software development disputes

Legal concerns in software support agreements

by

reviewed by

Malcolm Burrows

Software developers (Developers) need to ensure that they consider how they provide support (both technical and product support) when taking their application (Software) to market.  This applies regardless of the system architecture, however it is usually more important in the case of mission critical systems and those used for businesses.  In the world of software as a service and robust mature systems how support is to be provided can often be overlooked until an important customer asks to review the terms of service, the SLA or the support contract (Support Agreement) with an eye to negotiating the levels of service they can expect.

A Support Agreement can also be known as a service level agreement (SLA).  Regardless of how they are labelled it’s usual for such agreements to deal with the ‘levels of service’ and response times for example, that the customer can expect from the software developer or vendor.  One of the most important considerations for a Support Agreement is the distinction between support for the software, user support and technical or product support.  Related to this are the notions of supported and non-supported items and the issue of escalation procedures, particularly where the software supported is mission critical to the business.

Generally a Support Agreement is not a standalone obligation, its existence depends on the customer having a licence to the software from the Developer or a right to access the software in the case of a hosted application.  The factor being common to both is that the client does not own the software which they seek to obtain support for.

The installed versus hosted software divide

Apart from the parties to the agreement and the commercial terms such as what the customer will pay for support, the substantive clauses of Support Agreements differ depending on whether the software is installed on the client’s server infrastructure (Installed Software) or whether the developer arranges for hosting on third party infrastructure such as Microsoft Azure or Amazon web services (AWS)(Hosted Software).

In the case of Hosted Software it’s possible that customers share the hosting infrastructure with other users of that software potentially creating further legal issues to be addressed in the contracts. Regardless, Developers need to draft Support Agreements, taking the following into considerations:

Installed Software:

  • how and when updates to the Software are completed;
  • on what terms is the Developer allowed to access the customers’ server infrastructure;
  • whether the Developers’ employees and contractors need to be bound to any sort of obligation of confidence;
  • who is responsible for security and penetration testing for example;
  • access to the customers data and the customers instance of the software; and
  • responsibility for updates to the hosting environment.

Hosted Software:

  • who pays for the hosting;
  • whether a fair use policy is required for excess data use or hard data limits are to be set;
  • who has access to the environment;
  • how and when updates to the Software are done;
  • who is responsible for testing the updates; and
  • responsibility for backups of the data.

Clauses which are common in Service Level Agreements regardless of the hosting environment

Clauses which need to be considered by Developers regardless of how their software is architected in Support Agreements include:

  • the difference between technical (when the software produces errors) and product support (when users need help to make it work);
  • a precise definition or meaning of what constitutes an ‘issue or bug’;
  • the escalation procedure associated with bugs and expected resolution times;
  • items that are excluded from support;
  • pricing and payment for support provided;
  • whether the Developer offers any ‘uptime guarantees’;
  • how support is to be provided and the hours during which support will be provided;
  • whether support provided is part of a warranty claim from the Developer;
  • whether a Support Agreement is required for the Customer to obtain any other benefits such are upgrades or involvement in a user group for example;
  • whether support is packaged into levels such as a ‘bronze, silver or gold’ that entitles the customer to so many hours per month for example;
  • whether the customer requires the code to be placed in escrow in the event of liquidation of the Developer;
  • term or the duration of the agreement;
  • renewal terms;
  • a method of classifying the severity of an issue; and
  • uptime guarantees and whether any penalties should be imposed on the developer should these terms be breached.

There is very little Australian case law dealing specifically with Support Agreements and SLA’s both in the software development and managed services sector.  That said the case of Baan Australia Pty Ltd v George Weston Foods Ltd [2000] NSWSC 504 (8 June 2000) (Bann Australia) dealt with the issue of implied terms in these sorts of contracts.   The issues for determination by the Court in this case was whether or not various implied terms were to be imported into software licence and support agreement (SLSA) between the parties in order to provide George Weston Foods with a legal remedy against Baan Australia.  Because of this there was necessarily a discussion of the principles of business efficacy and the case of BP Refinery (Westernport Pty Ltd) v Hastings (1977) 180 CLR 266.

Baan Australia shows the length that some organisations will go to attempt to find a legal remedy in the Courts where the contracts, on their face do not assist.  This case also highlights the need for precision in drafting software licences and that care needs to be taken so as to avoid incorporating any pre-contractual representations into such contracts.

