Your website’s terms of use are worth getting right.

A poorly drafted agreement isn’t just a legal inconvenience; it’s an unenforceable one. We draft website terms that hold up wherever your business operates and wherever your users are.

Do websites legally need terms of use?

Yes, and the reasons go beyond liability protection. Depending on your jurisdiction and the nature of your platform, your website terms of use may need to address:

  • Consumer protection obligations — many jurisdictions require that clauses limiting liability, imposing indemnities, or restricting consumer rights be specifically drawn to the user’s attention in a conspicuous manner.
  • Data protection compliance — frameworks including the GDPR, POPIA, CCPA, and others require Responsible Parties and data controllers to establish lawful grounds for processing, maintain breach notification procedures, and make specific disclosures to users.
  • Electronic transaction requirements — suppliers offering goods or services online are frequently required by statute to make specific disclosures on their websites. Failure to do so can give consumers statutory cancellation rights.
  • Browsewrap enforceability — courts across common law jurisdictions have repeatedly invalidated “by using this site you agree” clauses where users had no clear, conspicuous notice that terms existed.

60% of browsewrap challenges succeed when notice is inadequate

3+ overlapping legal frameworks typically apply to a single website operating across multiple jurisdictions

14 days — the cancellation window consumers may acquire if required disclosures are missing, under frameworks including South Africa’s ECTA and the EU’s distance-selling rules

0 generic templates are drafted with your jurisdiction, platform, and user base in mind

What happens when terms of use go wrong

Most websites have terms. Few have terms that would survive a challenge. Here is what inadequate drafting actually costs.

Unenforceability at the worst moment

A user scrapes your content, trains an AI system on it, and you go to court, only to discover your browsewrap was never properly constituted. Courts in the US, EU, UK, and beyond have invalidated agreements where users had no reason to know terms existed.

Regulatory exposure

Whether it is GDPR in Europe, POPIA in South Africa, the CCPA in California, or another framework in your market, data protection law imposes duties that a well-drafted set of terms must acknowledge and that generic templates rarely address correctly.

AI training of your content

Without an express prohibition tied to remedies—injunctive relief, material breach designation, deletion certification requirements—a clause that merely says “no scraping” gives you a paper position, not an enforceable one. After Meta Platforms v. Bright Data (N.D. Cal. 2024), the standard has shifted.

Uncapped, un-tiered liability

A flat liability cap that doesn’t distinguish free users from paying users, and that doesn’t specify cumulative and not “per-incident”, leaves you exposed to cascading claims from a single technical incident. Courts have enforced per-incident readings where the cap was ambiguous.

Amendment clauses that don’t work

“Continued use constitutes acceptance” is unenforceable in most US states and faces serious scrutiny in EU and other consumer-protection contexts. We draft amendment regimes with advance notice periods, active rejection rights, and version archives—the architecture that courts actually uphold.

Privacy notice entanglement

Incorporating your privacy notice by reference into your terms of use restricts your right to update it without triggering the amendment procedure, and adds a layer of contract liability if you breach it. Decoupling them correctly requires a contractual necessity bridge clause.

Courts have frequently found browsewrap agreements unenforceable absent clear and conspicuous notice to users ~ Standard position across US, EU, UK, and common law jurisdictions. So the baseline your terms must clear

What your terms of use need to cover

We draft to the full stack: legal substance, jurisdictional compliance, and contractual precision. Here is what that means in practice.

  1. Browsewrap enforceability architecture. Acceptance tied to specific UI behaviours: page-load notice display, CTA adjacency, post-notice continuation, not a generic “by using this site you agree” line.
  2. AI and automated data collection. Prohibition clause with enforcement teeth: material breach designation, injunctive relief acknowledgement, 14-day deletion certification demand, and statutory carve-outs for lawful text and data mining rights in applicable jurisdictions.
  3. Jurisdiction-appropriate statutory compliance. The specific disclosures, consumer rights notices, and data protection provisions your terms must contain depend on where you operate and who you serve. We identify the applicable frameworks and draft to each of them.
  4. Tiered liability caps. Separate caps for free and paid users, each expressly stated as cumulative and not per-incident, with the look-back period anchored to the last event giving rise to the claim.
  5. Privacy separation and contractual necessity bridge. Privacy notice decoupled from the terms (preserving amendment flexibility) with a bridge clause identifying the processing necessary for service performance—closing the contractual necessity gap under GDPR, POPIA, and equivalent frameworks.
  6. Indemnification with procedural mechanics. Notice obligations, control of defence, settlement restrictions, cooperation requirements: the four components that make an indemnity clause operationalisable when a real third-party claim arrives.
  7. Amendment clause with active rejection right. Advance notice, written rejection mechanism, old terms preserved pending next usage period, and express carve-outs for policies that must remain freely revisable—the architecture courts enforce.
  8. Suspension and termination regime. Ordinary termination with notice and stated reason; immediate suspension limited to reasonable grounds plus urgency or security need: defensible in consumer and commercial contexts across jurisdictions.
  9. Optional modules. SaaS and subscription terms, marketplace and user-generated content terms, API access terms—each as a self-contained addendum activated only for the platforms that need them.

One agreement. Multiple jurisdictions.

A website is global by default. Your terms of use need to work wherever your users are, not just where you are incorporated.

We build jurisdiction-toggle architecture into every set of terms. That means the same document can address GDPR for your EU users, POPIA for your South African users, CCPA for Californians, and consumer protection requirements across common law markets — without becoming unreadable.

