Terms of service and privacy policies should be updated whenever the business changes
Hello, this is Legal Agent.
One of the things startups most often leave behind is their terms of service and privacy policy. A company drafts them once, at incorporation or launch, and the wording often stays untouched long after the service itself has moved on: pricing changes, a corporate plan gets added, users start posting content, an external AI service comes into use, data starts sitting on an overseas cloud. Sales materials describe the new features while the terms and privacy policy still describe the old business.
This is not simply an outdated document sitting around. Terms of service set out what the provider offers, what it prohibits, and how far its liability goes; a privacy policy tells users why personal data is collected and how it is used or shared. Both need to track the actual business.
When the business changes, the terms need to change too
Terms of service reflect where the service currently stands. Moving from a free beta to paid SaaS raises questions about pricing and cancellation; selling to corporate customers brings in admin accounts and permissions. A service where users post content needs rules on ownership and takedown, and a generative AI feature raises questions about input data and whether it is used for training. Every new feature or pricing change should trigger a check of which clauses it touches, not a one-time draft left alone.
Standard-terms rules and the amendment process
Posting a new version on the website does not automatically bind every existing user. Under the Civil Code, terms meeting the definition of standard terms (定型約款) can be amended within certain limits, but only where the change serves users' general interest, or is reasonable and consistent with the contract's purpose given the content and how it is announced. Changes to pricing, liability limits or cancellation terms, in particular, may call for individual consent or a longer notice period. This is hard to judge from the draft text alone; it needs looking at the service, the users and the business reason behind the change to design the process. Sales, product and management sometimes change terms on their own judgment at a startup, so legal should check the notice to users, sales materials and the cancellation flow together with the substantive change.
Consumer law and e-commerce rules narrow what terms can say
For a consumer-facing service, freedom to draft terms narrows further. The Consumer Contract Act allows rescission for improper solicitation and voids unfair contract terms, so a clause broadly disclaiming liability or imposing excessive burdens on a consumer may not hold up even if it is written into the terms. For e-commerce and subscriptions, disclosures under the Act on Specified Commercial Transactions and the design of the final confirmation screen matter too, including whether users can confirm price and cancellation terms right before ordering. Clean terms alone are not enough if the actual signup screen, ads or payment flow contradict them, so review should check the screens a user actually goes through, not only the document.
A privacy policy should reflect the actual data flow
A privacy policy is not just a template to fill in either. The APPI requires specifying the purpose of use as precisely as practicable, and generally requires disclosing that purpose in advance when personal data is collected directly and in writing from the individual, with different considerations for third-party provision or outsourcing. The APPI is reviewed roughly every three years, and a 2026 amendment bill introducing an administrative fine system is before the Diet as of this writing, so practical requirements may still change.
A startup's data flow tends to shift substantially as the business grows, from a simple contact form to a CRM, analytics and generative AI, sometimes including job applicant or business contact information. Reviewing a privacy policy works better starting from a data map than from the text itself: which screen collects whose information, who inside the company sees it, which SaaS tools it goes to, whether it sits on an overseas cloud, whether it feeds advertising or profiling, and whether it is simply outsourced or amounts to third-party provision. Editing the wording without checking this leaves a policy that does not match reality.
Input data and training use for AI features
Adding a generative AI feature to an existing service raises the question of where user input, possibly including internal documents, is sent, how it is stored, and whether it is used for training, which depends on whether the company runs its own model or uses an external API and how that provider's terms treat the data. Where users might input confidential business or personal information, prohibited inputs, security measures and a contact point should be spelled out clearly. An AI feature looks like one convenient addition on the product side, but legally it touches personal data, copyright and liability limits at once, so it should trigger a review of every related document at the time it launches.
Keep sales materials consistent
A common gap sits between the terms and what sales actually says: the terms reserve the right to change the service while a sales deck promises a feature is permanent, or support is "best efforts" in the terms but a proposal promises a 24-hour response. These gaps become real problems during negotiation or a dispute, so legal review should cover proposals, help pages and email templates too, especially once the sales team grows around Series A.
A checklist for reviewing terms and privacy policy
- do the service, pricing, contract term and cancellation method match actual operations?
- are admin accounts, sub-processing and support scope defined for corporate use?
- do the terms reflect user posting, file uploads and any AI feature?
- are prohibited conduct, suspension, deletion and change-of-service clauses workable in practice?
- do consumer-facing disclaimers hold up under the Consumer Contract Act?
- does the final confirmation screen match disclosure requirements for e-commerce and subscriptions?
- does the stated purpose of use match what is actually collected and used?
- have outsourcing, joint use, third-party provision and overseas transfers all been identified?
- is there a plan for reporting, notifying individuals and internal response if a breach occurs?
- do sales materials, FAQs, landing pages and signup and cancellation screens match the documents?
No single team can complete this alone; it needs input pulled together from product, sales and IT.
Treat this as ongoing change management, not a one-off delivery
LegalAgent treats terms of service and a privacy policy not as documents delivered once but as operating documents that update alongside the business: checking impact before a new feature launches, confirming how a price change applies to existing users, reviewing input data before an AI feature ships, and checking consent before an ad strategy changes. A one-off fix just drifts out of date again at the next business change, so having outside counsel support these decisions continuously, close to an internal legal team, is a more realistic structure for a startup.
Terms of service and a privacy policy mirror the business itself. Where the service has changed but the documents have not, a gap between practice and law has likely opened up somewhere.