Takeaways

SLA’s are as unique as the software and services they relate to.  There however are significant differences depending on how the software is hosted and which party is responsible for the hosting environment.    Whether the clauses listed above are appropriate will depend on the hosting, the ownership of the software and whether or not the software is used in a business environment.

Links and further references

Legislation

Competition and Consumer Act 2010 (Cth)
Corporations Act 2001 (Cth)
Copyright Act 1968 (Cth)
Privacy Act 1988 (Cth)

Cases

Baan Australia Pty Ltd v George Weston Foods Ltd [2000] NSWSC 504 (8 June 2000)
Peter Peter Pan’s Backpacker Adventure Travel Pty Ltd and Anor v Eye Jam Interactive Pty Ltd [2012] QSC 227

Further information about software development

If you need assistance with software support agreements, contact us for a confidential and obligation-free discussion:


Related insights about software development

  • AI businesses should have duty of care

    AI businesses should have duty of care

    In a recent interview with InnovationAus.com, Victorian Senator Michelle Ananda-Rajah (Senator) emphasised the need to adopt digital duty of care laws for artificial intelligence (AI) companies.[1]  As a representative of the ALP and former AI start-up founder, the Senator calls for the proposed digital duty of care to apply to AI companies.  If implemented, the…

    Read more …

  • Federal Court orders winding up of crypto mining investment scheme

    Federal Court orders winding up of crypto mining investment scheme

    The Federal Court of Australia delivered judgment in Australian Securities and Investments Commission v NGS Crypto Pty Ltd (No 5) [2025] FCA 1611, on 18 December 2025 ordering the winding up of two (2) cryptocurrency related entities after finding that they operated an unlicensed financial services business and an unregistered managed investment scheme in contravention…

    Read more …

  • Online Safety – is your online business a DIS or a RES?

    Online Safety – is your online business a DIS or a RES?

    Whether your online business has to comply with the obligations contained in the Online Safety Act 2021 (Cth) (OSA), and related standards and industry codes will largely depend on how your business is classified because of the functionality it provides to end users in Australia.

    Read more …

  • Bill to allow victims of AI deepfakes to sue for emotional damages

    Bill to allow victims of AI deepfakes to sue for emotional damages

    On 24 November 2025, Senator David Pocock introduced a private Senator’s bill, the Online Safety and Other Legislation Amendment (My Face, My Rights) Bill 2025 (Cth) (Bill) to amend the Online Safety Act 2021 (Cth) (Online Safety Act) and the Privacy Act 1988 (Cth) (Privacy Act). 

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    On 3 December 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss the proposed amendments to the Online Safety Act 2021 (Cth) through the introduction of the Online Safety and other legislation Amendment (My Face Rights) Bill (Cth) 2025 (My Face Rights…

    Read more …

  • Federal Gov rules out copyright text and data mining exception for AI

    Federal Gov rules out copyright text and data mining exception for AI

    On 26 October 2025, the Attorney-General, Hon Michelle Rowland MP, published a media release reiterating that the current Federal Government will not introduce a text and data mining (TDM) exception to copyright infringement in the Copyright Act 1968 (Cth) (Copyright Act).  The Attorney-General’s Department will instead engage in further consultations with members of the Copyright…

    Read more …

  • Australian Government announces a digital duty of care

    Australian Government announces a digital duty of care

    The Australian Government has announced that it will soon be introducing legislation to create a digital duty of care under the Online Safety Act 2021 (Cth) (Act) in response to findings from an independent Statutory Review of the Online Safety Act 2021 (Review).  The Honourable Anika Wells MP announced that “big tech” companies will soon…

    Read more …

  • Dundas Lawyers achieves SMB1001 gold level cyber security certification

    Dundas Lawyers achieves SMB1001 gold level cyber security certification

    On 14 November 2025 Dundas Lawyers achieved the Gold level of the SMB1001 cybersecurity standard.

    Read more …

  • OAIC publishes new guidance for under-16s social media ban

    OAIC publishes new guidance for under-16s social media ban

    On 10 October 2025, the Office of the Australian Information Commissioner (OAIC), led by Privacy Commissioner, Ms Carly Kind, released a twenty-nine (29) page Privacy Guidance on Part 4A (Social Media Minimum Age) of the Online Safety Act 2021 (New Guidance).  This New Guidance details the privacy obligations for Age-Restricted Social Media Platforms (Restricted Platforms)…

    Read more …

Send this to a friend