This website uses cookies

Read our Privacy policy and Terms of use for more information.

Laura Frederick, Chief Executive Officer of How to Contract, hosted this session with Patti Barnard, Founder of Patricia Salas Barnard PLLC, and Tiffany Bui LeTourneau, Partner at Apogee Law. Patti spent more than 20 years in-house, 15 of them in benefits administration, before opening her own fractional practice. Tiffany built her career at the intersection of law and technology and now handles commercial product and corporate work for tech companies. Both of them negotiate from the vendor seat and the customer seat, which meant nearly every answer arrived with the other side's argument attached.

They worked through the fundamentals in order, starting with what a customer actually receives in a subscription and why exit planning belongs at the front of the deal rather than the end. From there they covered the document stack and order of precedence, renewal and consumption pricing, service level commitments and the termination rights that make them worth anything, data and security terms a customer can actually enforce, how to define usage data, and the liability caps that set the value of every other promise in the agreement.

Here are our top ten takeaways from the speakers' comments during the webinar:

  1. Treat every SaaS deal as a data contract. You never own the software, you cannot run it yourself, and your data sits in an environment the vendor controls, often across subprocessors you did not pick. Breach, misuse, lockout, and regulatory inquiry all flow from that one fact. Patti captured it as a data custody agreement wearing a software subscription costume, and that framing tells you where to spend your review time.

  2. Plan the exit while everyone is still excited about going live. Signature energy goes into launching, and off-boarding turns out to be the hardest part of the relationship. Ask now how fast and how cleanly you can pull your data out in three years, because you will not get a better answer later. Patti checks for it immediately on every deal, and the ability to move forward when a vendor fails is usually the biggest risk you carry.

  3. Read the order form alongside the master agreement. The commercials define the deal more than the legal terms do. Seat counts, usage tiers, named users, and API call limits determine what you paid for and where overage charges land. Reviewing the master agreement on its own tells you the general rules and nothing about what you actually bought, so anything left out of the order form becomes the argument later.

  4. Set your order of precedence on purpose. Tiffany's three-part structure is a useful default, with the master agreement and its exhibits at the base, online policies subordinate to the negotiated contract, and the order form on top. Watch the overlap between personal data and confidential information, since your general terms and your data processing agreement can impose different obligations on the same information. Say plainly which document governs what.

  5. Make a renewal cap a condition of agreeing to auto-renewal. Silence on renewal pricing hands the vendor the next number, and most teams have no reliable tracker for the notice date. Ask for a cap in the 2 to 5 percent range, or the prior year's consumer price index increase, whichever comes in lower. Read the bottom of the order form too, because automatic annual increases hide in small text with an asterisk.

  6. Agree overage rates and bundling protection before signature. Exceed your seats or your storage without an agreed rate and the bill arrives after the fact, with no way back down without reopening the deal. Ask for protection so a vendor splitting its product into separate SKUs cannot charge you again for what you already licensed. The same discipline applies to consumption pricing, where you need to know precisely how the vendor defines a unit.

  7. Look past the uptime number to the exclusions. A 99.9 percent commitment reads well until you subtract scheduled maintenance, emergencies, degraded performance, and third party outages. Credits are normally engineered small, around 2 to 3 percent, and capped in total per quarter. Price the promise by what survives the exclusions rather than by the headline figure.

  8. Ask for a termination right when the misses keep coming. Credits do not fix a product that keeps failing, so push for a tier that lets you walk away after repeated misses. Watch for the vendor making the service level agreement your sole and exclusive remedy, because that can strip your breach claim and leave you with no exit. In some cases you are better off with no service level agreement and a clean right to terminate and pursue damages.

  9. Name the security controls you intend to enforce. Reasonable security measures is not a control, and neither is any other broad phrase. Ask for encryption, access management, a current SOC 2 report or equivalent, a named subprocessor list, quantified notice when controls change, and certified deletion at exit. Add Tiffany's third prong of an obligation to remediate what the audit identifies, so a failure to fix becomes a material breach.

  10. Define usage data with thresholds you can test. Most vendors have a legitimate reason to improve the product from usage data, so the fight is over the definition rather than the concept. Aggregated and de-identified mean nothing until you set a minimum number of customers and rule out aggregation inside a single sector. De-identified has to mean nobody can work back to your identity, and it is worth putting your technical lead in front of theirs to confirm how it actually happens.

Subscribe to Stay in the Loop

Every week we send practical contracting guidance, a look at what is coming up on the webinar calendar, and recaps like this one for the sessions you could not attend. Subscribe now and keep the useful material arriving in your inbox.