Terms for a connected device with an app

Customer terms for a hardware product sold with an app or cloud service, drafted for a fixed fee of £995 in five working days.

Share

Terms for a connected device with an app

Terms for a product that combines a physical device with an app or cloud service, drafted for how the two are sold and supported, covering goods and digital content under consumer law, product safety and the security requirements for connectable products, the support period and what happens when it ends, updates and features that depend on the service, data from the device, warranty and returns, and the app terms. £995, delivered in five working days.

Buy now, £995

A connected device is two products sold as one: goods, which carry the consumer's rights in goods, and digital content or a service, which carries a different set. The terms have to deal with both, meet the safety and security rules that now apply to consumer connectable products, say how long the device will be supported and what it will do when the service ends, handle the data the device collects, and set the warranty and returns position alongside the app terms. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Businesses in England and Wales selling smart home, wearable, fitness, security, vehicle, agricultural or industrial devices that depend on an app or cloud service for their function, to consumers, businesses or both.

What matters in terms for a connected device

Goods, digital content and the consumer's rights in each

The device is goods, with the consumer's rights to satisfactory quality, fitness and description and the short-term right to reject under the Consumer Rights Act 2015, and where the device includes digital content, section 16 treats the goods as non-conforming if the digital content does not conform; the app and cloud service are digital content and services under sections 34 and 49 with their own remedies. The terms should describe what is goods and what is digital content, provide the remedies for each, and not treat a software fault as outside the goods rights when the device cannot function without it.

Product safety and security requirements for connectable products

The device must meet product safety law, including the Electrical Equipment (Safety) Regulations 2016 and the Radio Equipment Regulations 2017 where they apply and the General Product Safety Regulations 2005 as the baseline, and as a consumer connectable product it must meet the security requirements under the Product Security and Telecommunications Infrastructure Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023: no universal default passwords, a published vulnerability disclosure policy, and a statement of the minimum period for which security updates will be provided. The terms should carry the statement and the policy reference, and the business's compliance statement should exist.

The support period and the end of the service

The terms should state the minimum period for which the device will receive security updates and the service will be supported, what the device will and will not do if the service is withdrawn or the business ceases to provide it, and what notice and remedy the customer receives: a refund or credit for a device that becomes unusable within a stated period, or a local mode that keeps core functions working. A device that becomes a brick without warning is where complaints and regulators arrive, and the terms should say what was promised.

Updates, changes and features that depend on the service

The terms should say that updates may be required for continued function and security, that the business may modify digital content within section 40 of the Consumer Rights Act 2015, which permits changes the contract provides for as long as the content still conforms, that features may be added or withdrawn, and which features depend on a subscription; a feature sold as included cannot later be moved behind a paywall without a right to cancel and a refund. Business customers should have the service description and change rights set out separately.

Data from the device

Devices collect location, usage, audio, video, biometric or health data, and the terms should refer to the privacy notice under the UK GDPR, describe the data the device collects and why, address data from people other than the buyer (household members, visitors, employees) and the buyer's responsibilities to them, state what happens to data on resale or return, and deal with data used to improve the product. Devices with cameras or microphones need particular care, and business deployments involving employees engage the employer's own obligations.

Warranty, returns, the app terms and liability

The terms should provide a warranty for the device alongside, not instead of, the statutory rights, state the returns process and the consumer's cancellation right under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 for online sales, address the return of the device with data removed, and set out the app terms: the licence, account, acceptable use and the store provisions. Liability should sit within the Consumer Rights Act 2015 for consumers, including section 46 for damage caused by the digital content, and within the Unfair Contract Terms Act 1977 for business customers, with the business's obligations under the Waste Electrical and Electronic Equipment Regulations 2013 for take-back stated where they apply.

What it costs

SaaS terms of service, £995. Your standard customer-facing terms. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

Our device works only with our cloud service. What if we shut the service down?

The terms state the support period and what happens after it. Within the period, shutting the service down leaves the customer with a device that does not conform, and a refund or credit is what the terms provide; a local mode that keeps core functions is the better answer where the product allows it.

Do we have to state how long we will provide security updates?

For consumer connectable products, yes: the security requirements include a published statement of the minimum update period. The terms carry it.

A customer's neighbour objects to our doorbell camera recording them. Is that our problem?

The buyer is the controller of what their device records, and the terms say so and explain their responsibilities. The product's design and the privacy notice are where the business's own obligations sit.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.