Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
If you are a UK B2B SaaS founder, the liability cap in your contract can decide whether one bad outage becomes a manageable commercial issue or a business-threatening claim. A lot of startups make the same mistakes. They accept the other side's standard cap without checking what is carved out, they agree to unlimited indemnities while thinking the cap still protects them, or they set a cap by copying a bigger supplier's contract without matching it to their actual risk profile.
That matters most just before you sign a customer MSA, supplier terms, reseller deal, or enterprise procurement paper. The liability section often looks technical, but it is really about who carries the financial risk when something goes wrong.
This guide explains how liability caps usually work in UK B2B SaaS contracts, which clauses can quietly bypass the cap, what legal limits apply under UK law, and how founders can negotiate a position that is commercially realistic without scaring off customers.
Overview
A liability cap is the contractual limit on what one party may have to pay if it breaches the agreement or causes loss. In B2B SaaS deals, the headline number only tells part of the story, because exclusions, carve-outs, indemnities, service levels, data protection wording and termination rights can change the real allocation of risk.
For UK businesses, the best liability clause is usually the one that matches the actual deal, the fees, the service model and the kinds of loss each side could realistically suffer.
- Check whether the cap applies per claim, per year, per event, or in aggregate.
- Check which claims sit outside the cap, including data protection, confidentiality, IP infringement and payment obligations.
- Check whether indirect or consequential loss is excluded, and whether the listed excluded losses include lost profits, revenue, savings, data or goodwill.
- Check the cap against the contract value, insurance cover and the worst realistic failure scenario.
- Check whether service credits are the customer's sole remedy for service levels, or whether they sit on top of damages.
- Check whether indemnities and third party claims are still subject to the cap.
What Liability Cap Contract B2B SaaS Startups Means For UK Businesses
For a UK SaaS business, a liability cap is not just legal wording, it is a pricing and risk decision built into the contract.
Most B2B SaaS agreements try to draw a line between acceptable commercial risk and open-ended exposure. A customer pays a subscription fee, often relatively modest compared with the possible business impact of downtime, data loss or a security incident. Without a negotiated limit, the startup could be exposed to a claim far larger than the revenue earned under the deal.
That is why founders often propose a cap linked to fees paid under the contract. A common starting point is fees paid in the last 12 months, total fees paid, or a multiple of annual fees. None of those numbers is automatically right. The right position depends on the service, customer profile and bargaining strength.
Why enterprise customers focus on liability caps
Customers are not being difficult when they push back on a low cap. They are looking at the operational importance of your platform. If your software handles payroll, customer communications, regulated records, or core workflow, the customer may say your fees are small compared with the potential loss from failure.
In practice, customers usually look at a few questions:
- How business-critical is the SaaS product?
- How sensitive is the data involved?
- How likely is a service failure to cause wider financial loss?
- How mature is the startup's security and incident response?
- Does the startup carry meaningful insurance?
If you can answer those points clearly, your negotiation position improves. Founders often lose leverage because they only say, "our cap is standard", which rarely persuades a serious buyer.
What UK law allows and restricts
UK law generally lets businesses agree limits of liability in B2B contracts, but there are important limits. You cannot exclude or restrict liability for fraud. You also cannot exclude liability for death or personal injury caused by negligence. Other exclusions and limitations may be subject to a reasonableness test under the Unfair Contract Terms Act 1977.
That does not mean every liability cap is invalid. It means a cap and related exclusions should be commercially justifiable in context. Courts may look at bargaining strength, whether the term was negotiated, whether insurance was available, and what the parties reasonably knew when they contracted.
For SaaS startups, the practical takeaway is simple. A low cap can still be enforceable, but it should make sense for the deal and be presented as part of a balanced risk allocation, not as a hidden attempt to avoid all responsibility.
Why the headline cap can be misleading
The main risk is assuming the cap figure tells you everything. It rarely does.
A contract might say liability is capped at 100 per cent of fees paid in the previous 12 months, then immediately carve out whole categories of claims. If data protection breaches, confidentiality breaches, IP infringement claims and indemnities all sit outside the cap, the practical exposure may be far higher than founders realise.
Equally, a customer may focus on increasing the cap from 100 per cent to 150 per cent of annual fees, when the more important issue is tightening overbroad carve-outs or excluding remote financial losses. Before you sign, look at the whole liability regime, not just the number.
