US SaaS contracts
How to review a SaaS MSA: the nine clauses that decide the deal
Most of an MSA is boilerplate that will never matter. A few clauses decide who pays when something goes wrong. Read those first, and read them as a set.
9.1Neither party shall be liable for indirect or consequential loss. Each party’s aggregate liability shall not exceed the fees paid in the preceding twelve (12) months, save for breach of Section 7 (Confidentiality) and the indemnity in Section 11, which are capped at three times that amount. Vendor’s liability shall in no event exceed one hundred dollars ($100).
- Limitation of liability, indemnities and data terms are one system — never negotiate them separately.
- Uptime and support commitments are only as real as the remedy attached to them.
- The clause most often signed unread is the one that governs renewal and price increases.
Start from the money, not the top
A master services agreement is read most effectively from the back. The recitals and definitions matter, but the clauses that will cost or save real money cluster in the final third: liability, indemnity, data, termination. Read those first, then go back to see whether the definitions quietly change what they mean.
1. Limitation of liability
This is the clause. Everything else in the agreement is priced through it. A typical vendor position caps total liability at twelve months of fees paid and excludes indirect and consequential damages entirely. A typical customer ask is a higher cap, often a multiple of annual fees, plus carve-outs for the things that matter most to them.
The carve-outs are where the negotiation lives. Common ones: breach of confidentiality, data protection obligations, indemnification obligations, gross negligence and wilful misconduct. A vendor can usually accept confidentiality and indemnity carve-outs; a customer asking for data breach to be fully uncapped is asking the vendor to insure the customer’s entire regulatory exposure for the price of a software subscription, and a “super cap” — a higher but finite figure for data incidents — is the usual landing point.
2. Indemnities
An indemnity is a promise to pay for someone else’s loss. Vendors routinely indemnify for third-party IP infringement claims arising from the service; that is standard and should be given. Customers often ask for a general indemnity covering breach of the agreement, which is not standard and effectively converts every contractual breach into an uncapped claim. Look at how the indemnity interacts with the liability cap: if indemnities are carved out of the cap, a broad indemnity is an unlimited liability.
3. Data protection and security
For any SaaS product that touches personal data, this is now the second-largest risk clause. Check three things: whether a data processing agreement is attached or incorporated by reference; what security standard the vendor commits to (a named framework and audit report, or vague “industry-standard measures”); and who bears the cost of a breach notification. If customers are in the EU or UK, the transfer mechanism has to be addressed explicitly.
4. Service levels and remedies
An uptime commitment without a remedy is a marketing statement. Look for the credit schedule, the cap on credits, whether credits are the sole and exclusive remedy, and whether repeated failure gives a termination right. Ninety-nine point nine percent uptime measured monthly allows about 43 minutes of downtime; measured annually it allows almost nine hours in a single stretch. The measurement window matters as much as the number.
5. Term, renewal and price
Auto-renewal with a 60- or 90-day notice window is standard and reasonable. Auto-renewal combined with an uncapped right to increase fees at renewal is not: it means the customer’s only defence against a 40% increase is to have diarised a notice date fourteen months earlier. Cap the increase — a percentage or an index — and make sure the notice period is workable for the customer’s procurement cycle.
6. Termination
Check termination for convenience (usually not available to the customer in a committed-term deal, and vendors should resist it), termination for cause (with a cure period), and what happens to data on exit — how long the customer has to retrieve it, in what format, and at what cost. A transition assistance clause matters more than it looks: without it, a customer who terminates for the vendor’s breach can still be held hostage on data export.
7. Intellectual property
The vendor owns the platform; the customer owns its data. That much is standard. The grey zone is anything created during the relationship — configurations, integrations, feedback, anonymised usage data. A feedback licence to the vendor is normal. A clause under which the vendor owns “derived data” or “insights” may be perfectly benign or may hand over something the customer considers a trade secret, depending on the product.
8. Confidentiality
Usually uncontroversial, with two exceptions. First, duration: a confidentiality obligation that expires three years after termination is inadequate for trade secrets, which should survive indefinitely. Second, the interplay with the liability cap discussed above.
9. Governing law and disputes
Rarely worth a fight for two US parties, but crucial for cross-border deals. A US vendor whose EU customer insists on local governing law needs local advice on what that changes — mandatory consumer, agency and data rules can override the contract regardless of what it says. Arbitration clauses are common and often sensible, but read the seat and the rules: an arbitration seated somewhere neither party has ever been is not a neutral choice, it is a costly one.
Negotiating these clauses one at a time, in order, with different people. The liability cap, the indemnity carve-outs and the data terms are a single risk allocation, and conceding one without adjusting the others changes the deal in ways nobody intended.
Next step
Have a contract like this on your desk?
Send it over. We will mark it up and walk you through it in twenty minutes — no cost, and you will know whether the desk is worth it.