For agencies and freelancers
What a maintenance contract has to say — and what it always leaves out
This is not a template to sign. It is the list of twelve decisions a maintenance contract has to make, with the two defensible answers to each, so you arrive at your lawyer's with a draft rather than a blank page.
What you leave with: twelve points to settle with both options and the trap in each, plus a ready-to-copy list of questions for a lawyer.
This is not legal advice
We make a monitoring tool. We are not a law firm. Nothing here is a model clause, nothing is presented as valid in your jurisdiction, and nothing replaces a professional reading before you sign.
What this page does, and it is worth real money: it tells you what you need to have decided before you go and see that professional. An hour of advice on a text you have already thought through costs far less than an hour of advice on an intention.
A maintenance contract is not there to win a lawsuit
Ninety-nine times out of a hundred, it is there to settle a conversation. “Is that included?” — it is written down. “How fast were you meant to respond?” — it is written down. On the day of the disagreement, it is not a judge who saves you, it is the sentence you read out together on the phone.
A useful maintenance contract is therefore short, precise about its limits, and readable by somebody who is not in the trade. Twelve pages the client never read settle nothing at all.
The twelve points below are the ones conversations derail on. Each has two defensible answers. What is not defensible is not having chosen.
The twelve points to settle
Take them in order and write your answer next to each. The result fits on one page, and it is the draft your lawyer will read.
1.The scope, defined by what sits outside it
What is NOT included in the retainer?
Option A
A closed list of what is included; everything else is out of scope.
Option B
A broad retainer with an explicit list of exclusions: redesign, new features, content, training.
The trap: a scope described only by what it contains stretches on its own. It is the exclusion list that holds, and it is the one everybody forgets to write.
2.The domain name
Who is the registrant, and who pays the renewal?
Option A
The client is registrant and pays the registrar directly; you have delegated access.
Option B
You front the renewal and re-invoice it, the client remaining registrant.
The trap: either way, write down who the registrant is. A maintenance contract that never mentions the domain leaves the question open until the day of departure — the worst possible moment.
3.Accounts and access
Whose name are the hosting, the CMS and the third-party services in?
Option A
Every account in the client's name, with you invited as administrator.
Option B
Accounts managed by you, with a written commitment to hand them over at the end.
The trap: option B only holds if the exit clause is precise — what, by when, in what form. Otherwise it creates exactly the situation you hate walking into on somebody else's client.
4.Response time and restoration time
How fast do you respond, and how fast is the site back up?
Option A
A single, simple response time, expressed in business hours.
Option B
Two distinct times by severity: site down on one side, routine request on the other.
The trap: never promise a restoration time for anything outside your control — host outage, registry incident, attack. You commit to your reaction, not to somebody else's.
5.Business hours
When are you reachable, and what happens outside those hours?
Option A
Business hours only, with requests received outside them counting from reopening.
Option B
Extended on-call, billed separately or included in a higher tier.
The trap: writing “we respond quickly” without defining “quickly” commits you to Sunday evening without being paid for it.
6.Backups
Who takes them, where do they live, and how far back can you go?
Option A
You take them, and you commit to a frequency and a retention period.
Option B
The host handles them, and you only commit to verifying that they exist.
The trap: the commitment that counts is not “we back up”, it is “we restore”. If you have never tested a restore on this site, do not write it.
7.Updates
What is your obligation the day an update breaks the site?
Option A
Updates applied after testing, with rollback included in the retainer.
Option B
Updates applied as they come, with fixing an incompatibility billed separately.
The trap: option B is defensible on a site you did not build. It is not defensible if the client discovers the rule on the day they need it.
8.Security
What do you commit to, and what do you refuse to promise?
Option A
A precisely described best-efforts obligation: updates, monitoring, accounts reviewed, valid certificate.
Option B
The same, plus a written procedure in case of compromise: who tells whom, how fast, who pays for the clean-up.
The trap: nobody can guarantee a site will never be attacked. A sentence that implies otherwise is a promise you will not keep.
9.Everything that renews
Who watches the deadlines, and what happens if one slips?
Option A
You keep the list of renewal dates and warn the client in advance.
Option B
The client keeps their own list; you only commit to what is in front of you.
The trap: a missed expiry is the most expensive and most humiliating incident in this trade. If nobody is named in the contract, it will be you, in front of the client, whatever the text says.
10.The end of the contract
What do you hand back, by when, and in what form?
Option A
A precise list: accounts, a full backup, an export of the DNS zone, an inventory of third-party services and their renewal dates.
Option B
The same list, plus a transition support package priced in advance.
The trap: this is the most important clause in the contract and the one written worst, because you draft it on a day when everything is fine. Write it as if you were the one taking over.
11.Price and revision
On what date and on what basis can the amount change?
Option A
Fixed price for the committed term, with any revision announced with notice.
Option B
Annual revision according to a rule written into the contract.
The trap: with no revision clause, it is a full renegotiation every year. With a vague one, it is a renegotiation AND an argument about the clause.
12.Subcontracting and cover
What happens if you are unavailable?
Option A
You may call on a colleague under your own responsibility, with the client informed.
Option B
A named stand-in is written into the contract, with the access they would need.
The trap: for a solo freelancer this is the point that reassures a serious client most, and the one people least dare to write down.
The four omissions that always come back
Content
“Could you just change the text on the pricing page?” Five minutes. Thirty times a year, that is a day and a half nobody invoiced. Decide whether it is included, and how far.
The mailbox
The client's email is almost never mentioned, and it is what produces the most panicked calls. Say whether you handle it — or say clearly that you do not.
Requests from a third party
The client's ad agency asks you to add a DNS record on a Friday evening. Who authorizes it, who bills it, and within what time?
Unused hours
Carried over, lost, or converted? With no written rule, the client is convinced they have been accumulating for three years, and they will say so the day they need them.
The questions to put to your lawyer
Copy into an email, or take to the meeting. They assume you have already settled the twelve points above — which is exactly what makes the hour of advice pay for itself.
Subject: Review of a website maintenance contract
Hello, I'm a [profession] and I offer my clients a website maintenance contract. I'd like the text I use reviewed. These are the points I need your view on: 1. Are my commitments drafted as a best-efforts obligation, or could they be read as a promise to deliver a given result? 2. Is my limitation of liability clause valid as written, and how far can it go? 3. Does the contract deal properly with ownership of the domain name, the accounts and the content produced? 4. Is what I provide for at the end of the contract precise enough to be enforceable? 5. Are my response times worded so that I'm not committing to outages outside my control? 6. Do I have the mandatory notices for this type of contract, and am I compliant if my client is a consumer rather than a business? 7. Is the handling of personal data covered, and does it need a separate document? 8. Are the renewal, notice and termination terms correctly drafted? 9. What happens if I stop trading mid-contract? 10. What is missing from this text that I haven't thought to ask you about? My current version is attached. [signature]
What turns a contract into a relationship that lasts
A well-written contract prevents arguments. It does not make anyone love the invoice. What makes people love the invoice is receiving something every month.
A monthly note, however short, saying what was checked, what was done, and what is coming: four lines is enough. The client no longer has to wonder what they are paying for, and you no longer have to justify it. Same information — it just arrives before the question instead of after.
It is also your own record. The day a client disputes something, twelve dated reports are worth every paragraph in the world.
Proof of work, produced on its own
DomainVigil continuously checks the domains, certificates, availability and reputation of the sites you manage, and publishes a status page at your client's own address. The contract says what you do; the report shows it was done.
Try it on one clientNo card required. You choose what your client sees.