SaaS Subscription Agreement (US) by OLL

Updated 19 March 2026

SaaS Subscription Agreement for cloud-based software services outlining terms between a provider and customer. Created by OLL's team of legal experts.

SaaS Subscription Agreement

Cover Page

Agreement Identification

Agreement Name:

[agreement name]

Effective Date:

[effective date]

Parties

Provider:

[provider name]

Address:

[provider address]

Notice Email:

[provider notice email]

Customer:

[customer name]

Address:

[customer address]

Notice Email:

[customer notice email]

Key Terms

Service Description:

[description of the saas service, including key features and environments]

Initial Subscription Term:

[initial term]

Renewal Terms:

[auto-renewal period, e.g., successive 12-month periods]

Fees:

[fee amount, pricing metric, and billing frequency]

Payment Terms:

[payment due period, e.g., net 30 days from invoice]

Governing Law:

[governing law]

Venue:

[venue]

Incorporated Documents

The following documents are incorporated by reference. In case of conflict, documents are applied in the following order of precedence: (1) Order Forms, (2) Data Protection Addendum, (3) Service Level Agreement, (4) these SaaS Terms, (5) Security Exhibit, (6) Acceptable Use Policy.

Data Protection Addendum:

[dpa reference or "not applicable"]

Service Level Agreement:

[sla reference or "standard sla applies"]

Security Exhibit:

[security exhibit reference or "standard security measures apply"]

Acceptable Use Policy:

[aup reference or url]

Support Policy:

[support policy reference or url]

SaaS Terms

Definitions

"Authorized Users" means employees, contractors, and agents of Customer and its Affiliates who are authorized by Customer to access the Service under this Agreement.

"Customer Data" means all data, content, and materials submitted by Customer or Authorized Users to the Service, excluding Usage Data.

"Documentation" means Provider's standard usage documentation for the Service, as updated from time to time.

"Order Form" means an ordering document specifying the Service, fees, Subscription Term, and other commercial terms, executed by both parties and referencing this Agreement.

"Personal Data" means Customer Data relating to an identified or identifiable natural person, as defined under applicable privacy laws.

"Security Incident" means any unauthorized access to, acquisition of, or disclosure of Customer Data, or any breach of Provider's security measures that compromises the confidentiality, integrity, or availability of Customer Data.

"Service" means Provider's proprietary cloud-based software-as-a-service offering identified in the applicable Order Form, including any Provider-supplied software, APIs, and Documentation.

"Subscription Term" means the period during which Customer has the right to access and use the Service as specified in an Order Form.

"Usage Data" means technical data about Customer's use of the Service, such as logs, performance metrics, and feature usage statistics, but excluding Customer Data.

Service Access and Grant of Rights

2.1 Subscription Grant. Subject to this Agreement and payment of applicable fees, Provider grants Customer a limited, non-exclusive, non-transferable right to access and use the Service during the Subscription Term solely for Customer's internal business purposes. This includes the right to use any Provider-supplied software and Documentation as part of such authorized use.

2.2 Authorized Users. Customer may permit Authorized Users to access the Service on Customer's behalf. Customer is responsible for: (a) provisioning and managing Authorized User accounts; (b) ensuring Authorized Users comply with this Agreement; (c) all activities conducted through Authorized User accounts; and (d) ensuring Authorized Users maintain the confidentiality of their login credentials. Customer will promptly notify Provider of any suspected unauthorized access.

2.3 Affiliates. Customer's Affiliates may use the Service under this Agreement as Authorized Users. Alternatively, Affiliates may execute separate Order Forms, which creates a separate agreement between each Affiliate and Provider. Neither Customer nor any Affiliate has rights under each other's separate agreements.

2.4 Restrictions. Customer will not and will not permit others to: (a) sell, sublicense, distribute, rent, or provide access to the Service to third parties; (b) reverse engineer, decompile, or attempt to derive source code from the Service, except as permitted by applicable law; (c) copy, modify, or create derivative works of the Service; (d) remove or obscure proprietary notices; (e) use the Service to develop a competing product; (f) circumvent or disable security features; (g) conduct vulnerability testing without Provider's prior written consent; or (h) use the Service in violation of applicable laws.

2.5 Reservation of Rights. Provider retains all right, title, and interest in the Service, Documentation, and all related intellectual property. No rights are granted except as expressly set forth in this Agreement.

Customer Responsibilities and Acceptable Use

3.1 Compliance. Customer will comply with any Acceptable Use Policy and represents that it has all necessary rights to use Customer Data with the Service without violating third-party rights.

