The software and SaaS licence contract: what it must cover
Last updated 3 August 2026 · Reviewed by Jaime Piñeira Pardo, lawyer registered with the ICAM bar, no. 138826 · English version of our Spanish guide.
A software licence or SaaS contract is the document that establishes what the client can do with your digital product: scope of use, service level agreement (SLA), code ownership, data protection (art. 28 GDPR), liability and exit. Without it, the law limits the transfer to the minimum. Managora drafts your bespoke contract, including the SLA and data processing addendum.
We handle the whole procedure for you, from start to finish.
You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €423.00 (21% VAT included), plus the tasa (official fee) where there is one.
What is new, and the law that applies
- Regulation (EU) 2023/2854 (Data Regulation): applicable from 12 September 2025. SaaS and cloud contracts must incorporate change of provider clauses (art. 25): maximum notice period, transitional migration period and data recovery timeframe.
- Costs for changing cloud or SaaS provider: only reduced costs during the transitional period and total prohibition of charging them from 12 January 2027.
- GDPR (Regulation (EU) 2016/679): without modifications; article 28 continues to require the written processing contract before starting the processing, and the AEPD sanctions it as an independent infringement.
- Texto refundido de la Ley de Propiedad Intelectual (RDL 1/1996): in force as of 3 August 2026; computer programmes are protected as a work in articles 95 to 104.
What is the difference between a software licence and a SaaS contract?
A licence of use authorises the client to use a programme that is installed on their own systems. Software is protected as a work by the texto refundido de la Ley de Propiedad Intelectual (Real Decreto Legislativo 1/1996, articles 95 to 104) (the Spanish Intellectual Property Act): the provider retains ownership and only grants a right of use with the scope stated in the contract.
SaaS (software as a service) does not deliver the programme: the client accesses a service over the internet that runs on the provider's infrastructure and pays a subscription. Legally it is a continuous provision of services, so the core obligations are availability, maintenance and security, not the delivery of a copy.
The distinction is not theoretical: it determines what is guaranteed (a conforming copy versus an available service), who safeguards the data and what happens when the contract ends. Many products combine both concepts (for example, an installable module with a cloud dashboard) and the contract must regulate each component separately.
If you sell to end consumers, consumer rules on digital content and services also apply, which restrict the clauses you can impose. This guide focuses on the business to business contract, which is the usual scenario for SaaS.
What scope must the licence set: users, sites and sublicences?
The golden rule is in article 43 of the Ley de Propiedad Intelectual: the transfer is limited to the expressly provided rights and modes of exploitation. If the contract is silent, the law interprets the silence restrictively: without an agreed term the transfer lasts 5 years and without a territory it is limited to the country where it is made.
Therefore the contract must quantify the use with a clear metric: named or concurrent users, sites or workplaces, environments (production, testing), instances or data volume. It must also state whether the client's group subsidiaries can use the software or if they need their own licence.
Exclusivity is not presumed: article 48 of the same law requires that an exclusive transfer be granted expressly. With sublicensing and contract assignment the opposite of what is usually believed occurs: the law prohibits them by default. The right of the non-exclusive assignee is untransferable (article 50.1) and the transfer of an exclusive assignment requires the express consent of the assignor (article 48.2). Therefore, if the provider wants to allow their client to sublicence or resell access, it is that authorisation that must be expressly stated in writing; even so, it is advisable for the contract to state it one way or the other to avoid doubts.
It is in the provider's interest to have a usage audit clause (to verify that the client does not exceed the contracted users) and a mechanism to regularise overuse. For the client, fixed expansion and renewal prices to avoid unilateral increases.
Who owns the code? The intellectual property of bespoke developments
A computer programme is a protected work from its creation, without the need for registration (articles 95 and 96 of the Ley de Propiedad Intelectual). When it is created by a salaried employee in the exercise of their duties, the exploitation rights belong to the employer unless otherwise agreed (article 97.4).
