Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- 1. Scope of service and inclusions
- 2. Fees, renewals and price changes
- 3. Service levels and downtime
- 4. Data ownership, access and use rights
- 5. Privacy and offshore storage
- 6. Security commitments
- 7. Intellectual property and usage restrictions
- 8. Liability caps and indemnities
- 9. Termination, suspension and exit
- 10. Entire agreement and reliance on promises
- Key Takeaways
SaaS contracts can look straightforward right up until something goes wrong. A provider promises easy onboarding, strong security and flexible pricing, but the legal terms often say something much narrower. New Zealand businesses regularly sign too quickly, rely on sales conversations instead of the written contract, or overlook clauses that let the provider change fees, suspend access or limit liability to a tiny amount.
That matters because software often sits at the centre of day to day operations. If your accounting platform, CRM, payroll system, ecommerce tool or customer database goes down, your business can lose revenue fast. The contract is where you find out who carries that risk.
This guide explains what SaaS contracts usually cover, which clauses deserve close attention before you sign, where founders and SMEs commonly get caught, and what practical questions to raise before you accept the provider's standard terms.
Overview
A SaaS agreement sets the legal rules for how your business can access and use software hosted by a provider. The main issue is not just price, it is whether the contract reflects how your business actually depends on the software, your data and the provider's promises.
For most New Zealand businesses, the contract should clearly deal with service scope, uptime, data handling, liability, payment changes, termination rights and what happens to your data when the arrangement ends.
- What services, users, modules and support levels are actually included
- Whether the provider can change fees, features or terms during the contract
- Service levels, outage commitments and any service credit process
- Who owns business data, who can access it and where it is stored
- Privacy Act 2020 issues, especially if personal information is hosted offshore
- Security commitments, incident notification and subcontractor use
- Liability caps, excluded losses and whether those limits are commercially realistic
- Termination rights, minimum terms, auto-renewal and exit assistance
- How you can retrieve your data, in what format, and by when
- Whether sales promises, implementation timelines or integrations are actually written into the contract
What SaaS Contracts Means For New Zealand Businesses
A SaaS contract is not just a software purchase document, it is an ongoing service arrangement that affects operations, compliance and customer relationships. Before you sign a contract, you need to know exactly what you are getting and what happens if the service underperforms.
Unlike old style software licences, SaaS usually means the provider hosts the platform and your business accesses it online. You typically pay a subscription fee, monthly or annually, and the provider keeps control of the infrastructure, updates and release cycle.
That setup creates convenience, but it also shifts key risks into the contract. Your business may not control when changes are rolled out, where data is stored, how backups are handled, or how quickly support responds when something breaks.
Why this matters in practice
For a founder or operations manager, the real question is simple: if the software fails, changes or becomes too expensive, how exposed is the business?
Think about common situations such as:
- Your CRM provider removes a feature your sales team relies on
- Your payroll platform suffers a security incident involving employee information
- Your ecommerce system goes offline during a promotion
- Your project management tool auto-renews for another year before anyone notices
- Your provider stores customer information overseas and you need to explain that to clients or staff
- Your team wants to leave the platform, but the contract says data export is limited or charged separately
Those issues are not unusual. They are often hidden in standard terms that businesses accept without negotiation.
Standard form terms are common, but not always balanced
Most SaaS providers use standard terms and present them as non-negotiable. That does not mean you should treat them as harmless. Even where a provider will not rewrite every clause, businesses can still ask questions, request operational commitments in writing, and negotiate the points that matter most.
The larger and more critical the software, the more carefully the contract should be reviewed. If the system handles sensitive customer data, supports regulated activity, or is deeply integrated into your business processes, weak legal terms can become a serious commercial problem.
New Zealand legal context
New Zealand businesses should also consider local legal obligations that sit around the contract. If the software handles personal information, your business still has responsibilities under the Privacy Act 2020, even if the provider is offshore. If marketing claims are made about functionality, security or integrations, those statements should be accurate and not misleading under the Fair Trading Act 1986.
Depending on the customer and the use case, other obligations may matter too. Some businesses need to think carefully about industry requirements, procurement rules, internal data governance, or contractual commitments they owe to their own customers.
The main point is this: a SaaS provider's standard terms will usually protect the provider first. Your job before you sign is to make sure the document also works for your business.
