What is a SaaS contract
A software as a service (SaaS) contract is the agreement under which a customer pays for access to software that runs on the vendor's systems, for as long as the subscription lasts. Nothing is installed. No copy changes hands. What the customer buys is a right to use a hosted application, together with promises about how well it will run, what happens to the data put into it, and what each side may do when the arrangement ends.
This guide is general information about how SaaS contracts are built, not legal advice on a specific one. The legal examples below are United States federal and state rules, named in place, and equivalents elsewhere differ.
The technical shape of what is being bought comes from the National Institute of Standards and Technology (NIST), which defines the SaaS service model this way: "The capability provided to the consumer is to use the provider's applications running on a cloud infrastructure." The customer "does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings" [1]. That single sentence explains why these contracts read the way they do. The customer controls almost nothing about how the software runs, so the contract has to do the work that possession of a copy used to do.
SaaS agreement, SaaS subscription agreement, software subscription agreement, cloud services agreement, online services agreement, and master subscription agreement all name the same instrument. None of those titles is a distinct legal category, and the title tells you nothing about the terms.
Four related documents are often mistaken for it, and they are not the same thing:
- A service level agreement (SLA) sets uptime and support commitments. In SaaS it is almost always an exhibit to the subscription contract rather than a standalone agreement.
- A data processing agreement (DPA) governs the vendor's handling of personal data and sits alongside the subscription contract, usually as an addendum.
- An end user license agreement (EULA) belongs to software that is installed on the user's own device. A pure SaaS product does not need one.
- An order form, sometimes called an order schedule, is where the commercial specifics live: which product, how many users, what price, which term. The order form is short and the master terms it points at are long. Both are the contract.
Structure varies more than vocabulary does. A negotiated enterprise deal is normally a master agreement plus order forms, so a later purchase adds a one page order rather than a new contract. A self-service purchase is normally clickthrough terms published on the vendor's site plus a checkout confirmation. The second kind is still a binding contract, and it is the kind organizations most often fail to keep a copy of.
The distinction that causes the most confusion is between a SaaS subscription and a traditional software license, and United States accounting rules draw it with unusual precision. The Financial Accounting Standards Board (FASB) defines a hosting arrangement as one "in which the customer of the software does not currently have possession of the software; rather, the software application resides on the vendor's or a third party's hardware, and the customer accesses and uses the software on an as-needed basis" [2].
A hosting arrangement only counts as including a software license if two conditions are both met: the customer "has the contractual right to take possession of the software at any time during the hosting period without significant penalty", and it is feasible for the customer to run that software on its own hardware or to have an unrelated third party host it. Arrangements that fail either test "are service contracts and do not constitute a purchase of, or convey a license to, software" [2].
Most SaaS fails both tests by design, which is the point. You are buying a service, not a thing.
| SaaS subscription | Traditional software license | |
|---|---|---|
| What the customer gets | A right to access a hosted application | A licensed copy, often perpetual |
| Where it runs | The vendor's or a third party's hardware [2] | The customer's servers or devices |
| When payment stops | Access stops, and so does use | The licensed copy usually keeps working |
| Upgrades | Applied by the vendor to everyone | Bought, scheduled, and installed by the customer |
| Money shape | Recurring subscription fees | License fee plus annual maintenance |
| Main compliance worry | Data location, security, and exit | License counts and audit or true-up exposure |
| US accounting test | Service contract [2] | Software license if both criteria are met [2] |
If the document in front of you grants a perpetual right to install and run software, you are reading a license, and the anatomy is different. Contracko covers that instrument separately in what is a software license agreement and how to manage software license agreements.
Purpose and common uses
The contract exists to convert a promise of continuous availability into something enforceable. A license is delivered once. A subscription is delivered every day for years, so the agreement has to say what "working" means, who carries the risk when it stops, and what the customer is owed if it stops too often.
It also settles two questions that have no natural answer in a hosted model. The first is whose data it is once it sits on the vendor's infrastructure. The second is how the customer gets that data back, in what format, and inside what window, when the relationship ends.