That rule does not cover external collaborators. If your product was written by a freelance developer or a development company without signing a transfer of rights, you are not the full owner of the code you paid for: the tacit transfer is limited to what is strictly necessary for the purpose of the commission. The solution is an express written transfer that includes the transformation of the code and all necessary modes of exploitation.
In bespoke developments on an existing product the contract must separate 3 layers: the provider's pre-existing software (which remains theirs), the specific developments commissioned by the client (whose ownership or broad licence is negotiated) and the general improvements derived from the project (which the provider usually reserves for their product as a whole).
If the licence falls on a patent or a utility model, it can be registered with the Oficina Española de Patentes y Marcas (the Spanish Patent and Trademark Office) so that it produces full effects against third parties (Ley 24/2015, de Patentes) (the Spanish Patents Act). If it falls on a registered industrial design, the registration of the licence with the OEPM is governed by the Ley 20/2003, de 7 de julio, de Protección Jurídica del Diseño Industrial (articles 33 and 60) (the Spanish Legal Protection of Industrial Design Act). Managora reviews whether your case requires it.
What must the SLA cover and how are penalties agreed?
The SLA (service level agreement) turns the commercial promise into measurable obligations: monthly availability percentage and how it is calculated, excluded maintenance windows, response and resolution times according to the severity of the incident, and support channels and hours.
The usual penalties are service credits: a percentage of the fee that is deducted if the agreed level is not reached. The contract must set the total ceiling for credits, whether they are the exclusive remedy or are added to damages compensation, and from what repeated breach the client can terminate the contract.
These penalty clauses are valid under the freedom of contract (article 1255 of the Código Civil) (the Spanish Civil Code), although the courts can moderate them if the breach is only partial (article 1154). Drafting them precisely avoids that discussion: what is measured, with what tool, who reports and in what timeframe it is claimed.
What does the GDPR require of the SaaS provider: the data processing addendum?
If the service hosts or processes personal data on behalf of the client (their employees, partners, patients or consumers), the SaaS provider acts as a data processor. Article 28.3 of the GDPR requires a written contract, signed before starting to process the data; its absence is an independent infringement punishable by the AEPD (the Spanish Data Protection Agency), both for the client (controller) and for the provider (processor).
That addendum, usually called a DPA (data processing agreement), has a mandatory minimum content that is summarised in the following table. It must also regulate sub-processors (for example, the cloud provider where the service is hosted), which require prior or general authorisation with the right to object.
2 points deserve special attention: the processor must notify security breaches to the controller without undue delay (the controller then has 72 hours to notify the AEPD, article 33 GDPR), and upon termination of the contract the data must be deleted or returned, at the client's choice, with certification of deletion.
If any sub-processor is outside the European Economic Area, the contract must cover the international transfer (chapter V of the GDPR, normally through standard contractual clauses of the European Commission).
How is liability limited and how is the exit from the contract agreed?
The limitation of liability is the most negotiated clause. The norm in SaaS is a compensation ceiling (for example, the fees paid in the last 12 months) and the exclusion of loss of profit and indirect damages. 2 legal limits: liability for wilful misconduct cannot be excluded (article 1102 of the Código Civil) and against consumers these clauses are heavily restricted.
The client must demand exceptions to the ceiling (carve-outs): third party intellectual property infringement, breach of confidentiality and data protection breaches are usually left outside the limit or with a higher ceiling.
The exit is agreed on the first day: export of the data in a structured and commonly used format, recovery period after termination, migration assistance and certified deletion. From 12 September 2025 the Data Regulation (EU) 2023/2854 obliges cloud and SaaS services to include change of provider clauses with maximum timeframes (see the timeframes table) and from 12 January 2027 it prohibits charging for the change process.
For critical software it is advisable to add an escrow agreement: the source code is deposited with a third party and released to the client only in the agreed scenarios (insolvency of the provider, cessation of maintenance). Managora drafts the deposit agreement together with the main contract.
Managora prepares your bespoke licence or SaaS contract, including the SLA and the data processing addendum, ready to sign with your clients. You can see the updated amount in the procedure file and order it online at any time.
