SaaS agreement template
The clauses that matter in SaaS are not the license — they are uptime, data and exit. goHeather writes the subscription terms, the service levels, the security commitments and the data return obligations, and flags the auto-renewal traps.
Any country or jurisdiction you tell it
Uptime SLA with credits that mean something
Customer data ownership and return on exit
Auto-renewal and price escalation surfaced
What is a SaaS Agreement?
Access to software somebody else runs
A SaaS agreement governs a subscription to software the vendor hosts and operates, which the customer accesses over the internet. The customer never installs anything, never owns a copy, and never has possession of the software itself.That shifts where the risk lives. In a traditional software license, the negotiation is about scope, restrictions and IP — what the customer may do with the copy they hold. In SaaS the customer holds nothing, so those questions matter less, and three others matter enormously: will the service be available, who owns and controls the data sitting in it, and how does the customer get that data out if the relationship ends.It also means the customer is exposed to operational risk they cannot mitigate themselves. If the service is down, there is nothing to restart. If the vendor is breached, the customer's data is in it. If the vendor fails, the data is somewhere the customer cannot reach. The contract is the only lever, which is why availability, security and exit terms deserve the attention that license scope gets in an on-premise deal.
What often goes wrong in a SaaS agreement
Patterns that come up again and again, and how goHeather handles them.
Accepting standard SaaS terms
- Auto-renewal at then-current list price with a 60-day notice window
- "Commercially reasonable efforts" instead of a measurable uptime commitment
- Broad rights for the vendor to use your data to train its models
- Immediate deletion of your data on termination, with no export window
- Data breach liability capped at twelve months of subscription fees
Building it with goHeather
- Renewal increases are capped and notified far enough ahead to act on
- A stated uptime percentage with defined measurement, exclusions and credits
- Data use is limited to providing the service, with training rights addressed explicitly
- A defined data retrieval window in a structured, machine-readable format
- Data breach and confidentiality carved out of the general liability cap
From blank page to signed SaaS agreement
goHeather is not a template download. It is a contract builder that walks you through the document, powered by the latest AI models.
- Start
Start from scratch or from a template
Describe the deal in your own words, or pick a SaaS Agreement template and work from there. Either way goHeather builds the document with you rather than handing you a file to fill in.
- Answer
Answer questions as it drafts
goHeather asks who the parties are, what the deal covers and where you operate, and writes each clause around your answers as you go.
- Review
See every clause explained
Each clause comes with a plain-English summary of what it does, so you know what the document says before you send it.
- Negotiate
Check what comes back
Upload the other side’s edits and goHeather shows each change against the version you sent, flagged by risk.
- Sign
Send it for signature
Collect e-signatures and keep the executed copy, the key dates and the renewal terms in one place.
20,000+
SMBs and small law firms trust goHeather
$1,419
Average saving vs. a lawyer per deal
10,500+
Lawyer-made templates to draft from
25+
Enterprise-grade security controls
Who needs a SaaS Agreement
Where this document usually shows up, and what else goHeather covers there.
- Technology
Selling your SaaS product
Your subscription agreement is negotiated on every enterprise deal. Know which positions you can concede and which you cannot.
See contract AI for technology companies - Procurement
Buying software subscriptions
SaaS spend renews quietly and escalates steadily. The renewal notice window is the most valuable date in the contract.
See contract AI for procurement - Finance
Subscription cost control
Auto-renewal, uncapped increases and overage charges are the three ways SaaS budgets drift. All three are contractual.
See contract AI for finance teams - Related
Installed software instead?
If the customer runs the software on their own infrastructure, a software license agreement is the right document.
See the software license template
Your contracts stay yours
A SaaS Agreement carries names, numbers and terms you would not want shared. goHeather protects every document you draft or upload with enterprise-grade controls, end-to-end encryption and trusted AI providers.
Learn more about securityContracts encrypted with gold-standard protection
Database provider meets bank-grade security
Your documents and data will never be sold
We do not use your data to train our models
SaaS agreements and the three clauses that matter most
goHeather is a technology company, not a law firm, and this page is not legal advice. It describes what our software does. Nothing here states the law or tells you what your contract needs — for that, talk to an attorney licensed where you operate.
In a SaaS relationship the customer holds nothing — no copy of the software, no control of the infrastructure, and often no independent copy of their own data. Everything they rely on is a contractual promise. The sections below cover the three promises that decide whether the deal is sound: availability, data, and exit. Plus the commercial terms that quietly drive the cost up. None of this is legal advice.
