Services/Technology & Software

SaaS Subscription Agreement (Enterprise).

Service levels, data handling and liability terms built for negotiating with enterprise customers, not just publishing on a website.

Typical turnaround

5–7 business days

In short

An enterprise SaaS subscription agreement sets out uptime commitments, service credits, data location and security obligations, and liability terms for a business customer paying for access to your platform under a negotiated contract rather than click-wrap terms. It needs to withstand procurement and legal review from customers who will push back on caps, indemnities and data handling commitments.

Why enterprise terms differ from a standard terms of use

A SaaS business selling to enterprise customers needs a different document from the click-wrap terms of use it publishes for self-service signups. Enterprise buyers negotiate — they expect defined service levels, audit rights, data processing terms and liability positions tailored to their procurement policies. Trying to push a consumer-style terms of use through an enterprise legal review usually stalls the deal. We draft a negotiable master subscription agreement with an order form structure, so commercial terms (price, term, users) sit in a short order form while the legal terms remain consistent across customers.

Service levels and service credits

An uptime commitment is only useful if it has a real remedy attached. We define uptime by reference to a measurement period and specific exclusions (scheduled maintenance, force majeure, customer-caused outages), and attach a service credit regime — a percentage of monthly fees credited for defined breach thresholds — as the customer's sole and exclusive remedy for availability failures. This protects the business from open-ended damages claims while still giving customers a genuine incentive-aligned remedy.

Data location, sub-processors and security

Enterprise customers increasingly ask where their data is hosted and who else can access it. We address data location (including whether data is held in Australia or offshore), a right for the customer to be notified of new sub-processors with an objection mechanism, and baseline security commitments — encryption in transit and at rest, access controls and incident response obligations — pitched at a level the business can actually sustain operationally.

Data ownership, portability and deletion on exit

Customer data should be expressly owned by the customer, with the SaaS provider granted only a licence to process it for the purposes of the service. We include export rights during the term and a defined data retention and deletion period after termination, so customers aren't left arguing about whether their data has actually been destroyed.

Liability, indemnities and IP infringement

We cap liability at a multiple of annual subscription fees, with standard carve-outs for confidentiality, data breach and IP infringement claims. An IP infringement indemnity from the provider to the customer is close to standard in enterprise deals — we draft it with the usual limitations (excluding customer modifications and use of the platform other than as authorised) rather than as an open-ended promise.

Term, renewal and price increases

Auto-renewal clauses need clear notice periods for non-renewal, and any right to increase price on renewal should be capped or tied to a defined index so customers aren't blindsided. Getting this balance right avoids both customer churn disputes and revenue leakage from silent renewals at old pricing.

What the fixed fee covers

  • Master subscription agreement with order form structure
  • Service level schedule with uptime commitment and service credit regime
  • Data location, sub-processor and security commitments
  • Data ownership, export and post-termination deletion clauses
  • Liability cap and IP infringement indemnity
  • One round of negotiation support for enterprise deals

Mistakes we see

  • Publishing consumer click-wrap terms and trying to use them for enterprise deals
  • Uptime commitments with no attached remedy, inviting damages claims instead of credits
  • No sub-processor notification right, breaching customer expectations set in their own compliance policies
  • Liability cap set too low to survive enterprise legal review, stalling every negotiation
  • Auto-renewal with no clear notice period, creating disputes at contract end

Who this is for

  • B2B SaaS businesses selling to mid-market and enterprise customers
  • Platforms handling customer data subject to security or compliance review
  • SaaS founders moving from self-service signup to negotiated enterprise contracts
  • Businesses preparing SaaS terms for a procurement or legal due diligence process

Frequently asked questions

Do we need both a standard terms of use and an enterprise agreement?
Most SaaS businesses maintain both — click-wrap terms for self-service signups and a negotiable master subscription agreement for enterprise deals that go through procurement. Trying to use one document for both audiences usually under-serves whichever segment wasn't the primary drafting target.
What uptime figure should we commit to?
That depends on your actual infrastructure and monitoring, not on what sounds impressive. Committing to a figure you can't consistently meet creates constant service credit exposure and reputational risk; we help set a commitment your operations team can genuinely stand behind.
Do we need a separate data processing agreement as well?
Yes, generally. The subscription agreement covers the commercial and service terms, while a data processing agreement addresses the specific obligations around handling personal information the customer's users input into your platform, particularly for Privacy Act and, if relevant, GDPR compliance.
Can we cap liability at the amount the customer has actually paid us?
That's the standard starting position and one most enterprise customers will accept in principle, though they'll often push to increase the multiple or carve out data breach and confidentiality claims from the cap. We negotiate that balance rather than accepting an uncapped position.
What happens to customer data if we get acquired or shut down?
We build in obligations to notify customers of a change of control or discontinuation of the service, with a defined transition period during which customers can export their data before it's deleted — this is increasingly a standard ask in enterprise due diligence.

Related

Talk to us

Get a fixed fee for this document

Send us a note about what you're working on. We'll respond within one business day and, if we're a fit, book a free 15-minute consultation with a senior lawyer.

We treat every message as confidential.

CallBook Call