Typical settings are familiar. A company buys a payroll, support desk, analytics, or contract management platform for a department. A vendor sells the same platform to thousands of customers on standard terms. A regulated buyer adds a security exhibit and a data processing agreement. A reseller or managed service provider resells access to an end customer, which is a different arrangement again and is covered by a reseller agreement.
The arrangement stops making sense when the workload must run on the customer's own infrastructure, when the data cannot leave a specified environment, or when the customer needs a guarantee that the software will still run in ten years regardless of the vendor's commercial position. None of those survive a hosted subscription intact.
Parties in a SaaS contract
The vendor, also called the provider, supplier, or licensor, runs and maintains the application, holds the intellectual property in the platform, provides support, and carries the security and availability obligations. It also decides the product roadmap, which is why changes to the service are rarely something the customer controls.
The customer, also called the subscriber or client, pays the fees, administers user accounts, controls what data goes into the system, and is responsible for how its people use it. Acceptable use obligations normally flow from the customer to its own users.
Authorized users are the named individuals who actually log in. They are not parties. The customer's contract usually makes it responsible for their acts and omissions, so the definition of an authorized user is a commercial term, not a technicality.
Affiliates are the group companies allowed to use the subscription. Whether they are covered matters at renewal, during reorganizations, and at exit. In one enterprise SaaS agreement filed with the United States Securities and Exchange Commission, the vendor granted the customer, its affiliates, and their authorized users "a subscription to access" the platform, with the scope set by each order schedule rather than by the master agreement [3].
Subprocessors are the vendors behind the vendor: hosting, analytics, support tooling, and increasingly model providers. They sign nothing with the customer, but the customer's own compliance obligations usually reach them. The contract or the data processing agreement should name them, or at least commit to a list and to notice before it changes.
Key terms and clauses
Subscription scope and users
The grant clause says what the customer may access, who may access it, and under what limits. Read it for the metric first. Seats, named users, concurrent users, transaction volume, API calls, and storage all behave differently when the business grows. A per-seat contract with a low cap and an expensive overage rate is a different commitment from the same price on a usage metric.
Restrictions usually prohibit reselling, benchmarking, reverse engineering, and use by anyone other than authorized users. Where the customer plans to connect the service to its own systems, check that the application programming interface (API) is inside the grant rather than sold separately.
Fees, renewal pricing, and overage
The order form carries the price. The master agreement carries the mechanics: when invoices are issued, what payment terms apply, whether fees are payable in advance, and what the vendor may do when an invoice is late. Suspension for non-payment is common and worth reading closely, because suspension of a system people work in every day is a business continuity event.
Two things decide what this costs over time. The first is the renewal uplift, meaning whether the vendor may increase prices on renewal and by how much. A cap on the increase is the single most valuable commercial term in most SaaS contracts. The second is how added users or usage are priced mid-term, and whether reducing them is possible at all before renewal. In the enterprise agreement filed with the Securities and Exchange Commission, the vendor had to give the customer "at least ninety (90) days prior written notice of any increase in rate" [3]. That is one negotiated example rather than a market standard, but it shows what a notice obligation looks like when it is written down.
Service levels and credits
The SLA answers three questions: what availability is promised, how downtime is measured, and what the customer gets when the promise is missed. Published examples show the shape. Google's Workspace service level agreement commits that "the Monthly Uptime Percentage will be at least 99.9% in any calendar month", and sets service credits of 3, 7, or 15 days of free service depending on how far below that figure the month falls [4].
Two details matter more than the headline percentage. The first is what counts as downtime, since scheduled maintenance and issues attributed to the customer's own network are usually excluded. The second is that credits are almost always the exclusive remedy, and they usually have to be claimed. Under that same SLA, the customer "must notify Google" by creating a support case "within thirty days from the time Customer becomes eligible to receive a Service Credit", or lose it [4]. A credit nobody claims is not compensation.
Support is a separate promise. Response targets by severity level, support hours, and escalation paths normally sit in their own exhibit. Contracko's service level agreement clause entry breaks down the drafting, and what is an SLA covers the instrument in full.
