Practice · SaaS contracts, MSAs and DPAs
The SaaS contract stack: MSAs, DPAs and the terms that close enterprise deals
A SaaS company's revenue depends on four documents: the terms of service its self-serve customers accept, the master services agreement its enterprise customers negotiate, the data processing agreement their privacy teams require, and the privacy policy that must agree with all three. Penwell Law drafts and negotiates that contract stack for SaaS and AI companies, with terms written to close enterprise deals.
The MSA and order form
Enterprise procurement will send its own paper, and negotiation always centers on the same terms: limitation of liability and its carve-outs, indemnification for IP and data claims, service levels and credits, termination and data return, and audit and security commitments. Penwell Law keeps a negotiation position for each, knows which positions are market for a company of the client's size, and tells the founder which terms matter most for the deal. The order form carries the commercial terms so the MSA can stay in place for years. Recurring deals get a negotiation playbook with the fallback for each contested term and the approval required to go past it, so routine contracts close without escalation to legal.
The DPA, the security addendum and the questionnaire
The data processing agreement is the document an enterprise customer's privacy team must approve before the deal signs. Under the CCPA and CPRA, a service provider contract must contain specific terms, and Article 28 of the GDPR specifies the processor clauses; a DPA that misses them is a compliance failure for the customer, which is why its privacy team will not sign without them. Penwell Law maintains a DPA that satisfies both regimes, with the standard contractual clauses and a transfer impact assessment ready for European customers, and a security addendum that matches the company's actual security practices. A security questionnaire is answered as a legal document, because its answers are incorporated into the contract as representations. Penwell Law negotiates customer-driven security terms as legal commitments and writes the incident response plan so that the notification decision under the contracts and California Civil Code section 1798.82 can be made within hours.
Privacy by design, in the product
Penwell Law reviews privacy at the design stage: data mapping, DPIAs where the processing warrants one, consent and notice frameworks, and cross-border data transfers under the GDPR, written into product and vendor terms for the engineering team. For AI products, the review covers training and inference data, including training-set provenance, secondary-use limits and the automated decision-making rules in the California Privacy Protection Agency's regulations, whose automated decision-making duties apply from January 1, 2027.
Terms of service and privacy policy that match the product
Terms of service copied from another company describe that company's product. Penwell Law drafts terms from the product itself: what the service does, what the customer may do with it, what the company may do with customer data, including whether it trains on that data, and what the company disclaims. For AI products, the acceptable-use policy, the output terms and the model-provider pass-through terms belong to the same document set, and the privacy policy is written last so that it describes what the contracts already permit.
Negotiating to close
Penwell Law drafts to market terms so the other side's lawyer can approve without escalation. It concedes minor terms and holds its positions on the clauses that carry real risk: liability caps, indemnity scope and data terms. Each concession and its reason go into the playbook, so the next negotiation starts from the last deal's terms.
Common questions
Frequently asked questions.
What should be in a SaaS master services agreement?
A SaaS master services agreement should cover scope and order-form structure, fees and payment, service levels, data protection and security commitments, intellectual property and license grants, confidentiality, warranties and disclaimers, indemnification, limitation of liability, term and termination, and data return. Negotiation turns on liability caps, indemnity scope and data terms.
When does a SaaS company need a data processing agreement?
A SaaS company needs a data processing agreement whenever it processes personal information on behalf of a customer covered by the CCPA or the GDPR. The CCPA and CPRA require specific service-provider contract terms, and Article 28 of the GDPR requires processor clauses whenever the customer's processing falls under the GDPR. Enterprise customers will not close without one.
Can a SaaS company train its AI on customer data?
A SaaS company can train AI on customer data only when its customer contracts clearly permit it and its privacy policy discloses it. Under the GDPR, a company that trains its own models on customer data also needs its own lawful basis as a controller. Penwell Law drafts the customer terms, the DPA and the privacy policy together so the answer is consistent across all three, and counsels on the FTC exposure of training on data customers did not expect to be used.
Does Penwell Law review contracts the customer sends, or only draft the company's own?
Both. Most enterprise deals arrive on the customer's paper, and the practice negotiates those as often as it drafts the company's templates.
Writing
Liam writes on the legal questions behind building and shipping technology: AI governance, privacy, and content rights. Read the blog →
Latest: Your Crawler Needs an Alibi
Start the conversation.
Contact
Based in Burlingame, California, working with clients and teams across Silicon Valley, the Bay Area, and nationally.
Inquiries