is a red flag to enterprise buyers.

The AI-specific clauses that matter

1. Training on customer data

The single most-asked question in AI startup procurement: do you train models on our data? The answer needs to be clearly yes or clearly no, in writing.

For most B2B AI products, the correct default is: no training on customer data without explicit opt-in. Say it plainly in the ToS.

2. Model provider disclosures

If you use OpenAI, Anthropic, or another provider under the hood, buyers want to know. List them as subprocessors. Some enterprises won't accept certain providers; better to know before contract signature.

3. Output ownership and warranties

Who owns the AI-generated output? Almost always the customer, subject to a license back to you. What warranty do you make about accuracy? Almost always none — "AI outputs may be inaccurate, verify before relying on them" is the standard.

4. Prompt and response retention

How long do you keep prompts and completions? Buyers regulated by HIPAA, financial services, or EU privacy law care about this. Keep it short and document it.

The subprocessor list

A public page listing every third party that processes customer data. Model providers (OpenAI, Anthropic), infrastructure (AWS, Cloudflare, Vercel), observability (Sentry, PostHog), email (Resend, Postmark).

Two rules: keep it current, and notify customers when it changes. Most enterprise DPAs require 30 days notice before adding a subprocessor.

How to get these documents without spending $10k

Options in order of cost:

Template + review

Start with a template from Common Paper, Ironclad's free library, or Termly. Get a lawyer to review the specific clauses that matter for your business. Cost: $500-$1500 in legal review.

This is right for pre-seed and seed. It gets you 90% of the way with 10% of the cost.

Full custom drafting

A lawyer writes it from scratch based on your business. Cost: $5-15k. Right for later stages, or when you're doing something structurally unusual.

The wrong option

Copying a competitor's terms wholesale. It's not obviously illegal, but the specifics are wrong for your business, and the clauses that matter to your customers are almost certainly not the ones your competitor optimized for.

What enterprise buyers actually check

From actual procurement questionnaires we've seen:

  • Do you have SOC 2? If not, when? (Aspirational answers are fine at early stage.)
  • Where is data stored geographically?
  • Encryption at rest and in transit — details.
  • Employee background checks and training.
  • Data breach notification timeline (usually 72 hours).
  • Subprocessor list and change notification.
  • Data retention and deletion on termination.
  • Backup policy.

You don't need SOC 2 to answer these. You need answers.

What we do on projects

For AI startups closing their first enterprise deal, the sequence is:

  1. Template ToS + Privacy + DPA, reviewed by a startup lawyer for the specifics.
  2. Public subprocessor list.
  3. A security overview page — one page describing encryption, access, backups, incident response.
  4. A trust page or shared folder with these documents plus any SOC 2 progress.

This unblocks 80% of B2B deals under $100k ACV. Anything bigger, you're negotiating custom terms anyway.

Mistakes we keep seeing

Silent training. Product uses customer data to fine-tune, doesn't mention it. Discovered during procurement. Deal dead.

Unlimited liability. Standard ToS caps liability at 12 months of fees. Missing this cap is a serious financial risk.

Auto-renewal without notice. Some jurisdictions require reminder emails and easy cancellation. Related reading: Chargebacks and payment disputes for SaaS.

Not updating docs when the stack changes. Add a new subprocessor without updating the list, and you're technically in breach with existing customers.

Common misconceptions

"I'll do this when we're bigger." The first enterprise buyer asks. You either have documents or you spend three weeks scrambling while the deal cools.

"GDPR is only for EU companies." If you serve EU users, it applies to you regardless of where you're based.

"AI outputs need a special license." Almost always no. Standard "customer owns output" language works.

FAQ

Do I need SOC 2 before I can sell to enterprises?

No. You need a credible plan and honest answers to the questionnaire. Small enterprises accept "SOC 2 in progress, expected Q3" more often than founders think.

What about HIPAA?

Only if you're touching protected health information. If you are, you need a BAA with your model provider — OpenAI, Anthropic, and AWS all offer one under specific terms.

How often should I update the docs?

Every time the stack changes materially. At minimum, review annually.

Where to go from here

If you're staring at your first enterprise procurement questionnaire, the fix is usually a weekend of clean-up, not a re-platforming. Related reading: Handling PII in AI applications and SaaS security audit checklist.

FAQ

Frequently asked questions

Can I use Common Paper templates as-is?+

As a starting point, yes. Get a lawyer to review the specifics — the templates are good, your business isn't identical to the template's assumed shape.

Do I need a DPA before I have customers?+

You need one before your first regulated or EU customer signs. Have a template ready.

What if I use OpenAI — do I need a separate DPA with them?+

Yes. OpenAI's DPA is available on their site. Sign it before processing customer data through their API.

Building something similar?

Let's talk in 30 minutes.

Book an intro
© 2026 Augere Labs