Launch in the EU — and hold up when customers, regulators and investors check.
Legal counsel for SaaS & AI companies entering the EU market — the contracts, GDPR and AI Act work that deals and audits hinge on.
Fixed prices·Plain English·No billable-hour games
30 minutes · no pitch · you leave with a plan
7+ years in-house at international tech & telecom · CIPP/E certified (IAPP)
Who I work with
If one of these is you, we should talk.SaaS founders selling to EU customers
B2B or B2C — if your users are in the EU, European law applies to you, wherever you're incorporated. Most US-template legal docs don't survive contact with it.
AI products generating content
Video, image, audio, or text generation for EU users triggers marking and disclosure duties from August 2026. I scope exactly what Art. 50 requires from your product — and cover the GDPR layer, which for GenAI products is usually the harder part.
Ukrainian & CEE tech expanding west
Entering the EU or US market and need the legal layer done right the first time — in your language, at sane prices, by someone who's done it from the inside.
Teams without a full-time lawyer
Senior legal support on demand — contract reviews, privacy questions, vendor DPAs — without the cost of a hire.
Services & fees
Fixed prices and a written scope agreed before work starts. Every project includes one revision round, a handover call, and 14 days of follow-up questions.EU Market-Entry Package
Everything you need to sell to EU customers without a regulatory blocker — in four weeks.
Regulatory mapping (GDPR roles, AI Act applicability screening, ePrivacy), geo & sanctions scope, structuring flags (Art. 27 representative, EU entity, VAT), the core document set, and a written 6–12 month roadmap.
SaaS Legal Pack
The documents your users accept at sign-up — and your enterprise buyers check before signing.
ToS aligned with EU consumer law, GDPR-compliant Privacy Policy, Cookie Policy, AUP, and a standard DPA — plus a practical memo on liability and key risks.
GDPR Compliance Audit
Know exactly where you would fail a regulator or an enterprise security review — and what to fix first.
A review of how your company actually handles personal data — lawful bases, ROPA, vendor DPAs, data subject rights, transfers — with risk-ranked findings and a remediation roadmap. DPIA, if required, is scoped separately. Not sure where you stand? Try the free interactive self-check →
Commercial Contract Review & Drafting
Senior review or drafting of your commercial documents — MSAs, SaaS agreements, SLAs, vendor and partnership contracts, NDAs and other commercial contracts — with markup and plain-language recommendations. Optional add-on: counterparty sanctions screening (EU · OFAC · UK).
DPA Review & Drafting
Data Processing Agreements reviewed or drafted with the annexes done properly — technical and organisational measures, sub-processor terms, transfer mechanics. Cross-border transfers needing SCCs and a transfer impact assessment are the usual scope extension.
Data Protection Impact Assessment (DPIA)
A regulator-ready DPIA for a specific processing operation: description of the processing, necessity and proportionality, risks to individuals, and mitigation measures — following the EDPB methodology. Usually commissioned after an audit flags the need.
AI Transparency Compliance Check (EU AI Act)
Your product mapped against Art. 50 by a lawyer: which duties actually attach to you as provider or deployer, where the gaps are, and the exact disclosure texts to implement. Delivered as a written memo you can show to an enterprise customer, an investor or a regulator — the free checklist tells you the rules, this tells you where you stand. Included in the EU Market-Entry Package as a screening step.
Policy Review & Upgrade
A legal review of the customer-facing documents you already have — ToS, Privacy Policy, Cookie Policy, AUP, Refund Policy — against EU requirements: a redline plus a short memo on what needs fixing and why.
Need three or more documents? The SaaS Legal Pack covers ToS, Privacy, Cookie, AUP and a DPA at better value. Already have documents? Review & upgrade — from $300 per document (§8).
Other documents — SLA, EULA, beta and trial terms, referral and affiliate terms, community guidelines, DMCA/takedown policy — from $250 to $700 depending on complexity. Email the details and get a fixed quote within 24 hours →
- 6 hours per month
- Ad-hoc questions & simple reviews
- Response within 2 business days
- 17 hours per month
- + drafting, DPAs, negotiations
- Response within 1 business day
- 27 hours per month
- + privacy operations: ROPA, DPIAs, incidents, vendor reviews
- Same-day response
The monthly fee is fixed. Hours show how much work each plan covers — anything beyond it gets a fixed price agreed before I start. Cancel with 30 days’ notice.
Not sure which one fits? Answer a few quick questions →
Document work? Skip the call.
For contract reviews, DPAs, and policy work, email the document (or a link) with two lines of context — you get a fixed quote within 24 hours. No call required; the quote is binding once you confirm scope.
Email for a fixed quote →Find your package
Four questions, 60 seconds. You get a recommendation and a starting price — the exact quote comes after a short call.Building a team in Ukraine?
Ukraine runs a special legal regime for tech companies — Diia City: 9% tax on distributed profit, flexible gig contracts with IP assignment built in, and a straightforward path for foreign founders through a Ukrainian entity. I handle residency end-to-end — eligibility audit, application, gig-contract templates, and the internal paperwork.
