Quick Answer
A SaaS agreement in India is a commercial contract governing subscription access to software delivered over the internet. It must address intellectual property ownership, data processing obligations under the Digital Personal Data Protection Act 2023, service levels, liability limits, and exit rights. All SaaS providers processing personal data of Indian users require a compliant data processing agreement with their sub-processors before Phase III enforcement begins in May 2027.
SaaS founders and enterprise technology buyers in India operate under a legal framework that rewards those who invest time drafting agreements carefully and penalizes those who treat contracts as administrative formalities. The stakes are real: ownership of code written by a vendor’s engineers, liability exposure during service outages, and control over your organization’s data when a SaaS provider becomes insolvent or is acquired.
This guide covers the legal essentials that every SaaS agreement in India must address. We write from both perspectives: the SaaS provider protecting its product, pricing, and intellectual property, and the enterprise customer limiting liability and securing its data rights. Both parties share an interest in contracts that work in practice, not just on paper.
Types of Technology Agreements in India
Technology businesses in India operate across several distinct agreement types. Each serves a different commercial purpose and carries different legal obligations. Using the wrong agreement structure for a given relationship is a common and preventable mistake.
Agreement Type | Purpose | Typical Parties |
SaaS Agreement | Governs subscription-based access to cloud-hosted software | SaaS provider and enterprise customer |
Software Licence Agreement | Grants rights to use software installed on the customer’s infrastructure | Software vendor and licensee |
Master Services Agreement (MSA) | Framework contract covering multiple technology services | IT services company and corporate client |
Data Processing Agreement (DPA) | Governs processing of personal data by a processor on behalf of a fiduciary | Data fiduciary and data processor |
Software Development Agreement | Governs custom software development, including IP ownership | Developer/vendor and commissioning party |
Technology Transfer Agreement | Transfers software or technology IP from one party to another | Licensor and transferee |
End User Licence Agreement (EULA) | Governs software use by individual end users | Software company and end users |
SaaS agreements and software licence agreements are frequently confused. The structural and legal differences between them are material, and we address these directly in a dedicated section below.
Key Clauses Every SaaS Agreement Must Have in India
A SaaS agreement is only as effective as its drafting. The following seven clauses are non-negotiable for any technology agreement in India intended to hold up commercially and legally.
1. Subscription and Payment Terms
The subscription and payment clause governs the pricing model, billing cycle, renewal terms, and consequences of late payment or non-payment. SaaS providers should specify:
- Whether pricing is per-user, per-module, or usage-based
- Auto-renewal terms and notice periods for cancellation
- Price escalation mechanisms, referencing a defined index or percentage cap
- Suspension rights on non-payment, including notice periods before suspension takes effect
Enterprise customers should negotiate for written notice before any price increase takes effect, and for a clear right to terminate without penalty if the new pricing exceeds a specified threshold.
2. Intellectual Property Ownership: The Most Critical Clause
IP ownership is the clause that startups most frequently draft incorrectly, often at significant cost.
The default position under Indian law (Section 17 of the Copyright Act 1957) is that copyright in a work created by an employee during the course of employment vests in the employer. However, this presumption does not automatically extend to contractors, freelancers, or third-party development agencies. If a SaaS provider has engaged external developers to build its platform and the development agreements do not contain an explicit IP assignment, ownership of that code may not rest with the SaaS provider.
For enterprise customers commissioning customizations, the position is equally important. A customization built by a SaaS provider’s engineers on a customer’s requirement does not automatically belong to the customer. The agreement must state explicitly who owns the customization, whether the provider retains a licence to use it across other products, and what happens to that customization on termination.
Key drafting points for this clause:
- The SaaS provider should own all platform IP, including updates, enhancements, and derivative works created independently
- Customer data remains the customer’s property at all times
- Customizations: negotiate ownership or, at minimum, a perpetual licence to use the customization even after the SaaS contract ends
- Any background IP each party brings to the relationship should be defined and excluded from any cross-licence
Altacit Global’s technology law practice regularly addresses IP ownership disputes that arise from poorly drafted SaaS agreements, many of which could have been avoided with a single correctly worded clause at the outset. See our IP practice guidance on trade secrets and technology licensing for further detail.
