COMMERCIAL · AHSAN MIAN

What to actually negotiate in a SaaS agreement

AUGUST 5, 2026 · 7 MIN READ · AHSAN MIAN

Most SaaS negotiations spend their energy on price and their attention on the wrong clauses. Eight terms decide who carries the risk when something goes wrong, and price is not one of them.

1. The liability cap, and what escapes it

Almost every SaaS agreement caps liability at fees paid in the preceding twelve months. The number matters less than the carve-outs. Standard exclusions from the cap are confidentiality breaches, indemnity obligations, and IP infringement. The two that get fought over are data breach and gross negligence.

If you are the customer and the vendor holds your personal information, an uncapped or super-capped data breach exposure is worth more than a discount on the subscription. If you are the vendor, a super-cap at two or three times annual fees is a common landing point and is easier to defend to your insurer than an unlimited one.

2. The IP indemnity

The vendor should indemnify the customer if the software infringes someone else's intellectual property, because the customer has no way to assess that risk. Watch for three limitations: whether the indemnity covers only patents or also copyright and trade secrets, whether it survives if the customer modifies or combines the software, and what the vendor's remedies are. A clause letting the vendor cure by "procuring the right to continue, replacing the software, or terminating and refunding" sounds fair until you realize option three leaves the customer with no product.

3. Data: ownership, use and getting it back

Say plainly that the customer owns its data, and be specific about what the vendor may do with it. Aggregated and anonymized use for product improvement is common and usually acceptable, but "improve our services" without qualification can swallow the clause. If AI training is contemplated, it needs to be addressed directly rather than left to inference.

The exit provisions are worth more than the entry ones. Everyone negotiates onboarding; almost nobody negotiates how they get their data out.

Ask for a defined export format, a defined window after termination during which the data remains retrievable, and a deletion obligation with confirmation. Without these, the practical cost of leaving a vendor can exceed the cost of staying with a bad one.

4. Privacy and sub-processors

If personal information is involved, a data processing agreement is not optional. Under Canadian privacy law the customer remains accountable for personal information it transfers to a service provider, which means the customer needs contractual assurance of comparable protection. Get the sub-processor list, a notice obligation before it changes, security commitments that are specific rather than "industry standard," breach notification within a defined number of hours, and clarity on where the data is stored and processed.

5. Service levels that mean something

An uptime commitment with a service credit as the sole remedy is not a service level, it is a small discount. Look at how uptime is measured, what counts as excluded downtime, whether scheduled maintenance is carved out entirely, and whether repeated failures give a termination right. For a system the business genuinely depends on, the termination right matters more than the credit.

6. Term, renewal and price increases

Auto-renewal is standard. The negotiable parts are the notice period to prevent renewal, whether that notice can be given by email to a named contact rather than by registered mail, and whether renewal pricing is capped. An uncapped renewal on a system with high switching costs is the vendor's strongest commercial position and the customer's weakest.

7. Termination for convenience

Customers ask for it; vendors resist it, correctly, because it undermines the revenue predictability the subscription model exists to create. A workable middle is termination for convenience at the end of a term with adequate notice, plus termination for cause on defined material breach with a cure period, plus a termination right tied to repeated service level failure.

8. Assignment and change of control

Both sides should be able to assign to a purchaser of the business, but a customer may reasonably want the right to terminate if the vendor is acquired by a competitor. On the vendor side, a broad customer consent right on change of control can become an obstacle in your own exit, when every customer contract needs a signature before closing.

A practical sequence. On the customer side, decide which of these eight you will not concede before the call, and trade the rest. On the vendor side, build the positions into a playbook once, with the fallbacks pre-approved, so your sales team can negotiate confidently without routing every deal through counsel. That is exactly the work a fractional General Counsel seat does in the first month.

Negotiating SaaS agreements regularly?

Fifteen minutes, no pitch. We will tell you which seats your company needs filled now, which can wait, and what it costs.

☕ Book a 15-min virtual coffee

This article is general information, not legal advice, and does not create a solicitor-client relationship. The law changes and its application depends on your circumstances. Speak to a lawyer about your situation.