1. The Clauses That Do the Work
    1. What Services Are Actually in Scope
    2. How Fast Support Arrives
    3. How the Price Is Calculated
    4. What Happens to Your Data
    5. Who Is Responsible for Backups
    6. Who Is Liable When Something Goes Wrong
    7. How Long the Deal Runs
    8. Who Owns What Is Built
    9. Insurance and Subcontracting
  2. Clauses Worth Adding When the Situation Calls for It
  3. How an Artificer Legal Practitioner Would Review Your IT Support Contract
  4. The Exit Clause Decides Who Controls Your Systems

You are reading this because a managed service provider has sent you a long agreement to sign, or you are putting your own together to send to clients. The document decides who fixes your systems, how fast, at what price, and who pays when something goes wrong. Many businesses sign these contracts without reading past the price page and discover the gaps only after an outage, a ransomware event, or a provider who will not hand back the passwords.

An IT support contract is a services agreement between your business and a provider of IT services. It can cover reactive break-fix work, ongoing managed services, or both. What sets it apart from a one-page quote is that it allocates risk. It sets the scope of work, the service levels, the fees, who owns what is built, who is liable when things fail, and what happens at the end of the relationship. It binds both parties and should displace the informal arrangements and verbal assurances made during the sales process. If the written contract says something different from what the salesperson promised, the written contract generally wins, so the drafting needs to be settled before anyone signs.

The Clauses That Do the Work

What Services Are Actually in Scope

The scope clause defines what the provider is actually engaged to do, and it is where most disputes start. It should list the systems covered, the locations, the number of users and devices, and the specific services provided: helpdesk, monitoring, patching, cloud administration, backups and security controls. It should also say what is not covered. Projects, hardware supply, third-party software licensing, site relocations and new applications are commonly excluded or priced separately, and that is workable as long as the exclusions are written down.

  • In scope: systems, locations, users and devices covered, and the services included for each.
  • Out of scope: major projects, hardware, third-party licensing, relocations and anything that needs a separate quote.
  • Change mechanism: how new work gets quoted, approved and added without rewriting the whole contract.

The drafting choice that matters most is precision. "Reasonable IT support" means whatever the provider decides it means. A detailed scope with a change mechanism is what turns a marketing promise into an enforceable obligation.

How Fast Support Arrives

Service levels turn "we will help you" into measurable commitments. The typical clause sets response and resolution targets by priority, the hours during which those targets apply, and how tickets are logged, escalated and reported. Business-hours cover for a level one ticket is very different from 24/7 cover for a critical outage, and the contract should say which applies.

The variant providers push for is a response-time commitment without a resolution-time commitment, or targets measured only during business hours with after-hours work billed separately. Uptime commitments for cloud services need an agreed measurement method, otherwise the number is unverifiable. It is common to put the SLA in a separate schedule so the metrics can be refined each year without renegotiating the whole agreement, and to link the targets to a remedy such as service credits, otherwise they have no teeth.

How the Price Is Calculated

Fees clauses need to answer three questions: what is the base price, what triggers extra charges, and how can the price change. The base can be a fixed monthly fee per user or device, a capped number of hours, or time and materials. The triggers for extras matter just as much. After-hours work, onsite callouts, projects and work outside scope should be identified up front so the monthly invoice does not come as a surprise.

  • Billing model: fixed monthly fee, capped hours, or time and materials, and what each includes.
  • Extra charges: after-hours work, callouts, projects and out-of-scope work, with rates or a mechanism for quoting.
  • Fee changes: notice required, and whether increases need agreement.
  • Payment terms: due dates, late fees, and suspension rights if invoices are unpaid.

