Accepting new privacy & SaaS matters

Privacy policies and ToS that survive a CCPA audit and an actual user complaint.

Most privacy policies on the web are templates copied from someone else's site, with the wrong AG contact, the wrong opt-out mechanism, and disclosures that don't match the actual data flows. I read your stack, draft the document, and tell you exactly which CPRA, GDPR, and FTC obligations are non-negotiable for the way you actually do business.

Sergei Tokmakov, Esq. · CA Bar #279869 · Licensed since 2011
See packages →
Sergei Tokmakov, Esq., California attorney, CA Bar #279869
01 · Engage me

Two ways to stop guessing on privacy.

Flat fees. Direct work with me. Pick by where you are: drafts that need an attorney's redline, or a coordinated document set that needs to be built.

You already have drafts

SaaS/Privacy Document Review

A coordinated attorney review and redline of the Privacy Policy and Terms of Service you already have, with a focused written risk and gap memo.

$1,500
flat fee · your existing Privacy Policy + Terms of Service
  • Redline of your existing Privacy Policy and Terms of Service, reviewed together so the two documents stop contradicting each other
  • CCPA/CPRA · GDPR · FTC alignment check tied to your actual data flows
  • Focused written risk and gap memo: what is broken, the controlling rule, and the fix
  • One consolidated revision after your team reviews
  • Clean versions you can publish
Pay $1,500 and send your drafts →
One document only. Either your Privacy Policy or your Terms of Service, redlined with a plain-English memo. $1,000 flat
Pay $1,000 →
Not sure yet. A written attorney read on one focused question or one document before you commit. $300
Get a $300 written consultation →

Custom privacy drafting outside either package (novel data flows, EU/UK representative coordination, regulator-response drafting) is hourly at $300 with a written estimate and ceiling before any hours are billed.

02 · How it works

Payment, delivery, and scope before you commit.

Flat-fee, direct work with me. Open any panel for the detail.

💳Payment How you pay and when work starts ?

The $1,500 SaaS/Privacy Document Review is a flat fee you pay through the PayPal button, then send me your drafts. The $2,750 Full Coordinated Launch Package can be paid up front or scoped through intake first; either way I confirm scope in writing before any drafting. The narrower $1,000 single-document review pays through its own button.

No hourly surprises on any flat-fee tier. Only custom drafting outside the packages is hourly, and that carries a written estimate with a ceiling before any hours are billed.

⚡Delivery When you get the draft back ?

Drafts in 2 to 3 business days, even for complex agreements. I work weekends when a matter needs it and it is engaged.

The $1,500 review comes back as a coordinated redline of your Privacy Policy and Terms of Service plus a focused written risk and gap memo, with one consolidated revision. The $2,750 package delivers the Privacy Policy, Terms of Service or MSA, DPA, supporting terms, and a launch and compliance gap memo, with two consolidated revision rounds.

📝After you pay What happens next ?

After you pay (or after I confirm the package scope), send your current Privacy Policy and ToS if you have them, your list of subprocessors and integrations, the jurisdictions where your users sit, and a one-paragraph description of your data flows.

I confirm the scope, draft the redline or documents, and send a written walkthrough. You get the revision rounds stated on your tier, then a clean version you can publish.

📐Scope What the flat fee covers, and what it does not ?

The flat fee covers the defined scope: your existing Privacy Policy and Terms of Service plus the risk memo for the $1,500 review, or the coordinated Privacy Policy, Terms of Service or MSA, DPA, supporting terms, and gap memo for the $2,750 package, with the revisions stated on each tier. One document on its own is the $1,000 single-document review.

Work beyond that defined scope, novel data flows, EU/UK representative coordination, regulator-response drafting, or extra documents, is handled through a $300 Written Attorney Consultation or a re-quote, so the flat fee stays predictable.

03 · Deliverables

What's actually in the $2,750 launch package.

Six concrete deliverables, each written for your specific stack and jurisdictions - not a generic template I rebadge.

01

CCPA + CPRA Disclosures

Notice at Collection, categories of personal information collected, business purposes for processing, retention periods, third parties to whom data is sold or shared, and the consumer rights matrix - tied to the actual data flows in your stack, not a copy-paste from a SaaS template.

