Last reviewed 29 August 2026
Software-as-a-service businesses sell continuing access, not a copy. The customer's data lives in your environment, availability is your responsibility, and the relationship renews rather than completing. Terms drafted from an on-premise licence template will not address any of that properly.
Good SaaS terms do three jobs: they define exactly what the customer is buying, they allocate risk in a way you can live with at scale, and they let you run the business — change pricing, deprecate features, suspend abusive accounts — without breaching your own contract.
This guide covers the clauses that matter for UK SaaS businesses selling to other businesses, and the traps that recur in customer negotiations.
Subscription, renewal and price changes
State the subscription term, the renewal mechanism and the notice required to prevent renewal. Auto-renewal is standard in B2B SaaS, but the notice period must be realistic — a 90-day notice window on an annual contract is often challenged and rarely worth the friction.
Reserve the right to change prices on renewal with defined notice. Mid-term increases are generally inappropriate unless tied to a specified index or a change in usage tier. Also address what happens when a customer exceeds their plan limits: automatic upgrade, overage charges or a requirement to purchase additional capacity.
Availability, support and service credits
If you publish an uptime commitment, define how availability is measured, over what period, and what is excluded — planned maintenance, emergency maintenance, force majeure, customer-caused issues and third-party network failures.
Service credits are the usual remedy. Make clear they are the exclusive remedy for availability failures and that the customer must claim them within a defined window. Without that, an availability commitment becomes an uncapped damages exposure.
Data protection and security
In most SaaS relationships the customer is the controller and the provider is the processor, so UK GDPR Article 28 requires a written data processing agreement covering subject matter, duration, nature and purpose, types of personal data, categories of data subject, and specified processor obligations.
Address sub-processors (a list and a change-notification process), international transfers (the UK addendum to the EU standard contractual clauses where relevant), security measures, breach notification timescales and assistance with data subject requests. Security commitments should reflect what you actually do; over-promising in the contract is a common source of later liability.
Acceptable use, suspension and customer data
An acceptable use policy lets you deal with abuse without terminating the whole contract. Include the right to suspend for non-payment, security risk, unlawful content or activity that threatens the platform for other customers, with notice where practical.
Be explicit that the customer owns its data, that you have a licence to process it to provide the service, and — if applicable — that you may use aggregated, anonymised data for analytics and product improvement. Customers increasingly scrutinise this clause, particularly where machine learning is involved, so drafting it clearly avoids a stalled negotiation later.
Liability, warranties and indemnities
Warrant that the service will materially conform to the documentation and be provided with reasonable skill and care. Exclude implied terms so far as permitted, remembering that exclusions in standard terms must be reasonable under the Unfair Contract Terms Act 1977.
Cap liability by reference to fees paid in a defined period, exclude indirect and consequential losses, and consider a higher or uncapped position only for data protection breaches caused by your negligence or for IP indemnity claims. Never exclude liability for death or personal injury caused by negligence, or for fraud.
Termination, exit and data return
Set out termination for convenience (if offered), for breach and for insolvency. On termination, state how long customer data remains available for export, in what format, and when it is deleted. A defined 30-day export window followed by deletion is common and easy to operate.
Enterprise customers will ask for exit assistance, migration support and sometimes continuity commitments. Price these separately rather than absorbing them into a standard subscription, and make sure the standard terms permit a bespoke exit schedule so your paper stack stays coherent.
Key points
- SaaS terms must address access and availability, not delivery of copies.
- Auto-renewal notice periods should be realistic or they invite dispute.
- A UK GDPR Article 28 processing agreement is mandatory where you process customer personal data.
- Service credits should be stated as the exclusive remedy for availability failures.
- Be explicit about ownership of customer data and any use of aggregated data.
- Define the post-termination data export window and deletion timetable.
Frequently asked questions
- Can I use click-through terms for B2B SaaS?
- Yes, provided the customer has a genuine opportunity to review the terms before accepting and the acceptance is recorded. Keep versioned copies with timestamps so you can prove which terms applied to a given signup.
- Am I a controller or a processor?
- For customer content you are usually a processor. For your own account, billing and marketing data about customer personnel you are usually a controller. Most SaaS providers are both, in different respects, and the contract should say so.
- Do I need an SLA?
- Not for every product. Self-serve plans often carry no uptime commitment at all. Enterprise customers will require one, so it is worth having a tiered position ready rather than negotiating from nothing.
- How do I change my terms for existing customers?
- Include a variation mechanism: notice of change, effective on renewal or after a defined period, with a right for the customer to terminate if the change is materially adverse. Unilateral change clauses with no notice and no exit right are vulnerable to challenge.
