Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Commercial Contracts and Terms of Sale6 min read

SaaS terms of sale: essential clauses for online software

Which clauses belong in your SaaS terms of sale in 2026? Scope, GDPR, SLA, Data Act exit arrangements, price, termination and liability. An actionable, up-to-date guide.

Your general terms of sale structure the commercial relationship for your online software. In 2026, they must reconcile French law (Code de commerce), customer confidence (SLA and security), GDPR compliance and new Data Act portability/exit requirements. This operational guide lists the essential clauses, with practical points to watch.

For tailored support, you can Discuss your firm's AI transformation or Explore AI and law resources. You can also read our articles on contracts and terms of sale.

1) Purpose and scope of the service

Describe precisely what the customer is buying. This is the primary source of disputes… and the provider’s first line of protection.

  • Delivered features (modules, integrations and available APIs), technical environment (supported browser and versions), limitations (number of users, storage and API throughput), prerequisites (SSO, browser and network).
  • Clear exclusions: Internet connections, devices and third-party services (email, ERP), customer-provided content.
  • Changes: ability to improve/modify features without fundamentally altering the essential service; information procedure.

Communicating terms of sale and their essential elements remains a B2B obligation (pre-contractual information and payment terms). See Service-Public Pro — terms of sale and the Code de commerce (particularly art. L441-1 and L441-10 on information obligations and payment deadlines).

Practical wording

  • “The Service includes A, B, C. Excluded are X (Internet access), Y (maintenance of customer systems), Z (data provided by third parties). Limits: U named users, S GB storage, Q API calls/day.”

2) Accounts, usage rights and prohibited uses

  • Non-exclusive, non-transferable usage licence; scope (legal entity, subsidiaries and territory).
  • Access management (named accounts, credential security and recommended MFA) and fair use (prevent abuse of shared resources).
  • Prohibited uses (intrusion attempts, mass scraping outside the API, reverse engineering and unlawful content).

3) Availability, SLA and support

  • Contractual uptime (e.g. 99.9%), maintenance windows, RTO/RPO targets, incident priorities, support channels/hours.
  • SLA credits (credit notes) and exclusions (force majeure, Internet, customer fault and third-party services). See good practices discussed in professional guides such as LegalPlace.

Model clause: structure

  • “Monthly availability: 99.9%. Scheduled maintenance: Saturday 22:00–02:00 CET (72-hour notice). If availability < target, a credit of X% of monthly fees applies. Excluded: (i) Internet, (ii) third-party services, (iii) misuse.”

4) Personal data and GDPR (DPA)

The GDPR requires a written data processing agreement (art. 28) where you process personal data on behalf of the customer. Specify subject matter, duration, purposes, categories of data and individuals, security measures, audit, sub-processors, transfers outside the EU and breach notification. See CNIL and the text of the GDPR on EUR‑Lex.

  • Roles: the customer is the controller, the SaaS provider is the processor (or joint controller depending on the use case).
  • Technical measures: encryption at rest/in transit, logging, logical segregation, backups and business continuity/disaster recovery plans.
  • Sub-processors: list, notification of changes and a reasonable right to object.
  • Transfers outside the EU: mechanisms (standard clauses) and customer information.

5) Information security

  • Enhanced duty of care (informed by standards such as ISO 27001), without promising infallibility.
  • Vulnerability management (remediation SLA), testing (periodic penetration tests), logs (retention period), incident notification within a defined timeframe.
  • Continuity plan and tested backups.

6) Exit arrangements, portability and Data Act

Exit arrangements are no longer optional. The Data Act (UE) 2023/2854 imposes rules on data access/portability and cloud-provider switching (gradual reduction of switching charges and migration requirements), applicable progressively from 2025–2026.

  • Export: documented open formats (CSV, JSON, Parquet), scope (data, metadata and necessary logs), extraction deadlines.
  • Migration assistance: support levels, limits and reasonable billing.
  • Deletion/anonymisation at contract end after return (deadlines and evidence of deletion).

Data Act points to watch

  • Avoid any clause improperly locking customers in; document realistic transfer interfaces and procedures; provide for the path to reducing switching charges in accordance with the Regulation.

7) Price, billing and indexation

  • Pricing structure (per user, usage or edition), options, minimums, indexation (INSEE index and cap).
  • Billing and payment deadlines compliant with the Code de commerce (art. L441‑10), and penalties/fixed compensation.
  • B2B electronic invoicing: anticipate the reform and its deadlines from 2026. See economie.gouv.fr for the timetable and Service‑Public Pro for practical arrangements.

