Manage Confidentiality and NDAs

Manage Confidentiality and NDAs — White‑Label Guide for Agencies

Confidentiality and NDAs are the guardrails that let agencies safely run white‑label link building at scale. This guide gives agency and reseller managers clause‑level language, templates, operational workflows and incident playbooks to protect client identity and outreach assets across vendor‑reseller‑client triads. Legal disclaimer: This article is informational and not legal advice—consult an attorney before using any contract language.

Why confidentiality matters in white‑label link building

White‑label link building depends on three parties: the client (brand), the reseller/agency, and the vendor (link provider). Breaches of confidentiality in that triad can expose client URLs, outreach contact lists, proprietary outreach scripts, or even SEO strategy — all of which create reputational, competitive and legal risk.

Client anonymity is often the primary requirement: brands pay for links that should not publicly reveal their identity or strategy. If a published link shows a client’s URL or a pitch email leaks a contact list, competitors can reverse‑engineer the link profile or solicit the same partners. Brand safety is at stake when link placements appear on questionable sites, and public exposure of outreach scripts hurts long‑term relationships with publishers and PR contacts.

Mini case (anonymized): Agency X engaged Vendor Y to place editorial links for “Client Z” (anonymized). During handoff, Vendor Y received a CSV titled “ClientZ_outreach_contacts.csv” without redaction. A contractor accidentally uploaded a spreadsheet to a public shared folder; two days later, a competitor scraped the outreach contacts, contacted several publishers, and began pushing competing content. Agency X had a mutual NDA covering outreach lists and immediate injunctive relief language; the NDA allowed a quick cease‑and‑desist and an emergency removal request to publishers, preventing further damage. This incident led Agency X to adopt pseudonymization and mandatory file passwording in vendor onboarding.

Industry‑specific risks include: link profile exposure revealing anchor text patterns; outreach scripts disclosing preferred pitches and publisher relationships; and contact lists enabling direct solicitations or data misuse. For an overview of service tiers and how confidentiality fits into your offering, see our White Label Link Building Solutions Guide and Reseller Packages.

Transition: Knowing why confidentiality matters leads directly to choosing the right NDA type for each relationship.

Types of NDAs and when to use each

NDAs come in flavors: one‑way (unilateral), two‑way (mutual), and limited‑purpose NDAs. Choose based on who discloses sensitive information, the direction of risk, and whether both parties exchange confidential assets.

Type When to use Pros / Cons
Unilateral (one‑way) Client → Reseller or Reseller → Vendor when only one side discloses Simple, fast; favors disclosing party. Less fair if vendor has proprietary methods.
Mutual (two‑way) Both parties share confidential info (e.g., reseller shares pricing models; vendor shares publisher lists) Balanced protections; better for ongoing partnerships but can slow negotiations.
Limited‑purpose When confidentiality is tied to a specific project or narrow set of deliverables Scops the fence around what’s confidential; reduces ambiguity.

Guidance for reseller<>vendor<>client scenarios: use a unilateral NDA when a client supplies sensitive URLs or proprietary data to the reseller, and the vendor only needs limited knowledge (e.g., anonymized URLs). Use a mutual NDA when the vendor will share publisher lists or proprietary outreach techniques that the reseller should not disclose. For partnerships that are narrowly scoped (single campaign or pilot), use a limited‑purpose NDA to define the duration and permitted use tightly. To decide whether you need mutual vs. unilateral protections for your business model, see our White‑Label vs Referral Partnerships.

Transition: After picking a NDA type, draft clauses precisely to cover link‑building specifics.

Key clauses every white‑label link building NDA must include

Below are the essential clauses tailored for link building, with annotated sample language and practical notes. Each entry shows why wording matters—there is a legal trade‑off between breadth and enforceability. For cited legal reference on remedies and definitions, see Cornell LII’s discussion on confidentiality agreements (Cornell LII).

1. Definition of Confidential Information

  • Sample language: “Confidential Information means all non‑public information disclosed by Disclosing Party to Receiving Party, whether oral, written or electronic, including but not limited to client URLs, outreach contact lists, outreach scripts, publisher relationships, pricing, technical processes and any redacted or pseudonymized variants thereof.”
  • Annotation: Use explicit examples (URLs, contact lists, outreach scripts) to avoid arguments about omission. Prefer “means” over “includes” when you want a narrower, definitional scope—”includes” may be interpreted as illustrative, making scope broader.

