legal issues in saas swanh infoxchange 2007 legal issues in saas swanh infoxchange 2007 claire r....

Post on 19-Dec-2015

214 Views

Category:

Documents

0 Downloads

Preview:

Click to see full reader

TRANSCRIPT

Legal Issues in Legal Issues in SaaSSaaS

SwANH InfoXchange 2007SwANH InfoXchange 2007

Claire R. Howard, Esq.Claire R. Howard, Esq.Getman, Stacey, Schulthess & Steere, P.A. Getman, Stacey, Schulthess & Steere, P.A. Three Executive Park Drive, Suite 9, Bedford, NH Three Executive Park Drive, Suite 9, Bedford, NH

0311003110www.GetmanStacey.comwww.GetmanStacey.com

choward@getmanstacey.comchoward@getmanstacey.com(603) 634 4300 (603) 634 4300

We make our mark, by building your We make our mark, by building your business.business. TMTM

2

IntroductionIntroduction

►What do we mean by SaaS?What do we mean by SaaS? Vendor (Licensor) Vendor (Licensor) Customer (Licensee)Customer (Licensee)

3

What’s the Diff?What’s the Diff?

► LicenseLicense – Customer “purchases” license – Customer “purchases” license for specified number of users or sites and for specified number of users or sites and software is hosted and maintained onsitesoftware is hosted and maintained onsite

► SaaSSaaS – Customer “leases” right to access – Customer “leases” right to access software via a network (generally the software via a network (generally the web) and access, upgrades, hosting, etc. web) and access, upgrades, hosting, etc. are provided by vendor (through 3are provided by vendor (through 3rdrd party?) seamlessly for a monthly fee party?) seamlessly for a monthly fee

4

Licensing v. SaaSLicensing v. SaaS

LicenseLicense SaaSSaaS

Purchase/perpetual Purchase/perpetual licenselicense

Monthly “lease” Monthly “lease” paymentpayment

Installed on Installed on customer hardware customer hardware onsiteonsite

Hosted offsiteHosted offsite

In-house IT In-house IT serviced and serviced and managed (may be managed (may be under SLA)under SLA)

All service and All service and upgrades by vendor upgrades by vendor included included

5

Licensing v. SaaSLicensing v. SaaS

►Why is Saas different (from a legal Why is Saas different (from a legal standpoint) than a traditional license standpoint) than a traditional license arrangement?arrangement? Significant shift of Significant shift of

responsibility/liabilityresponsibility/liability

6

SaaS On the SaaS On the Rise?Rise?

In 2005 SaaS represented ~ 5% of In 2005 SaaS represented ~ 5% of business software revenuebusiness software revenue

By 2011, ~ 25% will be By 2011, ~ 25% will be delivered as SaaSdelivered as SaaS

Gartner, Inc.Gartner, Inc.

7

► www.SaaS-showplace.comwww.SaaS-showplace.com - Poll October 8, 2007 - Poll October 8, 2007 59% - SaaS solutions are essential to 59% - SaaS solutions are essential to

operations of my businessoperations of my business 32% - Still trying to understand the benefits of 32% - Still trying to understand the benefits of

Saas solutionsSaas solutions 9% - SaaS solutions are still unproven and risky9% - SaaS solutions are still unproven and risky

- Bias? -- Bias? -

SaaS On the SaaS On the Rise?Rise?

8

The AgreementThe Agreement

►DataData Ownership (c)/liability (v)Ownership (c)/liability (v) Export availability (c)Export availability (c) Back-up and storage procedures (c & v)Back-up and storage procedures (c & v) Responsibility for data loss and cost of Responsibility for data loss and cost of

retrieval (c & v)retrieval (c & v) Privacy issues - e.g., SoX, HIPAA Privacy issues - e.g., SoX, HIPAA

compliance (c & v)compliance (c & v)

9

The AgreementThe Agreement

►Service Level Requirements Service Level Requirements Percentage of uptime required - Percentage of uptime required -

permissible downtime for routine permissible downtime for routine maintenancemaintenance►Salesforce.com 2005 outage Salesforce.com 2005 outage

Response times Response times Service availabilityService availability Exceptions (e.g., force majeure, failure to Exceptions (e.g., force majeure, failure to

notify, etc.)notify, etc.)

10

The AgreementThe Agreement

►Hosting Hardware & FacilityHosting Hardware & Facility Hardware redundancyHardware redundancy Server scalability in case of rapid demand Server scalability in case of rapid demand

increaseincrease Redundant power supplies (battery and Redundant power supplies (battery and

diesel backups) (v)diesel backups) (v) Facility staffing (v)Facility staffing (v)

11

The AgreementThe Agreement

►Software Escrow AgreementSoftware Escrow Agreement Do you offer (v) or ask for (c)?Do you offer (v) or ask for (c)?

►Bargaining powerBargaining power►How important is the software to day-to-day How important is the software to day-to-day

operations?operations?►““Release Event”Release Event”

12

Case Study – Case Study –

Dealpower.comDealpower.comDealpower.com Dealpower.com

►““Master Subscription Agreement” Master Subscription Agreement” ►Saas powerhouse Saas powerhouse ►Names Names havehave been changed been changed

13

Dealpower.com Dealpower.com

►Scenario #1Scenario #1 Customer enters into Dealpower.com Customer enters into Dealpower.com

agreement. After the initial term, the agreement. After the initial term, the Customer determines the service is not Customer determines the service is not adequate for its needs and terminates adequate for its needs and terminates AgreementAgreement

What happens to Customer’s data?What happens to Customer’s data?

