Stewart Law

SaaS Agreements

Stewart Law›Contract University›SaaS Agreements

Contract Types

SaaS Agreements

Software-as-a-Service agreements govern the subscription relationship between a software provider and its customers. Unlike traditional software licenses, SaaS customers do not receive a copy of the software — they access it over the internet, typically on a subscription basis. The SaaS agreement defines what the customer is getting, what the provider is responsible for, and what happens to the customer's data. These agreements are common across virtually every industry, and their terms deserve careful attention.

What This Contract Is

A SaaS agreement is a contract between a software provider and a customer that governs access to a cloud-based software platform on a subscription basis. The customer pays a recurring fee — typically monthly or annually — in exchange for the right to access and use the software. The provider hosts, maintains, and updates the software; the customer does not receive a copy of the underlying code. SaaS agreements typically address the scope of the subscription, the number of authorized users, service level commitments, data ownership and security, acceptable use, fees, renewal, and termination. Because the customer's data resides on the provider's infrastructure, data-related provisions are particularly important.

When It's Commonly Used

  • •A business is subscribing to a cloud-based software platform for operations, finance, HR, marketing, or customer management.
  • •A company is adopting a new enterprise software solution delivered as a hosted service.
  • •A startup is building its technology stack using third-party SaaS tools.
  • •A company is entering a multi-year enterprise software agreement with a major vendor.
  • •A business is evaluating a SaaS vendor's standard subscription terms before signing.
  • •A software company is establishing the standard terms for its own SaaS product.

How the Agreement Is Generally Structured

Subscription and Access Rights

Defines the scope of the subscription — the specific modules or features included, the number of authorized users, and any usage limitations.

Service Level Agreement (SLA)

Specifies the provider's uptime commitments, support response times, and the remedies available to the customer if the provider fails to meet those standards.

Data Ownership and Security

Addresses who owns the customer's data, how it is protected, what the provider's obligations are in the event of a security incident, and what happens to the data when the agreement ends.

Fees and Renewal

The subscription fee, billing cycle, price adjustment provisions, and automatic renewal terms.

Acceptable Use

Restrictions on how the customer may use the software, including prohibitions on reverse engineering, unauthorized access, and use for illegal purposes.

Intellectual Property

Confirms that the provider owns the software and that the customer receives only a limited right to access and use it. Addresses ownership of customer data and any configurations or customizations.

Confidentiality

Protects each party's non-public information, including the customer's data and the provider's proprietary technology.

Term and Termination

The duration of the subscription, renewal terms, and the circumstances under which either party may terminate — including what happens to the customer's data after termination.

Clauses Commonly Found in This Contract

Service Level Agreement

Defines the provider's uptime and performance commitments. Customers should examine whether the SLA covers the specific services they depend on and whether the remedies for SLA failures — typically service credits — are meaningful.

Limitation of Liability

Caps the provider's total liability to the customer. SaaS providers typically cap liability at fees paid in a recent period — often 12 months. Customers should evaluate whether this cap is adequate given the potential impact of a service outage or data loss.

Indemnification

Providers typically indemnify customers for IP infringement claims. Customers typically indemnify providers for claims arising from customer data and customer misuse of the platform.

Confidentiality

Protects the customer's data and the provider's proprietary technology. Customers should examine whether the confidentiality provisions are adequate given the sensitivity of the data they will store on the platform.

Consequential Damages

Most SaaS agreements exclude consequential damages — meaning the provider is not liable for lost profits, lost data, or business interruption losses even if caused by a service failure. Customers should understand the practical implications of this exclusion.

Termination for Convenience

Addresses whether the customer can exit the subscription before the end of the term and what fees apply. Annual subscriptions often do not allow early termination without paying the remaining fees.

Assignment

Addresses whether the customer may assign the subscription in connection with a merger or acquisition. Many SaaS agreements require the provider's consent for assignment.

Governing Law

Specifies which state's law governs the agreement and where disputes will be resolved.

What Stewart Law Looks For

  • ✓Whether the SLA covers the specific services the customer depends on and whether the uptime commitment is meaningful for the customer's use case.
  • ✓Whether the remedies for SLA failures — typically service credits — are proportionate to the impact of a service outage.
  • ✓Whether the limitation of liability cap is adequate given the potential impact of a service failure or data loss on the customer's business.
  • ✓Whether the data ownership provisions clearly establish that the customer owns its data and that the provider cannot use it for its own purposes.
  • ✓Whether the provider's data security obligations are clearly defined and whether the provider is required to notify the customer of a security incident.
  • ✓Whether the data return and deletion provisions are adequate — the customer should be able to export its data in a usable format before termination.
  • ✓Whether the automatic renewal provisions are clearly disclosed and whether the customer has adequate notice before the renewal date.
  • ✓Whether the acceptable use policy is reasonable and whether it could be used to suspend the customer's access for minor or technical violations.
  • ✓Whether the agreement addresses what happens to the customer's data if the provider is acquired or goes out of business.
  • ✓Whether price adjustment provisions allow the provider to increase fees unilaterally and on short notice.

