This example shows how Axi Legal reviews SaaS, software and platform contracts on liability, IP ownership, data processing, SLAs, term and termination. The names and contract details are fictional.
Click a risk for the finding, proposed wording and recommendation.
Article 11.2 fully excludes the supplier's liability for platform outages, while your organisation remains fully liable for damage to customers resulting from that outage. The problem is not only the absence of a cap — it is the combination of a full exclusion on the supplier's side and open-ended exposure on yours.
Recommendation: Propose a balanced liability arrangement tied to twelve months\' contract value. Ensure platform outages are not fully excluded, and require an uptime guarantee of at least 99.5% with service credits for shortfalls.
Article 7.1 provides that all changes to the platform — including custom integrations developed at your request — become the property of the supplier. Your organisation retains no right to use these customisations after termination of the agreement. This directly affects your operational continuity.
Recommendation: Make an explicit distinction between standard functionality and custom-developed modules. Record this in an annex at signing — not afterwards.
Article 14.4 contains no obligation for the supplier to export your data in a usable format on termination. In practice this means that after termination you are entirely dependent on the supplier's cooperation to get your own data back.
Recommendation: Ensure data export is standard in every SaaS agreement. Termination can always come unexpectedly — even if the platform works well.
The data processing agreement is attached but lacks a number of mandatory elements under GDPR Article 28: there is no arrangement for sub-processors, no audit right for the customer, no retention periods and no data-breach notification procedure. In a Data Protection Authority audit or a data breach, these gaps are a direct basis for enforcement. Because these points can be remedied relatively easily before signing, this qualifies as medium risk provided the DPA is fully completed.
Recommendation: Replace the current data processing agreement with a full DPA covering all of the above elements.
The contract contains no Service Level Agreement. There are no uptime guarantees, no definition of availability, no incident response times and no service credits for shortfalls. For a business-critical platform this means that, in the event of demonstrable downtime, you have no contractual basis for compensation or escalation. This risk is amplified because the agreement renews automatically with a long notice period, while no firm service levels have been agreed. You could therefore remain locked into a platform whose availability is insufficiently secured contractually.
Recommendation: Require an SLA as an annex to the contract. Set out at least uptime, incident response times and an escalation procedure.