All sample legal documents

IT Managed Services Agreement

A completed managed IT agreement covering service desk, monitoring, incident levels, security, UK GDPR processing, continuity, fees and exit.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# IT MANAGED SERVICES AGREEMENT

Date: 21 October 2029

Parties: Northstar Managed IT Limited and Fenwick Architects Limited

## 1. Parties and purpose

Northstar Managed IT Limited (Company No. 08776655), 5 Innovation Drive, Cambridge CB4 0WS, will provide Fenwick Architects Limited (Company No. 06622119), 30 Station Road, Cambridge CB1 2JH, with managed Microsoft 365, endpoint monitoring, patching, helpdesk and backup services for up to 65 users and 80 devices.

## 2. Scope, price and subject

The monthly fee is £4,200 plus VAT, including the listed services, and additional projects require a written change order. Priority 1 means a material outage or suspected ransomware and is acknowledged within 30 minutes 24/7; Priority 2 within four business hours; Priority 3 within one business day. Targets are service levels, not a warranty that an incident cannot happen.

## 3. Operating duties

Northstar will maintain an escalation rota, patch supported systems, test monthly backups and give a quarterly service report. Fenwick will nominate administrators, apply reasonable user security instructions, keep licences paid, approve maintenance windows and promptly report suspected compromise. Northstar may suspend a compromised account to protect the environment, notifying Fenwick as soon as safe.

## 4. Compliance, records and controls

Fenwick is controller and Northstar processor for documented support processing of user and client data. The parties will sign and follow a UK GDPR Article 28 data-processing schedule, use appropriate technical and organisational measures, restrict sub-processors, assist with rights requests and notify a personal-data breach without undue delay. Data must remain in approved UK or adequate locations unless an approved transfer safeguard applies.

## 5. Term, ending and remedies

Fenwick owns its data, configurations and bespoke documentation; Northstar owns tools, scripts and pre-existing IP and grants a licence necessary for use during and after the term where paid. Northstar must not use Fenwick confidential data for advertising, model training or unrelated analytics. Fenwick authorises remote administration only through named accounts with multi-factor authentication.

## 6. Liability and reservations

The initial term is 24 months from 1 November 2029, then monthly rolling with 90 days' notice. A party may terminate for an uncured material breach, insolvency or a serious security failure; Fenwick may terminate on 30 days' notice after a repeated Priority 1 service-level failure. Exit includes an encrypted data export and 20 hours' reasonable transition support, with deletion certified after retention ends.

## 7. Governing law and signatures

Neither party excludes liability for fraud, death or personal injury caused by negligence, deliberate data misuse or IP infringement. Other aggregate liability is capped at 12 months' fees, with a separate £500,000 cap for a data-protection breach caused by Northstar. England and Wales law governs; the directors sign on 21 October 2029.

Create a version for your situation

Create a tailored IT Managed Services