Why SaaS agreements matter
While consumer SaaS services typically rely on standard Terms of Service, B2B SaaS requires more comprehensive agreements that address:Custom terms
Enterprise customers often negotiate pricing, service levels, and specific terms that don’t fit in standard ToS
Higher stakes
Business customers depend on your service for operations, creating higher expectations and potential liability
Data obligations
You’re handling business data that may be confidential, regulated, or critical to customer operations
Compliance requirements
B2B customers need assurances about security, compliance, data protection, and availability
Y Combinator open-sourced its SaaS agreement template specifically to help startups navigate B2B sales. The template balances protecting both parties while remaining startup-friendly.
Key components
Services description
Clearly define what you’re providing: Service definition - Describe the software service, features, and functionality you’ll provide Access and availability - Specify how customers access the service (web, mobile, API, etc.) Service levels - Uptime commitments, if any (be realistic—don’t promise 99.99% if you can’t deliver) Limitations - What’s explicitly not included in the service Future functionality - Disclaim any obligation to maintain specific features or add promised featuresSubscription and fees
Define the financial terms:Subscription plans
Subscription plans
Detail the plan customer is purchasing: features included, user limits, usage caps, support level, etc.
Pricing
Pricing
Specify fees clearly:
- Base subscription fee
- Per-user, per-seat, or usage-based charges
- Setup or implementation fees
- Overage charges
- Professional services rates
Billing terms
Billing terms
Explain payment logistics:
- Billing frequency (monthly, annually)
- Payment method
- When payment is due
- Late payment consequences
- Automatic renewal terms
Price changes
Price changes
Reserve the right to increase prices with appropriate notice (typically 30-90 days for existing customers)
License and access rights
Grant limited rights to use your software: License scope - Non-exclusive, non-transferable right to access and use the service Permitted use - Only for customer’s internal business purposes User restrictions - Limit to specified number of users or within customer’s organization No transfer - Customer can’t transfer, sublicense, or resell access Suspension rights - Your right to suspend access for non-payment or terms violationsCustomer responsibilities
Define what the customer must do: Acceptable use - Comply with acceptable use policy (typically incorporated by reference) Lawful use - Only use service for lawful purposes in compliance with all applicable laws Security - Maintain security of credentials and promptly notify of any security breaches Cooperation - Provide reasonable cooperation needed for you to deliver services System requirements - Maintain compatible hardware, software, and network connectivityData and privacy
This section is critical for B2B SaaS: Customer data ownership - Customer owns all data they input into your system License to process - Customer grants you license to process their data as needed to provide services Data protection - Your commitments regarding data security, privacy, and compliance Data processing agreement - Reference to or incorporation of DPA for GDPR compliance Data backup - Your backup policies and customer’s responsibility to maintain their own backups Data return and deletion - What happens to customer data upon terminationFor EU customers or if processing EU residents’ data, you need a Data Processing Agreement (DPA) in addition to the main SaaS agreement. The DPA establishes the customer as controller and you as processor.
Confidentiality
Protect confidential information exchanged: Mutual obligations - Both parties agree to protect each other’s confidential information Definition - What constitutes confidential information Standard of care - Protect with same care as your own confidential information (but no less than reasonable care) Permitted disclosures - To employees, contractors, advisors with need to know Exclusions - Standard exclusions for public information, independently developed, etc. Duration - How long confidentiality obligations survive (typically 3-5 years)Service level agreement (SLA)
For enterprise customers, define commitments: Uptime commitment - Percentage uptime guaranteed (e.g., 99.9% monthly uptime) Measurement methodology - How uptime is calculated, what counts as downtime Exclusions - Scheduled maintenance, customer issues, force majeure, third-party services Service credits - What customer receives if you miss SLA (typically percentage of monthly fee) Sole remedy - Service credits are typically customer’s only remedy for availability issuesSupport and maintenance
Define support obligations: Support channels - Email, ticketing system, phone (if offered) Support hours - Business hours in specified timezone, or 24/7 for premium tiers Response times - Commitments by priority level (critical, high, medium, low) Scope of support - What support covers and doesn’t cover Maintenance windows - When you can perform scheduled maintenanceWarranties and disclaimers
