Contract Review Checklist for SaaS Agreements in India
A clause-by-clause checklist for SaaS agreements in India: SLAs, DPDP duties, IP in customer data, liability caps, exit, audits and sub-processors.
A SaaS agreement is the rental of somebody else's infrastructure with your data inside it, and the clauses that decide what happens when things go wrong are rarely the ones the sales conversation covers. This checklist works through the areas that determine whether an Indian customer can actually manage the relationship: service levels, data protection, intellectual property, liability, indemnity, exit, pricing, audit, the vendor's own supply chain, and the tax mechanics. The later items are the ones easiest to skip on a first read.
Service levels and service credits
Read the availability commitment together with its exclusions, because the exclusions define the number. Check the measurement window, since a monthly calculation and an annual one produce very different outcomes for the same outage. Check whether availability is measured platform-wide or for your tenant. Then check what is excluded: scheduled maintenance windows, emergency maintenance, force majeure, your own network, third-party dependencies and beta features.
Then check the remedy. Service credits are a discount, not compensation, and they are usually stated as the sole and exclusive remedy for downtime. If an outage would cost you materially more than a percentage of one month's fee, the clause worth negotiating is not a larger credit but a chronic-failure termination right: a defined number of missed months in a rolling period lets you exit without penalty and recover prepaid fees. Confirm whether credits must be claimed within a window, since unclaimed credits are commonly forfeited, and confirm that support response times are committed separately from uptime.
Data protection and DPDP considerations
In most SaaS arrangements the customer determines the purpose of processing and the vendor processes on its instructions. Section 8(2) of the Digital Personal Data Protection Act, 2023 provides that a Data Fiduciary may engage a Data Processor to process personal data on its behalf, for any activity related to the offering of goods or services to Data Principals, only under a valid contract. That makes the data processing terms a legal necessity rather than an annexure to skim. The Act received Presidential assent on 11 August 2023, and the Digital Personal Data Protection Rules, 2025 have since been notified in the Gazette; they are not a draft. Commencement is phased, with different provisions taking effect at different points rather than all at once, so confirm the exact provisions and the dates that apply to you from the Gazette notification and the material published by the Ministry of Electronics and Information Technology before committing to any compliance date in a contract.
Practical asks, whatever the phase-in position for your organisation: processing limited to providing the service with no independent use for the vendor's own purposes; a breach notification timeline short enough for you to meet your own obligations; cooperation with data principal requests for access, correction and erasure and with your grievance redressal process; defined security safeguards; deletion or return on termination; and disclosure of hosting locations with notice before they change. Separately, check the vendor's position under the CERT-In Directions dated 28 April 2022, issued under Section 70B(6) of the Information Technology Act, 2000, which require reporting of specified cyber incidents within six hours of noticing them and retention of ICT logs within Indian jurisdiction for a rolling period. Confirm the version of the directions currently in force and the applicable log retention period.
IP: customer data versus the product
Separate three buckets and make sure the contract does too. The vendor's platform, pre-existing IP and product improvements stay with the vendor and you receive a licence. Your data, content and configurations stay with you, and the vendor receives a narrow licence limited to providing the service. The contested middle is derived data, aggregated statistics, feedback and AI outputs.
Read carefully any licence granted 'to improve our services', which can extend to training models on your content. Ask for an express statement on whether customer data is used for model training and whether any resulting model is made available to other customers. Where the agreement contemplates bespoke development or deliverables you expect to own, note that Section 19(1) of the Copyright Act, 1957 requires an assignment of copyright to be in writing signed by the assignor or by his duly authorised agent: a clause stating that the customer 'shall own' the deliverable, without an express assignment, is weaker than it reads.
Liability cap: basis before size
Negotiate the basis before the number. Check whether the cap is calculated on fees paid in the preceding twelve months, total contract value or a fixed sum; whether it is per-claim or aggregate across the term; and whether it resets on renewal. A twelve-month fees cap on a small pilot is a very small number.
Then check what sits outside it. Carve-outs worth seeking are breach of confidentiality, data protection failures attributable to the vendor, the IP infringement indemnity, and fraud or wilful misconduct; expect the vendor to carve out your payment obligations in return. Read the exclusion of indirect and consequential loss line by line, because those lists often include the heads you actually care about, such as loss of data and the cost of procuring substitute services. Under Section 73 of the Indian Contract Act, 1872 damages are compensatory and remote losses are not recoverable in any event, and where a fixed sum is named as compensation for breach, Section 74 means a court will award reasonable compensation not exceeding that amount.
