Terms of service for online tools and portals

What the terms for a customer portal, an online tool or a subscription service need to cover, and the clauses that matter most when something goes wrong.

4 minread 859words last updated

The short answer

If you operate a customer portal, an online tool or a subscription service, its terms do four jobs: they define what the service is and is not, set the rules for users, state what you commit to and what you exclude, and describe how the relationship ends including what happens to data. The clauses people actually rely on when something goes wrong are narrower than the document: availability and what happens when it is not met, liability and its limits, data handling and security, the right to change the service and on what notice, and termination with export. Whether your users are consumers or businesses changes what is possible: consumer protection law imposes mandatory rights that terms cannot override, and unfair terms are unenforceable regardless of acceptance, while business-to-business relationships allow considerably more freedom of contract. However the terms are written, they must be accepted in a way you can prove, with a record of the version and the date, and changes need notice and often a right to leave.

What the terms must cover

SectionWhat it should say
The serviceWhat is provided, in what scope, and explicitly what is not
Accounts and usersEligibility, credentials, responsibility for user actions, sharing rules
Acceptable useWhat users may not do; consequences; suspension process
Fees and renewalPrice, billing cycle, renewal, notice to cancel, consequences of non-payment
AvailabilityWhat you commit to, planned maintenance, what happens when you miss it
SupportChannels, hours, response expectations
DataWho owns the customer’s data, what you do with it, security, the processing agreement, sub-processors, location
ConfidentialityBoth directions, with carve-outs
Intellectual propertyYours in the service, theirs in their content, any licence you need to operate
ChangesHow the service and the terms may change, with notice and rights
LiabilityLimits and exclusions, subject to what the law allows for the customer type
TerminationBy either side, notice, effect, export window, deletion
Law and disputesGoverning law, jurisdiction, and consumer dispute routes where relevant

Getting them right

  1. Describe the service accurately, including the limits; over-promising in terms creates the disputes.
  2. Decide your customer type and write for it; separate consumer and business terms if you serve both.
  3. State availability honestly, and only commit to what you measure.
  4. Cover data properly: ownership, processing agreement, security, sub-processors, locations, retention, export, deletion.
  5. Make acceptance explicit and record the version and date per account.
  6. Version the terms and keep the history.
  7. Give notice of changes with a right to terminate for material ones.
  8. Keep the language plain, which is a legal requirement for consumers and good practice everywhere.
  9. Have them reviewed by a lawyer once, and after any significant service change.

What customers actually read

In business-to-business sales the buyer’s checklist is short and predictable: what happens to our data, can we get it out, what are you liable for, what uptime do you commit to, how do we leave, and where is the processing agreement. A service whose terms answer those clearly shortens the sales cycle, and one that buries or omits them lengthens it. Writing the terms well is therefore commercial work as much as legal work.

What this means for you

Terms for a portal or online tool should define the service, the rules, your commitments, the data handling and the exit, with the clauses that matter, availability, liability, data, changes and termination, written precisely. Separate consumer and business terms, make acceptance explicit and recorded, version and give notice of changes, and keep the language plain. This is general information rather than legal advice; have the terms drafted or reviewed for what you actually provide.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Can we just copy terms from another service?

It is a poor idea. Copied terms describe a different service with different obligations, jurisdictions and data flows, and they may contain clauses that are unenforceable for your customer type or that commit you to more than you intend. They also fail exactly when needed, in a dispute, when the specific facts do not match. Use them to see the structure and have terms drafted for what you actually provide.

What is different for consumer users?

Consumer protection law applies and overrides unfair terms regardless of what the document says: mandatory withdrawal rights for distance contracts, restrictions on excluding liability, rules on automatic renewal and notice periods, and a requirement for plain language. Terms that try to limit statutory rights are simply unenforceable, so the effort belongs in explaining the service clearly and implementing the rules rather than in limiting them.

How should acceptance work?

An explicit action: a tick box, unticked, beside a link to the terms, at sign-up or first login, with a record of the version accepted and when. Terms buried in a footer that users are deemed to accept by browsing are weak. Store the acceptance record with the account, because in a dispute the question will be which version that user agreed to.

Sources

  1. EUR-Lex: Directive 93/13/EEC on unfair terms in consumer contracts (accessed 2026-09-12)
  2. EUR-Lex: Directive 2011/83/EU on consumer rights (accessed 2026-09-12)