SaaS Subscription Agreement: Buyer's Guide (2026)
A SaaS subscription agreement governs your data, liability, and exit rights. Learn what vendor standard clauses say vs. what to push for — before you sign.
Generate a master services agreement (msa) in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Is a SaaS Subscription Agreement?
A SaaS subscription agreement is a legally binding contract governing a customer's access to cloud-hosted software. It defines the license scope, subscription pricing, uptime commitments, data ownership, liability limits, and exit rights for both parties. Vendors draft the first version, which means the default terms protect the vendor — not you.
The distinction from a traditional software license matters: a SaaS agreement grants access rights only. Those rights end the moment the subscription ends. The customer can never install, copy, or retain the software after termination. Everything — pricing, uptime, data rights, exit terms, and AI training permissions — lives entirely inside the contract language.
Key takeaways
- A SaaS subscription agreement grants a non-exclusive, non-transferable right to access software — not to own or install it.
- Customers retain ownership of all data they upload; vendors receive only a limited processing license to deliver the service.
- Vertice's 2026 SaaS Inflation Index measured a 12.2% average enterprise SaaS price increase — roughly five times G7 consumer price inflation. Any contract without a price cap is an open-ended financial commitment.
- The FTC's Click-to-Cancel Rule was fully vacated by the Eighth Circuit on July 8, 2025; ROSCA enforcement (civil penalties up to $53,088 per violation) and California's AB 2863 auto-renewal law remain fully active.
- Best practice for the liability cap is a three-tier structure — a general cap, a super cap for data breaches, and uncapped exposure for fraud — not a single number. Most vendor first drafts offer only the single number.
Which Clauses Carry the Most Risk in a SaaS Subscription Agreement?
Nine clauses determine whether an agreement actually protects you or quietly exposes you to uncapped cost escalation, data loss, and liability.
License grant and acceptable use. The license clause confirms the customer has no ownership interest, bars resale or sublicensing, limits use to the subscription term, and restricts the purpose to internal business operations. The acceptable-use policy lists prohibitions — reverse engineering, credential sharing, exceeding usage limits — and violating it is typically grounds for immediate suspension without refund.
Subscription terms, pricing, and billing. This section defines what you receive and what you pay: feature set, user seats, storage limits, API call allowances, billing cycle, overage ("true-up") fees, price-change notice periods, and auto-renewal terms. Vendors writing their own form rarely include price-escalation caps. Watch specifically for pricing model change language: vendors can repackage a product, rename tiers, and introduce a new pricing structure that sidesteps a price cap entirely. A cap without an explicit prohibition on model changes is only half the protection.
Service Level Agreement (SLA). The SLA converts performance promises into enforceable obligations. 99.9% availability is the industry baseline for business-critical SaaS — roughly 43 minutes of allowable downtime per month. Mission-critical systems should target 99.99%, about 4 minutes per month. Service credits are the standard remedy but almost never apply automatically; customers must submit a claim within a vendor-specified window, typically 30 to 60 days after the affected period.
| SLA Tier | Uptime % | Allowable Downtime/Month | Allowable Downtime/Year | Typical Use Case |
|---|---|---|---|---|
| Standard | 99.0% | ~7.3 hours | ~3.65 days | Internal tools, low-criticality apps |
| Business | 99.5% | ~3.6 hours | ~1.83 days | SMB productivity SaaS |
| Business Critical | 99.9% | ~43 minutes | ~8.76 hours | CRM, ERP, collaboration platforms |
| Enterprise | 99.95% | ~21 minutes | ~4.38 hours | High-volume B2B platforms |
| Mission Critical | 99.99% | ~4 minutes | ~52 minutes | Payments, healthcare, financial services |
Data ownership and data rights. Customers retain all right, title, and interest in data they upload. The provider's license is strictly limited to service delivery. Scrutinize clauses permitting de-identification or anonymization — even anonymized data carries re-identification risk. The default post-termination export window in vendor agreements is typically 30 days, which is often insufficient for complex datasets.
