Contract & Dispute Prevention

How Much of Your Idea Do You Have to Reveal to Get a Quote — Pre-Contract Information Protection and NDAs

How much of your idea you actually have to disclose to get a quote, and what protects information before a contract exists. Covers what copyright and trade secret protection reach, which information a quote genuinely needs and which can wait until after signing, the four things that make an NDA do any work, exposure management when you compare several vendors, and draft clauses with a pre-quote checklist.

Son Yeongeun · Freesi·
Summary in 3 Lines
  • The law puts its weight behind output that has taken a form: code and screen layouts, documents managed as confidential, and data you handed over.
  • A quote is priced from the shape of the data, how many branches the exceptions have, and how many integrations are attached. Real data, partner names, and integration keys can wait until after the contract and a banded quote still comes back.
  • An NDA works when it identifies what is covered, bars use outside the stated purpose, and sets a destruction date. A document that only prohibits disclosure leaves the exact behaviour that worries people at the quote stage outside its clauses.

What the Law Protects, and What It Does Not

There is a point in writing a request-for-quote email where the cursor stops. Describe the project loosely and no usable number comes back. Describe it fully and the document travels to three or four companies you have never worked with. Nothing is signed yet, so there is little to point to if the file ends up somewhere it should not. The email gets postponed to next week.

The phrase "protecting my idea" sits at an angle to how these protections actually work.

Under Korean copyright law, as under the copyright law of English-speaking jurisdictions, copyright protects expression, not the idea behind it. "A system that takes bookings for neighborhood car washes through a messenger app" is a concept. What copyright attaches to is the code as written, the screen layout, the wording — output that has taken a form. Someone who hears the same concept and writes their own code has produced a separate work.

Trade secret protection has three elements: the information is not generally known, it carries independent economic value because it is not known, and reasonable measures have been taken to keep it secret. The third element is the one that gets argued in practice. A planning document uploaded with no marking on it, a file that opens for anyone holding the link, a deck dropped into a group chat — none of those give you much to stand on when you claim you managed the material as a secret. A CONFIDENTIAL marking, restricted access, and a record of who received what and when are what "reasonable measures" means in practice. All of it is ordinary file-handling discipline and costs nothing.

The protection you can actually lean on at the quote stage is the purpose-limitation clause in an NDA together with the order in which you disclose things. Korea's Unfair Competition Prevention Act added a provision in 2018 treating it as unfair competition to take an idea received during trade negotiations — a business proposal, a bid — and use it for your own benefit against the purpose for which it was given. The provision carries a carve-out: ideas the recipient already knew, or that are widely known in that industry, fall outside it. A concept written up as "I want to build a service like this" can land inside that carve-out. Where the provision has force is a specific method, documented and handed over, that people working in that industry did not already know — a particular calculation rule, a processing sequence, a grading standard refined over years.

Which leaves sequencing as the lever that is actually in your hands. Deciding what to say first and what to hold back reduces the volume of information that leaves your control more than a signed NDA does.

Wondering what your project would cost by these standards? check in 30 seconds

What a Vendor Actually Needs in Order to Quote

The first things a vendor checks when pricing are where the data comes from and what shape it arrives in, how many branches the exceptions have, and how many external services have to be attached. What business you are in reaches the number only through those three. A class-management system for 500 members and a gym-management system for 500 members land at similar prices when the screen count and rule count are similar, whatever the industry.

Needed for a quoteCan wait until after the contract
Screen and feature list (names only)Service name, brand, unreleased plans
Where the data comes from and what shape it is inThe actual data files
Type of integration (payments, SMS, maps)Integration accounts and API keys
User-count band and role distinctionsThe actual customer list
Number and complexity of business rulesThe real values in your pricing and margin formulas
Target date and budget bandInvestment plans, competitive strategy

The left column on its own produces a banded quote. The right column is what the work needs after the contract is signed. The customer list is needed when data is migrated, the API keys on the day the integration is attached, the real values in your pricing formula when the screens get filled in. At the moment a quote is written, a count in that slot — "three kinds of rule" — is enough for the effort to be calculated.

Substitution does the work. Where you would have written "automatic calculation using the price table for our 15 trading partners," write "10 to 20 trading partners, a different unit price for each, three calculation rules." The information the effort estimate runs on stays intact and the amount that leaves your hands shrinks. Brands work the same way: writing "a B2C booking service" in the slot where the unreleased service name would go costs the quote nothing. When you attach screenshots, check once that real customer names and amounts are not sitting in them.