14

Dealpower.com Dealpower.com

►Scenario #1Scenario #1 ““In the event this Agreement is In the event this Agreement is

terminated (other than by reason of your terminated (other than by reason of your breach), Dealpower.com will make breach), Dealpower.com will make available to you a file of the Customer available to you a file of the Customer Data Data within 30 dayswithin 30 days of termination of termination if you if you so requestso request at the time of termination.” at the time of termination.”►Right to delete more than 30 days after Right to delete more than 30 days after

terminationtermination

15

Dealpower.com Dealpower.com

►Scenario #2Scenario #2 Customer enters into Dealpower.com Customer enters into Dealpower.com

agreement, but runs into financial agreement, but runs into financial difficulty and falls behind on paymentsdifficulty and falls behind on payments

What happens under the Agreement to: What happens under the Agreement to: ►Customer’s access to the ServiceCustomer’s access to the Service►Customer’s dataCustomer’s data

16

Dealpower.com Dealpower.com

►Scenario #2Scenario #2 Access - “Dealpower.com reserves the right Access - “Dealpower.com reserves the right

to suspend or terminate this Agreement and to suspend or terminate this Agreement and your access to the Service if your account your access to the Service if your account becomes delinquent (falls into arrears).”becomes delinquent (falls into arrears).”

Data – “Dealpower.com reserves the right to Data – “Dealpower.com reserves the right to withhold, remove and/or discard Customer withhold, remove and/or discard Customer Data Data without noticewithout notice for any breach, including, for any breach, including, without limitation your nonpayment.” without limitation your nonpayment.”

17

Dealpower.com Dealpower.com

►Scenario #3Scenario #3 Customer enters into Agreement Customer enters into Agreement A hardware issue with the server results in A hardware issue with the server results in

Service being unavailable for 6 hours Service being unavailable for 6 hours during business day and Data not being during business day and Data not being backed-up correctlybacked-up correctly

What is remedy for Customer?What is remedy for Customer?

18

Dealpower.com Dealpower.com

►Scenario #3Scenario #3 ““You, not Dealpower.com shall have sole You, not Dealpower.com shall have sole

responsibility for the accuracy [of the responsibility for the accuracy [of the Data] . . . and Dealpower.com shall not be Data] . . . and Dealpower.com shall not be responsible or liable for the deletion, responsible or liable for the deletion, correction, destruction, damage, loss or correction, destruction, damage, loss or failure failure to storeto store any Data.” any Data.”

““Dealpower.com makes no representation, Dealpower.com makes no representation, warranty, or guaranty as to the warranty, or guaranty as to the reliabilityreliability, , timeliness, timeliness, qualityquality . . . . . . availabilityavailability, accuracy or , accuracy or completeness of the Service or any content.” completeness of the Service or any content.”

19

Dealpower.com Dealpower.com

►Scenario #3Scenario #3

NO uptime requirementsNO uptime requirements

NO response timesNO response times

NO credit/termination right for downtimeNO credit/termination right for downtime

20

Dealpower.com Dealpower.com

►Scenario #4Scenario #4 Customer enters into Agreement and after Customer enters into Agreement and after

6 months Dealpower.com begins having 6 months Dealpower.com begins having financial difficultyfinancial difficulty

Creditor of Dealpower.com seizes all Creditor of Dealpower.com seizes all Dealpower.com hardware and/or Dealpower.com hardware and/or Dealpower.com files for bankruptcyDealpower.com files for bankruptcy

What happens to Customer access & data?What happens to Customer access & data?

21

Dealpower.com Dealpower.com

► Scenario #4Scenario #4 Unclear Unclear No software escrow (Service will not be No software escrow (Service will not be

available to Customer going forward)available to Customer going forward) ““In the event this Agreement is In the event this Agreement is

terminated (other than by reason of your terminated (other than by reason of your breach), Dealpower.com will make breach), Dealpower.com will make available to you a file of the Customer available to you a file of the Customer Data Data within 30 dayswithin 30 days of termination of termination if you if you so requestso request at the time of termination.” at the time of termination.”

No explicit mention of Dealpower.com No explicit mention of Dealpower.com breachbreach

22

Dealpower.com Dealpower.com

►Scenario #5Scenario #5 Customer enters into Agreement and Customer enters into Agreement and

properly terminates at the end of the initial properly terminates at the end of the initial termterm

Dealpower.com timely provides Data to Dealpower.com timely provides Data to Customer, but does not delete or destroyCustomer, but does not delete or destroy

Data winds up in possession of Customer’s Data winds up in possession of Customer’s direct competitor through inadvertent direct competitor through inadvertent disclosure by Dealpower.comdisclosure by Dealpower.com

23

Dealpower.com Dealpower.com

►Scenario #5Scenario #5 Under Agreement, Dealpower.com has no Under Agreement, Dealpower.com has no

obligation to delete or destroy Dataobligation to delete or destroy Data ““Dealpower.com does not represent or Dealpower.com does not represent or

warrant that . . . use of the Service will be warrant that . . . use of the Service will be securesecure, timely, uninterrupted or error-free , timely, uninterrupted or error-free . . . .”. . . .”

24

QuestionsQuestions??

25

Claire R. Howard, Esq. Claire R. Howard, Esq. Getman, Stacey, Schulthess & Steere, P.A.Getman, Stacey, Schulthess & Steere, P.A.

Three Executive Park Drive, Suite 9Three Executive Park Drive, Suite 9Bedford, NH 03110Bedford, NH 03110

603.634.4300603.634.4300choward@getmanstacey.comchoward@getmanstacey.com

top related