What goHeather covers in a SaaS Agreement
These are the parts of a SaaS Agreement goHeather asks you about while it builds one, and the parts it looks at when you upload one somebody else sent. It is a description of what the product does — not a checklist for your document, and not a view on what yours needs.
- Subscription grant and users. Access rights, the number and type of authorised users, and whether affiliates and contractors may use the service. goHeather flags: Usage-based overage charges need a defined metric and a notification threshold, or the first surprise arrives with the invoice.
- Term, renewal and price increases. The subscription period, whether it renews automatically, and how the renewal price is set. goHeather flags: Renewal at then-current list price with a short notice window is the most common source of unexpected SaaS cost increases.
- Service levels and credits. The uptime commitment, how availability is measured, exclusions, and the credits payable when it is missed. goHeather flags: Credits are almost always the sole remedy, so persistent failure buys a discount rather than an exit unless a chronic-failure termination right is added.
- Customer data ownership. Confirmation that the customer owns its data and the limited license the vendor has to process it. goHeather flags: Rights to use customer data for product improvement or model training are increasingly broad and frequently conflict with the customer's own obligations.
- Security commitments. The technical and organisational measures the vendor maintains, certifications held, and breach notification timelines. goHeather flags: A reference to "industry standard security" commits to nothing measurable; named certifications and an attached security schedule do.
- Privacy and data processing. The data processing addendum, the legal basis for processing, subprocessors and international transfers. goHeather flags: State privacy laws impose their own expectations about what the contract has to say, so a data processing addendum written for one regime may not cover what another expects.
- Suspension rights. When the vendor may suspend access — non-payment, security risk, acceptable use breach. goHeather flags: Suspension for non-payment with no cure period can take a business offline over a disputed or misrouted invoice.
- Liability and indemnity. The cap, the carve-outs, and indemnities for IP infringement and data breach. goHeather flags: Data breach frequently sits inside a twelve-month fee cap that bears no relation to the cost of an actual incident.
- Termination and data return. How the subscription ends and the customer's right to export its data before access is cut off. goHeather flags: Immediate deletion on termination makes migration impossible; a 30 to 90 day retrieval window in a usable format is the standard ask.
What an uptime commitment has to specify
"Commercially reasonable efforts to make the service available" is not a service level. It creates no measurable entitlement and no remedy. A real SLA needs four things.
A stated availability percentage, measured over a defined period. 99.9% monthly allows about 43 minutes of downtime; 99.5% allows about 3.6 hours. The measurement period matters as much as the number — the same percentage measured annually rather than monthly permits a single long outage to be absorbed.
A definition of unavailability. Is the service down only when completely inaccessible, or also when a core function fails or response times degrade past a threshold? Vendor definitions tend to be narrow, and a service that is technically up but unusably slow will often not count.
The exclusions. Scheduled maintenance is universally excluded and commonly requires advance notice and a defined window. Also watch for exclusions covering the customer's own network, third-party providers and force majeure, which between them can absorb a large share of real-world downtime.
And the credits. These are the remedy, and they are almost always expressed as the sole and exclusive one — typically a percentage of monthly fees on a sliding scale, often requiring the customer to claim within a short period. Credits rarely approach the cost of an outage, so the important addition is a chronic failure termination right: if the SLA is missed in, say, three months out of any twelve, the customer may terminate without penalty and recover prepaid fees. That converts a discount into an exit.
- A stated percentage with a monthly measurement period
- A definition of unavailability covering degradation, not just total outage
- Limited, specified exclusions with advance notice for maintenance
- Credits plus a chronic-failure termination right
Who owns the data, and what the vendor may do with it
Start with an unambiguous statement that the customer owns its data and that the vendor receives only a limited license to process it as necessary to provide the service. That ownership statement is the foundation for everything else.
Then look at what the vendor may do beyond providing the service. Rights to use customer data for product improvement, analytics or training machine learning models have expanded significantly in recent vendor paper, and they are frequently incompatible with the customer's own commitments — a company that promised its users their information would not be used to train third-party models cannot grant that right to a vendor.
A commonly negotiated position permits the vendor to use aggregated and de-identified data that cannot reasonably be attributed to the customer or any individual, for service improvement, and requires express written consent for anything more. If model training is permitted at all, it should be opt-in, specific about what data is used, and subject to the same confidentiality and security commitments as everything else.
Privacy compliance sits alongside this. Where personal information is involved a data processing addendum is required, and what it has to cover depends on whose information is involved and where they are. goHeather asks what the service will hold and prompts for the addendum where one belongs, covering the ground these arrangements usually address: what the vendor may use the data for, whether it may be shared onward, how long it is kept and what its own subcontractors are held to. Which regimes reach your business is worth settling once with privacy counsel rather than per contract.
