The software and SaaS licence contract: what it must cover

Last updated 3 August 2026 · Reviewed by Jaime Piñeira Pardo, lawyer registered with the ICAM bar, no. 138826 · English version of our Spanish guide.

A software licence or SaaS contract is the document that establishes what the client can do with your digital product: scope of use, service level agreement (SLA), code ownership, data protection (art. 28 GDPR), liability and exit. Without it, the law limits the transfer to the minimum. Managora drafts your bespoke contract, including the SLA and data processing addendum.

We handle the whole procedure for you, from start to finish.

You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €423.00 (21% VAT included), plus the tasa (official fee) where there is one.

See the procedure

What is new, and the law that applies

  • Regulation (EU) 2023/2854 (Data Regulation): applicable from 12 September 2025. SaaS and cloud contracts must incorporate change of provider clauses (art. 25): maximum notice period, transitional migration period and data recovery timeframe.
  • Costs for changing cloud or SaaS provider: only reduced costs during the transitional period and total prohibition of charging them from 12 January 2027.
  • GDPR (Regulation (EU) 2016/679): without modifications; article 28 continues to require the written processing contract before starting the processing, and the AEPD sanctions it as an independent infringement.
  • Texto refundido de la Ley de Propiedad Intelectual (RDL 1/1996): in force as of 3 August 2026; computer programmes are protected as a work in articles 95 to 104.

What is the difference between a software licence and a SaaS contract?

A licence of use authorises the client to use a programme that is installed on their own systems. Software is protected as a work by the texto refundido de la Ley de Propiedad Intelectual (Real Decreto Legislativo 1/1996, articles 95 to 104) (the Spanish Intellectual Property Act): the provider retains ownership and only grants a right of use with the scope stated in the contract.

SaaS (software as a service) does not deliver the programme: the client accesses a service over the internet that runs on the provider's infrastructure and pays a subscription. Legally it is a continuous provision of services, so the core obligations are availability, maintenance and security, not the delivery of a copy.

The distinction is not theoretical: it determines what is guaranteed (a conforming copy versus an available service), who safeguards the data and what happens when the contract ends. Many products combine both concepts (for example, an installable module with a cloud dashboard) and the contract must regulate each component separately.

If you sell to end consumers, consumer rules on digital content and services also apply, which restrict the clauses you can impose. This guide focuses on the business to business contract, which is the usual scenario for SaaS.

What scope must the licence set: users, sites and sublicences?

The golden rule is in article 43 of the Ley de Propiedad Intelectual: the transfer is limited to the expressly provided rights and modes of exploitation. If the contract is silent, the law interprets the silence restrictively: without an agreed term the transfer lasts 5 years and without a territory it is limited to the country where it is made.

Therefore the contract must quantify the use with a clear metric: named or concurrent users, sites or workplaces, environments (production, testing), instances or data volume. It must also state whether the client's group subsidiaries can use the software or if they need their own licence.

Exclusivity is not presumed: article 48 of the same law requires that an exclusive transfer be granted expressly. With sublicensing and contract assignment the opposite of what is usually believed occurs: the law prohibits them by default. The right of the non-exclusive assignee is untransferable (article 50.1) and the transfer of an exclusive assignment requires the express consent of the assignor (article 48.2). Therefore, if the provider wants to allow their client to sublicence or resell access, it is that authorisation that must be expressly stated in writing; even so, it is advisable for the contract to state it one way or the other to avoid doubts.

It is in the provider's interest to have a usage audit clause (to verify that the client does not exceed the contracted users) and a mechanism to regularise overuse. For the client, fixed expansion and renewal prices to avoid unilateral increases.

Who owns the code? The intellectual property of bespoke developments

A computer programme is a protected work from its creation, without the need for registration (articles 95 and 96 of the Ley de Propiedad Intelectual). When it is created by a salaried employee in the exercise of their duties, the exploitation rights belong to the employer unless otherwise agreed (article 97.4).

That rule does not cover external collaborators. If your product was written by a freelance developer or a development company without signing a transfer of rights, you are not the full owner of the code you paid for: the tacit transfer is limited to what is strictly necessary for the purpose of the commission. The solution is an express written transfer that includes the transformation of the code and all necessary modes of exploitation.

In bespoke developments on an existing product the contract must separate 3 layers: the provider's pre-existing software (which remains theirs), the specific developments commissioned by the client (whose ownership or broad licence is negotiated) and the general improvements derived from the project (which the provider usually reserves for their product as a whole).

If the licence falls on a patent or a utility model, it can be registered with the Oficina Española de Patentes y Marcas (the Spanish Patent and Trademark Office) so that it produces full effects against third parties (Ley 24/2015, de Patentes) (the Spanish Patents Act). If it falls on a registered industrial design, the registration of the licence with the OEPM is governed by the Ley 20/2003, de 7 de julio, de Protección Jurídica del Diseño Industrial (articles 33 and 60) (the Spanish Legal Protection of Industrial Design Act). Managora reviews whether your case requires it.