One item does have to go out, or no quote comes back: the actual shape of the data. "We receive it in Excel" and "we receive several dozen Excel files a month, each partner using a different layout" are different builds. The first reads one file and loads it. The second brings layout detection, exception handling, and a screen where a person confirms what the system could not resolve. That layouts vary is not itself a secret, so it is worth saying up front. When it surfaces after the quotes are in, the number goes up, and by then the basis you were comparing vendors on has already come apart.

What Makes an NDA Work

If the definition of confidential information ends at a single line — "all information learned in connection with this matter" — a dispute stalls at the point where you have to identify what the confidential information actually was. A wide definition reads as strong, and it leaves whoever is judging the matter with no basis for drawing a boundary. Adding more clauses does not repair that. Four things decide whether the document does any work.

Identifying what is covered

There has to be a test someone can apply: material supplied in writing bearing a CONFIDENTIAL marking, or something said aloud and confirmed in writing within a set number of days. If you want what was said in a meeting to count as confidential information, that confirmation step has to be written into the clause for the claim to hold later.

A purpose-limitation clause

An NDA that only prohibits disclosure leaves the recipient's own use of the material untouched, as long as nothing is handed to a third party. That use is precisely what worries people at the quote stage. One line — "shall not use the information for any purpose other than the purpose for which it was provided" — is what covers it.

A destruction date

Check whether the document says what happens to the material you handed over if the quote goes nowhere. Templates drafted on the assumption that a contract follows sometimes end without addressing that case at all. A destruction deadline and a written notice that destruction happened are what make the clause get executed.

What follows a breach

Loss from a leak is hard to quantify, so parties may fix a liquidated-damages figure in advance. Korean courts can reduce a pre-agreed figure they find unreasonably excessive, so a number you can explain against the value of the project holds up better than a number chosen to intimidate.

Scale matters as well. Sending a five-page NDA in response to a repetitive-task automation request in the few-hundred-thousand-KRW range (roughly USD 200–700, project total) is a heavy procedure for the size of the job. A CONFIDENTIAL marking on the first page and one line in the email body — "please use this material only for the purpose of preparing a quote" — already leave a record that you managed the material as confidential. The NDA can come out at the second stage, when the detailed material changes hands.

Curious how a project like this actually goes?
See real cases and reviews of similar work first.
View real cases

Managing Exposure When You Ask Several Vendors

Sending the same request to three or four vendors is a normal comparison process. Giving all of them the same detailed pack multiplies your exposure by the number of vendors. You sign with one, and the detailed pack stays in the inboxes and on the servers of the rest.

Split it into two stages. Stage one is a one-page summary: a paragraph on what you want built, the feature list, the data-volume band, what has to be integrated, your target date, your budget band. In the inquiries we receive, that is enough to produce a banded quote. At stage two you narrow the field to two or three candidates, exchange an NDA, and hand over the detail.

If a vendor replies that they cannot quote from the summary, ask what else they need. When the follow-up questions are specific — how many exception cases there are, whether existing data has to be migrated — that vendor has earned the detailed pack. A reply that asks nothing and says "send us everything" gives you nothing to judge by. Asking back is an exposure control and a screening step at once. After the contract you will be doing requirements scoping together anyway, and this tells you in advance whether that conversation is going to work.

Two habits cover the document side. Put a CONFIDENTIAL marking, the date, and the recipient's name on the first page, and name a different recipient for each vendor — that leaves a trace of where a circulating file came from. Someone who strips the cover page and copies the body defeats it; a file that travels whole can still be traced. Then send the emails individually. Several vendors on CC tells competitors about each other and hands over their addresses. BCC has a way of surfacing during a reply chain, so separate emails are the safer habit.

The View from the Receiving Side

This section is written from where we sit, on the side receiving the request.

Running someone else's business concept means taking on sales, customer support, and working capital. That is a different line of business from development, and a team staffed for development does not move into it easily. The picture of a vendor lifting a concept whole and going off to execute it runs into that structure.

Two places do generate real disputes. One is code reuse. Carrying a module from one project into the next client's project is a normal part of development — writing login, permission handling, and file upload from scratch every time adds duration and cost and produces nothing new. The line sits at the parts where the client's business rules are embedded: pricing rules, dispatch ordering, inventory deduction logic, grading criteria, the things a company has refined over years. When that part moves, a competitor ends up with a system running on the same rules.