Step by step
- 1
Order the contract from the file(Available 24 hours a day)
Complete the online questionnaire: what product it is, how it is marketed (installable, cloud or mixed), who you sell to (businesses or consumers) and whether the service processes your clients' personal data.
- 2
Legal analysis of your model
Managora determines the correct concept (licence of use, SaaS or mixed contract), reviews the code ownership (employees, freelancers, previous developments) and defines the necessary addendums: SLA, processing agreement and, where appropriate, escrow.
- 3
Drafting of the bespoke draft
The body of the contract is drafted with the scope of the licence, intellectual property, limitation of liability and exit, together with the addendums: SLA with penalties and processing addendum of article 28 GDPR.
- 4
Review and adjustments with you
You review the draft and the business adjustments are incorporated: usage metrics, service levels, renewal prices, termination scenarios.
- 5
Delivery of the final version(The delivery time is confirmed when opening your file)
You receive the contract ready for signature between the parties. It is a private document: it is not submitted to any Administration nor does it accrue a tasa (official fee). If there is a licence on a patent, utility model or registered design, its registration with the OEPM is assessed.
Essential clauses of the software or SaaS contract
| Clause | What it must resolve | Main interest |
|---|---|---|
| Object and modality | Installable licence, SaaS or mixed; what the fee includes | Both parties |
| Scope of the licence | Users, sites, environments, subsidiaries, sublicence, exclusivity | Provider |
| Intellectual property | Code ownership and transfer of bespoke developments | Both parties |
| SLA | Availability, severities, service credits and their ceiling | Client |
| Processing agreement (art. 28 GDPR) | Instructions, security, sub-processors, breaches, end of contract | Mandatory for both |
| Limitation of liability | Compensation ceiling, exclusions and carve-outs | Provider |
| Reversibility and exit | Data export, recovery timeframes, migration assistance | Client |
| Source code escrow | Deposit with a third party and release scenarios | Client |
| Usage audit | Verification of real users and regularisation of overuse | Provider |
Minimum content of the data processing addendum (art. 28.3 GDPR)
| Element | What is agreed |
|---|---|
| Object, duration, nature and purpose | What processing the SaaS carries out and until when |
| Type of data and categories of data subjects | What data is processed and whose (employees, clients, users) |
| Documented instructions | The processor only processes the data according to the controller's orders |
| Confidentiality | Commitment to secrecy of authorised personnel |
| Security measures (art. 32 GDPR) | Technical and organisational measures appropriate to the risk |
| Sub-processors | Prior or general authorisation with the right to object |
| Assistance to the controller | Data subjects' rights, breach notification, impact assessments |
| End of processing | Deletion or return of the data, at the controller's choice |
| Audits | Information and inspections to demonstrate compliance |
Exit from a SaaS or cloud: timeframes of Regulation (EU) 2023/2854
| Concept | Rule | Validity |
|---|---|---|
| General application | Mandatory change of provider clauses in cloud and SaaS contracts (art. 25) | From 12-09-2025 |
| Notice period to initiate the change | Maximum 2 months | From 12-09-2025 |
| Transitional migration period | Maximum 30 calendar days; justifiably extendable up to 7 months if technically unfeasible | From 12-09-2025 |
| Data recovery | Minimum 30 calendar days after the transitional period | From 12-09-2025 |
| Costs for the change | Only reduced costs, directly linked to the change process | Until 11-01-2027 |
| Costs for the change | Prohibited to charge them | From 12-01-2027 |
Licence of use versus SaaS: which corresponds to your product
| Licence of use (installable) | SaaS (service subscription) | |
|---|---|---|
| What the client receives | Right to use a programme that they install on their systems | Remote access to a service in the cloud |
| Where it runs | On the client's infrastructure | On the provider's infrastructure |
| Usual payment | Single fee or per version, with separate maintenance | Periodic subscription per user or consumption |
| Updates | According to the maintenance contract | Included in the service |
| Personal data | Normally do not leave the client's systems | The provider is the data processor: mandatory DPA |
| Critical clause | Scope of the licence and code ownership | SLA, reversibility and exit |
| Reference norm | LPI, arts. 95 to 104 | Art. 28 GDPR and Data Regulation (EU) 2023/2854 |
Frequently asked questions
Can I use a free internet template for my SaaS contract?