What must the SLA cover and how are penalties agreed?

The SLA (service level agreement) turns the commercial promise into measurable obligations: monthly availability percentage and how it is calculated, excluded maintenance windows, response and resolution times according to the severity of the incident, and support channels and hours.

The usual penalties are service credits: a percentage of the fee that is deducted if the agreed level is not reached. The contract must set the total ceiling for credits, whether they are the exclusive remedy or are added to damages compensation, and from what repeated breach the client can terminate the contract.

These penalty clauses are valid under the freedom of contract (article 1255 of the Código Civil) (the Spanish Civil Code), although the courts can moderate them if the breach is only partial (article 1154). Drafting them precisely avoids that discussion: what is measured, with what tool, who reports and in what timeframe it is claimed.

What does the GDPR require of the SaaS provider: the data processing addendum?

If the service hosts or processes personal data on behalf of the client (their employees, partners, patients or consumers), the SaaS provider acts as a data processor. Article 28.3 of the GDPR requires a written contract, signed before starting to process the data; its absence is an independent infringement punishable by the AEPD (the Spanish Data Protection Agency), both for the client (controller) and for the provider (processor).

That addendum, usually called a DPA (data processing agreement), has a mandatory minimum content that is summarised in the following table. It must also regulate sub-processors (for example, the cloud provider where the service is hosted), which require prior or general authorisation with the right to object.

2 points deserve special attention: the processor must notify security breaches to the controller without undue delay (the controller then has 72 hours to notify the AEPD, article 33 GDPR), and upon termination of the contract the data must be deleted or returned, at the client's choice, with certification of deletion.

If any sub-processor is outside the European Economic Area, the contract must cover the international transfer (chapter V of the GDPR, normally through standard contractual clauses of the European Commission).

How is liability limited and how is the exit from the contract agreed?

The limitation of liability is the most negotiated clause. The norm in SaaS is a compensation ceiling (for example, the fees paid in the last 12 months) and the exclusion of loss of profit and indirect damages. 2 legal limits: liability for wilful misconduct cannot be excluded (article 1102 of the Código Civil) and against consumers these clauses are heavily restricted.

The client must demand exceptions to the ceiling (carve-outs): third party intellectual property infringement, breach of confidentiality and data protection breaches are usually left outside the limit or with a higher ceiling.

The exit is agreed on the first day: export of the data in a structured and commonly used format, recovery period after termination, migration assistance and certified deletion. From 12 September 2025 the Data Regulation (EU) 2023/2854 obliges cloud and SaaS services to include change of provider clauses with maximum timeframes (see the timeframes table) and from 12 January 2027 it prohibits charging for the change process.

For critical software it is advisable to add an escrow agreement: the source code is deposited with a third party and released to the client only in the agreed scenarios (insolvency of the provider, cessation of maintenance). Managora drafts the deposit agreement together with the main contract.

Managora prepares your bespoke licence or SaaS contract, including the SLA and the data processing addendum, ready to sign with your clients. You can see the updated amount in the procedure file and order it online at any time.

Step by step

  1. 1

    Order the contract from the file(Available 24 hours a day)

    Complete the online questionnaire: what product it is, how it is marketed (installable, cloud or mixed), who you sell to (businesses or consumers) and whether the service processes your clients' personal data.

  2. 2

    Legal analysis of your model

    Managora determines the correct concept (licence of use, SaaS or mixed contract), reviews the code ownership (employees, freelancers, previous developments) and defines the necessary addendums: SLA, processing agreement and, where appropriate, escrow.

  3. 3

    Drafting of the bespoke draft

    The body of the contract is drafted with the scope of the licence, intellectual property, limitation of liability and exit, together with the addendums: SLA with penalties and processing addendum of article 28 GDPR.

  4. 4

    Review and adjustments with you

    You review the draft and the business adjustments are incorporated: usage metrics, service levels, renewal prices, termination scenarios.

  5. 5

    Delivery of the final version(The delivery time is confirmed when opening your file)

    You receive the contract ready for signature between the parties. It is a private document: it is not submitted to any Administration nor does it accrue a tasa (official fee). If there is a licence on a patent, utility model or registered design, its registration with the OEPM is assessed.

