SaaS Agreement Template
A free SaaS agreement template covering the subscription and license grant, uptime and support commitments, customer data ownership, security and privacy obligations, auto-renewal, and what happens to the data when the contract ends. Download in PDF or Word.
Last updated: August 5, 2026
What Is a SaaS Agreement?
A SaaS agreement is the contract under which a software vendor gives a customer access to a hosted application rather than a copy of software. Because nothing is installed and nothing is sold, the document works differently from a traditional software license: it grants a subscription right of access, defines the users and usage limits included, sets a service level for availability and support, and describes what the vendor may do with the data the customer puts into the system.
Two sections carry most of the commercial weight. The first is data: the customer must own its own data, the vendor must be limited to using it to provide the service, and there must be a defined way to export it and a deadline for deleting it after termination. The second is the renewal and pricing mechanics — auto-renewal windows, notice periods, and the cap on how much the price can rise at renewal. Uptime credits attract attention, but it is usually the renewal terms and the exit path that determine whether a subscription becomes a trap.
When to Use This Template
- ✓You sell or buy access to a hosted software product on a subscription basis
- ✓The subscription includes usage limits such as seats, API calls, storage, or records
- ✓Availability, support response times, or service credits need to be committed in writing
- ✓Customer data, security obligations, and a data processing addendum have to be addressed
- ✓The subscription will auto-renew and both sides need clear notice and price-change rules
- ✓The customer needs a guaranteed way to export data and have it deleted after termination
Received a contract like this to sign?
Don't guess what's in it. ScanContract's AI flags risky clauses in 60 seconds.
Analyze My Contract FreeTemplate Preview
Full text of the template. Fields in [BRACKETS] are placeholders you fill in.
SaaS Agreement
1. 1. Parties and Definitions
This Software as a Service Agreement (the "Agreement") is entered into on [EFFECTIVE DATE] between [VENDOR NAME], a [ENTITY TYPE] located at [VENDOR ADDRESS] (the "Provider"), and [CUSTOMER NAME], a [ENTITY TYPE] located at [CUSTOMER ADDRESS] (the "Customer"). "Service" means the hosted software application described in the Order Form, together with its documentation and any updates made generally available. "Order Form" means the ordering document signed by both Parties that states the subscription plan, fees, term, and usage limits. "Authorized User" means an individual permitted by the Customer to access the Service under its account. "Customer Data" means all data, content, and materials submitted to the Service by or for the Customer.
2. 2. Subscription and License Grant
Subject to this Agreement and payment of the applicable fees, the Provider grants the Customer a non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use the Service for its internal business purposes, up to the usage limits stated in the Order Form. The Service is provided as a subscription to hosted software; no copy of the software is sold or delivered, and no rights are granted other than those expressly stated. The Customer may not resell, rent, time-share, or provide the Service to third parties as a service bureau, may not reverse engineer or attempt to derive the source code except as permitted by law, and may not use the Service to build a competing product. The Customer is responsible for the acts and omissions of its Authorized Users.
3. 3. Usage Limits, Seats, and Overage
The subscription includes [USAGE LIMITS, e.g., number of Authorized Users, API calls per month, storage volume, records, or environments] as stated in the Order Form. The Customer may add seats or capacity at any time at the rates in the Order Form, prorated to the end of the current Subscription Term. If usage exceeds the purchased limits, the Provider will notify the Customer and the Customer will either reduce usage or purchase additional capacity within [OVERAGE CURE PERIOD, e.g., 15 days]; unresolved overage is billed at [OVERAGE RATE]. Login credentials are personal to each Authorized User and may not be shared, although a seat may be reassigned when an individual leaves the organization of the Customer. The Provider may measure usage through the Service for billing and capacity purposes.
4. 4. Fees, Billing, Taxes, and Price Changes
The Customer will pay the subscription fees stated in the Order Form, billed [BILLING FREQUENCY, e.g., annually in advance or monthly in advance] by [PAYMENT METHOD]. Fees are due within [PAYMENT TERM, e.g., 30 days] of the invoice date, are non-refundable except as expressly provided, and are exclusive of taxes; the Customer is responsible for applicable sales, use, and similar taxes other than taxes on the income of the Provider. Amounts past due accrue a late charge of [LATE FEE PERCENTAGE] per month or the maximum permitted by law, whichever is less, and the Provider may suspend access after [SUSPENSION NOTICE, e.g., ten days] written notice of non-payment. The Provider may change fees effective at the start of a renewal term by giving at least [PRICE CHANGE NOTICE, e.g., 60 days] written notice, and any increase at renewal will not exceed [PRICE INCREASE CAP, e.g., 7 percent] over the fees in the expiring term.