Data ownership, privacy, and security
Well drafted SaaS contracts say plainly that the customer owns its data and that the vendor's rights in it are limited to providing the service. The filed enterprise agreement does exactly that, giving the customer "all rights, title, and interest in and to" its data, and giving the vendor only a license to use that data "to the extent necessary" for its intended use and "only during the term of this Agreement" [3].
Three questions decide whether that ownership means anything in practice:
- What may the vendor do with aggregated or anonymized data derived from your use, and may it train artificial intelligence models on your content? If the contract is silent, ask for it to be explicit.
- Where is the data stored and processed, and which subprocessors touch it?
- What security commitments are contractual rather than marketing? An independent audit report or certification, breach notification timeframes, encryption, and access controls belong in the security exhibit, where a change requires agreement.
Privacy law adds contract terms you do not get to skip. Under California's Consumer Privacy Act, a business that sells or discloses personal information to a third party, service provider, or contractor must do so under a contract that specifies the information is disclosed "only for limited and specified purposes" and obligates the recipient "to provide the same level of privacy protection" the statute requires [5]. Where European personal data is involved, the equivalent obligations sit in a data processing agreement.
Liability, warranties, and indemnities
Vendor warranties in SaaS are usually narrow, often limited to the service performing materially in line with its documentation, followed by a broad disclaimer of implied warranties. That pattern appears in the filed agreement, which warrants substantial conformity to the documentation and then excludes, in capitals, any implied warranty of merchantability or fitness for a particular purpose [3].
The liability cap is the number that matters. Caps are commonly set at fees paid over some recent period, which means a low-cost subscription carries a low cap regardless of the damage an outage or a data incident could cause. Look for what sits outside the cap, because the carve-outs are where the real allocation happens: confidentiality breaches, data security incidents, indemnity obligations, and fees owed.
The indemnity that matters to the customer is the vendor's intellectual property indemnity, covering claims that the service infringes someone else's rights. Check what the vendor may do if such a claim arrives, since the usual options include modifying the service, replacing it, or terminating the subscription and refunding the unused portion.
Term, termination, and exit
The term clause creates most of the calendar work. Read four things together: the length of the initial term, whether renewal is automatic, how much notice non-renewal requires, and how that notice must be delivered.
The filed enterprise agreement ran for an initial term of three years and then renewed automatically for one year at a time unless either party gave "written notice of non-renewal at least one hundred eighty (180) days prior to the end of the Initial Term or any Renewal Term" [3]. A 180 day notice period means the decision is due six months before the date most people have in their heads.
Exit provisions decide how much the ending hurts. Ask how long the data stays available for export after termination, in what format it comes out, whether the vendor charges for extraction, and how deletion is confirmed. The same filed agreement required confidential information to be destroyed within 45 days of termination, with 135 days allowed for information held on backup media, and committed the vendor to up to 180 days of transition assistance at a stated hourly rate [3]. Those figures are one negotiated outcome, not a norm, and the useful lesson is that each of them is negotiable and none of them appears by default.
Important dates and lifecycle events
SaaS contracts fail on dates more often than on drafting. The dates below are the ones worth holding as fields on the contract record rather than leaving inside the document.
| Date or event | Why it matters |
|---|---|
| Effective date | Starts the contract, and is often not the date service begins |
| Service start or go-live date | The term may run from here rather than from signature [3] |
| Initial term end date | The commitment period the pricing was based on |
| Non-renewal notice deadline | The real deadline. Calculate it backwards from the term end [3] |
| Auto-renewal date | When the next term and the next invoice begin |
| Price increase notice window | The period in which the vendor may notify an uplift [3] |
| Invoice and payment dates | Late payment can trigger suspension of the service |
| Usage measurement or true-up date | When seats or consumption are counted and billed |
| SLA credit claim deadline | Credits are usually forfeited if not claimed in time [4] |
| Security report refresh | Audit reports and certifications expire annually |
| Data export and deletion window | The gap between termination and data being gone [3] |
The deadline that does the damage is the non-renewal notice date, because it sits months before the renewal and nothing surfaces it automatically. Contracko's SaaS contract calculator takes a contract end date and a notice period and returns the cancellation deadline.
