Contract negotiation for startups usually begins as a cost decision. Early stage companies handle their own agreements to save money, and for a great many of them that is the right call. The difficulty is that the agreements where it goes wrong tend to be the large ones, signed under time pressure, with a counterparty whose paper was drafted to be signed rather than negotiated.
Speed is a real constraint, not an excuse. A company with eighteen months of runway cannot spend three of them redlining. But the cost of a rushed signature is rarely felt at signature. It surfaces two years later, in a clause nobody read closely.
What standard enterprise paper usually does to a vendor
Consider a non-US digital wellness company that signs a Fortune 500 health plan. The deal opens access to 50 million members. It is, on its face, the transaction that makes the company.
The customer sends its standard vendor agreement. Four provisions in that document commonly do more damage than the commercial terms are worth.
Ownership of improvements. Enterprise templates frequently assign to the customer anything developed in the course of performing the services. Read literally, that can capture model improvements, workflow refinements and features built to serve this customer that the vendor intended to sell to the next one. A vendor whose entire strategy is to build once and sell many times can sign away that strategy in a definition.
Rights in the data. The vendor is usually processing the customer’s data on the customer’s behalf, and restrictions on independent use are appropriate. What is negotiable is whether the vendor may use de-identified or aggregated data to improve its own product. If that right is not reserved in the agreement, it does not exist, and for a company whose product improves with data volume that is a structural problem rather than a legal one.
Liability. Standard templates cap the vendor’s liability at a multiple of fees while carving out data breach, confidentiality and indemnity obligations from the cap entirely. The effect is an unlimited exposure sitting behind a clause that reads like a limitation. IBM’s annual breach study has put the average cost of a US data breach above $9 million, and settlements in health data cases have run well past that. An uncapped breach obligation is not a legal risk to be managed. For a company of that size it is an existential one.
Indemnities. Broad indemnity language obliges the vendor to defend claims it has no ability to control, sometimes including claims arising from the customer’s own use of the product.
None of these are unusual and none are unreasonable to raise. Enterprise counterparties expect vendors to negotiate them. Vendors who do not raise them are frequently assumed not to have read the document.
The same problem from the buying side
Now reverse the roles. Your company commits a significant share of its budget to a platform it intends to build on.
The vendor underdelivers. The questions that follow are contractual, and the answers were set months earlier. Do you have acceptance criteria that let you reject the work, or only a warranty that the services will be performed in a professional manner? Can you terminate for repeated failure, or only for a material breach the vendor will dispute? If you terminate, does the vendor owe you transition assistance and a copy of your data in a usable format, or does the agreement go quiet at that point?
Then a third party alleges the software infringes its intellectual property. You look for the vendor’s IP indemnity and find its liability capped at twelve months of fees. The defense costs exceed that before the first substantive motion.
The practical lesson is the same in both directions. Contracts allocate risk, and the allocation is easy to change while the counterparty wants the deal and close to impossible afterwards.
What to look at when time is short
Where a full review is not feasible, four provisions carry most of the risk in a technology or data agreement.
- The liability cap, and specifically what is carved out of it.
- Ownership of anything created during performance, including improvements to the vendor’s own product.
- Data rights, including permitted use of de-identified and aggregated data.
- Termination and what happens to the data and the service on the way out.
Reviewing those four takes hours rather than weeks and addresses the exposures that most often prove fatal.
Talk to us
We negotiate technology and data agreements for healthcare and health technology companies on both the vendor and the purchaser side, including for startups facing their first enterprise counterparty. If you have an agreement in front of you, book a discovery call.
The information provided on this website is for general informational purposes only and should not be considered legal advice. No attorney-client relationship is created by accessing or using this website. Please consult with a qualified attorney before making any legal decisions. Global Link Law is not liable for any reliance on the information provided. Prior results do not guarantee a similar outcome.