Contracts for maintenance and hosting: the clauses that matter

The ten clauses that decide whether an ongoing web contract protects you, what fair wording looks like, and the combinations that trap.

4 minread 852words last updated

The short answer

An ongoing contract for maintenance and hosting is judged on ten clauses: what is in scope, what service levels apply, whose name the hosting is in, how data and privacy are handled, who is responsible for which security tasks, how changes are requested and priced, what the fees are and how they can rise, how long the term is and how it renews, how you exit and what is handed over, and what liability each side carries. The structure that keeps all ten honest is simple: hosting in your own accounts at the provider’s prices, and maintenance as a separately defined scope with its own fee. The trap is the opposite combination: bundled hosting in the supplier’s name, auto-renewal with long notice, undefined hand-over and a vague scope. Read the ten before signing, and have an advisor check the liability, data and termination wording for your jurisdiction.

The ten clauses

ClauseFairTrap
1. ScopeA list: monitoring, updates, backups with restore tests, security, performance, change budget, reporting, with cadence”Maintenance and support” with no list
2. Service levelsA severity table with response and resolution targets, hours, and monthly reporting of actuals”Best efforts”; one business day for everything
3. Hosting ownershipIn your accounts, provider prices, supplier as collaboratorIn the supplier’s name inside a bundled fee
4. Data and privacyProcessor terms; where data is; what the supplier may access; deletion at exitSilent
5. Security responsibilitiesWho patches, monitors, reviews access, responds to incidents, and how fastAssumed
6. Change processRequests, approval, pricing or a change budget, what is included versus quotedEvery change a surprise invoice, or unlimited changes never done
7. Fees and increasesFixed for the term; increases at renewal with notice, capped or indexedOpen-ended increase rights
8. Term and renewalOne to twelve months; renewal by agreement or with short notice either wayLong term; auto-renewal; notice only in a narrow window
9. Exit and hand-overNotice, defined hand-over included, cooperation with successor, data deletedUndefined; charged; contingent on final payment
10. LiabilityReasonable caps; carve-outs for data breach and gross negligence per your advisorTotal exclusion; or uncapped exposure for you

Reading before signing

  1. Find the scope list; if there is none, ask for one before anything else.
  2. Find the severity table; if there is none, ask for one.
  3. Check whose name the hosting is in and at what price; move it to yours.
  4. Read term, renewal and notice together; they decide how trapped you are.
  5. Read exit and hand-over; they decide what leaving costs.
  6. Have an advisor read liability, data and termination for your jurisdiction.
  7. Ask for last month’s report from an existing client, anonymised, to see the scope being delivered.

What fair looks like in one paragraph

Hosting in your accounts at provider prices, with the supplier as collaborator. Maintenance as a listed scope with cadence, a severity table, monitoring and a monthly report. Data handled under processor terms with a data map. Security responsibilities named. A change budget with a request process. Fixed fees for the term, increases only at renewal with notice and a cap. One to three months’ notice either way, hand-over included, cooperation with the successor, data deleted at exit. Liability caps your advisor accepts. That contract is boring and easy to leave, which is why you will not want to.

What this means for you

Judge an ongoing contract on the ten clauses, insist on hosting in your name and maintenance as a defined scope, and refuse the trap combination of bundled hosting, long auto-renewing terms and undefined hand-over. Have an advisor check liability, data and termination. A fair maintenance contract is specific, reported monthly and easy to leave, and that combination is what keeps the supplier earning it.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Should hosting and maintenance be in one contract?

They can be in one document with separate sections, but the hosting should be in your own accounts at the provider's prices, and the maintenance should be a defined scope with its own fee. Bundling both into one opaque monthly line in the supplier's name is the structure that makes the cost invisible, makes leaving expensive, and leaves it unclear who is responsible for what.

What service levels are reasonable?

A severity table with response and resolution targets: critical issues such as the site down or a security incident addressed within minutes to an hour at any time; important issues within business hours the same day; standard requests acknowledged within a business day. Reported monthly with times. Anything vaguer is a hope; anything promising instant everything is unsustainable.

How should fee increases be handled?

Stated in advance: a fixed fee for the term, increases only at renewal with notice, tied to a stated index or a cap. Pass-through of provider price changes for hosting in your own accounts is visible on the provider's invoice and needs no clause. Open-ended increase rights are a reason to negotiate before signing.