Technology Law · Contracts

Technology Contracts.

Cloud services agreements, SaaS and software licensing, IT procurement, vendor and outsourcing contracts, technology partnership arrangements and API/integration agreements — drawn from in-house procurement experience.

8Jurisdictions Covered
4Languages
Fortune 50 GC experience
Our Managing Partner has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across seven business lines and eight countries.
Dual-qualified: England & Wales + Greece
Our Managing Partner is dual-qualified in England & Wales and Greece, so English-law questions are advised on directly in-house. Court appearances remain before the Greek courts and international arbitral tribunals; English proceedings are conducted through instructed English correspondent counsel.
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Practical, deployment-ready drafting
Drafted and negotiated from the buyer's chair — terms calibrated to the deal's actual risk, not templated boilerplate.
About to sign a technology contract?
Tell us which vendor, platform or deal it involves. We'll flag the clauses that actually carry risk before you sign.
Request Consultation
Overview Scope of Service Process Why Us FAQs

Technology Contracts

The risk is rarely in the clauses
a generalist knows to look for.

A cloud, SaaS or IT procurement contract looks, on the surface, like any other commercial agreement — a scope of services, a price, a term. In practice it carries a distinct set of risks that a generalist commercial lawyer routinely misses: service-level commitments that read impressively but are unenforceable as drafted, data processing terms that are legally mandatory rather than optional extras, intellectual property ownership in custom development work that defaults the wrong way, liability caps set without reference to what a breach or an extended outage would actually cost, and exit terms that only get read after the vendor relationship has already turned difficult. A SaaS contract lawyer in Greece reads the exit provisions first, because that is where customers are most often trapped.

SLAs are not just an uptime percentage. A 99.9% availability commitment sounds precise, but the number is meaningless without defined measurement windows, service credits that are proportionate to the actual business impact of downtime, and carve-outs that do not quietly swallow the guarantee. A Data Processing Addendum (DPA) is not optional — under the GDPR, any cloud or SaaS vendor processing personal data on your behalf must be bound by a DPA setting out processing instructions, sub-processor controls and breach notification duties; a vendor's silence on this point is not a minor gap, it is a compliance failure waiting to surface.

"Every vendor's standard paper is drafted to protect the vendor. Reviewing it is not about being difficult — it is about finding the handful of clauses that will actually matter the day something goes wrong." On the vendor side, a SaaS contract lawyer in Greece works to keep liability proportionate to the subscription value.

Two further questions decide whether a technology contract is safe to sign. Who owns the output of custom integration or development work — the vendor's standard terms often default IP ownership to the vendor even where the client paid for bespoke work, unless the contract says otherwise. And what happens at exit — a contract with no transition assistance clause, no data export obligation and no defined off-boarding period can leave a business functionally locked into a vendor it no longer wants. Having negotiated large-scale IT procurement, vendor and outsourcing agreements from the buyer's side of the table, in-house, is what makes it possible to spot which of a vendor's standard terms are genuinely negotiable and which fights are worth having. Send the terms and we will mark the clauses worth negotiating.

Beyond the headline number
SLAs are not just uptime numbers
An availability percentage means little without measurement windows, proportionate service credits and carve-outs that do not swallow the guarantee.
GDPR requirement
DPAs are mandatory, not optional
Any vendor processing personal data on your behalf must be bound by a Data Processing Addendum — its absence is a compliance gap, not a formality to skip.
Common gap
Who owns custom integration work?
Vendor paper often defaults IP in bespoke development or integration work to the vendor, even where the client paid for it, unless the contract states otherwise.
Exit planning
Plan your exit before you sign
Transition assistance, data export rights and a defined off-boarding period should be negotiated at signing, not discovered when the relationship ends.

Scope of Service

From vendor paper
to signed, deployment-ready contract.

Cloud Services & SaaS Agreements
Reviewing and negotiating cloud hosting and SaaS subscription agreements — service scope, availability commitments, data handling, and step-in rights on renewal or termination.
CloudSaaSSubscription Terms
Core service →
01
Software Licensing
Drafting and negotiating on-premise and hybrid software licences — usage rights, seat and capacity metrics, source code escrow, and audit and compliance clauses.
LicensingEscrowAudit Rights
Core service →
02
IT Procurement & Vendor Contracts
Structuring and negotiating hardware, software and infrastructure procurement contracts — drawn directly from in-house experience running large-scale IT procurement.
ProcurementVendorInfrastructure
Core service →
03
Outsourcing & Managed Services
Negotiating outsourcing and managed services agreements — governance structures, transition-in and transition-out obligations, and step-in rights if performance fails.
OutsourcingManaged ServicesTransition
Core service →
04
Technology Partnership & API/Integration Agreements
Structuring technology partnership arrangements and API and system integration agreements — allocating IP ownership in custom-built connectors and joint development work.
PartnershipsAPIIntegration
Core service →
05
Data Processing Addenda & SLAs
Drafting and negotiating GDPR-compliant Data Processing Addenda and service-level agreements with measurable, enforceable availability and support commitments.
DPAGDPRSLAs
Core service →
06

How We Work

A contract process built around actual deal risk.

