top of page

What Should a SaaS Agreement Include? Key Clauses for SaaS and Software Companies

  • Oct 24, 2024
  • 11 min read

A SaaS agreement does more than give a customer permission to use software.

It establishes the legal and commercial framework for the relationship between the software provider and its customer.



That framework can determine how the software may be used, how the provider gets paid, who owns intellectual property, how customer data is handled, what service commitments apply, how liability is allocated and what happens when the relationship ends.


For growing SaaS, software and technology companies, these agreements can become particularly important as customers become larger, procurement processes become more sophisticated and contractual requirements become more demanding.

There is no universal SaaS agreement that works for every company.


The appropriate provisions depend on the product, customer base, pricing structure, services being provided, data environment and overall risk profile of the business.


However, there are several areas that SaaS companies should generally consider when developing or reviewing their customer agreements.


What Is a SaaS Agreement?


A Software-as-a-Service agreement governs a customer's access to software that is typically hosted and made available remotely by the provider.


Unlike a traditional software licence where software may be installed locally, a SaaS customer generally receives a contractual right to access and use the provider's platform during a defined subscription period.


A SaaS agreement may be structured as a standalone contract or form part of a broader contractual framework involving documents such as:

  • a Master Services Agreement;

  • an order form;

  • a Statement of Work;

  • a Service Level Agreement;

  • a data processing agreement;

  • security documentation; and

  • other product-specific or service-specific terms.


The right structure depends largely on how the company sells its product.


A relatively standardized SaaS business may operate efficiently with one primary agreement and an order form.


A company providing enterprise software, implementation and professional services may need a more modular structure.


1. Description of the SaaS Services


The agreement should clearly establish what the provider is actually offering.

This sounds straightforward, but ambiguity around scope is one of the easiest ways for expectations to diverge.


The agreement may need to distinguish between:

  • access to the software platform;

  • particular modules or functionality;

  • implementation;

  • configuration;

  • integrations;

  • training;

  • customer support;

  • professional services; and

  • separately purchased services.


The contractual description should correspond with the way the sales team describes the product.


If the contract promises something materially different from what the business intends to deliver, disputes can arise before more complicated legal provisions even become relevant.


2. Subscription Rights and Permitted Use


A SaaS agreement should generally establish what rights the customer receives.


This may include:

  • who may access the platform;

  • the number or category of authorized users;

  • geographic or organizational restrictions;

  • whether affiliates may use the service;

  • applicable usage limits;

  • account responsibilities; and

  • restrictions on copying, reverse engineering, reselling or otherwise misusing the software.


These provisions are particularly important where the company's pricing model is connected to users, transactions, storage, locations or another usage metric.


The agreement should support the economics of the subscription model rather than unintentionally permitting broader use than the customer purchased.


3. Customer Responsibilities


SaaS contracts frequently focus heavily on the provider's obligations.


The customer's responsibilities can be equally important.


Depending on the service, these may include obligations relating to:

  • account security;

  • authorized users;

  • accurate information;

  • appropriate use of the service;

  • customer systems and connectivity;

  • customer-provided data;

  • cooperation during implementation; and

  • compliance with applicable laws.


Where the provider's ability to perform depends on customer cooperation, the contract should clearly establish that dependency.


4. Fees, Invoicing and Payment


The agreement should align with the actual commercial arrangement.


Important provisions may include:

  • subscription fees;

  • implementation fees;

  • usage-based fees;

  • minimum commitments;

  • invoicing frequency;

  • payment deadlines;

  • applicable taxes;

  • disputed invoices;

  • late payments;

  • increases in fees; and

  • consequences of non-payment.


A mismatch between the contract and the pricing model can create unnecessary billing disputes.


Companies should also consider whether commercial details belong in the main agreement or an order form that can be updated for each customer without renegotiating the entire legal framework.


5. Subscription Term and Renewal


SaaS businesses frequently rely on recurring revenue.


The agreement should therefore clearly establish:

  • the initial subscription term;

  • whether the agreement renews automatically;

  • the length of renewal periods;

  • notice requirements for non-renewal;

  • whether pricing may change at renewal; and

  • what happens if the customer continues using the service after the term expires.