5. 5. Term, Renewal, and Termination
The initial Subscription Term is [INITIAL TERM, e.g., 12 months] beginning on [SUBSCRIPTION START DATE]. The subscription renews automatically for successive periods of [RENEWAL TERM] unless either Party gives written notice of non-renewal at least [NON-RENEWAL NOTICE, e.g., 30 days] before the end of the then-current term. Either Party may terminate for material breach that is not cured within [CURE PERIOD, e.g., 30 days] after written notice, and either Party may terminate immediately if the other becomes insolvent or ceases business. If the Customer terminates for uncured material breach by the Provider, the Provider will refund prepaid fees covering the remainder of the term. On termination, the rights of access granted under Section 2 end immediately and the Customer will pay all fees accrued through the termination date.
6. 6. Service Levels, Uptime, and Support
The Provider will use commercially reasonable efforts to make the Service available at least [UPTIME COMMITMENT, e.g., 99.9 percent] of the time each calendar month, measured as described in Exhibit A and excluding scheduled maintenance, emergency maintenance, force majeure events, failures of Customer systems or networks, and outages caused by third-party services outside the reasonable control of the Provider. Scheduled maintenance will be announced at least [MAINTENANCE NOTICE, e.g., 48 hours] in advance and will be performed within the window of [MAINTENANCE WINDOW]. If monthly availability falls below the commitment, the Customer may request a service credit of [CREDIT SCHEDULE, e.g., 5 percent of monthly fees for each full percentage point below the commitment, capped at 30 percent of monthly fees] by submitting a written request within [CREDIT REQUEST WINDOW, e.g., 30 days]. Service credits are the sole and exclusive remedy for failure to meet the availability commitment. Support is provided through [SUPPORT CHANNELS] during [SUPPORT HOURS] with target first-response times of [RESPONSE TARGETS BY SEVERITY].
7. 7. Customer Data and Ownership
As between the Parties, the Customer owns all right, title, and interest in Customer Data, and the Provider acquires no rights in it other than the limited rights granted here. The Customer grants the Provider a non-exclusive right to host, copy, process, transmit, and display Customer Data solely to provide, secure, support, and improve the Service for the Customer, and to comply with law. The Provider will not sell Customer Data, will not use it to train models made available to other customers except with written consent, and will not disclose it except as permitted in this Agreement or required by law after reasonable notice where legally permitted. The Provider may generate and use aggregated, de-identified statistics that do not identify the Customer, any Authorized User, or any individual. The Customer is responsible for the accuracy and legality of Customer Data and for having the rights necessary to submit it.
8. 8. Data Protection, Privacy, and Subprocessors
Where the Provider processes personal data contained in Customer Data on behalf of the Customer, the Parties will enter into the Data Processing Addendum attached as Exhibit B, which is incorporated by reference and controls over this Agreement in case of conflict on data protection matters. The Provider will process personal data only on documented instructions from the Customer, will ensure personnel with access are bound by confidentiality, and will assist the Customer with data subject requests and required assessments at the levels described in the Addendum. The Provider may engage subprocessors listed at [SUBPROCESSOR LIST LOCATION], will impose data protection obligations on them no less protective than those in the Addendum, will remain responsible for their performance, and will give at least [SUBPROCESSOR NOTICE, e.g., 30 days] notice before adding a new subprocessor so the Customer may object on reasonable grounds. Customer Data will be stored in [DATA RESIDENCY REGION] unless the Parties agree otherwise in writing.
9. 9. Security and Incident Response
The Provider will maintain an information security program with administrative, technical, and physical safeguards appropriate to the nature of the Service, including encryption of Customer Data in transit and at rest, role-based access controls, logging, vulnerability management, secure development practices, and periodic backups. The Provider will maintain [COMPLIANCE ATTESTATIONS, e.g., SOC 2 Type II or ISO 27001 certification] and will make a summary report available to the Customer under confidentiality on request no more than [AUDIT FREQUENCY, e.g., once per year]. The Provider will notify the Customer without undue delay and in any event within [BREACH NOTICE PERIOD, e.g., 72 hours] after becoming aware of a security incident affecting Customer Data, will provide the information reasonably needed for the Customer to meet its own notification obligations, and will take reasonable steps to contain and remediate the incident. The Customer is responsible for securing its own credentials, endpoints, and access administration, including prompt removal of users who leave.
10. 10. Data Export, Retention, and Deletion
During the Subscription Term the Customer may export Customer Data at any time using the export features of the Service in [EXPORT FORMATS, e.g., CSV and JSON] or through the API. On termination or expiration, the Provider will make Customer Data available for export for [EXPORT WINDOW, e.g., 30 days], after which the Provider will delete or irreversibly anonymize Customer Data within [DELETION PERIOD, e.g., 60 days], except for copies retained in routine backups which are deleted on the normal backup rotation, and except where retention is required by law. On written request the Provider will confirm deletion. Assisted migration or bulk extraction beyond the standard export features is available at [MIGRATION RATE]. The Provider will not withhold Customer Data as leverage in a fee dispute, provided undisputed amounts due at termination are paid.
