Seventeen documents, plus this note, that answer before it is asked almost everything a UK housebuilder, contract caterer or facilities management company puts to a supplier during onboarding. None of it is legal advice, and three documents must go to a solicitor before you use them once. Page 2 records what was verified and what was not.
One director, no employees. Pre-revenue. Cyber Essentials not currently held. Insurance not yet bought. Nothing in the pack asserts otherwise, and where a document names a role, a review cycle or a certificate that does not exist yet, it says so and gives a date. That is deliberate: a young supplier who names its gaps is easy to buy from, and one who is caught overstating them is not. Two documents are built twice, because each contains material that must never reach a customer: send the -ISSUE file and keep the -INTERNAL one.
| Document | Pages | Before use | What it is for |
|---|---|---|---|
| data-processing-agreement-ISSUE also built as -INTERNAL, 12 pages, with the checklist page | 11 | solicitor | UK GDPR Article 28 terms, you as processor, with annexes for the processing detail, the controller's own obligations and rights, the security measures and the sub-processors. Carries the retention clause and the hosting commitment. Send the ISSUE file: the INTERNAL one ends with a page telling the customer what is not confirmed. |
| terms-of-service-outline | 8 | solicitor | Instructions to counsel: every clause your subscription terms need, and suggested wording. Never send this to a customer. |
| pilot-agreement | 4 | solicitor | The £2,500 60-day proof of reach, and the only contract: the sales proposal is now accepted subject to it, and the signature lives here. Four success criteria, the refund with its exclusions, the data-protection super-cap, and the year-one price on the paper. |
| security-summary | 4 | tick, then issue | A checklist, not an assertion: tick only what is true today and write "not yet" for the rest. Sent unprompted after the demo, this turns a six-week IT queue into a two-week one. |
| supplier-questionnaire-answer-bank-ISSUE also built as -INTERNAL, 8 pages, with the verify badges | 6 | internal | The 60 questions UK buyers ask most, answered from your actual stack and your actual company. The orange verify badges are instructions to you, not answers. The ISSUE build strips them out. |
| dpia-and-monitoring-pack | 4 | issue as is | New. A pre-completed DPIA naming per-worker read receipts and chase lists as monitoring under the ICO's employment practices guidance, with the proportionality argument, the alternatives considered, ten risks and their measures, and what the product deliberately does not do. Volunteer it. On a unionised site it is the first question and this is the answer. |
| worker-privacy-notice-template | 3 | issue as is | New. For the customer to adapt and publish in its own name, because it is the customer's controller duty. Ends with a short form under 250 words written for translation into the languages on site. This removes the customer's biggest deployment objection. |
| privacy-notice-prospects | 3 | publish first | New. Your own Article 13 and 14 notice for business development contacts. This must be live at team-comms.com/privacy before the first cold email, and linked from the footer of every one. |
| cyber-essentials-checklist | 4 | internal | The five controls mapped to Laravel on AWS via Forge plus laptops, and where the automatic fails are. Work through it, then book the assessment. |
| policies/ health and safety, modern slavery, anti-bribery, equal opportunities, quality, environmental, information security, business continuity | 1 each | sign and date | The eight one-pagers a supplier form asks for. Each now carries a scale note saying what the company actually is, so no one has to pretend there is a board, a second approver or a monthly team meeting. Fill the brackets, sign, keep them in one folder: every item you cannot produce on the day adds one to three weeks to a deal. |
Send all three in one instruction: they share definitions and cross-refer, and one instruction is materially cheaper than three. Budget [£1,500 to £3,000] for a solicitor qualified in England and Wales. The DPA, because it creates statutory obligations you cannot vary, because its liability, audit and sub-processor clauses are what a customer's counsel redlines, and because Chapter V of the UK GDPR was rewritten on 5 February 2026 so older templates cite repealed provisions. The terms of service, because your liability cap sits on your own written standard terms and is subject to the reasonableness test in s.3 of the Unfair Contract Terms Act 1977: a cap set badly can be struck out entirely, leaving you uncapped. Start from Bonterms or Common Paper, never a US template. The pilot agreement, because it is now the only paper a plc division signs, and it carries a refund promise with exclusions, an incorporated DPA, a general liability cap and a data-protection super-cap set at your cyber policy limit.
The other fifteen documents do not need a solicitor. They need accurate numbers and two purchases, which is a different and more urgent problem. The two purchases are the cyber policy and the Cyber Essentials assessment, and everything else in the pack is drafted so that it stays true until they are made.
| # | Do this | Elapsed | Why in this position |
|---|---|---|---|
| 1 | Buy the insurance, cyber first. Then fill in the company basics: company number, VAT position, registered office, ICO registration, bank details, named contacts. Cyber before professional indemnity and public liability, because pilot agreement clause 14.3 sets the data-protection super-cap at the cyber policy limit and the clause cannot be written until the limit exists. | 1 to 3 days | Every other document has these in square brackets, so doing it once completes them all. Raising an insurance limit mid-procurement costs about three weeks: buy it before you are asked. Until it is bought, the pilot agreement says "will hold, before launch day", which is true; it must never say "holds", which would not be. |
| 2 | Book Cyber Essentials. Read the Danzell question set free first, fix the gaps, then pay the £320 plus VAT. Until the certificate is in hand, every document in this pack says "Cyber Essentials: not currently held. Assessment booked with [body], target [date]." Fill in the body and the date; do not delete the sentence. | 1 to 3 weeks | Longest lead time here and the item most frequently demanded. It is on the critical path of your first housebuilder deal. Start it today. |
| 3 | Measure the numbers marked [verify]. Run a timed restore drill; confirm backup frequency and retention; record the restore test date; decide the penetration testing position. | 2 to 3 days | These block the security summary and the answer bank, the two documents that actually shorten deals. A wrong answer here is worse than a slow one. |
| 4 | Sign and date the eight policies, publish the modern slavery statement, and instruct the solicitor on the DPA, the terms and the pilot agreement together. | 1 day, then 1 to 2 weeks | The policies depend on nothing else and a supplier portal will refuse to progress without them. The solicitor's work runs in parallel with Cyber Essentials, so start it the same week. |
| 5 | Publish the prospect privacy notice, the sub-processor list, the terms and the DPA at stable, versioned URLs, then send the security summary and the DPIA pack unprompted after every demo. | 1 day, then ongoing | The DPA and the order form incorporate documents by URL, so those URLs must exist, and the privacy notice must be live before the first cold email rather than after it. Sending the summary and the DPIA pack unprompted is the habit that compounds. |
Every regulatory reference was checked against the primary source on 28 August 2026, not against secondary commentary. The material findings, several of which correct what is in general circulation: