How we work

One contract, one person, clear responsibility.

half-work is your contracting party. Behind every engagement stands a senior freelancer we know personally, carrying their own professional indemnity insurance. In the directory they are pseudonymous — many work in parallel employment or for competitors and do not want to be crawled publicly. Towards you they are fully transparent after the briefing: real name, CV, photo. If your engagement produces an AI agent, an audit trail, explicit AI Act roles and a compliance documentation package come with it.

This is the substance — not a wall of guarantees, not insurance marketing.

01 // The contract

Fixed price, shadow run, formal acceptance

Every engagement is a work contract under §§ 631 ff. of the German Civil Code — a defined deliverable with formal acceptance under § 640. If the work does not conform, the statutory remedies apply: rectification first, and withdrawal if that fails. Standard German law, no bespoke construction — whether it is a content workflow, a RAG setup or an agent.

02 // The person behind it

A senior freelancer with their own insurance

Behind every engagement stands a senior freelancer with substantial domain practice whom we know personally. Pseudonymous in the directory by design; real name and CV go to you after the briefing. Their professional indemnity insurance covers their own advisory and audit work. On agent projects they also sign off the shadow run before go-live.

03 // Audit trail · for AI agents

Tamper-evident, still verifiable in ten years

If your engagement includes an agent, every interaction lands in a tamper-evident signed audit log that remains verifiable a decade later — relevant for GoBD, NIS2 and DORA. Samples, sign-offs and escalation decisions are documented; ongoing support includes a quarterly compliance report.

04 // Compliance package

Included in the contract

On handover you get a PDF bundle: DPIA template, draft data-processing agreement, extract of technical and organisational measures, AI Act classification and an audit-trail sample — everything your data protection officer needs for the internal file. What you do with it is your call. We supply the documentation neutrally.

Who is the provider, who is the deployer.

EU Regulation 2024/1689 distinguishes two roles with different obligations. We make the split explicit in the contract.

// Build phase

half-work is the provider

During the build, half-work acts as provider within the meaning of Art. 3(3) of Regulation 2024/1689. We are responsible for the conformity of the deliverable at the point of acceptance, and we document the risk class and the conformity evidence.

// From acceptance onwards

You are provider and deployer

On acceptance you take the agent into your own environment. You thereby become both provider and deployer within the meaning of Art. 26. Ongoing support from half-work does not change this — deployer responsibility is not delegable under the AI Act.

Why this way? Because it is the clean cut. Provider obligations belong where the system is actually used. We deliver what you need as the deployer — you keep control.

Honest limits.

  • We do not insure, and we do not broker insurance. No platform cyber policy, no insurance intermediation. If you want a cyber policy with an AI endorsement, arrange it with your own broker; we supply the compliance documentation neutrally.
  • We do not promise 100% correct AI output. AI is probabilistic. We deliver an audit trail, confidence tuning and human escalation — not perfection.
  • We do not create a direct claim against the freelancer. They are our subcontractor. All claims under the contract run through half-work.
  • We give no guarantee in the sense of § 443 BGB. Standard statutory liability with a cap at the project fee — sufficient and transparent.

What your legal and data protection people will ask.

Who is liable if the deliverable is defective, or an agent gives wrong information?

Standard German statutory liability: half-work is liable without limitation for intent and gross negligence, and under product liability law and for injury to life, body or health. For simple negligence, liability is capped at the foreseeable damage typical for the contract, at most the project fee or twelve monthly retainers. After acceptance, the client indemnifies half-work against third-party claims arising from operating the agent, except where half-work itself breached a duty. This split is standard in the B2B software market. The binding wording is in the German AGB, § 7 and § 8.

What happens at acceptance?

We present the work for acceptance — for agents, after the shadow run and with the compliance package. You have fourteen days to review. On a justified defect notice: rectification. On success: the final 50% of the fee falls due. If material defects persist after rectification, withdrawal under § 636 BGB applies. Standard work-contract law.

Where is data processed?

On EU servers (Netcup GmbH, Germany). Where a project specifically requires an external model provider such as Anthropic or OpenAI, that is documented separately in the data-processing agreement module. Details in the German privacy policy and DPA template.

What do I get at the end of the contract?

The accepted work in machine-readable form — for agents, additionally the blueprint, the compliance package and an audit-trail sample. It all remains your property, including when ongoing support ends.

We are not based in Germany. Does this still work?

Yes. We work with clients internationally; the contract is concluded in German and governed by German law, with Hamburg as the place of jurisdiction. For EU clients that means GDPR is the baseline rather than an add-on. If your legal team needs an English summary of the contract documents for review, ask us in the briefing and we will provide one — noting that the German text remains the binding version.

Sounds clean? Then let's talk.

Thirty minutes, free, with an honest assessment at the end.