02

Opt-Out & GPC Mechanics

"Do Not Sell or Share My Personal Information" link, "Limit the Use of My Sensitive Personal Information" link, Global Privacy Control honoring statement, and the actual opt-out endpoint or banner integration documented for your engineering team.

03

Data Broker / Subprocessor Registry

A working list of every vendor that touches user PI, categorized by processing role (controller, processor, sub-processor) and jurisdiction. Required as a CPRA disclosure if you sell or share, and required by GDPR Article 28 regardless. The starter registry feeds your DPA template.

04

Breach Notification Language

Notice clauses tied to California Civ. Code 1798.82, the 50-state mosaic, GDPR Article 33/34 timelines, and the FTC Health Breach Notification Rule when health data is in scope. Plus an internal escalation playbook so your team knows what to do in the first 72 hours.

05

Cookie + Tracking Compliance

Categorization of every cookie and tracker in your site's actual deployment, consent banner copy and configuration, and an updated cookie policy that matches the banner. Aligned with current CPPA enforcement positions on Google Analytics, Meta Pixel, and similar.

06

Sensitive Personal Info Handling

If you process precise geolocation, financial accounts, biometric identifiers, health data, or contents of communications, CPRA treats those differently. The launch package includes the notice language, the "Limit the Use" mechanism, and the storage/processing controls you need to claim the carve-outs.

04 · Triggers

When you need this before you ship.

If any of these scenarios match your business, the launch package pays for itself the moment a customer, investor, or regulator asks "show me your privacy program."

SaaS Pre-Launch

You're launching a SaaS product and need a defensible Privacy Policy and ToS on day one

Investors ask. Enterprise prospects ask. App stores reject the listing without a working privacy URL. Launching with a free generator policy is the fastest way to box yourself into representations you'll regret at the seed round diligence call.

E-commerce → CA

Your e-commerce store is expanding into California traffic and crossing CPRA thresholds

Once you cross 100,000 California consumers or households - or hit the revenue/sales-share triggers - you owe CPRA disclosures, GPC honoring, and the opt-out links. Most Shopify-default policies don't include any of these.

Health Data App

Your app collects health data and you're not sure whether HIPAA, CMIA, or the FTC HBNR applies

Most consumer health apps aren't HIPAA-covered, but they are subject to California's CMIA and the FTC Health Breach Notification Rule (recently expanded by the 2024 amendments). Each one has its own notice obligations and breach timelines.

B2B + EU Users

You're a B2B platform with EU users and your customers are starting to demand a DPA

Enterprise customers won't sign without a Data Processing Agreement that maps to GDPR Article 28. The $2,750 package includes a DPA you can send so deals stop stalling at procurement, plus the SCCs for international transfers.

FinTech / CFPB

You're a FinTech building toward CFPB and GLBA readiness

Section 1033 of Dodd-Frank, the GLBA Privacy Rule, the Safeguards Rule, and the new CFPB Personal Financial Data Rights rule all interact with your privacy notice. The launch package aligns the layers so your policy doesn't contradict your Reg E and 1033 posture.

05 · Defects I see

Common privacy policy mistakes I see weekly.

A scannable list of the defects I find in roughly half the policies that come across my desk - and what the corrected version looks like.

1

Wrong CA AG / CPPA contact

Templates copied in 2018–2020 still point users to the California Attorney General for CCPA complaints. Enforcement has shifted to the California Privacy Protection Agency (CPPA) for most consumer matters since July 2023.

FixUpdated complaint pathway pointing to the CPPA, with the AG retained for the carve-out matters where it still has jurisdiction.

2

Missing CMIA disclosures for healthcare data

Consumer health apps assume HIPAA doesn't apply (correct) and stop there (incorrect). California's CMIA reaches consumer-facing health and wellness data in ways the federal rule doesn't.

FixCMIA-compliant disclosure layer for California users, plus the FTC Health Breach Notification Rule alignment as expanded in the 2024 amendments.

3

No opt-out for sensitive personal information

CPRA created a separate "Limit the Use of My Sensitive Personal Information" right in addition to "Do Not Sell or Share." Most policies still only have the latter, leaving the SPI right unfulfilled.