3.2 Prohibited Uses. Customer will not use the Service for: (a) activities that violate applicable laws; (b) transmitting malware, viruses, or harmful code; (c) interfering with or disrupting the Service or other users; (d) unauthorized access to systems or data; (e) activities that materially impair Service availability or security; or (f) high-risk activities where Service failure could cause death, personal injury, or environmental damage.

3.3 Customer Data Responsibility. Customer is responsible for the accuracy, quality, and legality of Customer Data. If Customer Data includes content from third parties, Customer represents it has obtained all necessary consents and rights.

Fees and Payment

4.1 Fees. Customer will pay all fees specified in the applicable Order Form. Unless otherwise stated, fees are based on the pricing metric and measurement method specified in the Order Form.

4.2 Invoicing and Payment. Provider will invoice Customer according to the billing frequency specified in the Order Form. Customer will pay undisputed invoices within the Payment Terms stated on the Cover Page. If no Payment Terms are specified, payment is due within 30 days of invoice date.

4.3 Late Payments. Late payments will bear interest at the lesser of 1.5% per month or the maximum rate permitted by law. Provider may suspend Service access if payment is more than 30 days overdue, provided Provider gives Customer at least 10 days' prior written notice.

4.4 Taxes. Fees are exclusive of taxes. Customer is responsible for all sales, use, VAT, and similar taxes, excluding taxes on Provider's net income. Customer will provide valid exemption certificates upon request.

4.5 Usage-Based Fees. If fees are based on usage: (a) the Order Form will specify the metered unit and measurement method; (b) Provider's usage records are the authoritative source; (c) Customer may request usage data verification; and (d) overage fees will be invoiced and payable as specified in the Order Form.

4.6 Disputes. Customer must notify Provider of any disputed charges in good faith within 30 days of invoice date. The parties will attempt to resolve disputes within 15 days. Customer must pay undisputed amounts while disputes are pending.

Data Handling and Privacy

5.1 Customer Data Ownership. As between the parties, Customer retains all right, title, and interest in Customer Data. Provider acquires no ownership rights in Customer Data.

5.2 Permitted Use of Customer Data. Provider may access and use Customer Data solely to: (a) provide, maintain, and support the Service; (b) comply with applicable laws; and (c) respond to Customer requests. Provider will not sell Customer Data or use it for advertising purposes.

5.3 Usage Data. Provider may collect and use Usage Data to operate, improve, and support the Service and for lawful business purposes, including benchmarking and analytics. Provider will only disclose Usage Data externally if it is: (a) de-identified so it does not identify Customer or any individual; and (b) aggregated with data from other customers.

5.4 Data Protection Addendum. If Provider processes Personal Data on Customer's behalf, the parties will execute a Data Protection Addendum ("DPA") that: (a) defines processing purposes, data categories, and data subject types; (b) establishes confidentiality obligations for personnel; (c) specifies security measures; (d) governs subprocessor engagement; (e) addresses data subject rights assistance; and (f) specifies data deletion or return upon termination.

A DPA is required when processing Personal Data. For California residents, include CPRA service provider restrictions. For Massachusetts, include required security measures per 201 CMR 17.03.

5.5 Privacy Roles. When processing Personal Data under this Agreement: (a) Customer acts as the data controller (or business under CPRA); and (b) Provider acts as a data processor (or service provider under CPRA), processing Personal Data only on Customer's documented instructions. Provider will not combine Personal Data with data from other sources except as necessary to provide the Service.

5.6 Subprocessors. Provider may engage subprocessors to process Customer Data, provided: (a) subprocessors are bound by written confidentiality and data protection obligations at least as protective as this Agreement; (b) Provider maintains a current subprocessor list; (c) Provider notifies Customer of new subprocessors with reasonable advance notice; and (d) Customer may object to new subprocessors as specified in the DPA. Provider remains responsible for subprocessor compliance.

Security

6.1 Security Measures. Provider will implement and maintain administrative, technical, and physical security measures designed to protect Customer Data from unauthorized access, use, alteration, or disclosure. Security measures will be appropriate to the nature of the data processed and consistent with industry practices.

6.2 Security Standards. Provider will maintain security measures aligned with [recognized framework, e.g., soc 2 type ii, iso 27001, or nist csf]. Provider will provide evidence of compliance through: (a) independent audit reports (e.g., SOC 2 report); (b) certifications; or (c) a security questionnaire, upon Customer's reasonable request and subject to confidentiality obligations.

