Agreements · version 0.1.0 · effective: DRAFT

Standard Agreement for Small-Business AI and Managed Services (v0.1 draft)

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

In one line

A proposal for a short, open, plain-English standard contract between a small business and any AI or managed-services provider, built like Y Combinator's SAFE: one cover sheet of choices, fixed standard terms, and country modules.

The short version

This short version helps you understand the full text. Read the full text for the complete terms.

  • Small businesses sign long, one-sided contracts they cannot afford to check. A short public standard would cut cost, build trust, and speed decisions. (Full text, part A)
  • Y Combinator's SAFE shows the model: one short document, a few variables, published openly, versioned, with extras in side letters. (Part B)
  • Our proposal: a one-page Cover Sheet with about 12 choices, fixed Standard Terms that nobody edits, and a module for each country. (Part C)
  • We propose to publish it under Creative Commons Attribution 4.0 (CC BY 4.0), with a rule that only unmodified text may use the standard's name. (Part D)
  • Versions are numbered and dated, changes are explained in public, and anyone can comment. (Part E)
  • The v0.1 draft is below. It is a starting point for counsel and for comment, not a finished contract. (Part G)

Full text

Read the full text (about 9 minutes)

Part A. Why a standard helps

Cost. A café or a plumber cannot pay a lawyer to read a 30-page agreement for a €50-a-month service. A standard document only needs expert review once, by many people, and then everyone benefits.

Trust. If the terms are public and the same for everyone, the owner knows the provider has not hidden anything special in their copy. Differences live only on the Cover Sheet, where they are easy to compare.

Speed. When both sides know the standard, the only questions are the Cover Sheet choices. A deal can close in minutes, not weeks.

Fair defaults. A standard can set fair defaults for things small businesses rarely negotiate: who signs off on AI output, data export when you leave, and liability that is not one-sided.

Comparability. Owners can compare providers on price and service, not on legal fine print.

Part B. What the SAFE teaches

The SAFE (Simple Agreement for Future Equity) was created at Y Combinator by partner and lawyer Carolynn Levy and announced in December 2013 as a replacement for convertible notes. Lessons we take from it:

  1. Short and standard. YC describes it as one short document where usually the only term to negotiate is the valuation cap (ycombinator.com/documents).
  2. Published openly, free to use. YC published the standard document for all startups to use, not only its own (YC blog, "Announcing the Safe"; TechCrunch, 6 December 2013).
  3. Few variables. Each form differs only by a small number of filled-in terms (valuation cap, discount, or MFN) (ycombinator.com/safe).
  4. Extras go in side letters. YC advises keeping the SAFE unmodified and putting agreed extras (for example, pro rata rights) in a separate standard side letter (YC FAQ, ycombinator.com/documents).
  5. Versioned, with reasons. In 2018 YC replaced the original "pre-money" SAFE with the "post-money" SAFE and published a user guide explaining what changed and why (Primer for post-money safe v1.1).
  6. Local versions, honestly labelled. YC offers versions for Canada, the Cayman Islands, and Singapore, and tells users to consult a lawyer licensed in the relevant country (ycombinator.com/documents).
  7. A respected publisher. Adoption followed because YC used it for every company it funded, starting with its Winter 2014 batch (TechCrunch).

What differs for us: a SAFE has two sophisticated parties and one event (conversion). A services agreement runs for years, involves personal data, and often has a small business that the law may treat like a consumer. Our standard must therefore carry more mandatory protections, and more country modules.

Part C. Proposed structure

  1. Cover Sheet (variables). One page. The only place the parties make choices.
  2. Standard Terms (fixed). About 12 short sections in plain English. Never edited. Incorporated by reference with a version number.
  3. Country Modules. Short add-ons that adapt the Standard Terms to mandatory local law (US, Canada, UK, EU, Switzerland, Singapore, Australia, and New Zealand). The Cover Sheet names the module.
  4. Engine or Service Schedule. What exactly is provided (for example, "3 social posts a week, signed by the Customer").
  5. Standard Side Letters (optional). Outcome pricing, service credits, extra security, or data residency. Each is a fixed text with its own few variables.
  6. Data Processing Addendum. A standard DPA, also fixed, with the transfer clauses for each region.

