# Website Legal Check

The legal basics a UK business website must have, checked the way a visitor sees them, and who's behind the site.

Company details on the site matched to Companies House, privacy notice, cookies before consent (real browser), ICO fee, contact details; plus the registered company behind the site. The Business Score's legal category, on its own.

Every UK business website has a short list of things the law asks for: the company's registered details on the page (the Trading Disclosures Regulations 2015), a privacy notice that says what UK GDPR asks it to say, no advertising or tracking cookies before the visitor agrees (PECR; analytics-only cookies have been allowed under conditions since 5 February 2026, so they're noted, not scored), the ICO data protection fee, and an email and postal address (the E-Commerce Regulations 2002). This endpoint reads the homepage and its linked legal and contact pages, visits the site in a real browser to see what cookies land before anyone clicks, matches the details it finds to Companies House, and gives every check back with its result, what we saw and the rule it reads against. It also says who's behind the site: the registered company the site states or confirms, never a guess dressed as a fact. Not legal advice; it says so on every reply.

- Price: 4 credits (8 on the free plan)
- Page: https://meetkatalis.com/apis/website-legal
- OpenAPI: https://meetkatalis.com/openapi.yaml

## Endpoints

- `GET /api/v1/website-legal?url=…` — A domain or URL; add &company=<number> to name the company yourself

## Call it

```bash
curl -H "x-api-key: $KATALIS_API_KEY" \
  "https://meetkatalis.com/api/v1/website-legal?url=https://www.greggs.com"
```

```javascript
const res = await fetch("https://meetkatalis.com/api/v1/website-legal?url=https://www.greggs.com", {
  headers: { "x-api-key": process.env.KATALIS_API_KEY },
});
if (!res.ok) throw new Error(`Katalis ${res.status}: ${await res.text()}`);
console.log(await res.json());
```

```python
import os, requests

r = requests.get(
    "https://meetkatalis.com/api/v1/website-legal?url=https://www.greggs.com",
    headers={"x-api-key": os.environ["KATALIS_API_KEY"]},
    timeout=60,
)
r.raise_for_status()
print(r.json())
```

## Example response (a real reply)

```json
{
  "url": "https://www.greggs.com/",
  "behind": { "name": "GREGGS PLC", "number": "00502851", "status": "active", "type": "plc", "registeredOffice": "Greggs House, Quorum Business Park, Newcastle Upon Tyne, NE12 8BU, United Kingdom", "how": "stated on the site", "confirmed": true },
  "registrationsStated": [{ "number": "00502851", "kind": "company" }, { "number": "Z7225689", "kind": "ico" }],
  "legal": {
    "score": 100,
    "checks": [
      { "code": "privacy_notice", "result": "pass", "found": "A privacy notice is linked, and it covers the basics (what, why, how long, people's rights, who to contact)", "rule": "UK GDPR, Articles 13 and 14" },
      { "code": "cookies_before_consent", "result": "pass", "found": "We didn't see any of the common advertising or tracking cookies we test for set before visitors agree", "rule": "PECR, regulation 6" },
      { "code": "company_disclosure", "result": "pass", "found": "The registered name, company number and registered office are on the site (they match Companies House)", "rule": "The Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015" },
      { "code": "ico_fee", "result": "pass", "found": "On the ICO register of data protection fee payers", "rule": "The Data Protection (Charges and Information) Regulations 2018" },
      { "code": "ecommerce_contact", "result": "pass", "found": "An email address and a postal address are on the site", "rule": "The Electronic Commerce (EC Directive) Regulations 2002, regulation 6" }
    ],
    "couldntCheck": []
  },
  "pagesRead": [{ "kind": "privacy", "url": "https://www.greggs.com/legals/privacy-policy" }, { "kind": "cookies", "url": "https://www.greggs.com/legals/cookie-policy" }, { "kind": "terms", "url": "https://www.greggs.com/legals/terms-and-conditions" }, { "kind": "contact", "url": "https://www.greggs.com/contact" }]
}
```

## What you'd build with it

- **Web agencies.** Run it on every site you build or take over; fix the five things before the client's lawyer, or the ICO, finds them.
- **Onboarding and due diligence.** A supplier or partner site with no company details, no privacy notice and ad cookies before consent tells you something on day one.
- **Platforms and directories.** Show each listed business where it stands, and sell the fix.

## Why this one

- **What a visitor actually gets.** Cookies are read from a real browser visit with nothing clicked: what lands before consent, not what the cookie policy claims.
- **Matched to the register.** The company details on the site are checked against Companies House, and the company behind the site is confirmed by the site itself or marked as matched by name only.
- **Every check names its rule.** Result, what we saw, the regulation, and what to do: a fix list the client can act on, never a certificate.

## Conventions

- Auth: `x-api-key: kat_live_…` on every request (free key at https://meetkatalis.com/developers: a verified email and mobile, 100 credits a month, no card).
- One credit balance across every API; each endpoint's price is on its page and in `x-credits` in https://meetkatalis.com/openapi.yaml.
- Keys are camelCase everywhere. A registered company is `company: { name, number, status, statusDetail?, filingsOverdue? }` on the register endpoints; the enrichment family (enrich, score, assess, brand-kit, ai-visibility, tender-match) keeps `business` / `profile` with `companyNumber`.
- Every error has `code` and `requestId`; every reply an `x-request-id` header; a charged reply `x-credits-remaining`; a reply that gave credits back `x-credits-refunded`. Missing = 404 with `query`.
- Burst ceiling 60 requests a minute per key (429, `Retry-After`, no credits used). A failure on our side (5xx) gives the call's credits back.
- Company data contains public sector information licensed under the Open Government Licence v3.0.

Provided "as is"; results come from public sources and, in places, AI, and may be inaccurate or out of date; not legal, professional or credit advice. Terms: https://meetkatalis.com/apis/terms