Specify actual security certifications and audit artifacts available. Do not commit to controls you cannot evidence.

6.3 Security Incident Response. Provider will maintain incident response procedures and will:

Notify Customer of any Security Incident without undue delay, and in any event within 72 hours after confirmation of an incident affecting Customer Data;

Provide Customer with available information about the nature and scope of the incident, including categories of data and approximate number of data subjects affected;

Take reasonable steps to contain, investigate, and remediate the incident;

Preserve relevant evidence and logs;

Cooperate with Customer's reasonable requests for information needed to comply with breach notification obligations; and

Provide periodic updates as investigation proceeds and new information becomes available.

6.4 Breach Notification Responsibility. Customer is responsible for determining whether legal notification to individuals or regulators is required and for sending such notifications. Provider will provide Customer with information reasonably necessary to fulfill notification obligations. The parties will coordinate on the content and timing of any public communications regarding a Security Incident.

6.5 Incident Costs. Provider will bear the costs of investigating Security Incidents caused by Provider's failure to maintain required security measures. Costs for optional measures (such as credit monitoring or public relations) will be allocated as agreed by the parties.

6.6 Customer Audit Rights. Upon reasonable advance notice (not more than once per year unless a Security Incident has occurred), Customer may: (a) review Provider's then-current SOC 2 report or equivalent audit documentation; (b) submit reasonable security questionnaires; or (c) request a meeting with Provider's security personnel. Any audit or assessment will be conducted during normal business hours, subject to confidentiality, and designed to minimize disruption to Provider's operations.

Service Levels

7.1 Availability Commitment. Provider will use commercially reasonable efforts to maintain Service availability of at least [availability percentage, e.g., 99.9%] measured monthly, excluding Scheduled Maintenance and events outside Provider's reasonable control.

7.2 Scheduled Maintenance. Provider will provide reasonable advance notice of scheduled maintenance that may affect Service availability. Where practicable, Provider will schedule maintenance during off-peak hours.

7.3 Service Credits. If Provider fails to meet the availability commitment, Customer may request service credits as specified in the SLA. Service credits are Customer's sole and exclusive remedy for failure to meet availability commitments, unless chronic failures (three or more consecutive months) occur, in which case Customer may terminate the affected Order Form.

7.4 Support. Provider will provide support for the Service as described in the Support Policy. If no Support Policy is specified, Provider will provide support consistent with industry standards and its general practices.

Term, Renewal, and Termination

8.1 Agreement Term. This Agreement begins on the Effective Date and continues until all Order Forms have expired or been terminated.

8.2 Subscription Term. Each Subscription Term begins on the date specified in the Order Form and continues for the Initial Term. The Subscription Term will automatically renew for successive periods equal to the prior term unless either party provides written notice of non-renewal at least 30 days before the end of the then-current term.

8.3 Termination for Cause. Either party may terminate this Agreement or an Order Form if the other party: (a) materially breaches and fails to cure within 30 days after written notice; (b) becomes insolvent, makes an assignment for creditors' benefit, or becomes subject to bankruptcy proceedings not dismissed within 60 days; or (c) ceases operations without a successor.

8.4 Termination for Convenience. Customer may terminate an Order Form for convenience upon 30 days' written notice, subject to payment of fees for the remainder of the then-current Subscription Term unless otherwise specified in the Order Form.

8.5 Suspension. Provider may suspend Customer's access to the Service: (a) if Customer's account is more than 30 days overdue; (b) if Customer materially breaches Section 3 (Customer Responsibilities); or (c) if necessary to prevent harm to the Service, other customers, or third parties, or to comply with law. Provider will give Customer prior notice where practicable and will restore access promptly after the issue is resolved. Fees continue to accrue during suspension for Customer's breach.

8.6 Effect of Termination. Upon termination or expiration: (a) Customer's access rights cease; (b) each party will return or destroy the other's Confidential Information; and (c) Customer will pay any unpaid fees for Service provided through the termination date.

8.7 Data Export and Deletion. During the Subscription Term, Customer may export Customer Data using the Service's standard export features or as described in the Documentation. After termination: (a) Customer may request data export within 30 days; (b) Provider will delete Customer Data within 60 days after termination or Customer's export request, whichever is later; and (c) Provider will provide written confirmation of deletion upon request. Provider may retain Customer Data as required by law or pursuant to standard backup retention, subject to confidentiality and security obligations.

