MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
IT contracts define who is responsible for what regarding software, hosting, and digital services — and limit your risk if things go wrong. For an SME, this usually involves six documents: an SLA (availability and support), a Data Processing Agreement/DPA (personal data under the GDPR), a SaaS or cloud agreement (right to use online software), a license agreement (right to use software or IP), a maintenance/support contract, and a development agreement (having custom work built). They partially overlap and refer to one another. Below is what each contract serves and how they relate to each other.
The short answer
- SLA: availability (uptime), response times, service credits.
- Data Processing Agreement (DPA): mandatory when processing personal data (Art. 28 GDPR).
- SaaS/cloud agreement: right to use online software, not ownership.
- License Agreement: right of use of software or other intellectual property.
- Maintenance/support: updates, patches, helpdesk after delivery.
- Development agreement: custom building — IP, acceptance, delivery.
What IT contracts exist?
The term “IT contract” is an umbrella term. In practice, you rarely sign a single document that covers everything. For example, a supplier provides software (license or SaaS), keeps it running (SLA + maintenance), and processes your customer data in the process (DPA). Three or four pieces that together describe a single relationship. Knowing what each piece serves prevents an important subject from falling through the cracks.
The six most important pieces
1. Service Level Agreement (SLA)
Defines the service level: availability (e.g., 99.5% or 99.9% uptime), response times per priority, resolution times, maintenance windows, and service credits for failure to meet standards. Often a separate appendix to the main contract, allowing you to adjust service levels without reopening the entire contract.
2. Data Processing Agreement (DPA)
Required under Art. 28 GDPR as soon as a supplier processes personal data on your behalf — hosting, email marketing, CRM, accounting. DPA (Data Processing Agreement) is the English term for exactly the same document. You are the data controller, the supplier the data processor.
3. SaaS/cloud agreement
For online software purchased as a subscription. You are not buying software; you are renting a right of use. Important points: data ownership, exit and data return, availability, price changes, and liability. The DPA is usually attached to this as an appendix.
4. License Agreement
Right of use of software or other IP without a change of ownership — for example, an on-premise software package that you install on your own servers. Regulates scope, number of users, term, and remuneration.
5. Maintenance and support contract
Manages what happens after delivery: updates, security patches, bug fixes, and helpdesk. Essential for customization — without a maintenance agreement, you are left with a package that no one keeps up with anymore.
6. Development Agreement
For custom work built for you by a supplier. Manages intellectual property (transfer or license), acceptance criteria, delivery deadlines, additional work, and optionally source code escrow.
How are they related?
The pieces complement and refer to each other. A typical SaaS relationship:
- Main Agreement (SaaS): the right of use, the price, the term.
- SLA attached: availability and support.
- DPA attached: processing of personal data.
- General Terms and Conditions: liability, termination, disputes.
With custom development, the situation is different: a development agreement for building, a maintenance contract for subsequent stages, and—if the software processes personal data and the developer has access to it—another DPA. The risk of separate documents is inconsistency: one appendix promises 99.9% uptime, the other 99.5%. Therefore, include a precedence clause in the main contract that determines which document takes precedence in the event of a dispute.
Practical example
A wholesaler purchases a cloud inventory system. The supplier provides the software as a subscription (SaaS agreement), guarantees 99.5% availability with service credits (SLA), and processes customer and supplier data (DPA) in the process. Three pieces, one supplier. When the supplier threatened to go bankrupt after two years, the exit clause in the SaaS agreement proved invaluable: the wholesaler received its data back in a usable format within thirty days.
What you can do yourself and when not
Standard SaaS tools from major vendors (Microsoft, Google, major CRMs) come with ready-made terms and conditions, SLAs, and DPAs. You accept these online and archive them—you rarely need a lawyer for that. Do, however, read through the exit and price change clauses.
A lawyer becomes worthwhile for custom work, for suppliers willing to sign on your terms, for business-critical software, and whenever there is room for negotiation regarding liability or intellectual property. That is where the money is — and the risk.
Honest recommendation
First, map out which IT relationships you have and what document each requires. For standard tools, accepting and archiving the vendor's terms suffices — no lawyer needed. For custom work, business-critical systems, or negotiable contracts, a lawyer quickly pays for themselves: a good IP or liability clause costs a fraction of what a dispute costs. Expect to pay €500–€2,500 for reviewing or drafting a single document, and more for a complete custom package.
Delve deeper into the DPA/processor agreement, the SLA , and the contracts we draft.
Frequently Asked Questions
Usually six: SLA (availability and support), Data Processing Agreement/DPA (personal data), SaaS/Cloud Agreement (online software), License Agreement (IP usage rights), Maintenance/Support Contract, and Development Agreement (custom work). Which ones you need depends on your suppliers.
No. An SLA regulates the service level: uptime, response times, and service credits. A DPA (Data Processing Agreement) regulates the processing of personal data under Art. 28 GDPR. They are often both included as an appendix to the same main contract.
Only if a supplier processes personal data on your behalf — hosting, CRM, email marketing, accounting. This is the case with virtually every SaaS tool involving customer or employee data. Without a DPA, you risk an AP fine of up to 2% of global turnover.
With SaaS, you rent online software as a subscription, hosted by the supplier. With a classic license, you receive a right to use software that you often install yourself. SaaS is a service; a license is a right to use a product.
Include a ranking clause in the main contract that determines which document takes precedence in the event of a dispute — for example: main contract over SLA over general terms and conditions. This way, you know which agreement applies in the event of a dispute.
Usually not. Major suppliers offer ready-made terms and conditions, SLAs, and DPAs that you accept and archive online. Do read the exit and price change clauses, however. Hiring a lawyer pays off for custom work, business-critical software, and negotiable contracts.
Reviewing or drafting a single document typically costs €500–€2,500. A complete custom package (development and maintenance agreement with IP and escrow arrangements) costs more. The investment outweighs the costs of a dispute regarding liability or ownership.