Skip to content
Call, 0511 – 47 55 58 11

SaaS agreements: what matters

The classification of the contract type determines warranty rights and termination. It therefore belongs at the start of the drafting, not at the end.

SaaS agreements look alike and differ precisely in the points that count in a dispute. The drafting decides whether an outage stays an annoyance or becomes a business risk.

The points it turns on

Price adjustment and unilateral changes

A SaaS agreement runs for years, and both sides want to be able to adjust it in that time. That is the second major point of dispute alongside the exit.

A price adjustment clause survives review only where it names the trigger, ties the amount to comprehensible parameters and provides for a period of notice. A unilateral right of determination without such a tie is likely to be invalid under section 307 of the German Civil Code, and the original price then remains. A right of extraordinary termination when the increase takes effect is therefore not a concession but often the condition on which the clause rests at all.

The same pattern applies to changes in functionality. Maintenance, security and statutory requirements justify a reservation, removing an assured core function as a rule does not. Anyone who depends on a particular function therefore puts it into the description of services and not merely into the provider product description, which is written on unilaterally.

How we support you

We review provider agreements before signature, draft your own agreements on the supplier side and negotiate the points where risk and price are actually decided. Knowing both perspectives shortens the negotiation considerably.

A SaaS agreement before signature?

We tell you what is missing and what you should strike.

Have the contract reviewed

Frequently asked questions

Lease, services or works contract?

Under the case law of the Federal Court of Justice, merely making software available for use over the network points towards lease law. Where operation, maintenance and further development are added, a mixed contract arises. The classification determines warranty rights, price reduction and notice periods and should therefore not be left to chance.

What belongs in a service level agreement?

A measurable availability figure with a defined measurement period, clear response and restoration times by severity class, the treatment of maintenance windows and a legal consequence where the level is missed. Without a consequence, a service level is a statement of intent.

What happens to our data at the end?

That belongs expressly in the contract: in which format data is returned, within what period, at what price and how long access continues after termination. Without it you negotiate from the weakest position imaginable, namely after giving notice.

May the provider change the functionality unilaterally?

Only within limits. A right to change has to name the trigger and remain reasonable for the other side, otherwise it will hardly survive review under sections 307 and 308 no. 4 of the German Civil Code. Reservations that rest on maintenance, security and statutory requirements and leave the core functionality untouched are workable. Where a function the contract expressly relies on is removed, a right of extraordinary termination also comes into consideration.

Our customer passes on security requirements from the BSIG. Do we have to accept that?

The scope is negotiable, the occasion is not. Section 30(2) no. 4 BSIG counts supply chain security among the risk management measures an essential or important entity has to take. Security-related aspects of relationships with direct suppliers are named expressly. The customer is therefore passing on a duty of its own. What has to be settled is the precise scope, the notification and cooperation duties in an incident, the audit rights and the consequence of a deviation.

What does the annex on technical and organisational measures trigger?

More than its status as an annex suggests. What is concretely promised there becomes part of the agreed quality, and a deviation is then a defect and not merely a data protection matter. It therefore makes sense to separate warranted characteristics from a described current state, to tie any reservation of change to an equivalent level of protection, and to settle who reports a deviation and when.

What happens if the provider becomes insolvent?

Whether the contract continues is then for the insolvency administrator to decide, and you have no influence on that. Source code escrow helps only to a limited extent with SaaS, because the service can hardly be continued without its operating environment. More effective are an ongoing backup under your own control, a contractually assured export in a documented format, and the question whether operations could switch to an alternative at short notice.

Related