Balance warranties with realistic disclaimers: Limited warranties - Service will perform substantially as described, you have rights to provide the service Customer warranties - Customer has authority to enter agreement, will comply with terms Disclaimer of other warranties - Except for limited warranties above, service provided “AS IS” No warranty of results - Don’t guarantee specific business results or outcomesLimitation of liability
Critical protection for your startup: Liability cap - Total liability limited to fees paid in past 12 months (or 6 months for lower-tier plans) Excluded damages - No liability for indirect, incidental, consequential, or special damages Specific exclusions - Loss of profits, revenue, data, business interruption, reputation Exceptions - Liability limitations typically don’t apply to:- Your gross negligence or willful misconduct
- Your confidentiality obligations
- Your indemnification obligations
- Payment obligations
Indemnification
Define who protects whom from what: Your indemnification - You indemnify customer against claims that your service infringes third-party IP rights Customer indemnification - Customer indemnifies you against claims arising from:- Customer’s use of the service
- Customer data
- Customer’s violation of terms
- Customer’s violation of laws or third-party rights
Term and termination
Define relationship duration and exit:Initial term
Initial term
Length of initial commitment (month-to-month, 1 year, multi-year)
Renewal
Renewal
Whether agreement auto-renews and for what period
Termination for convenience
Termination for convenience
Whether either party can terminate without cause (typically with 30-90 days notice)
Termination for cause
Termination for cause
Right to terminate for material breach (usually after notice and opportunity to cure)
Effect of termination
Effect of termination
What happens when agreement ends:
- Access terminates
- Fees for full billing period remain due
- No refunds for prepaid amounts
- Data return/deletion procedures
- Survival of certain provisions (confidentiality, liability, etc.)
General provisions
Standard but important: Assignment - Customer can’t assign agreement without your consent (but you can assign to acquirer) Governing law - Which state/country law governs Dispute resolution - Court jurisdiction or arbitration requirements Entire agreement - This agreement supersedes all prior agreements and discussions Amendments - How agreement can be modified Severability - If one provision is invalid, others remain enforceable Waiver - Failure to enforce one provision doesn’t waive right to enforce it later Notices - How parties provide legal notices to each other Force majeure - Neither party liable for failures due to circumstances beyond reasonable controlOrder forms and statements of work
The main agreement is often a master services agreement (MSA) supplemented by: Order forms - Specify the plan, pricing, number of users, term, and other deal-specific details Statements of work (SOW) - For professional services, implementation, or custom developmentNegotiation strategy
What to hold firm on
Liability caps - Reasonable limitations are non-negotiable for startups IP ownership - You own your platform, customer owns their data No warranties beyond what you provide - Don’t let customers add custom warranties Data security approach - Don’t agree to specific security measures you haven’t implementedWhat you can negotiate
Pricing and payment terms - Volume discounts, multi-year discounts, payment schedules Service levels - Can tier SLAs by plan level Support terms - Can offer enhanced support for premium pricing Term length - Can offer better pricing for longer commitments Contract language - Can accept reasonable markup that doesn’t change substanceRed flags
Getting started
Y Combinator SaaS agreement
Download YC’s open-source SaaS agreement template, specifically designed for SaaS startups
Common mistakes to avoid
Overpromising in agreements
Overpromising in agreements
Sales pressure leads to promises about features, uptime, or capabilities you can’t consistently deliver. Under-promise and over-deliver instead.
No order form system
No order form system
Using one-off agreements for each customer creates chaos. Establish an MSA + order form structure early.
Accepting unlimited liability
Accepting unlimited liability
The first enterprise customer asks for unlimited liability, and you accept to close the deal. This can bankrupt your company.
Custom agreements for small customers
Custom agreements for small customers
Don’t negotiate detailed agreements for customers paying $100/month. Use standard Terms of Service for small customers; save MSAs for material contracts.
No lawyer review for big deals
No lawyer review for big deals
Your first $100K+ deal deserves legal review, even if the customer uses “standard” terms. Red flags are easier to spot before signing.
When to use different agreement types
Standard Terms of Service
- Self-service signups
- Small businesses and individuals
- Monthly recurring revenue < $1,000
- No custom terms needed
Simple SaaS agreement
- Mid-market customers
- Annual contracts 100K
- Standard plans with minor customization
- Limited negotiation
Comprehensive MSA
- Enterprise customers
- Deals > $100K annually
- Significant negotiation
- Custom SLAs, security requirements, compliance needs
- Multi-year commitments
As you grow, you’ll develop three tiers: (1) self-service with standard ToS, (2) sales-assisted with light SaaS agreement, and (3) enterprise with full MSA. Start simple and add complexity only when deal size justifies it.