What a workable SaaS contract does
A workable SaaS contract should match the service actually sold and bought. Buyers need continuity, security, usable data rights and predictable exposure. Suppliers need a bounded scope, controllable commitments, payment certainty and liability that fits the commercial model. The red flags usually sit where one side promises more than its systems, data rights or price can support.
SaaS contracts combine a commercial order, software licence or access right, service operations, data processing, security, support, IP, renewal and exit. Reviewing only the limitation-of-liability clause misses how those parts interact.
SaaS red-flags table: buyer and supplier
| Area | Buyer red flag | Supplier red flag |
|---|---|---|
| Scope | critical features exist only in sales material and not the contract | the agreement promises undefined customisation, outcomes or support |
| Pricing | usage, overage, renewal and increase mechanics are unclear | payment depends on acceptance or milestones the supplier cannot control |
| Service levels | no measurable availability, support or remedy for a critical service | absolute uptime, response or recovery commitments ignore exclusions and dependencies |
| Data and AI | customer data can be reused, retained or trained on beyond service delivery | the customer grants insufficient rights to host, secure, support and improve the agreed service |
| Exit | data export, switching assistance and deletion are missing | open-ended migration work is included without scope, timing or fees |
| Liability | important supplier failures sit outside meaningful remedies | uncapped or asymmetric exposure exceeds the contract economics or insurance |
1. The order form and service description disagree
List the service, plan, users, environments, integrations, implementation, support and dependencies that form the deal. Red flags include undefined “enterprise features”, a roadmap treated as a commitment, or an entire website incorporated by reference and changeable at any time.
Buyer check: can the team point to the feature or outcome it is paying for? Supplier check: can operations deliver every promise without bespoke work that was not priced?
2. Usage and pricing can change without a usable boundary
Define the billing unit, measurement source, included allowance, overage, tax, invoice dispute, late payment, renewal, price increase and downgrade mechanics. A unilateral-change right without notice, objective limits or a practical termination option can turn a predictable subscription into an open commitment.
3. Service levels are either cosmetic or impossible
A service level needs a definition, measurement method, exclusions, reporting process, remedy and claim window. Buyers should test whether credits matter for a critical outage. Suppliers should exclude customer systems, force majeure, planned maintenance and third-party dependencies only where the allocation is fair and observable.
4. Security obligations do not match the service
Connect the security schedule to the actual architecture, data, access model and risk. Avoid broad promises to comply with every customer policy or all “industry standards” without an identified version and scope. Buyers should look for ownership, evidence and incident cooperation; suppliers should keep commitments auditable and technically controllable.
5. The DPA and main agreement allocate different realities
Align roles, data categories, purposes, subprocessors, transfers, security, incidents, deletion, audits, hierarchy and liability. If the service uses AI, clarify prompts, files, outputs, telemetry, support content, model providers, retention, training and secondary use.
6. Customer data, service data and feedback are mixed together
Separate customer content and personal data from account data, security telemetry, aggregated statistics and feedback. Define what the supplier may use, for which purpose, whether data is identifiable, and what happens after termination.
A buyer should not grant ownership of its operational data by accident. A supplier still needs sufficient rights to host, transmit, back up, secure and support the service.
7. AI rights are broader than the product explanation
Red flags include a general right to use “all data” to improve any product, silent model-provider access, training controlled only by a setting that can change, or a warranty that AI outputs will always be correct. Match the contract to the actual AI workflow, controls and limitations.
8. IP language captures the wrong layer
Define the supplier platform, customer content, configurations, integrations, deliverables, documentation, feedback and third-party materials. Custom work needs a clear answer on ownership and reuse. An infringement indemnity should state scope, exclusions, defence control and available remedies.
9. Suspension can disable the business without proportionality
Suppliers need suspension rights for security, unlawful use, abuse and non-payment. Buyers need notice where possible, a cure path, limited scope and restoration. A red flag allows immediate suspension of the entire service for any minor breach or disputed invoice.
10. Renewal and termination do not match implementation cost
Review initial term, automatic renewal, notice windows, termination for cause, cure, insolvency, convenience, committed fees and early termination. Buyers should calendar notice dates. Suppliers should avoid building unrecovered implementation work into a contract that can be ended immediately without payment.
11. Exit and switching are an afterthought
The EU Data Act contains contractual and technical rules for switching between data-processing services and addresses obstacles, information, continuity and switching charges. Map export format, APIs, assistance, transition period, security, deletion and any charge against the service and the regulation’s scope.
Do not promise “functional equivalence” as if the supplier controls the destination system. Do not leave the buyer with an unusable export or an exit process that begins only after access ends.
12. Liability, indemnities and remedies do not form one system
Read the cap together with exclusions, super-caps, indemnities, service credits, insurance, warranty remedies, data obligations and third-party claims. A low cap can leave the buyer without a meaningful response; an unlimited cap can expose the supplier far beyond the fee and insurable risk.
13. Audit and compliance promises have no operating model
Define reports, certifications, questionnaires, regulator access, onsite audit triggers, frequency, confidentiality, costs and remediation. Buyers need enough evidence for their risk. Suppliers need a scalable process that does not give every customer unrestricted access to systems or other customers’ information.
14. The supplier can change material terms by posting a new URL
Identify which online terms may change, what counts as material, when notice is given and what the customer can do. Security improvements and ordinary product evolution need room; pricing, data use, core functionality and liability should not change silently mid-term.
15. Data-access terms ignore bargaining power and trade secrets
Article 13 of the Data Act addresses unfair data-access and data-use terms unilaterally imposed on another enterprise. The Trade Secrets Directive protects information only where the definition and reasonable secrecy measures are met. Review access, use, onward disclosure, derived data and confidentiality against both regimes and the actual negotiation.
Primary sources checked
- Regulation (EU) 2023/2854, Data Act — Official Journal 22 December 2023; checked 31 July 2026; locator: Articles 13 and 23–30.
- Regulation (EU) 2016/679, GDPR — Official Journal 4 May 2016; checked 31 July 2026; locator: Articles 28 and 32 and Chapter V.
- Directive (EU) 2016/943 on trade secrets — Official Journal 15 June 2016; checked 31 July 2026; locator: Articles 2–5.
Apply the red flags to the actual agreement. See what needs attention in Contract Review before the next negotiation round.
This guide is for general information only and is not legal advice. It was prepared by Outlex using public legal sources and product context. For advice on your specific situation, speak with a qualified lawyer.


