GO
Overall Score
PraktykaTrail
1. One-liner
Watches how your Polish contractors actually work, so a PIP inspector cannot reclassify them into employees.
2. Trend signal — why now?
On 8 July 2026 Poland’s National Labour Inspectorate (PIP) got a power it never had: it can now convert a B2B or civil-law contract into an employment contract by administrative decision, with no court case. Previously an inspector had to sue on the worker’s behalf. Now a regional labour inspector signs a decision, and per Kancelaria Gabrysiak an appeal to the labour court “nie wstrzymuje automatycznie jej skutków” — it does not suspend the effects. You treat the contractor as an employee from the day the decision is served, while you argue.
Three things make this urgent rather than merely interesting:
The amnesty is a countdown, not a reprieve. VATAX confirms a 12-month transition window from 8 July 2026 to 8 July 2027 in which voluntary corrections avoid PIP administrative fines. It does not shield you from ZUS or tax. So the amnesty removes the smallest part of the bill and leaves the large part running.
The exposure per head is brutal. A worked simulation via Zakaz Konkurencji puts one developer on an 18,000 PLN/month contract, reclassified three years back, at roughly 190,000 PLN (~€44K): ~66,000 PLN of back ZUS, ~54,000 PLN of holiday equivalent, plus a 60,000 PLN fine. ZUS arrears run up to five years. Fines doubled to a 2,000–60,000 PLN range.
The market is enormous and structurally exposed. Per eGospodarka, 73.6% of Polish IT job offers were B2B contracts, and GUS counts 229,000+ registered software/IT businesses, 99% of them under 10 people. Polish IT built its entire labour model on the thing that just became administratively reversible.
Here is the part that defines the product. Inspectors do not read your contract template. Poradnik Przedsiębiorcy states PIP analyses “faktyczny przebieg umowy, a nie tylko to, co widnieje na papierze” — the actual course of the engagement, not what’s on paper. Umowy w IT is blunter: every Slack message and every hour logged in a system can become evidence in a case determining an employment relationship. Daily standups, 9–17 hours, company laptops, leave-approval workflows — these are the red flags, and none of them live in a contract.
Provenance:
- Signal 1 (demand): PIP gains administrative reclassification power 8 July 2026; 12-month amnesty ends 8 July 2027; fines doubled to 60,000 PLN; law firms across Poland (EY, Conselion, DSK, RPMS, After Legal, Stasik) all launched manual “audyt umów B2B” offers — https://www.vatax.pl/blog/nowe-uprawnienia-pip-kluczowe-informacje — 2026-09-04
- Signal 2 (feasibility): The deciding evidence is operational, not contractual — inspectors weigh Slack, Jira, standups, timesheets and fixed hours; these all sit behind stable read APIs (Slack, Jira, Google/M365 Calendar) that cheap LLM classification can now score against the statutory criteria — https://umowywit.pl/nowe-uprawnienia-pip-a-umowy-b2b/ — 2026-09-04
- Signal 3 (economic): ~190,000 PLN modelled exposure per single reclassified developer, ZUS arrears to 5 years, against a base of 229,000+ Polish IT firms where 73.6% of roles are B2B — https://zakaz-konkurencji.pl/korekta-zus-5-lat-wstecz-ile-zaplacisz-po-decyzji-inspektora-symulacja/ — 2026-09-04 Category: Regulatory arbitrage
3. The opportunity
Every law firm in Poland is selling the same thing right now: a one-off manual audit of your B2B contracts. Conselion’s offer page describes a “zespół doświadczonych radców prawnych” reading contracts and producing a risk report with revised templates. No price listed, no software, no ongoing monitoring. Umowy w IT — itself a law firm — says the quiet part out loud: rather than software, what matters is “spójność dokumentacji z praktyką operacyjną,” consistency between documentation and actual operational practice.
That is the gap, stated by the incumbents themselves. They audit the paper. The inspector judges the practice. A contract audit is a photograph of the day you paid for it; the risk accumulates every day afterward, generated by team leads who have never read the contract and are just running their sprint.
The specific failure mode: a company pays 20,000 PLN for an audit in September, gets clean templates, and by March a project manager has instituted a daily 9:15 standup with attendance, moved everyone onto company laptops, and started approving contractors’ holidays in the HR tool. The audit is now worthless and nobody knows. When the inspector arrives, the evidence against the company was generated by its own tools, timestamped, and exported by the company’s own admins.
