Contract checklist for reviewing productivity software terms before purchase
Image: Work Stack Lab

Rules and ethics

Part of UK rules and ethics for productivity software sold in England, mapped before policies

Reading a productivity software contract, from the subscribed service to liability

Review seven contract areas before buying productivity software, including scope, implementation, data, security, changes, liability and a workable exit.

These seven areas for business productivity software contracts each link a written term to an operating event: ordering, setup, data use, security, service change, loss or exit. They were researched on 5 September 2026 for business customers in England, under an assumed England and Wales governing-law context.

It is not ranked, does not cover public procurement or sector-specific clauses, and is not a substitute for a solicitor's review.

What to take away

  • A link the supplier can change without notice should not be the only record of a material promise.
  • Without an acceptance method, the customer may pay for access while the intended workflow remains unusable.
  • Check the data processing schedule against the supplier's real hosting and support chain.
  • Avoid an unbounded promise to follow industry standard security.
  • A service credit may be one remedy without covering the customer's full operational consequence.

1. The subscribed service

Identify the product edition, authorised users, environments, storage or usage limits, documentation and order of precedence. Record whether beta, artificial intelligence or third-party functions sit inside the commitment. A link that the supplier can change without notice should not be the only record of a material promise.

2. Implementation and acceptance

Separate subscription access from migration, configuration, integration and training. Name the inputs each party must provide, the test data, acceptance criteria and response if a dependency is late. Without an acceptance method, the customer may pay for access while the intended workflow remains unusable.

3. Personal data and sub-processors

First decide which party is controller or processor for each purpose. The ICO says a controller using a processor needs a binding arrangement governing the processing.

Its detailed Article 28 contract guidance covers instructions, confidentiality, security, sub-processors, assistance, audits and end-of-contract treatment. Check the schedule against the supplier's real hosting and support chain.

4. Security and incident cooperation

Define authentication, administrator access, logging, vulnerability contact, incident notification and evidence the customer may request. Avoid an unbounded promise to follow industry standard security.

The National Cyber Security Centre's shared-responsibility explanation recommends contract terms that require relevant providers and their supply chains to cooperate with incident response. Allocation should match the architecture and each party's ability to act.

5. Service levels and controlled change

Write the measured service, calculation window, exclusions, planned maintenance treatment and remedy. Define how the supplier can alter functionality, support or price, and what notice or termination right follows a material change. A service credit may be one remedy without covering the customer's full operational consequence.

6. Liability and insurance

Connect liability wording to real events: lost data, confidentiality breach, prolonged unavailability or an intellectual-property claim.

The Unfair Contract Terms Act 1977 applies statutory controls to certain exclusions and restrictions, with a reasonableness test in relevant cases. Application depends on the facts, the parties and the term. Only a qualified lawyer should advise on caps, exclusions, indemnities and insurance fit.

Consumer-facing plans need a different check. The CMA's current unfair contract terms guidance concerns fairness and transparency under the Consumer Rights Act 2015, not ordinary negotiated business agreements.

7. Termination and usable exit

Specify renewal, notice, suspension, final charges, export format, assistance, access period, deletion and backup treatment. Test whether the export preserves identifiers and relationships needed by the next system. Name the person who confirms completion.

Mark each area agreed, unresolved or not applicable with a reason. The legal reviewer needs the order form, incorporated documents, product description and data map together; reviewing one set of terms in isolation can miss the promise that created the risk.

Before you act

  • Identify product edition, authorised users, environments, storage or usage limits.
  • Separate subscription access from migration, configuration, integration and training.
  • Decide which party is controller or processor for each purpose.
  • Define authentication, administrator access, logging, vulnerability contact and incident notification.
  • Write the measured service, calculation window, exclusions, planned maintenance treatment and remedy.
  • Specify renewal, notice, suspension, final charges, export format, assistance, access period, deletion and backup treatment.

Common questions

What should a customer check about the order of precedence in a productivity software contract?

The article says to identify the product edition, authorised users, environments, storage or usage limits, documentation and order of precedence. It warns that a link the supplier can change without notice should not be the only record of a material promise.

Why is an acceptance method important in implementation and acceptance?

The article explains that without an acceptance method, the customer may pay for access while the intended workflow remains unusable. It advises separating subscription access from migration, configuration, integration and training, and naming inputs, test data, acceptance criteria and response if a dependency is late.

What does the article say about liability and insurance in these contracts?

The article says to connect liability wording to realistic events such as lost data, confidentiality breach, prolonged unavailability or an intellectual-property claim. It notes that the Unfair Contract Terms Act 1977 applies statutory controls to certain exclusions and restrictions, with a reasonableness test in relevant cases.

More in Rules and ethics