SaaS Agreements for Providers and Their Customers
When you deliver software as a service, a product sale becomes an ongoing relationship. You host the application, control the infrastructure, release updates, process customer data, and keep the service available. Your contract should describe those operations with enough precision that both sides can price the deal and manage it after signing.
A strong SaaS agreement grants access to software and covers the order form, service description, support process, security commitments, data terms, payment rules, remedies, and exit plan. Each promise should match what your product and team can deliver.
The Contract Stack
Many providers use a master SaaS agreement with one or more supporting documents. The set may include an order form, service-level agreement, acceptable use policy, security schedule, data processing addendum, and support policy.
You should identify every part of the agreement, then state which one controls when terms conflict. An order form may control commercial terms, while a data processing addendum may govern the handling of personal data. An order-of-precedence clause resolves conflicts when two reasonable provisions require different results.
You should define the service, customer, authorized users, documentation, customer data, subscription term, and usage limits. You should also state how users accept the agreement and how you may update online terms. Your acceptance process should preserve the version you presented to the user and the evidence of assent. The article on website terms and online contract formation explains that process in detail.
The Service Definition and Rules for Change
You should describe the access right you grant during the subscription. Your agreement should address authorized users, account credentials, permitted business use, geographic or affiliate limits, technical documentation, and any third-party components. You should reserve ownership of the service, documentation, software, and related intellectual property.
You should also explain the customer's responsibilities. Those terms may cover account security, lawful instructions, required systems, authorized data, user conduct, and compliance with the acceptable use policy.
As you release updates, you may add or remove features, revise interfaces, or replace dependencies. Your agreement should state when you may make those changes and what notice you will provide before a material reduction in core functionality. If customers build around an application programming interface, you should address version support and deprecation. A general right to modify the service preserves flexibility, while a defined notice process protects the customer's implementation.
An SLA Based on Measurable Events
You should express an availability promise through a formula. A commitment of 99.9% allows about 43 minutes of unavailability in a 30-day month. A commitment of 99.99% allows about four minutes. Those figures mean little until the agreement defines the measurement.
Your service-level agreement should identify the service components covered by the commitment, the measurement source and monthly denominator, and the event that starts and ends an outage. It should also address scheduled maintenance and other permitted exclusions, the process and deadline for requesting a credit, the credit formula and any monthly limit, and the response to repeated failures.
You should choose credit levels that fit the subscription price and the effect of an outage. If service credits provide the customer's exclusive remedy for an availability failure, you should say so narrowly. A broad exclusive-remedy clause may unintentionally cover a security incident, confidentiality breach, or other claim outside the availability risk priced into the credit.
Repeated failures may justify a termination right. Your agreement should define the trigger by reference to specific service-level failures during a stated period. That approach provides both sides with an objective record and reduces disputes over whether performance became chronic.
Fees, Usage, Renewal, and Suspension
Your order form should state subscription fees, billing frequency, payment dates, taxes, usage allowances, and any overage calculation. You should define each billable unit so the customer can reproduce the charge. Your agreement should address disputed invoices, late payment, restoration after suspension, and the treatment of prepaid fees when the agreement ends.
For a negotiated business agreement, you should state the initial term, renewal term, price-change process, and deadline for giving nonrenewal notice. You should provide a practical way for the customer to deliver that notice and identify when it becomes effective.
Consumer subscriptions require a separate compliance analysis. The federal Restore Online Shoppers' Confidence Act requires clear and conspicuous disclosure of all material terms before obtaining billing information, express informed consent before charging the consumer, and simple mechanisms to stop recurring charges in covered online consumer transactions. See 15 U.S.C. § 8403.
California's Automatic Renewal Law imposes additional duties when you offer automatic renewal or continuous service to California consumers. Current law addresses conspicuous disclosures, affirmative consent, retainable acknowledgments, cancellation methods, renewal and price-change notices, annual reminders, and consent records. Amendments enacted in 2024 apply to contracts entered into, amended, or extended on or after July 1, 2025. See California Business and Professions Code §§ 17601 and 17602. The statute defines a consumer as an individual who seeks or acquires goods, services, money, or credit by purchase or lease for personal, family, or household purposes. A business subscription may fall outside that definition even when an individual employee completes the purchase.
