Privacy + Terms review for an AI SaaS adding de-identified data collection (California attorney)
Only freelancers located in the U.S. may apply.U.S. located freelancers only
Privacy + Terms review for an AI SaaS adding de-identified data collection (California attorney) Budget: open. Please propose your rate and an estimated number of hours. Pre-revenue California single-member LLC. We run a web app and API for LLM hallucination detection. We already have about 10 pages of Terms of Use, Privacy Policy, and a DPA / SCCs bundle drafted from reputable templates and cross-checked against peer policies. We have no users yet, so this is a clean slate. What we need reviewed: we are moving from a zero-retention stance to collecting and retaining prompt/response data from our US web-app users, de-identified, to improve the product. API traffic and EU/UK users stay zero-retention. We want a lawyer to pressure-test this posture and the disclosures before we turn it on. Core questions: • Is a "de-identified" (CCPA) claim defensible for machine-scrubbed free text, and how should we disclose the residual re-identification risk? We do not want to claim GDPR "anonymous." • FTC Section 5 exposure from setting this as our launch posture, given we have no existing users to grandfather. • Making de-identified collection a disclosed, mandatory condition of using the web app (no opt-out), with consent given by accepting the Terms at signup. Is that enforceable and not a dark pattern? • Collecting from US users only and excluding EU/UK to sidestep GDPR consent issues. Is that the right line? • Special-category data (health, etc.) that can appear in free text. How should we handle and disclose it? • A use-limitation we want to state: the data trains a classifier that produces a score, never a text-generating model, so it cannot be reproduced in any output. • A standard SaaS review of our existing Terms / Privacy / DPA: liability caps, indemnification, HIPAA/PHI prohibition, and CCPA disclosures. We also want a short, basic IP-safety check (a light touch, not a deep patent engagement): our founder is starting an outside contract role and wants simple assurance that the company's existing, already-patented, LLC-owned IP stays protected. Deliverable, in two parts: (1) your assessment of the questions above, delivered as written notes and followed by a call to talk them through; and (2) redline edits to our Terms of Use and Privacy Policy, and to the DPA where the retention change touches it, to implement the agreed posture. This is a review-and-revise engagement, not just a read-through, so please size your estimate accordingly (we'd guess several hours). The current drafts and a detailed question list are shared on hire. Requirements: licensed California attorney with privacy/data (CCPA and GDPR) and SaaS contract experience. Please include your rate and a rough hours estimate in your proposal.
- Hours to be determinedHourly
- < 1 monthDuration
- IntermediateExperience Level
- Remote Job
- One-time projectProject Type
Skills and Expertise
Activity on this job
- Proposals:Less than 5
- Last viewed by client:2 weeks ago
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- United StatesSan Diego4:45 PM
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by