White label maintenance agreement: a checklist of what it has to settle
A white label maintenance agreement has to settle five things before anyone logs in. Who talks to the client, what work is included, who has access and how it ends, what happens when something breaks, and how either side leaves. This checklist gives the question for each.
- By
- WP Ministry
- Published
In short
- Settle who the client hears from, the scope, access, what happens when something breaks and how either side leaves, before a login is shared.
- Get every schedule and limit as a number. How often, how many days a backup is kept, how many minutes, which hours in which time zone.
- Give each person at the partner an account of their own, and write down how each one is removed.
- Where the GDPR applies, Article 28 requires your client's written authorization before you bring in a partner, and you stay fully liable for it.
- Promise your client no more than your partner promises you.
- This is a checklist, not a contract. Have counsel review the agreement you sign.
A white label maintenance agreement has to settle five things before anyone logs in: who talks to the client, what work is included and what is not, who can access what and how that access is protected and ended, what happens when something breaks, and how either side leaves. The price belongs in it too, but nobody forgets that part.
This checklist is for an agency about to let another company maintain its clients' WordPress sites under the agency's name. Each item is a question to put to the partner, with what a clear answer looks like.
How to use it
Send the questions in writing. A clear answer has a number, a name or a date in it. Then check that every answer appears in the agreement or in a schedule attached to it. A reply in an email is not a term.
If you are still choosing a partner, start with the questions in how to choose a WordPress maintenance service.
Who the client hears from
- Whose name is on the reports, the alerts and the replies? A clear answer lists everything a client can see and says each carries your agency's name: the report, the sender's address, the signature on a reply. Ask also what a client who logs in to WordPress sees, such as the email address on the partner's account in the user list.
- Which address do replies come from, and who controls it? A clear answer is an address at your domain, or a mailbox you can open. If the mailbox is the partner's, the history of every conversation with your clients leaves when the partner does.
- May the partner ever contact a client directly? A clear answer is "never", or a short list of cases with you copied on each.
- Will the partner sell to your clients, now or later? A clear answer is a written undertaking not to, for a stated time after the agreement ends, and a rule for what happens if a client approaches the partner. Ask counsel what such a term may say where you are.
- What is confidential, and for how long? A clear answer covers the client list, the arrangement itself, every login and anything seen on a client's site. It binds anyone the partner employs or hires, it outlasts the agreement, and it stops the partner naming you or your clients as customers.
Scope: what is done, how often, and what is not
What WordPress maintenance includes describes each job. The agreement has to put a schedule on each one.
- Which updates are applied, how often, and what is checked afterward? WordPress's Updates screen lists what is waiting for WordPress itself, plugins, themes and translations. A clear answer names which of those are covered, the day or interval, and what someone looks at once the updates are in.
- What is in a backup, how often is it taken, where is it stored and for how long? WordPress's documentation says a full restore needs both the database and the files, and that copies belong in different places. A clear answer gives both parts, a frequency, a location away from the site's server, a number of days, and how you get a copy without asking. WordPress's hardening guide shows why the days matter: a site compromised on May 1 and noticed on May 12 needs a backup from before May 1.
- What does monitoring check, how often, and who is told? WordPress's documentation describes uptime monitoring as checking one or more URLs at regular intervals. A clear answer gives the interval, who receives the alert, and what the partner does about one outside its working hours.
- What is scanned, how often, and what happens after a finding? Finding malware and removing it are two jobs. A clear answer says whether cleanup is included or quoted, and who tells you.
- What does the report show, and when does it arrive? A clear answer is a sample under your brand and a day of the month. Compare it with the monthly maintenance report template.
- What counts as an edit, and how is time counted? A clear answer gives the allowance in minutes or hours, says whether it is per site or shared across your sites, names the smallest amount of time that is billed, and says whether unused time carries over.
- What is excluded, and how is it quoted? A clear answer is a list, a written quote before any extra work starts, and no charge without your approval.
Response: when requests are picked up
- By which channel do requests go in? A clear answer is one address or one ticket system, and a rule for whether your clients write to it or you forward.
- In which hours is someone reading it? A clear answer writes out the days, the hours, the time zone and the holidays. The promise should be the hours that are staffed. Your client's working day may be the partner's night.
