What Legal Documents Does a Subscription Software Business Need in New Zealand?

Alex Solo
byAlex Solo12 min read

Subscription software businesses often move fast on product, pricing and growth, then discover the legal documents were treated as an afterthought. That can cause real problems. A founder accepts a supplier’s standard terms without checking liability caps, puts a privacy statement on the website that does not match how customer data is actually handled, or starts charging recurring fees without clear cancellation and renewal wording. These mistakes usually surface when a customer complains, an enterprise client pushes back on the contract, or a data issue forces everyone to look closely at the paperwork.

The right legal documents for a subscription software business in New Zealand do more than tick a box. They help define what you are selling, who owns the IP, when customers can cancel, what happens if service levels slip, and how personal information is collected and used. This guide explains which documents matter most, what each one should cover, and where founders commonly get caught before they sign, onboard customers or accept another party’s standard terms.

Overview

A New Zealand SaaS or subscription software business usually needs a core set of customer, supplier, privacy and internal IP documents that match the way the product is sold and delivered. The exact mix depends on whether you sell self-serve subscriptions, negotiate enterprise deals, handle personal information, use contractors, or rely on third party infrastructure and integrations.

  • customer terms of service or a software subscription agreement
  • a privacy policy that reflects your actual data handling practices under the Privacy Act 2020
  • a data processing or data protection schedule where commercial customers expect more detail
  • service level terms, support terms, and clear renewal, billing and cancellation provisions
  • contractor, employee and founder IP clauses so the business owns the code, content and product assets
  • supplier agreements with cloud, development, payment and integration providers
  • confidentiality provisions and, where needed, stand-alone NDAs before deeper commercial discussions
  • fair marketing, pricing and refund wording that fits New Zealand consumer law obligations

The key point is simple: your legal documents should reflect the actual way your software is sold, delivered and supported in New Zealand. A generic overseas template often misses local consumer, privacy and contracting issues, and that is where founders often get caught.

Customer terms are the backbone of the business

If you offer self-serve sign-up, your website or checkout flow will usually need well-drafted customer terms of service. If you negotiate directly with larger customers, you may instead use a software subscription agreement or master services agreement with an order form.

Those documents should clearly deal with the commercial basics, including:

  • what the customer is subscribing to
  • fees, billing cycles and when price changes can occur
  • auto-renewal mechanics and how notice is given
  • cancellation rights, suspension rights and termination events
  • licence scope, user limits and acceptable use restrictions
  • service availability, maintenance windows and support response expectations
  • ownership of the platform, customer data and any customer-specific deliverables
  • warranties, disclaimers and liability caps
  • what happens on exit, including data return or deletion
  • dispute, governing law and notice clauses

Before you accept the provider’s standard terms from a template source, check whether they fit recurring billing, free trials, usage-based charging, implementation services and any onboarding commitments your sales team is actually making.

Privacy documents matter early, not later

If your software collects personal information, your privacy paperwork needs to match your real process from day one. In New Zealand, the Privacy Act 2020 affects how businesses collect, use, store and disclose personal information. Subscription software often handles names, email addresses, billing details, user analytics, support tickets and sometimes customer employee or end-user data.

Your privacy policy should explain, in plain language:

  • what personal information you collect
  • why you collect it
  • how you store and protect it
  • whether you share it with third party providers
  • whether information is held or accessed overseas
  • how people can request access to or correction of their information
  • who to contact about privacy questions

For business customers, a broader contract may also need a data protection schedule covering roles, security expectations, breach notification and subcontracting. Enterprise customers often ask for this before they sign, especially where your software processes staff or customer data on their behalf.

IP ownership documents protect the value of the software

If the business does not clearly own the software and related assets, the main asset of the company can become uncertain. That problem usually starts with founders, contractors or developers building product features without proper assignment clauses.

To reduce that risk, check that:

  • founder arrangements make it clear who owns pre-existing and newly created IP
  • employee agreements include IP ownership, confidentiality and moral rights wording where appropriate
  • contractor agreements assign IP to the business and deal with background materials and open source use
  • development agreements define deliverables, acceptance, warranties and ownership carefully

Before you spend money on setup or product expansion, make sure the company, not an individual developer or consultant, is the legal owner of the codebase, designs, product documentation and brand assets that matter.

Supplier contracts are often overlooked

Your own customer contract is only half the picture. Most subscription software businesses depend on cloud hosting, payment processors, CRM systems, email tools, support platforms, analytics providers and external developers. Those upstream contracts can create downstream risk if their service commitments, security obligations or liability settings do not line up with what you promise customers.

This is especially relevant if you offer uptime commitments, store sensitive information, or build key features on top of third party APIs. If a supplier can suspend your account quickly or exclude almost all liability, your customer promise may be much harder to honour.

Consumer law can still apply

Some subscription software businesses sell only to other businesses. Others sell to sole traders, startups and consumers, or operate a mixed model. That matters because New Zealand consumer law can affect what terms are enforceable, how you describe features, and whether broad disclaimers will hold up.

The Fair Trading Act 1986 affects how you market your product. Claims about performance, integrations, savings, compliance or AI capability should be accurate and supportable. If the Consumer Guarantees Act 1993 applies to a customer relationship, you also need to be careful about standard exclusions. Business-to-business contracting out can be possible in some cases, but the wording and context need to be right.

Before you sign a customer, supplier or development contract, make sure the document matches how the software business actually works. Founders often focus on price and term length first, but the harder issues usually sit in data, IP, liability and exit provisions.

Recurring fees, renewals and cancellation rights

Subscription businesses live and die on recurring revenue, so the contract needs to state exactly when charges start, how often they recur and what happens on renewal. Vague language creates disputes fast.

Check the wording around:

  • trial periods and when a paid subscription begins
  • monthly versus annual billing
  • automatic renewal and notice periods
  • mid-term upgrades or downgrades
  • non-payment, failed cards and suspension rights
  • refund policy and whether prepaid fees are non-refundable
  • who can cancel and how cancellation must be given

Before you rely on a verbal promise from sales or customer success, make sure the signed terms deal with these points clearly.

Service levels and support promises

If your team is talking about uptime, support response times or implementation assistance, those promises should appear in the contract or be carefully limited. Loose sales language can create expectations your product team never agreed to meet.

For many businesses, it makes sense to spell out:

  • support hours and support channels
  • target response times, if any
  • scheduled maintenance windows
  • what counts as downtime
  • any service credits and how they are claimed
  • what is excluded, such as third party outages or customer configuration issues

If you do not offer formal service levels, say that clearly rather than implying enterprise-grade commitments in marketing and staying silent in the contract.

Data use, security and breach response

Data clauses deserve close attention before you sign, especially where the customer asks security questions late in the deal. The legal issue is not only privacy compliance. It is also whether your team can realistically meet the promises in the contract.

Review points such as:

  • what customer data you are allowed to use and for what purpose
  • whether aggregated or de-identified data can be used for analytics or product improvement
  • minimum security commitments you are prepared to give
  • who must notify whom if there is a privacy or security incident
  • whether offshore hosting or subcontractors are involved
  • what happens to data on termination

If an enterprise customer sends a long security schedule, do not assume it is standard. Some schedules include audit rights, broad indemnities, or strict timelines that may not fit a smaller software business.

IP, custom work and customer content

Most SaaS deals are based on a licence, not a transfer of ownership. That distinction should be obvious in the contract. Problems often arise where the business also agrees to custom development, migration work or feature requests.

Before you sign, decide:

  • who owns the platform and underlying software
  • who owns custom configurations, reports or integrations
  • whether the customer receives a limited licence or broader rights
  • whether feedback can be used to improve the product
  • whether the customer promises it has rights to upload its content and data

This is where founders often get caught in enterprise negotiations. A customer may ask to own any deliverable connected with the project, but that wording can accidentally sweep in parts of the core platform.

Liability, indemnities and risk allocation

The liability clause decides how much financial risk sits with each party if things go wrong. Many founders glance at it, then sign, but it is one of the most commercial parts of the agreement.

Key issues include:

  • whether liability is capped, and at what level
  • whether the cap applies per claim or in total
  • which losses are excluded, such as indirect or consequential loss
  • whether fees paid in the last 12 months are used as the cap benchmark
  • whether there are uncapped risks, such as confidentiality, IP infringement or privacy breaches
  • whether either side gives an indemnity, and how wide it is

Before you sign, compare the legal risk to the contract value. A low-fee SaaS subscription should not usually carry open-ended exposure just because a customer says its template is non-negotiable.

Term, termination and exit planning

Exit rights matter even when the relationship looks promising. They become crucial if a customer stops paying, your product changes direction, or a supplier’s service no longer works for your stack.

The agreement should address:

  • initial term and renewal term
  • termination for breach and any cure period
  • termination for convenience, if offered
  • suspension rights for misuse or non-payment
  • what happens to access, data and confidentiality after termination
  • whether assistance with transition or export is included or charged separately

A practical exit clause prevents the end of the relationship becoming a dispute about data access, unpaid fees or ongoing licence rights.

The most common mistake is using legal documents that describe a different business model from your own. A software business with monthly renewals, implementation services and customer data processing needs more than a basic website terms template.

Using overseas SaaS templates without local review

US and UK templates often contain concepts that do not sit neatly with New Zealand law or market practice. They may also ignore local consumer issues, use foreign governing law, or include aggressive clauses your customer base will not accept.

A template can be a starting point, but it should not be the final answer before you sign or get a proper contract review.

Promising more in sales than the contract supports

Founders often say yes to security questionnaires, onboarding promises, custom timelines or integration outcomes to close the deal. If those points are not reflected properly in the contract, the business can end up carrying obligations it cannot prove or limit.

Keep sales language, proposal documents and final written terms aligned. That reduces the risk of later arguments about what was promised.

Forgetting that contractors can own the code they write

Paying for development does not automatically mean your business owns the resulting IP. Without a proper agreement, a contractor may retain rights in the code, documentation or designs they created.

This becomes a serious problem during investment due diligence, a sale process or a founder dispute. Clean IP assignment documents are much easier to obtain early than after relationships have soured.

Copying a privacy policy that does not match reality

A privacy policy should describe your actual practices, not an ideal version copied from another company. If your product uses overseas hosting, analytics tools, AI providers or subcontracted support, the wording should reflect that accurately.

A mismatch between the policy and your real process can undermine customer trust and create compliance problems at exactly the wrong time.

Ignoring supplier terms until there is an outage

Many businesses scrutinise customer contracts and click through supplier terms without much thought. The problem appears later, when a third party changes pricing, suspends an integration, limits support or suffers an incident that affects your own customers.

Before you accept the provider’s standard terms, check whether they let the supplier:

  • change the service materially on short notice
  • suspend or terminate easily
  • use your data broadly
  • exclude almost all liability
  • pass security and compliance risk back to you

Missing the difference between B2B and consumer customers

Some software businesses assume all users are businesses because the product is work-related. That is not always enough. If individuals, sole traders or very small operators are signing up through a self-serve flow, consumer law questions can still arise.

The safer approach is to define your customer base clearly and make sure your pricing, cancellation, refund and disclaimer wording fits that audience.

FAQs

Do I need both website terms and a separate SaaS agreement?

Not always. If you sell through a self-serve online model, one set of customer terms may be enough if it is drafted for subscription software. If you negotiate larger deals, you may also need a separate agreement or order form for enterprise customers.

Does a subscription software business in New Zealand need a privacy policy?

Usually, yes, if you collect personal information through the product, website, support channels or billing process. The policy should match your actual data handling and align with your obligations under the Privacy Act 2020.

Who owns the software if a contractor built it?

Do not assume the business owns it automatically. Ownership depends on the contract and the surrounding facts. A written contractor agreement with clear IP assignment wording is the safest approach.

Can I limit my liability in customer terms?

Often, yes, but the clause needs to be drafted carefully and may be affected by the customer type and the surrounding law. Broad exclusions copied from overseas templates may not be the best fit for a New Zealand subscription software business.

What if an enterprise customer sends its own contract?

You should review it before you sign. Customer paper often shifts risk on privacy, security, indemnities, service levels and termination in ways that are much broader than the deal value justifies.

Key Takeaways

  • The right legal documents for subscription software business in New Zealand usually include customer subscription terms, privacy documents, IP ownership clauses, supplier agreements and clear billing, renewal and cancellation wording.
  • Your contracts should reflect the real product, sales process and support model, not a generic overseas SaaS template.
  • Privacy, offshore data handling, customer data use and breach response need careful drafting, especially for enterprise deals.
  • IP ownership should be locked down with founders, employees and contractors before you rely on the value of the software.
  • Liability caps, indemnities, service levels and exit rights deserve close review before you sign.
  • Mixed B2B and consumer customer bases can create extra issues under New Zealand consumer and fair trading laws.

If you want help with customer terms, privacy documents, IP ownership clauses, supplier contracts, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.