11. 11. Acceptable Use and Suspension
The Customer will not use the Service to store or transmit unlawful, infringing, defamatory, or malicious content, to send unsolicited communications in violation of applicable law, to interfere with or disrupt the Service or its infrastructure, to circumvent usage limits or security controls, or to conduct penetration testing without prior written authorization. The Customer will comply with applicable export control and sanctions laws. The Provider may suspend access to the Service, in whole or in part, where suspension is reasonably necessary to prevent harm to the Service, to other customers, or to third parties, where required by law, or for non-payment after notice. Except in an emergency, the Provider will give notice before suspension and will restore access promptly once the cause is resolved. Suspension does not relieve the Customer of the obligation to pay fees for the suspended period unless the suspension was without cause.
12. 12. Provider Intellectual Property and Feedback
The Provider and its licensors retain all right, title, and interest in the Service, including its software, interfaces, documentation, and all improvements, and no rights are granted to the Customer except the subscription rights expressly stated in this Agreement. The Customer may not remove or obscure proprietary notices. If the Customer provides suggestions, ideas, or feedback about the Service, the Provider may use and incorporate that feedback without restriction or obligation, and the Customer waives any claim of ownership in resulting improvements. Each Party may use the name and logo of the other only as permitted in writing, except that the Provider may identify the Customer as a customer in a list of customers unless the Customer objects in writing.
13. 13. Warranties, Disclaimers, and Indemnification
The Provider warrants that the Service will perform materially in accordance with its documentation and that it will not materially reduce core functionality during a paid term. Except as expressly stated, the Service is provided on an as-is basis without warranties of any kind, and the Provider disclaims all implied warranties including merchantability, fitness for a particular purpose, and non-infringement, and does not warrant that the Service will be uninterrupted or error-free. The Provider will defend and indemnify the Customer against third-party claims that the Service infringes a United States patent, copyright, trademark, or trade secret, and will at its option procure the right to continue use, modify the Service, or terminate the affected subscription and refund prepaid unused fees. The Customer will defend and indemnify the Provider against third-party claims arising from Customer Data or from use of the Service in violation of this Agreement. The indemnified Party must give prompt notice, control of the defense, and reasonable cooperation.
14. 14. Limitation of Liability, Governing Law, and General Provisions
Neither Party will be liable for indirect, incidental, consequential, special, or punitive damages, or for lost profits, revenue, goodwill, or anticipated savings, even if advised such damages are possible. Except for the indemnification obligations in Section 13, breach of confidentiality, breach of data protection obligations, or the payment obligations of the Customer, the total aggregate liability of each Party arising out of this Agreement will not exceed the fees paid or payable by the Customer in the [LIABILITY CAP PERIOD, e.g., twelve months] preceding the event giving rise to the claim. Where a higher cap applies to data protection or security incidents, it is stated here: [ENHANCED CAP, e.g., two times the fees paid in the preceding twelve months]. These limits apply regardless of the theory of liability and survive termination. This Agreement is governed by the laws of the State of [GOVERNING STATE], without regard to conflict of laws rules, and disputes will be brought exclusively in the state or federal courts located in [VENUE COUNTY AND STATE]. This Agreement, its Order Forms, and its exhibits are the entire agreement between the Parties and supersede prior proposals and understandings, and any conflicting terms in a purchase order or online click-through are rejected. In case of conflict, an Order Form controls over this Agreement for the commercial terms it states, and the Data Processing Addendum controls for data protection. Amendments must be in writing and signed by both Parties, except that the Provider may update the documentation and non-material operational policies from time to time. Neither Party may assign without consent except to a successor of substantially all of its business. Neither Party is liable for delay caused by events beyond its reasonable control.
15. 15. Signatures
By signing below, both Parties confirm they have read and agree to this Agreement as of the Effective Date. PROVIDER: [VENDOR NAME]. Signature: ______________________. Printed Name: [PROVIDER SIGNER NAME]. Title: [TITLE]. Date: [DATE]. CUSTOMER: [CUSTOMER NAME]. Signature: ______________________. Printed Name: [CUSTOMER SIGNER NAME]. Title: [TITLE]. Date: [DATE]. This Agreement may be executed in counterparts, and electronic signatures have the same effect as original signatures on a single document.
