Statement of work
Define deliverables, dependencies, responsibilities, exclusions, schedule and acceptance. Avoid contracts where the commercial terms are precise but the deliverable is vague.
Intellectual property
State who owns code, designs, documentation, data models, prompts, test assets and other work product created for the project. Identify pre-existing vendor tools separately so ownership is not confused with a licence.
Open-source and third-party components
Require the provider to disclose significant third-party libraries, services and licences. This matters for commercial use, security updates and long-term maintenance.
Confidentiality and data
Define permitted use, access, storage, subprocessors, retention, deletion and incident notification. If personal data crosses borders, the buyer should confirm which laws apply to its own organization and what contractual safeguards are required.
Acceptance and warranty
Acceptance criteria should be testable. If a warranty period is included, clarify whether it covers defects against the agreed scope or new requests.
Termination and transition
Plan for a clean exit: source-code transfer, credential removal, data return or deletion, documentation, knowledge transfer and any final invoices.
Include an exit checklist
Termination clauses should cover repository access, cloud accounts, design source files, documentation, credentials, data return, deletion, unresolved defects and knowledge-transfer time. An agreement that defines ownership but not handoff can still leave a buyer operationally trapped.
Match liability terms to actual risk
Caps, indemnities, confidentiality obligations and insurance should reflect the type of work. A small brochure-site contract and a provider processing regulated customer data should not use the same risk template.
Address open-source and third-party components
Ownership language does not magically transfer third-party software. Require the provider to identify material open-source libraries, commercial plugins, stock assets and external services so the buyer understands licence obligations and recurring fees.
Define subcontracting notice
If confidentiality, data location or regulated information matters, the contract should state whether the provider may use subcontractors and what notice or approval is required. The buyer should know which legal entities and people may receive access.
Keep the commercial schedule readable
Core delivery terms should not be buried across proposals, chat threads and invoices. Keep the signed agreement, statement of work, rates, milestones, change process and named contacts together. Commercial clarity reduces disputes because both sides can see which document controls when assumptions conflict.