Fee variation terms are a common source of unfair contract term risk. Under Part 2-3 of the Australian Consumer Law (the ACL, Schedule 2 of the Competition and Consumer Act 2010 (Cth)), an unfair term in a standard form consumer or small business contract is void. A small business contract is one where at least one party employs fewer than 100 people or has turnover under $10 million. A term that lets the provider vary fees or change services unilaterally, without notice or agreement, can be unfair. Since 9 November 2023, proposing or relying on an unfair term is itself a contravention that carries penalties, up to the greater of $100 million, three times the benefit obtained, or 30 per cent of adjusted turnover for a body corporate.

What Happens to Your Data

An IT support provider sits inside your systems and sees employee records, customer data and confidential business information. The data clause allocates who is responsible for what: access controls, credential management, multi-factor authentication, change logging, patching cadence, endpoint protection and monitoring. It should also cover confidentiality, what the provider may do with your information, and what happens to it at the end of the contract.

  • Access and identity: who holds administrative credentials, MFA requirements, and logging of changes.
  • Security controls: patching cadence, endpoint protection, monitoring and reporting.
  • Confidentiality: what counts as confidential, permitted uses, and obligations that survive termination.
  • Privacy compliance: how personal information is handled, stored, transferred and deleted.

Where the Privacy Act 1988 (Cth) applies, these clauses carry legal weight. The Australian Privacy Principles bind APP entities, broadly organisations with annual turnover above $3 million, and also catch some smaller businesses, including health service providers, businesses that trade in personal information, and reporting entities under the anti-money laundering regime. An APP entity must take reasonable steps to secure personal information (APP 11) and reasonable steps before disclosing it to overseas recipients (APP 8), and must notify the Office of the Australian Information Commissioner and affected individuals when an eligible data breach occurs, being unauthorised access, disclosure or loss that is likely to result in serious harm (Part IIIC of the Privacy Act 1988 (Cth)). The contract should say which party runs the breach notification and who bears the cost, because both parties can be caught if personal information flows between them.

Who Is Responsible for Backups

Backup clauses fail in predictable ways. The provider says "we back up your data" and the customer assumes that means every system, restored instantly, forever. The clause should fix responsibility, frequency, retention and restoration targets, usually expressed as a recovery point objective (RPO) and recovery time objective (RTO), and should say how restores are tested. Backups that have never been restored are not backups.

The incident response half of the clause covers who does what when something goes wrong: notification obligations, escalation paths, containment roles, and how provider and customer coordinate. Where the customer is an APP entity, the incident clause should mesh with the notifiable data breaches obligations so that notification to the regulator and affected individuals happens within the timeframes the law requires.

Who Is Liable When Something Goes Wrong

The liability clause decides who pays when a service failure causes real damage: lost trading time, corrupted data, a regulatory penalty. Two drafting choices matter: the cap on the provider's liability and the exclusions around it.

  • Caps: a multiple of the fees (six or twelve months is common) that applies to everything except the carve-outs.
  • Carve-outs: fraud, wilful misconduct, breach of confidentiality and data loss are commonly excluded from the cap.
  • Consequential loss: exclusion of indirect or consequential loss, subject to the carve-outs.

Australian Consumer Law guarantees constrain what the provider can exclude. When services are supplied to a consumer, the ACL implies guarantees that the services will be rendered with due care and skill and be reasonably fit for any purpose made known to the provider (ss 60 and 61). A business is a consumer for these purposes if the price of the services does not exceed $100,000, or if the services are of a kind ordinarily acquired for personal, domestic or household use. The guarantees cannot be excluded or restricted by contract (s 64). For services that are not of a kind ordinarily acquired for personal use, however, the provider may validly limit its liability to supplying the services again or paying the cost of having them supplied again (s 64A). A clause that simply says "no liability" is void to the extent it conflicts with these rules, and an exclusion that leaves the customer with no real remedy can itself be an unfair term.

