Skip to main content
Certyneo

B2B SaaS Agreement – India template

Free
Customizable
Electronic signature

Overview

A B2B SaaS Agreement governs the subscription relationship between an Indian software-as-a-service provider and a business customer, covering access to the software, service levels, data handling, fees, and the parties' respective liabilities. Its enforceability as a contract rests on the Indian Contract Act 1872, and it is typically formed and signed electronically, which is expressly permitted under the Information Technology Act 2000. Electronic formation and signature: Sections 4 and 5 of the Information Technology Act 2000 give legal recognition to electronic records and electronic signatures, meaning a SaaS agreement validly entered into and signed online is enforceable in the same way as a paper contract, subject to the requirements the Act and its rules set for the signature method used. Where the provider handles sensitive personal data or information (as defined under the IT Rules), the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 require the body corporate to maintain documented reasonable security practices and to notify affected parties in the event of a security breach affecting such data. Data protection under the DPDP Act 2023: where the SaaS product processes personal data belonging to the customer's own end users (employees, customers, or other data principals), the Digital Personal Data Protection Act 2023 becomes relevant. The customer will typically be the Data Fiduciary determining the purpose and means of processing that personal data, while the SaaS provider acts as a Data Processor processing that data on the customer's instructions. The agreement should allocate the parties' respective obligations accordingly — including instructions-based processing, deletion or return of data on termination, and cooperation with the Data Fiduciary's obligations to data principals and to the Data Protection Board of India, as the DPDP Act's rules and enforcement mechanisms come into force. GST treatment: the supply of SaaS is generally treated as a supply of service under India's GST law. Whether a particular transaction attracts Central GST plus State GST (an intra-state supply) or Integrated GST (an inter-state supply, including exports) depends on the place-of-supply rules applicable to the transaction, which in turn depend on the location of the supplier and the recipient and, in some cases, on whether the transaction qualifies as an export of services. Where the customer is located outside India, the transaction may qualify for export-of-service treatment subject to conditions under the IGST Act, including receipt of payment in convertible foreign exchange. Parties should confirm the correct GST treatment and invoicing for their specific arrangement rather than assume a single default. Data localisation and cross-border transfer: depending on the sector and the nature of the data processed (for example, payment data subject to sector-specific localisation requirements, or personal data subject to the DPDP Act's cross-border transfer provisions), the parties may need to address where data is stored and processed, and any restriction on transferring it outside India. Core commercial terms: scope of the software service and permitted use, subscription fees and payment terms, service level commitments (uptime, support response times) and any service credit remedy for failure to meet them, data ownership and processing terms consistent with the DPDP Act framework described above, limitation of liability and indemnity provisions, intellectual property ownership (the provider retaining ownership of the software, the customer retaining ownership of its data), and termination provisions including the customer's right to export its data within a reasonable period after termination. When to use this agreement: whenever an Indian SaaS provider is onboarding a new business customer on a subscription basis, whether the customer is based in India or abroad. Common drafting mistakes: failing to clearly allocate Data Fiduciary and Data Processor roles under the DPDP Act, omitting a data export or deletion commitment on termination, assuming a single GST treatment without checking the place-of-supply analysis for the specific customer, and setting a limitation of liability clause without considering whether it would be enforceable under the reasonableness standards applied by Indian courts to standard-form contracts.

Information to customize

  • Name of the SaaS provider

  • Registered address of the provider

  • Name of the business customer

  • Registered address of the customer

  • Description of the SaaS product/service

  • Subscription fee and billing frequency

  • Service level commitment (uptime %)

  • Data Fiduciary / Data Processor allocation

  • Limitation of liability cap

  • Termination notice period (days)

  • State whose courts have jurisdiction

  • Effective date of the agreement

Customize your template

Signature recipient

Frequently asked questions

Is an electronically signed SaaS agreement valid in India?
Yes. The Information Technology Act 2000 gives legal recognition to electronic records and electronic signatures, so a SaaS agreement formed and signed online is enforceable in the same way as a paper contract, provided the signature method used meets the requirements of the Act and its rules.
Who is the Data Fiduciary and who is the Data Processor under this agreement?
Under the Digital Personal Data Protection Act 2023, the business customer is typically the Data Fiduciary determining why and how its end users' personal data is processed, while the SaaS provider acts as a Data Processor handling that data on the customer's instructions. The agreement should state this allocation explicitly rather than leave it implied.
Does GST apply to a SaaS subscription in India, and at what rate?
SaaS is generally treated as a supply of service under GST law. Whether CGST+SGST or IGST applies depends on the place-of-supply rules for the specific transaction, including whether the customer is located in the same state, a different state, or outside India (where export-of-service treatment may apply subject to conditions). Confirm the applicable treatment with a tax advisor for your specific customer base.
What happens to our data if we cancel our SaaS subscription?
A well-drafted agreement should guarantee a reasonable period after termination during which the customer can export its data in a usable format, followed by deletion or return of the data by the provider in accordance with the customer's instructions and applicable law, including the Digital Personal Data Protection Act 2023 where personal data is involved.
Can this agreement limit the SaaS provider's liability?
Parties can agree a limitation of liability clause under the Indian Contract Act 1872, but certain liabilities (for example, arising from gross negligence, wilful misconduct, or obligations that cannot be excluded as a matter of law) generally cannot be limited or excluded. The enforceability of a liability cap in a standard-form contract can also be reviewed by a court for reasonableness, so it should be set at a level the provider can justify.

Information about this template

Last updated
31 August 2026
Country
IN
Legal notice
This template is provided for information purposes only and must be adapted to your situation. It does not constitute personalised legal advice.