3. Data Processing and DPDP Compliance
The Digital Personal Data Protection Act 2023 imposes specific obligations on Data Fiduciaries (the party determining the purpose and means of processing) and on Data Processors (parties processing data on behalf of the fiduciary). In a SaaS relationship, the enterprise customer is typically the Data Fiduciary and the SaaS provider is the Data Processor.
The SaaS agreement must address:
- The categories of personal data being processed
- The purposes for which the SaaS provider may process that data
- Restrictions on sub-processing and requirements for written consent before engaging sub-processors
- Obligations to assist the customer in responding to Data Principal requests (access, correction, deletion)
- Security obligations, including encryption standards and access controls
- Breach notification timelines aligned with the DPDP Act’s requirements
A standalone Data Processing Agreement is required between the Data Fiduciary and the Data Processor under the DPDP Act framework. This is addressed in detail in a separate section below.
Where the SaaS agreement involves personal data transfers outside India, the contract must reflect any restrictions on cross-border transfers that the Data Protection Board of India imposes as the DPDP Rules 2025 are implemented through Phase III enforcement, beginning May 2027.
4. Service Level Agreement (SLA)
The SLA defines the performance commitments the SaaS provider makes to the customer, the measurement methodology, and the remedies for underperformance.
A commercially sound SLA in a SaaS agreement covering India should include:
- Uptime commitment: Typically expressed as a monthly availability percentage (99.5% or 99.9% are common benchmarks)
- Measurement window: Uptime measured over a calendar month, excluding scheduled maintenance
- Maintenance windows: Defined periods for planned downtime, with advance notice requirements
- Response and resolution times: Tiered by incident severity (P1 through P4)
- Service credits: The remedial mechanism for SLA failures, expressed as a percentage of monthly fees credited against future invoices
- Exclusions: Force majeure events, customer-caused downtime, and third-party infrastructure failures are typically excluded from uptime calculations
Enterprise customers should note that service credits are not damages. Unless the SLA contains an explicit right to terminate for persistent SLA failure (typically defined as failure to meet uptime commitments for a consecutive number of months), credits are the sole remedy for underperformance.
5. Limitation of Liability
Every SaaS agreement should contain a limitation of liability clause. The question is not whether to include one, but how to structure it.
Standard positions in the Indian market:
- The SaaS provider’s total aggregate liability is capped at the fees paid in the preceding 12 months
- Consequential, indirect, and loss of profit claims are mutually excluded
- Certain obligations are carved out of the cap entirely: death or personal injury, fraud or wilful misconduct, and IP indemnities typically survive the cap
For DPDP Act compliance, the limitation of liability clause must be drafted carefully. A blanket liability cap that purports to limit liability for personal data breaches may be unenforceable to the extent it conflicts with the SaaS provider’s statutory obligations as a Data Processor. Altacit Global recommends that DPDP-related liability be addressed through a specific carve-out that defines the maximum liability exposure for data breach events separately from the general liability cap.
From the enterprise customer’s perspective, negotiate for uncapped liability where the SaaS provider’s breach of its data processing obligations causes a regulatory penalty under the DPDP Act. The financial exposure from a DPDP violation (up to INR 250 crore per violation) makes this a material commercial point.
6. Termination and Data Portability on Exit
Termination clauses in SaaS agreements require attention to two separate issues: the right to terminate, and what happens to data on termination.
Rights to terminate should include:
- Termination for material breach (with a cure period, typically 30 days)
- Termination for convenience (typically with 30 to 90 days notice)
- Termination for insolvency of the other party
- Termination for persistent SLA failure
Data portability and deletion on exit is the clause most frequently omitted from SaaS agreements and the one that creates the most operational difficulty at contract end. The agreement should specify:
- The format in which customer data will be exported (open, machine-readable format)
- The timeline for export access following notice of termination
- The period during which the provider will retain data post-termination to allow for extraction
- The certified deletion or destruction of all customer data following the retention period, with written confirmation
Enterprise customers should negotiate for a transition assistance period post-termination, during which the SaaS provider continues to provide services and cooperate with data migration at a defined rate.
7. Governing Law and Dispute Resolution
SaaS agreements in India should specify governing law and the dispute resolution mechanism explicitly.
