How to Review a SaaS Agreement: Complete Guide
July 2026 · 8 min read
Software-as-a-Service (SaaS) agreements are among the most frequently reviewed contracts in modern legal practice. Nearly every business uses cloud software, and each subscription comes with terms that govern data ownership, service levels, liability, and termination rights. This guide covers everything attorneys need to check when reviewing a SaaS agreement.
What Makes SaaS Agreements Different
Unlike traditional software licenses where software is installed on-premise, SaaS agreements govern access to software hosted by the provider. This creates unique issues around data ownership, service availability, data security, and what happens to data when the relationship ends. The customer is effectively renting access to software and storing their data on someone else's servers.
The 14 Clauses Every SaaS Agreement Must Address
1. Service Level Agreement (SLA)
Does the contract specify uptime guarantees? What's the target (99.9%? 99.99%?)? Are there service credits for downtime? Is maintenance downtime excluded?
- Uptime commitment: 99.9% allows ~43 minutes/month of downtime. 99.99% allows only ~4 minutes. Know the difference.
- Service credits: Are they meaningful? A 5% credit for 8 hours of downtime may be far less than the actual business impact.
- Exclusions: Scheduled maintenance, force majeure, and customer-caused issues are typically excluded.
2. Data Ownership and Portability
Who owns the data the customer inputs into the SaaS platform? Can the customer export all their data? In what format?
- Ownership: The customer should retain ownership of all data they input. Watch for language granting the provider rights to customer data.
- Export: Is there a data export obligation? What format (CSV, JSON, XML)? Is it available during and after the term?
- Data deletion: Upon termination, is the provider required to delete customer data? What's the timeline?
3. Data Security and Breach Notification
- Security standards: Does the provider commit to specific standards (SOC 2, ISO 27001, HIPAA)?
- Breach notification: How quickly must the provider notify the customer of a data breach? 72 hours is common. Does the provider cover notification costs?
- Audit rights: Can the customer audit the provider's security? Are SOC 2 reports provided?
4. Data Processing and Privacy
- Processing purpose: The provider should process customer data only to provide the service. Watch for clauses allowing use for the provider's own purposes.
- Sub-processors: Does the provider use sub-processors? Is there a list? Can the customer object?
- GDPR/CCPA compliance: Does the agreement include a Data Processing Addendum (DPA)? Are international data transfers addressed?
5. Intellectual Property
- Platform IP: The provider retains ownership of the software. This is standard.
- Customer data: The customer retains ownership of their data.
- Feedback: Does the provider get rights to customer feedback or suggestions? Watch for broad feedback licenses.
- Custom configurations: If the customer builds custom workflows or integrations, who owns those?
6. Payment and Auto-Renewal
- Pricing: Is pricing fixed for the term? Are there annual increases (CPI, fixed percentage)?
- Auto-renewal: Does the contract auto-renew? What's the notice period to cancel? Some states require clear disclosure of auto-renewal terms.
- Price changes: Can the provider change pricing mid-term? Watch for clauses allowing unilateral price increases.
7. Termination and Data Return
- Termination for convenience: Can the customer terminate without cause? What's the notice period?
- Termination for cause: What constitutes material breach? Is there a cure period?
- Data transition: Upon termination, how long does the customer have to retrieve data? 30-90 days is standard.
- Transition assistance: Does the provider offer transition support? Is it included or extra cost?
8. Limitation of Liability
- Cap: Is the cap tied to fees paid in the preceding 12 months? This is standard but may be inadequate for data breach exposure.
- Carve-outs: What survives the cap? Data breach, confidentiality, and IP infringement typically survive.
- Data breach cap: Is there a separate (higher) cap for data breach liability? Many providers resist this.
9. Indemnification
- IP infringement: Does the provider indemnify against IP infringement claims? This is critical for SaaS.
- Data breach: Does the provider indemnify for losses from provider-caused breaches?
- Third-party claims: What's the scope of third-party claim coverage?
10. Confidentiality
- Mutual: Is confidentiality mutual? It should be.
- Duration: 3-5 years post-termination is standard.
- Definition: Is the definition broad enough to cover all sensitive information?
11. Usage Limits and Overages
- User limits: Are there seat limits? What happens if exceeded?
- Volume limits: Are there API call limits, storage limits, or bandwidth limits?
- Overage pricing: How are overages priced? Is it transparent?
12. Compliance and Regulatory
- Industry-specific: If the customer is in a regulated industry (healthcare, finance), does the SaaS meet compliance requirements?
- Audit: Does the provider undergo regular compliance audits? Are results available?
- Change in compliance: What happens if the provider loses a compliance certification?
13. Service Changes and Discontinuation
- Feature changes: Can the provider change features? What notice is required?
- Discontinuation: Can the provider discontinue the service entirely? What notice and transition is provided?
- Material changes: Can the customer terminate if material changes are made?
14. Governing Law and Dispute Resolution
- Governing law: Which jurisdiction governs?
- Arbitration: Is arbitration required? What are the rules and venue?
- Class action waivers: Are class actions waived?
SaaS Agreement Red Flags
- Unilateral price increases: Provider can raise prices mid-term.
- No data export: No obligation to return customer data in usable format.
- Broad data usage rights: Provider can use customer data for its own purposes.
- No SLA: No uptime commitment or remedies for downtime.
- Automatic renewal without notice: May be unenforceable in some states.
- Low liability cap with no breach carve-out: Inadequate protection for data incidents.
- Feature removal rights: Provider can remove features without notice or remedy.
How AI Helps with SaaS Agreement Review
Checking all 14 categories on every SaaS agreement is time-consuming. AI tools like ContractPeer can analyze SaaS agreements in seconds, flagging these issues automatically with severity ratings and recommendations.
This guide is for informational purposes only and does not constitute legal advice. SaaS agreements vary significantly. Always have a qualified attorney review contracts before signing.