Europe: GDPR contractual necessity, DSA transparency obligations, Brussels I consumer jurisdiction rules, age threshold compliance.

United States: State consumer protection carve-outs, COPPA age compliance, copyright agent registration, FTC negative option rules for subscriptions.

South Africa: POPIA Responsible Party designation, CPA compliance clause, ECTA statutory disclosure block.

UK and Commonwealth: Post-Brexit data adequacy considerations, Consumer Rights Act compatibility, distance-selling obligations.

Built on primary sources, not precedent recycling.

Our terms of use are developed against primary legal sources and leading reference frameworks as well as current browsewrap jurisprudence from US, EU, UK, and South African courts. That means no “shall” where simple present is the correct verb structure. No “indemnify and hold harmless” where “indemnify” is sufficient. Precision at the clause level is not pedantry; it is what courts read.

How we work with you

A fixed, predictable process. No open-ended engagement.

  1. Site and risk assessment. We review your website, your business model, your user base, and the jurisdictions you operate in. We identify which modules you need and where your current terms—if any—have gaps.
  2. Briefing and scope confirmation. We confirm scope, pricing, and turnaround in writing. No surprise scope creep. We identify the specific clauses that require your input so you know exactly what you need to provide.
  3. Drafting and review. You receive a clean annotated version explaining each substantive choice and the legal authority behind it, plus a plain-language operator guide covering implementation requirements: UI notice placement, version archiving, amendment notification procedures.
  4. Revision and sign-off. One round of revisions is included. We return a final clean version and a version-archived copy for your records. Where we have recommended clickwrap for high-risk provisions, we advise on implementation.

What you get that a template cannot provide

Off-the-shelf templates are drafted for no one in particular. That is their defining limitation.

IssueGeneric templateITLawCo terms
Jurisdiction-specific statutory complianceNot addressedFrameworks identified and drafted to
Consumer rights conspicuousness noticesNot addressedNamed clauses drawn to consumer’s attention
AI training prohibitionAbsent or toothlessMaterial breach, injunctive relief, deletion certification
Liability cap structureFlat, ambiguous, no per-incident clarificationTiered (free / paid), cumulative and not per-incident
Amendment enforceability“Continued use = acceptance”Advance notice, written rejection right, version archive
Privacy policy relationshipIncorporated by referenceDecoupled with contractual necessity bridge
Indemnity mechanicsOne paragraph, no proceduresNotice, control of defence, settlement restrictions, cooperation
Suspension and termination“Without notice, at our discretion”Tiered regime, jurisdiction-defensible, post-suspension notification
Verb structure precision“Shall” throughoutObligation, policy, condition — correct structure for each

Things clients ask before engaging us

Possibly not, but you should know what they cover and what they don’t. The most common gaps we find are: no AI training prohibition, ambiguous liability caps, amendment clauses that courts will not enforce, missing consumer rights notices required by the jurisdictions you operate in, and privacy notices incorrectly incorporated by reference. We offer a terms review service that gives you a prioritised remediation plan before you decide whether a full redraft is necessary.

A browsewrap binds users by continued use of your site, without requiring any affirmative action. A clickwrap requires the user to actively click “I agree” before proceeding. Browsewraps are appropriate for general website terms; clickwraps are legally safer for high-stakes provisions, e.g., arbitration clauses, AI training restrictions, subscription auto-renewal terms, and significant liability limitations. We advise you on which provisions require clickwrap treatment and design the notice architecture accordingly.

Usually, yes, if the terms are structured correctly. We build jurisdiction-toggle architecture into complex international terms, so the document addresses the applicable framework in each market without becoming a patchwork of contradictions. For very different regulatory environments, we may recommend modular addenda rather than a single monolithic document.

Partly. And the way this is drafted matters considerably. Processing genuinely necessary for the performance of your services can rely on contractual necessity as its lawful basis under GDPR, POPIA, and equivalent frameworks. But if your privacy notice is incorporated by reference into your Terms, you cannot update it without triggering the terms’ amendment procedure. The correct approach is to decouple them with a contractual necessity bridge clause. This affects your ability to adapt your data practices as your business grows.

Standard turnaround for a full set of terms (core terms plus any applicable modules) is 10 business days from briefing sign-off. A terms review takes 5 business days. We work on a fixed-fee basis: scope, price, and turnaround are agreed in writing before any work begins. Contact us for a scoping call and we will confirm fees for your specific requirements.

About ITLawCo

ITLawCo is an information technology law practice advising digital businesses on the legal frameworks that govern their operations: data protection, cloud and SaaS agreements, software licensing, IT contracts, and website legal compliance.

We work with clients across jurisdictions—from early-stage platforms to established enterprises—who need legal documents drafted to the standard their business and their users deserve. We do not recycle precedents; we draft to your specific platform, user base, and regulatory exposure.

Your terms of use should be an asset, not an afterthought.

Book a scoping call. We will assess your site, identify your exposure, and tell you exactly what you need—before you commit to anything.

Book a scoping call → Send us your current terms →

Professional disclaimer: This page provides general information for informational purposes only. It does not constitute legal advice and does not create an attorney-client relationship. Legal requirements vary by jurisdiction, business model, and the specific circumstances of each client. Consult a qualified legal professional in your jurisdiction before publishing or relying on any website terms of use.