Essential clauses of the software or SaaS contract

ClauseWhat it must resolveMain interest
Object and modalityInstallable licence, SaaS or mixed; what the fee includesBoth parties
Scope of the licenceUsers, sites, environments, subsidiaries, sublicence, exclusivityProvider
Intellectual propertyCode ownership and transfer of bespoke developmentsBoth parties
SLAAvailability, severities, service credits and their ceilingClient
Processing agreement (art. 28 GDPR)Instructions, security, sub-processors, breaches, end of contractMandatory for both
Limitation of liabilityCompensation ceiling, exclusions and carve-outsProvider
Reversibility and exitData export, recovery timeframes, migration assistanceClient
Source code escrowDeposit with a third party and release scenariosClient
Usage auditVerification of real users and regularisation of overuseProvider

Minimum content of the data processing addendum (art. 28.3 GDPR)

ElementWhat is agreed
Object, duration, nature and purposeWhat processing the SaaS carries out and until when
Type of data and categories of data subjectsWhat data is processed and whose (employees, clients, users)
Documented instructionsThe processor only processes the data according to the controller's orders
ConfidentialityCommitment to secrecy of authorised personnel
Security measures (art. 32 GDPR)Technical and organisational measures appropriate to the risk
Sub-processorsPrior or general authorisation with the right to object
Assistance to the controllerData subjects' rights, breach notification, impact assessments
End of processingDeletion or return of the data, at the controller's choice
AuditsInformation and inspections to demonstrate compliance

Exit from a SaaS or cloud: timeframes of Regulation (EU) 2023/2854

ConceptRuleValidity
General applicationMandatory change of provider clauses in cloud and SaaS contracts (art. 25)From 12-09-2025
Notice period to initiate the changeMaximum 2 monthsFrom 12-09-2025
Transitional migration periodMaximum 30 calendar days; justifiably extendable up to 7 months if technically unfeasibleFrom 12-09-2025
Data recoveryMinimum 30 calendar days after the transitional periodFrom 12-09-2025
Costs for the changeOnly reduced costs, directly linked to the change processUntil 11-01-2027
Costs for the changeProhibited to charge themFrom 12-01-2027

Licence of use versus SaaS: which corresponds to your product

Licence of use (installable)SaaS (service subscription)
What the client receivesRight to use a programme that they install on their systemsRemote access to a service in the cloud
Where it runsOn the client's infrastructureOn the provider's infrastructure
Usual paymentSingle fee or per version, with separate maintenancePeriodic subscription per user or consumption
UpdatesAccording to the maintenance contractIncluded in the service
Personal dataNormally do not leave the client's systemsThe provider is the data processor: mandatory DPA
Critical clauseScope of the licence and code ownershipSLA, reversibility and exit
Reference normLPI, arts. 95 to 104Art. 28 GDPR and Data Regulation (EU) 2023/2854

Frequently asked questions

Can I use a free internet template for my SaaS contract?

It is risky. Article 43 of the Ley de Propiedad Intelectual limits the transfer to what is expressly agreed: a template that does not describe your product leaves out uses that you wanted to allow or charge for. And a generic data protection addendum that does not reflect the real processing breaches article 28 GDPR even if it is signed. Managora drafts the contract based on your specific business model.

My freelance programmer never signed a transfer of rights, who owns the code?

The automatic ownership of article 97.4 of the LPI only covers salaried employees. With an external collaborator without a written agreement, the transfer is limited to what is strictly necessary for the purpose of the commission, 5 years and the country of the transfer. It is advisable to regularise it with an express written transfer; Managora prepares it together with the main contract.

Can my client sublicence or resell access if the contract says nothing?

No. The Ley de Propiedad Intelectual is restrictive by default: the right of the non-exclusive assignee is untransferable (article 50.1) and the transfer of an exclusive assignment requires the express consent of the assignor (article 48.2). If you want to allow sublicensing or resale, that authorisation must be expressly agreed in writing.

Is the data protection addendum (DPA) mandatory in a SaaS?

Yes, whenever the service processes personal data on behalf of the client. Article 28.3 of the GDPR requires a written contract before starting the processing, with a set minimum content. Its absence is punishable by the AEPD for both the controller and the processor.

What happens if the provider breaches the SLA?

The agreed penalties apply, normally service credits that are deducted from the fee, and if the breach is serious or repeated, the contract can provide for early termination. Without a written SLA there is only the general breach regime of the Código Civil, which is much slower and more uncertain to prove.

What happens to my data if I leave the SaaS or the provider closes?

The contract must guarantee the export of your data in a structured format and a recovery period. From 12 September 2025 the Data Regulation imposes maximum migration timeframes and, from 12 January 2027, prohibits charging for the change of provider. For the risk of closure or abandonment of the software, the additional protection is the source code escrow agreement.

How much does it cost and how long does it take?

There is no tasa (official fee): it is a private document between the parties that is not submitted to any Administration. You can see the updated amount of Managora's fees in the procedure file; the delivery time is confirmed when opening your file.

We handle the whole procedure for you, from start to finish.

You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €423.00 (21% VAT included), plus the tasa (official fee) where there is one.

See the procedure

Related procedures

The price, the tasa (official fee) and the current deadlines are on each procedure page.

Related guides