SaaS agreement
How to Review a SaaS / Subscription Agreement in India
A SaaS or subscription agreement is the contract that governs software you rent instead of own, accessed over the internet and paid for on a recurring cycle. Most people skim the order form for the price and the seat count and skip everything else, which is backwards. The order form is usually the least dangerous page. The risk sits in the linked "Terms of Service," the SLA schedule, and the DPA, documents most buyers never open before clicking "I Agree." (This guide is published by Adira, which makes contract review and CLM software, a commercial interest in you reading contracts carefully, but it is written to be useful whether or not you ever use our product.) This is a clause-by-clause walk through what to check in an Indian SaaS agreement, what Indian law says about the traps vendors build in, and a checklist to run before you sign.
What a SaaS agreement actually is, and the business deal first
A SaaS deal is rarely one document. It is usually three, stacked: the order form (price, tier, seats, term), the Terms of Service or Master Subscription Agreement (the real legal terms, often a standing website document the order form incorporates by reference and the vendor can change unilaterally), and schedules, the SLA and the DPA, sometimes bundled in, sometimes separate documents you must specifically ask for.
None of this needs a wet-ink signature to bind you. Section 10A of the Information Technology Act, 2000 means a contract formed by clicking "I Agree," or by continuing to use a service after seeing the terms, is not unenforceable merely because it happened on a screen, the same reasoning the Supreme Court applied to email-formed contracts in Trimex International FZE Ltd v Vedanta Aluminium Ltd, (2010) 3 SCC 1. The ToS you never read is still probably binding, so review it before you click. Full detail: are electronic signatures legally valid in India.
Before reading a single clause, fix three commercial facts. What exactly are you buying, a named seat count, a usage tier, or unlimited access, since vague scope makes every other clause harder to enforce. What is the tool actually used for, a CRM holding customer PII carries different stakes than an internal design tool. And who else should see this contract, IT for security and uptime, finance for auto-renewal and GST, legal for liability and termination, routed before signing, not after.
Clause by clause
Subscription scope and authorised users. Check what "a user" means, a named individual, a concurrent seat, or an email domain, and whether the vendor can audit and charge a true-up if you exceed the licensed count. A true-up clause with no cap or notice lets a vendor bill retroactively for growth you never flagged.
Fees and auto-renewal. The trap is never the renewal itself, it is the notice window, the number of days before renewal during which you must actively cancel or the contract rolls over, often with a price increase baked in. The Central Consumer Protection Authority's 2023 dark-patterns guidelines specifically name "Subscription Trap" and "SaaS Billing" as regulated practices, and freedom of contract under the Indian Contract Act, 1872 does not stop the notice-window mechanics from being one-sided in a B2B deal. Full mechanics and the worked calendar: auto-renewal and evergreen clauses in India.
SLA and uptime credits. The number that matters is not the uptime percentage, it is what you get when the vendor misses it. Almost every SLA pays a service credit, a rebate on fees, not real compensation, and states that credit is your "sole and exclusive remedy." Under Section 74 of the Contract Act, that named credit is treated as a ceiling, so check the cap against what an outage would really cost you. Full uptime maths and the Kailash Nath Associates case: SLA clauses explained for India.
Data protection and the DPA. Under the Digital Personal Data Protection Act, 2023, your company is almost certainly the "Data Fiduciary" for any personal data in the tool, employee, customer, or applicant data, and the vendor is the "Data Processor." Section 8(2) requires that engagement to run "only under a valid contract":
"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract." Source: Section 8, Digital Personal Data Protection Act, 2023
Section 8(1) keeps you, the fiduciary, responsible for the processor's conduct, so a vague "Vendor will keep data confidential" line does not discharge your own statutory duty. Check that the DPA names the roles, restricts the vendor to your instructions only, states a real security standard, and sets a breach-notice window well inside your own 72-hour reporting clock under the DPDP Rules, 2025. More depth: the DPDP data protection clause and data processing agreement clauses.
Security. Look for a stated standard, encryption, access controls, a named framework like ISO 27001 or SOC 2, rather than the undefined word "appropriate," and check whether it sits inside or outside the liability cap.