These provisions should align with the company's sales process and revenue model.

Renewal language should not be treated as boilerplate.


6. Implementation and Professional Services


Many SaaS companies provide more than access to software.


Implementation, migration, configuration, integrations, training and consulting may all form part of the customer relationship.


Where these services are material, the parties may use a Statement of Work to define:

  • deliverables;

  • milestones;

  • responsibilities;

  • assumptions;

  • timelines;

  • fees; and

  • acceptance requirements.


The agreements should also establish a process for dealing with changes in scope.

Without clear change-control provisions, additional customer requests can gradually become obligations without corresponding changes to pricing or timelines.


7. Customer Data


Customer data is often one of the most important components of a SaaS relationship.

The agreement should clearly distinguish between ownership of the provider's technology and ownership of customer-provided data.


Depending on the service, provisions may address:

  • customer ownership of data;

  • the provider's right to process that data;

  • permitted uses;

  • security;

  • access;

  • backups;

  • retention;

  • deletion;

  • return of data following termination; and

  • aggregated or de-identified information.


The contract should reflect what actually happens technically.


A contractual right to use data should not be broader than the business requires simply because similar wording appeared in another company's agreement.


8. Privacy and Data Protection


Where personal information is involved, privacy obligations may require separate consideration from general customer-data provisions.


The appropriate contractual framework will depend on several factors, including:

  • what information is collected;

  • whose information is processed;

  • where the provider and customer operate;

  • where data is stored;

  • whether third-party service providers are used; and

  • which privacy laws apply.


Enterprise customers may also request data processing agreements or additional privacy schedules.


These obligations should be coordinated with the company's actual privacy practices rather than addressed solely through contract language.


9. Cybersecurity


Cybersecurity obligations have become an increasingly significant part of SaaS contracting.


Enterprise customers may request commitments relating to matters such as:

  • technical and organizational safeguards;

  • access controls;

  • encryption;

  • vulnerability management;

  • incident notification;

  • backups;

  • business continuity;

  • disaster recovery;

  • security testing;

  • certifications; and

  • subcontractors or subprocessors.


One of the most important considerations is whether the company can actually comply with the commitments being requested.


A provider should be cautious about agreeing to broad security warranties that exceed its real-world security environment.


Contract language should reflect operational capability.


10. Service Levels


A Service Level Agreement, or SLA, may establish measurable commitments concerning service availability or support.


Depending on the product, an SLA may address:

  • uptime;

  • how availability is calculated;

  • scheduled maintenance;

  • excluded downtime;

  • support response times;

  • severity levels;

  • service credits; and

  • remedies for repeated failures.


The precise wording matters.


A commitment to "99.9% availability" does not answer important questions such as how downtime is measured, what events are excluded and what happens if the target is missed.


SLA obligations should be designed around service levels the provider can realistically maintain.


11. Intellectual Property Ownership


Intellectual property provisions are fundamental to a SaaS agreement.


The provider should generally preserve ownership of its underlying software, technology and other proprietary materials.


However, modern SaaS relationships can involve several additional categories of IP, including:

  • customer materials;

  • configurations;

  • integrations;

  • documentation;

  • custom developments;

  • professional-services deliverables;

  • suggestions and feedback; and

  • improvements to the platform.


The agreement should clearly distinguish these categories rather than relying on a single broadly worded ownership clause.


This becomes especially important where the provider performs custom work for larger customers.


12. Artificial Intelligence


SaaS companies incorporating artificial intelligence into their products may need additional contractual provisions.


Depending on the technology, issues may include:

  • rights in customer inputs;

  • rights in generated outputs;

  • whether inputs may be used for model training;

  • use of third-party AI models;

  • confidentiality;

  • intellectual property;

  • accuracy;

  • prohibited uses;

  • customer review of generated content; and

  • responsibility for decisions based on AI outputs.


Existing SaaS agreements may not adequately address these questions if AI functionality was added after the contract was originally prepared.


This is one reason growing companies should periodically consider whether they need to modernize their SaaS and IT contracts.


13. Confidentiality


SaaS relationships frequently involve access to confidential business information.


