Language: πŸ‡ΊπŸ‡Έ πŸ‡²πŸ‡½ πŸ‡·πŸ‡Ί
SaaS & Cloud

SaaS Subscription Agreement: build a starting draft free, or have me draft it around your deal

The generator below produces a clean starting draft with live preview. It cannot know your data flows, your customers’ procurement demands, or which liability cap survives negotiation. That part is my day job.

Sergei Tokmakov, California attorney, CA Bar #279869. Drafting SaaS agreements since 2011.

Sergei Tokmakov, Esq., California attorney, CA Bar #279869
Sergei Tokmakov, Esq.
California Bar #279869

The most common way a SaaS agreement reaches my desk

You already have a ChatGPT or Claude draft of a SaaS agreement

The clause language is probably fine. The risk is the six things the model had no way to know, because none of them are in its training data or in your prompt.

1. The paper you will actually signPast a certain deal size, the customer sends its own MSA or a procurement rider. The model drafted the wrong document.
2. Which liabilities sit outside your capIndemnity, data breach, confidentiality: the exclusions list, not the cap number, decides your exposure.
3. Whether your stack can perform the data termsA 24-hour breach notice and a subprocessor veto are promises your vendors have to keep, and the model never met your vendors.
4. Which regulated overlay appliesPHI needs a BAA. California health data can trigger the CMIA. The model does not know what your customers upload.
5. Who your buyers legally areCalifornia’s auto-renewal law binds consumer subscriptions. Sell to individuals and your “B2B” renewal clause is suddenly regulated.
6. How the SLA interacts with terminationCredits as sole remedy, chronic-failure exits, and refund of prepaid fees have to agree with each other. Three separate prompts will not make them.

$750 flat: one SaaS agreement drafted or redlined, written comments, up to three rounds of email revisions. Scope confirmed in writing after a conflict check; nothing here creates an attorney-client relationship.

Short answer

The liability cap in a generated SaaS agreement is the term least likely to survive contact with a real customer, and the exclusions under the cap, not the cap number, decide who eats a data breach. A “12 months of fees” cap with a data-breach carve-out is not a cap; it is an uncapped promise wearing one. Enterprise procurement knows this, which is why the redline you get back rewrites the exclusions first and the number second. The generator below writes a sound baseline; the exclusions negotiation is a judgment call about your data, your insurance, and your customer, not a template setting.

What does your cap actually cover? A 60-second check

Model the gap between the cap in your draft and one bad data incident. Every number here is your own assumption; the calculator just does the arithmetic your counterparty’s lawyer will do.

Notification, forensics, credit monitoring, legal, regulator response. Pick your own number; published breach studies vary widely.
Contract cap
Modeled incident cost
Recoverable under the cap
Uncapped / above-cap exposure

Arithmetic on your own inputs, not a prediction, a valuation, or legal advice. Real incidents and real caps both behave worse than models.

Where SaaS agreements actually bleed

Five consequences, not definitions. Each one is a place I have watched real money change hands. Tap to open.

The liability cap that eats the companyThe exclusions list decides the incident, not the cap number

Almost every SaaS draft caps liability at fees paid in the last 12 months. Almost every negotiated redline then pulls the liabilities that actually bankrupt companies out of that cap: indemnification, breach of confidentiality, and data-security failures. On the provider side, my job is to keep the exclusions list short and to price a super-cap, a higher multiple of fees for data claims, before the customer demands uncapped everything. On the customer side, it is the mirror image: a cap at 12 months of a $2,000 subscription is $24,000 of protection against a vendor holding a million records.

The one-line test. Read the sentence that starts “The foregoing limitation shall not apply to…” If it lists your data obligations, your cap does not cover the thing most likely to hurt you. Run the numbers in the calculator above.
Auto-renewal that voids itselfConsumer statutes and procurement riders vs your renewal clause

California’s automatic renewal law, Business and Professions Code section 17600 and following, is a consumer statute: section 17601 defines a consumer as an individual acquiring goods or services for personal, family, or household purposes, and the law was tightened again by AB 2863 for contracts entered into, amended, or extended on or after July 1, 2025. Two consequences for SaaS. If any slice of your subscribers are individuals, your renewal flow needs the consumer machinery: clear disclosure, affirmative consent, and easy cancellation. And even in pure B2B deals, where the statute does not reach, enterprise customers negotiate their own renewal protections anyway: 60- or 90-day non-renewal windows, price-increase caps, and notice-before-renewal duties that most procurement teams now demand as a matter of course.

The failure mode I see. A generated “B2B” agreement reused for a self-serve product sold to individuals, with a renewal clause that ignores the consumer statute entirely. The clause does not merely underperform; it invites a claim.

Statutory scope verified against Business and Professions Code section 17601 at leginfo.legislature.ca.gov on 2 August 2026, including the AB 2863 amendments (Stats. 2024, ch. 515).

The SLA credit that costs nothing and settles nothingWhat “sole remedy” does to an outage claim

A 99.9% uptime promise sounds like an obligation. Read the remedy: a credit of a few percent of one month’s fee, claimable only within 30 days, forfeited if unclaimed, and defined as the sole and exclusive remedy for availability failures. That last phrase is the entire point of the clause. It converts an outage from a breach-of-contract claim into a coupon. Providers should defend it, honestly, because it makes downtime survivable. Customers should attack the edges: how uptime is measured and by whose logs, what counts as excluded maintenance, whether chronic failure, say three missed months in a rolling six, unlocks termination and a pro-rata refund of prepaid fees rather than another coupon.