IP and feedback licence. You own your own data and content, stated explicitly, not assumed. Watch the "feedback licence": many ToS grant the vendor a broad, perpetual, royalty-free licence over any suggestion or bug report you send, wide enough to sweep in confidential information shared in a support ticket.
Limitation of liability: the fees-paid cap trap. This clause decides what every other promise above is actually worth. Most SaaS agreements cap total liability at a multiple of fees paid, commonly 12 months, excluding indirect and consequential damages entirely. On a discounted pilot or a low-cost tool holding critical data, that cap can be a small fraction of real exposure. Indian courts generally respect a negotiated cap and only strike one down under Section 23 where it is genuinely unconscionable, following Central Inland Water Transport Corporation Ltd v Brojo Nath Ganguly, 1986 AIR 1571. Do not count on that doctrine; negotiate the cap instead. Full mechanics and a worked rewrite: limitation of liability clauses in India.
Warranties and disclaimers. SaaS vendors typically disclaim everything they can, "AS IS," "WITHOUT WARRANTY OF ANY KIND." Check for at least a bare minimum, material conformance to documentation and no knowingly introduced malicious code, or you have nothing to point to if the tool simply does not work as promised.
Suspension for non-payment. Most contracts let the vendor suspend access, sometimes with no notice, for a late invoice. Check the grace period, whether you get a warning first, and whether suspension also blocks data export mid-dispute, a vendor that can suspend and lock your data at once holds enormous leverage.
Termination and data export or return. Check the export format (usable, not a proprietary dump), the retrieval window after termination before deletion, commonly 30 to 90 days, and whether export is free. Silence here lets the vendor decide, once the relationship has soured, how cooperative to be.
Unilateral "we may change these terms" amendment risk. Nearly every SaaS ToS reserves the vendor's right to update terms at any time, taking effect just by posting online, with continued use as your acceptance. Section 62 of the Contract Act lets parties vary a contract by agreement, but "agreement" is doing a lot of work in a clause where only one side actually agrees to anything. Push for advance notice and a right to terminate before a material change binds you. Full analysis: variation and amendment clauses in India.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| "User" defined precisely, with a capped, notified true-up process | Vague scope, or unlimited retroactive true-up billing | Billed for growth you never agreed to track against a cap |
| Non-renewal notice window is a specific number of days | "Reasonable notice," or a short window (7-15 days) easy to miss | Cannot calendar a deadline that is not written down |
| SLA credit is a primary remedy, with carve-outs for gross negligence | Credit is the "sole and exclusive remedy," no carve-outs | Recovery for a serious outage capped at a small rebate |
| DPA names Fiduciary/Processor roles, restricts processing to instructions | No DPDP role allocation, vendor free to use data broadly | Ambiguity over who answers to the Data Protection Board |
| Security standard is named and specific (encryption, ISO 27001) | Only "appropriate" or "reasonable," undefined | Nothing to hold the vendor to beyond the statute's own vague floor |
| Liability cap is a meaningful multiple of fees | Cap is one month's fees on a business-critical tool | A near-zero cap means near-zero recourse for a serious failure |
| Export format usable; retrieval window 30 days or more | No stated format, or a short window before deletion | Lose access to your own data during an offboarding dispute |
| Amendments need advance notice and a right to exit first | "We may update Terms at any time," continued use as acceptance | Agree today to terms the vendor changes tomorrow, no real consent |
Bad clause, better clause
Bad (a composite of clauses that show up constantly in vendor-drafted SaaS terms): "Company may update these Terms at any time by posting the revised Terms on its website, and Customer's continued use of the Service constitutes acceptance. Customer's sole and exclusive remedy for any failure to meet the Service Level shall be the service credit set out in Schedule A, capped at 5% of the fees paid in the month of the incident. Company's total liability under this Agreement shall not exceed the fees paid by Customer in the one (1) month preceding the claim. Upon termination for any reason, Company shall have no obligation to provide Customer's data in any format."