16. Disclaimer
This template is provided for general informational purposes only and is not legal advice. SaaS agreements intersect with privacy law, security regulation, consumer auto-renewal statutes, export control, and sector-specific rules that vary by jurisdiction and by the data involved. Review and adapt this document for your own facts, and have a licensed attorney review it before using it for regulated data, enterprise procurement, or cross-border processing. Use of this template does not create an attorney-client relationship with ScanContract.
Key Clauses Explained
What each important clause does — and what to watch out for before you sign.
Subscription Grant and Restrictions
Grants access rights for the term rather than selling software, and lists prohibited uses.
Customers should note that access ends when the subscription ends, which is why the export and deletion clause matters more than it looks. Vendors should keep the restrictions specific rather than sweeping, since an overbroad ban on benchmarking or integration can conflict with what an enterprise buyer actually needs to do with the product.
Uptime Commitment and Service Credits
Promises a monthly availability percentage and sets credits as the remedy when it is missed.
Read the exclusions before the percentage. An impressive number means little if scheduled maintenance, emergency maintenance, and third-party outages are all carved out. Customers should also notice that credits are usually the sole remedy, so a serious outage yields a small discount rather than damages, and should push for a termination right after repeated failures.
Customer Data Ownership and Use
Confirms the customer owns its data and limits what the vendor may do with it.
Look closely at the aggregated and de-identified data carve-out and at any language permitting use for model training. Customers should require written consent for training and confirm that de-identification is genuine. Vendors should keep the improvement right narrow enough to survive a security review by an enterprise buyer.
Auto-Renewal and Price Increases
Renews the subscription automatically unless notice is given and caps increases at renewal.
The notice window is the trap. A thirty-day non-renewal notice on an annual contract means the decision date arrives eleven months into a year nobody was tracking. Customers should calendar it on signing and insist on a percentage cap on increases. Vendors selling to consumers should check state auto-renewal disclosure statutes, which impose specific notice requirements.
Data Export and Deletion on Termination
Guarantees a window to retrieve data and a deadline for the vendor to delete it afterward.
Customers should confirm the export produces usable formats rather than a proprietary dump, and should test the export before they need it. Vendors should state plainly that data will not be withheld over a fee dispute, since that single sentence removes a common objection in procurement and is difficult to justify keeping out.
Data Processing Addendum and Subprocessors
Handles personal data obligations and gives notice before new subprocessors are added.
If the service touches personal data, the addendum is not optional paperwork; it is the document a regulator will ask for. Customers should check the subprocessor list, the notice period, and whether they can object. Vendors should keep the list public and current, because a stale list is one of the fastest ways to fail a security questionnaire.
Security Program and Breach Notification
Commits the vendor to specific safeguards and to notifying the customer quickly after an incident.
Customers should require a fixed notification deadline rather than a vague promise of prompt notice, because their own regulatory clocks start running from the moment they learn. Vendors should scope audit rights carefully, offering a report under confidentiality instead of open-ended on-site audits that are impossible to scale.
Limitation of Liability and Enhanced Cap
Caps total exposure at fees paid, with a higher cap for data protection and security failures.
A twelve-month fees cap is often smaller than the cost of one breach notification exercise. Customers handling sensitive data should negotiate a super-cap for security and privacy failures. Vendors should make sure whatever they agree to is actually within the limits of their cyber liability insurance rather than a number chosen to close a deal.
Frequently Asked Questions
What is the difference between a SaaS agreement and a software license?▾
What uptime should a SaaS agreement guarantee?▾
Who owns the data in a SaaS product?▾
Do I need a data processing addendum with my SaaS vendor?▾
How do I avoid being locked into an auto-renewal?▾
Related Templates
Website Terms of Service
A free website terms of service template you can publish on a site or app: how users accept the terms, account rules, acceptable use, intellectual property, disclaimers, limitation of liability, termination, and governing law. Download in PDF or Word.
Free download — PDF & Word →Software Development Agreement
A free software development agreement template covering the specification, milestones, acceptance testing, source code ownership, open source components, and post-delivery warranty. Download in PDF or Word and fill in the bracketed fields.
Free download — PDF & Word →IT Support / Managed Services Agreement
A free IT support and managed services agreement template for MSPs and internal buyers: covered devices and users, severity-based response times, patching and backup commitments, security obligations, out-of-scope work, and a documented exit. Download in PDF or Word.
Free download — PDF & Word →Mutual Non-Disclosure Agreement
A free mutual NDA template for situations where both companies will be sharing confidential information — partnerships, integrations, joint bids, and early acquisition talks. Download it in PDF or Word, fill in the bracketed fields, and sign.
Free download — PDF & Word →Downloaded a template? Analyze the final contract.
Before you sign, let ScanContract's AI check for risky clauses and missing protections.
Scan My Contract