You Are Launching a New IT Product
You have an MVP, application, SaaS service, platform or another digital product, but the legal model has not yet been built.
SOFTWARE • SaaS • STARTUP • DATA
We build the legal architecture of an IT business: structuring rights to code and the product, relationships with developers and clients, SaaS and licensing models, personal-data processing, corporate arrangements and investor transactions.
The work begins with the product model and the movement of data, money and rights. Only after that do we determine which agreements and documents are actually required.
WHEN AN IT LAWYER MAY BE NEEDED
You have an MVP, application, SaaS service, platform or another digital product, but the legal model has not yet been built.
Founders, employees, freelancers or contractors worked on the product, and it is necessary to determine who currently owns the exclusive rights.
Terms of product use, payment, access, restrictions, support and liability need to be structured in line with how the service actually operates.
The website or application includes registration, forms, analytics, CRM, newsletters or other processes involving personal data.
The infrastructure includes foreign hosting, analytics, CRM, APIs or other services, and it is necessary to determine what data is transferred to them and what legal requirements this creates.
The ownership interest, rights of the parties, decision-making procedure, financing and legal future of the product if the ownership structure changes need to be determined.
Before a major transaction, the customer requests documents on rights to the product, personal data, confidentiality, licensing or liability.
A client, developer, rights holder, partner or government authority has brought a claim, and the project’s legal structure needs to be reconstructed so a position can be developed.
Nikolay NemkovManaging Partner, Konsultant Law Firm
Managing Partner’s Commentary
Why an IT company’s legal documents cannot be prepared separately from who writes the code, how the product makes money, what data it collects and who actually receives access to the result.
APPROACH
Two IT services that look similar from the outside may require entirely different legal structures. The monetization model, relationships with developers, infrastructure, user categories, movement of personal data, third-party solutions and ownership structure of the project all matter.
We determine what the client receives, what the client pays for and which contractual model reflects the actual service or product.
We review who creates the code, design, content and documentation and how the exclusive rights are transferred to the company.
We identify what personal and other data the product receives, where it is processed and which external services participate in that chain.
We review the corporate structure, ownership interests, arrangements between founders and relationships with investors and key partners.
WHAT WE DO
We analyze the service model, users, payments, infrastructure, team, technologies used and principal legal risks.
We review agreements with authors, employees and contractors, ownership of exclusive rights, third-party components used and the documents relating to the software product.
We prepare documents governing development, delivery of work results, source code, confidentiality, technical documentation and intellectual property rights.
We structure terms for access to the service, licensing, implementation, development, technical support and other client-interaction models.
We analyze personal-data collection and processing, forms and consents, localization, notifications, external services and cross-border transfers depending on the product architecture.
We support arrangements between founders, corporate documents and the legal part of bringing in an investor, taking into account rights to the core product.
We handle conflicts with clients, developers, partners and rights holders, as well as other claims related to operation of the IT product.
LEGAL MAP OF THE PRODUCT
What exactly the company sells: software, a license, access to a service, development, implementation, data, support or a combination of several models.
Who created the code, interface, design and content and on what legal basis the company may use and dispose of them.
Who uses the product, what information the company receives and through which systems the information moves.
Who owns the company, how the founders’ roles are allocated and how the product is connected to investments and key transactions.
EXPERT COMMENTARY
Nikolay Nemkov and the experts at Konsultant Law Firm comment in the media on issues related to this practice area.
The firm has been practicing since 2007. We handle litigation and complex legal matters for businesses in Krasnoyarsk, Moscow and other regions of Russia.
A user agreement, personal-data policy and NDA work only as part of an overall structure. If an agreement with a developer does not secure the required rights, the product transfers data to external services differently from what the documents say, or the client agreement does not reflect the real SaaS model, a set of templates does not solve the problem.
An IT company’s legal documents should therefore reflect the product’s actual architecture and be updated together with material changes in technology, the team and the sales model.
You explain what the service does, who uses it, how it makes money and what stage the project has reached.
The team, contractors, clients, users, partners, investors, infrastructure and external services.
We review rights to the product, agreements, personal data, corporate documents and other legal weak points.
We determine what must be corrected before launch or a transaction and which documents and processes can be implemented at the next stage.
MANAGING PARTNER

Managing Partner, Konsultant Law Firm
More than 20 years of practice in complex property and corporate disputes. Practicing insolvency practitioner.
SOFTWARE
Computer programs are protected by copyright. State registration of a computer program or database is available at the rights holder’s discretion, but registration by itself does not correct problems in relationships with authors, employees and contractors.
An IT company needs documents showing who created the product and on what basis the company obtained the required exclusive rights to the results of that work.
PERSONAL DATA
Legal work with personal data starts with the product’s actual architecture: what information is collected, for what purposes, through which forms and SDKs, where the databases are located, who receives the information and which external services participate in the processing.
When personal data of Russian citizens is collected via the Internet, the law establishes requirements to use databases located in Russia for the operations with such data provided by law.
Before beginning a cross-border transfer of personal data, the controller must separately notify Roskomnadzor of the intention to carry out that transfer. The use of a foreign CRM, cloud service, analytics tool or other service therefore needs to be assessed by the actual movement of data in the specific architecture, not merely by the country associated with the service’s brand.
PERSONAL DATA CONTROLLER
Federal Law No. 152-FZ generally provides for notification of the authorized authority before personal-data processing begins, while the law establishes separate exceptions. Whether notification is required and what it should contain must therefore be determined from the company’s actual processes, not merely from whether a form exists on the website.
OPEN SOURCE
Use of third-party open-source components requires review of the applicable licenses and the conditions they impose on the particular way the product is used, distributed or modified. The fact that a library is available in a public repository does not by itself mean there are no licensing requirements.
There is no universal set. It depends on the product model, team, monetization method, users and data processing. Usually the first step is to review rights to the code and other development results, agreements with the team and clients, personal-data documents and the corporate relationships between the founders. Only after the product has been analyzed can the exact set of documents be determined.
This is not determined only by whether development was paid for. The author of the software, the nature of the parties’ relationship, the agreement, the exclusive-right provisions and the documents confirming creation and delivery of the work result all need to be considered. For a product created by several contractors, the chain of rights needs to be reviewed for every material component.
No. Computer programs are protected by copyright, and state registration of a computer program or database is carried out at the rights holder’s discretion. Registration can be a useful part of documenting a software product, but it does not replace agreements and documents proving ownership of the exclusive rights.
Federal Law No. 152-FZ generally requires a controller to notify Roskomnadzor of the intention to process personal data before such processing begins, but the law contains separate exceptions. Whether notification is required and what information it should contain must therefore be determined from the actual processes of the specific product and company.
The foreign origin of a service does not provide a universal answer. It is necessary to determine what personal data the service receives, where and how it is processed and whether a cross-border transfer occurs. When personal data of Russian citizens is collected via the Internet, the statutory requirements concerning localization of the operations with such data must be taken into account, and a separate Roskomnadzor notification procedure applies before cross-border transfer begins.
That depends on what the client actually receives and how the product works. In one model, granting the right to use software may be the central element; in another, services or a combination of obligations may be central. The legal structure should match the actual product model rather than being chosen solely by the title of a template agreement.
Before a transaction, it is useful to review the company’s rights to the core product, the corporate structure, the founders’ ownership interests, existing arrangements between them and the project’s obligations to third parties. The terms of the specific investment transaction should separately define the amount of investment, the parties’ rights, corporate governance and other matters material to the project.
Describe the product, the project stage and the main task. If the service is already operating, state who its users are, how payment works and whether the infrastructure includes employees, external developers or foreign services.