← Digital, E-Commerce & AI

Digital · Service levels

Service Level Agreement — SLA

An SLA is not an uptime figure placed in a quotation. It must show which service is measured, from what point, using which tool, which periods are excluded and what happens when the parameter is not met.

measurable uptime incidents by severity service credits
Core formulaAvailability calculated using an agreed method
Critical workflowDetection, notification, response, remediation and reporting
Usual remedyService credits without concealing other rights
01

What the SLA actually measures

Availability can be measured at the interface, API, infrastructure or essential-function level. If these reference points are unspecified, two accurate technical reports may produce different percentages.

The SLA specifies the time zone, measurement window, data source and rounding rule. Scheduled maintenance and events beyond the provider’s control are excluded only within clear limits.

02

Incidents and operational times

Response time is not resolution time. The agreement must separate acknowledgement of the incident, commencement of investigation, workaround, restoration and permanent resolution.

  • Severity: objective criteria based on affected users, data and functions.
  • Notification channel: portal, email, telephone and authorised persons.
  • Coverage: normal business hours, 24/7 or differentiated periods.
  • Escalation: technical and management levels with clear intervals.
  • Communication: regular updates and minimum information.
  • Post-mortem: cause, timeline, impact and preventive measures.
03

Service credits and liability

Credits can provide a swift, proportionate remedy, but must have a formula, a cap and a simple procedure. Requiring the credit to be claimed within a very short period can make the remedy illusory.

If service credits are declared the exclusive remedy, exceptions must be established for serious breaches, data loss, confidentiality, security or other situations where a simple discount does not cover the loss.

04

The SLA in relationships with cloud providers

A provider should not promise customers parameters that its own upstream contracts cannot support. The cloud region, managed services, maintenance and infrastructure provider’s limits must be checked.

For entities and providers within the scope of NIS2, incident management and reporting obligations are not replaced by the SLA. Government Emergency Ordinance No. 155/2024 and Commission Implementing Regulation (EU) 2024/2690 may affect operational processes and deadlines.

05

How we work together

  1. 01
    Mapping the service

    We clarify the product, users, technical workflows, commercial model and documents already in use.

  2. 02
    Legal analysis

    We establish the B2B or B2C regime, the parties’ roles, applicable legislation and risks to be allocated.

  3. 03
    Drafting and alignment

    We prepare the documentation for the SLA and incident procedure and align it with the interface, offer, technical processes and schedules.

  4. 04
    Implementation

    We deliver the final version and a clear set of observations for publication, signature, configuration or operational use.

QUESTIONS

Frequently asked questions

Is “99.9% uptime” sufficient wording?

No. The measured service, period, method, exclusions and source of truth must be defined. Otherwise, the percentage cannot be verified consistently.

Does response time mean the problem will be resolved?

No. The response acknowledges and starts handling the issue; resolution or a workaround must have separate targets.

Do credits eliminate all other liability?

Only if the agreement validly provides this and only within permitted limits. Certain breaches require exceptions and additional remedies.

Need an SLA for IT services?

Send your documents for a legal assessment and a solution tailored to your commercial objective.