- How long until a reply, and what is a reply? A clear answer gives a time inside those hours, and means a person's answer, not an automatic receipt. A reply is not a fix. A time for the fix is a separate number.
- What counts as an emergency, and what happens outside hours? A clear answer defines it, such as a site that does not load or a checkout that fails, gives the channel for it, and says who answers. "Nothing until the next working day" is a clear answer. You can plan around it.
Access and security
- How are logins shared and stored? A clear answer is that no password travels by email or chat and that the partner keeps logins in a password manager. Better, nothing is shared, because each person has an account of their own. For files, WordPress's hardening guide says to connect over SFTP where the host offers it, so that the password is encrypted on the way.
- Does each person at the partner have a separate account? A clear answer is one account per named person, a list of those names, and a notice to you when someone joins or leaves. WordPress's hardening guide notes that server logs show an IP address and a time but not which username logged in. With one shared login, nothing WordPress records can tell people apart either.
- Which role does each account hold? Of WordPress's six predefined roles, only an Administrator can update WordPress, plugins and themes on a single site, so the partner's accounts will be administrators. Least privilege, in NIST's definition, limits access to the minimum necessary for the assigned tasks. Apply it outside WordPress: an administrator on the site does not need to own the hosting account, the domain or the billing.
- Is a second step required at login? A clear answer is yes, on every partner account on every client site and on the partner's own email and password manager. WordPress's documentation defines two-step authentication as using two of three kinds of proof and points to plugins that add it. See how to set up two-factor authentication in WordPress.
- How do the partner's tools connect to a site? A clear answer names each tool, any plugin it installs, and the account it connects through. WordPress's documentation says an application password is tied to one user, cannot be used to log in to the dashboard, and can be revoked without touching that user's own password. Ask for one per tool, created under the partner's account and not yours.
- What else can the partner reach? A clear answer is a list for each site: the hosting panel, SFTP or SSH, the database, DNS, the registrar, analytics, the payment provider. Where a service lets an owner add a person with a login of their own, use that. Google Search Console does: an owner adds a user and removes them again.
- What is recorded? A clear answer is a log of who did what on which site and when, how long it is kept, and that you can ask for it.
- How is access removed? A clear answer gives a number of days after the agreement ends, and after any person leaves the partner, and a written confirmation. Then check it yourself, with the steps further down.
Client data
An administrator can see whatever the site holds, such as accounts, comments, form entries and orders. GDPR and WordPress lists what a site collects.
- What personal data can the partner see, and on which sites? A clear answer is a list by kind of data and kind of person, such as customers' names, addresses and orders on a store.
- On whose instructions does the partner act? A clear answer is yours, in writing, and for no purpose of its own.
- Who else does the partner use? A clear answer names each company and contractor that stores or can reach the data, such as backup storage, and says what happens before one is added.
- Where is the data stored, and where are the people who log in? A clear answer names countries for both.
- How soon are you told about a breach? A clear answer is a number of hours from the moment the partner knows, a named contact, and what the notice will contain.
- What happens to the data when the agreement ends? A clear answer says what is returned, what is deleted, by which date, and that the deletion includes backups.
What the GDPR's text requires, where it applies
The GDPR is Regulation (EU) 2016/679. Article 3 says it applies to processing in the context of the activities of an establishment of a controller or a processor in the European Union. It also applies to a controller or processor outside the Union, where the processing relates to offering goods or services to people in the Union or to monitoring their behavior there. Where it does not apply, neither does this section. Whether it reaches one of your clients is a question for counsel.
Article 4 defines a controller as the party that determines the purposes and means of the processing, and a processor as one that processes personal data on the controller's behalf. If your client is the controller for its site and you are its processor, a partner you bring in is what Article 28 calls "another processor". The European Data Protection Board's guidelines say the roles follow from what each party actually does, not from what a contract calls it.
| Article | What the text says, in short | What to settle |
|---|---|---|
| 28(2) | A processor does not engage another processor without the controller's prior written authorization, specific or general. Under a general one, it tells the controller of intended changes, so that the controller can object. | Whether your client agreement authorizes a partner |
| 28(3) | A contract sets out the subject matter, duration, nature and purpose of the processing, the type of personal data and the categories of people. It binds the processor to act only on documented instructions, to bind its people to confidentiality, to secure the data as Article 32 requires, to help the controller answer people's requests and meet Articles 32 to 36, to delete or return the data at the end as the controller chooses, and to allow audits. | That the partner agreement says each of these |
| 28(4), 28(9) | The same data protection obligations are placed on the other processor by a contract in writing. If it fails to meet them, the first processor remains fully liable to the controller. | That the partner owes you what you owe your client |
| 33(2) | A processor notifies the controller without undue delay after becoming aware of a personal data breach. | The hours until the partner tells you |
| 44 | Personal data goes to a country outside the Union only under the conditions of Chapter V. | Where the partner's people and storage are |
Each row is a short reading. The articles carry conditions that a table leaves out.