FixBoth links present, both tied to a working opt-out endpoint, both honored alongside Global Privacy Control.

4

"We don't sell your data" while running ad-tech

CPRA's definition of "sell" and "share" is broader than colloquial sale - cross-context behavioral advertising counts. Saying "we don't sell" while running Meta Pixel or Google Ads is a misrepresentation enforcement actions have already cited.

FixHonest "we share for cross-context behavioral advertising" disclosure plus the opt-out link, or actually disable the trackers.

5

Retention periods stated as "as long as necessary"

Both CPRA and GDPR require specific or specifically-determinable retention periods. "As long as necessary" alone is non-compliant and was the focus of multiple CPPA enforcement advisories in 2024.

FixCategory-specific retention table with concrete timeframes, plus the criteria for any "as long as necessary" residual category.

6

GDPR notice grafted on top of a CCPA notice without reconciling

Two notice frameworks stapled together produce contradictions: the CCPA layer says "we collect for business purposes" while the GDPR layer says "we have legitimate interests." Both can be true, but they need to map cleanly.

FixSingle unified notice with jurisdiction-specific sections that cross-reference rather than duplicate, and a clear data subject rights matrix.

7

Cookie banner that doesn't match the cookie policy

The banner says "we only use essential cookies" while the policy lists 47 trackers. Either the banner is misleading or the policy is. Either way, it's a CPPA target and a GDPR Article 7 consent-validity problem.

FixAudit of the actual deployed cookies, banner copy that matches, and consent management platform configured for granular opt-in where required.

8

Arbitration clause buried in ToS but not surfaced to users

Mass arbitration plaintiffs, the FAA's 2022 Sexual Assault carve-out, and the recent California App Store rulings all turn on whether the arbitration clause was reasonably surfaced. A clickwrap link buried 14 paragraphs deep is increasingly being held unenforceable.

FixConspicuous arbitration notice with checkbox or scroll-through acknowledgment, mass-arbitration protective language, and statutorily-mandated carve-outs.

06 · Pick your path

Free generator vs DIY rewrite vs attorney-drafted by me.

A four-row snapshot. The quick way to see whether the launch package pays for itself for your business stage.

What you get
Free template generator
DIY rewrite (in-house)
Attorney-drafted by me
Cost
$0
~10–25 hours of internal time
$1,500 review of your drafts / $2,750 full package
CCPA / CPRA accuracy
Generic, often outdated
Depends on staff expertise
Stack-specific, current
Audit-survivability
Low - representations don't match operations
Mixed
Designed to survive a CPPA inquiry
Time-to-launch
Same day
2–6 weeks
3–7 business days
DPA template included
No
Sometimes
Yes ($2,750 package)

Not sure which package you need?

Send me a one-paragraph description of your product and where your users live. I'll tell you whether the $1,500 review of your existing drafts is enough or whether the $2,750 launch package makes more sense.

Email me directly
Free triage

12 questions, one written gap report.

Before you pick a tier, run the Privacy Compliance Readiness Score. Score 0-100 plus a list of the failed items, mapped to CCPA, GDPR, vendor management, opt-out flow, and breach response. Score under 40 → the $2,750 launch package. Score 40-75 → the $1,500 review of what you already have. Score above 75 → quarterly maintenance.

Take the quiz →
07 · FAQ

Frequently asked questions.

Each answer resolves in one sentence before the expansion. Click any question for the full answer.

