Live data from Hacker News

Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

news.ycombinator.com

41–50 of 65 posts

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#41

I'm writing a TOS at the moment. Here's a question: has anyone ever heard of someone being sued for copyright violation for reusing parts of someone else's TOS or other posted legal document?

I have asked a lawyer this question. His response was: As for copyright over similar disclaimers, we, as attorneys have to use language that is acceptable as far as precedent and current law is concerned, thus, language will often be verbatim. Because of this there are no problems with copyright as far as the terms of use are concerned. The same principle is applied to real estate P&S contracts, as well as constructi…

In the UK I know it's not ok to e.g make a photocopy of a standard construction contract and, I'm guessing, any other type of contract where copyright is claimed by the author. In a contractual dispute, if it can be shown that you do not generally act in good faith, by infringing copyright in this case, it can be used as evidence to call into question your intention to carry out your obligations under the contract and therefore a judge could decide that the other party may be relinquished from thier obligations. UK contract law is pretty complicated though and IANAL by the way. Edited for clarity.

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#42
post #39
post #17

Great to see this discussion - I think that most contracts in many areas of law could be standardised. The same way that open source and creative commons licenses standardise those areas. A few of us are working on starting a non-profit to do that - taking the first small step of making an open UK employment contract. Anyone with a business in the UK who might be interested in using such a contract, do get in touch!…

> Great to see this discussion - I think that most contracts in many areas of law could be standardised. The same way that open source and creative commons licenses standardise those areas. In principle, this is a great idea. In practice, not so much. The problem with boilerplate contracts is that they're often unenforceable. In fact, simply having an IM conversation with someone in which you discuss and negotiate th…

In the UK most construction contracts are standardised. The most common construction contract is the Joint Contracts Tribunal Standard Building Contract. Also see New Engineering Contract. Architects use the RIBA Standard Form of Appointment and there are equivalents for other construction consultants. With all these contracts you must buy a copy of the contract every time you use it.

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#43
-------------------------------------------------------------------

Short answer to the question

Any of the current solutions to the Privacy Policy / TOS problem make you waste money and time. I've experienced this problem myself and decided to solve this hell of hassle once and for all, creating a privacy policy generator that is really compliant, with a company making money behind (and this grants quality), built to speak web designers' language (not lawyers' one), allowing to generate a fully-customized high-quality privacy policy within 3 minutes, by pressing a few buttons.

Here's the website: http://www.iubenda.com I'm the founder.

-------------------------------------------------------------------

-

# Small intro

As a web designer I've always faced this problem myself, that terrible hassle of getting rid of the privacy policy. Two years ago I told myself: why the hell nobody solves this problem once and for all? So, I started working on iubenda (http://www.iubenda.com), with the goal of giving any website owner in the world a way to generate a Privacy Policy without having to read a single legalese word.

After a whole year of thinking, another year of cust dev, a seed round and even the awesome Seedcamp experience, we are here to conquer the footer of every website in the world :P

To date we have 2k people waiting to try out the product, we're approaching 1M pageviews served by our privacy policy icon, we have 100 beta testers and we're able to generate a privacy policy both in English and Italian languages.

-------------------------------------------------------------------

-

# Why every solution mentioned is a mess (most of the times)

If you have to spend money and time on that boring document that nobody reads (aka privacy policy), the best you can hope is that the money is actually well spent.

The tough truth? Most of the times it's not, and I'll explain why.

-

## What are Privacy Policies about?

A Privacy Policy must inform the users visiting a website about the personal data collected, the use of those data, the parties involved (first and third parties) and few other minimal things.

The problem here is that every website is slightly different, different because is using different services collecting different data. Any web designer can get it, on some websites you put Google Analytics, on some others Google Analytics and Google Adsense, sometimes you use Mailchimp to manage a mailing list, and so on.

Now, the problem is that most of the privacy policies I read don't mention these services, making the privacy policy completely useless.

-

## So, you're basically telling me that I payed $1k for my privacy policy, and IT IS USELESS?

Yeah dude, the privacy policy can't be general, it must be specific, or it's just like not having a privacy policy at all. Of course you can fall into this hole while copy/pasting, while paying for a lawyer or while using a low-quality generator. Sometimes you may of course find a good lawyer or a good web company (like TRUSTe), but that kind of lawyer/service is usually expensive.

-

## Not every lawyer writes wrong privacy policies: here's a simple way to check yours

Try to ask your lawyer what a "cookie" actually is. Most will start talking about chocolate biscuits.

-

## So, what?

Since the world is never white or black, the Privacy Policy World is not about having or not having a privacy policy, there's a gray area in the middle: having a privacy policy that sucks. Sad but true, this is the most common situation.