2. Permitted Use & Purpose Limitation

  • Sample language: “Receiving Party will use Confidential Information solely to perform the Services described in Schedule A (the ‘Permitted Purpose’) and will not use Confidential Information for marketing, competing services, or business development.”
  • Annotation: Purpose limitation prevents scope creep—e.g., a vendor using a client’s contact list to pitch other clients. Attach a Schedule A listing permitted projects.

3. Exclusions from Confidential Information

  • Sample language: “Confidential Information does not include information that: (a) is or becomes public through no breach by Receiving Party; (b) was known to Receiving Party prior to disclosure; (c) is independently developed; or (d) is rightfully received from a third party without restriction.”
  • Annotation: Standard exclusions avoid over‑broad obligations. For link building, insist that “publicly available” does not include publisher pages that list client content only after agreement to remove client identifiers.

4. Subcontractors and Flow‑Down

  • Sample language: “Receiving Party may engage subcontractors to perform services only if (i) the subcontractor is bound by confidentiality obligations no less protective than this Agreement (flow‑down), and (ii) Receiving Party remains liable for subcontractor performance.”
  • Annotation: A flow‑down clause creates direct contractual expectations for subcontractors and preserves vicarious liability. See later section on managing subcontractors.

5. Non‑Solicitation & Non‑Circumvention

  • Sample language: “During the Term and for 12 months after, Receiving Party will not solicit or accept business from, or hire, contacts identified on Disclosing Party’s outreach lists without prior written consent.”
  • Annotation: Non‑solicit prevents vendor or contractor from cutting out the reseller or client. Timeframes should be reasonable—12 months is common in digital services.

6. Remedies and Injunctive Relief

  • Sample language: “Monetary damages may be inadequate; Disclosing Party is entitled to seek injunctive relief, specific performance, and any other equitable relief without posting a bond. The parties agree that liquidated damages of $X per breach (in lieu of actual damages) are reasonable and enforceable.”
  • Annotation: Injunctive relief lets you act fast to prevent publication. Liquidated damages are negotiable—be prepared to explain how you calculated X. For U.S. enforcement mechanics, consult legal resources like the Cornell LII or state bar guidance.

7. Return/Destruction of Materials

  • Sample language: “Upon termination or request, Receiving Party will promptly return or certify destruction of all Confidential Information, including copies, summaries, and derivatives, except to the extent retained for backup as set out in the retention schedule.”
  • Annotation: Include a retention exception for required legal backups and specify timelines and certification procedures.

8. Duration & Survival

  • Sample language: “Confidentiality obligations last for the Term and survive for five (5) years after termination for all Confidential Information, except trade secrets which survive as long as permitted under applicable law.”
  • Annotation: Link building often uses time‑limited confidentiality (3–5 years). Trade secrets can demand indefinite protection; tie survival to legal definitions where appropriate.

Transition: With clause-level choices made, use copy‑ready snippets to speed drafting.

Draft clause bank — ready‑to‑copy NDA clauses for link building

Below are copy‑ready snippets you can paste into drafts. Not legal advice — suggested wording. Customize per deal and have counsel review. Tailor the sample clauses below to the specifics of your white‑label reseller packages.

Mutual NDA intro (suggested wording — consult counsel):
“Each party may disclose Confidential Information. The parties agree that Confidential Information shall be held in strict confidence and used only for the Permitted Purpose.”

Confidential Information definition (tailored to URLs/outreach data — suggested wording):
“‘Confidential Information’ expressly includes: client URLs, target domains, publisher contact lists, outreach email templates, campaign schedules, anchor text strategies, CTR and placement reports, and any pseudonymized or redacted variants thereof.”

Flow‑down clause (suggested wording):
“Receiving Party will ensure subcontractors agree in writing to confidentiality obligations at least as protective as this Agreement and will remain fully liable for any subcontractor breach.”

Anonymity clause (suggested wording):
“Vendor will not identify client by name, logo, or URL in any outreach or public materials; all reporting and outreach templates provided to third parties must use pseudonyms or placeholder domains specified by Disclosing Party.”

Data minimization clause (suggested wording):
“Vendor will collect, access and retain only the minimum Confidential Information necessary to perform the Permitted Purpose and will document data elements accessed for each campaign in an access log.”

