Managed hosting agreement
A managed hosting agreement for a provider hosting customers' applications, websites and data, drafted from the provider's side for a fixed fee of £995 in five working days.
Managed hosting agreement
A managed hosting agreement for a provider hosting customers' applications and data, drafted from the provider's side, covering the hosting service and the infrastructure, availability and support, security, backups and disaster recovery, data location and data protection, the customer's content and acceptable use, fees, resources and overage, and suspension, termination and data return. £995, delivered in five working days.
Buy now, £995A managed hosting provider holds its customers' applications and data on infrastructure the customers never see, and the agreement has to say what the provider does with it: the service and its boundaries, the availability and support committed, the security and backups the provider performs and the disaster it will recover from, where the data lives, what the customer may put on the service, and how the relationship ends with the data returned. I draft that agreement for a fixed fee of £995, delivered in five working days.
Who this is for
Hosting providers, cloud service businesses and IT companies in England and Wales providing managed hosting of websites, applications, databases or environments for business customers, on their own infrastructure or resold from a public cloud.
What matters in a managed hosting agreement
The hosting service and the infrastructure
The agreement should define the service by a specification: the environment (dedicated, virtual or cloud), the resources (compute, storage, bandwidth), the managed elements (operating system, patching, monitoring, backups) and the elements the customer manages (its application and content), and should say whether the underlying infrastructure is the provider's own or a public cloud's, in which case the cloud provider's terms and limits apply to the customer's use and the provider passes through rather than warrants them. The provider's obligation is to provide the service with reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982.
Availability and support
The agreement should set an availability commitment for the hosted environment measured at the provider's network edge, with exclusions for scheduled maintenance, the customer's application, third-party networks and attacks, service credits as the remedy with a cap, support hours and response times by priority, and a termination right for persistent failure; a managed hosting provider is responsible for the platform being up, not for the customer's code running on it, and the agreement should say where the boundary is.
Security, backups and disaster recovery
The agreement should describe the security measures the provider maintains, the customer's responsibility for its own application security and credentials, the backup schedule and retention, the test restore frequency, the recovery time and recovery point objectives for a disaster, and what a disaster is; security should be stated as measures rather than as a guarantee, tested against Article 32 of the UK GDPR where personal data is hosted, and the provider should reserve the right to act on threats to the platform, including suspending a customer whose environment is compromised.
Data location and data protection
Because the customer's hosted content will contain personal data, the provider acts as processor and the agreement needs the Article 28 provisions of the UK GDPR: it should identify the hosting and backup locations, name every subprocessor including the public cloud and its regions, cover any transfer outside the UK under Article 46, and commit to breach notification fast enough for the customer to meet its own Article 33 deadline. The provider's own access to what it hosts should be confined to what the service needs, with every access logged.
The customer's content, acceptable use and the hosting position
The customer is responsible for its content and applications, for their lawfulness and for its own users, and the agreement should contain an acceptable use policy, a notice-and-takedown process that preserves the provider's position as a host under regulation 19 of the Electronic Commerce (EC Directive) Regulations 2002, the provider's right to suspend for breaches and for activity that threatens the platform or other customers, and the customer's indemnity for claims arising from its content. Resource abuse and fair use of unmetered elements should be defined.
Fees, overage, suspension, termination and data return
Monthly fees, the resources they buy, overage rates for usage above them, price rises on notice, statutory interest on late payment under the Late Payment of Commercial Debts (Interest) Act 1998, suspension after notice where invoices go unpaid, the initial term with its renewal, and termination for breach or insolvency all belong in the agreement. When it ends, the customer gets a fixed window to retrieve its applications and data, with help from the provider at the rates stated, and the provider deletes what remains once the window closes. Liability is capped at fees paid, data loss is limited to restoration from the most recent backup, the cap is drafted with section 11 of the Unfair Contract Terms Act 1977 in mind, and third-party rights are excluded under the Contracts (Rights of Third Parties) Act 1999.
What it costs
SaaS or technology contract, £995. One contract drafted for how your product or service is sold, delivered and supported. Five working days.
Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A bespoke contract drafted for how your product is sold, delivered and supported
- Service levels you can meet, with remedies that are proportionate rather than aspirational
- A liability position that is defensible and will survive enterprise procurement
- IP and data provisions that fit together rather than contradicting each other
- A commercial note on where you will get pushback and what is worth conceding
- One round of amendments
What is not included
- Negotiating individual enterprise deals, which I quote separately
- Advice on the law of jurisdictions outside England and Wales
- Technical security certification or audit
- Regulatory advice for regulated sectors such as financial services or health
Questions I am often asked
A customer's site was hacked through their own application. Is that our fault?
Not if the agreement makes the customer responsible for its application's security and the provider responsible for the platform, and the provider's platform measures were in place. The agreement draws that boundary and lets the provider suspend a compromised environment.
What do we owe if we lose a customer's data?
Restoration from the last backup within the stated recovery objectives, and liability within the cap. The agreement states the backup schedule so that the customer knows what the last backup means.
We host on a public cloud. Can we promise our customers the cloud's uptime?
You can pass through the cloud provider's commitments and add your own for the managed layer, but not warrant the cloud's performance as your own. The agreement distinguishes the two.
Related guidance and services
- SaaS and technology contracts, £995, the service this page describes
- Contract review, £495
- Data protection agreements and privacy terms, £795
- Reviewing a cloud hosting agreement
- Terms and conditions for a web hosting provider
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.