1. The essential clauses
    1. Licence grant and scope of use
    2. Acceptable use and prohibited conduct
    3. Fees, billing, and payment
    4. Service levels and support
    5. Data handling and privacy
    6. Intellectual property
    7. Warranties and disclaimers
    8. Liability cap and exclusions
    9. Term, termination, and suspension
    10. Changes to the terms
    11. Governing law, disputes, and notices
  2. Situational clauses worth considering
  3. How Artificer Legal can help
  4. The liability cap and exclusions clause

You have built a product — software, a web app, a mobile app, a SaaS platform — and now someone is asking you to tick a box accepting your terms, or you have received a draft agreement from a counterparty and are wondering whether it actually covers your situation. Either way, the document in front of you is your end user agreement: the contract that governs what your customers can do with your product, what you have promised them, and who bears the risk when something goes wrong.

An end user agreement is not a single fixed form. It can be called an End User Licence Agreement (EULA), Terms of Use, Subscription Terms, or a Master Subscription Agreement. The label matters less than the content. The document displaces the generic common law position — under which your obligations and your customer's rights would be set entirely by statute and implied terms — and replaces it with a negotiated (or at least clearly stated) set of rules. It sits alongside, but does not replace, your Privacy Policy, and may be supplemented by separate schedules for service levels, data processing, or API access.

The essential clauses

Licence grant and scope of use

This is the engine of the agreement. You are not selling your software; you are granting a limited permission to use it. The clause should define exactly who may use the product (named users, seats, departments, or the whole organisation), on which devices or environments, and for what purpose (personal, internal business, commercial resale, or something narrower).

Traps to watch for:

  • A licence that is silent on transferability will usually be interpreted as transferable under general contract law principles. State expressly that the licence is non-transferable and non-sublicensable unless you intend otherwise.
  • If you offer different tiers, ensure the licence clause ties to the plan purchased — otherwise a customer on a free plan may argue the same access rights as an enterprise customer.
  • Geographic limits matter if you are concerned about export controls, data residency, or regulatory requirements in specific markets.

Acceptable use and prohibited conduct

This clause sets the behavioural floor. It lists what customers must not do: reverse engineer, decompile, scrape, use the product to harm third parties, upload infringing content, or run security tests without permission. It also gives you the contractual right to suspend or terminate access if a customer breaches those rules.

The drafting choice that matters most is specificity. Broad "don't do anything harmful" language is enforceable in theory but hard to act on in practice. If your product has genuine abuse vectors — AI-generated content, user messaging, API access, payment flows — name them explicitly.

Fees, billing, and payment

This clause needs to answer three questions precisely: how much, when, and what happens if the customer does not pay.

Key drafting minimums:

  • State the billing cycle (monthly, annual, usage-based) and when charges fall due.
  • Explain what happens at renewal: automatic renewal is standard for SaaS but must be disclosed clearly, particularly if the customer is a consumer.
  • Set out suspension and termination rights for non-payment, and any cure period before you can exercise them.
  • Address upgrades, downgrades, and proration if your product has multiple tiers.

Refund language in this clause must be consistent with your obligations under the Australian Consumer Law. A flat "no refunds" position is not legally available to you where a consumer guarantee is breached (see the ACL section below).

Service levels and support

Unless you are prepared to guarantee specific uptime, keep this clause carefully hedged. "Reasonable efforts" availability language is far safer than a stated percentage if you cannot actually monitor and enforce against it. If you do offer a service level agreement with uptime commitments and service credits, put it in a separate schedule — keeping the main agreement clean.

Describe your support channels, response targets (if any), and what is explicitly out of scope. Make clear that your roadmap may change: product features are not contractual promises unless you have specifically warranted them.

Data handling and privacy

This clause serves two purposes. First, it gives users a high-level explanation of what data you collect and how it is used, pointing them to your linked Privacy Policy for the detail. Second, it establishes ownership: customer data belongs to the customer, and you hold it only to provide the service.