AI training and consumption pricing. This clause did not exist in pre-2024 SaaS templates. Standard "improve the service" language is now broad enough to permit AI model training on your data. Require an explicit prohibition: the vendor may not use customer data to train, fine-tune, or benchmark any AI model without separate written consent. When a vendor resists an outright prohibition, negotiate zero-retention processing as a fallback — the vendor processes your data to generate output but does not store or retain it for model improvement. A second AI-specific trap: generative AI features often carry consumption-based pricing that activates automatically with platform updates. According to Zylo's 2026 SaaS Management Index, 77.52% of IT leaders experienced unexpected charges tied to AI features in the past year. Require written opt-in consent before any AI-consumption charges can be activated, and set a hard cap on overages.
Data security and privacy compliance. Security provisions should specify encryption standards, access controls, backup schedules, incident-response procedures, and sub-processor lists. GDPR Article 28 mandates a Data Processing Agreement whenever a SaaS provider processes EU-resident personal data on your behalf. California's CPRA requires a written service-provider contract restricting the vendor's use of California residents' data. Our DPA and GDPR compliance guide covers what a compliant DPA must contain.
Intellectual property ownership. The provider owns the platform and all enhancements, including enhancements inspired by customer feedback. If the vendor builds custom features at your request and the agreement is silent on ownership, you may not own what you paid for.
Limitation of liability. Two components: (a) exclusion of indirect, consequential, and incidental damages, including lost profits; and (b) a monetary cap. Most SaaS guides treat this as a single number to argue over — the correct structure is a three-tier architecture covered in the next section. For how courts assess and sometimes refuse to enforce these clauses, see our limitation of liability guide.
Term, termination, and renewal. The 90-day cancellation notice window common in enterprise SaaS is where most buyers lose money — missing it by a single week locks you into another full term at the new, higher price. Negotiate data-return obligations and portability format here, not after termination.
How Should the Liability Cap in a SaaS Contract Be Structured?
Most SaaS buyer guides tell you to negotiate the liability cap. They don't tell you that the cap itself should have three tiers — and that collapsing all risk into a single number leaves you exposed in the scenarios that actually matter.
Tier 1 — General cap. Covers standard service outages, minor performance failures, and routine contract breach. The market standard is 12 months of fees paid in the period preceding the claim, applied mutually to both parties. This cap applies to most claims and is where most negotiations start and stop.
Tier 2 — Super cap. Applies to data breaches, confidentiality violations, and serious security incidents — categories where the real-world cost dwarfs the annual subscription fee. A super cap is carved out of the general cap and set higher: typically 3 to 5 times annual fees, or a fixed dollar figure tied to the vendor's cyber insurance policy limit, whichever is larger. Super caps are achievable in deals over $25,000 annually; smaller or less-leveraged vendors will accept them because it is a finite number they can insure against. Critically, the super cap must be structurally separate from the general cap — not a higher threshold drawn from the same aggregate pool. A series of service credits in Year 1 should not reduce the amount available to cover a data breach in Year 3.
Tier 3 — Uncapped exposure. Fraud, willful misconduct, and sometimes confidentiality breach sit above the super cap with no ceiling. Most vendors accept this carve-out because it maps to conduct their insurers exclude anyway.
IBM's Cost of a Data Breach Report 2024 put the average cost of a data breach at $4.88 million. A standard 12-month cap on a $100,000-per-year contract limits vendor liability to $100,000 — covering roughly 2% of a typical breach's cost. The super cap exists to bridge that gap without requiring the vendor to accept uninsurable unlimited exposure.
| Liability Tier | Trigger | Typical Amount | Structure |
|---|---|---|---|
| General cap | Standard service failures, outages, routine breach | 12 months of fees paid — applied to both parties equally | Shared aggregate pool |
| Super cap | Data breaches, confidentiality violations, serious security incidents | 3–5x annual fees, or vendor's cyber insurance limit (whichever is larger) | Separate, non-depleting pool; parallel to general cap |
| Uncapped | Fraud, willful misconduct; sometimes IP indemnification | No ceiling | Above both caps; maps to uninsurable conduct |
One drafting note: if the contract excludes consequential damages, confirm that the super cap clause explicitly designates specific breach-related costs — notification expenses, regulatory fines, credit monitoring, forensic investigation — as direct damages for purposes of the super cap. Courts have classified some of these costs as consequential, which would eliminate recovery under a standard damages exclusion.
What Does Vendor Standard Language Say vs. What Should You Negotiate?
