Forgotten password?

SaaS agreement (premium)

This is a detailed template agreement designed to cover the provisions of software as a service to a customer. It is highly flexible, and includes many optional provisions - albeit at the cost of some complexity.

This document extends our standard SaaS agreement template, including the following additional provisions: (i) an acceptance testing procedure; (ii) a change control procedure; (iii) contract management provisions, covering party representatives and project management meetings; (iv) customisation of the software; (v) customer IT system requirements; (vi) expenses and time sheets; (vii) mutual confidentiality obligations; (viii) publicity restrictions; (ix) non-solicitation of personnel; and (x) export law compliance.

These types of provision are most often found in higher value contracts or contracts involving at least one larger business.

The data protection clauses in this document are designed to help the parties to comply with the General Data Protection Regulation (GDPR).

Ask about this document

SaaS agreement (premium) contents

  1. Definitions: definitions.
  2. Term: commencement of term; end of term.
  3. Set Up Services: obligation to provide set up services; set up services timetable; delays in set up services consequent upon second party delays; hosted services set up and intellectual property rights.
  4. Acceptance procedure: obligation to carry our acceptance tests; assistance with acceptance tests; notification of results of hosted services acceptance tests; hosted services deemed to pass acceptance tests; information upon notice of failure of hosted services to pass acceptance tests; consequences of hosted services acceptance test failure; number of acceptance testing rounds; consequences of acceptance of hosted services.
  5. Hosted Services: creation of hosted services account (acceptance procedure optional); grant of licence to use hosted services; limitations on use of hosted services; prohibitions on the use of the hosted services; prevention of unauthorised access to hosted services; availability of hosted services and SLA; hosted services acceptable use policy; no damaging use of hosted services; no unlawful use of hosted services; no access to platform code.
  6. Customisations: agreement of parties to customisation (no SoF); rights in customisations owned by first party; rights to use customisations; use of customisations by others.
  7. Maintenance Services: maintenance services provision; standard of maintenance services; maintenance services in accordance with SLA; suspension of maintenance services.
  8. Support Services: support services provision; standard of support services; support services in accordance with SLA; suspension of support services.
  9. Customer
    general second party obligations; access to computer systems.
  10. Customer
    compliance of second party computer systems.
  11. Customer
    licence of second party data (hosted services); warranties relating to second party data; back-up of second party data; restoration of second party data.
  12. Integrations with Third Party Services: integration of third party services; right to remove third party services integrations;
     not responsible for supplying third party services;
    Third party services and 
    ; protection for personal data transferred to third party services provider; opportunity to consent to transfers of data to third party services provider; Consent to transfer of data to third party services; features of hosted services dependent upon third party services; Warranties relating to data transfered to third party services provider; charges relating to third party services; no warranties or liability in relation to third party services.
  13. Mobile App: mobile App governed by separate terms.
  14. No assignment of Intellectual Property Rights: no assignments of intellectual property rights.
  15. Representatives: instructions given by first party representatives; instructions given by second party representatives.
  16. Management: management meetings; notice to be given when requesting management meeting; attendance of representatives at management meetings.
  17. Change control: application of section to change requests; request changes at any time; change control notice to be in designated form; actions upon receipt of a change control notice; changes only take effect upon agreement of CCN.
  18. Charges: obligation to pay charges; time-base charges limitations; amounts inclusive or exclusive of VAT; variation of charges.
  19. Expenses: obligation to reimburse expenses; collection of evidence of expenses; supply of evidence of expenses.
  20. Timesheets: obligation to keep timesheets; obligation to supply timesheets.
  21. Payments: issue of invoices; time for payment of charges following invoice; payment methods; interest on late payments; interest on late payments.
  22. Confidentiality obligations: first party confidentiality undertaking; second party confidentiality undertaking; disclosure of confidential information to certain persons; exceptions to confidentiality obligations; disclosures of confidential information mandated by law etc; parties to stop using confidential information upon termination; parties to return or destroy confidential information following termination; confidentiality obligations after termination.
  23. Publicity: limited public disclosures; limited public disclosures by first party; limited public disclosures by second party; confidentiality obligations overriding.
  24. Data protection: compliance with data protection laws; warranty of
    's right to disclose personal data (GDPR); details of personal data processed by 
    the Provider
     (GDPR); purposes of processing of personal data by 
    the Provider
     (GDPR); duration of personal data processing by
    (GDPR); personal data processed by
    on instructions (GDPR); authorised international transfers of personal data (GDPR); informing 
     of illegal instructions (GDPR); personal data processed by
    as required by law (GDPR); confidentiality obligations on
     persons processing personal data (GDPR); security of personal data processed by 
     (GDPR); appointment of sub-processor by
    (GDPR); authorisation for
    to appoint sub-processors (GDPR);
     to assist with exercise of data subject rights (GDPR);
     to assist with compliance (GDPR); obligation to notify 
    of personal data breach (GDPR);
     to provide data protection compliance information (GDPR); deletion of personal data by 
     to allow audit (GDPR); changes to data protection law.
  25. Warranties: first party general warranties; hosted services general warranties; warranty of legality of hosted services; hosted services intellectual property infringement warranty; breach of hosted services infringement warranty; second party warranty of authority; exclusion of implied warranties and representations.
  26. Acknowledgements and warranty limitations: hosted services not error free; hosted services not entirely secure; hosted services compatibility limitation; no legal etc advice with hosted services.
  27. Indemnities: indemnity upon breach: any provision or specified provisions (with definition); conditions upon first party indemnity; indemnity upon breach: any provision or specified provisions (with definition); conditions upon second party indemnity; limitations of liability vs indemnities.
  28. Limitations and exclusions of liability: caveats to limits of liability; interpretation of limits of liability; no liability for force majeure; no liability for loss of profits; no liability for loss of revenue; no liability for loss of use; no liability for loss of opportunities; no liability for loss of data or software (subject to back-up obligations); no liability for consequential loss; per event liability cap upon services contract; aggregate liability cap upon services contract.
  29. Force Majeure Event: obligations suspended for force majeure; force majeure notification and information; mitigation of effects of force majeure.
  30. Termination: termination without cause (optionally assymetric); termination by either party without cause; termination upon breach; termination upon insolvency; termination upon non-payment; rights of termination supplemental or exclusive.
  31. Effects of termination: surviving provisions upon termination; termination does not affect accrued rights; charges on termination of contract.
  32. Non-solicitation of personnel: non-solicitation of employees by second party; non-solicitation of employees by first party.
  33. Notices: contractual notices must be in writing; methods of sending contractual notices to first party; methods of sending contractual notices to second party; substitute contact details for notices; acknowledgement of notice by email; deemed receipt of contractual notices.
  34. Subcontracting: no subcontracting without consent; subcontracting permitted; first party responsible for subcontracted obligations; subcontracting of hosting.
  35. Assignment: assignment by first party; assignment by second party.
  36. No waivers: no unwritten waivers of breach; no continuing waiver.
  37. Severability: severability of whole; severability of parts.
  38. Third party rights: third party rights: benefit; third party rights: exercise of rights.
  39. Variation: variation in writing and signed, subject to change control.
  40. Entire agreement: entire agreement: documents; no mispresentation; section subject to caveats to limits of liablity.
  41. Law and jurisdiction: governing law; jurisdiction.
  42. Interpretation: statutory references; section headings not affecting interpretation; calendar month meaning; no ejusdem generis.