The wedge is that this evidence is machine-readable and already exists. Slack, Jira, Google Calendar and M365 hold the exact signals the nine Deliveroo-style criteria turn on. Nobody is reading them for this purpose because the market’s muscle memory is “compliance = lawyer reads document.”
4. Target market
Primary customer: The COO, CFO or Head of People at a Polish software house, IT services firm, or digital agency with 20–200 contractors on B2B, revenue roughly 10–100M PLN. Warsaw, Kraków, Wrocław, Poznań, Gdańsk. The person who signed the law firm’s invoice and is now responsible for the thing not happening again. Secondary: Polish subsidiaries of foreign tech companies, where the parent’s legal team is asking uncomfortable questions.
Why they buy: They have a 190,000 PLN-per-head number in a slide deck and 60 contractors. The amnesty clock runs out 8 July 2027. They already paid a law firm for an audit and understand — because the law firm told them — that the audit only covers the paper. They cannot personally police whether 12 team leads are running standups that look like supervision. As DSK Kancelaria puts it, the risk lives in “procesy wewnętrzne, komunikacja, sposób zarządzania projektami oraz codzienne relacje.”
Rough TAM reasoning: 229,000+ registered Polish software/IT businesses. Filter hard to those with 20+ contractors and real exposure and you’re at maybe 4,000–8,000 firms. Widen beyond IT — construction, healthcare, logistics, media, all heavy B2B users — and it’s larger, but IT is the beachhead because the B2B share is 73.6% and the contractor value is highest, which makes the per-head exposure highest.
Why now for them: The power became real on 8 July 2026. The amnesty ends 8 July 2027. Between those two dates every Polish CFO with contractors has this on the risk register, funded, with a deadline. That is a nine-month selling window with a hard edge, and after July 2027 the pitch changes from “fix it cheaply now” to “you’re exposed” — still a business, but a less pleasant one.
5. Product sketch (MVP)
- Connect your stack in an afternoon — Slack, Jira (or Azure DevOps), and Google Workspace / M365 calendars, read-only OAuth. No agent on anyone’s laptop.
- Per-contractor risk score against the statutory criteria — each B2B person gets a score across control/subordination, fixed hours, organisational embedding, personal-performance-without-substitution, exclusivity, and use of company resources.
- Red-flag feed with the actual receipt — “Michał was @-mentioned in 47 standup threads at 09:15 in the last 30 days” with links, not a vague warning. The evidence an inspector would find, surfaced first to you.
- Trend line per team, not just per person — because reclassification risk is generated by managers. Shows which team lead is creating exposure across their whole squad.
- Practice-vs-contract drift alerts — you upload the contract terms once (substitution allowed? own equipment? fixed hours excluded?); the product flags when observed behaviour contradicts what you signed.
- Amnesty countdown and remediation queue — ranked list of who to fix first by exposure value before 8 July 2027, with the estimated PLN exposure per head.
- Inspection dossier export — a timestamped PDF per contractor evidencing autonomy: deliverable-based acceptance, multi-client availability, absence of hour-tracking, varied working patterns.
- Manager nudges — a private Slack DM to the team lead when their behaviour crosses a line, before it becomes 30 days of pattern.
6. AI angle — what’s load-bearing
Remove the AI and this is a dashboard of message counts, which proves nothing. The load-bearing work is classifying intent in ordinary work communication against legal criteria.
“Can you jump on this today?” from a client to a supplier is normal commercial coordination. “Can you jump on this today?” from a team lead who also approves your holiday, inside a mandatory 09:15 standup, on a company-issued laptop, is a subordination signal. Same sentence, different legal weight, and the difference is context that only a model can weigh at scale across 60 contractors and thousands of messages a week.
Three jobs the model does that rules cannot:
- Distinguish instruction from coordination — the core of the kierownictwo (direction/control) test. Keyword matching produces garbage here.
- Detect organisational embedding — being treated as part of the team: included in employee rituals, internal announcements, benefit threads, performance conversations.
- Draft the defensive narrative — turning “here are 200 events” into the paragraph a lawyer would write arguing autonomy, per criterion, with citations to specific artifacts.
The scoring must be conservative and explainable — every flag links to its source evidence, because a compliance buyer will not accept a black-box number they have to defend to an inspector.
