Hypercare window and transition to steady-state support.
Customisation
Configuration vs. Custom Development: Most modern software platforms support extensive configuration (workflows, roles, fields, reports) with optional custom development for unique logic.
Customization areas you might encounter:
Data model extensions (custom fields, objects/entities)
Business process automation (workflows, micro-flows, rules)
Vendor-supported customization vs. third-party/custom code
Upgrade path impact (customizations may require rework after major releases)
Performance implications of heavy custom logic
Data governance and compliance: Role-based access controls, audit trails, data retention policies, encryption at rest/in transit.
Additional Costs
Setup/Implementation Fees: Often a one-time implementation fee covering discovery, configuration, data migration, integrations, and training.
Subscription License / Cloud Fees: Ongoing recurring costs per user or per unit of capacity (e.g., per seat, per workflow, per API call), typically with tiered pricing.
Data Migration Fees: If substantial data cleansing/migration is required, vendors may charge separately.
Integrations/Connectors: Some connectors are bundled; others are billed per connector or per data volume.
Customization/Development: One-time or ongoing charges for custom builds, API work, or bespoke modules.
Training: Optional admin/user training sessions or certification programs.
Maintenance & Support:
Standard Support: Regular SLAs, response times, and access to knowledge base.
Data segregation and multi-tenant controls: strong isolation in multi-tenant environments.
Application security practices: secure development lifecycle, code reviews, dependency management.
Updates
Deployment model: all-at-once, canary, or phased rollout by region/tenant.
Upgrade messaging: release notes with new features, deprecations, and breaking changes.
Backward compatibility: compatibility assurances and upgrade guides.
Testing and sandboxes: dedicated staging/testing environments; ability to pilot updates.
Downtime/maintenance windows: scheduled maintenance, with notifications in advance.
Rollback capability: plan to revert to previous version if issues occur.
Data schema migrations: managed migration scripts, with impact analysis and rollback.
Data Ownership and Portability
Data ownership
Always owned by the customer: Your organization retains ownership of all data you input, generate, or store within Nomadia.
Rights to access: You retain the right to export or retrieve your data upon termination, subject to any reasonable retention or escrow provisions.
Data access and export
Data export formats: CSV, JSON, XML, or API-based exports; availability of complete data dumps for all entities.
Scheduled exports: Ability to configure periodic data exports for backups or migration.
Common negotiation points:
Guarantee of non-lock-in: no coercive fees to export data.
Data schema compatibility: export preserves data relationships, timestamps, and metadata.
Data retention post-termination
Standard policy: data remains accessible for a defined grace period (e.g., 30–90 days) to allow export. Alternative: immediate deletion with a confirmed final export window.
Data destruction
Secure deletion certifications on request (e.g., DoD 5200.38, NIST SP 800-88 equivalent).
Data sanitization and destruction timelines after termination.
Subprocessor disclosures
List of third parties with access to data and their roles (hosting, backups, analytics).
Vendor responsibility for subprocessors and any data transfer safeguards (SCCs/UK IDTA, etc.).
Scaling Up / Down
Elastic scaling model
Granularity: per-user, per-tenant, or per-usage unit (e.g., seats, workflows, API calls).
Lead time: typical 2–15 business days for provisioning changes; expedited changes may incur a rush fee.
Pricing impact
Upward adjustments: prorated billing for mid-cycle additions; volume discounts may increase with scale.
Downward adjustments: credit for unused licenses or a proportional reduction at the next billing cycle, subject to minimum term constraints.
Minimums and caps
Minimum term length (e.g., 12 months) or minimum user count.
Price protection terms (e.g., caps on price increases for a renewal period).
Scaling during term
Rules for temporary surges (e.g., seasonal spikes) and any surcharge.
Ability to pause or suspend licenses instead of terminating them (to preserve data when on hold).
Data migration during scale changes
Seamless provisioning/deprovisioning with audit trails.
Retention of historical data when reducing usage, with export option.
The terms & conditions for contract renewal and cancellation
Renewal mechanics
Auto-renewal: whether renewal is automatic, and notification requirements (30–120 days prior).
Pricing at renewal: fixed, capped, or subject to price increase with justification.
Term length at renewal: same as initial term or different configurable term.
Cancellation rights
Early termination: penalties, if any; notice period required.
During term: ability to cancel add-ons or modules without terminating core service.
Data access after cancellation: continued access for a wind-down period for export; data deletion policy after wind-down.
Data and service continuity
Service level continuity: if contract ends, continuation options (temporary renewal, sunset period).
In-flight projects: handling of ongoing implementations, milestones, and professional services commitments.
Transition assistance
Data migration assistance: support to export data or migrate to another platform post-termination.
Knowledge transfer: provision of documentation or training to facilitate handover.
Security and compliance post-termination
Data removal timelines and verification.
Return or destruction certificates for data and backups.
Audit and governance
Rights to audit billing, renewal terms, and data handling practices (restricted to confidentiality provisions).
Dispute resolution and termination for cause
SLA breach consequences, cure periods, and termination rights for material breaches.
Compliance
ISO 27001 (information security management)
SOC 2 Type II (trust services criteria)
SOC 1 (controls relevant to financial reporting, if applicable)
PCI DSS (if processing payment data)
HIPAA/HITRUST (for healthcare data)
GDPR/UK GDPR adherence and data processing addendum (DPA)
CSA STAR or other cloud security certifications (for cloud providers)
FedRAMP, IRAP, or other government-specific attestations (if servicing government)