Breach notification clause (suggested wording):
“Receiving Party will notify Disclosing Party within 48 hours of any suspected or confirmed unauthorized disclosure, including a summary of affected data, remediation steps taken, and planned further mitigation.”

Signature & execution (suggested wording):
“This Agreement may be executed electronically via e‑signature and in counterparts; electronic signatures have the same force as originals.”

Not legal advice — suggested wording. Each snippet ranges 30–80 words and is designed to be dropped into your standard NDA template and then redlined with counsel as needed.

Transition: Implementing NDAs across multiple vendors reliably requires a structured workflow.

Step‑by‑step process to implement NDAs across reseller, vendor and client relationships

Operationalize NDAs with a playbook to avoid one‑off mistakes. Below are 14 steps with short checklists for each.

  1. Determine NDA type

    • Checklist: Decide unilateral vs mutual vs limited‑purpose; document reasons in contract file.
  2. Define scope and Permitted Purpose

    • Checklist: Attach Schedule A listing campaigns, assets (URLs, lists), and allowed uses.
  3. Identify sensitive assets

    • Checklist: Create an asset register: client URLs, contact lists, outreach templates, proprietary tools.
  4. Map parties & responsibilities

    • Checklist: Assign Disclosing and Receiving Party labels; designate contact persons for notices.
  5. Attach handling & retention schedules

    • Checklist: Define retention duration, backup exceptions, and destruction certification steps.
  6. Include flow‑down requirements

    • Checklist: Require subcontractor NDAs and attestations; collect signed copies pre‑onboarding.
  7. Set technical controls

    • Checklist: Require SFTP, passworded ZIPs or PGP for files; define password rotation and MFA rules.
  8. Draft and circulate draft

    • Checklist: Use your clause bank snippets; mark editable fields; attach schedules.
  9. Redlining & negotiation

    • Checklist: Track redlines, require business justification for carve‑outs, keep an issues log.
  10. Countersignature & execution

    • Checklist: Use e‑signature (DocuSign/HelloSign); capture execution metadata and store PDFs.
  11. Secure storage & version control

    • Checklist: Save signed NDA in contract repository; maintain document control and naming convention (e.g., NDA_Client_Project_V1_signed.pdf).
  12. Grant access & enforce least privilege

    • Checklist: Provision access only to named users; use role‑based permissions and password managers for shared credentials.
  13. Periodic review & renewal

    • Checklist: Review NDAs annually; re‑execute if scope changes; log expirations.
  14. Offboarding & termination handling

    • Checklist: Revoke access, collect destruction certifications, and record retention exceptions.

Checklist notes: When defining the scope of an NDA, align confidential deliverables with the service levels described in our White Hat Link Building Service Guide and Pricing Details. If you’re productizing services, see Productize White‑Label Link Services for contract standardization tips that streamline NDA rollout.

Transition: With contracts in place, operational tactics keep client identity safe during outreach and reporting.

Protecting client identity in outreach and reporting

Protecting client identity requires operational and editorial controls: redaction, pseudonymization, and reporting aggregation are practical tools. Pseudonymization: replace client names and URLs with placeholders or redirect tracking domains; redaction: remove client identifiers from documents; aggregated reporting: show outcomes without per‑domain attribution.

How‑to steps:

  1. Use placeholder domains and redirects

    • Example: Use campaign.example.com to proxy outbound links; map redirects so publishers see an innocuous hostname while analytics record the true destination.
  2. Pseudonymize contact lists

    • Example: Replace “ClientName” with “Client‑A” in CSVs provided to vendors; keep a mapping table in a secure, access‑controlled vault.
  3. Redact sensitive fields

    • Example: Remove client emails, billing info, and internal notes before sharing outreach spreadsheets. Use search/replace scripts to ensure no residual mentions.
  4. Use white‑label reporting

    • Example: Create reports that show placement counts, domain authority metrics and clicks without linking placements to client domains; use the White‑Label Report Template to standardize.
  5. Lock outreach scripts

    • Example: Provide vendors with non‑editable PDFs of outreach templates using placeholders; require prior approval for any publisher‑facing customization.

Comparison table — Anonymization methods

Method Use case Pros / Cons
Redaction One‑off docs where specific fields must be removed Simple; risk of missed instances unless automated.
Pseudonyms/Placeholder Domains Ongoing vendor access and reporting Preserves workflows; requires mapping security.
Aggregated Reporting Performance reporting without per‑placement exposure Good for public or cross‑client dashboards; hides granular detail.

