A cloud or SaaS contract looks harmless at signing. The pricing is clear, the product works, and the supplier says the terms are standard.
The problem shows up later. When the service goes down, when data is exposed, or when a major customer asks what protection you actually have. That is the moment the contract stops being paperwork and starts deciding who carries the loss.
For a scaling tech business, your product often runs on other people's infrastructure. Your suppliers' contracts are effectively part of your own risk profile, whether you have read them closely or not.
Liability caps are where the real risk hides
The liability cap sets the maximum a supplier will pay you if they fail. In most standard cloud and SaaS terms, that cap is low. Often it is limited to the fees you paid in the previous twelve months.
Picture the mismatch. You pay a supplier fifty thousand pounds a year. Their platform fails, you lose a key customer worth ten times that, plus the cost of putting things right. Under a standard cap, your recovery is limited to roughly what you paid. The rest sits with you.
This is why the cap matters more than the price. A cheaper contract with a punishing cap can be far more expensive than a dearer one that shares risk properly.
Watch for the exclusions
Even where a cap looks reasonable, the exclusions often remove the cover you most need. Standard terms frequently exclude liability for loss of profit, loss of data, business interruption and indirect loss.
Those are precisely the losses a tech business suffers when a supplier fails. If they are carved out, the headline cap can be close to meaningless. Read the exclusions before you take comfort from the cap.
Service levels that promise less than they appear to
Uptime commitments look reassuring. A promise of high availability suggests the service will almost always be there. The detail decides whether that promise is worth anything.
- How is uptime measured, and over what period? A monthly figure hides a lot compared with a daily one.
- What counts as excused downtime? Maintenance windows and third party failures are often excluded.
- What do you actually get if they miss the target? Usually a small service credit, not real compensation.
Data protection terms that do not match reality
If your supplier processes personal data on your behalf, you need a Data Processing Agreement (DPA) that reflects what actually happens. Under UK General Data Protection Regulation (UK GDPR), you remain responsible to your own customers even when a supplier causes the breach.
Check what the DPA really says. Where is the data stored and processed? What happens if it moves outside the UK? What are the supplier's obligations if they suffer a breach, and how quickly must they tell you? If the terms are vague, the risk lands on you when a regulator or customer starts asking questions.
Exit and termination. The clause everyone forgets
Signing up is easy. Getting out is where businesses get stuck. Weak exit terms can leave you trapped in a service that no longer fits, or unable to retrieve your own data on sensible terms.
- Can the supplier terminate at short notice or change the terms unilaterally?
- How do you get your data back on exit, in what format, and at what cost?
- Is there a transition period to move to another provider without disruption?
Exit terms rarely feel urgent when you are signing. They become urgent fast when the relationship sours or the supplier is acquired and priorities change.
Concentration risk and digital resilience
Many tech businesses now depend on a small number of critical providers. If one of them fails, the effect can ripple through your whole operation. Regulators are increasingly focused on this, and larger customers are asking harder questions about how resilient your supply chain is.
Knowing which suppliers are genuinely critical, and what your contracts say when one of them stops working, is becoming part of running a credible business at scale.
What to check before you sign the next one
- The liability cap, and whether it bears any relation to the harm a failure could cause.
- The exclusions, especially loss of profit, data and business interruption.
- The real value of the service levels, not just the headline uptime figure.
- Whether the data protection terms match how your data is actually handled.
- Your exit rights, data return and the ability to move providers cleanly.
The bottom line
Standard cloud and SaaS terms are written to protect the supplier, not you. That is not a scandal. It is simply the starting position, and it is one you can negotiate from if you know where the risk sits.
The businesses that check these terms before signing keep the risk where it belongs. The ones that assume standard means safe find out the hard way, usually at the worst possible moment.
Before you sign the next cloud or SaaS contract, get the risk checked properly. Book a call with the Ethiqs team