The Federal Trade Commission adopted broader negative-option amendments in 2024, but the Eighth Circuit vacated those amendments in July 2025. See Custom Communications, Inc. v. Federal Trade Commission, 142 F.4th 1060 (8th Cir. 2025). In March 2026, the FTC opened a new rulemaking inquiry and confirmed that the original rule currently covers only prenotification plans. See the FTC's 2026 Negative Option Rule notice. For an online consumer SaaS subscription, you should analyze ROSCA, applicable state autorenewal laws, and the FTC Act's prohibition against unfair or deceptive practices.
Data Categories and Data Rights
The single label "customer data" covers several categories that need different legal and operational treatment. You should define the data your service handles. Those definitions may separate content submitted by the customer or its users, account and contact information, billing records, support communications, service telemetry and usage metrics, deidentified or aggregated information, provider software and analytics, documentation, and feedback supplied by users.
The customer may retain its rights in submitted content while granting you a limited license to host, copy, transmit, and process that content to provide and secure the service. Your rights in account data and telemetry should fit your privacy notice, confidentiality duties, and applicable law. If you want to use customer content or personal data to train an artificial intelligence model, you should address that use in a specific term instead of relying on a general service license.
Your agreement should explain how the customer can export its data, the available format, the timing, and any fee. It should state how long export access continues after termination. Your deletion clause should account for backups, legal holds, fraud prevention, security logs, and records that law requires you to retain. You should keep retained data protected and identify when ordinary backup rotation will remove it.
The Data Processing Addendum
Privacy roles depend on the facts. A provider may handle some data on the customer's instructions, acting as a processor, and decide the purpose of other processing, acting as a controller. Your contract should describe those roles accurately.
Texas law requires a contract when a processor performs processing for a controller covered by the Texas Data Privacy and Security Act. The contract must address the processing instructions, nature and purpose, data type, duration, and each party's rights and obligations. It must also cover confidentiality, deletion or return, compliance information, assessments, and subprocessors. See Texas Business and Commerce Code § 541.104.
If the European Union's General Data Protection Regulation applies, Article 28 requires specified processor terms, including documented instructions, confidentiality, security, subprocessor controls, assistance, deletion or return, and audit information. See Regulation (EU) 2016/679, Article 28.
Your data processing addendum should also address international transfers, requests from data subjects, government demands, and conflicts with the main agreement. You should match each contractual promise to the systems, vendors, and personnel that perform the work.
Security Promises in the Contract
You should place material security commitments in the agreement or an incorporated security schedule. If you put those commitments on a changeable web page, you lose a reliable record of the controls promised for a particular subscription.
You should describe safeguards by reference to the service's risks and the data involved. The schedule may address encryption, access control, authentication, logging, vulnerability management, secure development, backups, business continuity, employee controls, and vendor oversight.
You should use security labels precisely. A SOC 2 report records an independent accountant's examination of controls under the AICPA's trust services criteria. ISO/IEC 27001 provides requirements for an information security management system and supports certification within a defined scope. You should promise a report or certification only when you can identify the covered service, period, and scope. The NIST Cybersecurity Framework 2.0 can also help you organize risk management without turning every framework statement into a contractual warranty.
Your agreement should state what assurance material customers receive, how often they receive it, and how they may use it. If you provide a penetration-test summary or audit report, you should protect sensitive findings while giving the customer meaningful evidence of your program.
Incident Notice and the Customer's Deadlines
You should define the events that trigger notice. A clause that triggers only on a "confirmed data breach" may delay the information your customer needs. You can require notice after discovery of a defined security incident affecting customer data, followed by updates as the investigation develops.
Texas law sets different deadlines for maintainers and owners. A person that maintains sensitive personal information it does not own must notify the owner or license holder immediately after discovering a breach. The owner generally must notify affected Texas residents without unreasonable delay and no later than 60 days after determining that a breach occurred. A breach affecting at least 250 Texas residents can also trigger notice to the Texas attorney general as soon as practicable and no later than 30 days after that determination. See Texas Business and Commerce Code § 521.053.
Other laws use different triggers. A business associate covered by HIPAA must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information. See 45 C.F.R. § 164.410. Under the GDPR, a processor must notify the controller without undue delay after becoming aware of a personal data breach, while the controller may face a 72-hour supervisory-authority deadline. See Regulation (EU) 2016/679, Article 33.
