- Licence grant
- Intellectual property ownership
- Acceptable use and prohibited conduct
- Liability limitation and disclaimer
- Unfair contract terms
- Privacy and data handling
- Termination and consequences of termination
- Governing law and dispute resolution
- Optional and situational clauses
- How Artificer Legal can help you get this right
- The liability limitation clause
You have built a SaaS product. A reseller is about to start selling it for you, or you are about to go live with a self-serve sign-up flow. Someone on your team drops a draft end user licence agreement (EULA) into a shared folder — or, more likely, asks whether you even need one. The document looks dense. You are not sure which parts are critical and which are filler.
A EULA is the direct contract between you, the SaaS supplier, and each end user who accesses your software. It is separate from any reseller agreement you have with a distribution partner: the reseller agreement governs the commercial relationship between you and the reseller; the EULA governs what users can and cannot do once they are inside your platform. Where you sell through a reseller, the EULA is the mechanism by which you retain a direct legal relationship with users — without it, you have no direct recourse if a user misuses the platform, and you must go via the reseller every time something goes wrong.
Licence grant
The licence grant clause is the core of any EULA. It defines exactly what right the user receives — and, by implication, everything they do not receive.
A well-drafted grant will specify:
- Scope — is the licence limited to a named user, a number of seats, or an entire organisation?
- Duration — is it subscription-based (expiring on non-renewal) or perpetual?
- Territory — is access restricted to Australia or worldwide?
- Permitted purposes — internal business use only, or does the user have the right to on-sell outputs?
The drafting choice that matters most here is making the grant non-exclusive, non-transferable and non-sublicensable unless you have a deliberate reason to do otherwise. If you leave those restrictions out, a user could arguably assign the licence to a competitor or sub-licence it to third parties.
The trap to watch: a grant clause that is too narrow can prevent legitimate use and generate friction with enterprise customers. Strike the right balance by carving out the specific uses you actually expect users to make of the platform — accessing dashboards, generating reports, exporting data in specified formats — rather than drafting in vague generalities.
Intellectual property ownership
Your software is a literary work for copyright purposes under s 47AB of the Copyright Act 1968 (Cth), and the EULA is where you make ownership unambiguous.
This clause should state clearly that:
- You own all intellectual property in the platform, the underlying code, the documentation, and any updates or enhancements
- The user receives only the limited licence granted above — no assignment, no transfer of ownership
- Nothing in the agreement grants the user the right to decompile, reverse-engineer, or copy the source code
A related trap is user-generated content. If your platform allows users to upload content or data, the EULA needs to address who owns that content and what licence you need to host, process, and display it. Failing to take at least a non-exclusive licence to user data will leave you unable to operate your own product lawfully.
Acceptable use and prohibited conduct
This clause sets the behavioural rules for using the platform. It is also the clause that gives you the contractual basis to suspend or terminate a user's access without having to establish that they have breached some implied term.
Common prohibited conduct provisions include:
- Uploading malicious code, malware, or content that infringes a third party's intellectual property
- Using the platform to harass, defame, or unlawfully discriminate against others
- Sharing login credentials or allowing access by more users than the licence permits
- Scraping, crawling, or systematically extracting data from the platform
- Attempting to circumvent technical access controls or security measures
For SaaS products, this clause carries more commercial weight than it does in a traditional software licence, because your platform is typically multi-tenanted. One user's behaviour — whether it is a data dump that degrades performance or content that exposes you to third-party IP claims — can directly affect other users. The prohibited conduct clause, paired with a right of immediate suspension, is your first line of operational defence.
Liability limitation and disclaimer
SaaS platforms are delivered over the internet. Downtime happens. Maintenance windows are necessary. Data can be lost. Without a carefully drafted liability clause, each of those events is a potential damages claim.
A liability clause in a EULA typically does two things:
- Caps total liability — usually to the fees paid in the 12 months before the relevant incident, or a fixed AUD amount
- Excludes consequential loss — loss of profits, loss of data, loss of opportunity, and similar indirect losses
The important constraint: s 64 of the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) voids any term that purports to exclude, restrict or modify a consumer guarantee. If your users are "consumers" within the meaning of the ACL — broadly, individuals or businesses acquiring services priced under $100,000 for personal, domestic, or household use — you cannot exclude those guarantees entirely.
However, s 64A of the ACL provides that where goods or services are not ordinarily acquired for personal, domestic, or household use, a supplier may limit its liability to re-supplying the services or paying the cost of having them re-supplied. For a B2B SaaS product used by businesses for business purposes, this limitation approach is generally permissible — but it needs to be drafted carefully to sit within what s 64A allows.
The trap here is a blanket "all liability excluded" clause. Courts have no difficulty striking those down in consumer contexts, and the ACCC will treat such clauses as potential unfair contract terms where the contract is a standard form agreement offered to small businesses.
Unfair contract terms
If your EULA is a standard form contract — pre-drafted terms offered on a take-it-or-leave-it basis — it will be subject to the unfair contract terms regime under the ACL. Since 9 November 2023, including an unfair term in a standard form contract is itself unlawful and attracts financial penalties, not merely the consequence of the term being void.
