# Contracts, SLAs and data rights

> What each vendor contract document covers, the clauses that decide cost, risk and your exit, why service credits are small and which terms to negotiate first.

Source: https://docs.lumina-erp.com/first-and-third-parties/contracts-slas-and-data-rights/

**In short.** A vendor relationship is governed by a stack of documents, and the clauses that matter most are rarely on the order form: renewal and price terms, data ownership and return, the liability cap and termination. Service credits almost never cover the cost of an outage, so negotiate the right to leave and to get your data back first.

A vendor contract is rarely one document. It is a stack: a master agreement that sets the rules, order forms that set the price, statements of work for projects and addenda for service levels and data. The terms that cost companies the most are usually not the price. The expensive terms are an auto-renewal nobody diarized, an uncapped increase, a liability cap smaller than one bad week and a data return clause that says nothing about format or timing.

:::caution[Not legal advice]
This page explains common commercial terms in plain language so you can ask better questions. It is not legal advice, and contract law varies by jurisdiction and by the exact wording. Have qualified counsel review any agreement before you sign, and always for agreements involving regulated data (personal, health or payment card data), large spend or long terms.
:::

## The contract stack at a glance

The table lists the documents in a typical stack and what to check in each.

| Document | What it covers | Drafted by | Watch for |
|---|---|---|---|
| MSA (master services or master subscription agreement) | The legal framework for everything you buy: liability, indemnity, confidentiality, termination, governing law | Vendor | Clauses that let the vendor change terms by updating a web page |
| Order form or quote | What you buy, quantities, price, term, renewal | Vendor | Auto-renewal and increase language that overrides the MSA |
| SOW (statement of work) | A project: scope, deliverables, assumptions, acceptance, fees | Vendor or implementer, negotiated | Assumptions that shift cost to you when they turn out false |
| SLA (service level agreement) | Measured targets such as uptime and support response, and remedies for misses | Vendor | Narrow uptime definitions, broad exclusions, small credits |
| DPA (data processing agreement or addendum) | How the vendor handles personal data on your behalf: purposes, security, subprocessors, return and deletion | Vendor, often a standard form | Subprocessor changes by notice only, vague deletion terms |
| BAA (business associate agreement) | HIPAA terms required when a vendor handles protected health information for a covered entity or another business associate | Either party | Signing one when it is required is not optional |
| NDA (non-disclosure agreement) | Confidentiality before and during evaluation | Either party | One-way NDAs that protect only the vendor |

Most MSAs include an order of precedence clause that says which document wins when two conflict. Read it closely. If the order form wins over the MSA, a line on a quote can undo a protection you negotiated.

### Why regulators care about some of these documents

Some of this stack is required by law for certain data. The GDPR (Article 28) requires a binding contract when a processor handles personal data for a controller, with terms such as acting only on documented instructions, using subprocessors only with authorization and deleting or returning the data at the end. The HIPAA rules (45 CFR 164.504(e)) set required contents for business associate contracts, including returning or destroying health information at termination where feasible.

The FTC Safeguards Rule (16 CFR 314.4(f)) requires covered financial institutions, a group that can include businesses that extend credit to consumers, to require service providers by contract to maintain safeguards. California's CCPA also requires specific contract terms with service providers and contractors that receive personal information. The 2023 interagency guidance for banks lists contract topics, from performance measures to ownership, audit and termination, that make a useful checklist for any industry.

## The clauses to read

The tables below are long because each row has cost someone money. Read the rows that apply to the vendor in front of you.