The other is data. A customer list or transaction history handed over for testing does not disappear when acceptance is signed off. It has to be deleted separately from the vendor's laptop, the development server, the staging database, and the backups. Material kept deliberately and material left behind because nobody cleaned up produce the same outcome. So a destruction clause is worth writing to cover "the data provided and all copies thereof," with development servers and backups named explicitly. There is also the option of handing over pseudonymized sample data in the first place. Names and phone numbers get masked and the digit counts, formats, and edge cases survive, so development and testing are unaffected.

One point cuts against the client here. Demanding a blanket ban on code reuse raises the quote, because login, permission handling, and payment integration then have to be written from scratch. Narrowing the restriction to the portions carrying your business rules, with general-purpose modules and open source excluded, closes the gap you were worried about and leaves the price where it was.

Draft Clauses and a Pre-Quote Checklist

The clauses below need a number of days filled in to work as a draft. Where the amounts are large or personal data changes hands, a lawyer's review before signing is worth the cost.

Purpose limitation — "Party B (Vendor) shall not use information provided by Party A (Client) for any purpose other than performance of this contract, nor provide such information to any third party."

Identifying confidential information — "Confidential information means material provided by Party A in written or electronic form bearing a CONFIDENTIAL marking, and information provided orally and notified in writing as confidential within ○ days thereafter."

Limit on reuse of business rules — "Party B shall not use, in any other client project, the portions developed under this project that reflect Party A's business rules. General-purpose modules and open-source software held by Party B prior to execution of this contract are excluded."

Destruction of materials — "Party B shall destroy the data provided by Party A and all copies thereof, including copies held on development servers and in backups, within ○ days of acceptance completion or termination of this contract, and shall notify Party A of the result in writing."

Things to confirm at the quote stage:

If you cannot decide how much to send, one summary page and a question about what else is needed is a complete first move. Freesi quotes in that order — a banded quote from the summary, detailed material after an NDA at the second stage.

Rough estimate in 5 seconds

Two questions, no contact info. Ranges are from real contracted prices.

Wondering what your project would cost?

Enter your requirements and see a quote range in 30 seconds — based on real project prices. No sales calls.

Frequently Asked Questions

I asked for an NDA and the vendor wants to use their own template. Can I just sign it?
A vendor putting their own form forward is not unusual in itself. Vendors have their own technical information and existing modules to protect, so the document is sometimes written as mutual, with obligations running both ways. Three places are worth reading when one arrives. Whether the clause defining confidential information reaches both sides' material. Whether the non-disclosure clause stands alone, with nothing stopping the recipient from putting the material to use in their own business. Whether the destruction clause still operates in the case where no contract follows. If the answer is that they will not sign anything, ask why. "Not needed at the summary stage, let us sign one before the detailed material moves" is a judgment about sequencing. A refusal with no reason attached leaves you short of a basis for handing over the detailed pack, and the option then is to keep the CONFIDENTIAL marking on the document and one line in the email, and stop at the summary stage.
I have already sent a detailed plan to several vendors. Is there anything left to do?
You cannot pull back what went out, and three things are still available. Write out a list of who received what and when — leaving the originals in your sent folder preserves both the timestamp and the content. Send a destruction request to the vendors you have ruled out; one line does it ("the material sent on [date] was provided for the purpose of preparing a quote, please destroy it"), and the email itself becomes a record that you managed the material as confidential. Then hold everything not yet sent until the contract is signed: real data, integration keys, customer lists, the real values in your pricing formulas. If what has gone out so far is a feature list and a concept, the remaining risk sits with the things still to come.
What if the vendor builds the same service from my idea?
To argue it you need a record of what you gave them and when, and something that reads as a trace of them having used it. Three things to have ready. Keep the original files and the sending email unmodified, with the CONFIDENTIAL first page intact. If their product has appeared, capture the screen layout, the wording, and the processing sequence, and record whether items that existed only in your material have moved across, with dates attached to the captures. And where your contract carries a purpose-limitation clause and a limit on reuse of business rules, you can argue breach of contract before anyone has to weigh the unfair-competition elements. Where no contract was signed, the NDA exchanged at the quote stage plays that role.

Related Guides

Share

Comments

0/1000
Freesi
Son Yeongeun
Lead developer at Freesi — SI software outsourcing · N:D
admin@freesi.net
Get a 30-Second AI Quote