Most SaaS agreement guides list what clauses exist. None show you both sides of the same clause. This table does. The left column reflects common vendor opening positions; the right column shows what buyers can realistically achieve.
| Clause | Vendor's Typical Starting Position | Buyer's Target Position |
|---|---|---|
| General liability cap | 3–6 months of fees paid | 12 months of fees, applied equally to both parties |
| Super cap (data breaches) | Not included; all risk in general cap | 3–5x annual fees, structurally separate from general cap |
| Price escalation at renewal | No cap; vendor sole discretion | Fixed annual cap of 3–5%; or CPI-U capped at 5%, whichever is lower |
| Pricing model change | Vendor may update pricing structure unilaterally | No structural change to pricing model without 90 days' written notice and buyer's written consent |
| Auto-renewal notice window | 30 days before renewal date | 60–90 days; vendor required to send written reminder 120 days before |
| Data export window post-termination | 30 days, in vendor's proprietary format | 60–90 days, in machine-readable open format (CSV, JSON, or equivalent) — fee-free |
| SLA credit claim deadline | 30 days after affected period; manual claim required | 60 days; automatic credit application without customer submission |
| AI training restriction | Silent, or broad "improve the service" language | Explicit prohibition; zero-retention processing as fallback for any GenAI features |
| AI consumption charges | Auto-activated with platform updates; billed in arrears monthly | Written opt-in consent required before activation; hard quarterly overage cap |
The pricing model change row matters more than most buyers realize. A 4% annual price cap negotiated at signing is worthless if the vendor repackages its product, renames tiers, and introduces a new pricing structure that technically isn't subject to the original cap. Explicit model-change protection — requiring your written consent before any structural pricing change — is the only reliable defense.
What Auto-Renewal Laws Apply After the FTC's Click-to-Cancel Rule Was Vacated?
The federal landscape shifted materially in 2025 and remains unsettled heading into 2026.
FTC Negative Option Rule — vacated July 8, 2025. In Custom Communications, Inc. v. Federal Trade Commission, the Eighth Circuit unanimously vacated the FTC's Negative Option Rule on procedural grounds. The court held the FTC failed to conduct the preliminary regulatory analysis required under Section 22 of the FTC Act after an Administrative Law Judge determined the rule's economic impact exceeded $100 million. The FTC did not seek rehearing or Supreme Court review. On January 30, 2026, the FTC submitted a new draft ANPRM to OIRA; the comment period closed April 13, 2026 with no proposed regulatory text. A revised rule is at minimum 12 to 18 months away from taking effect.
What still applies federally — ROSCA (15 U.S.C. §§ 8401–8405). The Restore Online Shoppers' Confidence Act prohibits charging consumers through a negative option feature unless the seller clearly discloses all material terms, obtains express informed consent, and provides simple cancellation mechanisms. Civil penalties can reach $53,088 per violation as of the 2025 FTC inflation adjustment. The FTC settled with Amazon on September 25, 2025 for a $1 billion civil penalty plus $1.5 billion in consumer refunds — the largest ROSCA settlement in the statute's history — for deceptive Prime auto-enrollment practices. In December 2025, the FTC filed an amended complaint against Uber alleging that canceling Uber One required consumers to navigate up to 23 screens and 32 actions — the clearest enforcement signal yet that cancellation complexity alone constitutes a ROSCA violation. Chegg settled separately for $7.5 million in September 2025 for burying cancellation options inside multi-step flows with default "pause" settings that prevented completion.
California Automatic Renewal Law (CARL), amended by AB 2863 (effective July 1, 2025). Requires express affirmative consent to auto-renewal terms obtained separately from general agreement acceptance, cancellation via the same medium used to subscribe, retention of consent records for at least three years, and annual renewal reminders regardless of subscription length.
Other active state laws. New York, Connecticut, Massachusetts, Maryland, and Arkansas each enacted or amended auto-renewal laws in 2025. In January 2026, New York City's mayor signed an executive order directing city enforcement against deceptive subscription practices, signaling accelerating state and local action to fill the gap left by the vacated federal rule. For how auto-renewal obligations translate into specific contract language, see our auto-renewal clause guide.
How Much Can a Poorly Written SaaS Contract Actually Cost You?
Here is a worked example using published 2026 market data.
A company signs a $150,000-per-year enterprise SaaS contract in January 2024 with four gaps: no price-escalation cap, a 90-day cancellation notice window, a 30-day data export window post-termination, and no AI training restriction.