Schedule 1 (Hosted Services particulars)

  1. Set Up Services: specification of software set up services prompt.
  2. Specification of Hosted Services: specification of hosted services prompt.
  3. Customer
    prompt for indentification of customer system requirements.
  4. Financial provisions: financial provisions prompt.
  5. Representatives: first party representatives; second party representatives.
  6. Contractual notices: prompt for first party contractual notice address details; prompt for second party contractual notice address details.

Schedule 2 (Acceptable Use Policy)

  1. Introduction: definitions for acceptable use policy; parties to acceptable use policy; agreement to policy by using services; express agreement to policy; services user minimum age under policy.
  2. General usage rules: no damaging use of services; no unlawful use of services; content must comply with provisions of part.
  3. Unlawful Content: no unlawful user content: general prohibition; no unlawful user content: specific prohibitions; previous complaints and user content.
  4. Graphic material: age suitability of user content; no violence in user content; no pornographic user content.
  5. Factual accuracy: content must be truthful; content must not risk defamation.
  6. Negligent advice: no professional advice in user content; no negligent advice in user content.
  7. Etiquette: content appropriate etc; no offensive content; no annoying content; no hostile communications; no deliberate offense; no content flooding; no duplicate content; categorisation of content; appropriate content titles; courtesy to service users.
  8. Marketing and spam: prohibition on marketing activities; no spam in user content; sending spam using email addresses; no promotion of marketing schemes; avoidance of IP blacklisting.
  9. Regulated businesses: no gambling-related activities; no pharmaceutical activities; no weapon-related activities.
  10. Monitoring: acknowledgement relating to monitoring.
  11. Data mining: no data mining.
  12. Hyperlinks: no hyperlinks to prohibited content.
  13. Harmful software: no harmful software; no risky software.

Schedule 3 (Availability SLA)

  1. Introduction to availability SLA: purpose of hosted services availability SLA; informal definition of uptime.
  2. Availability: uptime commitment; measurement of uptime; reporting of uptime measurements.
  3. Service credits: earning service credits; amount of service credits; application of service credits; service credits are sole remedy; service credits upon termination.
  4. Exceptions: list of exceptions to availablity commitment.

Schedule 4 (Maintenance SLA)

  1. Introduction: introduction to maintenance SLA.
  2. Scheduled Maintenance Services: notice of scheduled maintenance to hosted services; times for provision of maintenance services.
  3. Updates: notice of SaaS updates; application of platform updates.
  4. Upgrades: obligation to release upgrades; notice of SaaS upgrades; application of SaaS upgrades.

Schedule 5 (Support SLA)

  1. Introduction: introduction to support SLA.
  2. Helpdesk: helpdesk obligation; purpose of support services helpdesk; access to helpdesk; times of helpdesk availability; all requests for support to go through helpdesk.
  3. Response and resolution: hosted services support issue categorisation; allocation of support issue severity categories; support response times; contents of response to support request; support resolution times.
  4. Provision of Support Services: support services to be provided remotely.
  5. Limitations on Support Services: excessive use of hosted services support; misuse of hosted service and support services.

Schedule 6 (Form of CCN)

  1. Introduction: title of change; change control notice number; change proposor; date of change control notice; summary of proposed change.
  2. Change details: insert details of change.
  3. Impact of Change: impact upon resources; impact upon timetable; impact upon charges; other effects of proposed change.
  4. Agreement to Change: acceptance of change by signature; form of signature block for first party; form of signature block for second party.

Schedule 7 (Data processing information)

  1. Categories of data subject: prompt for categories of data subject.
  2. Types of Personal Data: prompt for types of personal data.
  3. Purposes of processing: prompt for personal data processing purposes.
  4. Security measures for Personal Data: prompt for security measures for personal data.
  5. Sub-processors of Personal Data: prompt for identifying sub-processors of personal data.