Better: "Company shall give Customer at least thirty (30) days' written notice, by email to Customer's designated contract owner, before any amendment to these Terms takes effect; Customer may terminate for convenience before that date if it does not accept the change. Customer's Service Credit under Schedule A is its primary remedy for a Service Level failure but does not limit Customer's right to terminate for repeated failures, or to claim for Company's gross negligence or wilful misconduct. Company's total liability under this Agreement shall not exceed an amount equal to the fees paid by Customer in the twelve (12) months preceding the claim, except for breaches of confidentiality, Company's indemnity obligations, or Company's gross negligence or wilful misconduct, for which liability shall not exceed three (3) times that amount. On termination, Company shall make Customer's data available for export in a commonly used, machine-readable format for at least sixty (60) days, at no additional charge, before deletion."
What changed: silent unilateral amendment became notice-and-exit; the SLA credit gained carve-outs instead of being the sole remedy; the cap moved from one month to twelve, with a higher super-cap for what matters most; and data export became a stated, time-bound, free obligation.
Printable checklist
- Seat/usage count defined precisely, with a capped, notified true-up process
- Auto-renewal notice window is a specific, calendared number of days; price rise capped
- Uptime measured monthly; exclusions narrow; SLA credit is not the sole remedy
- DPA names Fiduciary/Processor roles; processing limited to your instructions
- Vendor breach-notice window sits inside your own 72-hour reporting clock
- Data location stated, with notice before it changes
- Security standard is specific (encryption, access controls, a named framework)
- You own your own data and content; feedback licence is limited
- Liability cap is a real multiple of fees, with carve-outs for fraud and IP infringement
- At least a bare warranty of conformance to documentation exists
- Suspension for non-payment needs a grace period, notice, and does not block data export
- Post-termination export window is 30+ days, usable format, no extra charge
- Amendment to standard terms requires notice and a right to exit first
- GST treatment and governing law/forum are both stated clearly
India execution notes
DPDP roles. Your company is almost always the Data Fiduciary and the SaaS vendor the Data Processor for any personal data in the tool. This is not paperwork: Section 8(1) keeps the fiduciary responsible for the processor's conduct, so the DPA is how you push that operational risk back onto the vendor by contract, since the statute will not let you shift the underlying legal responsibility.
GST on SaaS. A SaaS subscription is a supply of service, classified under SAC 9983, taxed at the standard 18% rate. Buying from an Indian vendor, expect this on the invoice as CGST plus SGST, or IGST inter-state. Buying from a foreign vendor with no India presence, Section 14 of the Integrated Goods and Services Tax Act, 2017 puts the tax obligation on the foreign supplier for a sale to a "non-taxable online recipient":
"On supply of online information and database access or retrieval services by any person located in a non-taxable territory and received by a non-taxable online recipient, the supplier of services located in a non-taxable territory shall be the person liable for paying integrated tax on such supply of services." Source: Section 14, Integrated Goods and Services Tax Act, 2017
If your business is GST-registered, that route usually does not apply, and GST is instead payable by you under reverse charge as an import of service, unless the foreign vendor has separately registered in India and is charging GST directly. Confirm which regime applies before you assume the quoted price is final.
Cross-border data. Section 16 of the DPDP Act allows transfer outside India by default, restricting only countries the government names by notification, none so far. The contract should still state where the vendor processes and stores data, and require notice before that location changes.
When a lawyer is worth it, and the US contrast
This checklist gets you through most SaaS agreements on your own, especially low-stakes tools. Bring in a lawyer for a large committed spend, personal data at real scale, a liability cap you cannot move in negotiation, or any clause that departs from what this guide describes as normal. A DPA for a payroll or health-records platform deserves a specialist's eyes.
Globally, the mechanics look similar, seats, SLAs, credits, caps, unilateral amendment, but US courts generally enforce a "sole remedy" or amendment clause as written, with no statutory filter comparable to Sections 23 and 74 of the Indian Contract Act asking whether the outcome is reasonable. The US also has no single federal law comparable to the DPDP Act, so a DPA drafted for a US customer may not map cleanly onto what an Indian Data Fiduciary needs.
