SaaS Agreement
A subscription agreement under which a customer accesses software hosted by the vendor on a recurring-fee basis, rather than installing software locally. Distinct from a software license in that the customer receives a service, not a license to a copy. Typical issues include uptime SLAs, data processing addenda, exit and data-portability provisions, and regulatory compliance.
A SaaS (software-as-a-service) agreement is a subscription contract under which a customer accesses software hosted on the vendor's infrastructure for a recurring fee, rather than installing a copy of the software locally. SaaS agreements are services contracts, not licenses to a copy of software. The legal and practical implications differ materially from traditional software licensing.
Uptime and service level agreements
SLAs typically express uptime as a percentage (commonly 99.9% or 99.95%) measured monthly. The remedy for SLA breach is almost always a service credit, a percentage of the monthly fee, rather than monetary damages or termination. Customers should negotiate (1) the measurement method (e.g., excluding scheduled maintenance windows); (2) the cap on credits; (3) the trigger threshold for termination rights; and (4) the cumulative credit ceiling that triggers a refund versus service-credit posture.
Data processing and security
Where the SaaS vendor processes personal data on the customer's behalf, the customer is the "controller" and the vendor is the "processor" under the TDPSA. The vendor agreement must include a data processing addendum (DPA) addressing the requirements of § 541.104, including the purpose and duration of processing, the type of personal data, the rights and obligations of the controller, deletion or return of data on termination, and security measures. HIPAA-regulated data requires a Business Associate Agreement; PCI-regulated data requires PCI DSS attestation provisions.
Termination and data portability
Exit provisions are critical. Standard practice: on termination, the vendor must provide the customer's data in a usable export format (typically CSV, JSON, or the vendor's standard API export) for a defined retrieval window (typically 30-90 days), after which the vendor deletes the customer's data and certifies destruction. Without explicit data-portability provisions, the customer may face vendor lock-in or, worse, data loss on contract expiration.
Indemnification and limitation of liability
Most SaaS agreements include vendor IP indemnification (against third-party claims that the service infringes IP rights), customer indemnification (against claims arising from customer data or use), and a mutual limitation of liability typically capped at fees paid in the preceding 12 months. Customers handling regulated data should negotiate carve-outs from the liability cap for data-breach indemnification, gross negligence, willful misconduct, and IP indemnification.
SaaS contracts are often presented as non-negotiable click-through "online order forms" tied to the vendor's standard terms. Material customers should resist this posture and negotiate the DPA, security exhibit, SLA, indemnification, and liability cap as a matter of routine. The cost of a one-time negotiation is far smaller than the cost of a downstream breach where the contract terms allocate the consequences against the customer.