Terms of service for online tools and portals
What the terms for a customer portal, an online tool or a subscription service need to cover, and the clauses that matter most when something goes wrong.
The short answer
If you operate a customer portal, an online tool or a subscription service, its terms do four jobs: they define what the service is and is not, set the rules for users, state what you commit to and what you exclude, and describe how the relationship ends including what happens to data. The clauses people actually rely on when something goes wrong are narrower than the document: availability and what happens when it is not met, liability and its limits, data handling and security, the right to change the service and on what notice, and termination with export. Whether your users are consumers or businesses changes what is possible: consumer protection law imposes mandatory rights that terms cannot override, and unfair terms are unenforceable regardless of acceptance, while business-to-business relationships allow considerably more freedom of contract. However the terms are written, they must be accepted in a way you can prove, with a record of the version and the date, and changes need notice and often a right to leave.
What the terms must cover
| Section | What it should say |
|---|---|
| The service | What is provided, in what scope, and explicitly what is not |
| Accounts and users | Eligibility, credentials, responsibility for user actions, sharing rules |
| Acceptable use | What users may not do; consequences; suspension process |
| Fees and renewal | Price, billing cycle, renewal, notice to cancel, consequences of non-payment |
| Availability | What you commit to, planned maintenance, what happens when you miss it |
| Support | Channels, hours, response expectations |
| Data | Who owns the customer’s data, what you do with it, security, the processing agreement, sub-processors, location |
| Confidentiality | Both directions, with carve-outs |
| Intellectual property | Yours in the service, theirs in their content, any licence you need to operate |
| Changes | How the service and the terms may change, with notice and rights |
| Liability | Limits and exclusions, subject to what the law allows for the customer type |
| Termination | By either side, notice, effect, export window, deletion |
| Law and disputes | Governing law, jurisdiction, and consumer dispute routes where relevant |
Getting them right
- Describe the service accurately, including the limits; over-promising in terms creates the disputes.
- Decide your customer type and write for it; separate consumer and business terms if you serve both.
- State availability honestly, and only commit to what you measure.
- Cover data properly: ownership, processing agreement, security, sub-processors, locations, retention, export, deletion.
- Make acceptance explicit and record the version and date per account.
- Version the terms and keep the history.
- Give notice of changes with a right to terminate for material ones.
- Keep the language plain, which is a legal requirement for consumers and good practice everywhere.
- Have them reviewed by a lawyer once, and after any significant service change.
What customers actually read
In business-to-business sales the buyer’s checklist is short and predictable: what happens to our data, can we get it out, what are you liable for, what uptime do you commit to, how do we leave, and where is the processing agreement. A service whose terms answer those clearly shortens the sales cycle, and one that buries or omits them lengthens it. Writing the terms well is therefore commercial work as much as legal work.
What this means for you
Terms for a portal or online tool should define the service, the rules, your commitments, the data handling and the exit, with the clauses that matter, availability, liability, data, changes and termination, written precisely. Separate consumer and business terms, make acceptance explicit and recorded, version and give notice of changes, and keep the language plain. This is general information rather than legal advice; have the terms drafted or reviewed for what you actually provide.
Frequently asked questions
Can we just copy terms from another service?
It is a poor idea. Copied terms describe a different service with different obligations, jurisdictions and data flows, and they may contain clauses that are unenforceable for your customer type or that commit you to more than you intend. They also fail exactly when needed, in a dispute, when the specific facts do not match. Use them to see the structure and have terms drafted for what you actually provide.
What is different for consumer users?
Consumer protection law applies and overrides unfair terms regardless of what the document says: mandatory withdrawal rights for distance contracts, restrictions on excluding liability, rules on automatic renewal and notice periods, and a requirement for plain language. Terms that try to limit statutory rights are simply unenforceable, so the effort belongs in explaining the service clearly and implementing the rules rather than in limiting them.
How should acceptance work?
An explicit action: a tick box, unticked, beside a link to the terms, at sign-up or first login, with a record of the version accepted and when. Terms buried in a footer that users are deemed to accept by browsing are weak. Store the acceptance record with the account, because in a dispute the question will be which version that user agreed to.
Sources
- EUR-Lex: Directive 93/13/EEC on unfair terms in consumer contracts (accessed 2026-09-12)
- EUR-Lex: Directive 2011/83/EU on consumer rights (accessed 2026-09-12)