legal-scaffold

Generate multi-jurisdiction SaaS legal document drafts from project facts.

3|2|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/robotijn/ctoc --skill legal-scaffold
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: legal-scaffold
Source: https://github.com/robotijn/ctoc/tree/main/skills/saas/legal-scaffold
Command: npx skills add https://github.com/robotijn/ctoc --skill legal-scaffold

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SaaS founders operating across multiple jurisdictions (EU, UK, Canada, Quebec, US) face complex, ever-changing legal requirements for mandatory documents like privacy policies, terms of service, and cookie policies. Hiring a lawyer to draft these from scratch is expensive and time-consuming, while generic templates often fail compliance audits and expose the business to regulatory penalties.

Core Features & Use Cases

  • Multi-jurisdiction legal document generation: Creates drafts of all required legal documents (Privacy Policy, Terms of Service, Cookie Policy, DPA, AUP, subprocessor list, data retention schedule, AI disclosure, accessibility statement) tailored to the project's fact set and target regions.
  • 2026 regulatory compliance: Incorporates latest requirements including Quebec Law 25 portability rights, EU AI Act Article 50 transparency obligations, DSA terms clarity rules, and CCPA/CPRA provisions to avoid outdated or non-compliant drafts.
  • Production integration guidance: Includes ready-to-use code examples for serving legal documents via web routes in Next.js, FastAPI, and .NET, plus a checklist of common compliance pitfalls (missing cookie consent banners, absent right-to-delete UI, etc.) to avoid audit failures.
  • Use case: A solo founder building a subscription SaaS with EU users can generate all required legal drafts in minutes by providing their project name, domain, billing model, data collection practices, and AI usage details, instead of spending weeks researching global regulations.

Quick Start

Provide your SaaS project details including name, domain, billing model, data collected, AI usage, and target regions to the legal-scaffold skill to generate ready-to-review drafts of all required legal documents.

Frequently Asked Questions about legal-scaffold

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate GDPR compliant privacy policies and terms of service for a SaaS application?

Generate GDPR compliant privacy policies and terms of service by providing a minimal project fact set including your SaaS name, domain, billing model, data collection practices, and target jurisdictions. The tool outputs tailored legal drafts meeting EU, UK, Canada, Quebec, and US regulatory requirements.

What legal documents do I need for a SaaS product with users in the EU and California?

SaaS products with EU and California users require privacy policies, terms of service, cookie policies, data processing agreements, acceptable use policies, subprocessor lists, data retention schedules, AI disclosures, and accessibility statements to meet GDPR, CCPA/CPRA, and DSA compliance obligations.

How to serve generated legal documents like cookie policies in a Next.js or FastAPI application?

Serve generated legal documents in Next.js or FastAPI applications using included production-ready code examples for web routes. The tool provides integration guidance and highlights common compliance pitfalls, such as missing cookie consent banners, to help avoid audit failures.

Can I draft a data processing agreement and subprocessor list for a pre-revenue SaaS startup?

Yes, you can draft a data processing agreement and subprocessor list for pre-revenue SaaS startups. The tool scales from pre-revenue to enterprise stages, generating mandatory legal documents from a minimal project fact set without requiring extensive legal expertise.

Does a generic SaaS legal template meet EU AI Act disclosure requirements?

Generic SaaS legal templates often fail compliance audits because they lack EU AI Act Article 50 transparency obligations, DSA terms clarity rules, and Quebec Law 25 provisions. Generating drafts from your specific project fact set ensures mandatory AI disclosures and regulatory requirements are met.