DM Champ Docs

Hosted Legal Pages for Your White Label

Your clients sign up on your domain, agree to terms on your signup page, and sometimes ask you for a privacy policy, a security overview or a Data Processing Agreement before they will put customer data through your platform. Writing those from scratch is slow, and linking the platform’s own documents would name a company your clients have never heard of.

The Legal pages card on the White Labeling panel gives you four ready-made documents, filled with your company details and served on your own domain:

Page URL on your domain What it is
Terms of Service /legal/terms The agreement between you and the businesses that use your platform
Privacy Policy /legal/privacy What personal data the platform processes, why, and the rights people have
Data Security /legal/security Where data is stored, how it is protected, how long it is kept. Written to be forwarded to a client’s reviewer
Data Processing Agreement /legal/dpa A GDPR Article 28 agreement between your client (controller) and you (processor), with a signature block for both parties

Every page names your legal entity as the contracting party. The company behind the platform is only ever described as “the platform provider” and is never named, so nothing on these pages reveals what your product is built on.

Warning: These are templates, not legal advice. They are written for a typical agency reselling a messaging and AI platform, in English, under the GDPR. Review them with your own legal counsel and adapt them to your business, your pricing and the laws that apply to you before you rely on them. You are the party named in every document.

Switching the pages on

Go to Settings → White Labeling, pick the white label you want (if you run more than one), and scroll to the Legal pages card, just below Brand.

  1. Legal entity. The registered company name your clients contract with. Leave it empty to use the Company name from the Brand card.
  2. Registered address. One line per element (street, city, country). It appears in the contact sections and in the DPA signature block.
  3. Country. Where your company is established. The Terms use it as the governing law and the courts for disputes. Leave it empty and the Terms say “our country of establishment” instead, which is weaker; fill it in.
  4. Registration number. Chamber of commerce or company number. Optional.
  5. Privacy contact email. Where data-protection requests and security reports go. Leave it empty to use the Support email from the Brand card.
  6. Switch on Publish the pages on my domain, tick the confirmation that you will review the templates with your own counsel, and click Save.

The card then lists the four URLs. Open each one and read it: the pages show exactly what your clients will see, with a Print or save as PDF button and a Copy text button if you want to take the wording into your own document.

The switch needs your custom domain to be connected (see Custom Domain), because the pages are served on it. Until a domain is verified the switch stays off.

Linking the pages from signup and emails

Publishing the pages does not change your signup page by itself. Click Use these links on the signup page and in emails under the URL list: it fills the Brand card’s Terms of service URL and Privacy policy URL with the hosted pages, so the “I agree to the Terms” line on your signup page links to them, and it adds “Terms” and “Privacy” to your email footer links under Email Branding when there is room (the footer holds four links; existing ones are never replaced). If you already link your own documents there, leave the button alone and keep your links.

Your docs domain forwards as well: docs.yourbrand.com/legal/terms (and the other three paths) redirects to the same page on your app domain, so either address works in a proposal or an email signature.

What each document says

The wording is deliberately generic, so it fits most agencies without editing. In short:

  • Terms of Service cover the service description, accounts, fees (“as set out in the plan, order or proposal you accepted”, so your pricing lives in your own proposals), acceptable use and messaging-channel rules, AI features and their limits, data ownership and export, sub-processors, availability and support, warranties, a liability cap of the fees paid in the last 12 months, termination with a 30-day export window, and governing law in your country.
  • Privacy Policy explains that you are the controller for account data and the processor for your clients’ contacts and messages, what is collected, why, the legal bases, who data is shared with (described by category), transfers outside the EEA, retention periods, security, data-subject rights, cookies and contact details.
  • Data Security states where data lives (dedicated servers in the EU, files and backups in the EU), encryption in transit and at rest, who can access data, how AI providers handle message content, backups and deletion timelines, monitoring and breach notification, and that the platform is not SOC 2 or ISO 27001 certified.
  • Data Processing Agreement mirrors the structure of a standard Article 28 agreement: roles, subject matter and duration, data categories, your obligations as processor, sub-processors and the 14-day change notice, breach notification, audits, international transfers, no AI training on customer data, and three annexes (processing description, technical and organisational measures, sub-processor categories). It ends with a signature block for your client and for you.

The facts the pages state about the platform itself (EU hosting, encryption, backup and retention windows, AI providers processing content under commercial API terms that exclude model training) match what is published in the platform’s own privacy documentation. When those facts change, the templates change with them.

Signing a DPA with a client

Open /legal/dpa on your domain, click Print or save as PDF, and send the PDF to your client. They fill in the Controller block (their legal name, address, signatory, date, signature), you sign the Processor block, and each side keeps a copy. The DPA refers to your Terms of Service, so publish both.

Your own DPA with the platform, where you are the controller and the platform is your processor, is a separate document: see Get a Signed DPA. Sign that one once as the agency; the hosted DPA is what you sign with each client.

Changing or unpublishing the pages

Edit any field on the card and click Save: the pages update immediately and the “Last updated” date at the top of each one moves to today. Turn Publish the pages on my domain off to unpublish; the URLs then answer “Not published”, so clear the Brand card’s Terms and Privacy URL fields too if you had pointed them there.

Limitations

  • The pages are in English only. If you need another language, use Copy text as a starting point and host your own translation, then link it from the Brand card.
  • They cannot be edited in the app. A clause that does not fit your business is a reason to publish your own document instead, not to leave a wrong one live.
  • Your clients’ end customers (the people who message your clients) are covered by your clients’ own privacy notices; the hosted Privacy Policy explains that split, but it is not a substitute for a client’s notice.