Sectors

Technology & SaaS

Last updated: 22 September 2026

Technology and SaaS businesses run into a particular set of legal questions: who owns the code and content, what the platform promises its users, how customer data is handled and how the product is licensed. These are the issues that come up most often, and where each is covered.

What comes up

Customer data and the DPDP Act

A SaaS business usually handles personal data in two capacities: as a data fiduciary for its own users and staff, deciding why and how their data is processed, and as a data processor for business customers whose end users' data it stores or processes on their instructions. The obligations differ, and contracts with customers should say which applies to which data.

The Digital Personal Data Protection Act, 2023 applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to people in India. The Digital Personal Data Protection Rules, 2025 bring its obligations into force in phases, which gives businesses a window to prepare notices, consent flows, security safeguards and breach-response processes.

Platform terms and customer contracts

Terms of service, subscription agreements and service level commitments define what the platform promises, what customers may do with it, and who bears the risk when something fails. With business customers, the points most often negotiated are limitation of liability, indemnities, data protection terms, uptime commitments and what happens to customer data when the contract ends.

Terms written for a different product, or copied from another platform, tend to promise too much or too little. They should match how the product actually works and how it is sold.

Owning the code, content and brand

Under the Copyright Act, 1957, a company generally owns work created by its employees in the course of their employment, but not work created by freelancers, agencies, or co-founders before they joined, unless those rights are assigned to it in writing. Gaps here are among the most common findings when investors carry out due diligence on a technology company.

The product name and logo are protected separately, through trademark registration, which is worth securing before the brand becomes widely known.

Licensing software and technology

Licensing a product, integrating third-party technology or white-labelling for a partner each creates rights and restrictions that need to be written down: the scope of use, territory, exclusivity, fees, support obligations, and what happens to the licence if either side is acquired. Open-source components carry licence conditions of their own that can affect how the product may be distributed.

Raising investment

Investors in a technology company review the cap table, founders' agreements, IP ownership and data protection position before they invest. The round itself is usually documented in a term sheet, a share subscription agreement and a shareholders' agreement, which together set out what the investor pays for, the rights it receives and what the founders commit to.

Customers and users outside India

A platform with users in the European Union may be subject to the GDPR, which applies to businesses outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Contracts with overseas customers also raise questions of governing law, dispute resolution and cross-border transfers of data.

Portrait of Kanika Marwaha Bindal

Written and reviewed by

Kanika Marwaha Bindal

Advocate, Gurugram. Postgraduate in Corporate Laws, NLU Jodhpur.

She trains Internal Committees and serves as an external member on POSH committees, and has advised clients in India, the UAE, the United States, Canada, Japan and Australia.