Does CCPA apply to my SaaS?
If you cross any one of three thresholds - revenue, consumer count, or revenue-from-sale percentage - yes.
CCPA/CPRA applies if your business meets any one of three thresholds: (1) annual gross revenue over $26.625M (2025 figure), (2) buying, selling, sharing, or receiving personal information of 100,000+ California consumers or households, or (3) deriving 50%+ of annual revenue from selling or sharing California personal information. SaaS companies most commonly cross the second threshold the moment they have a meaningful California user base, even pre-revenue. The $2,750 launch package includes a written threshold analysis tied to your business model.
Can I just use a free Privacy Policy generator?
You can publish one, but a misaligned policy is worse than no policy because it's a written representation regulators and plaintiffs can quote back at you.
Free generators routinely produce policies that misstate your data practices, list incorrect AG contact information, omit CPRA sensitive personal information disclosures, fail to include the mandatory CCPA Notice at Collection, and contain opt-out language that doesn't match your actual mechanism. The $1,000 review catches the worst of these defects and gives you a corrected draft you can publish.
What's the difference between a Privacy Policy and a DPA?
A Privacy Policy is your public-facing notice to consumers. A DPA is a contract between you and a vendor or B2B customer that allocates GDPR/CCPA responsibilities.
A DPA specifies who is the controller, who is the processor, what categories of data are processed, what security measures apply, and how international transfers are handled. The $2,750 launch package includes both because most B2B SaaS companies need both, and they have to be consistent with each other - a privacy policy that disclaims processing on behalf of customers while a DPA assumes it creates a contradiction enforcement actions have cited.
Do I need a CCPA opt-out link if I'm pre-revenue?
Possibly - pre-revenue does not exempt you from CCPA. Only the three thresholds do.
If you collect personal information from California users and you sell or share it with third parties (which includes most ad-tech and analytics integrations as currently interpreted by the CPPA), you need a "Do Not Sell or Share My Personal Information" link, a "Limit the Use of My Sensitive Personal Information" link if you process sensitive PI, and an opt-out preference signal (Global Privacy Control) honoring mechanism. The review tells you which links you actually need based on your stack.
What if my customers are EU residents?
GDPR applies extraterritorially when you offer goods or services to people in the EU/UK or monitor their behavior - that means a longer notice, a lawful basis for each activity, and probably an EU representative.
You need a GDPR-compliant privacy notice (longer and more specific than CCPA), a lawful basis for each processing activity, an EU representative if you don't have an EU establishment, Standard Contractual Clauses for international transfers, and a Data Processing Agreement template for your processors. The $2,750 launch package includes the GDPR layer when applicable; the EU representative engagement itself is a separate vendor service I can refer.
How long does the launch package take?
Five to seven business days for the first draft once I have your inputs.
Inputs I need: current Privacy Policy if any, current ToS, list of subprocessors, list of integrations, jurisdictions where you have users, and a one-paragraph description of your data flows. Two consolidated revision rounds are included. If you need a faster turnaround for a launch deadline, tell me at engagement and I'll price an expedited timeline separately.
Are you a California attorney?
Yes - California Bar #279869, licensed since 2011. I work with clients nationwide on privacy and ToS matters.
I'm Sergei Tokmakov, licensed in California (CA Bar #279869) since 2011. Privacy and ToS work is contract drafting and federal-statutory compliance, not state-specific litigation, so I work with clients nationwide. Engagement is via email and Zoom.
Live interactive demo

Try a HIPAA-aware contract workroom

If your privacy policy touches health data, HIPAA, or CMIA, see how I paper those obligations in practice. Change a breach-notice window or a marketing claim and watch the room flag the risk in real time: live preview with surgical yellow highlighting, click-any-clause comments, and track-changes style suggestions.

Open the live demo workroom How I build these for firms
Fictional demo data. Built by Sergei Tokmakov, Esq., California attorney and AI engineer.

Conversations on this topic

Real questions from the Terms.Law forum where founders, freelancers, and tenants worked through situations like yours.

Get the launch package started.

Email me your current Privacy Policy and ToS (or a note that you don't have one yet) plus a one-paragraph product description. I'll send back a scope confirmation and the PayPal invoice within one business day.

Email me to start →

Disclaimer. The information on this page is for informational purposes only and does not constitute legal advice. Reading this page or contacting me does not create an attorney-client relationship. Privacy and consumer-protection law is evolving rapidly - CPRA enforcement, CPPA rulemaking, FTC HBNR amendments, EU/UK divergence, and the patchwork of state comprehensive privacy laws all change the analysis - and any engagement is current as of the engagement date. Sergei Tokmakov is licensed in California (CA Bar #279869); privacy and ToS matters that don't require state-specific litigation are handled nationwide. Past results do not guarantee future outcomes.