It is risky. Article 43 of the Ley de Propiedad Intelectual limits the transfer to what is expressly agreed: a template that does not describe your product leaves out uses that you wanted to allow or charge for. And a generic data protection addendum that does not reflect the real processing breaches article 28 GDPR even if it is signed. Managora drafts the contract based on your specific business model.
My freelance programmer never signed a transfer of rights, who owns the code?
The automatic ownership of article 97.4 of the LPI only covers salaried employees. With an external collaborator without a written agreement, the transfer is limited to what is strictly necessary for the purpose of the commission, 5 years and the country of the transfer. It is advisable to regularise it with an express written transfer; Managora prepares it together with the main contract.
Can my client sublicence or resell access if the contract says nothing?
No. The Ley de Propiedad Intelectual is restrictive by default: the right of the non-exclusive assignee is untransferable (article 50.1) and the transfer of an exclusive assignment requires the express consent of the assignor (article 48.2). If you want to allow sublicensing or resale, that authorisation must be expressly agreed in writing.
Is the data protection addendum (DPA) mandatory in a SaaS?
Yes, whenever the service processes personal data on behalf of the client. Article 28.3 of the GDPR requires a written contract before starting the processing, with a set minimum content. Its absence is punishable by the AEPD for both the controller and the processor.
What happens if the provider breaches the SLA?
The agreed penalties apply, normally service credits that are deducted from the fee, and if the breach is serious or repeated, the contract can provide for early termination. Without a written SLA there is only the general breach regime of the Código Civil, which is much slower and more uncertain to prove.
What happens to my data if I leave the SaaS or the provider closes?
The contract must guarantee the export of your data in a structured format and a recovery period. From 12 September 2025 the Data Regulation imposes maximum migration timeframes and, from 12 January 2027, prohibits charging for the change of provider. For the risk of closure or abandonment of the software, the additional protection is the source code escrow agreement.
How much does it cost and how long does it take?
There is no tasa (official fee): it is a private document between the parties that is not submitted to any Administration. You can see the updated amount of Managora's fees in the procedure file; the delivery time is confirmed when opening your file.
We handle the whole procedure for you, from start to finish.
You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €423.00 (21% VAT included), plus the tasa (official fee) where there is one.
Related procedures
The price, the tasa (official fee) and the current deadlines are on each procedure page.
Related guides
- VAT for the self-employed in Spain: modelo 303 and modelo 390
- Registering as autónomo in Spain: Hacienda and Seguridad Social
- IRPF for the self-employed in Spain: payments on account and withholdings
- The Spanish tax return (IRPF, modelo 100)
- Spanish Corporation Tax: modelo 200 and instalment payments
- How to Set Up a Sociedad Limitada (SL) in Spain: Steps, Capital and Accounts
- Registering a Trademark (OEPM and EUIPO): Steps and Renewal
- Hiring an employee: Seguridad Social registration and contract
- Managing a Spanish SL: directors, bylaws, capital and company books
- Deferring debts with Hacienda and Social Security
- Opening a premises: opening, activity and building licences
- Hacienda informative returns: forms 347, 349, 720 and 721
- Kit Digital: the grant to digitise freelancers and SMEs
- Deregistering as an autónomo and cessation of activity (self-employed unemployment)
- Change your tax address and census details (Form 030)
- Dissolve and liquidate a limited company: steps, deadlines and costs
- Digital certificate and electronic signature for companies and autónomos in Spain
- Register a patent, a design or a work: protect your creation
- Opening or taking over a bar in Spain: licences, APPCC and allergens
- Importing and exporting: EORI, DUA and customs
- Appealing to Hacienda: TEAR/TEAC, rectification and binding rulings