Indemnity scope
An indemnity is only as good as its scope, its exclusions and its interaction with the cap. Contracts of indemnity are addressed in Sections 124 and 125 of the Indian Contract Act, 1872, but the commercial work is done by the drafting. For the IP infringement indemnity, confirm it covers third-party claims that the service infringes IP, that the vendor controls the defence with your consent to any settlement affecting you, and that if the vendor cannot procure a right or modify the service you may terminate and recover prepaid fees.
Read the exclusions. Combination with your materials, your modifications, use outside the documentation and continued use after notice are standard, but they should not be drafted so widely that ordinary use falls outside cover. Where the service includes AI features, ask expressly whether the indemnity extends to outputs generated by those features.
Termination, exit and data return
Exit is commonly under-drafted in a SaaS agreement and is the part you will need under pressure. Confirm who may terminate for convenience and on what notice, whether prepaid fees are refunded, the cure period for breach, and what happens on insolvency, remembering that a moratorium under the Insolvency and Bankruptcy Code, 2016 can constrain what a counterparty may do once proceedings begin. Take advice on the current position for your specific situation.
Then draft the exit mechanics rather than assuming them: the export format and whether its schema is documented, the period after termination during which export remains available, whether transition assistance is offered and at what rate, certification of deletion, and whether the vendor may suspend the service for non-payment while a good-faith dispute is running. A contract promising data return in 'a commercially reasonable format' has promised nothing.
Price escalation and renewal
Cap the uplift and pin the mechanism. Check whether escalation applies to list price or to your discounted price, whether it is capped at a stated percentage or tied to a named published index, and whether additional seats and modules bought later attract the same discount. Then check the renewal notice window against your own approval cycle, since an auto-renewal requiring sixty days' notice is a trap for an organisation whose budget approvals take ninety. Confirm the overage mechanism too: what happens when you exceed committed volumes, and at what rate.
Audit rights
On-site customer audits are rarely granted by multi-tenant SaaS vendors, and asking for one you will never exercise spends negotiating capital badly. The realistic package is an annual independent assurance report or certification shared under NDA, a security questionnaire with a committed response time, audit rights over the vendor's compliance with the data processing terms, and, if you are a regulated entity, the access rights your regulator requires. Financial-sector customers should check the Reserve Bank of India directions on outsourcing and IT governance applicable to their entity type, since those directions drive specific contractual requirements including supervisory access. Confirm the version of the applicable directions currently in force.
Sub-processors and the supply chain
Your data will not stay with the vendor you signed with. Ask for the sub-processor list at signature, a notice period before additions, an objection right with a defined consequence (usually termination without penalty if the objection cannot be resolved), and a statement that the vendor remains liable for its sub-processors' acts and omissions as for its own. Check whether affiliates are excluded from the definition of sub-processor, and check how model and AI infrastructure providers are treated, since these are often the sub-processors that see the most content.
Indian tax and invoicing mechanics
Two commercial points belong in the review. State whether fees are inclusive or exclusive of GST, and confirm the invoice will carry your GSTIN and the correct place of supply, because input tax credit under Section 16 of the Central Goods and Services Tax Act, 2017 depends on the supplier's compliance as well as your own. For payments to a non-resident vendor, identify the withholding position and any double taxation avoidance agreement relief available under the governing income-tax legislation, then read the gross-up clause, which decides who bears that cost. Note that the Income-tax Act, 2025 has replaced the Income-tax Act, 1961, so section numbers taken from older precedents, templates or commentary should not be relied on: verify the current provision against the bare Act before citing it. The characterisation of software and SaaS payments is fact-specific, so take advice rather than copying a clause from another deal.
Running the checklist in practice
Turn this into a scored review rather than a reading exercise. Record your standard position on each area, mark every incoming agreement against it, and keep a note of which deviations you accepted and why, because that record is what turns individual negotiations into a playbook. LexVio produces a 0-100 Legal Health Score with clause-level risk flags on a reviewed agreement, together with tracked-change redlines exportable to Word; Nexus extends the same view across a portfolio with search by clause type, clause benchmarking and drift alerts when executed positions move away from your standard. The Legal Health Score is LexVio's own assessment of the document as reviewed and is not weighted to your playbook, so the record of accepted deviations remains a discipline your team maintains alongside it. The judgment about which deviations are acceptable stays with the person who signs off.
