Your own paper
Subcontractor agreements for software houses: B2B contractors under Polish and Estonian law
Your client’s MSA promises IP, confidentiality and non-solicit. Your contractor agreement has to deliver them — or you have promised what you do not own.
6.1Contractor assigns all rights in the results of the Services to Companyassigns to Company all economic copyright in the results of the Services, without territorial limitation and for the full term of protection, in the following fields of exploitation: reproduction by any technique; distribution and lending of copies; entry into computer memory and hosting; public communication and making available online; adaptation, translation and modification, including creation and exploitation of derivative works.
- Every promise in your client MSA has to exist in your contractor paper, in at least the same scope and no later.
- Polish assignments must enumerate fields of exploitation; a blanket “all rights” clause leaves gaps.
- A post-term non-compete on a Polish or German contractor needs compensation to be enforceable. A non-solicit usually does not.
The back-to-back principle
A software house is a two-sided contract business. On one side are enterprise clients whose templates demand ownership, confidentiality, security commitments and restraint on hiring. On the other side are contractors — in most CEE software houses, B2B contractors rather than employees — who actually write the code.
The rule is boring and absolute: you cannot grant downstream what you have not acquired upstream. Every obligation you accept in a client MSA should have a mirror in the contractor agreement, in at least the same scope, effective at least as early, and lasting at least as long. Most of the expensive surprises in this business come from a mismatch in one of those three dimensions.
The practical way to run the check is to read the client MSA with a pen and list every promise that depends on someone other than you performing: IP assignment, confidentiality, data protection, security controls, non-solicitation, audit rights, background checks. Then open the contractor template and find each one. What is missing is your exposure.
IP assignment: the Polish fields-of-exploitation rule
Polish copyright law does not recognise a general transfer of “all rights”. An assignment is effective only for the fields of exploitation — the pola eksploatacji — expressly identified in the contract, and only for fields known at the time it was signed. A clause reading “Contractor assigns all rights in the work to Company” is not a wide assignment; it is an assignment with unpredictable holes.
For software, the fields that matter are reproduction by any technique, distribution and lending of copies, entry into computer memory and hosting, making available to the public online, and — the one that is most often omitted and most often needed — adaptation, translation and modification including the creation and exploitation of derivative works. Without the last of those, you may own the code and still lack the right to let your client modify it, which is precisely what the client MSA promised.
Two further Polish points. The assignment should be for the full term of protection and without territorial limitation, stated expressly. And the agreement should deal with remuneration: Polish law contemplates separate remuneration for each field of exploitation unless the contract says the agreed fee covers all of them, so say that it does.
Estonia is simpler. Economic rights in a work transfer by agreement without an enumeration requirement, so a well-drafted general assignment works. Moral rights cannot be transferred, and the standard approach is a licence and an undertaking not to assert them so far as the law allows. If your team spans both countries, write one template that satisfies the Polish requirement and use it in both — the enumeration does no harm under Estonian law.
Confidentiality flow-down
Client NDAs and MSA confidentiality clauses typically run for three to five years after the engagement, cover the client’s affiliates, and require you to impose equivalent obligations on anyone you give access to. The contractor agreement therefore needs a confidentiality clause that is at least as long, at least as broad, and survives termination.
Two details are worth the extra sentence. First, name the client’s confidential information as protected in its own right, not merely as your information — some client templates require the contractor to be capable of being held to the obligation directly. Second, deal with return and deletion: on termination the contractor deletes client material from personal devices and repositories and confirms it in writing. If your client MSA contains a deletion obligation and your contractor keeps the repository on a personal laptop, you cannot honestly certify compliance.
Non-compete and non-solicit for B2B contractors
This is where the jurisdictions diverge sharply, and where templates copied from English-law precedents cause real problems.
- Poland. A post-term non-compete with a B2B contractor is enforceable only if the contract provides compensation for the restraint period. No compensation, no restraint — and a court will not rewrite it for you. A restraint during the term needs no separate payment.
- Estonia. A post-term restraint must be reasonable in scope, duration and geography, and must be compensated. Twelve months is the usual outer edge for a developer.
- Germany. If any of your contractors are German, a post-term non-compete requires Karenzentschädigung of at least fifty per cent of prior earnings for the restraint period. Without it the clause is unenforceable, and a badly drafted one can leave the contractor free to choose whether to comply.
The consequence is straightforward: for most software houses, a post-term non-compete on contractors is not worth the price. A non-solicitation of clients and colleagues is cheaper, is not subject to the same compensation rules in most of the region, and protects the thing you actually care about. Combine it with a strong confidentiality clause and IP assignment, and you have most of the protection a non-compete promises without paying for a restraint you will probably never enforce.
Contractor or employee: the status risk
A B2B contractor who works fixed hours, under your direction, on your equipment, exclusively for you, with paid leave, is an employee in substance whatever the contract says. The consequences are tax and social-security reassessment, and in some cases employment claims.
In Poland the test przedsiębiorcy and the general case law on the boundary between an employment relationship and a services contract both look at the same factors: subordination, fixed working time, place of work, whether the contractor bears business risk, and whether they work for other clients. In Estonia, contractors frequently operate through their own OÜ, which helps, but the substance test still applies.
What to put in the paper, and more importantly what to do in practice: define deliverables and acceptance rather than hours; let the contractor choose where and when to work within project deadlines; do not prohibit other clients outright; make the contractor responsible for their own equipment and their own taxes; and do not run them through your internal HR processes. The gap between what the contract says and how the relationship actually works is the risk, and only the second half of that is within your control day to day.
Termination and notice, matched to the client SOW
If your client can terminate a statement of work on thirty days’ notice and your contractor has a three-month notice period, you are carrying two months of cost with no revenue against it. Conversely, if your contractor can leave on a week’s notice in the middle of a fixed-price milestone, you carry the delivery risk.
Align them. Notice periods in contractor agreements should track the notice period in the client engagement they serve, with a mechanism to extend for the duration of a specific milestone. Where the client SOW has a transition-assistance obligation, the contractor agreement should have one too.
New paper does not fix old gaps. Run a short remediation: a one-page confirmatory assignment and confidentiality undertaking for every active contractor, listing fields of exploitation and covering work already delivered. It is a five-minute signature for them and it closes the exposure on every project currently running. Do it before a diligence process asks, not during one.
One template, or several
Most software houses end up with one master contractor agreement plus short per-project orders. The master carries IP, confidentiality, data protection, non-solicit and status provisions; the order carries scope, rate, duration and the client-specific obligations that flow down from that project’s MSA. That structure lets you onboard a contractor in a day and still pass a client audit, and it means a change in one client’s requirements does not require renegotiating your whole contractor base.
Next step
Have a contract like this on your desk?
Send it over. We will mark it up and walk you through it in twenty minutes — no cost, and you will know whether the desk is worth it.