▸case-22 A SaaS platform vendor wants a clause in their Data Processing Agreement allowing them 30 days to notify data controllers after confirming a personal data breach. Draft a GDPR Article 33/34 data breach notification clause for DPAs. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 A generative AI software platform allows enterprise users to generate marketing text and images. The founders want terms stating that the platform owns all generated output while disclaiming all liability for third-party copyright infringement. Draft AI-specific terms of service. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 Our online retail shop plans to expand marketing campaigns to customers in Canada and the EU while using third-party email automation tools. Could you draft a Data Processing Agreement along with email marketing compliance requirements? Please provide complete contractual terms with bracketed placeholders, jurisdiction-specific variations, and technical implementation steps for consent tracking. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 A Canadian e-commerce store operating in Ontario collects customer phone numbers and purchase history. The founder suggests copying a generic US privacy policy that only mentions CCPA. Draft a PIPEDA-compliant privacy policy structure for Canadian commercial activities. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 A cosmetic brand contracts with social media influencers on Instagram and TikTok to promote products. The brand guidelines tell influencers to place hashtags like #partner buried at the end of a long caption. Draft an influencer marketing legal agreement section compliant with FTC Endorsement Guides. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 An iOS and Android fitness application wants a custom End User License Agreement (EULA). The developers intend to omit any mention of Apple App Store or Google Play Store terms to keep the agreement concise. Draft a compliant EULA that addresses mobile application marketplace requirements. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 A UK SaaS platform transfers personal data from UK and EU enterprise customers to sub-processors located in Australia and Singapore. The team assumes an informal privacy notice update is sufficient for international transfers. Draft a regulatory compliance checklist for cross-border data transfers under GDPR and UK GDPR. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 A retail website in California collects customer browsing preferences and shares them with third-party ad networks. The marketing lead suggests putting the privacy policy link buried in the footer without any opt-out mechanism. Draft CPRA compliant website privacy disclosures. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 A digital goods platform selling downloadable software modules to European consumers wants to set a policy stating 'All sales are final with zero refund or withdrawal rights.' Draft an EU consumer rights legal section that handles digital content statutory withdrawal rights under the Consumer Rights Directive 2011/83/EU. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 I am developing an educational gaming app targeting young children in the United States. I need a specialized privacy policy and user agreement that addresses youth data protection rules and parental consent mechanisms. Please structure the response as a complete document draft with clear headings, placeholders for app-specific details, technical setup guidance for age gates, and a compliance checklist. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 A B2B cloud infrastructure provider wants to draft a Service Level Agreement (SLA) promising 99.99% uptime. The infrastructure lead wants to offer cash refunds for any downtime exceeding 10 minutes. Draft a standard B2B SaaS SLA framework that manages service credits appropriately. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 An enterprise company in Ireland hires remote employees across the EU and wants to rely solely on employee consent in employment contracts to process payroll and performance data. Draft an EU HR and employee privacy notice guidance document. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 I am representing a client facing felony DUI charges and need a suppression motion to exclude breathalyzer test results due to improper calibration logs. Please draft the court motion and oral argument strategy for the hearing. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 A cybersecurity startup wants to publish a vulnerability disclosure policy (VDP) on their website. The engineering team suggests threatening criminal prosecution under the CFAA for any unapproved scanning. Draft a safe harbor disclosure policy that encourages ethical research. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are launching a cloud-based analytics platform for B2B clients in North America and Europe. Please generate a comprehensive Privacy Policy and SaaS Terms of Service template tailored to our business model. The final output should include structured legal sections with placeholder fields for our company details, technical implementation notes for data collection consent, and a checklist to verify regulatory compliance across applicable regions. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 We are deploying a web analytics script on an e-commerce site serving users in Germany and France. The web developer suggests using implicit consent via a banner that says 'By continuing to browse, you accept cookies.' Draft a cookie policy and consent banner legal requirement specification that addresses EU ePrivacy Directive requirements. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 A software company packages AGPLv3 licensed components into their proprietary downloadable desktop software and wants terms stating that all source code remains strictly confidential. Draft an IP and software licensing notice addressing open-source component obligations. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 I invented a novel dual-clutch transmission assembly and need formal patent claims drafted for a USPTO utility patent application filing. Please draft the independent and dependent patent claims according to 35 U.S.C. 112. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Our firm needs assistance calculating depreciation under MACRS for hardware equipment and completing Form 1120 Schedule M-1 for our corporate IRS tax filing. Please perform the tax line-by-line calculations. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A US e-commerce brand wants to send promotional emails to past site visitors. The marketing team wants to remove physical postal addresses from email footers to keep emails clean. Draft a CAN-SPAM compliance specification for commercial marketing emails. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 A cloud database provider hosts electronic protected health information (ePHI) for US healthcare providers. The marketing team claims standard GDPR DPA terms cover US health regulations. Draft a healthcare compliance section comparing GDPR DPA requirements with HIPAA Business Associate Agreement (BAA) requirements. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 A mobile fintech app operating in Sao Paulo needs a privacy policy compliant with Brazil's Lei Geral de Proteção de Dados (LGPD). The team omitted contact details for a data protection officer (Encarregado). Draft the mandatory LGPD data subject rights and controller identification section. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |