Vordex logo
UK SaaS contract analysisMulti-document reviewBefore approval or renewal
HomeSaaS Contract Review UK

Turn a SaaS contract pack into a decision-ready risk report

Vordex analyses the documents behind a software subscription and connects commercial terms, DPA wording, security promises, SLA remedies, liability limits, renewal mechanics and exit rights.

The product is built around clause evidence and cross-document relationships. It shows what triggered a warning, why the wording matters and which issue should be accepted, negotiated or escalated.

Clause evidenceThe wording behind each finding stays visible.
Contract-stack mappingRelated clauses are read as one commercial position.
Decision supportEach issue ends with a focused review prompt.

Vordex provides contract analysis and general information, not legal advice. Actual findings depend on the documents and wording supplied.

01Upload the SaaS documents you want reviewed.
02Vordex maps clause relationships and warning triggers.
03Review the evidence, commercial effect and next step.
SaaS Contract Pack Upload

Build the document set Vordex should analyse

A SaaS deal is often split across signed terms, schedules and referenced policies. The workflow starts by giving the analysis enough context to connect those documents without pretending that missing or live web terms have already been reviewed.

Add the available deal documents

Supply the documents that form the approval, renewal or exit decision. Missing schedules can then be identified as missing evidence rather than silently assumed.

Commercial paperOrder form, quote, renewal notice or amendment.
Core termsMaster SaaS agreement and acceptable-use wording.
Service documentsSLA, support schedule and service descriptions.
Data documentsDPA, sub-processor terms and security schedule.

The analysis follows the contract hierarchy

Vordex is designed to connect the commercial front page with the documents that qualify, override or narrow it.

1
Identify the deal structureFind the term, price, order scope and incorporated documents.
2
Connect related clausesRead SLA, DPA, security, liability and exit wording together.
3
Expose missing evidenceFlag an absent schedule, version or linked term instead of filling the gap.
4
Produce the review outputShow evidence, warning trigger, commercial effect and decision prompt.

Preserve the version actually reviewed

Where supplier paper points to a web policy, include the relevant version in the pack. Vordex should not be treated as automatically retrieving every external page.

Version controlKeep the date or version attached to the accepted wording.
Negotiated priorityInclude amendments that override standard supplier terms.
Missing-document signalLet the report state what could not be verified from the pack.
Human approvalUse the output to assign ownership, negotiate or escalate.
Contract Stack Mapper

See what each document contributes to the risk picture

Every input is mapped to a specific analysis function. The page explains the wording Vordex examines, the condition that can trigger a warning and the output produced for the reviewer.

Order form

Protective field
Vordex analyses
Term, committed quantity, pricing basis, renewal route, notice details, incorporated documents and contract hierarchy.
Warning trigger
The commercial front page depends on unidentified, undated or changeable online terms.
Report output
A deal-structure finding showing which commercial promise depends on another document.

Master SaaS terms

Core analysis
Vordex analyses
Licence scope, users, affiliates, acceptable use, suspension, product changes, warranties, IP and governing terms.
Warning trigger
The real operating model is wider than the licence or the supplier can materially change access without a clear remedy.
Report output
A permitted-use map with the limiting clause and a focused approval or negotiation prompt.

SLA and support schedule

Review closely
Vordex analyses
Uptime measurement, exclusions, maintenance, response targets, resolution language, credits and repeated-failure rights.
Warning trigger
The headline service promise is weakened by broad exclusions or a service-credit-only remedy.
Report output
An SLA finding that separates the promise, measurement rule, remedy and continuity consequence.

DPA and data schedules

Core analysis
Vordex analyses
Processing roles, instructions, confidentiality, security, sub-processors, transfers, assistance, return and deletion.
Warning trigger
A processor obligation is missing, vague, inconsistent with the main terms or dependent on an unprovided schedule.
Report output
A data-processing issue with clause evidence, affected review field and escalation prompt.

Security schedule

Protective field
Vordex analyses
Access controls, authentication, encryption, logging, backups, incident notification, resilience and evidence rights.
Warning trigger
Security language is generic, key controls are conditional, or incident support is not operationally clear.
Report output
A security finding showing the promise, missing detail and the procurement question that remains open.

Linked policies and amendments

Often hidden
Vordex analyses
Policy references, version dates, precedence, unilateral update rights, sub-processor lists and negotiated overrides.
Warning trigger
The signed pack does not identify the accepted version or an amendment conflicts with a live policy.
Report output
A version-control or hierarchy warning tied to the affected commercial or data position.
Commercial Terms Analysis

Translate supplier paper into the operating deal

Vordex focuses on whether the licence, commercial commitments, supplier controls and rights wording match how the customer intends to buy, deploy and depend on the platform.

Who can use the platform

Licence boundary map

Core analysis
Analysed
  • Named customer entity, group companies, contractors and authorised users.
  • Seat, API, storage, geography, environment and product-tier restrictions.
  • Internal-use wording against customer-facing or managed-service use.
Warning triggers
  • Affiliate or contractor use is not covered.
  • Operational use exceeds the stated licence purpose.
  • Suspension can be triggered by broad or subjective usage restrictions.
Report outputs
  • Permitted-use summary.
  • Limiting clause evidence.
  • Targeted approval or amendment prompt.
What the customer is buying

Commercial commitment map

Protective field
Analysed
  • Initial term, committed spend, seats, usage tiers, overages and true-ups.
  • Invoice timing, non-refundable fees, downgrade restrictions and price mechanics.
  • Order-form terms against the master agreement and renewal wording.
Warning triggers
  • Usage growth becomes the next minimum commitment.
  • Negotiated pricing resets to an undefined list rate.
  • A downgrade or cancellation right is narrower than the sales position suggests.
Report outputs
  • Commercial obligation summary.
  • Pricing or commitment warning.
  • Clause-linked internal review point.
What the supplier can alter

Change and suspension controls

Review closely
Analysed
  • Product-change rights, online-policy updates and feature withdrawal wording.
  • Suspension grounds, cure periods, proportionality and access during a dispute.
  • Notice obligations and remedies for materially adverse changes.
Warning triggers
  • Continued use is treated as acceptance of material new terms.
  • Core functionality can be reduced without an exit route.
  • Suspension can block data access before the issue is resolved.
Report outputs
  • Supplier-control finding.
  • Affected service or data dependency.
  • Focused change-control or suspension prompt.
Who owns and may reuse what

IP, customer data and usage rights

Often hidden
Analysed
  • Platform IP, customer materials, configurations, outputs, feedback and telemetry.
  • Aggregated data, analytics and product-improvement wording.
  • AI or beta feature terms where they are included in the supplied pack.
Warning triggers
  • A broad licence reaches confidential content or identifiable data.
  • Customer-created configuration or output rights are unclear.
  • New feature terms introduce a use that is not aligned with the DPA.
Report outputs
  • Rights-allocation summary.
  • Data-use or IP warning.
  • Narrowed review question for the relevant team.
DPA and Security Analysis

Connect official review fields to the actual contract wording

Legal and regulatory references support defined product checks. They are kept subordinate to the analysis: what Vordex reads, what causes a warning and what the report tells the user to review next.

Processor contract fields

Core analysis
Product fieldVordex examines the supplied wording for processing instructions, confidentiality, security, sub-processors, assistance, return or deletion and audit information.
Warning triggerA required review field is missing, incomplete or located in a schedule that has not been supplied.
Report outputA processor-term finding naming the field, evidence and follow-up question. This is issue spotting, not a compliance certificate.

Sub-processors and international access

Review closely
Product fieldVordex checks the supplied sub-processor, hosting, remote-access and transfer wording alongside the DPA and security terms.
Warning triggerUK hosting is stated but overseas support, backups or sub-processor access is not clearly addressed in the contract pack.
Report outputA location or transfer-dependency warning showing the documents that need reconciliation.

Security and incident commitments

Protective field
Product fieldVordex analyses contractual promises on authentication, privileged access, logging, backups, incident notice and security evidence.
Warning triggerThe contract uses general security language without enough operational detail for the intended dependency.
Report outputA security-evidence finding with the unresolved procurement question and relevant clause context.

Return, deletion and end-of-service handling

High attention
Product fieldVordex checks whether the supplied terms address return or deletion, backup retention, sub-processor handling and any post-termination access window.
Warning triggerDeletion is promised without a timeframe, backup treatment or a usable route to retrieve the customer data needed for migration.
Report outputAn exit-data finding tying the data term to termination, suspension and migration wording elsewhere in the pack.
SLA and Service Continuity

Follow the path from uptime promise to real customer leverage

The product does not stop at a headline percentage. It traces how availability is measured, which outages disappear through exclusions, what remedy remains and whether repeated failure creates a usable continuity or exit route.

01

Service promise

AnalysedThe stated uptime, support coverage, response targets and any service-specific commitments.
TriggerThe promise is marketing-level or uses undefined terms that cannot be measured from the contract.
OutputA service-promise summary with the evidence Vordex found.
02

Measurement model

AnalysedMeasurement period, calculation method, scheduled maintenance, exclusions and customer reporting route.
TriggerExcluded downtime can remove the outages most likely to affect the customer.
OutputAn SLA measurement warning identifying which exclusion changes the headline result.
03

Remedy path

AnalysedCredit bands, claim deadlines, sole-remedy language and conditions for obtaining relief.
TriggerA small future credit is the only contractual response to serious or repeated failure.
OutputA remedy finding showing the practical value and any restriction on other rights.
04

Repeated failure

AnalysedChronic failure thresholds, termination rights, escalation, root-cause reporting and corrective action.
TriggerRepeated misses do not create additional leverage or the threshold is difficult to reach.
OutputA continuity warning with the missing or weak escalation route.
05

Operational continuity

AnalysedData access during suspension, read-only access, export support, transition assistance and shutdown wording.
TriggerThe customer can lose access before it can preserve data or move an important workflow.
OutputA continuity and exit finding connected to suspension, termination and data-return clauses.
Liability and Indemnity Engine

Map the cap, exclusions and risk allocation as one system

A liability cap is not meaningful in isolation. Vordex examines the monetary formula, aggregation, excluded losses, carve-outs, indemnities and claims process together so the reviewer can see where the exposure actually sits.

Illustrative liability relationship map

The bars are a visual explanation of how the review connects different parts of the clause set. They are not a numerical risk score or legal conclusion.

General supplier capFee based
Read against the subscription value and business dependency.
Excluded loss categoriesWide
Check whether the exclusions remove the losses that matter most.
Customer indemnity scopeBroad
Compare customer exposure with supplier IP and security protection.
Field
Vordex analyses
Warning trigger
Report output
Cap basis
Fees paid, fees payable, current order fees, annual fees or another monetary reference.
The reference amount is low, uncertain or unrelated to the customer dependency.
Cap formula and affected contract value shown together.
Cap period and aggregation
Per claim, per event, annual, rolling period or one aggregate pot for the full term.
Several incidents share one cap or earlier claims consume protection for later losses.
Aggregation warning with the wording driving the result.
Excluded losses
Data loss, revenue, profits, savings, goodwill, business interruption and indirect-loss wording.
The exclusions remove losses most likely to arise from the customer use case.
Loss-category finding linked to the stated service dependency.
Carve-outs and separate caps
IP, confidentiality, data protection, security, payment and other exceptions to the general cap.
Supplier exposure stays narrow while customer obligations sit above or outside the cap.
Asymmetry finding comparing both parties' positions.
Indemnity allocation
Supplier IP cover, customer data or use indemnities, exclusions and fault requirements.
The customer indemnity is broad, uncapped or reaches loss caused by supplier-controlled conduct.
Indemnity scope, cap treatment and negotiation focus.
Claim handling
Notice, defence control, settlement consent, cooperation and replacement or workaround remedies.
One party can settle on terms that affect the other without adequate consent or control.
Claims-process warning with the practical decision point.
Renewal and Exit Risk

Expose the deadlines and dependencies that control whether the customer can leave

The renewal and exit review links notice, price, suspension, export and deletion wording. This prevents a favourable termination clause from being read separately from a short export window or immediate access restriction.

Notice window

Review closely
Vordex analysesDeadline, notice method, recipient, deemed receipt and whether the window sits before internal review normally begins.
Warning triggerA long advance-notice period can pass before finance, security or operations revisit the contract.
Report outputThe report states the notice mechanics and flags the timing risk for internal action.

Renewed term

Often hidden
Vordex analysesMonth-to-month, annual or multi-year renewal and whether the term changes after the first period.
Warning triggerA missed deadline commits the customer to another lengthy term with limited downgrade rights.
Report outputRenewal consequence linked to the exact term wording.

Renewal price

High attention
Vordex analysesFixed uplift, indexation, then-current list price, usage true-up and approval requirements.
Warning triggerNegotiated pricing disappears or usage growth becomes the next minimum commitment.
Report outputPricing-reset warning with the formula or undefined reference identified.

Suspension before exit

High attention
Vordex analysesNon-payment, suspected misuse, security grounds, cure periods, proportionality and data access during suspension.
Warning triggerThe supplier can block access before the customer resolves a dispute or retrieves its data.
Report outputSuspension risk connected to the data-return and continuity position.

Export and transition

Protective field
Vordex analysesExport scope, format, timing, read-only access, API support and paid transition assistance.
Warning triggerA standard export omits configuration, logs, metadata, attachments or workflow history needed for migration.
Report outputExit-readiness finding listing the unresolved export fields.

Deletion and backups

Core analysis
Vordex analysesDeletion timing, backup cycles, access restrictions, sub-processor deletion and confirmation language.
Warning triggerBackup retention is indefinite or deletion is stated without a workable timetable or evidence route.
Report outputPost-termination data finding mapped back to the DPA and security schedule.
Analysis Output Preview

Move from dense clauses to an evidence-led review queue

The preview below demonstrates the product logic. Each finding keeps the clause context visible, explains the trigger and converts the issue into a focused decision output. Actual results depend on the uploaded contract pack.

Illustrative output preview
SaaS Contract Analysis Report
Example findings are synthetic and show report structure only. They do not describe a specific supplier or guarantee that the same findings will appear in another contract.
Evidence firstEach issue points back to the wording that caused it.
Cross-document contextRelated clauses are connected before the risk is described.
Actionable reviewOutputs support acceptance, negotiation or escalation.
R-01 | Liability

Liability cap may not match platform dependency

High attention
Clause evidenceSupplier liability is limited to fees paid in the previous 12 months, while data loss and lost savings are excluded.
Why it triggeredA fee-based aggregate cap combines with exclusions that remove losses relevant to a business-critical workflow.
Decision outputCap basis, excluded losses, affected dependency and a focused higher-cap or carve-out review prompt.
R-02 | Renewal

Renewal window can close before internal approval

Review closely
Clause evidenceThe order renews for another 12 months unless notice is received at least 90 days before expiry.
Why it triggeredThe notice period is long and the contract requires receipt through a specified legal-notice route.
Decision outputNotice deadline mechanics, renewed term consequence and the internal action that needs ownership.
R-03 | Data processing

DPA position depends on an unprovided schedule

Core analysis
Clause evidenceThe master terms refer to supplier data-processing terms and a sub-processor list available online.
Why it triggeredThe accepted version, processing description and sub-processor terms are not present in the supplied pack.
Decision outputMissing-document warning and the exact data-processing fields that cannot yet be reconciled.
R-04 | Service continuity

SLA remedy is confined to a future credit

Often hidden
Clause evidenceService credits are stated to be the sole and exclusive remedy for availability failure.
Why it triggeredThe contract offers no separate route for repeated failure, serious disruption or a commercially unusable service.
Decision outputRemedy limitation, chronic-failure gap and a targeted termination or escalation review prompt.
SaaS Review Scenarios

Use the same analysis engine at different points in the supplier lifecycle

The input documents and decision change by scenario, but the product discipline stays the same: identify the clause evidence, explain the trigger and produce a review output tied to the commercial decision.

New supplier approval

InputOrder form, SaaS terms, DPA, SLA and security schedule before signature.
DecisionCan the business approve the supplier paper as written, or which issues need ownership?
OutputClause-linked commercial, data, service and liability findings for the approval record.

Renewal decision

InputCurrent contract pack, renewal wording and any updated policies provided by the supplier.
DecisionWhat changes, deadlines or exit constraints must be understood before the renewal window closes?
OutputRenewal mechanics, price-reset risk, updated-term conflicts and exit readiness in one view.

Security and DPA review

InputDPA, security schedule, sub-processor terms and relevant master-agreement clauses.
DecisionWhich contractual questions remain open for privacy, security or procurement reviewers?
OutputEvidence-based issue spotting mapped to processor, transfer, incident and data-return fields.

Group or contractor rollout

InputLicence terms, order form, acceptable-use wording and the intended operating model.
DecisionAre affiliates, contractors, implementation partners and customer-facing workflows actually permitted?
OutputA licence-boundary summary and the clauses that restrict the proposed deployment.

Business-critical SaaS purchase

InputFull supplier pack for a platform supporting finance, operations, HR, reporting or customer delivery.
DecisionDo SLA, liability, security and exit protections match the operational dependency?
OutputCross-document findings that show where a low remedy or weak exit term amplifies the business risk.