8.8 Survival. The following sections survive termination: Definitions, Payment (for accrued amounts), Data Handling (Sections 5.1, 5.3), Security (Section 6 regarding incidents discovered post-termination), Intellectual Property, Confidentiality, Limitation of Liability, Indemnification, and General Provisions.

Confidentiality

9.1 Confidential Information. "Confidential Information" means non-public information disclosed by one party to the other that is designated as confidential or that a reasonable person would understand to be confidential given its nature and circumstances of disclosure. Customer Data is Customer's Confidential Information. Provider's technical and pricing information is Provider's Confidential Information.

9.2 Obligations. The receiving party will: (a) use Confidential Information only to exercise rights and fulfill obligations under this Agreement; (b) not disclose Confidential Information to third parties except as permitted herein; and (c) protect Confidential Information using at least the same care as for its own similar information and no less than reasonable care.

9.3 Permitted Disclosures. A party may disclose Confidential Information to employees, contractors, and advisors with a need to know, provided they are bound by confidentiality obligations at least as protective as this Section.

9.4 Exclusions. Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was rightfully known before receipt; (c) is rightfully obtained from a third party without confidentiality restrictions; or (d) is independently developed without use of Confidential Information.

9.5 Compelled Disclosure. A party may disclose Confidential Information if required by law, provided it gives the other party reasonable advance notice (where legally permitted) and cooperates in seeking protective treatment.

9.6 Duration. Confidentiality obligations continue for 3 years after disclosure, except for trade secrets, which remain protected indefinitely.

Warranties

10.1 Mutual Warranties. Each party represents and warrants that: (a) it has the legal power and authority to enter into this Agreement; and (b) it will not introduce malware or malicious code into the Service.

10.2 Provider Warranties. Provider warrants that: (a) the Service will perform materially as described in the Documentation during the Subscription Term; and (b) Provider will not materially decrease the Service's overall functionality during a Subscription Term.

10.3 Warranty Remedy. If Provider breaches Section 10.2, Customer's exclusive remedy is for Provider to use reasonable efforts to correct the non-conformity. If Provider cannot correct the non-conformity within 30 days after notice, either party may terminate the affected Order Form and Provider will refund prepaid fees for the unused portion of the Subscription Term.

10.4 Disclaimers. EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, EACH PARTY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. PROVIDER DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE. THESE DISCLAIMERS APPLY TO THE MAXIMUM EXTENT PERMITTED BY LAW.

Limitation of Liability

11.1 Liability Cap. EXCEPT FOR UNCAPPED CLAIMS, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER IN THE 12 MONTHS PRECEDING THE CLAIM ("GENERAL CAP").

11.2 Consequential Damages Waiver. EXCEPT FOR UNCAPPED CLAIMS, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR DAMAGES FOR LOST PROFITS, REVENUE, DATA, OR USE, EVEN IF ADVISED OF THEIR POSSIBILITY.

11.3 Enhanced Cap. For Enhanced Claims, each party's total liability will not exceed three times (3x) the General Cap.

11.4 Definitions.

"Enhanced Claims" means: (a) Provider's breach of Section 6 (Security); (b) either party's breach of Section 5 (Data Handling) or any DPA.

"Uncapped Claims" means: (a) indemnification obligations under Section 12; (b) infringement or misappropriation of intellectual property rights; (c) breach of confidentiality (excluding Customer Data breaches, which are Enhanced Claims); (d) fraud or willful misconduct; and (e) liabilities that cannot be limited by law.

11.5 Basis of Bargain. The limitations in this Section reflect the allocation of risk between the parties and are an essential element of the basis of the bargain. This Section applies regardless of the form of action and survives even if any limited remedy fails of its essential purpose.

Indemnification

12.1 Provider Indemnification. Provider will defend Customer against third-party claims alleging that the Service, as provided and used in accordance with this Agreement, infringes a third party's intellectual property rights, and will indemnify Customer for damages awarded or settlements approved by Provider.

12.2 Customer Indemnification. Customer will defend Provider against third-party claims arising from: (a) Customer Data or Customer's use of Customer Data with the Service; or (b) Customer's breach of Section 3 (Customer Responsibilities), and will indemnify Provider for damages awarded or settlements approved by Customer.

12.3 Indemnification Procedures. The indemnified party will: (a) promptly notify the indemnifying party of the claim; (b) give the indemnifying party sole control of defense and settlement; and (c) provide reasonable cooperation. The indemnifying party may not settle in a manner that admits fault or imposes non-monetary obligations on the indemnified party without consent.