Legal Issues To Check Before You Sign
The most important SaaS clauses are the ones that decide who bears the operational risk when service, data or pricing does not go to plan. Before you accept the provider's standard terms, read the agreement as if the relationship has already soured.
1. Scope of service and inclusions
The contract should state what you are buying in clear terms. If the provider has promised a specific module, integration, onboarding package, support response time or implementation date, it should appear in the agreement or an attached order form.
Check points such as:
- The exact product name and plan tier
- Included users, storage, transactions or usage thresholds
- Whether setup, migration or training is included
- Support channels and support hours
- Any exclusions, beta features or dependency on third party tools
This is where founders often get caught. A sales call may describe a feature as available, but the contract may say future functionality is not guaranteed.
2. Fees, renewals and price changes
Pricing clauses often look simple, but they can hide broad provider discretion. Before you sign, check whether the provider can increase fees during the initial term, on renewal, or after certain usage triggers.
You should also look at:
- Minimum contract length
- Auto-renewal periods and notice deadlines
- Charges for extra users, API calls, storage or premium support
- Payment terms, late fees and suspension rights
- Whether prepaid fees are refundable on termination
If the software is business critical, surprise fee increases can be hard to absorb because switching providers quickly may not be realistic.
3. Service levels and downtime
If uptime matters to your operations, the contract should say what service standard applies and what happens if the provider misses it. Marketing language about reliability is not the same as a legally binding commitment.
Look for:
- An uptime percentage and how it is measured
- Scheduled maintenance rules
- Support response and resolution targets
- Service credits, and whether they are your only remedy
- Any broad exclusions that make the uptime promise hard to enforce
Service credits can be useful, but they may be small compared with the actual loss to your business. If a system outage would hit revenue, operations or customer commitments, think carefully about whether the contractual remedy is enough.
4. Data ownership, access and use rights
Your business should retain clear rights in its own data. The agreement should also explain what rights the provider has to host, copy, process, analyse or de-identify that data.
Before you rely on a verbal promise, confirm:
- That your business owns or controls its uploaded data
- Whether the provider can use data for analytics, benchmarking or product improvement
- Who can access the data internally and through subprocessors
- How often backups are taken and how restoration works
- How data can be exported during the term and after termination
Data portability matters more than many businesses expect. If the relationship ends badly, the practical ability to extract usable data quickly can decide how disruptive the transition becomes.
5. Privacy and offshore storage
If the platform handles personal information, privacy terms and your privacy notice deserve close attention. New Zealand businesses can still be responsible for how personal information is handled, even when a software provider hosts data overseas.
Questions to ask include:
- Where is the data stored and processed
- Which countries can provider staff or subcontractors access it from
- What technical and organisational safeguards are promised
- How quickly will the provider notify you of a privacy or security incident
- Whether the contract gives enough information for your own privacy disclosures
This area is especially important for HR systems, health related tools, education platforms, fintech products and businesses managing large customer databases.
6. Security commitments
A generic statement that the provider uses industry standard security is rarely enough on its own. If security is a core reason you chose the software, ask for more specific commitments.
Useful contract points may cover:
- Encryption standards
- Access controls and authentication measures
- Vulnerability testing and patching practices
- Incident response obligations
- Audit rights, security reports or compliance certifications where relevant
You do not always need a long security schedule, but you do need enough clarity to assess whether the platform fits your risk profile.
7. Intellectual property and usage restrictions
The provider will usually keep ownership of the software and grant your business a limited right to use it. That is normal. The problem is when usage restrictions are drafted so broadly that ordinary business activity creates technical breach risk.
Check whether the terms restrict:
- Affiliates or contractors accessing the platform
- Use in certain jurisdictions or industries
- API use, integrations or custom development
- Benchmarking or public comments about performance
- Assignment during a sale of your business
If your business may restructure, raise investment or sell assets, assignment and change of control clauses deserve a close look.
8. Liability caps and indemnities
Liability clauses often decide whether the provider bears meaningful responsibility when things go wrong. Many SaaS contracts cap liability at the fees paid in the last 12 months, and exclude indirect, consequential or loss of profit claims entirely.
That may be commercially acceptable for low risk tools. It may be inadequate for software handling sensitive data or core revenue operations.
Pay attention to:
- The total liability cap and whether it applies per claim or in aggregate
- Which claims are carved out of the cap, such as confidentiality or privacy breaches
- Whether the provider gives any indemnity for third party intellectual property infringement
- Whether your business is taking on broad indemnities in return
If the provider asks you to indemnify them for almost anything connected to your use of the platform, that risk allocation may be too one sided.