A confidentiality provision may establish:

  • what constitutes confidential information;

  • permitted uses;

  • disclosure restrictions;

  • permitted recipients;

  • required safeguards;

  • legal disclosure exceptions; and

  • how long confidentiality obligations continue.


Where customer information is particularly sensitive, confidentiality provisions should also be coordinated with security and data-protection obligations.


14. Warranties


Warranties define certain promises concerning the service.


Depending on the transaction, warranties may address matters such as:

  • authority to enter into the agreement;

  • conformity with documentation;

  • professional performance of services;

  • compliance with certain laws; and

  • intellectual property.


Providers should be cautious about making absolute promises concerning uninterrupted, error-free or completely secure software.


The warranty structure should correspond with the actual product and service commitments.


15. Disclaimers


A SaaS agreement often also contains disclaimers addressing matters outside the provider's reasonable control.


Depending on the product, this may include:

  • third-party services;

  • customer systems;

  • internet connectivity;

  • particular business results;

  • uninterrupted operation;

  • errors;

  • external integrations; and

  • information generated or processed through the platform.


The appropriate disclaimer language will depend on the product and applicable law.


16. Indemnification


Indemnification provisions determine when one party may be required to protect the other against specified third-party claims.


In SaaS agreements, negotiations frequently involve claims relating to:

  • intellectual property infringement;

  • customer content;

  • misuse of the platform;

  • privacy or data issues; and

  • violations of applicable laws.


Indemnities can create significant exposure.


They should therefore be reviewed together with the limitation-of-liability provisions rather than treated as standalone boilerplate.


17. Limitation of Liability


Limitation of liability is one of the most heavily negotiated provisions in many SaaS agreements.


A limitation-of-liability clause may address:

  • the overall monetary cap on liability;

  • exclusion of indirect or consequential damages;

  • special caps for certain categories of claims;

  • claims excluded from the general cap; and

  • liabilities that cannot legally be restricted.


A customer may seek unlimited liability for particular risks.


The provider may seek a cap connected to fees paid under the agreement.

There is no single correct structure.


The appropriate position depends on the value of the contract, the nature of the software, insurance coverage, the parties' bargaining power and the risks involved.


For SaaS companies negotiating recurring enterprise agreements, these positions should ideally be established before each new negotiation begins.


18. Suspension Rights


A SaaS provider may need the ability to suspend access to its platform in certain circumstances.


These may include:

  • non-payment;

  • security threats;

  • unlawful activity;

  • prohibited use;

  • risk to other customers or systems; and

  • material breaches of the agreement.


Suspension rights should be drafted carefully so the provider can protect its platform without creating unnecessarily broad or commercially unreasonable discretion.


19. Termination


The agreement should clearly establish when either party may terminate the relationship.


This commonly includes termination for material breach.


The parties may also negotiate:

  • cure periods;

  • termination for insolvency;

  • termination for convenience;

  • customer-specific exit rights; and

  • termination following repeated service failures.


Termination provisions can materially affect the value of recurring revenue.


For that reason, SaaS companies should be particularly cautious about accepting broad customer termination-for-convenience rights without understanding the commercial consequences.


20. What Happens After Termination?


A SaaS contract should not stop at the point of termination.


The agreement may also need to address:

  • unpaid fees;

  • customer access;

  • data export;

  • data deletion;

  • transition services;

  • continuing confidentiality obligations;

  • intellectual property provisions; and

  • other clauses that survive termination.


For some customers, exit and data-transition rights can become significant procurement issues.


21. Third-Party Services and Integrations


Modern SaaS products frequently depend on third-party platforms, APIs, hosting providers or integrations.


The contract should consider whether the provider is taking responsibility for systems it does not control.


Where appropriate, the agreement may distinguish between the provider's own services and third-party functionality.


22. Assignment and Change of Control


Assignment provisions can become particularly important when a SaaS company raises capital, restructures or is acquired.


A provision requiring customer consent to any assignment can create complications during a future transaction.


Companies should therefore consider assignment and change-of-control provisions with their longer-term corporate strategy in mind rather than treating them as insignificant boilerplate.


23. Governing Law and Dispute Resolution


The agreement should establish the governing law and the mechanism for resolving disputes.


For companies selling across multiple jurisdictions, customers may request their own governing law.