7. Localization angle
This is a Poland-first product and that is the entire point, not a coat of paint. The scoring logic encodes Polish case law and the PIP’s specific two-stage procedure, the UI and all generated dossiers are Polish, and pricing is in PLN. Payment is standard B2B invoicing with 14-day terms and split payment — Polish finance teams will not put a compliance tool on a company card.
The expansion path is genuinely attractive because the same shape is happening across the EU on different clocks. The Netherlands introduced a legal presumption of employment below €38/hour with the burden of proof on the hiring company (Loyens & Loeff), and Dutch DBA enforcement resumed in full on 1 January 2026. Each country needs its own criteria model but the same evidence pipeline. Poland first, because the administrative-decision power makes it the sharpest and because the Dutch static-assessment niche is already occupied by Beheersingsmodel and similar tools — the Dutch entry should be the practice-monitoring layer those tools lack, not another questionnaire.
8. Business model — path to $1M–$5M ARR
Pricing: Per contractor monitored per month, PLN, banded:
- Audyt — 2,900 PLN/mo, up to 25 contractors
- Kontrola — 5,900 PLN/mo, up to 75 contractors
- Grupa — 11,900 PLN/mo, up to 200 contractors + multi-entity
Roughly 80–120 PLN per contractor per month at the low band, falling to ~60 PLN at the top. Benchmark: the Dutch comparable Beheersingsmodel charges €11–17.50 per contractor per month for a static questionnaire-based assessment; continuous monitoring of live operational data justifies sitting in that range. Against a 190,000 PLN per-head exposure, a 5,900 PLN/mo subscription is noise — it pays for itself if it prevents a fraction of one reclassification.
ACV: 70,000 PLN ($19K) blended, weighted to the middle band.
Rough math to $1M ARR: ~4.0M PLN. That’s ~57 customers at the 5,900 PLN band, or a realistic mix of ~35 mid + ~20 small + ~8 large. Out of 4,000–8,000 qualified Polish IT firms, that is under 1% penetration. Very reachable.
Rough math to $5M ARR: ~20M PLN. Needs roughly 280 customers at blended ACV — which means either meaningful penetration of Polish IT plus adjacent verticals (construction, healthcare, logistics all run heavy B2B), or the second country. I’d plan on Poland getting to $2M and the Netherlands/Czechia carrying the rest.
Expansion path: Contractor count grows naturally as clients scale. Then: multi-entity for groups, the inspection-dossier export as a paid add-on when a control actually lands, ZUS/tax exposure modelling, and a white-label tier sold through the law firms — they keep the advisory relationship and resell monitoring, which turns the obvious competitor into a channel.
9. Go-to-market wedge — first 100 customers
1. Ride the law firms rather than fight them. Every firm listed above (Conselion, DSK, RPMS, After Legal, Stasik, Dudkowiak, ASB) is selling manual B2B audits right now and every one of them has told the client “the audit is a snapshot, practice is what matters.” That is a referral pitch that writes itself: they keep the high-margin advisory and the follow-on disputes, we take the monitoring subscription they don’t want to staff, they take 20% recurring. Target the 30 mid-size Polish employment-law practices with an active “audyt umów B2B” landing page — they are self-identifying as having the exact client list. Ten partnerships, three referrals each per quarter.
2. Scrape the self-identified exposed. Just Join IT and No Fluff Jobs list Polish IT job postings with contract type on the face of the ad. Filter for companies posting B2B roles at volume — those firms are publicly declaring both their contractor count and their model. A few hundred companies are visible this way with named hiring managers. Outreach opens with their own posting: “You’ve advertised 14 B2B roles this quarter. Here’s what a PIP inspector would see in your Slack.” Free 14-day connected read-only scan producing a real risk report is the offer — the report is the demo, and it will be alarming, because these companies do run standups.
3. The amnesty deadline as an event. A co-hosted webinar with one law firm — “Zostało X miesięcy do 8 lipca 2027” — with a live scored anonymised case study. KPMG already ran a B2B/PIP webinar in this market, which proves the audience assembles for this topic. Run it monthly with a different partner firm as the clock runs down, and publish a free “PIP readiness scan” that scores a company from a short questionnaire and captures the lead.
4. IT employer associations and CFO communities. SoDA (Software Development Association Poland) and Polish HR/CFO LinkedIn communities are dense with exactly this buyer. One good conference talk showing real anonymised Slack-derived risk patterns is worth more than a quarter of ads in this market.
