Axi Legal Sample report · no real client data
Risk report · SaaS & Software · Business package

SaaS and software agreement
Acme B.V.

📄 18 pages 📅 Analysed 13 May 2026 ⏱ Review within two business days
Overall risk High
3 critical issues · 5 high-priority issues

This example shows how Axi Legal reviews SaaS, software and platform contracts on liability, IP ownership, data processing, SLAs, term and termination. The names and contract details are fictional.

This SaaS contract contains three critical provisions and two additional points of attention that must be addressed before signing. For platform outages there is no balanced liability arrangement, while IP ownership for custom work and existing software is insufficiently delineated. There is also no firm obligation to export data on termination. Combined with an incomplete data processing agreement, the main commercial and legal risks sit too heavily with your organisation.
⚠ High risk (3)
No balanced liability for platform outages
Unclear IP ownership for custom work
No data export on termination
◈ Medium risk (3)
Data processing agreement incomplete
SLA and service credits missing
Automatic renewal, long notice period
✓ Low / acceptable (3)
Governing law: NL ✓
Confidentiality adequate ✓
Invoicing and payment clear ✓

Click a risk for the finding, proposed wording and recommendation.

No balanced liability for platform outages High risk
Article
Art. 11.2
Exposure
Unilaterally unlimited
Priority
Amend

Article 11.2 fully excludes the supplier's liability for platform outages, while your organisation remains fully liable for damage to customers resulting from that outage. The problem is not only the absence of a cap — it is the combination of a full exclusion on the supplier's side and open-ended exposure on yours.

✎ Alternative clause wording
"The supplier's total liability for damage resulting from attributable unavailability of the platform is limited to the amount paid under the agreement in the twelve (12) months preceding the event causing the damage, up to a maximum of €250,000 per event or series of related events."

Recommendation: Propose a balanced liability arrangement tied to twelve months\' contract value. Ensure platform outages are not fully excluded, and require an uptime guarantee of at least 99.5% with service credits for shortfalls.

©
Unclear IP ownership for custom work High risk
Article
Art. 7.1–7.3
Scope
Alle aanpassingen
Priority
Amend

Article 7.1 provides that all changes to the platform — including custom integrations developed at your request — become the property of the supplier. Your organisation retains no right to use these customisations after termination of the agreement. This directly affects your operational continuity.

✎ Alternative clause wording
"Pre-existing software, standard functionality and generic platform improvements remain the property of the supplier. Custom components developed specifically for the customer are described in schedule [x]. To the extent transfer is not agreed, the customer obtains a perpetual, irrevocable, non-exclusive and royalty-free right of use for internal use and continuity purposes."

Recommendation: Make an explicit distinction between standard functionality and custom-developed modules. Record this in an annex at signing — not afterwards.

No data export on termination High risk
Article
Art. 14.4
Risk
Vendor lock-in
Priority
Amend

Article 14.4 contains no obligation for the supplier to export your data in a usable format on termination. In practice this means that after termination you are entirely dependent on the supplier's cooperation to get your own data back.

✎ Alternative clause wording
"On termination of the agreement, for any reason whatsoever, the supplier shall make available to the customer within ten (10) business days a complete data export in a common, structured and machine-readable format.

Recommendation: Ensure data export is standard in every SaaS agreement. Termination can always come unexpectedly — even if the platform works well.

Data processing agreement incomplete Medium risk
Basis
GDPR Art. 28
Risk
Enforcement risk
Priority
Complete

The data processing agreement is attached but lacks a number of mandatory elements under GDPR Article 28: there is no arrangement for sub-processors, no audit right for the customer, no retention periods and no data-breach notification procedure. In a Data Protection Authority audit or a data breach, these gaps are a direct basis for enforcement. Because these points can be remedied relatively easily before signing, this qualifies as medium risk provided the DPA is fully completed.

DPA checklist — minimum required
Subject, duration and purpose of processing
Sub-processors and right to object
Type of personal data and data subjects
Data-breach notification procedure
Security measures
Customer audit right
Retention periods
Transfer outside the EEA
Deletion or return of data

Recommendation: Replace the current data processing agreement with a full DPA covering all of the above elements.

SLA and service credits missing Medium risk
Article
Not included
Risk
No protection for outages
Priority
Add

The contract contains no Service Level Agreement. There are no uptime guarantees, no definition of availability, no incident response times and no service credits for shortfalls. For a business-critical platform this means that, in the event of demonstrable downtime, you have no contractual basis for compensation or escalation. This risk is amplified because the agreement renews automatically with a long notice period, while no firm service levels have been agreed. You could therefore remain locked into a platform whose availability is insufficiently secured contractually.

✎ Alternative clause wording
"The supplier guarantees platform availability of at least 99.5% per calendar month, measured on a monthly basis and excluding planned maintenance. Where availability falls below 99.5%, the customer receives a service credit of 10% of the monthly fee, rising to a maximum of 30% for repeated or serious shortfalls."

Recommendation: Require an SLA as an annex to the contract. Set out at least uptime, incident response times and an escalation procedure.

LB
L. Beute
CFO / General Counsel · 20+ jaar internationale ervaring · 50+ landen
"The analysis has been personally reviewed by me as a practical contract risk analysis. The aim is not to write a legal memo, but to make clear before signing which provisions you can accept, must amend, or can use as a negotiating point. This shows you quickly where the risks are and what you can do about them. The proposed clauses are intended as a directly usable basis for negotiation."
Professioneel gevalideerd op 13 mei 2026
Concrete amendments included for the relevant risks
Handled confidentially · not used for AI model training
Executive summary bijgevoegd
Want to know which provisions to amend before signing? Have your SaaS contract or software agreement reviewed and receive, within two business days as standard, a clear risk overview with concrete recommendations. From €199 excl. VAT. Fixed price before payment. Most contract risks are easy to resolve before signing.
Have your contract reviewed →