Release notes detailing new features, deprecations, and bug fixes.
Impact analysis for integrations and customizations.
Compatibility testing guidance for existing configurations and APIs.
Backward compatibility and deprecation planning:
Notice periods before deprecating features.
Guidance for migrating customizations or data models to new versions.
Testing support:
Sandboxed or staging environments to validate updates before production.
Migration guides and rollback procedures in case issues arise.
Data Ownership and Portability
Customer ownership of data: The customer retains ownership of all data uploaded, generated, or migrated into the system.
Vendor data rights: The vendor typically only holds metadata necessary to operate the service and provide support (e.g., logs for service quality), not customer business data.
Data access rights: The customer should have full access to export data at any time, in standard formats.
Data retention after termination: Clear policy on how long the vendor retains data after contract end, including deletion timelines and residual backups.
Data portability
Export formats: Availability of raw data exports (CSV, JSON, XML) and reports in standard formats.
Data structure documentation: Access to data model diagrams (entities, fields, relationships) to facilitate migration.
APIs for data extraction: Availability of REST/GraphQL APIs or other mechanisms to pull data on termination or for ongoing integration.
Transition support: Optional assistance during the handover period (data export validation, migration support) and a defined cutover plan.
Scaling Up / Down
Elastic licensing or user tiers: Ability to add/remove users or modules with pro-rated pricing.
Seat-based vs. usage-based pricing: Options to scale insights and capacity as you grow or shrink.
Module/feature scalability: Ability to enable/disable modules without re-architecting the solution.
Upward scalability: Clear price escalators for additional users, data volume, or new modules.
Downward scalability: Policies for reducing seats/modules, with any minimum commitment or notice period.
Lead times: How far in advance you must notify the provider to scale, and typical provisioning timelines.
Data migration considerations: Impact on storage, performance, or data retention when scaling.
The terms & conditions for contract renewal and cancellation
Renewal type: Automatic vs. opt-in renewal; term length (annual, multi-year).
Price changes: Notice periods and caps on price increases; whether increases are tied to CPI or market rates.
Redemption and renewal incentives: Discounts, added features, or loyalty benefits for multi-year renewals.
Change in scope: How scope changes at renewal are handled (new modules, data growth).
Termination rights: Notice period (e.g., 30, 60, 90 days) and whether termination is allowed mid-term for cause or convenience.
Fees on early termination: Any early-termination penalties, unused prepaid amounts, or data retrieval costs.
Data export obligation: Timeline and process to export data before cancellation; ongoing access to export tools for a grace period.
Post-termination support: Access to support or services after cancellation and any associated fees.
Compliance
ISO/IEC 27001: Information security management system certification.
SOC 2 / SOC 3: Controls relevant to security, availability, processing integrity, confidentiality, and privacy.
HIPAA / HITECH: If handling protected health information (PHI) in healthcare contexts.
GDPR / CCPA / other data privacy laws: Data handling, subject access, and cross-border data transfer compliance.
FedRAMP / NIST: For U.S. federal or regulated environments.
PCI DSS: If handling payment card data.
CSA STAR / cloud security: Cloud security alliance benchmarks for cloud providers.
Industry-specific: E.g., FINRA, FISMA, or local regulatory standards depending on sector.