- How access rights are defined
- Acceptable use and prohibited conduct
- Fees, billing and auto-renewal
- Intellectual property ownership
- Data handling and security obligations
- Warranties and service levels
- Liability caps and exclusions
- Termination and what happens to data
- Optional and situational clauses
- How Artificer Legal can help you get this right
- The clause that most often determines who wins
You've built the product. The first enterprise customer wants to sign up, and their procurement team has just asked for your customer terms. Or you've found a SaaS terms template online and you're wondering which clauses actually matter, which ones carry hidden risk, and which ones you can afford to leave thin. Either way, you're at the document stage — and the choices you make now will govern every customer relationship you have.
SaaS terms (sometimes called a subscription agreement or platform agreement) are the contract between your business and every customer who accesses your software. Unlike a one-off sale, SaaS terms bind an ongoing relationship: access, data, support, renewals, pricing and what happens when things go wrong. They sit above your privacy policy and website terms, which govern separate relationships (data handling and general visitors respectively). Getting the customer terms right is the commercial and legal foundation your platform runs on.
How access rights are defined
The access clause is the heart of the agreement. It describes what the customer actually receives: a non-exclusive, non-transferable, revocable licence to access and use the platform during the subscription term, for the customer's own internal business purposes.
Each word carries weight:
- Non-exclusive: you can licence the same platform to many customers simultaneously.
- Non-transferable: the customer cannot assign their access to a third party or resell your product without a separate agreement.
- Revocable: you can terminate access if the customer breaches the terms.
- Internal business purposes: restricts use to the customer's own organisation and prevents on-selling or embedding your platform in a competitor's product.
The trap here is vagueness. If the access clause just says "use the platform", it leaves scope, permitted users and permitted purposes undefined. Specify whether access covers only named users, a certain number of seats, or the customer's entire organisation — because disputes about user counts are common, and they affect both your revenue and your support obligations.
Acceptable use and prohibited conduct
The acceptable use clause sets the boundaries of what customers can do on your platform. It typically prohibits reverse engineering, scraping, attempting to circumvent security controls, uploading malicious code, using the platform to harm third parties, and breaching applicable law.
Key drafting choices:
- List specific prohibited uses relevant to your platform (a payments tool has different risks to a document collaboration tool).
- Include a right for you to suspend access immediately on a breach of acceptable use, without the full notice-and-cure cycle that applies to other defaults.
- State what happens to the customer's data on suspension — this matters for enterprise customers who may have compliance obligations of their own.
The counterparty will often push to narrow suspension rights. Hold firm on the right to suspend for security incidents or illegal use; you can negotiate notice periods for commercial disputes.
Fees, billing and auto-renewal
Spell out the pricing structure, billing cycle, renewal mechanics and what happens if the customer wants to upgrade, downgrade or cancel mid-cycle.
- Auto-renewal: state the renewal period (typically monthly or annual), the notice period required to cancel (commonly 30 days before renewal), and what happens if notice arrives late.
- Price changes: reserve the right to adjust pricing on renewal with reasonable advance notice (at least 30 days is typical; more for annual plans).
- Usage-based fees: if any component is consumption-based, define how usage is measured, when it is invoiced and what happens if usage exceeds plan limits.
The trap is the unilateral variation clause — a clause that lets you change prices (or other key terms) at will, at any time, without notice. Under the unfair contract terms (UCT) regime in the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)), amended by the Treasury Laws Amendment (More Competition, Better Prices) Act 2022 (Cth), a term that permits one party to vary price or core obligations without adequate notice is at significant risk of being declared unfair. Since 9 November 2023, it is unlawful — not merely voidable — to propose, use or rely on an unfair contract term in a standard form contract. The extended definition of "small business" now captures businesses with up to 100 employees or annual turnover up to $10 million, meaning most of your customers may be protected. Draft variation clauses with a fixed notice period and a right for the customer to exit if they object.
Intellectual property ownership
Both parties bring IP into the relationship, and both leave with it.
Your IP — the platform, code, algorithms, documentation and any improvements — must remain yours. The clause grants the customer only the access licence described above; it does not transfer ownership. Include a specific statement that the customer acquires no ownership rights in the platform, even if they request custom features.
The customer's IP — their data, their content uploaded to your platform — remains theirs. Grant yourself only the limited licence you need to provide the service (store, process, transmit), not a broader right to use customer content for your own purposes.
A third category often overlooked: aggregated, de-identified usage data. You may want to analyse usage patterns to improve the product. If so, include an express right to collect and use anonymised data for product improvement, with a clear statement that it will not be used to identify individual customers or their data.
Data handling and security obligations
This clause does significant compliance work. It should address:
- What you collect and process: specify that you act as a processor of customer personal information for the purposes of delivering the service, and that you will comply with applicable privacy law.
- Security controls: describe the minimum security standards you maintain (encryption in transit and at rest, access controls, vendor due diligence). Do not promise standards you cannot consistently meet.
- Sub-processors: if you use third-party infrastructure (cloud hosting, analytics, support tools), acknowledge that and state your obligations to impose equivalent protections on sub-processors.
- Data breach response: commit to notifying the customer within a defined period (24–72 hours is common for enterprise; align with your own obligations under the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth)).
The NDB scheme requires entities covered by the Privacy Act 1988 (Cth) — generally, organisations with annual turnover above $3 million, plus certain categories of smaller businesses — to notify affected individuals and the Office of the Australian Information Commissioner when an eligible data breach is likely to result in serious harm. Even if your business currently falls below the turnover threshold, enterprise procurement teams will expect you to operate as if the scheme applies, and many will require contractual commitments to that effect.