Three more things bear on a white label arrangement. The first two are guidance, not the regulation's text.
- Say how, and say how fast. The Board's guidelines say the agreement should not merely restate the GDPR but say concretely how each requirement is met, and that it may be appropriate to set a time, such as a number of hours, for the processor's notice of a breach. Under Article 33(1), a controller that has to notify its authority does so, where feasible, within 72 hours of becoming aware of the breach.
- The client may need to know who the partner is. The Board's Opinion 22/2024 concludes that a controller should have the identity of every processor and sub-processor readily available at all times: name, address and contact person. Ask counsel how that sits with keeping the partner's name from a client.
- There are standard clauses. The European Commission published standard contractual clauses for controllers and processors on 4 June 2021. Article 28(6) says a contract may be based on them in whole or in part.
The GDPR is not the only law of its kind. California's Consumer Privacy Act, for one, requires a business it covers to have an agreement with a service provider to which it discloses personal information (Civil Code section 1798.100(d)).
When something breaks
- Who is responsible when an update breaks a site, and what is fixed at no charge? A clear answer says the partner restores the site, at no charge, when work it did was the cause, and says what is quoted when the cause was something else. The line should be one you could repeat to a client.
- What is the restore commitment? A clear answer says which backup is used, how soon work starts inside the staffed hours, and how much recent data may be lost. With one backup a day, that can be a day of orders and form entries.
- What happens if a site is hacked? A clear answer says who is told and when, whether cleanup is included or quoted, and who decides to take the site offline. The hacked WordPress site runbook shows the order of work.
- Who speaks to the client during an incident? A clear answer is you, with the partner sending you a written account of what happened and when.
- What are the limits of liability? This one is for counsel. Ask whether the partner's liability is capped, at what, what is excluded from it, and how that compares with what you have accepted toward your own clients. Take no figure from another company's contract.
- Is the partner insured? Ask what kind of cover it holds and for proof of it. Ask your own insurer whether your policy covers work that a subcontractor does in your name.
Money
- What is the price per site, and where does it step? A clear answer gives the price, the number of sites at which it changes, and whether the lower price then applies to every site or only to the ones above the step.
- Is there a minimum? A clear answer names any minimum number of sites, monthly fee or term.
- What happens when a site is added or removed in the middle of a month? A clear answer says whether the month is charged in part or in full, and from which day.
- When is the invoice raised, in which currency, and for which period? A clear answer says whether you pay before the month or after it.
- How much notice comes before a price change? A clear answer is longer than the notice you owe your own clients, so that you can pass a change on.
- What happens if an invoice is late? A clear answer says when work pauses, and that backups and access are not withheld.
The care plan margin calculator shows what is left from each plan once the partner is paid.
Leaving
- How much notice does each side give? A clear answer is a number of days for you and one for the partner. The partner's should be long enough for you to move every site elsewhere.
- What is handed over? A clear answer lists the newest full backup of each site in a form you can restore without the partner's tools, past reports, every login and license held for you, and notes on what the partner installed.
- What does the partner remove? A clear answer lists its accounts, its application passwords, its plugins and its connections to hosting and other services, with a date.
- When is client data deleted? A clear answer gives a date for the partner's copies and backups, and a written confirmation.
- What happens to a site in the middle of an incident? A clear answer says the work continues to a stated point, or is handed over with a written account.
- What outlasts the agreement? Confidentiality, and the undertaking not to sell to your clients.
- What if the partner is the one that ends it, or stops trading? A clear answer is the same handover.
Check that access has ended
The agreement should say that the partner removes its own access and confirms it in writing. Check anyway, on every site. These steps use WP-CLI, and each can also be done on the Users screen.