Implementation tactics (practical examples):

  • Use placeholder anchors and avoid using brand names in anchor text; substitute generic descriptors like “industry insights”.
  • Remove schema markup or meta tags containing client names on published partner pages, or route through a neutral domain.
  • In PR outreach, use neutral bylines and company bios; do not share internal memos or proprietary pitching angles with vendors.
  • Cross‑check anonymization steps against our QA Checklist for White‑Label Links before publish.

Transition: Anonymization helps, but technical data handling completes the protection layer.

Secure data handling and transfer best practices

Technical controls reduce accidental disclosures. According to a 2024 NIST guidance on cybersecurity (NIST Cybersecurity Framework), encryption, least privilege and audit logging are core controls (NIST).

  1. Use secure file transfer: Mandate SFTP or secure cloud links with expiration for sharing CSVs and reports; avoid open shared drives.
  2. Encrypt at rest and in transit: Use TLS for web transfers and PGP/SMIME for email attachments when sending lists; require passworded ZIPs where PGP is not feasible.
  3. MFA and password management: Require multi‑factor authentication and a team password manager for shared credentials; rotate vendor passwords quarterly.
  4. Least privilege & access controls: Grant vendor access only to named assets; implement role‑based access control and review access quarterly.
  5. Audit logs & monitoring: Maintain access logs and set alerts for anomalous downloads or sharing events; retain logs per retention schedule.
  6. File naming conventions: Use standardized names (e.g., ClientA_ProjectX_URLs_20260601_redacted.csv) to indicate status and redaction level.
  7. Storage retention: Define retention schedules and automatic deletion for temporary files; retain only backups required by law.
  8. Vendor security attestations: Request SOC2 reports or security questionnaires from vendors performing hosting or handling sensitive lists.

For incident response and breach handling guidance, consult CISA resources on incident response (CISA).

Transition: Flowing controls to subcontractors is crucial—here’s how to manage them contractually and operationally.

Managing subcontractors and vendor flow‑downs

Subcontractors (subprocessors) are frequent in link building—outsourced outreach controllers, content writers, or local PR contacts. Use a flow‑down clause to contractually bind them and operationally control their access.

Recommended contract language: include an explicit flow‑down and vendor responsibility matrix specifying which tasks may be subcontracted, approval processes, and who holds liability. Practical steps:

  • Require each subcontractor to sign a standalone NDA that mirrors the principal NDA’s key clauses (flow‑down).
  • Collect security attestations and maintain a registry of subcontractors with expiration dates and physical location (for cross‑border checks).
  • Perform periodic attestations where subcontractors confirm they have no retained copies of confidential contact lists after project completion.

Checklist — contractual & operational steps:

  • Insert flow‑down clause and specify subcontractor approval process.
  • Require indemnity for breaches caused by subcontractors.
  • Run quarterly audits or request SOC2/type II where applicable.
  • Maintain evidence of signed subcontractor NDAs and attestations.

For broader commercial clauses and how they interact with NDAs, review Reseller Agreements: Key Clauses.

Transition: Negotiation often stalls on a few predictable points—here’s how to handle them.

Negotiating, redlining, and common sticking points

Negotiation friction typically centers on scope (broad vs narrow definitions), remedies (liquidated damages), non‑solicit windows, and subcontractor liabilities. Know your leverage: agencies selling ongoing work can insist on injunctive relief; vendors supplying standardized placements might prefer liability caps.

Common vendor objections and counter‑proposals:

  • Objection: “Liquidated damages are too high.” Counter: “We can tie liquidated damages to proven remediation costs and market harm; propose a capped amount with an injunctive carve‑in.”
  • Objection: “No‑hire provision is too broad.” Counter: “Reduce to contacts explicitly listed in Schedule B and limit to 12 months.”
  • Objection: “Indemnity for subcontractors is unconscionable.” Counter: “Accept indemnity for gross negligence or willful misconduct; require flow‑down obligations.”

Negotiation scripts — short phrases to use:

  • “Let’s narrow the definition to Schedule A items — that keeps everyday communications free.”
  • “We’ll accept a reasonable liability cap if injunctive relief remains available for publication risk.”
  • “We require signed subcontractor NDAs and one‑page attestations for each contractor — can you provide that?”