Supplier replacement and exit

InputTermination, suspension, DPA, export, deletion and transition-assistance wording.
DecisionCan the customer retrieve what it needs and leave without losing access, evidence or continuity?
OutputExit sequence, data-return gaps, backup treatment and transition questions for the migration plan.
Pricing

Choose the depth that matches the contract pack

Detailed Analysis is the main route for a multi-document SaaS deal. Basic Check remains the lower-cost first pass for simpler terms and an initial view of obvious contract risk.

Primary

Detailed Analysis

£17.99

Designed for contract stacks where order forms, SaaS terms, SLAs, DPAs, security schedules, liability wording and renewal or exit mechanics need to be read together.

  • Clause-level evidence across the supplied SaaS pack.
  • Cross-document mapping for commercial, data, SLA and liability terms.
  • Warning triggers explained in plain English.
  • Focused review prompts for acceptance, negotiation or escalation.

Basic SaaS Contract Check

£7.99

A faster starting point for straightforward SaaS terms where the business wants to identify common commercial, renewal, liability and data issues before deciding whether deeper review is needed.

  • Lower-cost first pass for simpler SaaS agreements.
  • Common licence, renewal, liability and data warning fields.
  • Plain-English issue descriptions.
  • Clear route to deeper analysis where the pack is more complex.

Vordex is not a law firm and does not provide legal advice. Use an appropriate human reviewer and obtain advice from a qualified solicitor for high-value, regulated, disputed, bespoke, cross-border or business-critical SaaS contracts.

Product FAQ

Questions about the SaaS contract analysis workflow

The answers below explain how to use the product and where its limits sit. They are not a substitute for advice on a specific contract.

What should I include in a SaaS contract pack?
Include the documents you want Vordex to analyse, such as the order form, master SaaS terms, SLA, DPA, security schedule, support policy, sub-processor terms and negotiated amendments. Where a signed document points to online terms, include a saved or copied version so the relevant wording is available for analysis.
Can Vordex review several SaaS documents as one deal?
Detailed Analysis is designed for heavier contract packs where commercial, service, data and liability positions are split across several documents. The output connects related clauses so a favourable promise in one document is not read in isolation from an exclusion, cap or change right elsewhere.
What does the SaaS analysis output show?
The output is designed to show the relevant clause evidence, the issue category, a plain-English explanation of the commercial effect and a focused review prompt. The exact findings depend on the wording and documents supplied.
What is the difference between Basic Check and Detailed Analysis?
Basic Check is a lower-cost first pass for simpler SaaS terms. Detailed Analysis is the primary option for multi-document packs, linked DPAs, security schedules, heavier liability wording, renewal decisions and contracts where clause relationships need closer review.
Does Vordex certify that a SaaS contract is legally compliant?
No. Vordex provides contract analysis and general information. It does not certify compliance, guarantee enforceability or provide legal advice. Its role is to surface wording, conflicts and review points so an appropriate person can make the decision or escalate specific issues.
How are UK legal and regulatory references used?
References such as UK GDPR Article 28, ICO processor guidance and NCSC SaaS security guidance are used to frame specific review fields. They are not presented as a legal opinion, and Vordex should not be treated as live regulatory monitoring unless that capability is expressly stated elsewhere in the product.
Does Vordex automatically fetch every linked web policy?
Do not assume that every external webpage is automatically retrieved. For the clearest analysis, provide the versions of linked terms, policies or schedules that form part of the deal. This also preserves evidence of the wording reviewed at the time of approval or renewal.
Can the page be used for a SaaS renewal review?
Yes. The workflow is suited to renewal decisions because it focuses on notice windows, renewed term length, pricing changes, online-term changes, SLA history questions, liability position and exit readiness. It does not itself serve contractual notice.
Does SaaS Contract Review UK replace a solicitor?
No. Use a qualified solicitor for high-value, regulated, heavily negotiated, disputed, cross-border or business-critical contracts, and whenever you need legal advice rather than software-assisted contract analysis.

Put the whole SaaS contract stack into one review decision

Upload the documents you want analysed and move from supplier paperwork to clause evidence, warning triggers and a focused decision queue.

Contract analysis and general information only. Vordex does not certify compliance, guarantee enforceability or replace a qualified solicitor.