Step 1: List the administrators
Every administrator you do not recognize is a question for the partner. On the Users screen, the role links above the table do the same.
bashwp user list --role=administrator --fields=ID,user_login,user_email,user_registeredStep 2: Look for application passwords
Replace
partner-loginwith the username. WP-CLI printscreatedandlast_usedas Unix timestamps. The Application Passwords section of the user's profile shows the same list as dates. Run it for your own account as well: a tool that was connected under your login keeps working after the partner's account is gone.bashwp user application-password list partner-login --fields=uuid,name,created,last_used,last_ipStep 3: Delete each account the partner used
Deleting a user deletes every post that user owns unless you name an account to receive them. Without
--reassign, WP-CLI warns of this and asks before it goes on.--reassigntakes the ID of the receiving account, so replace1with the right one from the first step. Deleting the account ends its application passwords too.bashwp user delete partner-login --reassign=1Step 4: Close what is outside WordPress
Remove the partner from the hosting panel, SFTP and SSH, the database, DNS, the registrar and the backup storage, and remove any plugin that connected the site to its tools. Change every password that was ever shared. In Google Search Console, an owner who verified with a token can regain access until that token is taken off the site, and Google lists the tokens when you remove the owner.
Red flags
- Anything promised with no limit. Edits, support requests or sites with no number attached. The number exists, and you will learn it later.
- A response promise with no hours. A reply time means nothing until it says which days, which hours and which time zone.
- No named way to end access. If nobody can say how accounts are removed, they are not removed.
- A partner that insists on owning the hosting account or the domain. ICANN calls the person or entity that holds the rights to a registered domain name the registrant. If that is the partner, the rights are the partner's.
- One shared login for the partner's whole team.
- Backups only the partner can reach.
- A guarantee that a site will never be hacked or never go down. Nobody controls that.
- No answer about who else handles the data, or where.
Make your client agreement match
You cannot promise a client more than your partner promises you. Read the two agreements side by side.
| Your client agreement says | The partner agreement has to say |
|---|---|
| Hours of cover and a reply time | The same hours or wider, and a faster reply, so that you have time to pass things on |
| How often backups are taken and how long they are kept | At least the same |
| An allowance for small changes | At least the same, or you do the difference yourself |
| A restore when an update breaks the site | The same, at no charge to you |
| A notice period to end the plan | A longer one from the partner to you |
| Notice of a price change | A longer one from the partner to you |
| How soon the client is told about a breach | A shorter time from the partner to you |
| What you are liable for | A question for counsel: whether the partner's limits leave you carrying the gap |
Check two more things in your client agreement. Does it let you hand the work to another company at all? And where the GDPR applies, does it give the written authorization that Article 28(2) requires? The care plan proposal template is a starting point for the client's side.
WP Ministry's white label is its Essential care plan, delivered under your agency's brand, for agencies with three or more client sites. Put these questions to it as you would to anyone.
Common questions
Do I have to tell my clients that another company does the work?
Your agreement with each client decides whether you may hand work to someone else, so start there. Where the GDPR applies and you are the client's processor, Article 28(2) requires the client's written authorization before you engage another processor, and the European Data Protection Board's opinion is that a controller should have the identity of every sub-processor available. Ask counsel what that means for your clients.
What if the partner will not change its standard terms?
Then its standard terms are the answers. Read them against each question here. Where they are silent, ask for the answer in writing as part of the agreement, and promise your clients nothing the terms do not cover.
Should the partner use my administrator account or accounts of its own?
Accounts of its own, one for each person. With a shared login nobody can tell who did what, and ending access means changing a password that you also use. A separate account is deleted on the day the work ends.
Who answers to my client if the partner makes a mistake?
Your client has an agreement with you and none with the partner, so it will come to you. What you can then recover from the partner is whatever your agreement with it says, which is the reason to read the two together. Where the GDPR applies, Article 28(4) says the first processor remains fully liable to the controller for the other processor's obligations.
- GuideShould you outsource WordPress maintenance? A decision guide for agencies and freelancers
- GuideHow to price WordPress care plans: find your floor, find the ceiling, then build tiers
- GuideHow to sell WordPress care plans: when to offer one, what to say and how to answer objections
- ResourceTaking over a client's WordPress site: a checklist to run before you change anything
- ResourceMonthly WordPress maintenance report template
- ResourceWordPress care plan proposal template for agencies