Legal Issues To Check Before You Sign
Before you sign a contract with a liability cap, make sure the cap actually covers the claims you think it covers.
How the cap is calculated
The first question is mechanical but crucial. What is the cap measured against, and over what period?
Common formulations include:
- fees paid or payable in the previous 12 months;
- total fees paid or payable under the agreement;
- a fixed sum;
- a multiple of annual recurring fees;
- different caps for different claim types.
A rolling 12 month cap often suits SaaS subscriptions because it tracks contract value over time. A total-fees cap may be more acceptable for short fixed-term projects. A fixed cap can work where fees are low but the parties want certainty.
Watch the phrase "paid or payable". If the wording only uses fees paid, a claim early in the term may leave you with an unexpectedly low cap. If it includes fees payable, the cap may be higher than your current cash exposure suggests.
Whether the cap is aggregate or claim-by-claim
A cap should usually state whether it applies in aggregate across all claims or to each claim separately. That drafting point changes the economics quickly.
If the cap applies to each claim, multiple incidents can multiply exposure. If the cap is aggregate, once the limit is reached there is no further financial liability for covered claims. Startups commonly prefer an aggregate cap, especially for recurring services where multiple related complaints could arise from one underlying issue.
Exclusions of indirect and consequential loss
Most SaaS contracts exclude indirect or consequential loss, but founders should not assume that solves everything. Those legal labels can be uncertain in application, and many contracts also list specific excluded losses for clarity.
Useful listed exclusions often include:
- loss of profit;
- loss of revenue;
- loss of anticipated savings;
- loss of business or contracts;
- loss of goodwill;
- loss or corruption of data, unless expressly accepted elsewhere.
Customers may resist broad exclusion of data loss if your service hosts or processes important information. In that case, the negotiation may shift to service credits, backup commitments, recovery obligations and a higher but still limited cap.
Carve-outs from the cap
This is where founders often get caught. A sensible-looking cap can be hollowed out by wide carve-outs.
Typical carve-outs may include:
- fraud or fraudulent misrepresentation;
- death or personal injury caused by negligence;
- breach of confidentiality;
- data protection breaches;
- IP infringement claims;
- fees and charges payable under the contract;
- indemnity claims.
Some of those carve-outs are expected. Others need careful drafting. For example, putting all confidentiality breaches outside the cap can be too broad for a SaaS provider, because almost any handling of customer information may be argued to be confidential information. A more balanced position may be a separate higher cap for confidentiality and data protection breaches, rather than unlimited liability.
Indemnities that bypass the cap
An indemnity is often drafted as a promise to reimburse specific losses or third party claims. The problem is that indemnities are sometimes excluded from the general cap entirely.
Check whether your contract includes indemnities for:
- IP infringement;
- data protection breaches;
- security incidents;
- third party claims caused by your service;
- regulatory fines or investigation costs.
Do not assume these clauses are standard or harmless. An uncapped indemnity can expose a startup to costs well beyond subscription revenue. If a customer wants an indemnity, ask whether it can be subject to the main cap or at least a separate defined cap.
Data protection and security risk
Where the SaaS product processes personal data, liability wording often overlaps with the data processing clause and privacy notice. Customers may ask for uncapped liability for breaches of data protection law or security failures. Startups often accept this too quickly because it sounds non-negotiable.
In reality, the better question is what risk is being allocated. Is the startup acting as processor under the customer's instructions? Does the customer control what personal data enters the system? Is the claim about a technical breach, misuse of data, or a wider regulatory penalty?
A separate data protection cap is common. The amount might be a multiple of fees or a fixed higher sum. That can be more realistic than full unlimited liability, especially for smaller contracts.
Service levels, refunds and sole remedy wording
Service credits can quietly affect liability exposure. If your SLA offers credits for downtime, the contract should say whether those credits are the customer's exclusive remedy for that failure, except for specified serious breaches.
Without sole remedy wording, a customer may argue it can claim credits and damages. That is not always what the startup priced for. Before you accept the provider's standard terms, or before you issue your own written terms, line up the SLA with the liability clause so the remedies work together.
Insurance and practical recoverability
Your contract cap should be informed by insurance, but not dictated by it. Insurance limits, exclusions, deductibles and notification requirements all matter.
If you propose a cap far above your available cover, ask yourself whether the business could absorb the uninsured part. If you set a cap well below any plausible loss, expect customer pushback. A founder-friendly position is one you can explain with evidence, not just preference.
