By business type

Terms & Conditions Generator for agencies

Written for the agency’s own policy, the client sites it builds, and the processor role in between.

Generate your terms and conditions Read the terms and conditions guide

Agency terms are where scope disputes are won or lost. The clauses that matter are the ones nobody reads until there is a problem: what happens to work in progress, who owns deliverables before final payment, and what a client is entitled to at the end of the relationship.

An agency has three privacy problems and usually documents only the first. There is the agency’s own site and CRM, where you are a controller. There is client data you hold to do the work - ad account access, analytics logins, CRM exports, customer lists for a campaign - where you are a processor. And there are the sites you build and hand over, where the tracking you installed becomes someone else’s legal exposure.

The middle one is where the contractual risk sits. If you touch client customer data, GDPR Article 28 requires a written processor agreement, and most agency master service agreements do not contain one. Without it, both sides are non-compliant, and the client finds out during their own audit rather than yours.

The third is where the reputational risk sits. An agency that installs GTM, a Meta pixel, a heatmap and a chat widget during a build, and hands over without documenting them, has left a client publishing a privacy policy that is inaccurate from day one. Increasingly, clients notice.

What a terms and conditions for an agency has to cover

How an agency actually moves personal data

Client customer lists for campaigns

Uploading a customer list to an ad platform for matching is processing on the client’s behalf, and it needs their basis, not yours.

Ad account and analytics access

Delegated access to a client’s Google Ads, Meta Business Manager or GA4 property gives you access to personal data under their control.

Creative assets containing personal data

Testimonials, case study material, customer photographs and user-generated content used in campaigns.

Your own project tooling

Notion, Slack, Figma, Asana and Drive all end up holding client personal data, which makes them sub-processors even though nobody thinks of them that way.

Freelance and offshore contractors

A common sub-processing relationship that most agency contracts do not disclose, and that transfer rules may also cover.

Tracking installed on client sites

Whatever you add during a build becomes a permanent part of the client’s processing, and it needs handing over in writing.

Third parties the draft will ask you about

Google Ads and GA4 · Meta Business Manager · HubSpot · Notion or Asana · Slack · Figma · Dropbox or Google Drive · freelance contractors

The rules that apply

Article 28 processor agreements

Required in writing wherever you process client personal data. It is the document clients now ask for at onboarding, not at renewal.

Sub-processor disclosure to clients

Your own tooling - project management, analytics, reporting, freelancers - are sub-processors from the client’s point of view.

Freelancers and contractors

Anyone outside your legal entity handling client data is a sub-processor needing a contract and, usually, client authorisation.

Marketing consent on behalf of clients

Running a client’s email or ads programme means operating on their consent records. If the records are weak, the exposure is theirs and the professional embarrassment is yours.

Hand-over documentation

Not a legal requirement, but the practical difference between a clean hand-over and a client publishing a policy that misdescribes their own site.

What the generated terms and conditions contains

The agency compliance stack

  1. Publish your own privacy policy as a controller

    Covering your site, your CRM, your recruitment and your client contacts.

  2. Add an Article 28 schedule to your MSA

    One schedule, reusable across clients, covering instructions, confidentiality, security, sub-processors, assistance, deletion and audit.

  3. Maintain a sub-processor list

    Including your tooling and any contractors, ready to send when a client asks.

  4. Standardise a hand-over pack

    Every tag installed, what it collects, which policy sections it affects, and who now owns each one.

  5. Set a client-data retention rule

    Delete or return exports at project end, and actually run it.

  6. Give each client site its own documents

    Generated from that site’s actual stack rather than copied from the last build.

Where this usually goes wrong

No processor agreement with clients

The single most common agency gap. It surfaces when the client’s own compliance review asks for one and there is nothing to send.

Undisclosed sub-processors

Freelancers, offshore teams and the project tooling holding client data all count, and clients increasingly ask for the list.

Installing tracking without documenting it

Hand-over should include the exact list of tags, what each collects, and what the client now needs to disclose.

Reusing one privacy policy across every client site

Different sites, different tools, different processors, different markets. A shared template is inaccurate on most of them by definition.

Holding client data indefinitely after a project ends

Article 28 requires deletion or return at the end. Agency drives are full of exports from clients who left years ago.

Running email campaigns on consent nobody can evidence

If the client cannot produce the consent record, the campaign should not go out.

Frequently asked questions

Is my agency a controller or a processor?

A controller for your own business data - your site, your CRM, your staff - and a processor for client data you handle on their instructions. Most agencies need both a privacy policy and a processor agreement.

Do I need a DPA with my clients?

If you process personal data on their behalf, yes, and Article 28 requires it in writing. Adding it as a schedule to your standard contract is far easier than negotiating one per client.

Am I responsible for tracking I installed on a client site?

The client is the controller once they operate the site, but you carry professional responsibility for what you installed and for documenting it. Undocumented tracking is the source of most post-hand-over disputes.

Can I use one privacy policy across all my client sites?

Not accurately. Each site has a different toolset, different processors and often different markets, and an inaccurate transparency notice is itself a breach for the client.

Are my freelancers sub-processors?

If they handle client personal data, yes. That means a contract, and usually disclosure to and authorisation from the client.

Are terms and conditions legally binding?

They are when the user had a genuine opportunity to read them and took a positive step to accept. Clickwrap - a ticked box next to a visible link - holds up far more reliably than a "by using this site you agree" line in the footer.

What is the difference between terms of service and terms and conditions?

Nothing substantive. "Terms and conditions" is the more common phrasing in the UK and Commonwealth markets, "terms of service" in the US and in SaaS. The clauses do the same job.

Can I limit my liability to zero?

No. Most consumer regimes void attempts to exclude liability for death, personal injury or fraud, and unfair-terms rules strike out caps a court considers unreasonable. A cap that is drafted to survive review is worth more than one that is struck out entirely.

Do I need terms if I sell nothing?

If users can register, post, comment or upload, yes - the terms are what let you moderate, suspend and remove content without being in breach of contract yourself.

Terms & Conditions Generator for agencies

Answer a short questionnaire and get a draft written for an agency. Free to start, no card required.

Generate your terms and conditions

Other documents an agency needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.