Whether that request should be accepted will depend on the circumstances and the significance of the transaction.


Does Every SaaS Agreement Need All of These Clauses?


No. A SaaS agreement should be proportionate to the business and the transaction.

A startup selling a standardized subscription to small businesses does not necessarily need the same contracting framework as an established software company negotiating multi-year enterprise agreements with banks, hospitals or multinational organizations.


More clauses do not necessarily produce a better contract.


The goal is to identify the legal and commercial issues that actually matter to the business.


Should SaaS Companies Use an MSA, Order Form and SOW?


For some SaaS companies, separating the contractual documents can create a more scalable contracting process.


One common structure is:

Master Services Agreement → Order Form → Statement of Work → Service Level Agreement


The MSA establishes the overarching legal framework.


The order form captures customer-specific commercial terms.


The SOW governs implementation or professional services where required.


The SLA establishes applicable service commitments.


This structure allows the company to sell additional products or services without renegotiating the entire contract each time.


However, the documents must clearly establish their hierarchy and interaction.


A modular structure that contains conflicting provisions can create more uncertainty rather than less.


When Should a SaaS Company Have Its Agreement Reviewed?


A SaaS company should consider reviewing its agreement when there has been a material change in its:

  • product;

  • services;

  • pricing;

  • customer base;

  • sales model;

  • implementation process;

  • data practices;

  • security environment;

  • use of AI;

  • geographic markets; or

  • enterprise contracting requirements.


Companies experiencing repeated customer redlines may also benefit from reviewing whether the standard agreement continues to reflect commercially realistic positions.

For businesses that have significantly evolved since their agreements were first prepared, a broader SaaS contract modernization project may be appropriate.


SaaS Agreement Lawyers for Technology Companies


Delta Law advises SaaS, software and technology companies on the commercial contracts that support their businesses.


Our work includes drafting, reviewing and negotiating SaaS agreements, Master Services Agreements, software licensing agreements, Statements of Work, Service Level Agreements and other technology contracts.


For companies negotiating customer and vendor contracts on an ongoing basis, Delta Law also provides ongoing legal support designed to support recurring commercial contracting needs.


Need Help With a SaaS Agreement?


Whether you are preparing your first SaaS agreement, replacing an agreement your business has outgrown or negotiating an enterprise customer's contract, the appropriate legal framework should reflect how your technology business actually operates.


Book a consultation with Delta Law to discuss your SaaS or software agreements.

Frequently Asked Questions About SaaS Agreements

What is another name for a SaaS agreement?

Depending on the business and transaction, SaaS terms may appear in a SaaS Agreement, Master Services Agreement, Cloud Services Agreement, Subscription Agreement or Software Services Agreement. The title matters less than whether the agreement accurately governs the service being provided.


What is the difference between a SaaS agreement and a software licence agreement?

A traditional software licence commonly grants rights to install or use software, while SaaS generally involves remote access to provider-hosted software. The distinction can affect provisions concerning access rights, hosting, security, data and service availability.


What is the difference between an MSA and a SaaS agreement?

An MSA establishes the overarching contractual framework between the parties.

A SaaS agreement specifically governs access to and use of SaaS services. For some businesses, the SaaS provisions are contained directly within the MSA rather than in a separate agreement.


Does a SaaS agreement need an SLA?

Not every SaaS agreement requires a separate SLA. Whether one is appropriate depends on the service being offered and the customer's requirements. Enterprise customers frequently request measurable commitments relating to availability, support and response times.


Who owns customer data in a SaaS agreement?

That depends on the contract, but SaaS agreements commonly preserve the customer's ownership of customer-provided data while giving the provider limited rights to process that data for purposes connected with providing the service.

The wording should reflect the company's actual data practices.


Should a SaaS agreement address AI?

If artificial intelligence functionality forms part of the product or service, the agreement should be reviewed to determine whether provisions concerning inputs, outputs, training rights, third-party models, intellectual property, confidentiality and acceptable use are required.


Can a lawyer review an existing SaaS agreement?

Yes. A SaaS lawyer can review an existing contract, identify areas of legal or commercial concern and determine whether amendments are sufficient or whether the agreement should be more substantially modernized.


bottom of page