Warranties and service levels
Consumer guarantees under the Australian Consumer Law require that services be provided with due care and skill, be fit for any stated purpose, and be supplied within a reasonable time. Your SaaS terms cannot exclude or limit these guarantees where they apply to consumers.
For B2B customers, you can negotiate a narrower warranty position:
- A limited warranty that the platform will perform materially in accordance with your documentation.
- An express disclaimer of implied warranties beyond those that cannot be excluded by law.
- If you offer an SLA, cross-reference it here: the SLA sets measurable uptime and support response commitments, and service credits are the contractual remedy for falling below them.
Avoid promising specific uptime percentages in your main terms unless you can consistently meet them — use an SLA (which you can update operationally) for the metrics, and keep the main terms focused on the framework.
Liability caps and exclusions
This is the clause that decides who bears the financial consequences when something goes wrong.
Mutual exclusion of consequential loss: neither party is liable for indirect, consequential, incidental, special or punitive loss. For SaaS, this typically includes lost profits, lost data, loss of business opportunity and reputational harm.
Cap on total liability: limit each party's aggregate liability to the amount of fees paid in the 12 months preceding the claim (or a fixed dollar figure for lower-value plans). This is standard and commercially reasonable.
Carve-outs from the cap: the cap does not apply to everything. Common carve-outs include death or personal injury caused by negligence, fraud, wilful misconduct, and breaches of data protection obligations. Enterprise customers will push for security breach and IP indemnity carve-outs — negotiate the scope carefully.
The ACL constraint: to the extent a customer guarantee cannot be excluded by law, your liability for a failure of that guarantee must remain uncapped (or capped at remedying or replacing the service, or refunding its cost), depending on whether the failure was major. Structure your clause to acknowledge this rather than attempt to exclude it, which would be void in any event.
Termination and what happens to data
Specify the triggers for termination:
- For convenience: either party may terminate on notice (typically 30 days), subject to pro-rata fee adjustments.
- For cause: breach by either party, subject to a cure period (commonly 14–30 days for remediable breaches); immediate termination for insolvency, fraud or serious security breach.
- On expiry: if the subscription term ends and is not renewed, that is not termination for cause — but the same data-return obligations should apply.
The data-return clause is frequently underdrafted. State how long you will retain customer data after termination (30–90 days is typical), in what format it can be exported, and what happens to it after that period. Enterprise customers will negotiate this carefully, particularly where the data has regulatory retention requirements of its own.
Optional and situational clauses
Not every SaaS agreement needs all of these, but each has a clear trigger:
- Data processing agreement (DPA): required when you process personal information on behalf of a customer who is itself regulated by the Privacy Act 1988 (Cth) or by overseas data protection law (such as the GDPR). The DPA sets out the precise processing instructions and sub-processor obligations in detail that the main terms leave flexible.
- Audit rights: enterprise and government customers may require the right to audit your security controls or data handling practices. If you accept this, narrow the frequency (once per year), the notice period (at least 30 days), and the cost-allocation (customer bears its own costs unless a material breach is found).
- Confidentiality: if the main terms do not already include a standalone confidentiality clause, add one — particularly for B2B platforms where the customer will be uploading sensitive business information.
- Force majeure: excludes liability for events outside a party's reasonable control (infrastructure outages caused by third-party providers, natural disasters, cyberattacks by nation-state actors). Relevant for platforms with uptime commitments.
- Jurisdiction and governing law: specify New South Wales (or whichever state suits your business) as the governing law and the courts of that jurisdiction for disputes. Without this, an overseas customer may argue their local law applies.
How Artificer Legal can help you get this right
SaaS terms require legal judgement, not just template-filling. The clauses that look routine on the surface — liability caps, UCT compliance, data handling, acceptable use — are precisely where disputes crystallise and where ill-considered drafting costs the most.
At Artificer Legal, our practitioners review and draft SaaS terms with a focus on the clauses that carry the real commercial weight. We push back on liability carve-outs that expose you to unlimited claims, tighten acceptable use and suspension rights so they actually work when you need them, and ensure your terms sit within the boundaries the ACL and the UCT regime impose. For enterprise sales, we negotiate the DPA and security exhibit alongside the main terms, so your standard document set is enterprise-ready from the start.
The order in which we tackle these matters: access rights and IP first (because they define the product), then liability and warranties (because they define your exposure), then data and security obligations (because enterprise procurement will not proceed without them). Fees and renewal mechanics are usually the last point of negotiation but the first place disputes appear in practice.
The clause that most often determines who wins
Liability caps and exclusions are skipped, abbreviated or borrowed from unrelated templates more often than any other clause in a SaaS agreement — and they are the clause a court turns to first when something goes seriously wrong. A well-drafted cap protects you from catastrophic exposure; a poorly drafted one either fails to limit your liability (because the carve-outs swallow the cap) or is void in part (because it purports to exclude non-excludable ACL guarantees).
The deeper point is this: SaaS terms are not a compliance checkbox. They are a live operational document that governs every customer relationship on your platform. They need to reflect your actual architecture, your actual pricing model and your actual data handling practices — and they need to be reviewed when any of those things change. A document that accurately described your product at launch may actively mislead customers (and expose you under the ACL's misleading conduct provisions) after a major feature change, a pricing restructure, or a shift to offshore infrastructure.