Realistically: channels 1 and 2 get to the first 100. Channel 2 alone — a few hundred identifiable high-B2B-volume firms, free scan, ~10% conversion — plus a handful of productive law-firm partnerships covers it inside three quarters.
10. Build complexity — justification
Medium. The integrations are the work: Slack, Jira/Azure DevOps and Google/M365 calendar OAuth, incremental sync, and sane handling of large message volumes without hoarding content you don’t need. All well-documented, stable, off-the-shelf APIs — no reverse engineering, no scraping.
The genuinely hard parts are the criteria model and the privacy posture. The scoring needs a Polish employment lawyer’s input to be defensible, and the product reads workplace communications, so data minimisation, GDPR lawful basis, retention limits and works-council/contractor transparency have to be right from day one, not bolted on. Store derived signals and evidence pointers, not message archives.
Realistic v1: 12–16 weeks for two people, one strong backend engineer plus a founder doing the legal-criteria work with a paid lawyer advisor. That’s Slack + Jira + calendar, scoring across the criteria, red-flag feed, and PDF export. Azure DevOps, manager nudges and multi-entity come after first revenue.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Read-only analysis of a company’s own business data with its consent. GDPR-sensitive and requires proper lawful basis, DPIA and contractor transparency — handled, not blocking. |
| Ethical — no harm / dark patterns | ✅ | Worth naming honestly: this helps firms defend contractor status, and some of those arrangements are disguised employment. But the product’s actual output is “your practice looks like employment — change the practice or change the contract,” which pushes toward compliance either way. It surfaces the same evidence an inspector would. It must not be built as a coaching tool for concealing subordination, and that line belongs in the product’s own guidance. |
| Market exists (evidence above) | ✅ | Multiple law firms selling manual versions today; 229K+ IT firms; 73.6% B2B; dated enforcement power and dated amnesty. |
| 1–5 person team can build this | ✅ | Two people, 12–16 weeks, standard APIs. |
| Launchable with <$50K / ₹40L | ✅ | Two founders’ time, lawyer advisor retainer, modest inference cost. Well under. |
All five pass.
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 17/20 | ~190,000 PLN modelled exposure per head, five-year ZUS lookback, immediately-enforceable decisions that appeals don’t suspend, and a hard amnesty deadline. Not 18+ only because it’s a probabilistic risk — the pain is a possible inspection, not a monthly invoice, and some firms will gamble. |
| Demand evidence | 15 | 12/15 | Strong: a dozen law firms actively selling the manual version, KPMG running webinars, dated statute. Held below 13 because I could not find raw operator complaints in forums — the demand is visible through vendors and legal press, not yet through buyers’ own words. That’s the softest part of the case. |
| Build feasibility | 15 | 11/15 | Standard OAuth integrations and LLM classification, but three integrations plus a defensible criteria model plus a serious privacy posture is 12–16 weeks, not 6. |
| Distribution clarity | 15 | 12/15 | Job boards expose contract type, so the target list self-identifies; law firms are a natural channel with an aligned incentive. Not higher because the buyer is a cautious CFO/COO and the deal needs a security and GDPR review. |
| Revenue mechanics | 15 | 12/15 | Pricing is anchored to a real Dutch comparable (€11–17.50/contractor/mo) and trivially justified against exposure. ~57 customers to $1M. Docked for the $5M path leaning on geographic expansion. |
| Time to first revenue | 10 | 8/10 | The free connected scan produces an alarming report immediately, and the deadline does the closing. Realistically 6–10 weeks from launch, slowed by procurement and data-access approval. |
| Defensibility | 10 | 5/10 | Honest score. The integrations are public and the criteria are published case law — this is copyable. The moat is the accumulating longitudinal evidence trail (which a switching customer forfeits), the law-firm channel relationships, and a 12-month head start inside a window that closes. Real but soft. |
| Total | 100 | 77/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · domain-expertise-required
Needs an engineer comfortable with multi-tenant OAuth integrations and privacy-by-design, plus genuine access to Polish employment-law expertise. A Polish-speaking founder or co-founder is close to mandatory — this is sold in Polish to Polish finance and legal buyers.
Key assumptions to validate (3–5)
- Assumption: Firms will grant read-only access to Slack and Jira for compliance scoring. How to test: Offer the free connected scan to 20 target firms. Count how many actually complete OAuth versus how many stall at security review. This is the assumption most likely to kill the product — measure it before writing integration code.