For domestic India SaaS agreements, Indian law and jurisdiction in a specified city (Chennai, Bangalore, or Hyderabad, depending on the parties’ locations) is standard.
For cross-border SaaS agreements involving international enterprise customers or multinational SaaS providers, arbitration is the preferred mechanism. Key considerations:
- Seat of arbitration: Singapore (SIAC) or Mumbai (MCIA) are the most commonly selected seats for technology contracts
- Institutional rules: SIAC Rules 2025 or MCIA Rules 2021
- Number of arbitrators: Single arbitrator for lower-value disputes; three-member panel for high-value contracts
- Language: English
- Interim relief: Confirm that parties retain the right to seek emergency arbitration or interim relief from courts in India
Governing law and dispute resolution interact with IP ownership, data localization under the DPDP Act, and enforcement of awards. These provisions should be reviewed as a connected set, not in isolation. Our arbitration practice provides further guidance on structuring dispute resolution clauses for technology contracts.
SaaS Agreement vs Software Licence: Key Differences
The structural difference between a SaaS agreement and a software licence agreement in India is more than definitional. The two models carry different legal, tax, and commercial consequences.
Dimension | SaaS Agreement | Software Licence Agreement |
Delivery model | Cloud-hosted; customer accesses via browser or API | Software installed on customer’s servers or devices |
IP ownership | Provider retains all IP; customer receives no licence to the underlying code | Provider grants a licence to use the software; IP remains with vendor |
Customization rights | Limited by terms of agreement; requires specific negotiation | More commonly negotiated; source code access sometimes included |
Data residency | Data sits on provider’s infrastructure; location matters for DPDP compliance | Data sits on customer’s infrastructure; greater customer control |
Termination | Access terminated on contract end; data export critical | Licence persists unless revoked; software remains on customer systems |
GST treatment | Treated as a supply of service for GST purposes | May be treated as supply of goods or service depending on whether a perpetual licence is granted |
Regulatory applicability | DPDP Act DPA required if personal data is processed | DPDP Act applies if personal data is processed; structure depends on deployment |
Typical contract term | Annual or multi-year subscription with renewal | Perpetual or defined-term licence |
The GST treatment difference has real cash flow implications. SaaS subscriptions attract GST as a service at 18%. Perpetual software licences may be taxed differently depending on classification. Technology buyers and SaaS providers should confirm the correct GST classification with their tax advisors before finalizing pricing.
Data Processing Agreement Under the DPDP Act: Mandatory for SaaS Providers
The Digital Personal Data Protection Act 2023 requires Data Fiduciaries to enter into a contract with Data Processors that process personal data on their behalf. This contract is the Data Processing Agreement.
For SaaS providers in India, this is a mandatory legal requirement, not an optional addendum. The DPDP Act makes the Data Fiduciary responsible for ensuring that its Data Processors comply with applicable data protection obligations. A SaaS agreement that does not include or incorporate a Data Processing Agreement leaves the enterprise customer exposed to regulatory liability.
A compliant Data Processing Agreement under the DPDP Act framework must cover:
- Purpose limitation: The Data Processor may process personal data only for the purposes specified in the agreement and as directed by the Data Fiduciary.
- Sub-processor controls: The Data Processor must obtain written authorization before engaging sub-processors and must impose equivalent obligations on them.
- Security safeguards: The Data Processor must implement reasonable technical and organizational measures to prevent personal data breaches.
- Breach notification: The Data Processor must notify the Data Fiduciary of any personal data breach without undue delay, enabling the fiduciary to meet its notification obligations to the Data Protection Board of India.
- Data deletion: On termination of the agreement, the Data Processor must delete all personal data and provide confirmation of deletion to the Data Fiduciary.
- Audit rights: The Data Fiduciary must retain the right to audit the Data Processor’s compliance with the agreement.
Phase III of the DPDP Act, which brings full enforcement of processor obligations and the penalty framework (up to INR 250 crore per violation), is expected to take effect from May 2027. SaaS providers should treat this as a deadline for completing, not beginning, their DPDP compliance program. For a complete analysis of DPDP compliance obligations, refer to our DPDP Act Compliance Guide for IT and Tech Companies.
