How to Draft a Software as a Service (SaaS) Agreement?
Introduction
Software businesses have changed the way companies use technology. Instead of purchasing software permanently and installing it on their own computers, businesses can now access software through the internet. This model is commonly known as Software as a Service (SaaS).
Examples include software used for:
Accounting;
Customer relationship management;
Human resources;
Project management;
Communication;
Data storage;
Marketing;
Business analytics.
In a SaaS arrangement, the customer generally does not purchase the software itself. Instead, the customer receives a right to access and use the software for a particular period, usually against a subscription fee.
Because the software is accessed online, a SaaS relationship involves several legal issues beyond ordinary software licensing.
For example, the parties may need to decide:
Who owns the software?
Who owns customer data?
How will personal data be protected?
What happens if the service stops working?
What support will the provider give?
What happens when the subscription ends?
Can the customer download its data?
What happens if there is a security breach?
A properly drafted SaaS Agreement addresses these questions before they become disputes.
What is a SaaS Agreement?
A SaaS Agreement is a legal contract between a software provider and a customer under which the provider gives the customer access to software or an online platform for an agreed period and subject to specified conditions. The provider generally:
Hosts the software.
Maintains the platform.
Provides access to authorised users.
Performs updates and maintenance.
Provides technical support.
Protects the platform and data according to the agreed standards.
The customer generally:
Pays subscription fees.
Uses the platform according to the agreement.
Maintains the confidentiality of login credentials.
Ensures authorised use.
Complies with applicable laws.
A SaaS Agreement therefore defines the relationship between the technology provider and its customer.
Why is a SaaS Agreement Important?
It Defines the Customer's Access Rights The agreement should clearly state what the customer is permitted to do with the software. This prevents customers from assuming that subscription automatically gives them ownership of the software.
It Protects the Software Provider The provider invests significant resources in developing and maintaining its platform. The agreement can protect source code, software architecture, algorithms, designs, trade secrets, documentation, trademarks. It can also restrict unauthorised copying, reverse engineering, resale, or misuse, subject to applicable law.
It Protects Customer Data Customers may upload important information to a SaaS platform. This could include employee information, customer records, financial information, business documents, contact information, personal data. The agreement should explain how this information will be handled.
It Establishes Payment Obligations The agreement should clearly state subscription fees, billing frequency, taxes, payment deadlines, renewal charges, late payment consequences, refund policy. This helps avoid billing disputes.
It Establishes Service Expectations A SaaS customer expects the software to remain available and functional. The agreement can establish service availability, maintenance periods, support response times, incident management, service credits. These terms are often contained in a Service Level Agreement (SLA).
What should a SaaS agreement cover?
A good SaaS Agreement should be drafted according to the nature of the software and the relationship between the parties. Important areas include:
Parties Identify the SaaS provider and customer.
Description of Services Explain exactly what software or services are being provided.
User Access Define who can access the platform and under what conditions.
Subscription Mention subscription duration, renewal, and applicable plans.
Fees Clearly state pricing and payment terms.
Data Define ownership, access, processing, security, and deletion of customer data.
Intellectual Property Clarify ownership of the software, customer content, modifications, and other intellectual property.
Security Set out appropriate technical and organisational security obligations.
Support Specify technical support and maintenance arrangements.
Termination Explain how the agreement can be terminated and what happens afterward.
Liability Define responsibility for losses, subject to applicable law.
Key clauses In A SaaS Agreement
Description of Services The agreement should clearly describe the SaaS product. It may include:
Software name.
Features.
Modules.
Hosting arrangement.
Integrations.
Included services.
Technical specifications.
If the provider offers different subscription plans, the applicable plan should be identified.
Grant of Access The agreement should explain the nature of the customer's right to use the software. For example, the provider may grant the customer a: limited, non-exclusive, non-transferable right to access and use the SaaS platform during the subscription period. This makes it clear that the customer receives access rather than ownership of the underlying software.
User Restriction The agreement should establish prohibited activities. Depending on the software, customers may be restricted from:
Copying the software.
Reselling access without permission.
Attempting to access source code.
Circumventing security controls.
Using the platform for unlawful purposes.
Sharing accounts beyond authorised limits.
The restrictions should be reasonable and consistent with applicable law.
Account Management The agreement should explain customer responsibilities relating to accounts. It may require the customer to:
Maintain accurate account information.
Keep passwords confidential.
Restrict access to authorised users.
Notify the provider of suspected unauthorised access.
For enterprise SaaS products, the agreement may also provide for administrator accounts and user management.
Subscription Term and Renewal The agreement should clearly state:
Initial subscription period.
Renewal period.
Automatic renewal, if applicable.
Renewal pricing.
Notice required for non-renewal.
For example: "The subscription shall automatically renew for successive one-year periods unless either party provides written notice of non-renewal." The customer should be given clear information regarding renewal obligations.
Pricing and Payment Terms
Payment provisions are among the most important parts of a SaaS Agreement. The agreement should specify:
Subscription Fees State whether fees are monthly, quarterly, annually or based on usage.
Usage-Based Charges Some SaaS products charge according to number of users, storage, transactions, API usage and computing resources. The pricing formula should be clear.
Taxes The agreement should clarify that applicable taxes will be charged according to law.
Late Payment The agreement may specify consequences for overdue payments, such as interest, suspension, termination after notice. Any such provision should be legally appropriate and commercially reasonable.
Data Protection and Security
Data protection is one of the most important issues in SaaS transactions. A provider may process personal data on behalf of its customers. Therefore, the agreement should clearly explain the responsibilities of each party.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a legal framework concerning processing of digital personal data. The Act provides for obligations relating to processing personal data and recognises rights of individuals concerning their personal data.
The SaaS Agreement should therefore consider:
Purpose of data processing.
Categories of data.
Security safeguards.
Data access.
Data breach procedures.
Data retention.
Data deletion.
Data return.
Use of subprocessors.
Customer instructions.
Data Breach The agreement should establish what happens if unauthorised access or a security incident occurs. It may specify:
Notification procedure.
Cooperation between parties.
Investigation.
Remedial measures.
Regulatory cooperation.
The exact obligations should be aligned with applicable law.
Intellectual Property Rights
Intellectual property is often the most valuable asset of a SaaS business. The agreement should clearly state that the provider retains ownership of its software, source code, platform, algorithms, documentation, trademarks, designs, proprietary technology. The customer generally receives a limited right to access and use the platform.
Customer Data: Customer data should be treated separately from the provider's intellectual property.
The agreement should clearly establish:
Who owns the data?
Who can process it?
For what purpose can it be used?
What happens to it after termination?
This distinction can prevent major disputes.
Service Levels and Customer Support
A SaaS Agreement should explain the level of service that the provider is expected to provide. A separate SLA may specify:
Uptime commitment.
Support hours.
Response time.
Resolution targets.
Planned maintenance.
Emergency support.
Service credits.
For example, different incidents may receive different response times:
Critical issue – immediate response.
High-priority issue – response within a specified period.
Normal issue – response within a longer period.
The agreement should also clarify that service levels may have reasonable exclusions, such as outages caused by events outside the provider's control.
Confidentiality and Non-Disclosure
A SaaS provider and customer may exchange sensitive business information during the relationship. The agreement should therefore contain confidentiality obligations covering:
Business information.
Technical information.
Pricing and commercial terms.
Customer information.
Security information.
Product roadmaps.
Trade secrets.
The clause should also explain when confidential information may be disclosed, such as where disclosure is required by law.
Warranties and Disclaimers
The SaaS Agreement should clearly explain what the provider promises regarding the software. Depending on the service, the provider may agree that:
The software will substantially perform as described.
The provider will provide agreed support.
The service will be maintained according to the applicable SLA.
The agreement may also contain reasonable disclaimers regarding interruptions caused by circumstances outside the provider's control.
Warranties should not be drafted so broadly that the provider unintentionally guarantees uninterrupted or error-free service.
Indemnity Clause
An indemnity clause determines when one party must protect the other against specified claims, losses, or liabilities. A SaaS Agreement may include indemnities relating to:
Intellectual property infringement.
Breach of confidentiality.
Unauthorised use of the platform.
Certain data protection violations.
Third-party claims.
The scope of indemnity should be clearly defined instead of using unnecessarily broad language.
Limitation of Liability
A SaaS provider should carefully consider how liability is allocated under the agreement. The contract may specify:
Maximum liability.
Types of recoverable losses.
Excluded indirect or consequential losses, where legally permissible.
Exceptions to the liability cap.
For example, the parties may agree that ordinary contractual liability is capped at a specified amount, while certain matters such as fraud, wilful misconduct, or other legally required exceptions are treated separately.
