The Terms & Conditions page combined the website and platform. It already covered accounts, acceptable use, human use, fair usage, AI accuracy, customer content, fees, availability, termination, liability and governing law. It excluded some indirect losses but did not set a financial liability cap or explicitly list the commercial outcomes that are not guaranteed.
The Privacy Policy covered accounts, project information, usage, enquiries, AI providers, transfers, retention, rights, security and cookies. It did not adequately distinguish website subscribers, AIO Fusion's own journalist database, customer-controlled information or paid disclosures of media contacts.
A Journalist privacy rights page and request flow already existed. These provide useful rights-handling functionality but do not substitute for a complete privacy notice, lawful-basis assessments, source permissions or indirect-collection transparency.
Cookies were mentioned briefly in the Privacy Policy. Google Analytics was loaded directly in the HTML before an app-level consent choice. There was no app-level category preference mechanism found during this review.
Separate Website Terms of Use, an expanded Privacy Policy, a Cookie Policy and this comparison/review pack are available for review. The existing platform terms remain accessible separately; these review documents do not automatically substitute a new contract.
The website draft expressly avoids guarantees of AI citation, rankings, coverage, journalist replies, traffic, leads, sales, revenue or return on investment. It distinguishes indicators and examples from promises of success.
Cookie controls keep optional Google Analytics off before acceptance, offer an equally accessible essential-only choice, store the choice, allow changes from the footer, and avoid a full-screen consent overlay.
The privacy draft distinguishes own-controller activity from customer-instructed processing, professional media sources and recipients, subscriber activity, rights and areas requiring factual confirmation. It removes unsupported blanket assurances rather than inventing provider contracts, transfer arrangements or deletion deadlines.
Suggested wording: AIO Fusion will provide the contracted service with reasonable care and skill, subject to the applicable agreement. It does not guarantee any particular search ranking, inclusion or citation in an AI answer, media coverage, journalist response, publication, traffic, lead, sale, revenue, return on investment or other business outcome.
Suggested wording: Audits, scores, recommendations, contact relevance and AI-generated material are indicative outputs based on the information and methodology available at the time. They are not certifications, guarantees or substitutes for professional judgement. AI outputs and source information may be inaccurate, incomplete or outdated. Customers must review and verify material before publication or outreach.
Suggested wording: Results depend on factors outside AIO Fusion's control, including third-party models and services, search systems, editorial decisions, competitors and customer implementation. Nothing in this clause removes an express service commitment, agreed remedy or liability that cannot lawfully be excluded.
Apply approved wording consistently to the platform agreement, order forms, sales materials, demos and any customer-facing claims. A disclaimer cannot cure a contradictory promise elsewhere.
Preserve express carve-outs for death/personal injury caused by negligence, fraud/fraudulent misrepresentation and liabilities or statutory rights that cannot lawfully be excluded or capped. Privacy notices must not require individuals to waive data-protection rights.
For business contracts, propose exclusions for indirect or consequential loss and carefully defined business losses, subject to applicable law and reasonableness. The adviser must assess losses that might be direct, insurance, standard-term incorporation and whether an exclusion would defeat the service's core obligation.
Discussion proposal only: an aggregate general cap linked to fees paid or payable for the affected services during the preceding 12 months, with a separately agreed minimum for free/beta or low-fee services. No amount or multiplier has been approved. The cap should be a clearly defined aggregate over an agreed period, not an unlimited reset per claim.
Consider whether confidentiality, data-protection/security or intellectual-property liabilities require a separate higher cap, an indemnity or a different treatment. Do not assume those liabilities can all be put under a very low general cap. Regulatory fines and third-party statutory rights need specific advice.
Any indemnity for customer-uploaded unlawful material or misuse should be proportionate, tied to customer responsibility and subject to reasonable claims-handling, mitigation and allocation of responsibility. Do not add an unlimited blanket indemnity without advice.
Fair usage, automatic suspension, refunds, termination and data return/deletion provisions also need review. Customer negligence or poor implementation should not become a blanket excuse for AIO Fusion's own breach. Consumer rights cannot simply be removed by calling everyone a business user.
Confirm corporate details, target jurisdictions, whether customers are exclusively businesses, contractual acceptance and the hierarchy between website terms, platform terms, order forms and a data-processing agreement.
Complete legitimate-interests assessments for the journalist database, source/licensing checks, the indirect-collection notification approach and any documented exemption; assess whether a DPIA is appropriate. Review profiling and customer access/outreach terms.
Confirm actual suppliers and subprocessors, AI retention/training terms, payment-provider roles, hosting locations, transfer mechanisms and supporting contracts. The code alone cannot establish these.
Approve retention and deletion schedules and check that rights-request, correction, suppression and backup procedures can meet them. Confirm ICO registration/fee obligations, privacy responsibility and whether any representative or DPO requirement applies.
Review marketing opt-in and unsubscribe handling before launching insights subscriptions; distinguish corporate contacts, sole traders and individual subscribers where relevant.
Check the deployed cookie inventory, consent expiry, rejection and withdrawal, linked Google account settings, third-party embeds, proxy/hosting technologies and any region-specific requirements.
Approve the no-results wording, exclusions, cap structure and insurance alignment. Obtain legal sign-off before converting review drafts into adopted agreements; plan customer notice or renewed acceptance for material changes.
This comparison was based on the project implementation and current public policy components, not a complete production cookie scan, supplier-contract audit, independent security audit or legal opinion. Drafting alone does not make a business compliant.
The preparation consulted current ICO guidance on the right to be informed, legitimate interests and storage/access exceptions, plus sections 2 and 11 of the Unfair Contract Terms Act 1977. The updated ICO guidance recognises a conditional statistical-purpose exception; the proposed implementation uses opt-in instead of assuming that exception applies.
No review email has been sent, no final liability cap has been agreed, and a review badge does not by itself determine whether a publicly displayed term would have legal effect. A qualified adviser should approve both wording and publication/acceptance arrangements.