Contracts for maintenance and hosting: the clauses that matter
The ten clauses that decide whether an ongoing web contract protects you, what fair wording looks like, and the combinations that trap.
The short answer
An ongoing contract for maintenance and hosting is judged on ten clauses: what is in scope, what service levels apply, whose name the hosting is in, how data and privacy are handled, who is responsible for which security tasks, how changes are requested and priced, what the fees are and how they can rise, how long the term is and how it renews, how you exit and what is handed over, and what liability each side carries. The structure that keeps all ten honest is simple: hosting in your own accounts at the provider’s prices, and maintenance as a separately defined scope with its own fee. The trap is the opposite combination: bundled hosting in the supplier’s name, auto-renewal with long notice, undefined hand-over and a vague scope. Read the ten before signing, and have an advisor check the liability, data and termination wording for your jurisdiction.
The ten clauses
| Clause | Fair | Trap |
|---|---|---|
| 1. Scope | A list: monitoring, updates, backups with restore tests, security, performance, change budget, reporting, with cadence | ”Maintenance and support” with no list |
| 2. Service levels | A severity table with response and resolution targets, hours, and monthly reporting of actuals | ”Best efforts”; one business day for everything |
| 3. Hosting ownership | In your accounts, provider prices, supplier as collaborator | In the supplier’s name inside a bundled fee |
| 4. Data and privacy | Processor terms; where data is; what the supplier may access; deletion at exit | Silent |
| 5. Security responsibilities | Who patches, monitors, reviews access, responds to incidents, and how fast | Assumed |
| 6. Change process | Requests, approval, pricing or a change budget, what is included versus quoted | Every change a surprise invoice, or unlimited changes never done |
| 7. Fees and increases | Fixed for the term; increases at renewal with notice, capped or indexed | Open-ended increase rights |
| 8. Term and renewal | One to twelve months; renewal by agreement or with short notice either way | Long term; auto-renewal; notice only in a narrow window |
| 9. Exit and hand-over | Notice, defined hand-over included, cooperation with successor, data deleted | Undefined; charged; contingent on final payment |
| 10. Liability | Reasonable caps; carve-outs for data breach and gross negligence per your advisor | Total exclusion; or uncapped exposure for you |
Reading before signing
- Find the scope list; if there is none, ask for one before anything else.
- Find the severity table; if there is none, ask for one.
- Check whose name the hosting is in and at what price; move it to yours.
- Read term, renewal and notice together; they decide how trapped you are.
- Read exit and hand-over; they decide what leaving costs.
- Have an advisor read liability, data and termination for your jurisdiction.
- Ask for last month’s report from an existing client, anonymised, to see the scope being delivered.
What fair looks like in one paragraph
Hosting in your accounts at provider prices, with the supplier as collaborator. Maintenance as a listed scope with cadence, a severity table, monitoring and a monthly report. Data handled under processor terms with a data map. Security responsibilities named. A change budget with a request process. Fixed fees for the term, increases only at renewal with notice and a cap. One to three months’ notice either way, hand-over included, cooperation with the successor, data deleted at exit. Liability caps your advisor accepts. That contract is boring and easy to leave, which is why you will not want to.
What this means for you
Judge an ongoing contract on the ten clauses, insist on hosting in your name and maintenance as a defined scope, and refuse the trap combination of bundled hosting, long auto-renewing terms and undefined hand-over. Have an advisor check liability, data and termination. A fair maintenance contract is specific, reported monthly and easy to leave, and that combination is what keeps the supplier earning it.
Frequently asked questions
Should hosting and maintenance be in one contract?
They can be in one document with separate sections, but the hosting should be in your own accounts at the provider's prices, and the maintenance should be a defined scope with its own fee. Bundling both into one opaque monthly line in the supplier's name is the structure that makes the cost invisible, makes leaving expensive, and leaves it unclear who is responsible for what.
What service levels are reasonable?
A severity table with response and resolution targets: critical issues such as the site down or a security incident addressed within minutes to an hour at any time; important issues within business hours the same day; standard requests acknowledged within a business day. Reported monthly with times. Anything vaguer is a hope; anything promising instant everything is unsustainable.
How should fee increases be handled?
Stated in advance: a fixed fee for the term, increases only at renewal with notice, tied to a stated index or a cap. Pass-through of provider price changes for hosting in your own accounts is visible on the provider's invoice and needs no clause. Open-ended increase rights are a reason to negotiate before signing.