12.4 Mitigation. If the Service is or may become subject to an infringement claim, Provider may, at its option: (a) procure the right for Customer to continue using the Service; (b) modify the Service to be non-infringing without materially reducing functionality; or (c) if neither option is commercially reasonable, terminate the affected Order Form and refund prepaid fees for the unused Subscription Term.

12.5 Exclusions. Provider's indemnification obligations do not apply to claims arising from: (a) modifications not made by Provider; (b) combination with non-Provider products; (c) Customer's continued use after receiving notice to discontinue; or (d) use outside the scope of this Agreement.

Compliance with Laws and Export Controls

13.1 General Compliance. Each party will comply with all laws applicable to its performance under this Agreement.

13.2 Export Controls. The Service may be subject to U.S. export control laws and regulations. Each party represents that it is not: (a) located in a country subject to U.S. embargo; (b) listed on any U.S. government restricted party list; or (c) owned or controlled by any such person or entity. Customer will not: (a) permit access to the Service from embargoed countries or by restricted parties; (b) export or re-export any technical data received from Provider in violation of export laws; or (c) submit to the Service any data controlled under ITAR.

13.3 Customer Compliance Obligations. If Customer provides Service access to end users, Customer will implement appropriate controls and flow-down restrictions to ensure compliance with this Section.

General Provisions

14.1 Order of Precedence. In case of conflict, documents control in the following order: (1) Order Forms (with later Order Forms controlling over earlier ones); (2) Data Protection Addendum; (3) Service Level Agreement; (4) these SaaS Terms; (5) other exhibits and attachments. An Order Form may not modify these Terms unless it specifically identifies the provisions being superseded.

14.2 Notices. Notices under this Agreement must be in writing and delivered to the addresses on the Cover Page by: (a) personal delivery; (b) certified mail (deemed received upon receipt); (c) overnight courier (deemed received one business day after dispatch); or (d) email (deemed received upon delivery confirmation). Either party may update its notice address with written notice.

14.3 Assignment. Neither party may assign this Agreement without the other's prior written consent, except that either party may assign in connection with a merger, acquisition, or sale of all or substantially all assets upon notice to the other party. Any prohibited assignment is void.

14.4 Force Majeure. Neither party is liable for delays or failures due to events beyond its reasonable control (such as natural disasters, war, terrorism, or government action), except for payment obligations. If a force majeure event continues for more than 30 days, either party may terminate affected Order Forms upon notice.

14.5 Amendments. Amendments to this Agreement must be in writing and signed by authorized representatives of both parties.

14.6 Waiver. Failure to enforce any provision is not a waiver. Waivers must be in writing and signed by the waiving party.

14.7 Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary, and remaining provisions will continue in effect.

14.8 Entire Agreement. This Agreement, including all Order Forms and incorporated documents, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements. Terms in Customer purchase orders or similar documents do not modify this Agreement.

14.9 Independent Contractors. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, or agency relationship.

14.10 No Third-Party Beneficiaries. This Agreement does not create third-party beneficiary rights.

14.11 Counterparts. This Agreement may be executed in counterparts, including electronic copies, each of which is an original and together constitute one agreement.

Signatures

By signing below, each party agrees to this Agreement as of the Effective Date.

Provider: [provider name]

Signature: ____________________________

Name: [signatory name]

Title: [signatory title]

Date: [effective date]

Customer: [customer name]

Signature: ____________________________

Name: [signatory name]

Title: [signatory title]

Date: [effective date]

About this template

What is this template?

SaaS Subscription Agreement (US) by OLL is a free, ready-to-use SaaS Agreements template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.

When should you use it?

Reach for this SaaS Agreements template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with United States of America in mind, though you should always review the final wording against the laws that apply to you.

What's typically included?

A well-drafted SaaS Agreements usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.

Jurisdiction
United States of America
Source
OL
SaaS Subscription Agreement (US) by OLL
from Open Legal Library
Document info
HTML document. Document created on Thu Mar 19th, 2026. Last updated on Thu Mar 19th, 2026.
This document is public
Licensed under CC BY-SA 4.0 (Attribution-ShareAlike).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
OLOpen Legal Library
Pocket Privacy Policy by Mozilla
OLOpen Legal Library
Consultancy Agreement (Denmark) by Seedsummit
OLOpen Legal Library
Personal Training Contract by EasyLegalDocs
OLOpen Legal Library
Past-Due Invoice Letter by EasyLegalDocs
OLOpen Legal Library
Online Cloud Service Terms
OLOpen Legal Library
Non-Poaching Agreement by EasyLegalDocs