Customer data, AI training, auto-renewal rules, CERT-In incident reporting, liability caps and getting your data out at the end — our new guide covers the SaaS contract from both sides.
Software sold as a service is sold on trust: that it will be available, that data put into it is safe, and that the customer can leave. Our new SaaS subscription agreement guide explains how that trust is written down.
For providers
The guide recommends a master subscription agreement with an order form for each customer, and schedules for service levels, data processing and security. It explains why business customers now ask for a data processing addendum under the Digital Personal Data Protection Act, why they increasingly insist that their data is not used to train AI models, and why a clause giving the provider broad rights over all customer data is now a commercial problem.
For customers
The guide lists the questions to ask before moving your business onto someone else’s software: where the data is hosted, what happens on non-payment, whether suspension deletes data, what export format is available, and how quickly the provider will tell you about a security incident.
Rules that apply alongside the contract
- The consumer protection authority’s guidelines on dark patterns treat hard-to-cancel subscriptions as a prohibited practice.
- The RBI’s e-mandate framework governs recurring card and UPI payments.
- CERT-In’s directions require specified cyber incidents to be reported within six hours.
The guide links to our service level agreement and DPDP privacy policy guides for the detail.
News on this page is general information, not legal advice. For your own matter, talk to our team, or find an advocate for court work — the advocate’s fee is engaged and paid by you directly.