Year 2 (January 2025). The vendor applies a 12.2% price increase at renewal — the documented average from Vertice's 2026 SaaS Inflation Index across thousands of contracts. New annual fee: $168,300. The procurement team misses the 90-day cancellation window by two weeks because the opt-out deadline fell in early October, buried in Section 14(b) of an agreement nobody re-read. The renewal is automatic. No refund.
Year 3 (January 2026). Another 12.2% increase. Annual fee: $188,793. The team, now aware of the notice window, submits cancellation in time — but their data is in a proprietary export format requiring six months of engineering migration work. They sign for a fourth year rather than absorb the migration cost.
Three-year cost without negotiated protections: $150,000 + $168,300 + $188,793 = $507,093
With a 4% annual price cap, 60-day data export window, and 90-day advance renewal notice negotiated at signing:
Year 2: $156,000 | Year 3: $162,240
Three-year cost with negotiated protections: $150,000 + $156,000 + $162,240 = $468,240
Negotiated savings over three years: $38,853 on a single contract. The average organization manages 211 SaaS renewals per year (Zylo 2026 SaaS Management Index). Apply that math across even a fraction of a typical portfolio and the business case for contract discipline is immediate.
How Do You Draft or Review a SaaS Subscription Agreement?
These steps apply whether you are a vendor drafting your first agreement or a buyer reviewing one that just arrived.
-
Define scope precisely. List which features, modules, API access rights, geographic availability, and user seats are included — and what triggers additional charges, overages, or forced tier upgrades. Vendors routinely bundle new AI features into core plans and reprice at renewal; require advance written notice before any such change takes effect.
-
Negotiate the SLA before signing. Agree on uptime percentage, measurement period (monthly is better for buyers than annually), the definition of "downtime," scheduled maintenance exclusions, and the credit schedule. Confirm whether credits require a manual claim or apply automatically.
-
Negotiate the three-tier liability structure. Establish the general cap (12 months of fees, mutual), the super cap (3–5x annual fees for data breaches, structurally separate and non-depleting), and the uncapped carve-outs (fraud, willful misconduct). Explicitly list data breach costs — notification, regulatory fines, credit monitoring, forensics — as direct damages within the super cap.
-
Confirm data ownership and AI training restrictions. The agreement must state customer ownership of all data, provider license limited to service delivery, and prohibition on AI model training without separate written consent. If the vendor resists a prohibition, negotiate zero-retention processing language for any GenAI features: the vendor generates the output but does not store the input.
-
Address AI consumption pricing separately. Require written opt-in consent before any AI-feature billing activates. Set a hard quarterly overage cap. With 77.52% of IT leaders reporting unexpected AI charges in 2025 (Zylo 2026 SaaS Management Index), this clause belongs on every checklist, not just agreements with explicit AI branding.
-
Attach or negotiate a DPA. If any EU or California resident personal data flows through the platform, a GDPR Article 28–compliant DPA and CCPA service-provider addendum are legally required before processing begins. Most enterprise SaaS vendors have standard DPA templates — request one at signing.
-
Negotiate a price cap and model-change protection together. A fixed annual cap of 3–5% is achievable at most vendors. Pair it with explicit language prohibiting structural pricing model changes without your written consent — otherwise the cap is easy to sidestep at the next tier refresh.
-
Set a calendar reminder 120 days before every renewal date. Start renegotiation or termination conversations well before the notice window opens. Do not rely on vendor renewal reminders, which are designed to reach you when your leverage is lowest.
-
Negotiate data portability terms explicitly. Require 60 to 90 days to export data after termination, in a machine-readable open format specified by name (CSV, JSON, or XLSX), at no migration fee. Without this clause, exit leverage falls to zero at termination.
For a draft ready for attorney review, generate a Master Service Agreement on Pactlio or generate a services agreement — our AI agent panel debates and refines the document before you see it.
For how SaaS agreements interact with master agreements and statements of work, see MSA vs. SOW explained and what is a Master Service Agreement. For a complete contracts checklist specific to SaaS companies, see contracts every SaaS company needs.
Which Jurisdiction Rules Apply to Your SaaS Contract?