-------------------------------------------------------------------

-

# Carrot after the stick

After analyzing this situation and getting to the conclusion above (privacy policies are expensive, and they even suck), I simply started working on a solution, and here I tell you what I did.

-

## Rethinking the Privacy Policy from scratch

The Privacy Policy model had to be rebuilt from scratch. The current model was a lawyer's parturition, but the only thing that lawyers are able to build is boring documents that nobody ever read. How can you accept such a state of things?

So I studied the law to extract the naked privacy requirements: personal data collected, use of those data, parties involved (first and third parties).

-

## Personal data

The personal data collected depend on the services used on the website, such as Google Analytics or Google Adsense. Other ways to collect data are the mailing list, the registration form, the comment system. All these uses are standardized, they're the same on every website. Since the web design world is moving fast to SaaS services, outsourcing most of the personal data collection, the standardization is even increasing.

-

## Use of the data

Another requirement for the Privacy Policy is the data collection purpose, but if the world is made of websites using standardized services, the purpose corresponds to the purpose of those services, like "analytics" or "advertising". Another point is gone.

-

## Parties involved

The website itself will always be an involved party, but what about the others? Wait, those SaaS services have a company behind, and that company is that third party we are looking for (such as Google for Google Analytics). Bingo!

-

## We have the ingredients, now the recipe

The next step was to put this all into a simple UI, allowing to generate a Privacy Policy with all the complexity hidden behind.

The good news is that we made it.

The model required a database made of privacy policy pieces referring to the standardized services (Google Analytics, etc), with some room for customization too (e.g. Registration forms don't always ask the same information). These pieces had to be assembled like a puzzle, and that's the reason why software exists.

-

## Who's more clever than me?

Ok, I'm kidding. The truth is that the process is simple, very simple, but quite powerful. And it generates beautiful privacy policies with nearly no effort. Completely awesome.

FYI, my cat on the keyboard says: "'0ììp"

-------------------------------------------------------------------

-

# SO WHAT?!

Ehm, I spent a whole hour writing this comment, you spent a few minutes of your valuable time to read.

Since our motto is "conquering the footer of every website in the world", I feel more or less like Brain from "Pinky and the Brain": - What are we going to do tonight, Brain? - The same thing we do every night, Pinky... Try and take over the world!

If you're interested in solving once and for all that hell of hassle of writing a privacy policy (w/ TOS coming soon), be sure to try out our product:

http://www.iubenda.com

(we're in private beta, but out moving fast)

Ah, of course we rely on a strong legal cofounder ;)

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#44
post #43

------------------------------------------------------------------- Short answer to the question Any of the current solutions to the Privacy Policy / TOS problem make you waste money and time. I've experienced this problem myself and decided to solve this hell of hassle once and for all, creating a privacy policy generator that is really compliant, with a company making money behind (and this grants quality), built t…

It looks good, but wouldn't it repel potential customers? Might be more effective to obfuscate all the data collection stuff. (Sorry, I don't like it myself, just wondering).

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#45
post #44
post #43

------------------------------------------------------------------- Short answer to the question Any of the current solutions to the Privacy Policy / TOS problem make you waste money and time. I've experienced this problem myself and decided to solve this hell of hassle once and for all, creating a privacy policy generator that is really compliant, with a company making money behind (and this grants quality), built t…

It looks good, but wouldn't it repel potential customers? Might be more effective to obfuscate all the data collection stuff. (Sorry, I don't like it myself, just wondering).

Privacy is about making people confident, about making people trust you. If people feel safe, they will share anything, and a clear privacy policy makes people feel safer.

TRUSTe reported several tests on this side, even Facebook had a huge benefit from changing the "privacy policy" policy to something more clear.

Just to tell something more on this side, we are working with http://dribbble.com/jonnotie to make our privacy policies not only useful, but even beautiful :) Stay tuned :P

Re: Poll: Where did you get your site/app's Terms of Service & Privacy Policy?

#48
It looks like a number of folks who use lawyers said they tried to cut costs by preparing the first draft and then having their lawyer look at it. Curiously, this can actually take a lawyer more time to review (and, hence, cost more money). I'd at least consider asking the lawyer for their base form that is the closest starting point for your business and working from that to prepare your first draft for their review.

Virtually any lawyer that does the same type of work repeatedly will have a set of base forms they usually start from. The cost benefit is that they don't have to review things in as much detail because they are already familiar with it (they essentially draft and review documents as diffs from their base form). If you give them a form they've never seen, they literally have to read (and understand) every word.

Post reply on HN