Automatic renewal law is a live area in the United States, and it does not apply evenly. The Federal Trade Commission (FTC) amended its Negative Option Rule in October 2024 to add click to cancel requirements. On July 8, 2025, the United States Court of Appeals for the Eighth Circuit vacated that amended rule, holding that the agency had failed to conduct the preliminary regulatory analysis required by section 22 of the FTC Act, and the vacatur reinstated the earlier rule first promulgated in 1973 [6]. The Commission published an advance notice of proposed rulemaking, so as of September 2026 the 1973 rule is the one in force and the click to cancel requirements are not [6].
What still applies federally is the Restore Online Shoppers' Confidence Act (ROSCA), which the Commission describes as "the only Federal law primarily designed to regulate negative option marketing", limited to seller transactions effected on the internet [6]. ROSCA prohibits charging a consumer for goods or services sold online through a negative option feature unless the seller clearly and conspicuously discloses all material terms before obtaining billing information, obtains "express informed consent" before charging, and provides "simple mechanisms for a consumer to stop recurring charges" [7].
State law differs, and the differences matter to business buyers. In New York, no automatic renewal provision in "a contract for service, maintenance or repair to or for any real or personal property" is enforceable against the recipient unless the provider gives written notice "at least fifteen days and not more than thirty days previous to the time specified for serving such notice", and that statute applies where the recipient is a company as well as an individual [8]. It does not reach contracts whose renewal period is one month or less, and its scope is tied to service, maintenance, or repair of property, so it does not automatically cover every software subscription. In California, the automatic renewal law applies to offers made to consumers, requires the renewal terms to be disclosed clearly and conspicuously before the agreement is fulfilled, and requires a "cost-effective, timely, and easy-to-use mechanism for cancellation"; its 2024 amendments apply to contracts entered into, amended, or extended on or after July 1, 2025 [5]. Neither consumer statute rescues a business that missed a negotiated 180 day notice deadline in a negotiated enterprise contract. The contract does that work, or nothing does.
Risks and common mistakes
Missing the notice window. The most expensive mistake in SaaS is silence. A renewal happens because nobody acted, and the customer is committed for another full term at a price it did not review.
Treating the order form as the whole contract. The order form is a page. The terms it incorporates by reference may be thirty, may sit on a web page, and may allow the vendor to update them. Store what the order form points at, and record whether the vendor can change it unilaterally.
No record of the clickthrough purchases. Departments buy SaaS with a card, agree to online terms, and file nothing. The organization is then bound by terms it cannot produce, renewing on dates it does not know.
Assuming service credits are compensation. They are a discount on future service, usually capped, usually the exclusive remedy, and usually forfeited unless claimed within a stated window [4].
Leaving data exit unplanned. Export format, export window, extraction cost, and deletion confirmation are cheap to negotiate at signature and very expensive to request during a dispute.
Assuming a fallback that does not exist. Unless the contract gives a right to take possession of the software, there is no copy to fall back on if the service ends [2]. Continuity protection has to be built from data export rights, notice periods, and sometimes escrow.
Ignoring quiet changes. Subprocessor lists, security exhibits, acceptable use policies, and model training terms change between renewals. If nobody is assigned to read the change notices, the contract you agreed to drifts away from the contract you are operating under.
Renewing without usage data. Seat counts grow and rarely shrink. Renewal is the only moment the number is genuinely negotiable, and it needs actual usage figures rather than the last invoice.
SaaS contract management checklist
Capture at signature
- Store the order form and the master terms it incorporates as one record, including a dated copy of any terms that live on the vendor's website.
- Record the commercial metric in its own field: seats, named users, usage units, or consumption, with the contracted quantity and the overage rate.
- Record the initial term end date, the renewal length, and the notice period as three separate fields.
- Calculate the non-renewal notice deadline and store that date. Do not store only the expiry date and plan to work it out later.
- Record whether the vendor may raise prices on renewal, any cap on the increase, and the notice it owes before doing so.
- Record the uptime commitment, the credit percentages, and the deadline for claiming a credit.
- Record where data is hosted, the current subprocessor list, and whether the vendor may use your content to train models.