Your customer’s data, your subprocessors, and the flow-down you never paperedDPAs, BAAs, and promises your vendors must keep

The data terms you sign are promises your vendors have to perform. If your DPA gives the customer a subprocessor veto and a 24-hour incident notice, but your hosting provider owes you neither, you have signed a contract your own stack cannot execute. Where protected health information is in play, the overlay is statutory: a business associate agreement is required, and under 45 CFR 164.410 a business associate must report a breach without unreasonable delay and no later than 60 calendar days after discovery. Counterparty forms routinely compress that to 24 or 72 hours and start the clock at the incident rather than discovery, which is a materially harder promise than the regulation imposes.

If PHI is anywhere near your product: the BAA page covers what the counterparty’s form adds on top of the rule, or I draft the standalone BAA for $750. A product that is the thing holding the data usually needs the coordinated healthcare stack instead.

Breach-notification timing verified against 45 CFR 164.410 on 2 August 2026.

IP in, IP out: configurations, integrations, and AI-assisted outputConfigurations, integrations, and AI output nobody defined

“Provider owns the platform, customer owns customer data” reads clean and decides almost nothing. A live deployment generates a third category: configurations, workflows, integrations, fine-tuned models, usage analytics, and AI-assisted output built from the customer’s prompts on the provider’s machinery. Whoever fails to define that category donates it. Providers want express rights to usage data and to improvements; customers want their prompts, outputs, and trained artifacts walled off from other customers, and increasingly want a no-training clause with teeth. If your product has an AI feature, the output-ownership question is its own discipline; I keep a running analysis of how the major model providers handle it at ai-output-rights.

Questions I get about SaaS agreementsAI drafts, caps, auto-renewal, SLA credits, DPAs and BAAs
Is an AI-generated SaaS agreement safe to sign?

The clause language is usually competent. The danger is what the model had no way to know: the paper your enterprise customer will actually send back, whether your subprocessor stack can perform the data terms, which liabilities sit inside or outside the cap, and whether a regulated overlay such as HIPAA applies. A model draft is a reasonable first pass and a poor last one.

What liability cap is standard?

Twelve months of fees is the common baseline, but the exclusions decide the outcome: carved-out indemnity, data, and confidentiality liabilities are uncapped. The negotiated middle ground in data-heavy deals is a super-cap, a higher multiple of fees for data claims. The number matters less than which claims it governs.

Does California’s auto-renewal law apply to my B2B contracts?

Section 17601 defines the protected buyer as an individual purchasing for personal, family, or household purposes, so a pure B2B subscription sits outside it. The traps: products sold to individuals are consumer contracts no matter what the seller calls itself, the statute was tightened again for contracts entered into, amended, or extended on or after July 1, 2025, and enterprise customers negotiate renewal-notice and price-cap terms regardless of any statute.

Are SLA credits a real remedy?

By themselves, rarely. The phrase that matters is “sole and exclusive remedy,” which converts an outage claim into a small coupon. What gives an SLA teeth: honest measurement, narrow exclusions, and a chronic-failure termination right with a pro-rata refund of prepaid fees.

Can I just use the free generator below?

For a straightforward deal where you control the paper, a generated agreement plus a careful read is a defensible starting point, and I built the generator so that it would be. Where I would not rely on it alone: when the customer sends its own form, when regulated data is in scope, when the deal is large enough that the cap and exclusions will be negotiated, or when the agreement has to agree with a DPA, BAA, or Terms of Service drafted at a different time.

Free SaaS agreement generator: a starting draft, not a signable contractFill the form and the document builds in place with live preview. Word, PDF, and print export. Use it to control the paper before the customer sends theirs.
Read this before you use the output. This generator assembles a standard SaaS subscription agreement from your form inputs. It does not know your customer’s form, your vendor stack, your insurance, or whether a regulated overlay applies to your data. It is not legal advice, and using it does not make me your attorney.

You now have a draft I have never read. It is a sound starting point and a poor finished contract, because it was assembled from your form inputs, not from your deal. If a real counterparty will sign this, the $750 flat fee covers me redlining exactly what you just generated, up to three revision rounds by email.

Send me this draft: $750

Work with me on it

If one agreement is all you need, buy the one agreement. I will tell you when your deal needs less than you think, and when the documents around it have to agree with it.

Most SaaS deals land here

SaaS agreement, drafted or redlined

$750
  • Drafted from your deal, or redlined against the draft you generated or the customer’s paper, either side of the table
  • Written comments on the cap, exclusions, renewal, SLA remedies, and data terms
  • Up to three rounds of email revisions
Request this package, $750

Complex or enterprise agreement

$1,200
  • Enterprise paper, multi-product platforms, regulated data, or heavy negotiation
  • One complex or compliance-sensitive agreement, drafted or redlined
  • Coordination with your DPA, BAA, and Terms of Service where they overlap
Request this package, $1,200

Written attorney consultation

$240
  • One narrow question answered in writing: the cap, the renewal clause, the data terms
  • Send the draft and your question; get issues, risks, and next steps
  • Not a full redline; the honest choice when you need an answer, not a document
Request this package, $240

Launching a health-adjacent product? The $2,500 Healthcare SaaS Legal Package papers the whole stack. A full document set for a standard SaaS launch is the SaaS Legal Package hub. No free consultations, case evaluations, or document review.

See a contract negotiated, not just generated

How I work through a contract with a client: live preview, click-any-clause comments, track-changes suggestions. Fictional demo data.

Disclaimer. This page is general legal information, not legal advice. Using the generator, reading this page, or emailing me does not create an attorney-client relationship; that requires a conflict check and a written engagement agreement. Generated documents are starting drafts. Statutes change; citations here were verified against the primary sources on the dates noted. I am licensed in California. I do not carry professional liability (malpractice) insurance, and I give you that disclosure in writing with every engagement agreement.

Sergei Tokmakov, Esq. · California Bar #279869 · owner@terms.law