MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A SaaS agreement governs the purchase of online software as a subscription — you are not buying anything; you receive a right to use software running on the supplier's end. The key points are: you receive a right of use, not ownership; your data remains yours (data ownership and portability); there are clear exit and termination agreements regarding data return; a data processing agreement is attached as an appendix; and price changes, liability, and availability are regulated. Unlike a purchase, you pay for as long as you use the service, and access ceases upon cancellation. Below are things to look out for before signing.
The short answer
- Usage rights: you rent access, you do not buy software.
- Data ownership: your data remains yours, even during the subscription.
- Exit: how to cancel and get your data back in a usable format.
- Data Processing Agreement: attached, to the processing of personal data.
- Price: how and when the supplier may increase it.
- Availability: uptime and support, usually via an SLA.
Purchase versus subscription
With traditional software, you purchase a license and install the package yourself. With SaaS, you purchase software as a service: it runs at the vendor, and you log in via the browser. You pay for as long as you use it, and access stops as soon as you cancel. That difference determines where the risks lie — not in ownership of the software, but in your dependence on a vendor who manages your data and work environment.
Right of use, not ownership
The SaaS agreement grants you a right of use: the right to use the software within certain limits. Pay attention to the scope:
- Number of users or accounts.
- Permitted use and any restrictions (for example, no resale).
- What happens in case of overruns (additional payment or blockage).
You receive no source code and no ownership. If you want software that becomes yours, you are in the world of custom development, not SaaS.
Data ownership and portability
The most sensitive point with SaaS is your data. Ensure that the agreement explicitly stipulates:
- Ownership: your entered data remains yours; the supplier acquires no rights to it.
- Portability: you can export your data at any time in a usable, common format (for example, CSV, not a locked-down export file).
- Use by supplier: whether and how the supplier may use your data, for example, anonymized for product improvement.
Without a clear agreement, you are stuck: your data is in a system that you cannot leave without re-entering everything.
Exit and data return
The exit clause is the most important provision you hope you never need. Rule:
- Notice period and whether the subscription renews tacitly.
- Data return: within what timeframe will you receive a complete export, and in what format.
- Deletion: that the supplier deletes your data after expiration, with proof.
- Transition period: will you keep access for a little while longer to migrate?
Also consider the worst-case scenario: what if the supplier goes bankrupt? An exit arrangement that guarantees data return within a short period is your salvation in that case.
Data Processing Agreement attached
As soon as the SaaS tool processes personal data — and this is almost always the case with customer, employee, or contact data — a Data Processing Agreement (DPA) is mandatory under Art. 28 GDPR. This is normally attached as an appendix to the SaaS agreement. Verify that the DPA is actually included and that it regulates security, sub-processors, and data return.
Price changes, liability and availability
Price change: many SaaS contracts allow the supplier to adjust the price annually. Pay attention to the threshold (for example, linked to indexation), the notice period, and whether you are allowed to terminate the contract early in the event of an increase.
Liability: Suppliers often limit their liability to the annual fee. For a business-critical service, you want to know whether that ceiling is reasonable and whether significant damage (data loss, data breach) is covered by it.
Availability: guaranteed uptime and support are usually stated in a separate SLA. Without an enforceable availability standard, you have no rights in the event of an outage.
Practical example
A consultancy firm switches to a cloud project system. During the negotiations, the firm focuses on three things: the data (export to CSV at any time, deletion upon completion with proof), the exit (thirty days data return, even in the event of bankruptcy), and the price (increases only annually, capped at inflation, with the right of termination). When the supplier announced a substantially higher price after two years, the firm was able to switch without penalty based on the termination clause — including a clean data export.
Honest recommendation
For an inexpensive, non-critical SaaS tool, accepting the standard terms and conditions suffices—be sure to check the exit and price change clauses. You don't need a lawyer for that. As soon as the tool is business-critical, contains a lot of data, or is expensive, have the agreement reviewed: data ownership, exit and data return, the liability ceiling, and the DPA appendix. A good exit clause costs a fraction of what a forced migration or data loss costs.
Read more about the DPA included as an attachment, the SLA for availability , and the license agreement for the difference compared to classic software.
Frequently Asked Questions
A SaaS agreement governs the purchase of online software as a subscription. You receive a right to use software running at the supplier, not ownership. You pay for as long as you use it, and access ceases upon cancellation.
Your entered data remains yours, provided the agreement explicitly stipulates this. Also arrange for portability (export in a common format at any time) and for the supplier to delete your data after the agreement expires. Without an agreement, you could end up stuck.
When purchasing, you receive a license and install the software yourself. With SaaS, you acquire software as a service that runs at the supplier; you pay for as long as you use it and lose access upon cancellation. The risk lies in your dependence, not in ownership.
The exit clause determines how you terminate the contract and recover your data in a usable format, within what timeframe, and whether this also applies in the event of bankruptcy. Without a proper exit arrangement, you are tied to the supplier or lose your data in the event of bankruptcy.
Yes, as soon as the tool processes personal data, a Data Processing Agreement (DPA) is mandatory under Art. 28 GDPR. This is normally attached as an appendix to the SaaS agreement. Verify that the DPA is actually included and handles security and data return.
Often yes, but watch the limits: preferably link the increase to indexation, agree on a notice period, and stipulate the right to terminate the contract early in the event of an increase. Without those agreements, you are faced with a fait accompli.
For an inexpensive, non-critical tool, usually not — check the exit and price change clauses yourself. For a business-critical, data-intensive, or expensive tool, a lawyer pays off: data ownership, exit, the liability ceiling, and the DPA appendix.