Skip to content
Websites & online business

The parts of a SaaS agreement that decide what you actually bought

A SaaS agreement is not one document, and the parts that matter are rarely the parts that get negotiated. The order form gets attention because it has the price on it. The service level exhibit, the data terms and the exit clause get skimmed, and those are the three that decide what happens on the worst day of the relationship. This is what to read, in what order, and what each clause is actually promising.

8 min readPublished How we write these

The short version

  • Read the order form first: term, renewal date, notice window, quantity, unit price and uplift cap. It is the only page written for you rather than for everyone.
  • Service credits are almost always the sole and exclusive remedy for downtime, they are paid in service rather than money, and they are usually forfeited if you do not claim within a stated window.
  • "You own your data" settles very little. The operative terms are the licence the vendor takes back, the export format, and how long after termination export still works.
  • Cap the renewal uplift in the first contract. Once the headline discount is agreed there is nothing left to trade for it.

The agreement is a stack, and most of it is not in the file you were sent

A SaaS contract is rarely one document. There is an order form carrying the commercial terms, master subscription terms incorporated by reference — usually as a URL rather than an attachment — and then a set of exhibits: the service level agreement, a data processing agreement, a security schedule, an acceptable use policy, a support policy. Each has its own change mechanism. The ones the vendor can amend without asking you are the ones to read first.

Ask for the complete set as dated files before signature. A URL is not a record: if the master terms live at an address the vendor controls, the version you agreed to will not be the version you can produce in two years. The fix is one line saying the terms as at the effective date govern for the term, and that changes take effect at renewal.

Where the risk sits in the stack

A SaaS contract as delivered

The order form is the only part written for you. Everything below it is written for every customer at once, and the bottom two can usually be changed without your signature.

What an uptime number actually promises

Availability commitments are arithmetic, and the arithmetic is less generous than the number looks.

CommitmentDowntime allowed in a 30-day monthDowntime allowed in a year
99.5%3 hours 36 minutesabout 43 hours 48 minutes
99.9%43 minutes 12 secondsabout 8 hours 46 minutes
99.95%21 minutes 36 secondsabout 4 hours 23 minutes
99.99%4 minutes 19 secondsabout 52 minutes 34 seconds
Calculated on a 30-day month and a 365-day year. The step from 99.9% to 99.95% halves the budget, which is why it usually sits behind a higher price tier.

Then read the exclusions, because they define what the number is measured against. Scheduled maintenance is normally excluded, and where the agreement does not cap it, "scheduled" can absorb an unbounded number of hours. Emergency maintenance, third-party network failures, your own configuration, beta features and force majeure are usually excluded too. A 99.99% commitment measured only against total unavailability of one API is a weaker promise than 99.9% measured against the whole service.

  • What is measured. The whole service, or a named component? Login, API and the admin console frequently carry different targets, and some carry none.
  • Who measures it. Vendor telemetry is the default. Ask whether independent monitoring or your own synthetic checks are admissible evidence.
  • How maintenance is bounded. A monthly cap in hours, an advance notice period, and a window outside your operating hours.
  • What counts as down. Full unavailability only, or degraded performance and elevated error rates as well. Partial degradation is the common failure and the common exclusion.

Service credits are a discount, not a remedy

The standard structure is a ladder: miss the target and the customer receives a credit against future fees, steepening as availability falls. Google's Workspace SLA is a fair example of the shape — a 99.9% monthly commitment, credits paid as three, seven or fifteen additional days of service depending on how far the month fell short, a requirement that the customer open a support case within thirty days of becoming eligible, and wording making the credit the customer's "sole and exclusive remedy" for the failure.

Three consequences follow, and they hold for nearly every SLA you will be handed.

  1. Credits are claimed, not paid. There is a window, and an unclaimed credit is simply not honoured. This belongs in the incident runbook, because the engineer who notices the outage is not the person who reads the contract.
  2. Credits are denominated in service. A credit against future fees is worth nothing in the scenario where the outage is the reason you are leaving.
  3. Sole and exclusive means sole and exclusive. If an hour of downtime costs you more than a month of subscription fees, the SLA is not the clause that helps — and it may have just excluded the clause that would.

Data: ownership is the easy part

Almost every SaaS agreement now states that the customer owns its data. The sentence is close to free for the vendor to give and settles less than it appears to. What matters is the licence the vendor takes back, and what survives termination.

Four questions the ownership sentence does not answer

  1. Licence scope

    The vendor needs rights to host, transmit and display your data to run the service. Anything wider than "to provide the service" is a different bargain.

    Usually fine
  2. Aggregated and de-identified use

    This is where the licence widens, it frequently survives termination, and in some products the aggregate is the product.

    Often uncapped
  3. Model training

    Ask for it off by default, for the restriction to reach sub-processors, and for it to cover fine-tuning and evaluation rather than only initial training.

    A separate question
  4. Export during suspension

    Where suspension for non-payment also cuts off export, a routine billing dispute stops being about money.

    The whole relationship
Vendors routinely answer the second question no and the third yes, which is why they have to be asked separately. The fourth is the one that converts a billing dispute into a hostage negotiation.