### Money and term

These clauses set what you pay and for how long.

| Clause | What it does | Good terms | Common trap |
|---|---|---|---|
| Term and auto-renewal | Sets the initial term and whether it renews automatically | Renewal only with notice you can realistically meet (30 to 60 days), or annual renewal after a multi-year start | Renews for another full multi-year term unless you give notice 90 or more days ahead |
| Price increase cap | Limits how much fees can rise at renewal or each year | A fixed cap, or the lower of a fixed cap and an inflation index, applying to renewals too | No cap, or a cap that covers the initial term only |
| Minimums and true-ups | Minimum users, volume or spend, and periodic reconciliation | Minimums that match your realistic floor | Minimums that rise automatically, or cannot be reduced at renewal |
| Payment terms | When invoices are due and what happens when late | Net 30 in arrears for usage, clear late fee | Suspension of service on short notice for a disputed invoice |

With invented round numbers, the cost of a missing cap is easy to see. A $50,000 a year subscription over five years costs $265,457 with increases of 3% a year, $276,282 at 5% and $299,236 at 9%. The difference between a 3% cap and no real cap is about $34,000 on one contract.

### Service levels

These clauses define the service you are promised and the remedy when it falls short.

| Clause | What it does | Good terms | Common trap |
|---|---|---|---|
| Uptime definition | Defines "available" and how it is measured | Measured by the vendor with monitoring you can see, and covering the functions you use rather than a login page | "Available" means the service responds at all, even if orders cannot be saved |
| Exclusions | Lists downtime that does not count | Scheduled maintenance limited in hours, announced in advance, outside your business hours | Unlimited emergency maintenance, and outages caused by the vendor's own providers excluded |
| Measurement period | The window over which uptime is calculated | Monthly | Quarterly or annual windows, which dilute one bad day |
| Service credits | The remedy for missing the target | Credits applied automatically, plus a right to terminate after repeated misses | You must claim within days, credits capped at a small share of one month's fee and credits are the sole remedy |
| Support response versus resolution | Response is when someone acknowledges, and resolution is when it is fixed | Severity levels with response and target restore times, and escalation contacts | Only response times are promised, and "response" can be an automated email |

### Risk allocation

These clauses decide who pays when something goes wrong.

| Clause | What it does | Good terms | Common trap |
|---|---|---|---|
| Limitation of liability | Caps what either side can recover | A cap tied to fees (often 12 months) with carve-outs, and a higher cap for data breaches | A cap of fees paid in the last 3 or 6 months, with no carve-outs |
| Carve-outs | Claims the cap does not apply to | Breach of confidentiality, data protection obligations, indemnity, gross negligence or wilful misconduct | Carve-outs that protect only the vendor, such as unpaid fees |
| Exclusion of indirect damages | Bars lost profits and consequential losses | Mutual, with data breach costs (notification, forensics, credit monitoring) treated as direct | Every realistic cost of an outage or breach counted as "indirect" |
| Indemnity | One party defends and pays for specified third-party claims | Vendor indemnifies for IP infringement and for its breach of data or security obligations | Only you indemnify, or the vendor indemnity is capped at a tiny amount |
| Insurance | Requires the vendor to carry coverage | Cyber liability and professional liability at stated limits, with certificates on request | No insurance requirement at all |

Take an invented add-on that costs $4,000 a month. A liability cap of 12 months of fees is $48,000. A cap of fees paid in the prior three months is $12,000. A data incident that requires notifying 20,000 customers could cost several times either figure. That gap makes the data breach carve-out or super-cap one of the most valuable lines in the MSA.

### Data

These clauses govern your data during the contract and after it ends.

| Clause | What it does | Good terms | Common trap |
|---|---|---|---|
| Data ownership | Says whose data it is | You own your data and anything derived from it that identifies you or your customers | Vendor gets a broad license to "use data to improve services" including training models on it |
| Data return | What you get back and when | Complete export, in a named machine-readable format, within a stated period (for example 30 days after termination), at no or stated cost | "Data available through professional services at current rates" |
| Deletion and certification | What happens to copies after return | Deletion within a stated period, including backups on their normal cycle, with written certification | No deletion commitment, or indefinite retention "as required" |
| Subprocessors | Other companies the vendor uses to handle your data | A published list, advance notice of changes and a right to object or terminate | Changes by updating a web page with no notice |
| Security obligations | What the vendor must do to protect data | A defined standard or control set, an annual independent report such as SOC 2 Type 2 and a duty to fix findings | "Commercially reasonable security" and nothing else |
| Breach notice | When the vendor must tell you about an incident | A fixed time after discovery (often 24 to 72 hours), with details and cooperation | "Without undue delay" and no content requirements |
| Audit rights | Your right to verify | Right to receive reports and questionnaires yearly, and to audit after an incident | No rights at all, or audits only at your full cost with 90 days notice |
| Data location | Where data is stored and processed | Stated regions, with notice before changes | Silent |

### Change and exit

These clauses decide how easily you can leave.

| Clause | What it does | Good terms | Common trap |
|---|---|---|---|
| Assignment and change of control | Whether the contract can be transferred, including when the vendor is acquired | Notice of a change of control and a right to terminate if the buyer is a competitor or the service changes materially | Vendor can assign freely, but you cannot |
| Termination for convenience | Leaving without having to prove fault | Available to you with 60 to 90 days notice after an initial period, with a known fee | Not available, so you pay the rest of the term |
| Termination for cause | Leaving when the vendor breaches | Clear cure periods, and repeated SLA misses count as cause | Cure periods so long the breach never matures |
| Transition assistance | Help moving to a replacement | A stated number of months of continued service and help at stated rates after notice | Service stops on the termination date |
| Escrow | Access to source code or a running copy if the vendor fails | For on-premises or critical custom software: a deposit with an escrow agent, verified, with clear release triggers | An escrow deposit nobody has ever tested, or triggers limited to formal bankruptcy |

Escrow matters less for cloud software than it used to, because code without the vendor's hosting environment is hard to run. For cloud services, strong data return terms and transition assistance usually protect you more.

In the European Union, the Data Act (Regulation (EU) 2023/2854) now sets switching rights for customers of cloud and other data processing services. They include a maximum two-month notice period to start switching, a transition period of up to 30 calendar days in most cases and the removal of switching charges from 12 January 2027 (as read on EUR-Lex, retrieved 2026-09-28). If you buy from providers that serve EU customers, ask whether they offer those terms to you too.

## Why service credits rarely cover an outage

Service credits look like protection, but they amount to a small discount, and the SLA often says they are your only remedy.

Take an invented distributor that pays $4,000 a month for a cloud order management add-on with a 99.9% monthly uptime commitment. The credit schedule is 10% of the monthly fee below 99.9%, 25% below 99.0% and 50% below 95.0%. The table works through one outage.

| Step | Calculation | Result |
|---|---|---|
| Minutes in a 30-day month | 30 × 24 × 60 | 43,200 minutes |
| Downtime allowed at 99.9% | 43,200 × 0.1% | 43.2 minutes |
| Actual outage, on a Tuesday morning | 216 minutes | 3.6 hours |
| Actual availability | (43,200 − 216) ÷ 43,200 | 99.5% |
| Credit tier | Below 99.9%, not below 99.0% | 10% |
| Service credit | $4,000 × 10% | $400 |
| Estimated cost to the business (invented) | Orders taken on paper and re-keyed, overtime, two missed truck cutoffs, expedited freight | $18,000 |
| Credit as a share of the cost | $400 ÷ $18,000 | About 2% |

That assumes the credit is paid. Often it is not, because the outage fell in a "maintenance window", the service was slow but technically up or nobody filed the claim within the required days.

What to negotiate instead of bigger credits:

- A right to terminate after repeated misses, for example three months below target in any 12
- Credits applied automatically, without a claim
- An uptime definition based on the functions you use, such as order entry and API availability
- Root cause reports within a stated time after major incidents

Build resilience of your own as well. A documented manual fallback for order taking is worth more than any credit.

