← Digital, E-Commerce & AI

Web3 · Platform terms

Terms and conditions for Web3 platforms and dApps

A dApp may use a permissionless protocol, but users generally interact with an interface, domain, wallet connector and team making certain decisions. Terms must describe this architecture and the limits of actual control precisely.

wallets and on-chain activity actual roles MiCA and DSA
Central questionWho controls the interface, protocol and keys
Technical riskIrreversible transactions, oracles, bridges and smart contracts
Legal riskThe service may fall under MiCA, AML, DSA or consumer law
01

Decentralisation must be described, not declared

Terms identify the front-end operator, developers, governance organisation, key administrators and third-party providers. If an entity can stop the interface, upgrade a contract or collect fees, that control matters.

Calling a protocol completely decentralised offers no protection where technical and economic reality indicates otherwise. The document separates operator services from actions users execute directly on the blockchain.

02

Wallets, signatures and transactions

Users must understand when they are merely connecting a wallet, signing a message or authorising a transaction that moves assets or grants permissions.

  • Custodial versus non-custodial arrangements and who controls keys.
  • Network, gas token and variable costs.
  • Finality and limits on reversing transactions.
  • Approvals, permissions and malicious contract risks.
  • Oracles, bridges, indexers and off-chain services.
  • Forks, upgrades, emergency pauses and governance.
03

Risks cannot be transferred without limit

Terms may explain volatility, lost keys, address errors, front-running and vulnerabilities, but cannot make every operator act the user’s risk. Liability limits are calibrated to control and the B2B or B2C regime.

The interface must avoid misleading claims about returns, security or audits. A technical audit reduces risk but does not guarantee a defect-free smart contract.

04

MiCA, DSA, GDPR and other regimes

If a project issues cryptoassets, offers them publicly or provides custody, exchange, execution or transfer services, MiCA and Regulation (EU) 2023/1113 may apply. The dApp label is no exclusion.

An interface hosting or intermediating content or offers may fall under the Digital Services Act depending on its function. Wallet data can be personal data when linked to an individual, so GDPR analysis remains necessary.

05

How we work together

  1. 01
    Inventory and architecture

    We clarify technology, actors, data flows, interface and the intended commercial outcome.

  2. 02
    Legal classification

    We establish roles, applicable regimes, risks and information requiring completion.

  3. 03
    Drafting or audit

    We prepare the Web3 platform terms and risk matrix, coordinating the document with the product, technical processes and available evidence.

  4. 04
    Implementation and review

    We deliver the final version, priority actions and reference points to monitor as products or legislation change.

QUESTIONS

Frequently asked questions

Does a decentralised dApp need no terms?

If an interface or service is operated for users, terms may be necessary. Classification depends on actual control and activities, not the label.

Does a disclaimer remove smart contract liability?

Not completely. Its effect depends on the law, user status and operator control. Fraud, gross negligence and mandatory rights cannot be neutralised by generic wording.

Are wallet addresses always anonymous?

No. They may become personal data if linked, or reasonably linkable, to a person through additional information.

Need terms and conditions for a Web3 platform?

Send your documents for a legal assessment and a solution tailored to your commercial objective.