9. Termination, suspension and exit
The contract should tell you how to leave, not just how to sign up. Before you spend money on setup, check the practical and legal path out of the arrangement.
Look at:
- Termination for convenience rights, if any
- Termination for breach and cure periods
- Provider suspension rights for non-payment, alleged misuse or security concerns
- Data retrieval windows after termination
- Exit support, migration assistance and related charges
A provider's right to suspend access can be especially disruptive. If suspension can happen immediately and broadly, your business may lose access before a dispute is properly resolved.
10. Entire agreement and reliance on promises
If something mattered in the sales process, it should be written down. Many SaaS agreements say the written contract is the entire agreement and that the customer has not relied on outside statements.
That means verbal assurances about integration capability, implementation timing, custom features or future product roadmap may carry little weight unless recorded in the contract.
Common Mistakes With SaaS Contracts
The biggest mistakes usually happen before the first invoice is paid. Businesses often assume the provider's standard paper is routine, but the risk sits in the details no one checks until there is an outage, a data issue or a difficult renewal.
Signing based on the demo, not the contract
A polished demo can create confidence, but demos are not legal commitments. If your team chose the software because of a specific workflow, report, integration or automation, that should be reflected in the written terms.
Ignoring the exit process
Many SMEs focus heavily on onboarding and almost not at all on offboarding. That is backwards. If your data cannot be exported in a usable format, or only within a short window after termination, switching later can become expensive and chaotic.
Accepting broad unilateral change rights
Some contracts let the provider update features, security practices, pricing and even terms of use with minimal notice. That can be manageable for low stakes tools, but risky for software embedded in your business processes.
If the provider can make material changes without giving you a clear right to exit, you may be locked into a moving target.
Overlooking privacy responsibilities
Businesses sometimes assume the SaaS provider alone is responsible for privacy compliance and data protection because the provider stores the data. In reality, your business may still need to explain collection and disclosure practices, respond to access requests and assess whether offshore handling is appropriate.
Not matching the contract to business criticality
Not every SaaS tool needs the same level of review. A low cost internal scheduling tool does not usually justify the same legal effort as a platform that stores customer records, processes payments or underpins service delivery.
Problems arise when businesses treat a mission critical system as if it were a minor software subscription.
Leaving procurement to one team only
Legal, operations, security and finance often spot different issues. A founder may focus on features, finance may focus on cost, and IT may focus on integrations. If only one person reviews the deal, key risks can be missed.
Assuming larger brands always offer fair terms
Well known software providers often use heavily provider friendly contracts simply because they can. Brand recognition is not the same as balanced risk allocation. Before you sign, read the liability, termination and data clauses as closely as the pricing page.
FAQs
Are SaaS contracts negotiable?
Often, yes. A provider may not change every clause, but many will clarify service scope, adjust notice periods, record privacy or security commitments, or negotiate liability and exit terms for business customers.
Who owns the data in a SaaS platform?
The contract should make this clear, but in many cases the customer retains rights in its business data while the provider owns the software. You should still check what use rights the provider claims over uploaded, derived or de-identified data.
Do New Zealand businesses need to worry about offshore data storage?
Yes. If personal information is involved, offshore hosting and access arrangements can matter under the Privacy Act 2020 and for your own customer or employee disclosures. You should know where data is stored and who can access it.
What if the provider changes the terms after we sign?
That depends on the contract. Some agreements allow unilateral updates, while others limit changes or give customers a termination right if a change is materially adverse. This point is worth checking before you sign.
What is the most overlooked SaaS clause?
Exit and data retrieval terms are often overlooked. A business may only discover the real impact of those clauses when it tries to migrate away under time pressure.
Key Takeaways
- SaaS contracts are ongoing service agreements, not just simple software purchases.
- Before you sign, confirm the written contract matches the provider's promises on features, integrations, support and timing.
- Pay close attention to fees, auto-renewal, service levels, privacy terms, security obligations, liability caps and suspension rights.
- Your business should understand who controls the data, where it is stored, and how you can export it if the relationship ends.
- Standard SaaS terms often favour the provider, especially on liability, unilateral changes and termination.
- The more business critical the software is, the more carefully the contract should be reviewed and negotiated.
If you want help with contract review, privacy and data terms, liability clauses, or exit and data migration terms, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.





