SaaS contracts under US law

US law for software companies with US lawyers in Munich

Your SaaS product is attracting customers in the US, a US partner is set to distribute your software, or a US company wishes to licence your code – yet your existing contract is tailored to German customers. For German software companies with US ambitions, the contractual framework therefore often becomes the first real hurdle in the United States.

We advise German software companies on the contractual and legal aspects of setting up their US operations. This advice is provided by our US lawyers in Munich – in collaboration with our colleagues in New York, Boston and San Francisco where necessary.

Challenges

US customers and US partners expect contractual structures that differ from standard German terms and conditions – in terms of liability limitations, notice periods and service level agreements. Anyone who applies a German contract to the US market without modification runs risks that often only become apparent in the event of a dispute.

Added to this are US data protection laws at state level and open-source licence chains, which US investors scrutinise closely during due diligence – often without founders being prepared for this.

Solutions

We draft SaaS contracts, service level agreements and liability clauses in such a way that they are legally sound in the US – whilst still remaining valid in Germany.

We assess the specific implications of US data protection law and open-source licence chains for your product before investors or customers ask about them. This ensures you are well prepared for negotiations and due diligence reviews.

Let’s talk about your US contracts.

Whether it’s a SaaS contract, a licensing model or a distribution structure: during the initial consultation, we clarify what contractual framework your software product requires for the US market and where improvements are needed. You’ll speak directly to our US lawyers in Munich – and where necessary, we’ll bring in our colleagues in New York, Boston or San Francisco.

Our services

Four building blocks for the legal foundation of your US business – from SaaS and licence agreements, through US data protection law and open-source safeguards, to setting up your sales structure. All four follow the same principle: contracts and structures that are legally sound under US law and do not hinder your business model.

Drafting SaaS and licence agreements under US law

US customers and US partners expect contractual structures that differ significantly from standard German terms and conditions: their own service level agreements with clearly quantified availability guarantees, far-reaching limitations of liability and notice periods which, in line with US practice, are shorter and more unilateral than is customary under German law. The licensing structure itself – whether subscription-based, usage-based pricing or a reseller model – also has a direct impact on the contractual arrangements, as each model allocates risks and payment obligations differently.

We draft and review SaaS and licence agreements to ensure they are legally sound in the US whilst also aligning with your existing German contractual framework. We tailor service level agreements, liability clauses and termination provisions to your specific licensing model – whether it involves direct sales, subscriptions or reseller business.

Understanding US data protection law and the CCPA

There is no uniform US federal data protection law: data protection in the US is largely a matter for the individual states, each with its own state privacy laws and its own systems of fines. The best known of these is the California Consumer Privacy Act (CCPA), which imposes specific rights of access, erasure and objection on companies with Californian users – regardless of whether the company itself is based in the US. For SaaS providers with German GDPR processes, this means that their European compliance structure does not automatically cover US requirements.

We assess which US data protection obligations apply to your product and user base, and highlight where your GDPR processes need to be supplemented. This creates a data protection framework that is effective in California and other US states, without requiring you to set up a duplicate compliance structure for Europe.

Clarifying open-source licence chains and IP issues

Many software products are based on open-source components whose licence terms are interpreted and enforced differently in the US than in Germany – this applies to copyleft licences such as the GPL as well as to permissive licences. Anyone entering into negotiations with US customers or US investors must expect the licence chain to be scrutinised in detail as part of a due diligence review – right down to the individual component.

We can help you review your open-source licence chains and identify areas where improvements are needed before an investor or client due diligence process begins. This ensures you are well prepared for the review, rather than having to answer questions only once the process is already underway.

Establishing sales structures in the USA

Direct sales, resellers and system integrators are the most common distribution channels for software in the USA – and each comes with its own contractual requirements: commission arrangements and exclusivity for resellers; liability and support issues for system integrators; and differing termination and non-competition clauses depending on the distribution model. A contract that is suitable for direct sales does not automatically apply to a reseller or partner model.

We provide legal support for the establishment of your US sales structure, from the initial partner agreement through to ongoing support, and tailor each agreement to the specific sales model.

Frequently Asked Questions

It is not strictly necessary, but the key clauses – the service level agreement, limitation of liability and notice periods – must be adapted to US requirements. We will review your existing contract and highlight where amendments are required. This will ensure that the contract remains valid in Germany whilst also being acceptable to US customers.

This depends on whether your product reaches users in California and exceeds certain thresholds – having a US headquarters is not a prerequisite for this. We use your user base to determine whether, and to what extent, the CCPA or other state privacy laws apply.

This is usually carried out as part of a technical and legal due diligence process, during which the licence chain is traced right down to the individual component. Unresolved licensing issues can delay the completion of a funding round. We can help you prepare for this review before it begins.