Strategy & Consultancy

Online Legal

Your website needs to follow basic legal requirements related to data, privacy and user information. Missing or unclear elements can create risks and affect how your business is perceived.

Key Benefits for this service

Your website includes elements that need to follow legal requirements, even if they seem simple at first glance. When these are incomplete or unclear, they can create risks and affect how your business is perceived. This review helps you understand what needs attention and what to fix, so your website stays aligned, clear and properly structured.

Clear compliance

You understand exactly what legal elements are present, missing or incomplete on your website.

Reduced risk

You identify potential issues early and avoid problems related to data, privacy and user information.

Complete setup

You know what documents and sections your website needs and how they should be structured.

Clear next steps

You receive straightforward recommendations that can be implemented without confusion.
Pick What Fits You Best

Choose Your Service Type

Every website has different needs when it comes to legal compliance. Some require a quick check, while others need a more detailed review of data, privacy and required documents. Choose the option that fits your current situation and get clear guidance on what needs to be updated, added or clarified.

Legal pages review

We review your website to identify missing or incomplete legal elements related to data, privacy and user information. You get a clear overview of what needs to be updated or added.
What's included
Terms & conditions review and gap analysis

Privacy policy accuracy and completeness check

Cookie policy and consent mechanism review

Refund, disclaimer and any additional legal page assessment

This audit looks at the key legal elements your website should include to operate properly. We check how user data is handled, what information is collected and how it is communicated. We also review the presence and structure of essential pages such as privacy policy, cookies and terms. You receive clear feedback on what is missing, incomplete or unclear, along with practical recommendations that can be implemented easily. The goal is to help you understand exactly where your website stands and what needs to be done next.
View more
View less
Delivery time
starting at 7 business days
Experts

Ana M.

Book This Service

GDPR compliance review

We assess how your website and business processes handle personal data and identify where you're exposed under GDPR.
What's included
Lawful basis for data processing assessment

Consent mechanism and opt-in flow review

Data subject rights compliance check

Third-party data sharing and processor review

GDPR compliance isn't a one-time checkbox — it touches how you collect data, store it, process it, share it and respond when someone asks what you hold on them. We review your website and associated business processes against the core GDPR requirements: lawful basis for processing, consent quality, cookie and tracking compliance, data subject rights (access, erasure, portability), and your relationships with third-party processors such as CRMs, email platforms and analytics tools. You receive a prioritised compliance gap report with clear, actionable steps — and an honest view of where your current exposure lies.
View more
View less
Delivery time
starting at 7 business days
Experts

Ana M.

Book This Service

DORA readiness assessment

We assess your organisation's digital operational resilience posture against DORA requirements and identify the gaps you need to close before enforcement applies.
What's included
ICT risk management framework review

Incident classification and reporting process assessment

Third-party ICT provider and contract review

Digital resilience testing and continuity gap analysis

The Digital Operational Resilience Act sets binding requirements for financial entities and their ICT service providers across the EU — covering risk management, incident reporting, resilience testing and third-party oversight. Non-compliance carries significant regulatory risk. We assess your current posture across all five DORA pillars, identify where your policies, processes and contracts fall short of the requirements, and deliver a structured readiness report with a prioritised remediation roadmap. The assessment is practical and scoped to your organisation's size and role — not a generic enterprise framework applied regardless of context.
View more
View less
Delivery time
starting at 7 business days
Experts

Ana M.

Book This Service

NIS2 readiness assessment

We assess your organisation's digital operational resilience posture against DORA requirements and identify the gaps you need to close before enforcement applies.
What's included
Scope and entity classification check (essential vs important)

Cybersecurity risk management measures review

Incident detection, reporting and response assessment

Supply chain security and third-party oversight review

NIS2 significantly expands the scope of EU cybersecurity obligations — bringing medium and large businesses across a wide range of sectors under binding requirements for risk management, incident reporting, business continuity and supply chain security. Many organisations don't yet know whether they're in scope, let alone whether they're compliant. We start by confirming your classification, then assess your current cybersecurity governance, technical measures and incident handling processes against the NIS2 requirements. You receive a clear gap analysis with a prioritised action plan sized to your organisation — not a framework designed for enterprises ten times your size.
View more
View less
Delivery time
starting at 7 business days
Experts

Ana M.

Book This Service

Data retention & processing policy audit

We assess your organisation's digital operational resilience posture against DORA requirements and identify the gaps you need to close before enforcement applies.
What's included
Data retention schedule review and gap analysis

Lawful basis and purpose limitation assessment

Data deletion and disposal process review

Records of processing activities (ROPA) check

Keeping data longer than necessary, processing it without a clear lawful basis or failing to document what you hold and why are among the most common compliance failures — and among the most penalised. We review your data retention schedules, processing activities, deletion procedures and records of processing against GDPR requirements and relevant sector obligations. We assess whether the data you hold is justified, whether it's being disposed of correctly and whether your documentation would withstand scrutiny from a regulator. You receive a practical audit report with specific policy improvements and a retention schedule template calibrated to your business.
View more
View less
Delivery time
starting at 7 business days
Experts

Ana M.

Book This Service
Legal advice for small and medium businesses

Keep your online business legally safe

Talk to out digital lawyer
Schedule a no-obligation 15-minute consultation.