It depends. Capping liability at the fees paid is common in the market, but accepting it on its own for critical processes is unwise, because the loss is often many times the amount paid. Under the Turkish Code of Obligations (No. 6098) agreements that exclude liability for gross fault or intent in advance are void, so an absolute fees-paid cap gives no protection in those cases in any event.
The balanced answer is tiered caps set by the type of loss: separate and higher caps — or carve-outs from the cap altogether — for data breach, intellectual property infringement and confidentiality. Alongside that, require the supplier to carry professional indemnity or cyber insurance, and set a human-in-the-loop approval threshold for critical decisions. The supplier’s IP indemnity undertaking should be secured expressly in the contract as well.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.