- Company powers of attorney: notarial and electronic (Apodera/REA)
- E-commerce VAT: the One Stop Shop OSS/IOSS (modelo 369)
- Spanish wealth tax and the tax on large fortunes (modelo 714)
- Public subsidies for companies and freelancers: how to apply
- Commercial contracts: sale, agency, distribution and senior management
- Capital yield and non-resident withholdings: forms 123, 193 and 216
- Changes to your company: registered office, corporate purpose and capital reduction
- Maternity deduction and dependent child benefits (form 140)
- Advanced corporate tax obligations: related-party transactions (232) and income attribution (184)
- Ordered to close your premises: how to appeal the closure order and stay open
- You own 5% of a company and they hide the accounts: how to force an audit at the company's expense
- Modelo 211: the 3% withholding when you buy a property from a non-resident
- Leaving the recargo de equivalencia as an ecommerce or Amazon seller
- AEAT financial information returns: forms 165, 345, 198, 117 and 038
- Recover VAT: refund of VAT paid in another EU country (360-361) and special cases (308)
- Environmental taxes: non-reusable plastic (592), waste (593) and fluorinated gases (587)
- Group taxation: tax consolidation (220 and 222) and VAT group (039, 322 and 353)
- Financial sector taxes: the tasa Tobin (Tobin tax, 604) and the insurance premium tax (480)
- Form 037: the simplified census registration versus form 036
- Energy taxes: hydrocarbons (581), electricity (560) and IVPEE (583)
- Cryptocurrencies and Hacienda: the tax report and how to reply to a request
- Platform economy: DAC7 (forms 040 and 238) and the digital services tax (490)
- The exit tax: the tax on leaving when moving your residence outside Spain
- Company IAE: form 848, municipal self-assessment and deferral of local taxes
- The 7p exemption: work carried out abroad free of income tax up to €60,100
- Tax representative in Spain and the special tax of form 213
- Tax residence in Spain and double taxation conflicts
- The RIC: Canary Islands investment reserve and form 282
- Content creators (OnlyFans, YouTube, Twitch): registration and taxes
- Ex officio review and extraordinary appeal: appealing when the deadline has passed
- International trademark: the Madrid System (WIPO) and the European Union trademark (EUIPO)
- Defending your trademark: opposition, suspension, nullity, revocation and monitoring (OEPM)
- The comunidad de bienes: setting it up, taxes and when to choose an SL
- Corporate director or shareholder: classification, RETA registration and contributions
- The shareholders' agreement and the participatory loan: shielding and financing the company
- Buying or selling a company: the share purchase agreement (SPA)
- The partner's right of separation: dividends (art. 348 bis) and other causes
- Mergers and spin-offs: structural modifications and the FEAC tax regime
- Opening a branch of a foreign company in Spain: registration and obligations
- Negative assessment and closed sheet: unblocking your company at the Commercial Registry
- The family business: family protocol and generational handover with ISD reduction
- Voluntary insolvency proceedings: when your company cannot pay
- Business financing contracts: factoring, leasing, renting and credit assignment
- The franchise contract: setting up a business under another brand
- The food health register (RGSEAA): step-by-step registration
- Opening a clinic or aesthetic centre: the health operating authorisation
- Selling cosmetics in the EU: CPNP notification and the responsible person
- The zoological centre register: breeders, boarding kennels and pet shops
- Operating drones professionally: registering as an operator with AESA
- Denied premises licence or unlicensed activity: how to legalise it
- Reporting to the CNMC: unfair market competition and administrative barriers
- Company statistical and registry obligations: INE, Intrastat and Registro Industrial
- Selling on Amazon Europe: Extended Producer Responsibility (EPR) and LUCID
- Publish a book or magazine: ISBN, ISSN and legal deposit
- The security guard TIP: requirements, exam and issuance
- Reporting workplace bullying or sexual harassment to the Labour Inspectorate
- Civil servants: requesting compatibility for another activity and voluntary transfer