US SaaS contracts

How to review a SaaS MSA: the nine clauses that decide the deal

Most of an MSA is boilerplate that will never matter. A few clauses decide who pays when something goes wrong. Read those first, and read them as a set.

Master services agreement§ 9 Liability

9.1Neither party shall be liable for indirect or consequential loss. Each party’s aggregate liability shall not exceed the fees paid in the preceding twelve (12) months, save for breach of Section 7 (Confidentiality) and the indemnity in Section 11, which are capped at three times that amount. Vendor’s liability shall in no event exceed one hundred dollars ($100).

Guide example§ 9
In short
  • Limitation of liability, indemnities and data terms are one system — never negotiate them separately.
  • Uptime and support commitments are only as real as the remedy attached to them.
  • The clause most often signed unread is the one that governs renewal and price increases.

Start from the money, not the top

A master services agreement is read most effectively from the back. The recitals and definitions matter, but the clauses that will cost or save real money cluster in the final third: liability, indemnity, data, termination. Read those first, then go back to see whether the definitions quietly change what they mean.

1. Limitation of liability

This is the clause. Everything else in the agreement is priced through it. A typical vendor position caps total liability at twelve months of fees paid and excludes indirect and consequential damages entirely. A typical customer ask is a higher cap, often a multiple of annual fees, plus carve-outs for the things that matter most to them.

The carve-outs are where the negotiation lives. Common ones: breach of confidentiality, data protection obligations, indemnification obligations, gross negligence and wilful misconduct. A vendor can usually accept confidentiality and indemnity carve-outs; a customer asking for data breach to be fully uncapped is asking the vendor to insure the customer’s entire regulatory exposure for the price of a software subscription, and a “super cap” — a higher but finite figure for data incidents — is the usual landing point.

2. Indemnities

An indemnity is a promise to pay for someone else’s loss. Vendors routinely indemnify for third-party IP infringement claims arising from the service; that is standard and should be given. Customers often ask for a general indemnity covering breach of the agreement, which is not standard and effectively converts every contractual breach into an uncapped claim. Look at how the indemnity interacts with the liability cap: if indemnities are carved out of the cap, a broad indemnity is an unlimited liability.

3. Data protection and security

For any SaaS product that touches personal data, this is now the second-largest risk clause. Check three things: whether a data processing agreement is attached or incorporated by reference; what security standard the vendor commits to (a named framework and audit report, or vague “industry-standard measures”); and who bears the cost of a breach notification. If customers are in the EU or UK, the transfer mechanism has to be addressed explicitly.

4. Service levels and remedies

An uptime commitment without a remedy is a marketing statement. Look for the credit schedule, the cap on credits, whether credits are the sole and exclusive remedy, and whether repeated failure gives a termination right. Ninety-nine point nine percent uptime measured monthly allows about 43 minutes of downtime; measured annually it allows almost nine hours in a single stretch. The measurement window matters as much as the number.

5. Term, renewal and price

Auto-renewal with a 60- or 90-day notice window is standard and reasonable. Auto-renewal combined with an uncapped right to increase fees at renewal is not: it means the customer’s only defence against a 40% increase is to have diarised a notice date fourteen months earlier. Cap the increase — a percentage or an index — and make sure the notice period is workable for the customer’s procurement cycle.

6. Termination

Check termination for convenience (usually not available to the customer in a committed-term deal, and vendors should resist it), termination for cause (with a cure period), and what happens to data on exit — how long the customer has to retrieve it, in what format, and at what cost. A transition assistance clause matters more than it looks: without it, a customer who terminates for the vendor’s breach can still be held hostage on data export.

7. Intellectual property

The vendor owns the platform; the customer owns its data. That much is standard. The grey zone is anything created during the relationship — configurations, integrations, feedback, anonymised usage data. A feedback licence to the vendor is normal. A clause under which the vendor owns “derived data” or “insights” may be perfectly benign or may hand over something the customer considers a trade secret, depending on the product.

8. Confidentiality

Usually uncontroversial, with two exceptions. First, duration: a confidentiality obligation that expires three years after termination is inadequate for trade secrets, which should survive indefinitely. Second, the interplay with the liability cap discussed above.

9. Governing law and disputes

Rarely worth a fight for two US parties, but crucial for cross-border deals. A US vendor whose EU customer insists on local governing law needs local advice on what that changes — mandatory consumer, agency and data rules can override the contract regardless of what it says. Arbitration clauses are common and often sensible, but read the seat and the rules: an arbitration seated somewhere neither party has ever been is not a neutral choice, it is a costly one.

The mistake we see most

Negotiating these clauses one at a time, in order, with different people. The liability cap, the indemnity carve-outs and the data terms are a single risk allocation, and conceding one without adjusting the others changes the deal in ways nobody intended.

General information, not legal advice. This page describes how US and cross-border commercial contracts commonly work; it is not advice on your situation and does not create an attorney–client relationship. For advice on a specific contract, speak to a lawyer qualified in the relevant jurisdiction.

Next step

Have a contract like this on your desk?

Send it over. We will mark it up and walk you through it in twenty minutes — no cost, and you will know whether the desk is worth it.

Book a contract call