Specific points to address:

  • What rights do you have to use aggregated or de-identified data for product improvement or analytics?
  • How can a customer export their data, and for how long after termination can they access it?
  • If you process personal information on behalf of a business customer, you may need a separate Data Processing Agreement — your main terms should acknowledge when that module applies.

The Privacy Act 1988 (Cth) regulates how organisations handle personal information. Private sector organisations with an annual turnover above $3 million are covered, along with some smaller organisations regardless of turnover (for example, those that trade in personal information or provide health services). If the Act applies to your business, you must comply with the Australian Privacy Principles — which include obligations about collection, use, disclosure, security, and access to personal information.

Intellectual property

This clause does two things. It confirms that you own everything you built — the software, the code, the documentation, the brand — and that nothing in the agreement transfers that ownership to the customer. It then addresses user-generated content: if your platform allows users to upload or create content, you need a licence from them broad enough to operate the service (hosting, processing, displaying) without claiming ownership.

Warranties and disclaimers

Most end user agreements disclaim implied warranties: the software is provided "as is", may contain bugs, and is not guaranteed to be error-free or uninterrupted. That framing is commercially standard and largely appropriate — but it cannot override the consumer guarantees implied by law.

s 64 of Schedule 2 of the *Competition and Consumer Act 2010* (Cth) (the Australian Consumer Law, or ACL) voids any term that purports to exclude, restrict, or modify consumer guarantees. The ACL guarantees that services will be rendered with due care and skill, be fit for any purpose the consumer makes known, and be supplied within a reasonable time. You cannot contract out of these. Your disclaimer clause should include express language acknowledging that nothing in the agreement excludes non-excludable consumer guarantees.

Liability cap and exclusions

This is the clause that will decide who bears the loss when something goes seriously wrong.

Common structure:

  • Exclusion of consequential loss: exclude liability for indirect, consequential, special, or punitive loss (lost profits, lost data, business interruption). Courts will enforce these if drafted clearly.
  • Liability cap: limit your aggregate liability to fees paid in the preceding 12 months, or some other defined amount. This is the variant most customers will push back on — enterprise customers in particular may seek a higher cap or carve-outs for specific claim types.
  • Carve-outs from the cap: death, personal injury, fraud, and breaches of confidentiality are commonly excluded from the cap and cannot be capped in some circumstances. Non-excludable ACL guarantees must also survive.

The ACL again constrains what you can do here. Under s 64A of Schedule 2 of the *Competition and Consumer Act 2010* (Cth), where a guarantee applies and the acquirer is not a consumer (for example, a business customer), you may be able to limit your liability to resupplying the service or paying the cost of resupply — but you cannot eliminate it entirely.

s 18 of Schedule 2 of the *Competition and Consumer Act 2010* (Cth) prohibits misleading or deceptive conduct in trade or commerce. Overstated capability claims in your marketing or onboarding flow can create liability that your limitation clause will not protect you from. s 29 of the ACL separately prohibits false or misleading representations about goods and services and can attract significant civil penalties.

Term, termination, and suspension

State the initial term (month-to-month, annual, or perpetual for a perpetual licence) and what happens at its end. Key points:

  • Grounds on which either party may terminate for cause (material breach, insolvency, regulatory compulsion).
  • Notice requirements and any cure period before termination takes effect.
  • Your right to suspend for security, compliance, or non-payment reasons — suspension is often preferable to immediate termination and should be available as an intermediate step.
  • What happens to customer data after termination: access period, deletion timeline, and any applicable export mechanism.

Changes to the terms

You will need to update your terms as your product evolves and as the law changes. This clause gives you the right to do so — but it must be fair. Reasonable notice of material changes (typically 30 days by email or in-app notification) is standard. Give customers a meaningful right to terminate without penalty if they object to a material change. Provisions that let you change terms with no notice and no exit right for the customer are increasingly risky, particularly where the ACL's unfair contract terms regime applies to standard form contracts with small businesses and consumers.