Common Mistakes With Liability Cap Contract B2B SaaS Startups
The most common mistake is treating the liability clause as a late-stage redline issue instead of a pricing and product risk issue from the start.
Accepting "market standard" wording without context
There is no single market standard cap for UK B2B SaaS. The right result for a low-cost workflow tool is different from the right result for software handling sensitive operational data.
Founders sometimes copy terms from larger vendors or procurement templates from enterprise customers. That can create a mismatch between legal exposure, revenue and technical controls.
Confusing a cap with real protection
A contract can contain a neat liability cap and still leave the startup exposed. The usual reasons are:
- important claims are carved out;
- indemnities sit outside the cap;
- the cap applies per claim instead of in aggregate;
- payment obligations are one-way and uncapped for the startup;
- the customer can stack remedies.
Before you rely on a verbal promise that the clause is "just boilerplate", read the liability wording alongside indemnities, data protection, confidentiality, IP and SLA provisions.
Offering unlimited liability to win one deal
This usually feels easier in the moment and much harder later. One enterprise customer may insist on uncapped exposure for security or data issues. A founder trying to close the deal may accept, thinking the risk is theoretical.
The problem is not only that the risk may be real. It is also that the signed contract can become the reference point for future customers, investors and due diligence. A one-off concession has a habit of turning into a precedent.
Ignoring the supplier side of the stack
Your customer contract is only half the picture. If you rely on cloud hosting, APIs, analytics tools, communications providers or outsourced development, check whether their liability to you is much lower than your liability to your customer.
This is a classic back-to-back risk gap. If a critical subcontractor causes the incident, your recovery from them may be capped at a small monthly fee while your customer claim sits at a much higher level.
Look for alignment across the supply chain on:
- service levels;
- security commitments;
- IP ownership and infringement risk;
- termination rights;
- liability caps and carve-outs.
Forgetting to match the clause to the deal stage
An early pilot, a proof of concept and a business-critical multi-year deployment should not always carry the same liability position. Startups often miss the chance to scale risk as the relationship develops.
You may be able to agree a lower cap during a pilot, then revisit it when usage grows, security review is complete, and the pricing model changes. That approach can be more commercially acceptable than arguing over a single permanent position.
Negotiating the number, not the story
Customers are more likely to accept your cap if you explain why it is fair. Good reasons might include the subscription price, the nature of the service, contractual backups, customer configuration responsibilities, agreed service credits, and the insurance available.
Founders often go straight to haggling over percentages. A better approach is to explain the risk model in plain English, then offer targeted movement where the customer's concern is genuine.
FAQs
What is a typical liability cap in a UK B2B SaaS contract?
There is no fixed rule, but a common starting point is the fees paid or payable in the previous 12 months. Some deals use a multiple of annual fees, and some have separate higher caps for data protection or confidentiality claims.
Can a UK SaaS startup exclude all liability?
No. Some liabilities cannot be excluded, including fraud and death or personal injury caused by negligence. Other exclusions may be tested for reasonableness under UK law.
Should data protection breaches be uncapped?
Not necessarily. Many contracts use a separate higher cap for data protection and security claims instead of unlimited liability. The right position depends on the data involved, the service model and bargaining strength.
Do indemnities usually sit outside the liability cap?
Sometimes, but they do not have to. This is a key negotiation point. If an indemnity sits outside the cap, the startup's exposure can be much higher than the headline limit suggests.
Is the customer's standard contract safe to sign if the cap looks reasonable?
Not on that point alone. You need to read the full liability regime, including carve-outs, indemnities, exclusions of loss, service levels, termination rights and data protection terms before you sign.
Key Takeaways
- A liability cap sets the financial limit for certain claims, but the real risk depends on the whole contract, not just the headline figure.
- Check how the cap is calculated, whether it is aggregate, and whether important claims are carved out.
- Review indemnities, confidentiality, data protection, IP and service credit clauses carefully, because these often reshape the actual exposure.
- Use a cap that matches the contract value, service criticality, insurance position and likely loss scenario.
- A balanced explanation of your risk model usually works better than simply insisting your wording is standard.
- Supplier terms matter too, because a gap between your upstream and customer-facing liability can leave your startup carrying the difference.
If you want help with contract drafting, contract review, indemnity and carve-out negotiation, data protection risk allocation, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.