- Record the post-termination data export window, the export format, and any extraction fee.
- Name an internal owner for the contract and the vendor's named contact, and record who has authority to approve an increase.
- Attach the SLA, security exhibit, data processing agreement, and any signed change notices to the same record.
Put in the diary
- A reminder at the non-renewal notice deadline, and an earlier one that leaves time to gather usage data and decide.
- A reminder before each price increase notice window opens.
- A reminder before any usage measurement or true-up date.
- A reminder to review the month's availability against the SLA, early enough to claim a credit inside the window [4].
- An annual reminder to collect the vendor's refreshed audit report or certification.
- A reminder at the start of any post-termination export window, assigned to whoever will run the export.
Review on a cadence
- Every quarter, compare licensed seats or usage against actual usage, and record the gap so renewal is negotiated on evidence.
- Every quarter, check the change notices received from the vendor against the terms on file, including subprocessor and policy updates.
- Twice a year, review the portfolio for duplicate tools bought by different departments.
- Before every renewal, walk through what would happen if this vendor went away in ninety days, and fix whatever that exposes.
Most of that is record keeping, and it runs for as long as the subscription does. Contracko keeps subscription contracts, order forms, and exhibits on one record in a searchable contract repository, and uses AI extraction to pull dates, parties, values, and obligations out of the documents rather than having them typed in. Custom fields hold the things a SaaS contract needs tracked that a generic contract does not, such as the seat count, the notice deadline, the uplift cap, and the data export window. Expiration reminders can be assigned to the colleague who has to act, repeat on a schedule, and renew when the contract renews, and reporting shows annual contract value, upcoming renewals, and top vendors across the whole portfolio rather than one agreement at a time. There is a free trial if you want to load a live subscription agreement and see what comes out.
If your question is how to run this across a whole software estate rather than how one contract works, SaaS contract management covers the workflow.
Sources
[1] National Institute of Standards and Technology, Special Publication 800-145, The NIST Definition of Cloud Computing (the SaaS service model and what the customer does not control). nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf
[2] Financial Accounting Standards Board, Accounting Standards Update 2018-15, Internal-Use Software (Subtopic 350-40) (definition of a hosting arrangement, and the two criteria that separate a software license from a service contract). storage.fasb.org/ASU%202018-15.pdf
[3] U.S. Securities and Exchange Commission, Software as a Service Agreement between Anthem, Inc. and Castlight Health, Inc. (a filed enterprise SaaS contract used here as a worked example of grant, pricing notice, data ownership, term, and exit clauses). sec.gov/Archives/edgar/data/1433714/000143371419000036/ex101softwareasaservic.htm
[4] Google, Google Workspace Service Level Agreement (a published uptime commitment, service credit tiers, and the deadline for claiming a credit). workspace.google.com/terms/sla.html
[5] California statutes, Civil Code section 1798.100(d) and Business and Professions Code section 17602 (contract terms a business must impose when disclosing personal information to a service provider or contractor, and the automatic renewal disclosures, cancellation mechanism, and July 1, 2025 applicability of the 2024 amendments). leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.100 and leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=17602
[6] Federal Trade Commission, Rule Concerning the Use of Prenotification Negative Option Plans, Advance Notice of Proposed Rulemaking (the Eighth Circuit's July 2025 vacatur of the 2024 amended rule, the reinstated 1973 rule, and the scope of ROSCA). ftc.gov/system/files/ftc_gov/pdf/p064202negativeoptionruleanprm.pdf
[7] U.S. Code, 15 U.S.C. 8403, Restore Online Shoppers' Confidence Act (disclosure, express informed consent, and simple cancellation requirements for online negative option charges to consumers). law.cornell.edu/uscode/text/15/8403
[8] New York General Obligations Law, section 5-903 (automatic renewal of service, maintenance, or repair contracts is unenforceable without notice 15 to 30 days before the cancellation deadline). nysenate.gov/legislation/laws/GOB/5-903
Images in this article were generated with the assistance of AI.
Get started with Contracko
Take the hassle out of contract and subscription management. Contracko empowers you to stay organized, on time, and in control. Start simplifying today.