Back to Knowledge
Close-up of a person in a dark suit signing a document on a desk, only the hands and pen visible.
Your code is the product. Your contract is what makes the customer buy it.

Sales

Your first UK SaaS contract: clauses that matter at seed stage

Liability under UCTA, indemnities, IP on customer data, UK GDPR wording. Three clauses decide the rest.

7 min read

Your first paid customer will either send you their paper or wait for yours. Send yours. A short, fair SaaS contract drafted for your business reduces every later negotiation to a redline conversation rather than a restart from a Word document built for someone else. Budget 4,000 to 8,000 pounds of solicitor time on the first template; you will reuse it for the next fifty customers.

The contract sits on top of three UK frameworks: the Sale of Goods Act 1979 and Supply of Goods and Services Act 1982 (terms implied into services contracts), the Unfair Contract Terms Act 1977 (UCTA, the statute that decides which liability exclusions you can rely on in B2B), and UK GDPR plus the Data Protection Act 2018 (the data layer, the subject of its own article). Plant the contract in that frame and the rest reads itself.

Liability cap

The cap is the number your customer will negotiate hardest. UK market for seed SaaS is 12 months of fees paid in the 12 months preceding the claim, with carve-outs for confidentiality breaches and IP indemnities. UCTA s.2(1) forbids excluding liability for death or personal injury caused by negligence outright. UCTA s.2(2) plus s.3 (in business-to-business contracts on written standard terms) make any other exclusion subject to a reasonableness test under UCTA s.11 and Schedule 2. A 12-month-fees cap is consistently held reasonable; an absurdly low cap (one month, fixed fee at 1,000 pounds) for a high-value contract is consistently held unreasonable and struck down entirely.

An enterprise customer wants uncapped liability on IP infringement and confidentiality. Can I sign?

Probably yes, with conditions. Uncapped IP indemnity is market-standard for enterprise SaaS once your IP hygiene is in place: a written third-party-licence inventory, no copyleft code in the shipped product, contributor license agreements (CLAs) from outside committers, and clear provenance for any training data feeding AI features. With all four, uncapped IP indemnity is signable. Uncapped confidentiality is also defensible if your breach-notification SLA is tight and you carry cyber insurance with a confidentiality endorsement. Anything broader (uncapped on security, uncapped on SLA, uncapped on everything) means walk away or rescope.

Indemnities, not the same as liability

An indemnity is a contractual promise to compensate the other party for a specified loss, often sitting outside the liability cap. UK customers ask for three: an IP infringement indemnity (you defend and pay if your product infringes a third party's IP), a data protection indemnity (you cover their UK GDPR fines if caused by your breach), and a confidentiality indemnity (you cover their losses from your leak). Grant the IP indemnity, push back hard on the data indemnity (the Information Commissioner's Office can fine the customer directly under UK GDPR, and you cannot insure that risk for them without specialist coverage), and refuse standalone confidentiality indemnities in favour of caps with carve-outs. Indemnities trigger UCTA scrutiny too, so the same reasonableness test applies.

Data and IP ownership

Be explicit. The customer owns its data, including personal data and tenant-derived analytics. You own the product, including improvements you make while serving them. You receive a licence to use customer data only to operate and improve the service. Avoid clauses that hand the customer rights to derived data unless you have thought through what that means for your model, especially if you train AI on cross-tenant signals. A 'no use of customer data for training' clause should be a hard yes or a paid upgrade, not a silent concession. Watch the CDPA 1988 default: copyright in code your team writes vests in the company under s.11(2) only if they are employees, so contractor agreements must include explicit IP assignment.

Term, renewal, termination

Annual term with auto-renewal and a 30-day notice window is the UK B2B SaaS default. Termination for material breach should be mutual, with a 30-day cure period. Termination for convenience is rare in B2B SaaS but enterprise customers ask; if granted, attach pro-rata refund and a notice of at least 90 days to protect cash flow. Add a material adverse change (MAC) clause for the customer's insolvency: under the Insolvency Act 1986, you cannot enforce ipso facto termination against a customer in administration without the administrator's consent, so frame the MAC as a payment-acceleration trigger rather than an automatic termination.

What is the practical difference between English law and English jurisdiction?

Two separate clauses doing two separate things. The governing law clause picks the body of law the courts apply (English and Welsh law, Scots law, Northern Irish law are distinct UK jurisdictions). The jurisdiction clause picks which courts hear disputes (commonly the English courts at the Royal Courts of Justice in London, the Business and Property Courts). Use English law and the exclusive jurisdiction of the English courts for any contract worth under 2 million pounds. Arbitration under LCIA or ICC rules adds 50,000 to 150,000 pounds of admin cost before the first hearing and makes sense only at higher contract values.

UK GDPR wording without overpromising

Include a short data protection clause that points to a separate Data Processing Addendum (DPA) for the operational detail. The clause should confirm controller and processor roles, list the data categories, point to the sub-processor list, and cross-refer to UK GDPR Articles 28, 32 and 44 plus the Data Protection Act 2018. Do not try to cover GDPR in the main contract; the DPA is a separate signed document for good reason. UK enterprise customers (especially in financial services regulated by the FCA) will read your DPA before they read your main agreement, so the cross-references must match.

Should I add a Most-Favoured-Nation clause for the first customer who asks?

No. MFN clauses (the promise that no other customer gets better terms) sound like a small concession at deal close and become a strategic straitjacket six months later when you want to run a discounted pilot or a strategic logo deal. If the customer needs price protection, give a fixed-percentage discount with a sunset, not an MFN. Once an MFN is in any contract, you must check every new deal against it for years.

Things to skip in version one

Service credits, SLA penalties and complex governance committees belong in enterprise contracts, not seed paper. Keep your first contract under 15 pages. If it is longer, you are negotiating against yourself.

Sources

  1. 01Unfair Contract Terms Act 1977, ss.2-3 and Schedule 2 (reasonableness test for liability exclusions)(UCTA 1977 ss.2-3, Sch.2)
  2. 02Supply of Goods and Services Act 1982, s.13 (implied term: reasonable care and skill)(SGSA 1982 s.13)
  3. 03UK General Data Protection Regulation, Articles 28, 32, 44 (processor contracts, security, transfers)(UK GDPR Arts. 28, 32, 44)
  4. 04Data Protection Act 2018 (companion to UK GDPR)(DPA 2018)
  5. 05Insolvency Act 1986, Schedule B1 (moratorium on enforcement against companies in administration)(IA 1986 Sch.B1)
  6. 06Copyright, Designs and Patents Act 1988, s.11 (first ownership of copyright)(CDPA 1988 s.11)