All sample legal documents

Sample Managed Service Agreement

A worked example for an ongoing technology service covering service levels, security, fees, support, changes, data handling and exit assistance.

Jurisdiction: General technology-services sample - privacy, security and sector rules apply

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

MANAGED SERVICE AGREEMENT

Important notice

This fictional example is a general technology contract and is not legal advice or a universally valid managed-service form. The parties must adapt it to the applicable jurisdiction, privacy and cybersecurity laws, regulated-sector requirements, tax treatment, resilience expectations and procurement rules. A separate data-processing addendum, security schedule, service credits mechanism or formal deed may be required. No term overrides a mandatory legal obligation.

1. Parties and service

This Agreement is made on 15 September 2026 between Evergreen Health Supplies Ltd, of 33 Alder Street, Nottingham NG1 2GS, the Customer, and Cloudbridge Operations Ltd, of 5 Orion Campus, Derby DE1 9XY, the Provider. From 1 October 2026, the Provider will monitor, host and support the Customer's inventory and order-management platform, called StockPilot, for the Customer's United Kingdom distribution business. The Provider will supply the services described in this Agreement and the service description dated 10 September 2026.

2. Term and governance

The initial term is three years ending on 30 September 2029. It renews for one-year periods unless either party gives 120 days' written notice before the current term ends. Service managers will meet monthly to review availability, incidents, security events, service reports, planned changes and open risks.

3. Service levels and support

The Provider will make StockPilot available 99.8 percent of each calendar month, excluding agreed maintenance, emergency maintenance reasonably required to protect the service, Customer-caused outages and events beyond reasonable control. The Provider will give at least five business days' notice of planned maintenance and schedule it outside the Customer's peak order period where practicable.

A priority-one incident means a complete outage or suspected compromise affecting order processing. The Provider will acknowledge it within 30 minutes, provide hourly updates and use continuous reasonable efforts to restore service within four hours. A priority-two incident materially affects a major function and will be acknowledged within two hours with a target resolution of one business day. Lower priorities will be handled during support hours.

If monthly availability falls below 99.8 percent, the Customer may claim a service credit of 5 percent of that month's recurring fee. Availability below 99.0 percent gives a credit of 10 percent. Credits are the Customer's exclusive financial remedy for a service-level failure, except for fraud, wilful misconduct, confidentiality breaches, data-protection liability and matters that cannot lawfully be limited.

4. Fees and expenses

The Customer will pay a recurring managed-service fee of £18,500 per month, plus VAT, and a one-time transition fee of £42,000. The Provider will invoice monthly in advance for the recurring fee and on completion of transition milestones for the one-time fee. The Customer will pay undisputed invoices within 30 days. The Provider must give written details of a disputed item and may suspend only materially affected services after 15 days' notice of overdue undisputed sums. Annual recurring fees may increase by the lower of 4 percent or the increase in the Consumer Prices Index, with 60 days' notice.

5. Customer responsibilities

The Customer will nominate authorised users, provide accurate data, maintain suitable connectivity at its premises and make timely decisions. It remains responsible for its business processes, user permissions, lawful instructions and the accuracy of information entered into StockPilot. The Customer must not intentionally introduce malicious code or allow unauthorised access.

6. Security and data

The Provider will maintain an information-security programme appropriate to the service, including access controls, multi-factor authentication for administrative access, encryption in transit and at rest, logging, vulnerability management, backups and staff confidentiality commitments. It will notify the Customer without undue delay and, where practicable, within 24 hours after confirming a security incident affecting Customer data, provide material updates and cooperate with proportionate investigation and recovery.

The Customer owns its business data. The Provider may process it only to deliver, secure and improve the services in a way consistent with the Customer's documented instructions and applicable law. The parties will sign and follow a data-processing addendum where required. The Provider will not sell Customer data or use it for unrelated advertising. Aggregated information that cannot reasonably identify the Customer or an individual may be used to improve service capacity and reliability.

7. Intellectual property

Each party retains its pre-existing software, tools, methods, trademarks and documentation. The Customer grants the Provider a limited licence to use Customer materials to perform the services. The Provider owns its platform, operational tools and general improvements, while the Customer owns reports and Customer-specific configuration data.

8. Changes and subcontractors

Either party may request a change. The Provider will state the effect on price, security, service levels and timing before work begins, and no material change is binding without written approval. The Provider may use approved hosting and support subcontractors, remains responsible for their performance and must impose equivalent confidentiality and security duties.

9. Termination and exit

Either party may terminate for a material breach not cured within 30 days, insolvency where lawful or a force majeure event lasting 60 days. The Customer may terminate if three priority-one incidents in a rolling 90-day period are caused by the Provider's failure to meet its obligations. On expiry or termination, the Provider will provide up to 90 days of reasonable exit assistance, export Customer data in a commonly used format and securely delete remaining copies when legally permitted. Exit assistance is charged at the Provider's then-current rates unless termination resulted from the Provider's uncured material breach.

10. Governing law and formalities

The parties propose the law of England and Wales and the courts of Nottingham, but this example does not determine the law governing personal data, regulated health information or cross-border services. The parties must confirm required privacy notices, data-processing terms, security certifications, continuity plans, authority to sign and any procurement or sector-specific formalities before relying on it.

Signatures

For Evergreen Health Supplies Ltd: Laura Whitmore, Finance Director Signature: ____________________ Date: 15 September 2026

For Cloudbridge Operations Ltd: Ethan Okafor, Managing Director Signature: ____________________ Date: 15 September 2026

Create a version for your situation

Create a tailored Managed Service Agreement