The four questions it has to answer
What is included, written as a list of work rather than a category. “Managed IT services” tells you nothing. “Every computer monitored and patched, backups taken daily and restore-tested quarterly, email and password management, unlimited support requests during the stated hours” tells you what you bought.
What costs extra, and who decides. Hardware, licences, projects and after-hours work usually sit outside the fee. The agreement should say so, and should say that anything extra gets quoted and approved before it starts.
How fast somebody responds, during which hours, and what counts as a response. There is a difference between a person contacting you and work beginning, and a good agreement says which one it is promising.
What happens at the end. Who holds the accounts, the domain and the licences, what documentation you receive, how long they keep copies of your data, and when their access comes off.
Clauses worth reading twice
Automatic renewal, together with the notice window. A term that renews for another year unless you write ninety days before the anniversary is a term most owners discover on day ninety-one. Minimum term, and any early-exit fee. Price escalation, which often appears as a right to adjust fees annually with no ceiling written anywhere.
Ownership. The domain, the email tenant, the licences, the documentation and the monitoring software should be named as yours. Offboarding fees, which turn leaving into a purchase. And a change-of-control clause, so you know what happens if the company is bought by somebody you did not choose.
Response times, written properly
One number cannot honestly cover a jammed printer and a clinic that cannot see its bookings. A good agreement sets out two or three categories, defines them by how much of your business has stopped, states the hours each one applies in, and names the exceptions.
Ask for the definition of “response” in the same paragraph. Ask what happens when the commitment is missed, since a promise with nothing attached to it is a sentence rather than a term.
The parts about your data
Where your information is stored, who at the provider can see it, and whether any of the work is subcontracted. What happens to it when the agreement ends, how long copies are kept, and how deletion is confirmed. Who tells you if there is a breach, how quickly, and what they do next.
None of this is legal advice. On any agreement with a term longer than a month, having your own lawyer read it is money well spent.
What ours says
Month to month, ended by 30 days written notice. The monthly price is the one published on our pricing page. Coverage hours are agreed with you and written in before you sign. Hardware and licences are billed at what they cost us, with no commission from any supplier. Your data is handled in line with PIPEDA, and with PHIPA where health records are involved. When you leave, the accounts, the passwords, the documentation and the data go with you, and our access comes off.
We hold no security certifications, and the agreement says so instead of implying otherwise. What it does carry is a written description of the protections actually in place.