Part D. Licence for publication

Recommendation: publish the text under CC BY 4.0, which lets anyone use and adapt it with attribution. Add a short naming rule: only unmodified Standard Terms may be described as "the Standard Agreement vX.Y". Modified versions must drop the name and say they are modified.

Why not CC BY-ND (no derivatives)? It protects the standard but blocks local lawyers from improving it. The naming rule protects the standard while allowing improvement. YC's own SAFE forms carry a Creative Commons licence; counsel should confirm its exact terms before we cite it as a precedent.

The name itself should be checked for trademark conflicts before launch.

Part E. Governance and versioning

  • Semantic versions. v0.x drafts; v1.0 first recommended version. Minor versions (1.1) clarify; major versions (2.0) change rights or duties.
  • Public change log with the reason for every change, as the SAFE primer did.
  • Open comment on each draft for at least 60 days, through a public repository and email.
  • Advisory panel: at least one practising lawyer per country module, two small-business owners, a consumer or small-business advocate, and two providers other than qypu. qypu should not hold a majority.
  • Stewardship: start at qypu; move to a neutral body (for example, a foundation or an industry association) once at least 3 other providers adopt it.
  • No forced upgrades. A signed agreement stays on its version until both parties agree to move.

Part F. Risks

RiskMitigation
One text cannot fit 8 legal systemsCountry Modules; local counsel review; honest labelling of what is not covered
Seen as a qypu sales toolNeutral governance; CC BY licence; other providers on the panel
Users rely on it without adviceClear notice: "Standard text; consider advice"; plain Cover Sheet guidance
Out-of-date lawAnnual review; dated modules; change log
Liability for the authorsDisclaimer of responsibility for use; no legal advice given
Competition law (standard terms among competitors)No pricing coordination; counsel review of governance
Unfair terms laws (AU, NZ, UK, EU)Balanced defaults; caps and termination rights reviewed per module

Part G. v0.1 draft — DRAFT, requires review by qualified counsel in each jurisdiction

G1. Cover Sheet

#VariableChoice
1Provider[Name, address, company number]
2Customer[Name, address, company number or sole trader]
3Service Schedule[Attach: what is delivered, how often, which channels or systems]
4Start date and term[Date] · [Monthly rolling / 12 months]
5Who signs output[Named Customer approvers; default: every public output needs Customer sign-off]
6Fees[Fixed: amount per period] or [Outcome: Side Letter A]
7Payment terms[Default: monthly in advance, 14 days]
8Liability cap[Default: greater of 12 months' fees or a stated amount]
9Notice to end[Default: Customer 30 days; Provider 60 days]
10Data location[Default: as listed by Provider; or Side Letter C]
11Country Module[US-[state] / CA-[province] / UK / EU-[member state] / CH / SG / AU / NZ]
12Standard version[v0.1]

G2. Standard Terms

1. What this is. These Standard Terms, the Cover Sheet, the Service Schedule, the Country Module, any Side Letters, and the DPA form one agreement. If they conflict, this order applies: Country Module, Cover Sheet, Side Letters, DPA (for personal data), Standard Terms, Service Schedule.

2. The service. The Provider delivers the service in the Service Schedule with reasonable skill and care, and tells the Customer promptly about anything that will stop it doing so.

3. Who decides (editorial responsibility). The Customer decides what is published or acted on in its name. The Provider must not publish, send, pay, or commit on the Customer's behalf without the sign-off named in Cover Sheet item 5. The Provider keeps a record of each sign-off.

4. AI use and disclosure. The Provider tells the Customer which parts of the service use AI and which AI providers process Customer data. The Provider labels AI-generated content where the law or the platform requires, and never removes provenance marks. The Provider does not use Customer data to train AI models unless the Customer opts in on a separate signed form.

