What we changed in our legal pages for 2026, and why a three-client MSP bothers
Global Privacy Control honoured on every page, twenty state privacy laws, an appeal process, breach-notice deadlines, AI clauses and a DMCA agent: the 2026 update to SentinelGrid's terms and privacy policy.
A managed IT provider gets administrator access to everything a client owns. We think that means the contract and the privacy policy should be as carefully maintained as the backups. This week we rewrote ours, for SentinelGrid and for VerifyBlox, the Roblox-to-Discord verification service we run, against the law as it stands in August 2026. Here is what changed and why.
The signal we now actually obey
The most concrete change isn't in the policy; it's in the pages. If your browser sends the Global Privacy Control header, Google Analytics no longer starts on any SentinelGrid or VerifyBlox page. One if statement in the analytics loader, on every page we serve.
We don't sell data, so there's nothing else for the signal to switch off, but by 2026 a dozen state laws treat GPC as a legal opt-out, and a policy that says "we honour GPC where our configuration supports it" is a policy that hasn't checked. Now it's checked.
Twenty states and one honest paragraph
As of this year twenty U.S. states have comprehensive consumer privacy laws in force, with Indiana, Kentucky and Rhode Island arriving on January 1. Almost every one of them applies only to businesses above a size threshold that a small studio does not meet. Florida's own Digital Bill of Rights starts at a billion dollars of revenue.
The previous policy implied those rights applied to us. The new one says the truth: most of them don't, and we extend them to everyone anyway: access, correction, deletion, portability, opt-out, and an appeal process with a named response time, which several of the newer laws require and which almost no small business bothers to write down.
Deadlines with numbers in them
"We will notify you as required by law" is the sentence every policy has and nobody can act on. The new pages state the actual limits: our own target of 72 hours from confirming an incident, the 72-hour regulator deadline under the GDPR, and the 30 days the Florida Information Protection Act allows for notifying residents. The Subprocessors & Security page now lists the statutory outer bounds we work inside, and the Managed IT terms say how we help a client meet theirs under HIPAA or PCI DSS.
AI, stated plainly
Two AI laws moved this year. Colorado replaced its 2024 AI Act with a narrower disclosure law that starts in 2027, and the EU's Digital Omnibus pushed the AI Act's high-risk obligations out to December 2027, while leaving the outright prohibitions exactly where they were.
Our policy now says what we do with AI, which is very little: a daily planning summary for our own checklist and a pre-review of HR mailbox requests. Nothing that makes a decision about a person. For SentinelVision it says something stronger: the system detects objects and draws boxes, it does not identify, categorise or score people, and it is designed to stay outside the biometric practices the AI Act prohibits and the biometric-privacy laws in Illinois and Texas regulate. That was always the design; now it's a commitment in writing.
The children's rule we don't fall under, and the one VerifyBlox almost does
The FTC's amended COPPA Rule took full effect on April 22. SentinelGrid's services are for adults and businesses, so it doesn't apply. The policy now says so instead of leaving you to guess.
VerifyBlox is the interesting case. It is a 13-and-over service, but it sits on top of Roblox, which is popular with people well under 13. So its new policy does what the amended Rule would require if it did apply: a written retention schedule with a period for every category of data, a written security programme, and a commitment that actual knowledge of an under-13 user means deletion, not a form. If a regulator ever asks the question, the answer is already on the page.
The clauses that were simply missing
Some of this was catching up. VerifyBlox's terms had no governing law at all; they now say Florida, with a thirty-day talk-first clause before anyone sues. They had no automatic-renewal disclosure, which the Restore Online Shoppers' Confidence Act and about thirty state laws require of any subscription, so there is now a plain statement of what renews, when, for how much, and a promise that cancelling online takes no more steps than signing up did. Both sites now have a DMCA agent, an electronic-signature clause that matches how agreements are actually signed in the client portal, and the boilerplate (severability, assignment, force majeure) that lawyers include and small sites forget.
Why bother
Because it's the same discipline as everything else here. We publish the build status so nobody buys a feature that doesn't exist, and a status page so nobody has to take uptime on faith. Legal pages that say what the law actually is, and what we actually do, are the same idea applied to trust.
The updated documents are all under /legal, each with a version number and a change note at the bottom. If you're a managed IT client or thinking about becoming one, the service terms and the plans are the two pages worth ten minutes.