SaaS contracts are global by nature. These are the jurisdiction-specific rules that most often affect these agreements.
| Jurisdiction | Key Rules | Current Status (September 2026) |
|---|---|---|
| United States (Federal) | ROSCA (15 U.S.C. §§ 8401–8405); FTC Section 5 | Active. Click-to-Cancel Rule vacated July 2025; ANPRM comment period closed April 2026. Civil penalties up to $53,088/violation. |
| California | CARL (Bus. & Prof. Code § 17601 et seq., amended by AB 2863); CCPA/CPRA | AB 2863 effective July 1, 2025 for new/amended contracts; strictest US auto-renewal standard; $2,500/violation civil penalty for CARL violations. |
| New York, CT, MA, MD, AR | State auto-renewal laws enacted or amended in 2025; New York City executive order January 2026 | Each adds requirements broadly aligned with California's approach; vary on notice periods and consent requirements. |
| European Union | GDPR (Regulation 2016/679), Art. 28 DPA; EU AI Act for AI-enabled SaaS | Applies to any vendor processing EU-resident personal data regardless of vendor location. GDPR fines up to €20M or 4% of global turnover. |
| United Kingdom | UK GDPR + UK IDTA for cross-border transfers | Legally distinct from EU GDPR since Brexit; separate IDTA or SCCs with UK Addendum required for international data transfers. |
| Canada | PIPEDA (federal) + Quebec Law 25 | Quebec Law 25 Phase 3 obligations active since September 2023; GDPR-equivalent requirements for Quebec-resident data. |
| India | Digital Personal Data Protection Act (DPDPA) 2023 | Rules being finalized; requires reasonable security safeguards, explicit consent, and data principal rights. |
Common Mistakes to Avoid
- Signing with no SLA. An "as-is" service with no uptime commitment gives you no contractual remedy when the platform fails during a critical business period. Any substantive B2B SaaS deal should specify uptime percentage, measurement period, credit schedule, and claim deadline.
- Treating the liability cap as a single number. A one-number cap of three months of fees on a $150,000-per-year contract limits vendor liability to $37,500 — covering roughly 1% of a major data breach's cost. Negotiate a three-tier structure: general cap (12 months of fees), super cap (3–5x annual fees for breaches), uncapped for fraud and willful misconduct.
- Missing the auto-renewal notice window. Enterprise SaaS agreements typically require 60 to 90 days' notice to cancel. Set calendar reminders 120 days before every renewal date. Do not rely on vendor renewal reminders, which are designed to reach you when your leverage is lowest.
- Leaving data portability undefined. Without explicit contract language requiring return of your data in an open, machine-readable format within a specified post-termination window, you may face a costly migration at precisely the moment you have the least leverage over the vendor.
- Failing to attach a DPA for EU or California data. Operating without a compliant DPA creates immediate regulatory exposure under GDPR Article 28 and risks losing the CCPA "service provider" exemption for both parties.
- Accepting a price cap without model-change protection. Vendors can repackage their product and introduce a new pricing structure that sidesteps the cap entirely. Add explicit language requiring your written consent before any pricing model change takes effect.
- Ignoring AI consumption pricing. 77.52% of IT leaders experienced unexpected charges from AI features in 2025 (Zylo 2026 SaaS Management Index). Require written opt-in consent before any AI-feature billing activates, and set a hard overage cap.
- Leaving "improve the service" language untouched. This phrase is now standard boilerplate for permitting AI model training on customer data. Add an explicit prohibition plus zero-retention processing as a fallback before signing any agreement that touches sensitive, regulated, or commercially valuable data.