The types of terms most likely to attract scrutiny in a SaaS EULA include:
- Clauses that let you unilaterally vary the features of the service or the price without adequate notice to the user
- Automatic renewal provisions that are buried and difficult to opt out of
- Indemnity clauses that are one-sided and require the user to indemnify you for losses arising from your own conduct
- Termination-for-convenience clauses that allow you to cut off access without notice and with no refund obligation
Drafting these clauses in a balanced way — giving adequate notice periods, tying indemnities to the relevant party's fault, providing fair termination entitlements — reduces both legal risk and the reputational damage that comes from being publicly identified as a business using unfair terms.
Privacy and data handling
If your SaaS collects, stores, or processes personal information about users (which almost every SaaS product does), your EULA should address how you handle that data and cross-reference your privacy policy.
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) govern how you collect and handle personal information. Under s 6D of the Act, the Act's small business exemption applies to businesses with annual turnover of $3 million or less — but that exemption does not extend to operators that trade in personal information (including by providing personal information to another entity in connection with a service) or that have opted in to coverage.
Even if you fall below the threshold today, your EULA should be built for compliance from the start. The Privacy and Other Legislation Amendment Act 2024 (Cth), which received Royal Assent on 10 December 2024, introduced further reforms to the privacy framework, and broader coverage of small businesses remains a live reform question.
Practical provisions to include:
- A description of the categories of data you collect and why
- A statement that personal data is handled in accordance with your privacy policy (linked from the EULA)
- Obligations on users not to upload third-party personal information without obtaining any necessary consents
- Disclosure if data is processed or stored outside Australia
Termination and consequences of termination
The termination clause sets out the circumstances in which either party can end the licence, and what happens to the user's access and data when they do.
Key drafting considerations:
- For-cause termination by you — triggered by breach of the acceptable use provisions, non-payment, or insolvency of the user; typically immediate on notice
- Convenience termination by you — acceptable, but should require reasonable notice (30 days is a common minimum for business SaaS) and address any prepaid fees
- User termination — the user's right to terminate on notice and export their data before the licence ends
The trap that generates the most disputes is the data deletion provision. If your EULA says you will delete user data 30 days after termination, build that capability before you launch — disputes about data retention obligations after a relationship breaks down are common and expensive.
Governing law and dispute resolution
Specify that the EULA is governed by the laws of a nominated Australian state or territory and that disputes will be heard in the courts of that jurisdiction. Most Australian SaaS providers nominate their home state.
Where you have enterprise customers, consider whether an escalation or mediation step before litigation reduces cost for both parties. A tiered dispute resolution clause — internal escalation, then mediation, then litigation — is standard in commercial SaaS agreements.
Optional and situational clauses
Depending on your product and customer base, you may also need:
- Service level commitments — if you make uptime promises in marketing, back them up (or disclaim them) in the EULA; mismatches between sales representations and contract terms create ACL exposure.
- Third-party integrations — if your platform connects to third-party services (payment gateways, mapping, communications APIs), a clause that limits your liability for those services and directs users to third-party terms reduces your exposure.
- Free trials and beta access — a separate or modified EULA for trial access, with clear statements about data handling, feature limitations, and when standard terms kick in.
- Export controls — if your SaaS can be accessed from overseas, a clause requiring users to comply with applicable export control laws protects you from downstream compliance risk.
- Modification of the EULA — a mechanism to update terms on notice, with a clear statement that continued use after the notice period constitutes acceptance of the new terms.
How Artificer Legal can help you get this right
A EULA looks like a boilerplate document until something goes wrong. The clauses that look standard — liability caps, data deletion, IP ownership of user-generated content — are exactly the ones that become disputed when a reseller relationship breaks down or a customer claims their data was mishandled.
At Artificer Legal, we review and draft SaaS EULAs and supporting reseller agreements with a focus on the practical risks Australian technology businesses face. That means examining:
- Whether your liability cap sits within what the ACL permits for your user base
- Whether your standard form terms create unfair contract term exposure post the November 2023 reforms
- Whether your privacy provisions are built for where your business is heading, not just where it is today
- How your EULA and reseller agreement interact, and whether both documents say the same thing about the consequences of user breach
If you are about to launch, onboard a reseller, or are revisiting terms that have not been updated in a few years, it is worth a review before the terms become the problem.
The liability limitation clause
The liability limitation clause is the one that most often determines the outcome of a SaaS dispute — and the one most often drafted in a way that will not hold up. A blanket exclusion of all liability is unenforceable in a consumer context and creates unfair contract terms risk in a B2B context. A cap pitched too high defeats the purpose; one pitched too low may not survive a proportionality challenge. Getting the cap right, excluding the right heads of loss, and ensuring the carve-outs (for fraud, personal injury, and IP indemnities) are in place is the single most commercially significant drafting task in the document.
Beyond the liability clause: a SaaS EULA is the direct contract between you and every person who uses your platform. It defines what you have licensed, what users may not do, what happens to their data, and what recourse each side has when things go wrong. The effort invested in getting it right at the outset is almost always less than the cost of litigating ambiguity later.