FAQ
Do I need to sign a SaaS agreement for it to bind me in India? No. Under Section 10A of the IT Act, 2000, clicking "I Agree" or continuing to use the service after seeing the terms is enough to form a binding contract. Review the terms before you click.
Is the SLA credit the only compensation I can get if a SaaS outage hurts my business? Usually yes, if the clause names it your sole and exclusive remedy, which Indian courts generally enforce between commercial parties. Negotiate a carve-out for gross negligence or repeated failures if this risk matters to you.
Who is responsible for DPDP compliance, me or my SaaS vendor? You are, as the Data Fiduciary, for any personal data you put into the tool. Section 8(1) of the DPDP Act keeps you responsible for a vendor's processing, so the DPA is how you push accountability back onto them by contract.
Can a SaaS vendor legally change its Terms of Service without telling me? Most ToS reserve exactly that right, effective just by posting online, but genuine consent to a future, unseen change is legally shaky. Push for advance notice and a right to terminate before a material change binds you.
Does GST apply if I buy a SaaS subscription from a foreign company? Often yes, but who pays depends on your GST registration and the vendor's India presence. A registered business typically pays under reverse charge as an import of service, unless the foreign vendor has registered under India's OIDAR scheme and charges it directly.
You can mark up a SaaS agreement clause by clause, for free, in Weave, before you push back on a vendor's standard terms.
This guide gets you to a working understanding of what a SaaS or subscription agreement should contain and what Indian law says about the traps that show up most often. It does not tell you whether a specific clause in your specific contract is enforceable, or fair for your deal size and risk, that depends on the exact wording and facts, and is not legal advice. Talk to a lawyer before you sign a SaaS agreement involving significant spend, sensitive data, or terms that depart from what this guide describes as normal.
Frequently asked questions
- Do I need to sign a SaaS agreement for it to bind me in India?
- No. Under Section 10A of the Information Technology Act, 2000, clicking "I Agree" or continuing to use the service after seeing the terms is enough to form a binding contract. Review the terms before you click, not after.
- Is the SLA credit the only compensation I can get if a SaaS outage hurts my business?
- Usually yes, if the clause names it your sole and exclusive remedy, which Indian courts generally enforce between commercial parties as a limitation of liability. Negotiate a carve-out for gross negligence or repeated failures if this risk matters to you.
- Who is responsible for DPDP compliance, me or my SaaS vendor?
- You are, as the Data Fiduciary, for any personal data you put into the tool. Section 8(1) of the Digital Personal Data Protection Act, 2023 keeps you responsible for a vendor's processing, so the DPA is how you push accountability back onto them by contract.
- Can a SaaS vendor legally change its Terms of Service without telling me?
- Most Terms of Service reserve exactly that right, effective just by posting the change online, but genuine consent to a future, unseen change is legally shaky under ordinary contract principles. Push for advance notice and a right to terminate before a material change binds you.
- Does GST apply if I buy a SaaS subscription from a foreign company?
- Often yes, but who pays it depends on your GST registration status and the vendor's India presence. A GST-registered business typically pays GST on the import of the service under reverse charge, unless the foreign vendor has registered under India's OIDAR scheme and is charging it directly.
- What should I check first if I only have time to review one part of a SaaS contract?
- The liability cap and whether the SLA credit is the sole remedy. Together they decide what every other promise in the contract is actually worth if the vendor fails badly.
Sources
- Section 8, Digital Personal Data Protection Act, 2023 (MeitY)
- Section 14, Integrated Goods and Services Tax Act, 2017 (CBIC)
- Section 74, Indian Contract Act, 1872 (Indian Kanoon)
- Section 23, Indian Contract Act, 1872 (Indian Kanoon)
- Section 10A, Information Technology Act, 2000 (Indian Kanoon)
- Trimex International FZE Ltd v Vedanta Aluminium Ltd, (2010) 3 SCC 1 (Indian Kanoon)
- Guidelines for Prevention and Regulation of Dark Patterns, 2023, Department of Consumer Affairs
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free