Price revision clause

  • “The Provider may adjust prices with 30 days’ written notice. For an increase > X%, the Customer may terminate within 15 days, effective at the end of the current period.”

8) Term, renewal and termination

  • Subscription: monthly/annual, automatic renewal and non-renewal arrangements.
  • Termination for breach (cure notice), termination for convenience (if offered), effects (read-only access, exit arrangements and deletion).

9) Intellectual property and content

  • Software and trademarks: provider’s rights reserved; no assignment without express provision. See reminders from INPI on protecting software and intangible assets.
  • Customer data/content: customer ownership; limited licence to the provider for performance (hosting, backup and support).
  • Feedback and suggestions: permission to freely use non-confidential feedback.

10) Liability, warranties and force majeure

  • Limitation of liability: caps (e.g. 12 months of fees), exclusion of indirect loss (lost revenue, unbacked-up data), except gross negligence/wilful misconduct and privacy infringements under applicable law.
  • Limited warranties (substantial conformity, service “as is” outside scope).
  • Force majeure (external, unforeseeable and irresistible events, see Code civil, art. 1218), and disclaimer for Internet outages.

11) B2C compliance: where users are consumers

  • Clear pre-contractual information, withdrawal right and exceptions for digital content/services where performance has begun with express agreement.
  • Consumer mediation: mediator’s contact details in case of dispute. See economie.gouv.fr and justice.fr (mediation) for applicable principles.

12) Enforceability and evidence of acceptance

  • Express acceptance (unticked checkbox, electronic signature), timestamp, archiving evidence.
  • Updates: information/notice procedure; termination right for a materially adverse change.
  • Governing law and jurisdiction (B2B: valid jurisdiction clause; B2C: mandatory consumer protections).
  • Subcontracting clause and contract assignment (reasonable prior control).
  • Confidentiality, customer references (with a right to object), notification (email, portal and registered mail).

Quick checklist: adapt as necessary

  • Defined purpose/scope, explicit limitations and exclusions.
  • Documented SLA (uptime, support and credits), maintenance and Internet disclaimers.
  • Complete GDPR DPA (art. 28), security, processors and transfers.
  • Exit arrangements/portability: formats, deadlines, assistance (+ Data Act compliance).
  • Price, electronic invoicing (2026 deadlines) and L441‑10 penalties.
  • Term, renewal, termination and effects (read-only access, deletion).
  • IP and customer content; capped liability; force majeure.
  • Acceptance/archiving of terms of sale; update procedure.

2026 roadmap: Data Act + e-invoicing

  1. Map the data processed and flows (who? where? how long?).
  2. Update the DPA and security schedules (logs, backups and remediation).
  3. Design exit arrangements: exports, APIs, migration playbooks and charges compliant with the Data Act.
  4. Review prices/billing and anticipate electronic invoicing (processes, formats and platforms).
  5. Legal review of liability/force majeure and B2C compliance where relevant.

In B2B, missing GDPR or portability clauses may expose you to administrative penalties (CNIL up to 4% of worldwide turnover) and competition-related non-compliance under the Data Act. See CNIL and EUR‑Lex.

Further reading

See our related guides: Terms of use vs terms of sale: differences and obligations, Services agreement: template and GDPR and AI: legal obligations.

Further reading

Related resources

Frequently asked questions

FAQ

Which clauses are essential in SaaS terms of sale?

Scope and exclusions, accounts/licences, SLA and support, security/GDPR (DPA), exit arrangements/portability (Data Act), price/billing, term/termination, IP, liability/force majeure and governing law.

Does the Data Act apply to all SaaS?

It imposes rules on data access portability and provider switching for cloud services. Many obligations become effective from 2025–2026; adapt your exit and migration clauses.

How can liability be limited without unfair terms?

Set a cap (e.g. 12 months of fees), exclude indirect loss, provide SLA credits and list exclusions (Internet and third parties), while retaining mandatory statutory liabilities.

Are terms of sale enough to cover GDPR requirements?

No. A DPA (art. 28 GDPR) is required, specifying purposes, security measures, processors and transfers, with incident notifications and audit arrangements.

What should data exit arrangements include?

Open formats (CSV/JSON), export scope, deadlines, migration assistance, reasonable cost, post-contract deletion and Data Act compliance.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles