- Define the service scope and each party's liability.
- Describe availability levels, support and the change procedure.
- Agree rights to data, code and deliverables.
- Check liability caps and a safe exit plan.
1. Scope and service outcome
The contract should start by answering what the company is actually buying. The product name and a general reference to the vendor's website are usually not enough. Specify features, environment, user numbers, integrations, input data and the outcome the vendor is responsible for.
If the service is to be implemented or configured, the document should separate the go-live phase from subsequent service provision.
2. Implementation, acceptance and changes
The timetable should set milestones, responsible persons, acceptance criteria and delay consequences. The change procedure should match project practice.
3. SLA, support and security
The SLA should define availability, measurement, exclusions, incident categories, response and resolution times. Check whether a service credit is the sole remedy for outages.
4. Data and intellectual property
Separate rights to the product from rights to configuration and materials created for the customer. The right to export and migrate data on exit is key.
5. Liability and safeguards
Liability is typically capped at recent months' fees. Assess whether the cap and its exceptions are proportionate.
6. Term and termination
The agreement should address auto-renewal, termination and price changes. A safe exit means a transition period, migration and data deletion.
7. Pre-signature checklist
- Scope, integrations, user numbers and outcome
- Timetable and acceptance criteria
- SLA, security, data, audit
- IP, licences, export
- Liability, caps, indemnity
- Termination and jurisdiction
Frequently asked questions
For a simple service it may be a starting point. For business-critical systems, check scope, data, security, liability and exit, and document deviations.
It depends on the contract. Vendors often state credits as the exclusive SLA remedy. Assess proportionality and the response to repeated failures.
When the vendor processes personal data on the customer's behalf. We assess the parties' roles from the actual data flow.
Need a specific contract reviewed?
Send a brief outline. After an initial review we will confirm how we can help.
Discuss the contract