When to push back table (simple guidance):

Issue When to push back
Unlimited liability Always push back—insist on a reasonable cap tied to fees or a multiple thereof.
Vague confidential definition Push back—demand specific examples and an exclusions list.
No return/destroy clause Push back—require return or certified destruction within a set window.

Clarify relationship ownership as part of negotiations — read Who Owns Relationships — You or Vendor? for guidance on control and client contact clauses.

Transition: If a breach occurs, follow a clear escalation and notification plan.

Breach detection, notification and enforcement

Have a documented breach response plan aligned to contractual notification timelines. According to CISA guidance (see CISA), rapid detection and containment reduce damage. Also consult legal resources on remedies and injunctions (e.g., Cornell LII).

How‑to steps:

  1. 0–72 hours (initial response)
    • Confirm scope: what data, which systems, which publishers.
    • Notify internal incident lead and legal counsel.
    • Send initial vendor notification per NDA (48‑hour clause if present).
    • Contain: revoke access, disable credentials, take affected files offline.
  2. 72 hours–30 days (investigation & remediation)
    • Forensics: capture logs, preserve evidence, identify the root cause.
    • Remediation: remove exposed content, request takedown from publishers, rotate credentials.
    • Communication: provide status updates to client and impacted parties.
  3. >30 days (enforcement & lessons learned)
    • Consider enforcement: injunctive relief, mediation, damages, or liquidated damages where agreed.
    • Document lessons learned and update controls and NDAs.

Breach notification email template (short):

Subject: Urgent: Suspected Confidentiality Breach – Immediate Action Required

We have identified a potential unauthorized disclosure affecting [description of data]. Please confirm receipt of this notice within 4 hours and provide a remediation plan within 24 hours. We have temporarily revoked access to [systems/files]. Contact: [Incident Lead name/email/phone].

Enforcement options: emergency injunctive relief to halt publication; damages or liquidated damages per NDA; alternative dispute resolution clauses (mediation/arbitration) for cost‑effective outcomes.

Transition: Keep records of everything—retention and audit trails support enforcement and compliance.

Retention, recordkeeping, and auditability

Maintain a retention schedule and auditable trails for NDAs, access logs and outreach data. Good recordkeeping proves due diligence in the event of disputes.

  1. Retention schedule bullets:
    • Signed NDAs: retain for duration of relationship + 7 years.
    • Outreach contact lists: retain only as required by active campaign; purge within 90 days after campaign end unless otherwise agreed.
    • Access logs and audit trails: retain for 1–3 years depending on regulatory needs.
  2. Auditability steps:
    • Store NDAs in a central contract repository with versioning.
    • Log every file access and export; require justification for downloads.
    • Run quarterly compliance checks and produce attestations for clients.

Transition: Cross‑border work introduces additional legal constraints—know when to get counsel involved.

Cross‑border and regulatory considerations

Cross‑border data transfers and international clients trigger privacy laws like the GDPR. For EU clients, pseudonymization and a lawful basis for processing are critical. Consult official EU guidance (see the European Data Protection Board resources at EDPB and practical summaries at gdpr.eu).

US domestic vs EU/GDPR comparison bullets:

  • US: Contract law and state privacy laws vary; prioritize injunctive relief and liquidated damages clauses for speedy remedy.
  • EU/GDPR: Data controllers/processors rules apply—ensure legal basis, data transfer mechanisms (SCCs/adequacy), and appropriate technical measures (encryption, pseudonymization).

When to involve counsel: negotiating jurisdiction and governing law clauses, handling potential data subject access requests (DSARs), and drafting transfer mechanisms for personal data crossing borders.

Transition: Finish with a short red flags checklist and one‑page playbook summary for quick reference.

Red flags, checklist and playbook summary

Watch for suspicious or risky contract language and operational gaps. The must‑have / avoid two‑column list below helps vet NDAs quickly.

Must‑Have Avoid
Clear definition with examples Vague “proprietary information” without examples
Flow‑down and subcontractor obligations No return/destruction provision
Reasonable duration and survival Unlimited liability for routine breaches
Breach notification timeline & injunctive relief No breach notification or long notice windows

Red flags checklist (Do / Don’t):

  • Do: Require signed subcontractor NDAs and maintain a registry.
  • Don’t: Accept undefined “Confidential Information” that can be expanded later.
  • Do: Insist on return/destruction certification and retention schedules.
  • Don’t: Accept vendor requests for blanket rights to use contact lists for other clients.