- Assumption: The operational signal is strong enough to be actionable — real firms show clear, defensible red-flag patterns rather than ambiguous mush. How to test: Run the analysis manually on 3 friendly companies’ exports. If a lawyer can’t tell high-risk from low-risk contractors from the output, the thesis fails.
- Assumption: CFOs will pay a recurring subscription rather than treating a one-off law-firm audit as sufficient. How to test: 15 discovery calls with firms that already bought an audit. Ask directly what they’ve done since and whether anything monitors drift.
- Assumption: Law firms will partner rather than build or block. How to test: Pitch 8 firms with the referral model; a firm that says “we’d just do this in-house” is a signal, but a firm that says “we don’t want to staff monitoring” is the business.
Risk flags
- Regulatory risk (significant): Poland’s VBAR-equivalent churn is real — the Dutch government scrapped its own VBAR clarification in March 2026 after market unrest. Polish rules could soften, or the amnesty could be extended, deflating urgency. The statute is enacted and in force, which is the important thing, but the urgency is more fragile than the duty.
- Platform dependency: Slack and Atlassian API terms and pricing govern the data pipeline. Atlassian in particular has been re-pricing developer access, and Xero’s March 2026 shift to per-connection and per-GB egress billing shows how quickly a platform can convert free API access into a per-customer cost line. Model that risk into gross margin from the start.
- Privacy backlash: “Software that reads your Slack” is a bad headline waiting to happen, and contractors themselves may object. Mitigate by analysing metadata and derived signals rather than storing content, being transparent with monitored contractors, and never shipping individual-performance features — the moment this looks like productivity surveillance, it’s dead.
- Window risk: Peak urgency is the run-up to 8 July 2027. Launching much past Q1 2027 means selling into a market that has either fixed the problem or decided to live with it.
- Buyer sophistication: Larger firms may conclude their existing HR/legal team plus an annual audit is enough. The counter is the manager-behaviour trend line — no annual audit catches a team lead who introduced mandatory standups in March.
14. Structured verdict
Score: 77/100
Verdict: GO
Confidence: Medium
Best-fit builder: Polish-speaking technical founder with an employment-law advisor on retainer
Time to revenue: 6–10 weeks post-launch; 4–5 months from a standing start
Capital to launch: ~$15–25K (lawyer advisor, inference, infra, two founders' time)
Top 3 assumptions to validate first:
1. Firms will actually complete read-only OAuth to Slack/Jira for compliance — offer 20 free scans, count completions vs security-review stalls
2. Operational signal is legally meaningful — run manual analysis on 3 friendly companies, have a lawyer grade whether the output separates high from low risk
3. Recurring monitoring beats a one-off audit in the buyer's mind — 15 discovery calls with firms that already bought a law-firm audit
Kill criteria:
- Abandon if fewer than 5 of 20 target firms complete the data connection — the product is unsellable regardless of how good the analysis is
- Abandon if an employment lawyer reviewing 3 real scored outputs cannot distinguish high-risk from low-risk contractors
- Abandon if the amnesty is extended beyond July 2027 or the administrative-decision power is suspended, and no comparable EU deadline (NL, CZ) is within 12 months
- Abandon if Slack or Atlassian restrict the required read scopes, or price them above ~15% of gross margin
15. Next step — 1-week validation sprint
- Day 1–2: Build the target list from Just Join IT and No Fluff Jobs — every company that posted 5+ B2B roles in the last quarter, with named hiring managers and estimated contractor headcount. Should yield 200+ firms. In parallel, book a paid two-hour consultation with a Polish employment lawyer to pressure-test which operational signals actually carry weight before an inspector, and which are noise.
- Day 3–4: Get raw exports from 3 friendly Polish software houses — a month of Slack channel metadata, Jira assignment history, calendar patterns. Score them by hand against the criteria. This is the real test: does the operational data separate risky from safe contractors, or is everything ambiguous?
- Day 5: Take the three hand-scored reports back to the lawyer and to 10 CFO/COO conversations from the target list. Ask for a paid pilot at 5,900 PLN/mo, not for feedback.
Falsifiable outcome: Go if (a) the lawyer confirms the hand-scored reports would materially help defend a control, and (b) at least 3 of 10 CFOs agree to a paid pilot before any software exists. Fewer than 3 paid pilots, or a lawyer who says the operational evidence is not what decides these cases, and the idea dies here — cheaply, in a week, before a line of integration code gets written.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai