SaaS Subscription Agreement (England & Wales) — England & Wales | IndexLaw Templates
Saas subscription agreementEngland & Wales
SaaS Subscription Agreement (England & Wales)
A business-to-business agreement for a Customer's subscription to a Provider's hosted software service under the law of England and Wales, with service standards, optional service levels, fees, Customer Data, AI-training limits, security, UK GDPR processor terms, IP indemnity, confidentiality, a tiered liability cap and data return on exit.
What it covers
Business-to-business subscriptions to a hosted software service for a fixed or automatically renewing term, governed by the law of England and Wales.
Deals where the Provider processes personal data for the Customer as processor under UK GDPR Article 28.
Optional service levels with service credits, implementation services, hosting location and fee changes on renewal.
What it does not cover
Consumer subscriptions (the template assumes both parties act in the course of business).
On-premises software licences and source-code or SaaS escrow; use a software licence and a separate three-party escrow agreement.
Bespoke development or large managed-services projects needing milestones and acceptance testing.
Regulated outsourcing (for example financial services, health or public sector) needing regulator-mandated terms.
A full negotiated data processing agreement, international transfer clauses and security schedule; the template sets the core processor terms and lets a separate DPA prevail.
Document preview19 sections
INDEXLAW / CONTRACT LIBRARYAGREEMENT TEMPLATE
SaaS Subscription Agreement (England & Wales)
England & Wales
Highlighted blanks are the details your parties fill in.
Parties
This agreement is dated the date on which it is signed by the last of the parties.
This agreement is made between [TO BE CONFIRMED — Customer] (the "Customer") and [TO BE CONFIRMED — Provider] (the "Provider").
Key Terms
"Service" means [TO BE CONFIRMED — Service (the hosted software service, its modules and any usage limits)].
"Authorised Users" means the Customer's employees and individual contractors whom the Customer permits to use the Service, up to the number of users covered by the Subscription Fees.
Related agreements
Explore more templates in this category or region.
A business-to-business SaaS subscription agreement governed by the law of the Abu Dhabi Global Market, with service standards, optional service levels, fees, Customer Data and AI-training limits, security, processor terms under the ADGM Data Protection Regulations 2021, IP indemnity, a tiered liability cap and the exclusive jurisdiction of the ADGM Courts.
Jurisdiction
Abu Dhabi Global Market (ADGM)
"Initial Term" means 12 months starting on the date of this agreement.
"Renewal Term" means each successive period of 12 months.
"Subscription Fees" means [TO BE CONFIRMED — Subscription Fees (amount, currency and basis, e.g. per user per year)].
"Support Services" means the Provider's standard technical support for the Service, as described in the Documentation.
"Service Levels" means availability of the Service of at least 99.5% in each calendar month, excluding maintenance notified at least 48 hours in advance, with a service credit of 5% of that month's Subscription Fees for each 0.5% (or part) by which availability falls short, up to 25%.
"Implementation Services" means [TO BE CONFIRMED — Implementation Services].
"Processing Details" means hosting, storage and other processing of personal data in Customer Data for the Subscription Term and the data export period, in order to provide the Service; the personal data are names, contact details, account and usage details and any other personal data the Customer chooses to submit; the data subjects are the Customer's personnel, its Authorised Users and its customers and contacts.
"Liability Cap" means the total Subscription Fees paid and payable by the Customer in the 12 months before the event giving rise to the claim.
Definitions
"Affiliate" means an entity that controls, is controlled by or is under common control with a party, where control means owning more than 50% of the voting rights or having the power to direct its management.
"Customer Data" means the data, content and materials that the Customer or its Authorised Users submit to the Service, and the output the Service generates from them for the Customer, excluding Usage Data.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and any other law relating to the processing of personal data that applies to a party.
"Documentation" means the user guides, specifications and policies for the Service that the Provider makes available to the Customer, as updated from time to time.
"Subscription Term" means the Initial Term together with any Renewal Terms.
"Usage Data" means data about the operation, performance and use of the Service, such as logs and usage metrics, that does not contain Customer Data.
Subscription
Subject to this agreement, the Provider grants the Customer a non-exclusive, non-transferable right during the Subscription Term for its Authorised Users to access and use the Service and the Documentation for the Customer's internal business purposes.
The Customer is responsible for its Authorised Users' use of the Service. It must ensure that they keep their login credentials confidential and do not share them, and must notify the Provider promptly after becoming aware of any unauthorised access to its accounts.
The Customer must not, and must ensure that its Authorised Users do not: (a) copy, modify, reverse engineer, decompile or create derivative works of the Service, except to the extent the law does not allow this restriction; (b) sell, resell, sublicense or otherwise make the Service available to a third party; (c) use the Service to build a competing product or service; (d) introduce malicious code into the Service, interfere with its operation, or carry out security or load testing on it without the Provider's consent; (e) access the Service other than through the interfaces the Provider provides; (f) use the Service in breach of applicable law, or submit Customer Data that the Customer has no right to use; or (g) use the Service where its failure could reasonably be expected to cause death, personal injury or serious environmental damage.
Service
The Provider must provide the Service with reasonable skill and care, in accordance with good industry practice, and so that it performs materially in accordance with the Documentation.
If the Service does not perform materially in accordance with the Documentation, the Customer must notify the Provider with enough detail to reproduce the problem, and the Provider must use reasonable endeavours to correct it promptly. If it is not corrected within 30 days after the notice, the Customer may terminate the affected subscription by written notice and receive a refund of prepaid Subscription Fees for the unused part of the Subscription Term.
The Provider may update the Service and the Documentation. Unless required by law or to address a security risk, an update must not materially reduce the functionality, performance or security of the Service during the Subscription Term, and the Provider must give reasonable advance notice of any update that materially affects how the Customer uses the Service.
The Provider must provide the Support Services during the Subscription Term at no additional charge.
The Provider must use reasonable endeavours to meet the Service Levels. Service credits stated in the Service Levels are the Customer's sole financial remedy for a failure to meet them, but do not limit the Customer's right to terminate for material breach. A failure to meet the Service Levels in any three months in a rolling 12-month period is a material breach that cannot be remedied.
Implementation
The Provider must perform the Implementation Services with reasonable skill and care and in accordance with any timetable agreed in writing. The Customer must give the Provider the cooperation, information, decisions and access it reasonably requires to perform them.
The Customer must pay [TO BE CONFIRMED — Implementation fees] for the Implementation Services, invoiced on completion and payable in the same way as the Subscription Fees unless the parties agree otherwise in writing.
Suspension
The Provider may suspend access to all or part of the Service only to the extent and for as long as reasonably necessary: (a) to address a material threat to the security or integrity of the Service or to other customers, including one caused by a breach of the Subscription clause; (b) to comply with law; or (c) if an undisputed amount is more than 30 days overdue and remains unpaid 10 business days after the Provider gives written notice of intended suspension. Except in an emergency, the Provider must give prior notice of a suspension under (a) or (b) with its reasons. It must restore access promptly once the reason for the suspension is resolved.
Fees and Payment
The Provider may invoice the Subscription Fees annually in advance. The Customer must pay each valid invoice within 30 days after receiving it, in the currency stated in the Subscription Fees. Except as this agreement expressly provides, Subscription Fees are non-refundable.
If the Customer disputes an invoice in good faith, it must notify the Provider with reasons before payment is due and pay the undisputed part on time. A disputed amount is not overdue, and the Service may not be suspended for it, until the dispute is resolved. The parties must try in good faith to resolve the dispute within 30 days.
All amounts payable under this agreement are exclusive of VAT. The Customer must pay any VAT properly chargeable in addition, on receipt of a valid VAT invoice.
If the Customer fails to pay an undisputed amount by its due date, the Provider may charge interest on it from the due date until payment at 4% a year above the Bank of England base rate, calculated daily. The parties agree that this is a substantial remedy for late payment.
The Provider may change the Subscription Fees with effect from the start of a Renewal Term by giving the Customer written notice at least 30 days before the last day on which the Customer may give notice of non-renewal.
Customer Data
As between the parties, the Customer owns all rights in Customer Data. The Customer grants the Provider a non-exclusive licence, for as long as this agreement requires the Provider to hold Customer Data, to host, copy, process and transmit it only as necessary to provide, secure and support the Service, to perform this agreement and to comply with law. The Customer is responsible for the lawfulness of Customer Data and for having all rights and consents needed for that use.
The Provider may collect and use Usage Data to operate, maintain, secure and improve its products and services. It may disclose Usage Data to third parties only in aggregated form that does not identify the Customer, any Authorised User or any other individual.
The Provider must not use Customer Data to train, fine-tune or otherwise develop any artificial intelligence or machine learning model, other than a model used only to provide the Service to the Customer, without the Customer's prior written consent.
The Provider must host and store Customer Data only in [TO BE CONFIRMED — Hosting location for Customer Data] and must not move it elsewhere without the Customer's prior written consent. This does not prevent remote access permitted under the Data Protection clause.
Security
The Provider must implement and maintain appropriate technical and organisational measures, in line with good industry practice, to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The Provider must notify the Customer without undue delay after becoming aware of a security incident affecting Customer Data, and must give the Customer the information and cooperation it reasonably needs to respond to the incident and meet its legal obligations.
The Provider must back up Customer Data regularly in line with good industry practice, and must maintain, and test at least once a year, a business continuity and disaster recovery plan designed to restore the Service and Customer Data promptly after a disruption.
Data Protection
Each party must comply with Data Protection Law in connection with this agreement. To the extent the Provider processes personal data in Customer Data on the Customer's behalf, the Customer is the controller, the Provider is the processor, and the Processing Details describe the processing. If the parties sign a separate data processing agreement, it prevails over the Data Protection clause to the extent of any conflict.
For personal data that it processes as processor under the Data Protection clause, the Provider must: (a) process it only on the Customer's documented instructions, including those in this agreement, unless the law requires otherwise, in which case it must tell the Customer first unless the law prohibits this, and tell the Customer promptly if in its opinion an instruction breaches Data Protection Law; (b) ensure that persons authorised to process it are bound by confidentiality; (c) protect it as the Security clause requires; (d) taking into account the nature of the processing, assist the Customer in responding to requests from data subjects and in meeting its obligations on security, breach notification, impact assessments and consultation with the regulator; (e) notify the Customer without undue delay after becoming aware of a personal data breach; (f) at the end of the Subscription Term, delete or return it as the Customer chooses, unless the law requires the Provider to retain it; and (g) make available the information needed to demonstrate compliance with this clause, and allow and contribute to audits, including inspections, by the Customer or an auditor it appoints, on reasonable notice and subject to confidentiality.
The Customer authorises the Provider to engage sub-processors. The Provider must keep a current list available to the Customer, give at least 30 days notice before adding or replacing one, bind each sub-processor to data protection terms no less protective than this agreement, and remain liable for its sub-processors. If the Customer objects on reasonable data protection grounds within that period and the objection is not resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid Subscription Fees for the unused part of the Subscription Term.
The Provider must not transfer personal data in Customer Data outside the United Kingdom, or permit a sub-processor to do so, unless the transfer complies with Data Protection Law, including any requirement for appropriate safeguards.
Intellectual Property
The Provider and its licensors own all intellectual property rights in the Service, the Documentation and Usage Data, including improvements to them. Except for the rights expressly granted in this agreement, the Customer acquires no right in them.
If the Customer gives the Provider suggestions or feedback about the Service, the Provider may use them freely without obligation to the Customer, provided that it does not identify the Customer or disclose the Customer's Confidential Information.
Indemnities
The Provider must defend the Customer against any claim by a third party that the Customer's use of the Service in accordance with this agreement infringes that third party's intellectual property rights, and must pay the damages, costs and settlement amounts finally awarded against the Customer or agreed by the Provider in settlement. This indemnity does not apply to the extent a claim arises from Customer Data, a modification not made by or for the Provider, use in combination with items the Provider did not supply or specify, or use in breach of this agreement. If a claim is made or is likely, the Provider may at its cost obtain the right for the Customer to continue using the Service, or modify or replace the Service so that it is non-infringing without materially reducing its functionality, or, if neither is reasonably possible, terminate the affected subscription and refund prepaid Subscription Fees for the unused part of the Subscription Term.
The Customer must defend the Provider against any claim by a third party that Customer Data, or the Customer's use of the Service in breach of the Subscription clause, infringes that third party's rights or breaches applicable law, and must pay the damages, costs and settlement amounts finally awarded against the Provider or agreed by the Customer in settlement.
A party claiming under an indemnity in this agreement must: (a) notify the indemnifying party promptly, although delay relieves it only to the extent it is prejudiced; (b) let it control the defence and settlement, but no settlement may admit fault by, or impose obligations on, the protected party without that party's consent, which must not be unreasonably withheld; and (c) give reasonable cooperation at the indemnifying party's expense. The protected party may join the defence with its own advisers at its own cost.
Confidentiality
"Confidential Information" means information disclosed by or for one party (the discloser) to the other (the recipient) in connection with this agreement that is marked as confidential or would reasonably be understood to be confidential, including Customer Data and non-public information about the Service. The recipient must use it only to perform or exercise its rights under this agreement, protect it with at least reasonable care, and disclose it only to its and its Affiliates' employees, contractors and professional advisers who need to know it and are bound by equivalent confidentiality obligations, for whose compliance the recipient is responsible. These obligations continue for five years after this agreement ends and, for trade secrets and Customer Data, for as long as they remain confidential.
Confidential Information does not include information that the recipient can show: (a) is or becomes public other than through its breach; (b) it lawfully knew without restriction before disclosure; (c) it lawfully receives from a third party without restriction; or (d) it develops independently without using the discloser's Confidential Information. The recipient may disclose Confidential Information to the extent required by law, a court or a regulator, if it gives the discloser prompt notice where legally permitted and reasonable help to seek protective treatment.
Warranties
Each party warrants that it has full power and authority to enter into and perform this agreement, and that it will comply with all laws that apply to it in performing this agreement.
Except as expressly stated in this agreement, all warranties, conditions and other terms implied by statute or common law are excluded to the fullest extent permitted by law. The Provider does not warrant that the Service will be uninterrupted or error-free, and is not responsible for delays, failures or losses caused by networks or systems that it does not control.
Limitation of Liability
Nothing in this agreement limits or excludes either party's liability for: (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot be limited or excluded under the law of England and Wales.
Except for liability that this agreement does not limit or exclude, neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for: (a) loss of profits, revenue, business, goodwill or anticipated savings, whether direct or indirect; or (b) any indirect or consequential loss. This clause does not limit amounts payable under the Indemnities clause.
Except for liability that this agreement does not limit or exclude, each party's total aggregate liability arising out of or in connection with this agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the Liability Cap. However: (a) for claims arising from a party's breach of the Data Protection, Security or Confidentiality clauses, that party's total aggregate liability is limited to three times the Liability Cap, and these claims do not use up the Liability Cap; and (b) the caps do not apply to the Customer's obligation to pay Subscription Fees properly due or to a party's liability under the Indemnities clause.
Term and Termination
This agreement starts on its date and continues for the Initial Term. It then renews automatically for successive Renewal Terms unless either party gives the other written notice of non-renewal at least 30 days before the end of the then-current term.
Either party may terminate this agreement immediately by written notice if the other party: (a) commits a material breach that cannot be remedied; (b) commits a material breach that can be remedied and does not remedy it within 30 days after receiving written notice describing it; or (c) becomes insolvent, makes an arrangement with its creditors, has an administrator, receiver or liquidator appointed, or ceases to carry on business, except where the law prevents termination on that ground.
For 30 days after expiry or termination, the Provider must allow the Customer to export Customer Data in a commonly used machine-readable format at no extra charge. After that period, the Provider must delete Customer Data, including copies held by its sub-processors, within 90 days, unless the law requires it to retain it, and must confirm deletion in writing on request.
On expiry or termination: (a) the Customer's right to use the Service ends; (b) the Customer must pay all fees properly due up to that date; (c) the Provider must refund prepaid Subscription Fees for the unused part of the Subscription Term if the Customer terminates for the Provider's breach or another provision of this agreement gives a refund on that termination; and (d) each party must on request return or destroy the other's Confidential Information other than Customer Data (which is exported and deleted as set out above), except copies the law requires it to keep or held in routine back-ups, which remain confidential. Accrued rights, and clauses intended to survive termination, are unaffected.
The following continue after expiry or termination of this agreement, together with any other provision that by its nature is intended to continue: (a) the obligation to pay fees and other amounts accrued or properly due before expiry or termination, and the Fees and Payment clause so far as it applies to them; (b) the provisions of the Term and Termination clause on the export, return and deletion of Customer Data and on the effects of expiry or termination; (c) the Customer Data clause, and the Data Protection clause for as long as the Provider or any sub-processor holds personal data in Customer Data; (d) the Confidentiality clause, for the period it states; (e) the Intellectual Property clause, including the Provider's rights in feedback; (f) the Indemnities and Limitation of Liability clauses; (g) the General clause, so far as it concerns notices, entire agreement, variation, waiver, severance and third party rights; and (h) the Governing Law and Jurisdiction clause.
General
Neither party is liable for delay or failure to perform, other than a payment obligation, caused by an event beyond its reasonable control, if it promptly notifies the other party and uses reasonable endeavours to minimise the effect. This does not excuse a failure that the Provider's business continuity and disaster recovery plan should have prevented. If the event prevents the Service from operating materially for more than 30 consecutive days, either party may terminate this agreement by written notice, and the Provider must refund prepaid Subscription Fees for the unused part of the Subscription Term.
Neither party may assign or transfer this agreement without the other party's prior written consent, which must not be unreasonably withheld or delayed. However, either party may assign this agreement as a whole on written notice to an Affiliate, or to a successor to all or substantially all of the business or assets to which this agreement relates.
The Provider may use subcontractors to perform its obligations, but remains responsible for their acts and omissions as if they were its own.
Neither party may use the other party's name or logo, or announce this agreement publicly, without the other party's prior written consent.
Each party must comply with the Bribery Act 2010 and with all anti-bribery, anti-corruption, sanctions and export control laws that apply to it in connection with this agreement. The Customer must not allow the Service to be accessed or used in breach of those sanctions or export control laws. Either party may terminate this agreement immediately by written notice if the other party becomes subject to sanctions that make performing this agreement unlawful.
A notice under this agreement must be in writing and delivered by hand, by pre-paid recorded delivery or courier, or by email to the address the recipient has given for notices or, if none, its registered office. It is received on delivery by hand or courier, or when the email is sent unless the sender receives a failure message; a notice received outside 9.00 am to 5.00 pm on a business day in the place of receipt is received at 9.00 am on the next business day.
This agreement is the entire agreement between the parties about its subject matter and supersedes all prior discussions and arrangements. Each party acknowledges that it has not relied on any statement, representation or assurance not set out in this agreement, but nothing in this clause limits liability for fraud or fraudulent misrepresentation. Terms in any purchase order or other document of the Customer do not apply.
A variation of this agreement is effective only if it is in writing and signed by or for both parties. A failure or delay in exercising a right is not a waiver of it. If any provision is found invalid or unenforceable, it is to be modified to the minimum extent necessary to make it enforceable, and the rest of this agreement is unaffected. Nothing in this agreement creates a partnership, joint venture or agency between the parties.
A person who is not a party to this agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
This agreement may be signed in any number of counterparts, including by electronic signature, which together form one agreement.
Governing Law and Jurisdiction
This agreement and any dispute or claim, including a non-contractual dispute or claim, arising out of or in connection with it or its subject matter or formation are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction to settle any such dispute or claim.
A business-to-business SaaS subscription agreement governed by DIFC law, with service standards, fees, Customer Data and AI-training limits, security, processor terms under the DIFC Data Protection Law, IP indemnity, a tiered liability cap drafted for the DIFC Implied Terms in Contracts and Unfair Terms Law, and the exclusive jurisdiction of the DIFC Courts.
A law-neutral business-to-business SaaS subscription agreement for cross-border deals, with the governing law and arbitration or courts as variables (defaults: English law and LCIA arbitration in London), withholding-tax options, Customer Data and AI-training limits, processor terms, IP indemnity, a tiered liability cap, sanctions compliance and the CISG excluded.
A business-to-business cloud service agreement adapted from the Common Paper Cloud Service Agreement Standard Terms v3.0 for a single signed contract under Delaware, New York or California law, with balanced and leaning variants on suspension, AI training, data export, the liability cap and publicity, conspicuous warranty and liability disclaimers, optional California service-provider and New York renewal-notice terms, and export-control and sanctions terms.
Jurisdiction
Delaware, United States · New York, United States · California, United States · United States (Federal)
A business-to-business SaaS subscription agreement for the UAE mainland under UAE federal law and the law of the chosen emirate, with service standards, fees and simple-interest late payment, Customer Data and AI-training limits, PDPL processor terms, IP indemnity, a tiered liability cap, and onshore courts or DIAC arbitration.
A balanced England & Wales agreement for a startup or board advisor (usually an individual) engaged as an independent contractor, paid in equity, a cash fee or both: services and time commitment, an optional board-approved share or option grant with monthly vesting, cliff and optional acceleration, confidentiality, IP in work product, conflicts, liability and short-notice termination.
A balanced agreement for a Client retaining a Consultant (a firm, or an individual through a company or in their own name) to give advice and expert support paid mainly by time — a day rate, hourly rate or retainer — under the law of England and Wales.
A convertible loan note for an English private company: an unsecured loan from one Investor that converts into shares on a qualified financing at a discount and/or under a valuation cap, with repayment or conversion on an exit, at maturity or on default, governed by the law of England and Wales.
An offer of employment for an Employer hiring an Employee in England and Wales, drafted to serve as the statutory written statement of particulars: role, start date, pay, hours, holiday, sick pay, pension, notice, confidentiality, intellectual property, optional post-employment restrictions and English governing law.