Sources
- Vertice 2026 SaaS Inflation Index (12.2% average enterprise SaaS price increase): https://www.vertice.one/l/saas-inflation-index-report
- Zylo 2026 SaaS Management Index (79% price increase rate; 16.8% avg. renewal savings; 211 renewals/yr; 38% treat renewals as cost opportunity; 77.52% unexpected AI charges): https://zylo.com/blog/saas-agreement-checklist
- Eighth Circuit — Custom Communications, Inc. v. FTC (vacatur of Negative Option Rule, July 8, 2025): https://ecf.ca8.uscourts.gov/opndir/25/07/243137P.pdf
- Arnold & Porter — FTC and State AGs Continue to Scrutinize Subscription Practices (ROSCA civil penalties; Amazon $1B + $1.5B settlement; FTC ANPRM January 2026): https://www.arnoldporter.com/en/perspectives/advisories/2026/02/ftc-and-state-ags-continue-to-scrutinize-subscription-practices
- Goodwin Law — FTC's Click-to-Cancel Rule Gets New Life (Uber amended complaint Dec. 15, 2025; 23 screens / 32 actions to cancel): https://www.goodwinlaw.com/en/insights/publications/2026/02/alerts-practices-ba-ftcs-click-to-cancel-rule-gets-new-life
- Fasthoff Law Firm — Auto Renewal and Subscription Compliance (Amazon settlement details; FTC ANPRM March 2026; CARL AB 2863): https://fasthofflawfirm.com/blog/auto-renewal-subscription-compliance
- ROSCA (Restore Online Shoppers' Confidence Act), 15 U.S.C. §§ 8401–8405 — FTC Legal Library: https://www.ftc.gov/legal-library/browse/statutes/restore-online-shoppers-confidence-act
- California Automatic Renewal Law, amended by AB 2863 (Bus. & Prof. Code § 17601 et seq.): https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2863
- Axiom Law — How In-House Counsel Should Negotiate SaaS Contracts (layered liability architecture; super cap 3–5x fees; zero-retention processing): https://www.axiomlaw.com/blog/saas-contract-negotiation
- ContractHQ — The 'super-cap' and why some contracts have one (three-tier liability mechanics; general cap vs. super cap structure): https://contracthq.app/blog/super-cap-liability
- IBM Cost of a Data Breach Report 2024 (average breach cost $4.88M): https://www.ibm.com/reports/data-breach
- GDPR Article 28 — Data Processor Requirements: https://gdpr-info.eu/art-28-gdpr/
- California Privacy Protection Agency — CPRA Regulations: https://cppa.ca.gov/regulations/
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What is a SaaS subscription agreement?▾
A SaaS subscription agreement is a legally binding contract between a cloud software provider and a customer governing access to the provider's software. It covers the license grant, subscription pricing, uptime commitments, data ownership, liability limits, and termination rights. Unlike a traditional software license, it grants access — not ownership — of the software.
Is a SaaS subscription agreement the same as terms of service?▾
No. Terms of service set general conduct rules for individual users and are typically non-negotiable clickwrap agreements. A SaaS subscription agreement is a negotiated B2B contract covering uptime guarantees, data processing obligations, service credits, liability caps, price-escalation limits, and enterprise-specific terms that standard terms of service never address.
Who owns customer data in a SaaS agreement?▾
The customer retains all right, title, and interest in data they upload or create on the platform. The provider receives only a limited license to process that data for service delivery. Watch for broad 'improve the service' clauses — in agreements with AI features, these often permit model training on your data without explicit consent.
What is a layered liability cap in a SaaS contract?▾
A layered liability cap uses three tiers: a general cap (typically 12 months of fees) for routine failures; a super cap (3–5x annual fees) for data breaches and confidentiality violations; and uncapped exposure for fraud and willful misconduct. Negotiate all three tiers separately. Most vendor first drafts use only the general cap.
What uptime percentage should I expect in a SaaS SLA?▾
99.9% uptime — roughly 43 minutes of allowable downtime per month — is the industry baseline for business-critical SaaS. Mission-critical applications like payments or healthcare systems should target 99.99%, which permits only about 4 minutes per month. Always verify whether uptime is measured monthly or annually; annual measurement can hide short, severe outages.
What happened to the FTC's Click-to-Cancel rule for SaaS auto-renewals?▾
The Eighth Circuit vacated the FTC's Negative Option Rule (Click-to-Cancel) on July 8, 2025, in Custom Communications, Inc. v. FTC, on procedural grounds. The rule no longer applies. The FTC submitted a draft ANPRM to OIRA on January 30, 2026. ROSCA and Section 5 FTC Act enforcement continue. California's AB 2863, effective July 1, 2025, remains fully in force.
When do I need a Data Processing Agreement with my SaaS vendor?▾
GDPR Article 28 mandates a Data Processing Agreement whenever your SaaS provider processes personal data of EU residents on your behalf. California's CPRA requires a written service-provider contract restricting vendor use of California residents' personal data. Most enterprise SaaS deals involving any personal data require a DPA or privacy addendum before processing begins.
What is the difference between a SaaS subscription agreement and a Master Service Agreement?▾
An MSA is the overarching contract covering IP ownership, liability, confidentiality, and dispute resolution across the entire relationship. The SaaS subscription agreement or order form sits underneath it, specifying the product tier, user count, term, and price for a specific deal. Both documents govern the relationship and must be read together.