SaaS agreement template

The full text, free to read and copy — subscription grant, service levels, customer data and ownership, security, term and termination, and the data return obligation written as an obligation rather than a courtesy.

Open

The exit clause you will read exactly once

Exit terms are negotiated at the point of least leverage, immediately after you have decided to buy, and used at the point of most stress. They are worth ten minutes now.

What an exit clause has to cover

  • A retrieval window after termination, stated in days, during which export still functions. Thirty days is common; ninety is obtainable.
  • A named export format and, better, a named mechanism — a documented API, a bulk export job, a published schema. "A commercially reasonable format" is not a format.
  • Whether the export includes everything or only the obvious tables: attachments, audit logs, prior versions, comments, configuration, metadata.
  • Deletion on request with written confirmation, and a stated backup expiry after which residual copies are gone.
  • Transition assistance at a defined day rate, so the vendor is obliged to help rather than merely free to quote.
  • A refund of prepaid fees where you terminate for the vendor's breach. Without it, a termination-for-cause right is decorative.

Then run the export once inside the first ninety days, while you still have an implementation team and the vendor's attention. An export you have never executed is a plan, not a capability.

Price: the year-one number is not the negotiation

Discounts are given on the first term and recovered at renewal. The clause to fix before signature is the ceiling on increases, because afterwards there is nothing left to trade for it.

  • Cap the uplift as the lesser of a fixed percentage and a named published inflation index. Name the index; "inflation" is not a series.
  • Cap it per renewal, not per year of the renewal. A three per cent cap applied once for each year of a three-year renewal is nine per cent, and that construction is now common enough to close off in the drafting.
  • Fix the unit price for additional seats, separately for the current term and the renewal term, or growth gets priced at list.
  • Check whether quantities can be reduced at renewal. Many agreements quietly prohibit it, which turns a fall in headcount into a stranded cost.

Read the renewal notice mechanics against your own calendar rather than the vendor's. Auto-renewal clauses covers how those windows work and what happens when one is missed; in enterprise SaaS the window sits in the order form and is measured backwards from a date nobody has diarised.

Liability, and why the cap is the wrong number to argue about

Vendor paper usually caps total liability at the fees paid in the twelve months before the claim. That is a normal opening position, and moving it to two or three times fees is a normal outcome. It is also not where the exposure is decided.

What decides exposure is which claims sit outside the cap. The categories that conventionally belong outside or above it are the vendor's intellectual property indemnity, breach of confidentiality, breach of the data protection obligations, fraud and wilful misconduct. Where a vendor will not put data breach fully outside, the usual landing zone is a supercap: a separate, higher ceiling for that category alone, expressed as a multiple of fees or a fixed sum.

A first pass in twenty minutes

  1. Order form: term, renewal date, notice window, quantity, unit price, uplift cap. Diarise the notice date before you file the contract anywhere.
  2. Search the master terms for "sole and exclusive", "aggregate", "de-identified", "train", "suspend" and "material". Those six strings locate most of what matters.
  3. Open the service level exhibit and read the exclusions before the uptime figure.
  4. Open the data processing agreement and check the sub-processor list, the objection right and the transfer mechanism. If there is no DPA and the vendor handles personal data, the gap is in your compliance as much as theirs — see data processing agreements.
  5. Find the post-termination retrieval window and the export format. If either is unstated, get both in writing before signature rather than after.

None of this needs a lawyer to begin. It needs four documents read in a deliberate order — order form, service levels, data terms, then the master terms — because the commercial page tells you what the risk is worth and the exhibits tell you whether the promise behind it is real. Competent vendors expect these questions and answer them quickly. A vendor that becomes evasive specifically about export and exit has told you something more useful than the answer would have been.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Is 99.9% uptime good enough?

It depends entirely on what it is measured against. 99.9% allows roughly 43 minutes of downtime in a 30-day month, but the exclusions decide whether real incidents count. Scheduled maintenance, degraded performance and third-party network failures are commonly excluded, so a headline figure with a broad exclusions list can permit far more disruption than the percentage suggests.

What happens if a vendor misses its SLA?

In most agreements the customer becomes eligible for a service credit against future fees, provided the customer claims it within a stated window. The credit is usually expressed as the sole and exclusive remedy, which means no separate damages claim for that downtime. Customers with real dependency should negotiate a right to terminate for repeated misses instead of a larger credit.

Does the customer own its data in a SaaS contract?

Nearly all modern agreements say so, and the statement is worth little on its own. Read the licence the vendor takes back, any carve-out for aggregated or de-identified data, whether customer data may be used to train models, and what the vendor may do after termination. Those four terms determine what ownership actually amounts to.

How long do I have to export data after cancelling?

Only as long as the contract says. Thirty days after termination is the common default and ninety is often available on request. Where nothing is stated, the vendor is under no clear obligation to keep the data accessible at all. Get the window, the format and the mechanism written into the agreement rather than relying on the current product behaviour.

Can a SaaS vendor raise the price at renewal?

Yes, unless the agreement caps it. The usual protection is a cap expressed as the lesser of a fixed percentage and a named inflation index, applied once per renewal rather than once for each year of a multi-year renewal. Fixing the unit price for additional seats matters as much, since unpriced growth is charged at list.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week