The clause should be drafted according to the nature and risk of the SaaS service.
Termination of a SaaS Agreement
The agreement should explain when either party can terminate the relationship. Termination may occur because of:
Material breach.
Non-payment.
Insolvency.
Repeated security violations.
Expiry of the subscription.
Other agreed contractual grounds.
The agreement should also specify whether the breaching party gets an opportunity to cure the breach before termination.
Data Portability and Deletion
A good SaaS Agreement should clearly answer: What happens to customer data when the subscription ends? The agreement may provide that the customer can export its data in a commonly usable format within a specified period.
After that period, the provider may delete the data, subject to:
Applicable law.
Legal retention requirements.
Backup systems.
Contractual obligations.
The agreement should explain the process rather than simply stating that data will be "deleted."
Force Majeure
SaaS businesses may experience disruptions caused by events beyond their reasonable control. A force majeure clause can address events such as:
Natural disasters.
War.
Government restrictions.
Major infrastructure failures.
Certain widespread cyber incidents.
Internet or telecommunications failures beyond reasonable control.
The clause should explain the consequences of such an event and whether the parties must provide notice.
Governing Law and Dispute Resolution
The agreement should specify which law governs the contract. For an Indian SaaS provider, the parties may choose Indian law, subject to the circumstances and applicable legal requirements. The agreement should also specify how disputes will be resolved. Possible mechanisms include negotiation, mediation, arbitration, courts.
If arbitration is selected, the agreement should clearly identify matters such as:
Seat of arbitration.
Number of arbitrators.
Appointment procedure.
Language.
Applicable arbitration law.
A vague dispute resolution clause can itself become the subject of a dispute.
Electronic execution of a SaaS Agreement
SaaS agreements are often accepted electronically through:
Online platforms.
Click-wrap agreements.
Electronic signatures.
Emails.
Digital contracting systems.
Section 10A of the Information Technology Act, 2000 recognises contracts formed through electronic means and provides that a contract cannot be treated as unenforceable merely because electronic records or electronic means were used in its formation.
Therefore, SaaS businesses should maintain appropriate records showing:
Terms presented to the customer.
Customer acceptance.
Date and time of acceptance.
Version of the agreement.
Identity or account details of the accepting party.
This can help establish what terms were accepted.
How Lead India can help you?
Drafting a SaaS Agreement requires an understanding of both technology and contract law. Our legal team can assist with:
Drafting customised SaaS Agreements.
Reviewing SaaS contracts.
Drafting Service Level Agreements.
Preparing data processing provisions.
Protecting software and intellectual property.
Drafting confidentiality provisions.
Reviewing indemnity and liability clauses.
Drafting termination and data-return provisions.
Advising on electronic contracts.
Reviewing customer and vendor SaaS arrangements.
Advising on Indian data protection requirements.
A customised agreement can help protect the SaaS provider while giving customers greater clarity regarding their rights and responsibilities.
Conclusion
A well-drafted SaaS Agreement clearly defines software access, payments, data protection, intellectual property, security, support, liability, termination, and data return. It should comply with applicable Indian laws, including the DPDP Act, 2023 and Information Technology Act, 2000. Clear terms help prevent disputes and protect both the SaaS provider and customer.
FAQs
1. What is a SaaS Agreement?
A SaaS Agreement is a contract between a software provider and customer that governs access to and use of online software services. It generally covers subscription, payment, data, security, intellectual property, support, liability, and termination.
2. Is a SaaS Agreement legally necessary?
While the exact documentation required depends on the arrangement, a written SaaS Agreement is strongly advisable because it clearly records the rights and obligations of both parties.
3. Who owns the software in a SaaS arrangement?
Usually, the SaaS provider retains ownership of its software and grants the customer a limited right to access and use it during the subscription period. The agreement should clearly state the ownership position.
4. Who owns customer data in a SaaS Agreement?
The agreement should clearly define ownership and permitted use of customer data. Customer data and the provider's underlying software should generally be treated as separate matters.
5. What happens to data after a SaaS subscription ends?
The agreement should specify whether the customer can export its data, how long it will remain available, and when it will be deleted, subject to applicable legal retention requirements.
6. What is an SLA in a SaaS Agreement?
A Service Level Agreement establishes service standards such as availability, support response times, maintenance procedures, and remedies such as service credits where applicable.