Altacit Global advises SaaS providers on structuring Data Processing Agreements that satisfy the DPDP Act framework while remaining commercially workable for enterprise customers. Our team assists companies operating across Chennai, Bangalore, and Hyderabad with end-to-end DPDP agreement preparation and review.
Terms of Service and Privacy Policy: Legal Requirements for SaaS
SaaS providers operating in India must publish a Terms of Service and a Privacy Policy that satisfy both the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and the requirements of the DPDP Act 2023.
Terms of Service must address:
- Acceptable use obligations and prohibited activities
- Liability disclaimers and service availability
- Subscription terms, payment, and renewal
- Intellectual property ownership and licence grants
- Governing law and dispute resolution
Privacy Policy must address:
- Categories of personal data collected
- Purposes for which personal data is processed
- Disclosure of sub-processors and third-party data sharing
- Cross-border transfer practices
- Data Principal rights (access, correction, erasure, withdrawal of consent)
- Retention periods
- Grievance officer details (mandatory under the IT Rules 2021)
The DPDP Act 2023 requires consent to be sought through a clear and plain language notice, separate from the Privacy Policy. Bundled consent embedded in terms of service does not satisfy the DPDP Act’s consent requirements. SaaS providers should implement a standalone consent mechanism for personal data processing that references the Privacy Policy but does not substitute it.
Structure Your SaaS Agreements Correctly From the Start
A poorly drafted SaaS agreement creates risk at every stage of the commercial relationship: unresolved IP ownership at product launch, liability exposure during a service outage, and data portability disputes at contract end. These are all foreseeable problems with documented legal solutions.
Altacit Global’s technology law team assists SaaS founders, product heads, and enterprise legal teams in drafting, reviewing, and negotiating SaaS agreements, software licensing agreements, Master Services Agreements, and Data Processing Agreements that comply with Indian law and the DPDP Act 2023. Our team advises technology companies across Chennai, Bangalore, and Hyderabad.
For a detailed review of your SaaS agreement or technology contract, contact us at info@altacit.com. We offer fixed-scope contract review engagements and end-to-end DPDP compliance advisory for SaaS businesses at all stages.
Frequently Asked Questions: SaaS Agreements India
Q1: Is a SaaS agreement the same as a licence in India?
No. A SaaS agreement and a software licence agreement are legally distinct. A SaaS agreement provides subscription-based access to software hosted on the provider’s infrastructure; the customer never receives a licence to the underlying code. A software licence agreement grants the customer specific rights to use software, typically installed on the customer’s own systems, and may include source code access. The two models carry different GST treatment, IP implications, and data residency consequences. Selecting the wrong agreement structure for the commercial relationship is a common and avoidable mistake.
Q2: What happens to my data if the SaaS provider goes insolvent?
Under Indian insolvency law (the Insolvency and Bankruptcy Code 2016), customer data held by an insolvent SaaS provider becomes part of the insolvency estate and is subject to the control of the insolvency resolution professional. Unless the SaaS agreement contains explicit data portability rights, certified deletion obligations, and provisions for access during a transition period, enterprise customers may find it difficult to retrieve their data promptly. The practical safeguard is a clearly drafted termination and data portability clause, combined with regular data exports throughout the contract term.
Q3: Can a SaaS provider modify the agreement unilaterally?
Only if the agreement permits it. Many consumer-facing SaaS terms of service include unilateral modification rights with notice. Enterprise SaaS agreements should not include unilateral modification rights for material terms, including pricing, SLAs, data processing obligations, and liability limits. Enterprise customers should negotiate for a mutual amendment requirement (written agreement signed by both parties) for any material change, and for a right to terminate without penalty if the SaaS provider modifies the agreement in a way that is materially adverse to the customer’s interests.
Q4: Is a verbal SaaS agreement binding in India?
A verbal agreement may be enforceable under the Indian Contract Act 1872 if it satisfies the elements of a valid contract (offer, acceptance, consideration, and capacity). However, verbal SaaS agreements are practically unenforceable. The terms are impossible to verify, the parties’ obligations cannot be documented with precision, and the DPDP Act’s requirement for a written Data Processing Agreement means that any SaaS relationship involving personal data processing requires written documentation as a matter of law. All SaaS agreements in India should be in writing, signed by authorized signatories, and reviewed by qualified legal counsel before execution.



