Eliga Consultancy Services

Eliga Consultancy Services Contact information, map and directions, contact form, opening hours, services, ratings, photos, videos and announcements from Eliga Consultancy Services, Information Technology Company, London.

Fractional Counsel for Tech and SaaS Businesses
Eliga provides embedded in-house legal support to tech startups and SaaS businesses without the cost or rigidity of a full-time hire.

10/08/2026

The same contract. Three businesses. Three different answers.

A twelve person SaaS company, three weeks from closing a raise. The two clauses that matter are change of control and the IP position, because in ninety days a buyer's diligence will price exactly those, and a clause that lets this customer walk on acquisition is worth more than the contract itself.

An agency delivering the same scope through subcontractors. Completely different two. The flow down and the indemnity, because their real exposure sits with people they do not employ and cannot supervise on the day it goes wrong.

A company whose customer is regulated. Different again. Audit rights and the breach notification clock, because their customer's obligations land on them, and the clock they have agreed to downstream is shorter than the one they can actually meet upstream.

Same paper. Same clauses on the page. The risk sits somewhere different in each business, and no amount of reading the document tells you where.

That is the distinction we keep coming back to. A review reads the contract. Counsel reads the business, then reads the contract.

If the person advising you cannot name your funding timeline, your delivery model and who your customer answers to, they are not choosing your two clauses. They are choosing the average ones.

Book a consultation link in comments.

A Data Processing Agreement is easy to treat as the document you sign because someone in procurement asked for it.But a ...
09/08/2026

A Data Processing Agreement is easy to treat as the document you sign because someone in procurement asked for it.

But a DPA is really answering a much more important question:
WHO IS RESPONSIBLE FOR WHAT WHEN PERSONAL DATA MOVES BETWEEN TWO BUSINESSES?
And that opens up some very practical questions.
→ Who is actually the Controller and who is the Processor?
→ What data are we talking about?
→ What is the Processor allowed to do with it?
→ Who else can access it?
→ Where can the data go?
→ What security has actually been promised?
→ How quickly does the other party need to tell you about a breach?
→ And when the contract ends, where does the data go?

If your DPA answers those questions with phrases like "customer data", "industry standard security" or "as required", it may be worth looking again.

We have put the anatomy of a DPA into one practical Q&A covering 14 questions worth answering before you sign.

Read the full article link in comments.
Book a consultation link in comments.

The Anatomy of a Data Processing AgreementParts 5 & 6: the final stretchSub-processing & Transfers: know who else touche...
07/08/2026

The Anatomy of a Data Processing Agreement
Parts 5 & 6: the final stretch

Sub-processing & Transfers: know who else touches the data, and where it goes. A Sub-processor added quietly overseas can breach the agreement even if the work is fine, so get transfer safeguards in writing before data leaves the country.

Breach, Audit & Termination: the section everyone skips, until they need it. "Reasonable efforts to notify" is not a deadline. Insist on a specific window for breach notification, real audit rights, and a clear data return/deletion obligation at termination.

That's the full series: 6 parts, one contract, no more guessing what's actually in your DPA.

Book a consultation link in comments

The Anatomy of a Data Processing Agreement : Part 4"Industry standard security" says nothing. A DPA should name actual m...
07/08/2026

The Anatomy of a Data Processing Agreement : Part 4

"Industry standard security" says nothing. A DPA should name actual measures: encryption, access control, staff training, backups, monitoring, incident response matched to the risk level of the data, and reviewable.

✔ Technical measures named
✔ Organisational measures named
✔ Standard matches the risk
✔ Auditable

Book a consultation link in comments.

07/08/2026

The Anatomy of a Data Processing Agreement

Part 3 : Processing Instructions
Question: does your DPA say exactly what can be done with the data, or just imply it?

A Processor should only ever act on the Controller's documented instructions — not on assumption, not on "whatever makes sense."

A good DPA should clearly define:
✔ The purpose of processing
✔ The scope of what's covered
✔ The duration it applies for
✔ What happens if an instruction falls outside all of that

Vague scope today becomes a dispute later.

06/08/2026

The Anatomy of a Data Processing Agreement

Part 2 : Roles & Responsibilities
Question: does your DPA actually say who's who?

A Controller decides why and how data is processed. A Processor only acts on instructions. A Sub-processor is anyone the Processor brings in to help.

Mixing these up isn't just semantics, it moves liability. Call yourself a "processor" when you're actually deciding purposes, and you may have just taken on Controller-level risk.

A good DPA should clearly show:
✔ Who is the Controller
✔ Who is the Processor, and the limits of their instructions
✔ Which Sub-processors are permitted
✔ Whether new ones need sign-off first

Know your role before you sign.

Book a consultation link in comments.

06/08/2026

The Anatomy of a Data Processing Agreement

Part 1 : What is Personal Data?
Question: what exactly counts as personal data in a DPA?

Not just names and email addresses. Think about everything your business collects:
• Customer records
• Support tickets
• Usage analytics
• Payment information
• Device identifiers
• IP addresses

One of the biggest mistakes we see is describing data too broadly. If your agreement simply says "customer data," you're leaving room for confusion later.

A good DPA should clearly identify:
✔ What data is processed
✔ Why it is processed
✔ Who it belongs to
✔ How long it is retained

The clearer this section is, the easier procurement becomes.

Book a consultation link in comments.

04/08/2026

Before you sign anything, five checks that take an afternoon and catch most of what matters.

Read the liability clause against a real number. Write down the worst plausible failure, put a figure on it, then see whether the cap covers it. If the answer embarrasses you, that is the finding.

Find every indemnity and ask what triggers it. One that survives termination is an obligation you keep after the relationship ends.

Check who owns what after termination. Configuration, data, integrations, anything built during the engagement. Templates are vague here, and vagueness favours whoever has better lawyers later.

Say the data arrangement out loud. If you decide why personal data is used and how, you are a controller whatever the document is headed.

Name the clause you least understand. That is where to spend your money if you spend it once.

Book a consultation - Link in comments.
Read the full article - Link in comments.

03/08/2026

We ran 746 real legal buying questions through AI assistants.

The ten most cited sources are all regulators, software vendors or document services. Not one is a practice you can call.

A template is a starting position, not a negotiated agreement. It cannot read your risk, push back on a one sided clause, or sit in the room when the other side says no.

Information has never been cheaper. Judgement applied to your deal is the part that still costs something, and still matters.

Book a consultation with Dhruve Sennik link in comments.
Read more with an article we have just added link in comments.

hashtag hashtag hashtag hashtag hashtag

03/08/2026

We ran 746 real legal buying questions through AI assistants. Questions like "who reviews a SaaS contract", "what should we check in a client's DPA", "how much does a contract review cost".

Then we looked at which sources the machines cited back.

The ten most cited are all regulators, software vendors or document services. The ICO and NIST at the top, then Stripe, PandaDoc, DocuSign, LegalZoom, Clio, TermsFeed, Rocket Lawyer, Law Insider.

That is a real shift, and it is worth sitting with. When a founder asks an AI assistant for legal help, the answer that comes back is increasingly a document to download, not a person to talk to.

A template is not a bad thing. It is a starting position. But a starting position cannot read your commercial risk, cannot push back on a one-sided indemnity, and cannot sit in the negotiation when the other side says no.

The gap is not information. Information has never been cheaper. The gap is judgement applied to your specific deal.

If you are about to sign something because a template said it looked standard, that is exactly the moment to have counsel in the room.

Book a consultation link in comments.

Address

London

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when Eliga Consultancy Services posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share