Ask about Diia City on a callFree tools
Two self-checks you can run before talking to anyone — including me.AI Act Transparency Checklist
Does Art. 50 apply to your product, and does it meet obligations that are already in force? A 15-minute self-check: five triggers, scenario-by-scenario items, and the red flags that mean you need more than transparency work.
Download the checklist (PDF)Fillable PDF · no email required.
Want me to email you when the rules change? Leave your address — optional, and used for nothing else.
Noted — I’ll write only when Art. 50 changes.
GDPR Self-Check
An interactive gap analysis: 40 items across 10 areas — scope, data mapping, ROPA, lawful bases, vendors, data subject rights, transfers, DPIA. Mark each item red, yellow or green, export the summary, and bring it to a call.
Open the self-check →No email required. Your marks stay in your browser.
How it works
Intro call — free, 20 min
You describe the situation. I tell you honestly whether and how I can help — and what it costs.
Fixed quote in 24h
A one-page proposal with scope, timeline, and price. No hourly surprises, ever.
Delivery
Documents and advice in plain language — built for founders, not for other lawyers.
Support
Handover call plus two weeks of follow-up questions included in every project.
Why me
I've spent 7+ years as in-house counsel at international CPaaS and telecom companies — sitting on the client's side of the table. I know what businesses actually need from a lawyer: decisions and documents, not 40-page memos.
- CIPP/E certified (IAPP) — the global standard for European data protection
- Hands-on with GDPR, DPAs, SCCs, and cross-border transfers daily since 2019
- Practical sanctions-screening experience (OFAC, EU, UK)
- Fixed prices, fast turnaround, direct communication — no associates in between
Questions founders ask
Are you qualified to advise on EU law?
I advise on GDPR and EU regulatory compliance as a compliance consultant with CIPP/E certification and years of hands-on EU privacy work for international companies. This work doesn't require admission to an EU bar. For matters that do — litigation, formal legal opinions for regulators — I bring in local counsel from my network and coordinate the process.
We're not based in the EU. Does this even apply to us?
If you have users in the EU — yes. GDPR applies to anyone offering services to people in the EU (Art. 3(2)), and the AI Act follows the same logic for AI systems whose output is used there. Where you're incorporated doesn't shield you.
What if my project doesn't fit these packages?
Most don't fit perfectly. Book a call — I'll scope it and give you a fixed quote within a day.
We already have a lawyer.
That's good — most of my clients do too. I usually come in for the EU-specific layer (GDPR, AI Act) that general counsel often outsources anyway. A second pair of senior eyes on EU compliance is cheap insurance.
Do you cover the full AI Act?
My AI Act work is focused on Article 50 — the transparency, marking, and disclosure duties for AI-generated content that apply from 2 August 2026. That's what most SaaS and GenAI products actually face right now, and I've handled it hands-on. High-risk system classification and conformity assessments are a different discipline: if that's your situation, I'll say so on the intro call and can bring in a specialist from my network rather than learn on your budget.
Can a foreign founder use Ukraine's Diia City regime?
Yes. Diia City residency requires a Ukrainian legal entity, but its founders and beneficiaries can be foreign — setting up the entity is part of the scope. The regime offers 9% tax on distributed profit and flexible gig contracts with IP assignment built in. If you're weighing it as part of your setup, we'll cover it on the intro call.
How do I know if my company has GDPR gaps?
Start with the free interactive GDPR self-check — 40 items across 10 areas, from scope and ROPA to transfers and DPIA. Mark what's in place, export the summary, and you'll see your gaps in about 15 minutes. If the red column worries you, that's exactly what the GDPR Compliance Audit turns into a prioritized remediation plan.
Does the GDPR audit include a DPIA?
No — by design. The audit determines whether any of your processing operations require a Data Protection Impact Assessment; the DPIA itself is a separate, fixed-price piece of work (from $900). That keeps the audit price honest for the majority of companies that don't need one.
Why “from” pricing?
Each base price covers a defined scope, described in the service itself. If your situation adds scope — extra products, B2C consumer law, cross-border transfers needing SCCs — the quote goes up, and the proposal lists exactly which factors shaped it. You always get a fixed number before work starts, never an hourly meter.
You're based in Ukraine — how do you ensure continuity?
Fair question. The practice runs cloud-first: documents, communication, and files live in redundant cloud services, with backup power and connectivity at the workplace. Deadlines are agreed in writing before work starts and are treated as contractual. In 7+ years of in-house work through 2022–2026, client deadlines were kept — that standard carries over here.
Our enterprise customers ask for internal policies — can you help?
Yes. Procurement questionnaires and investor due diligence often ask for a Code of Conduct, anti-bribery and whistleblowing policies, an information security policy, or a data retention policy. This isn't a fixed package — the right set depends on your headcount, market and who is asking, so it's scoped individually after a call. Bring the questionnaire you were sent and we'll work from it.
How do payments work?
Fixed fee agreed upfront. Smaller projects are paid on signing; larger ones split 50% to start, 50% on delivery. Retainers are billed monthly in advance. Invoices in USD or EUR.
Launching in the EU? Building with AI?
A 30-minute call is enough to know where you stand. No pitch — just useful answers.
Book a free intro call