→ Stage 3 / 6
Secure your assets and frame their exploitation.
A tech startup is worth almost nothing for its offices or its furniture: its value lies in its brand, its code, its data and its contracts. These are precisely the assets that an investor or an acquirer pays for.
Three assets, three reflexes. The trademark (name + logo): file it with the INPI (the French trademark office) before launch, after checking that no one is already using it — registering your company or reserving the domain name does not protect the trademark. The software: code is protected as soon as it is written, but only if your company actually owns it; if a freelancer or an agency developed it, you need a written assignment agreement, failing which you do not own your own product. The data: a database that you have invested time and money to build can be protected, provided you keep proof of that investment.
The GDPR governs the way you process personal data and applies from your very first user. The AI Act adds the new European rules on artificial intelligence: what concerns you depends on the use case (a tool that screens CVs is "high-risk"; a simple chatbot mainly has to disclose that it is an AI). Start with three things: a register listing the data you collect (why, and for how long), clear information to users, and contracts with the providers who handle that data. The absence of a register is the most common gap — and the first document you will be asked for. Do it at 200 users, not at 200,000.
Open source saves precious time, but it has its rules. Some licences are "permissive": you use the code almost without constraint. Others are "copyleft" (contaminating): if you build on them, you may be required to publish your own code — in other words, to make it public. For a startup whose entire value is its code, this is a real issue in due diligence. The right reflex costs an hour: keep a list of the open-source building blocks you use and check for copyleft licences before integrating them.
Your terms of sale (CGV) and terms of use (CGU) are the contract between you and your customer: they decide who is liable when something goes wrong. The trap is to copy generic terms found online that do not match what you actually sell — a SaaS subscription, a one-off service and a marketplace do not have the same needs. The essentials to include: exactly what you provide, the price and payment, the limits of your liability, what happens to the customer's data, and how the contract ends. In B2C, mandatory consumer protections also apply. Have them drafted — or at least reviewed — to fit your actual model before your first sales.
Code, like designs, text or other content, is protected by copyright: the author (the person who creates) remains the rights holder; there is no automatic transfer to the company. For software, code written by an employee in the course of their duties vests automatically in the employer; but for everything else, and for a freelancer, nothing passes without a written and precise assignment (rights covered, media, term, territory).
Bespoke, balanced and protective GTC, tailored to your business model.
Development, hosting, maintenance, licences: contracts that protect your IP and your revenues.
Exclusive distribution, selective distribution, franchising: choose the model that maximises your network.
Legal action and emergency measures to protect your know-how and your customer base.
Valid, proportionate and enforceable clauses, tailored to your sector of activity.
Drafting, renewal, review, assignment: master every aspect of your commercial lease.
A lawyer frames your matter at the first meeting, the firm's AI accelerates the drafting.
Book a meeting →