How security commitments are usually expressed
"Industry standard security measures" commits to nothing. A meaningful security clause names specifics: encryption in transit and at rest with stated standards, access controls, logging, penetration testing frequency, and personnel screening — usually set out in a security schedule attached to the agreement.
Certifications are the practical shorthand. SOC 2 Type II is the common baseline for enterprise SaaS, with ISO 27001 frequently alongside it, and sector-specific frameworks such as HITRUST for healthcare or FedRAMP for federal buyers. Require the certification to be maintained throughout the term, with reports provided annually, and require notice if it lapses.
Breach notification is where the drafting matters most. The customer has its own statutory obligations of its own if something goes wrong, often on a clock that starts the moment the incident is discovered. If the vendor's obligation is to notify "promptly" or "without undue delay", the customer may not learn in time to meet its own deadline. Ask for a fixed period — 72 hours or less from discovery is the common enterprise position — along with an obligation to cooperate in the investigation and in any regulatory notification.
Then check where breach liability sits. Data breach costs scale with the number of records, not with the subscription fee, so a breach capped at twelve months of fees can leave the customer bearing most of an incident. A super-cap for data breach — a multiple of fees, or a separate stated figure — is a standard enterprise ask, and cyber insurance with the customer named as an additional insured is worth requiring alongside it.
The two dates that decide what SaaS costs you
Almost every SaaS agreement renews automatically. The two dates that matter are the renewal date and the notice deadline, and the second is the one people miss. A sixty or ninety-day notice window on an annual subscription means the decision has to be made well before anyone is thinking about it.
Worse, many agreements renew "at Provider's then-current list price", and the increase may not be communicated before the notice window closes. Two terms commonly negotiated to address this are a cap on the renewal increase — 3% to 5% annually, or an index — and a requirement that any increase be notified at least thirty days before the notice deadline, so the customer can actually respond to it.
At the other end, data portability is what makes leaving possible. The agreement should give a defined retrieval window after termination — thirty to ninety days — during which the customer can export its data in a structured, machine-readable, commonly used format. "Available on request" or "in Provider's standard format" can mean a PDF dump that no successor system can ingest.
Also consider a transition assistance obligation at agreed rates, and, for a service the business genuinely depends on, ask what happens if the vendor fails. Escrow is less useful for SaaS than for licensed software, because source code without the operational environment is rarely runnable. More practical protections are a commitment to provide regular data exports during the term, so the customer always holds a recent copy, and continuity terms triggered by insolvency.
Why goHeather asks what data the service will hold
SaaS agreements carry obligations that depend less on where you are incorporated than on whose information ends up in the system. goHeather asks what the service will hold — ordinary business data, personal information about customers or staff, anything in a regulated sector — and where the parties and the data sit, then builds the data, security and breach-notification terms around those answers and prompts you for a data processing addendum where one belongs. It flags terms in an uploaded agreement that look out of step with what you told it, particularly around what the vendor may do with your data and how quickly you would hear about an incident. What it does not do is tell you which privacy regimes apply to your business. That is a question for privacy counsel, and it is worth settling once rather than per contract.
Before you go. goHeather is a technology company, not a law firm. We do not provide legal advice, legal opinions, or any view on whether a contract or a clause will hold up. Everything above describes what our software does when you build or upload a document. Rules differ from state to state and change over time, and what is right for your business depends on facts we do not have. Have an attorney licensed where you operate review anything that matters.
Other contracts goHeather builds
goHeather drafts any business contract. These are the ones that usually travel with this one.
- Software
Software License Agreement template
License software rather than sell it: what the customer may do with it, and what stays yours.
See the software license template - Framework
Master Service Agreement template
Negotiate the legal terms once, then run every project under a short statement of work.
See the MSA template - Channel
Reseller Agreement template
Let a partner sell your software or services: margin, deal registration, support split and who owns the customer.
See the reseller agreement template
Need a different contract?
goHeather drafts any business contract, not just the ones listed here. Browse every template or start from a blank brief.
SaaS agreement template questions
What people ask before they build a SaaS Agreement.

Still have questions?
Build a SaaS agreement and see what goHeather produces, or book a short demo and we will go through one of your own documents with you.

Trusted by 20,000+ SMBs and small law firms
Get the SaaS terms right on both sides
Build a SaaS agreement with a real SLA, clear data ownership and a workable exit. Or upload the subscription terms you were sent.
Free to try