Governing law, disputes, and notices

Choose an Australian state or territory as the governing law and jurisdiction. For most Australian businesses, the state where your principal office is located is the natural choice. Include a brief dispute resolution ladder: informal negotiation first, then mediation if negotiation fails, with litigation as the last resort. Set practical rules for how notices are given — email is standard; specify the address and when email notice is taken to be received.

Situational clauses worth considering

  • API schedule: If you expose a developer API, add a schedule covering rate limits, key management, attribution requirements, and what happens when a key is compromised.
  • Data Processing Agreement (DPA): Enterprise B2B customers increasingly require a DPA before signing. Your main terms should confirm that a DPA applies to processing of personal data on their behalf, with the DPA as an attached schedule or linked document.
  • Service Level Agreement (SLA): If you are prepared to commit to uptime percentages and service credits, keep the SLA in a separate schedule so the main terms remain readable and you can update the SLA without re-executing the whole agreement.
  • Acceptable Use Policy: If you host user content, messaging, or community features, a separate AUP (referenced from the main terms) lets you update conduct rules without amending the core contract.
  • Enterprise order form: For self-serve and enterprise plans running off the same base terms, an order form or statement of work can capture the negotiated variables (price, seats, custom SLAs, specific DPA terms) without redrafting the whole agreement.

An end user agreement that looks complete on its surface can still expose your business to significant risk if the key commercial clauses are poorly calibrated or if the ACL compliance language is missing or wrong. When we review or draft these agreements, our focus is typically on:

  • The liability cap: Is it calibrated to your actual revenue exposure? Does it include the right carve-outs? Enterprise customers will negotiate this clause hard, and the starting position matters.
  • ACL compliance: We will confirm that your disclaimers and limitation of liability clauses include the non-excludable consumer guarantee language required by s 64 of the ACL, and that your refund and remedy language does not create an unlawful representation under s 29.
  • Data and privacy alignment: We check that your data handling clause, your Privacy Policy, and any DPA are internally consistent and that the Privacy Act obligations applicable to your business are properly reflected.
  • Acceptance mechanics: We will advise on whether your clickwrap acceptance process — the checkbox, the version record, the notification method for updates — is robust enough to be enforceable if a customer disputes what they agreed to.
  • Termination and suspension rights: We look at whether your suspension and termination triggers are wide enough to protect you in practice (security incidents, regulatory compulsion, serious misuse) and whether the post-termination data obligations are workable.

If you are launching a new product, updating terms after a significant product change, or preparing for an enterprise sale that will involve counterparty negotiation, an Artificer Legal practitioner can review your current position and prepare or redraft the relevant documents.

The liability cap and exclusions clause

In practice, more end-user-agreement disputes turn on the liability cap and exclusions clause than any other. Businesses often treat this clause as boilerplate and paste in the highest cap they can get away with — only to find, when a claim arises, that the carve-outs do not work as intended, the non-excludable ACL language is missing, or the consequential loss exclusion is drafted too narrowly to catch the loss they are actually facing. Getting this clause right at the drafting stage is far cheaper than litigating it later.

To bring it back to what the document is really for: an end user agreement is not primarily a risk-shifting mechanism. It is a clear statement of the deal — what you are offering, what you are not, and what happens if things go sideways. The businesses that get the most out of their terms are the ones that treat the agreement as a communication tool first and a liability shield second. That means plain language, accurate descriptions of what the product actually does, and honest disclosure of the limitations. A document like that is also far more enforceable than one drafted to obscure as much as it reveals.

The key points to carry forward: match the document structure to your delivery model (EULA for installed software, SaaS Terms for subscriptions, Terms of Use for platforms); ensure your liability and warranty clauses do not attempt to exclude non-excludable ACL consumer guarantees; address data ownership and the Privacy Act explicitly; use clickwrap acceptance with a version record; and build in a fair mechanism for updating the terms as your product evolves.