Business rules & automations: Approval processes, triggers, SLAs, notifications.
Customizations: Any required fields, bespoke forms, or UI tweaks. Some platforms support low-code/no-code customization; others require development for advanced changes.
Integrations
API & connectors: Establish connections to existing systems (HRIS, ATS, CRM, ERP, SSO, BI tools).
Security & compliance: Ensure data encryption, access controls, audit logs, and regulatory requirements (GDPR, HIPAA, etc.).
Customisation
Fields and data model: Custom objects, fields, validation rules.
Workflows and automation: Custom SLAs, approval processes, multi-step workflows.
Data residency & localization: Options for data storage location compliance with regional laws.
Audit logs & monitoring: Immutable logs of access, changes, and data exports; anomaly detection.
Regular security assessments: Penetration testing, vulnerability scanning, and remediation processes.
Data retention and deletion: Defined policies for data retention, archival, and secure deletion on request.
Backup and disaster recovery: Regular backups, RPO/RTO targets, and tested recovery procedures.
Privacy compliance: GDPR, CCPA, HIPAA (where applicable) and data processing agreements (DPAs).
Secure development lifecycle: Secure coding practices, code reviews, and change management for deployments.
Third-party risk management: Vendor risk assessments for integrations and connectors.
Updates
Release cadence: Vendors vary—some publish quarterly small-feature releases, others have monthly updates, and some operate on a semi-annual major release cadence.
Content of releases: New features, enhancements, security fixes, bug fixes, and sometimes deprecations.
Deployment model:
SaaS: Updates are usually rolled out by the provider with minimal customer effort; some customers can opt into preview features.
On-premises: Updates require planning, testing, and potential customization adjustments.
Change management: Release notes, upgrade guides, and compatibility notes are provided; customers may be able to defer non-critical updates in some cases.
Backward compatibility: Vendors typically publish deprecation timelines for features and provide migration guides for breaking changes.
Testing & sandbox: Often a staging environment is used to test updates before production.
Data Ownership and Portability
Ownership assertion: The customer retains ownership of all data you input into the Nexxt platform, including system-generated data derived from that data.
Data processing agreements (DPAs): The vendor should provide a DPA that clarifies data ownership, processor roles, and data handling responsibilities.
Data access rights: The customer has reasonable access to export or retrieve data in a structured, commonly used format on request.
Data use limitations: Data may only be used to provide the service and improve the product, unless the customer consents to additional uses (e.g., anonymized analytics). Any broader data use should require consent and contract amendment.
Scaling Up / Down
Scaling options: Typically offered as a per-user or per-seat model, with tiered modules. Providers may allow volume-based discounts for larger deployments.
Adjustment windows: Minimum commitment periods and notice requirements (e.g., monthly, quarterly, or annual renewal cycles) before scaling changes take effect.
Proration: If you scale down, there may be proration of annual fees or an adjustment in the next renewal term. Scaling up generally increases fees proportional to new usage.
Limitations: Some features or modules may have minimums or maximums; certain add-ons may require minimum licenses.
The terms & conditions for contract renewal and cancellation
Renewal cadence: Often annual, with auto-renewal unless canceled within a specified window.
Price adjustments: Possible annual increases (e.g., CPI-based, market-based, or negotiated uplift). Seek a cap or predefined escalation schedule.
Renewal notice: Required notice period to opt out or negotiate (commonly 30–90 days before term end).
Termination rights: Usually for cause (breach) with cure periods; sometimes for convenience with termination fees or notice.
Data return requirements: Obligation for vendor to deliver data export in a usable format at termination.
Transition assistance: Availability of offboarding support, data migration assistance, and knowledge transfer during a wind-down.
Post-termination support: Limited access to support or self-service resources for a defined grace period, if applicable.
Refunds and settlements: Policy on refunds for unused licenses or prepaid fees, if termination occurs mid-term.
Non-compete/Non-solicit impact: Ensure there are no conflicting restrictions that hinder migration to a competitor.
Compliance
ISO 27001 / ISO 27701 (information security management and privacy management)
SOC 2 Type II / SOC 3 (security and controls over a period)
SOC 1 (if relevant to financial reporting)
HIPAA / HITECH (if handling protected health information)
GDPR compliance and DPAs (data processing agreements, data subject rights)
CCPA/CPRA compliance (where applicable for California residents)
PCI DSS (if processing payment data)
FedRAMP or other government-related compliance (for public sector deployments)
** data residency/localization certifications** (regional data storage requirements)
Cloud security alliance/CSA STAR (if relevant to your risk profile)