Areas That May Deserve Closer Attention

  • ⚑A limitation of liability cap that is set at a nominal amount — such as one month of fees — that would provide no meaningful recourse for a significant service failure or data loss.
  • ⚑A broad exclusion of consequential damages that eliminates the customer's ability to recover lost profits or business interruption losses caused by a service outage.
  • ⚑SLA remedies that are capped at a small percentage of monthly fees, making them commercially insignificant.
  • ⚑Data ownership provisions that allow the provider to use customer data for its own purposes, including product improvement or marketing.
  • ⚑Automatic renewal provisions that extend the agreement for a full year unless the customer provides advance notice — often 30 to 90 days before the renewal date.
  • ⚑Acceptable use provisions that allow the provider to suspend access immediately and without notice for alleged violations.
  • ⚑Data return provisions that require the customer to request its data within a short window after termination, after which the data is deleted.
  • ⚑Security provisions that are vague or that do not require the provider to notify the customer of a data breach within a defined timeframe.

Party Perspectives

Customer

  • •Wants meaningful SLA commitments with proportionate remedies for failures.
  • •Seeks clear data ownership provisions and the right to export data at any time.
  • •Wants a liability cap that is adequate given the potential impact of a service failure.
  • •Prefers the ability to terminate for convenience without significant fees.
  • •Wants strong data security obligations and prompt breach notification.

SaaS Provider

  • •Wants a low liability cap — typically limited to fees paid in a recent period.
  • •Seeks broad exclusions of consequential damages.
  • •Prefers automatic renewal provisions to maintain recurring revenue.
  • •Wants the right to suspend access for non-payment or acceptable use violations.
  • •Seeks the right to modify the service and the agreement with reasonable notice.

Related Contract University Terms

When to Have an Attorney Review It

SaaS agreements presented by the provider are typically drafted in the provider's favor. Before signing a significant enterprise software agreement — particularly one involving sensitive data, a long-term commitment, or a high annual fee — it is worth having the agreement reviewed. Attorney review is especially valuable when the agreement involves data security obligations, significant limitation of liability provisions, or automatic renewal terms that could lock the customer into an extended commitment.

Frequently Asked Questions

Who owns my data in a SaaS agreement?

The customer typically owns its data, and the provider is granted a limited license to process it in order to deliver the service. However, some SaaS agreements include provisions that allow the provider to use customer data for product improvement, analytics, or other purposes. Customers should review the data ownership and use provisions carefully before signing.

What happens to my data when I cancel a SaaS subscription?

Most SaaS agreements include a data return and deletion provision that specifies how long the provider will retain customer data after termination and how the customer can export it. Customers should ensure they can export their data in a usable format before the subscription ends. Some agreements provide only a short window — often 30 to 90 days — after which the data is deleted.

What is an uptime SLA, and what remedies are available if it is not met?

An uptime SLA specifies the percentage of time the service will be available — typically expressed as a percentage such as 99.9%. If the provider fails to meet the uptime commitment, the customer is typically entitled to service credits — a reduction in future fees. Customers should evaluate whether the service credits are proportionate to the impact of a service outage on their business.

Can I negotiate a SaaS provider's standard terms?

For enterprise agreements, yes — many SaaS providers will negotiate their standard terms for significant customers. Key areas for negotiation typically include the limitation of liability cap, data security obligations, SLA remedies, and automatic renewal provisions. Smaller or self-service subscriptions are typically offered on a take-it-or-leave-it basis.

What should I look for in a SaaS agreement's security provisions?

Security provisions should specify the provider's obligations to protect customer data, including the security standards the provider follows, the provider's obligations in the event of a security incident, and the timeframe within which the provider must notify the customer of a breach. Customers who handle sensitive data — such as personal information, financial data, or health information — should pay particular attention to these provisions.

Have a Contract Using These Provisions?

Contract language operates as part of the agreement as a whole.

Contract Review by a Licensed Attorney — Starting at $150

Upload Your Contract & Get a Quote