How Long the Deal Runs

Term clauses decide how the relationship starts, renews and ends. The common structures are a fixed initial term with automatic renewal, a fixed term with a fresh agreement each period, and month-to-month. Automatic renewal is convenient, but it is also where customers get locked in. A 24-month term that silently renews unless notice is given 60 days before the anniversary can be an unfair term in a small business contract, because it creates a significant imbalance with little notice and no genuine option to exit. Termination clauses should cover termination for breach, for insolvency and for prolonged service failure, plus termination for convenience with a notice period. The price of early exit should be agreed in advance rather than negotiated at the moment of exit. If the provider's template penalises exit heavily, that is a clause to challenge during negotiation.

Who Owns What Is Built

Custom code, scripts, documentation, monitoring configurations and reporting tools are all created during an engagement, and the contract should say who owns them. The customer usually wants ownership of anything built specifically for its environment, with the provider keeping ownership of its underlying tools and granting a licence to use them. The clause should also deal with the return or deletion of materials at the end of the contract and with any tools the provider has deployed inside the customer's environment. Where technicians work onsite or use customer equipment, the contract should also confirm the employment or contractor status of the people involved, so that intellectual property created by them is not lost by default.

Insurance and Subcontracting

The insurance clause should require the provider to carry professional indemnity and public liability cover, and cyber insurance where the engagement involves customer data. It should set minimum cover levels, require certificates of currency, and give the customer notice if cover lapses. The subcontracting clause should say whether subcontractors may be used and on what terms. Offshore subcontractors raise a particular issue: if personal information is involved, disclosing it to an overseas recipient can trigger APP 8 obligations for an APP entity, so the contract should identify where work is performed and who is accountable for it.

Clauses Worth Adding When the Situation Calls for It

Not every engagement needs every clause, but the following earn their place when the trigger applies:

  • Data processing terms: when the provider handles personal information on your behalf, allocate the privacy obligations, subprocessors and breach handling in a dedicated schedule.
  • Audit and reporting rights: when you operate in health, finance, government supply or another regulated sector, and need evidence of compliance with security standards.
  • Service credits: when the SLA matters commercially, tie missed targets to a credit against fees so the targets have consequences.
  • Cyber insurance requirements: when the provider holds your data or your customers' data, set a minimum level of cyber cover and require proof.
  • Change of control: when continuity matters, require consent or notice if the provider's business is sold or its key personnel change mid-term.

An Artificer Legal practitioner would review this agreement in a particular order: scope first, because everything else hangs off it; then the SLA and its remedies; then fees and variation mechanics; then data, security and breach allocation; then the liability cap and carve-outs; and finally the exit and offboarding clauses. The clauses we push back on most often are unilateral variation clauses, silent automatic renewal, liability caps that swallow the SLA remedies, and missing offboarding obligations. We would also check the ACL exposure: whether the customer is a consumer for guarantee purposes, whether the re-supply limitation in s 64A is available, and whether any term in a standard form agreement is exposed under the unfair contract terms regime. Where personal information is involved, we would map which party is an APP entity, who runs breach notification, and whether overseas disclosure obligations are dealt with. The outcome is a marked-up agreement where each risk is priced, allocated and written down in terms a court can enforce.

The Exit Clause Decides Who Controls Your Systems

The clause most often skipped in IT support contracts is the one nobody wants to think about: what happens when the relationship ends. On the day the contract terminates, the provider holds your administrative credentials, your backups and your domain. If the contract is silent, you are negotiating for the return of your own systems with a provider who has no remaining incentive to help. The exit clause should fix the notice period, the handover of credentials and documentation in a usable format, the return or deletion of data, and the cooperation obligations during a transition period. It is the difference between a clean move and a data hostage situation, and it is the clause to insist on before signing.

The rest of the agreement supports that outcome. Scope defines what the provider must actually deliver, the SLA and service credits give the commitments teeth, the fee and variation terms control the cost, the data clauses allocate security and breach responsibilities, and the liability cap allocates risk within the limits the ACL allows. An IT support contract that covers those bases, drafted in plain language and reviewed before signing, is what keeps the relationship working and makes the exit painless.