SaaS Contract Review: 5 Clauses That Always Need Redlining
SaaS Contract Review: 5 Clauses That Always Need Redlining
As transactional counsel, you know the drill: a 40-page SaaS agreement lands on your desk, and the clock is ticking. While every clause matters, certain provisions consistently create outsized risk for your client—whether they are the subscriber or the provider. Below are five clauses that demand immediate redlining, with practical examples grounded in US common law.
1. Limitation of Liability: The "Liability Cap" Trap
Why it needs redlining: Standard SaaS vendor forms often cap liability at the fees paid over the prior 12 months. For a subscriber, this can be dangerously low if a service outage causes lost revenue or data corruption. For a provider, an uncapped liability exposure to consequential damages is equally untenable.
Practical example: Your client, a logistics company, subscribes to a route-optimization SaaS. The vendor’s draft caps liability at $50,000. If the platform fails during peak holiday shipping, your client could lose $2 million in sales. Redline to carve out unlimited liability for breaches of confidentiality, data security, and IP infringement. For general liability, negotiate a multiplier of fees (e.g., 3x annual fees) or a fixed floor linked to actual damages.
Tip: Under UCC § 2-719, a court may strike a limitation of liability that fails its essential purpose. Use this leverage to argue that a low cap on data loss is unconscionable when the SaaS provider controls all backups.
2. Service Level Agreements (SLAs): The "Uptime" Shell Game
Why it needs redlining: Many SLAs define uptime as "availability of the platform" but exclude scheduled maintenance, force majeure, and third-party dependencies. This effectively makes the SLA meaningless. For a provider, overly aggressive uptime commitments (e.g., 99.999%) are impossible without massive infrastructure investment.
Practical example: The vendor’s SLA promises 99.9% uptime but defines "downtime" as only internal server failures. When an AWS outage takes the SaaS offline for 12 hours, your client gets zero credit. Redline to require specific uptime calculations (monthly, not annual), clear definitions of "excused downtime," and automatic service credits (e.g., 5% of monthly fees per 0.1% below the threshold). For providers, cap total credits to 100% of fees and exclude force majeure events.
3. Data Security and Breach Notification: The "Best Efforts" Problem
Why it needs redlining: Vague language like "commercially reasonable security measures" or "best efforts to notify" is a litigation magnet. US state laws (e.g., California’s CCPA, New York’s SHIELD Act) require specific security standards and prompt notification. A subscriber must ensure the vendor’s obligations mirror statutory duties.
Practical example: The contract says vendor will "notify customer of a data breach promptly." Redline to define "promptly" as within 24 hours of confirmed breach, require the vendor to provide a detailed incident report, and indemnify the subscriber for all costs (including regulatory fines). For providers, push back by capping indemnity to the subscriber’s own negligence and requiring the subscriber to cooperate in the investigation.
4. Audit Rights: The "On Your Own Dime" Clause
Why it needs redlining: Vendors often restrict audit rights to once per year, require 30 days’ notice, and limit scope to "compliance with the agreement." This prevents a subscriber from verifying data deletion, security controls, or usage limits. Conversely, providers need protection against disruptive or competitive audits.
Practical example: Your client suspects the vendor is not deleting customer data after termination. The contract allows an audit only with 60 days’ notice and at the subscriber’s full cost. Redline to allow audits on 10 business days’ notice for cause (e.g., suspected breach), with the vendor bearing costs if non-compliance is found. For providers, limit audits to once per year, require a mutually agreed third-party auditor, and exclude confidential information of other customers.
5. Termination for Convenience: The "No Off-Ramp" Scenario
Why it needs redlining: Many SaaS contracts lock a subscriber into a multi-year term with no early exit, even if the product fails to deliver. Conversely, providers need to avoid subscriber walkouts that leave them with unpaid fees. The Uniform Commercial Code’s right to cure (UCC § 2-508) is often waived in these contracts.
Practical example: The contract has a three-year term and no termination for convenience. After six months, the vendor releases a buggy update that crashes your client’s CRM. Redline to include a 30-day termination for convenience clause after the first year, or a "material breach" definition that covers repeated SLA failures. For providers, negotiate a termination fee (e.g., 50% of remaining fees) and require 60 days’ written notice with a cure period for non-payment.
Key Takeaway: Every redline should tie back to a business reality. Use the UCC, state data privacy laws, and common law precedent on unconscionability to frame your arguments. A well-redlined SaaS contract doesn’t just reduce risk—it builds trust between the parties.
This article is for informational purposes only and does not constitute legal advice. Always consult with a licensed attorney regarding your specific contract needs.
Audit your next contract in under 15 seconds
Paste any clause into Attyflow. Get a risk score, legal analysis, and a bulletproof redline — instantly.
Request Sandbox Access