5. Customer data. The Customer owns its data and content. The Provider uses them only to provide the service. The DPA applies to personal data. The Provider keeps a public list of subprocessors and gives 30 days' notice of changes.

6. Security. The Provider keeps security measures appropriate to the risk, publishes a plain description of them labelled "in place" or "planned", and tells the Customer about a breach affecting Customer data without undue delay and within 72 hours of confirming it.

7. Fees. The Customer pays the fees on the Cover Sheet. The Provider may raise fees only with 60 days' notice, and the Customer may end the agreement before the increase applies.

8. Accounts and access. Accounts, domains, and channels belong to the Customer and stay in the Customer's name. The Provider uses delegated access (such as OAuth or user roles), never the Customer's personal passwords, unless the Customer agrees in writing.

9. Liability. Neither party limits liability: for fraud; for death or personal injury caused by negligence; or for anything else the law does not allow to be limited. Otherwise each party's total liability in any 12 months is limited to the cap on the Cover Sheet, and neither is liable for indirect loss or lost profits.

10. Ending the agreement. Either party may end the agreement with the notice on the Cover Sheet, or at once if the other materially breaches and does not fix it within 14 days of notice.

11. Exit and data portability. On any ending, the Provider: gives the Customer at least 30 days to export all Customer data in a common, machine-readable format, free of charge; hands back control of every account and channel; helps for up to 30 days with a reasonable handover to a new provider at no more than cost; then deletes Customer data and confirms in writing, except for data the law requires it to keep.

12. Changes and general. These Standard Terms change only by a new version. Signed agreements stay on their version until both parties agree in writing. Notices are by email to the addresses on the Cover Sheet. Neither party may transfer the agreement without consent, except with a sale of its whole business.

G3. Country Modules (outline)

  • US: governing law of the Customer's state by default; CCPA service-provider terms in the DPA; state auto-renewal rules for renewals; no class-action waiver by default.
  • Canada: law of the Customer's province; PIPEDA and provincial privacy terms; Quebec Law 25 transfer assessment; French-language version available for Quebec customers (Charter of the French Language).
  • UK: law of England and Wales (or Scotland or Northern Ireland, at the Customer's choice); UK GDPR and the IDTA or UK Addendum; terms reviewed for reasonableness under the Unfair Contract Terms Act 1977.
  • EU: law of the Customer's member state; GDPR and SCCs; EU Data Act switching terms (notice, export, and charges); AI Act Art. 50 disclosure duties allocated.
  • Switzerland: Swiss law; revFADP; Swiss SCC amendments.
  • Singapore: Singapore law; PDPA terms, including 3-day breach notice support.
  • Australia: law of the Customer's state or territory; Australian Consumer Law guarantees preserved; unfair contract terms review for small-business contracts; Privacy Act APP 8.
  • New Zealand: NZ law; Consumer Guarantees Act and Fair Trading Act preserved where they apply; Privacy Act IPP 12.

G4. Standard Side Letters (outline)

  • A. Outcome pricing: baseline, measurement method, share, cap, measurement period, audit right, and dispute resolution by an agreed independent expert.
  • B. Service credits: targets and credits as a percentage of monthly fees.
  • C. Data residency: named regions and the consequences of change.

Change log

  • 2026-10-10 · 0.1.0 · First public draft for comment and counsel review.

Open questions for counsel

We publish these while the page is a draft, so you can see what is not settled yet.

  • Whether a single standard can be "fair" under unfair-terms regimes in Australia, New Zealand, the UK, and the EU without module-specific rewrites.
  • Competition law review of multi-provider governance.
  • Trademark clearance of the standard's name; licence choice (CC BY 4.0 plus naming rule versus CC BY-ND 4.0).
  • Confirm the licence actually used by YC on current SAFE forms before citing it.
  • Liability disclaimer for authors and stewards of a published standard.

Useful for: Business owners, IT and security reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.