# What Clauses to Check Before Signing a SaaS Vendor Contract

SaaS contracts are everywhere. Your CRM, your accounting software, your project management tool — almost every piece of software your business uses comes with a contract that most people never read.

That's a mistake.

SaaS contracts can contain clauses that give vendors sweeping rights over your data, lock you in for years, or leave you with no recourse if the service fails. Here's what to look for before you sign.

**1\. Data ownership and portability**

Who owns the data you put into the platform? The answer should always be: you do. Look for clear language stating that you retain ownership of your data.

Equally important: can you get your data out? Check for data export provisions. If the vendor goes bust or you want to switch, you need to be able to extract your data in a usable format. Some vendors make this deliberately difficult.

**2\. Data processing and GDPR compliance**

If you're a UK business and the SaaS vendor processes personal data on your behalf, they are a data processor under UK GDPR. The contract must include a Data Processing Agreement (DPA) or data processing clauses covering:

*   What data is processed and for what purpose
    
*   Security measures in place
    
*   Sub-processor disclosure
    
*   Data breach notification obligations
    
*   Data deletion on contract termination
    

If the vendor doesn't offer a DPA, that's a serious red flag.

**3\. Uptime and SLA**

What happens if the service goes down? Check:

*   The guaranteed uptime percentage (99.9% means ~8.7 hours downtime per year; 99.99% means ~52 minutes)
    
*   What credits or remedies are available if SLA is breached
    
*   What counts as "downtime" vs "scheduled maintenance"
    
*   Whether SLA credits are your only remedy or whether you can terminate for persistent failure
    

Many SaaS contracts define SLA credits so narrowly they're effectively worthless. Read carefully.

**4\. Auto-renewal and notice periods**

One of the most common contract traps for SMEs. Many SaaS contracts auto-renew for a full year unless you give written notice 30, 60, or even 90 days before the renewal date.

Miss the notice period by one day and you're locked in for another year.

Set a calendar reminder the moment you sign. And push to negotiate shorter notice periods — 30 days is reasonable for most SaaS tools.

**5\. Liability and indemnity**

As with all commercial contracts, check the liability cap. For SaaS:

*   Is the cap mutual or one-sided?
    
*   Is it capped at the amount you've paid in the last 12 months? That might be very low.
    
*   Are there carve-outs for data breaches? (There should be — data breach liability should not be subject to the standard cap)
    
*   What indemnity do they offer for IP infringement claims?
    

**6\. Price changes**

Can the vendor increase prices during your contract term? Many SaaS contracts allow annual price increases of up to 10% without consent. Over 3-5 years, that compounds significantly.

Negotiate a price lock or a cap on annual increases (e.g. CPI inflation only).

**7\. Termination for convenience**

Can you exit the contract before the term ends, and at what cost? Look for:

*   Termination for convenience provisions (the right to exit with notice, without cause)
    
*   Early termination fees
    
*   What happens to your data after termination
    

**The bottom line**

SaaS contracts are not standard or fair by default — they're drafted to protect the vendor. Take 30 minutes to review key clauses before signing. Use AI contract analysis tools to surface the clauses that matter most, flag risks, and generate negotiation guidance.

The cost of a bad SaaS contract compounds over years. The cost of reviewing it properly is measured in minutes.