Printable one‑page playbook summary (text only):

  • Step 1: Choose NDA type (Unilateral/Mutual/Limited)
  • Step 2: Attach Schedule A listing confidential assets (URLs, lists, scripts)
  • Step 3: Include flow‑down and require subcontractor NDAs
  • Step 4: Specify breach notice (48 hours) and injunctive relief
  • Step 5: Operational controls—SFTP/PGP, passworded files, MFA, least privilege
  • Step 6: Anonymize: pseudonyms/placeholders, aggregated reports
  • Step 7: Store signed NDAs in central repo; maintain access logs
  • Step 8: Test breach response quarterly; update playbook after incidents

Transition: Appendix includes a downloadable template, toolkit and next steps, plus a final legal caveat.

Appendix — Checklist, sample NDA template download and next steps

Toolkit offered (used and refined in X engagements): downloadable sample NDA, implementation checklist, and a breach notification email template. These templates have been used in multiple vendor onboarding cycles and updated after vendor feedback; consider them starting points only.

Download the Sample NDA Template, implementation checklist, and breach notification email. Legal disclaimer: This template is a starting point and not legal advice—have counsel review before execution.

Next steps:

  • Map confidential assets for each client campaign and attach Schedule A to the NDA.
  • Run vendor security checks and obtain signed subcontractor NDAs before any data transfer.
  • Implement the breach playbook and test incident response within 90 days.

Transition to conclusion: Summarize the key takeaways and recommended actions.

Conclusion: Manage Confidentiality and NDAs proactively to protect client identity, preserve publisher relationships, and reduce legal and reputational exposure. Use purpose‑limited NDAs, explicit definitions that include URLs and outreach lists, flow‑down clauses for subcontractors, and technical controls (SFTP, encryption, MFA). Maintain auditable records and a tested breach response. Ready your templates, run security attestations, and consult counsel for cross‑border work — then operationalize the playbook above.

Frequently Asked Questions

What is an NDA and when should a white‑label agency use one?

An NDA (non‑disclosure agreement) is a contract protecting non‑public information. Use one whenever client URLs, outreach contact lists, outreach scripts, or publisher relationships are shared with resellers or vendors to prevent disclosure, outline permitted use, and set breach remedies.

Mutual NDA vs unilateral NDA — which is better for vendor and reseller relationships?

Use a unilateral NDA when only one party discloses sensitive data (e.g., client URLs). Choose a mutual NDA when both sides share confidential assets (publisher lists, proprietary methods). Mutual NDAs balance obligations but may slow negotiations.

How do I redact or anonymize a client’s identity before outreach and reporting?

Replace client names and URLs with pseudonyms or placeholder domains, remove identifying metadata, use aggregated reporting, and map redirects for analytics. Keep a secure mapping table and certify redaction before sharing files with vendors.

How do I implement NDAs across multiple vendors and subcontractors step by step?

Follow a 14‑step workflow: choose NDA type, define scope and Schedule A, identify assets, require subcontractor flow‑downs, set technical controls, circulate drafts, e‑sign, store signed copies centrally, enforce least privilege, review quarterly, and manage offboarding.

How long does an NDA need to last for link building confidentiality?

Common survival periods are 3–5 years for confidential information, with trade secrets surviving as allowed by law. Tailor duration to campaign lifecycle and competitive risk; specify survival language in the NDA.

What should I do if a vendor or subcontractor breaches the NDA?

Follow your breach plan: contain the exposure, notify stakeholders within contractual timelines, conduct forensics, request takedown/remediation, and consider injunctive relief, liquidated damages, or mediation per the NDA.

How do cross‑border clients affect NDA language and data transfer requirements?

Cross‑border work may trigger data protection laws (e.g., GDPR). Add clauses for lawful transfer mechanisms (SCCs), specify governing law and jurisdiction, and include technical measures like pseudonymization and encryption; involve counsel for EU transfers.

What clauses are common red flags to avoid in a link‑building NDA?

Avoid vague confidentiality definitions, no return/destruction provisions, unlimited liability, missing flow‑down obligations, and overly long survival clauses. Insist on clear examples, reasonable caps, and subcontractor protections.