## Negotiation priorities

You will not win every point. This table ranks where we would spend negotiating effort for a typical mid-market software or service contract. Adjust it for your risk: a vendor holding customer card data moves security and breach terms up.

| Priority | Term | Why it ranks here |
|---|---|---|
| 1 | Data ownership, return format and timing, deletion certificate | Without it, leaving is slow, costly or impossible |
| 2 | Price increase cap, including renewals | Compounds every year you stay |
| 3 | Renewal notice window and term length | Missed windows lock in years of spend |
| 4 | Liability cap with data breach carve-out or higher cap | Determines who pays for the worst day |
| 5 | Termination rights: for repeated SLA misses, change of control and for convenience | Your exit when the relationship fails |
| 6 | Transition assistance | Keeps service running while you switch |
| 7 | Breach notice timing and security obligations | Lets you meet your own legal and customer duties |
| 8 | Subprocessor notice and objection | Controls who else holds your data |
| 9 | SLA definitions and credits | Useful, but rarely changes outcomes on its own |
| 10 | Payment terms and minimums | Cash matters, but usually lower risk |

:::tip[Ask for the change in writing, on the right document]
A promise in an email or a sales deck is not part of the contract unless the contract says so, and many MSAs say the opposite. Put agreed changes in an amendment or the order form, and check the order of precedence clause so the change wins.
:::

## Red flags in a vendor contract

Any of these terms deserves a pushback before signature.

| Red flag | Why it matters |
|---|---|
| Terms incorporated "by reference" from a URL the vendor can change | The deal can change without your signature |
| Auto-renewal for the full original term | A missed date becomes a multi-year commitment |
| Price increases "at the vendor's then-current rates" | No cap at all |
| Liability capped at a few months of fees with no carve-outs | You carry nearly all of the risk of the vendor's mistakes |
| Broad rights to use your data, including aggregated or for product training, with no opt-out | Your data becomes their asset |
| No DPA offered when the vendor clearly processes personal data | They may not understand their own obligations |
| Refusal to sign a BAA when handling health information | A legal requirement is being skipped |
| Data export only through paid services, with no stated format | Exit cost is unknown and set by the vendor |

## Questions to ask before you sign

- Which document wins if the order form and the MSA disagree?
- What exactly counts as downtime, and what is excluded?
- What is the credit process, and are credits the only remedy?
- What is the liability cap, and which claims are carved out?
- Who owns our data, and what may you do with it, including aggregated or anonymized forms?
- In what format, how fast and at what cost do we get our data back, and when will you delete it?
- Which subprocessors handle our data, and how will we hear about changes?
- How quickly will you tell us about a security incident, and what will you tell us?
- What happens to this contract if you are acquired?
- What does it cost to leave early, and what transition help will you provide?

## Review your largest contracts

Pull your five largest vendor contracts and, for each, find four things: the renewal date and notice window, the price increase terms, the liability cap and the data return clause. Put them in your vendor register (see [Managing vendors after go-live](/first-and-third-parties/managing-vendors-after-go-live/)). Where a data return clause is missing or vague, flag that contract for renegotiation at the next renewal, and bring counsel in before that conversation.

## Sources

- [Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, OCC, June 2023)](https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-management)
- [Regulation (EU) 2016/679 (GDPR), Article 28 Processor (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
- [16 CFR 314.4, FTC Safeguards Rule elements, including oversight of service providers (eCFR)](https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314)
- [45 CFR 164.504, HIPAA business associate contract requirements (eCFR)](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504)
- [CCPA laws and regulations (California Privacy Protection Agency)](https://cppa.ca.gov/regulations/)
- [Regulation (EU) 2023/2854 (Data Act), Chapter VI on switching between data processing services (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj)

---

Epicor, Prophet 21, P21 and DynaChange are trademarks or registered trademarks of Epicor Software Corporation registered in the United States and other countries. Kinetic is a trademark of Epicor Software Corporation. Lumina ERP is an independent consultancy and is not affiliated with, sponsored by or endorsed by Epicor.