STEP 01
Requirements & Risk Mapping
Understanding what the technology actually does, what data it touches and what an outage or breach would cost — before a single clause is reviewed.
STEP 02
Drafting or Vendor-Paper Review
Drafting the agreement from scratch, or line-by-line review of the vendor's standard terms to flag which clauses are genuinely negotiable.
STEP 03
Negotiation
Negotiating SLAs, liability caps, data processing terms, IP ownership and exit provisions directly with the counterparty or its legal team.
STEP 04
Execution & Contract Lifecycle Management
Finalising execution and tracking renewal dates, SLA performance and compliance obligations through the life of the contract.

Why Pantazis & Associates

Contract advice from someone
who has actually run procurement.

In-House · Fortune 50
Fortune 50 GC experience
Managing Partner Dionysios Pantazis has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across seven business lines and eight countries.
Dual Qualification · International
England & Wales + Greece — English-law vendor paper covered directly
Most global cloud and SaaS providers govern their standard terms by English law — reviewed and negotiated directly under a single instruction, without a referral to a second firm.
Publications · Speaking
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Commercial · Business-First
Practical drafting calibrated to actual deal risk
Advice grounded in having sat on the buyer's side of the procurement table — prioritising the clauses that matter when something goes wrong, not exhaustive redlines for their own sake.
Telecoms · First of Its Kind
The first Managed Services transaction in Cyprus
Acted for a major telecoms operator on the first Managed Services transaction concluded in Cyprus, structuring a model with no domestic precedent.
Telecoms · 5G
5G rollout contracts
Handled the contracts underpinning a 5G network rollout for a key telecoms company, covering supply, deployment and service levels.

Frequently Asked Questions

Questions about technology contracts.

What should I check in a SaaS vendor's standard terms before signing?+

Start with five areas vendors' standard paper is drafted to minimise, not clarify: the service-level commitment, including how availability is measured and whether service credits are proportionate to actual business impact; the liability cap, and whether it bears any relation to what a data breach or extended outage would actually cost you; data processing terms, including whether a proper Data Processing Addendum is included or needs to be added; ownership of any custom configuration or integration work; and exit terms — transition assistance, data export rights and a defined off-boarding period. Most SaaS agreements are negotiable on these points even when presented as non-negotiable "standard terms," particularly for contracts of meaningful commercial value.

Do I need a separate Data Processing Agreement (DPA) with my cloud provider?+

Yes, if the provider processes any personal data on your behalf — which covers the great majority of cloud and SaaS relationships. Under the GDPR, a controller (your business) is legally required to have a written agreement with any processor (the vendor) that sets out the subject matter and duration of processing, the vendor's obligations, sub-processor controls, data security measures and breach notification duties. This is not a courtesy document — its absence is a compliance failure that a regulator or an auditor will flag. Many vendors offer a standard DPA as an add-on or embedded addendum; where one is not offered, it needs to be negotiated as a condition of signing, not treated as optional.

Who owns the code/IP from custom integration or development work?+

It depends entirely on what the contract says, and vendor standard terms frequently default ownership to the vendor even where the client commissioned and paid for bespoke work. Without an explicit IP assignment or licence-back clause covering custom integrations, API connectors or configuration work, the business that paid for the development may find it does not actually own — or even have an unrestricted right to keep using — the very thing it commissioned. This becomes a serious problem if the vendor relationship ends, since work you assumed was yours may not be portable to a replacement vendor. We make sure ownership or licence terms for any bespoke work are addressed explicitly, not left to a vendor's default position.

What happens if our vendor fails to meet its SLA?+

That depends on what remedies the contract actually provides, which is precisely why the SLA needs to be reviewed before signing rather than after a failure occurs. Well-drafted SLAs specify measurable service credits tied to the severity and duration of the failure, a right to escalate or terminate after repeated or severe breaches, and — for genuinely critical services — a liability carve-out so the vendor's standard liability cap does not also apply to SLA failures. Many standard SLAs offer only modest service credits as the sole remedy, with no escalation or termination right attached, which leaves a business with no real leverage when the failure actually matters. We negotiate these remedies upfront so they are enforceable when needed, not aspirational.

Can you review contracts governed by English law, not just Greek law?+

Yes — this is a routine part of the practice. A large share of global cloud, SaaS and technology vendor agreements are governed by English law, or by the law of a US state with an English-law-trained lawyer handling the negotiation, and dual qualification in England & Wales alongside Greece means these contracts are reviewed and negotiated directly, without a referral to a second firm or a second round of instructions. Where a contract sits across both Greek regulatory requirements — data protection, sector-specific rules — and a foreign governing law, both angles are covered under a single instruction.

About to sign a technology contract?
Get it reviewed before you're locked in.

A confidential conversation about the deal, the vendor, and the clauses that actually carry risk.