You should set a provider-to-customer deadline that leaves the customer time to investigate and meet the laws that apply to it. Your clause should require ongoing updates, preservation of evidence, reasonable cooperation, and a process for coordinating notices. You should allocate investigation and notification costs with the parties' roles and fault in mind.
Warranties, SLA Remedies, and Disclaimers
An express warranty may state that the service will materially conform to its documentation or that you will provide specified professional services in a professional manner. You should pair the warranty with a workable remedy, such as correction, re-performance, termination, or a refund for the affected period.
You should draft disclaimers to coexist with those promises. A broad disclaimer can undermine the commercial warranty that induced the sale. Your agreement should state any customer warranties as well, including its authority to provide customer data and direct your processing.
You should keep service-level remedies in the same risk structure. Credits can resolve measured availability failures. Security, confidentiality, data-processing, and intellectual-property obligations need remedies suited to those duties.
Liability Allocation
Liability caps should fit the individual SaaS deal. You should set the general cap by considering contract value, service criticality, data sensitivity, available insurance, and the losses each side can control. Your clause should define the fee period used in the calculation and whether all claims aggregate under one cap.
The parties may negotiate different treatment for confidentiality, data security, indemnity, infringement, payment obligations, gross negligence, or intentional misconduct. Some agreements use a separate higher cap for selected risks. Others leave a narrow category outside the cap. Your language should reflect the deal rather than an assumed market formula.
You should define excluded damages carefully. Labels such as direct, indirect, consequential, lost profits, and lost data can overlap depending on the facts and governing law. Your agreement should identify the categories the parties intend to exclude and coordinate those exclusions with the available remedies.
Indemnity as a Procedure
An intellectual-property indemnity should identify the claims covered and the provider's response options. The provider may agree to defend a third-party claim alleging that the authorized use of the service infringes specified rights. Exclusions may address customer modifications, combinations the provider did not supply, customer specifications, unauthorized use, or continued use after the provider offers a replacement.
You should state what happens when infringement prevents continued use. Possible remedies include obtaining a license, modifying or replacing the service, or terminating the affected subscription and refunding an agreed portion of prepaid fees.
A customer indemnity may cover third-party claims arising from customer content, unlawful instructions, or prohibited use. For every indemnity, you should address prompt notice, control of the defense, cooperation, settlement authority, and the effect of delayed notice. Your agreement should then state how the indemnity interacts with the liability cap and insurance requirements.
Suspension, Termination, and Exit
Suspension can protect the service during nonpayment, unlawful use, or an urgent security threat. Your agreement should define the trigger, scope, notice, cure opportunity, and restoration process. It should allow immediate action when delay would create material harm, while requiring prompt notice and efforts to limit the suspension.
Termination rights should cover material breach and any agreed cure period. You may also address repeated service-level failures, prolonged force majeure, regulatory restrictions, or termination for convenience. Your agreement should state the financial result of each termination ground, including prepaid fees, accrued charges, and outstanding usage.
You rely on exit terms after the relationship has deteriorated. Your agreement should specify the export method, assistance, timing, fees, deletion process, and survival of confidentiality, payment, liability, and dispute terms. Customers with critical workloads may also negotiate transition services, backups, source-code escrow, or other continuity measures. Source code alone may provide little continuity for a hosted service, so you should identify any infrastructure, build materials, credentials, and transition help the customer would also require.
Bankruptcy law can limit the termination and license terms you negotiate. Section 365(e) of the Bankruptcy Code limits certain provisions that terminate or modify a contract solely because of insolvency or a bankruptcy filing. Section 365(n) may let a licensee retain specified intellectual-property rights after rejection of an executory contract. See 11 U.S.C. § 365. In Mission Product Holdings, Inc. v. Tempnology, LLC, 587 U.S. 370 (2019), the Supreme Court held that rejection constitutes a breach and leaves in place rights that would survive a breach outside bankruptcy. A provider can stop operating a hosted service after rejection, so data portability and continuity planning protect the customer if that happens.
Matching the Agreement to the Service
Your SaaS agreement should describe the product you operate today and the changes you can support tomorrow. You should verify every operational promise with the people responsible for billing, infrastructure, security, privacy, support, and offboarding.
Specific terms reduce surprises during sales and provide both sides with a usable process when performance falls short. They also preserve the records a dispute will require. You should build the contract from the service outward and include contract review in the same release plan when the service changes.
Related practice area: Internet & eCommerce
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry