Please fill all the required fields!
The required fields are marked red.

A software as a service agreement is not a software licence. Nothing is delivered to the customer, and nothing is owned. The customer is buying continuing access to a service the provider controls, running on infrastructure the provider chooses, holding data the customer cannot afford to lose.
That structure changes which clauses actually matter. This guide from the Business Law team at Libra Law covers the terms that determine whether a SaaS relationship works, from both sides of the table.
Three differences drive everything else:
The grant clause should be precise about what the customer is buying:
Ambiguity here produces uncomfortable conversations at renewal. If your organization has contractors or a shared-services entity, confirm in writing that they are covered.
The commercial mechanics deserve close reading:
Customers should push for a cap on renewal increases. Providers should be clear about them, because unpriced escalation is a common source of churn and disputes.
An uptime commitment is only meaningful if three things are defined: the measurement period, the exclusions, and the remedy.
Watch the exclusions. Scheduled maintenance, emergency maintenance, third-party infrastructure failures, and force majeure are commonly excluded, and a broadly drafted exclusion list can reduce a 99.9% commitment to something close to a statement of intent.
Watch the remedy too. The standard remedy is a service credit, usually a small percentage of monthly fees. For a system genuinely critical to a customer’s operations, a service credit is not a remedy, it is a rebate. Customers with real dependency should negotiate a termination right triggered by chronic failure, for example repeated breaches across consecutive months.
Also confirm support terms separately: hours of coverage, response time by severity, and escalation path.
Address each of these explicitly:
Ownership. The customer should own its data. Say so.
Provider use rights. Providers need a licence to host and process the data to deliver the service. Read how far that licence goes. Pay particular attention to rights to use customer data for product improvement, analytics, benchmarking, or model training. If aggregated or de-identified use is permitted, define de-identification and prohibit re-identification.
Location and subprocessors. Where is the data stored, and which third parties touch it? Cross-border storage raises privacy and, for some sectors, contractual and regulatory issues.
Security. Specify standards, encryption at rest and in transit, access controls, and whether the provider will produce audit reports or certifications.
Breach notification. Define a notification timeline to the customer, in hours or days, not “promptly.”
Privacy compliance. Alberta’s Personal Information Protection Act governs private-sector handling of personal information in the province and includes breach reporting obligations to the Office of the Information and Privacy Commissioner where a real risk of significant harm exists. Federal privacy legislation may also apply. The contract should allocate responsibility for compliance and for notification.
Backup and retention. Frequency, retention period, and recovery objectives.
This is the clause customers regret not negotiating.
On termination, the customer needs to get its data out in a usable form. Require:
Providers should be equally clear, because vague exit terms invite disputes at the worst moment in a commercial relationship.
Providers reserve the right to modify the service. Customers should seek a floor: a commitment not to materially degrade core functionality during a paid term, notice before material changes, and a termination right if a change materially reduces functionality the customer relies on.
Similarly, providers frequently reserve the right to update the terms of service by posting a new version. A customer signing a negotiated agreement should ensure that the negotiated terms cannot be unilaterally amended by a website posting.
Expect a cap on liability, commonly tied to fees paid over the preceding 12 months, and an exclusion of indirect and consequential loss.
The negotiation is over the carve-outs. Customers typically seek carve-outs, or a higher super-cap, for:
Providers should give an IP infringement indemnity for the service itself. Customers should expect to indemnify for their own data and their users’ misuse.
Also confirm insurance: commercial general liability, cyber and privacy liability, and technology errors and omissions coverage, with amounts appropriate to the risk.
Specify Alberta law and Alberta courts, or a defined arbitration process. Cross-border SaaS contracts frequently default to the provider’s home jurisdiction, and a customer accepting that should understand what enforcement will actually look like.
In a SaaS agreement, the clauses that decide your outcome are data ownership, exit and portability, service levels with meaningful remedies, and renewal mechanics. Ownership of software is beside the point, because nobody is buying software.
Whether you are selling a platform or subscribing to one, talk to a business lawyer at Libra Law before you sign.
This article is for general informational purposes only and does not constitute legal advice. For advice specific to your situation, consult a qualified professional.