saas-msa-review
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseSaaS / Subscription Agreement Review
SaaS/订阅协议审查
Matter context
事项背景
Matter context. Check in the practice-level CLAUDE.md. If is (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run or say ." Load the active matter's for matter-specific context and overrides. Write outputs to the matter folder at . Never read another matter's files unless is .
## Matter workspacesEnabled✗/commercial-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/commercial-legal/matters/<matter-slug>/Cross-matter contexton事项背景:查看实践级CLAUDE.md中的部分。如果为(内部用户默认设置),则跳过本段剩余内容——技能将使用实践级上下文,事项机制不可见。如果已启用且无活跃事项,请询问:“这属于哪个事项?请运行或说明。”加载活跃事项的以获取事项特定上下文和覆盖规则。将输出写入事项文件夹:。除非为,否则切勿读取其他事项的文件。
## Matter workspacesEnabled✗/commercial-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/commercial-legal/matters/<matter-slug>/Cross-matter contextonPurpose
目的
SaaS agreements have a distinct risk profile from one-time vendor contracts. The dollars compound over renewals, the data accumulates, and the switching cost grows every month. This skill reviews with that in mind.
It runs the standard playbook check from and adds a SaaS-specific overlay on the terms that bite hardest in subscription deals.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdSaaS协议的风险特征与一次性供应商合同截然不同。费用会在续订时累积,数据不断增加,每月的转换成本也会上升。本技能的审查正是基于这一考量。
它会执行中的标准手册检查,并针对订阅交易中最容易引发问题的条款添加SaaS专项覆盖。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdJurisdiction assumption
管辖地假设
SaaS terms (auto-renewal notice requirements, price-escalation caps, data-portability mandates, subprocessor rules) are jurisdiction-sensitive — California, New York, and EU rules diverge materially, and some states have auto-renewal statutes that override private contract terms. This review applies the team's positions from , which assume the governing law recorded there. If the agreement picks a different governing law, or the deal spans jurisdictions with statutory overrides (e.g., EU-based users, California consumers), flag it — the analysis may not transfer as written.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdNo silent supplement. If a research query to the configured legal research tool (Westlaw, or firm platform) returns few or no results for a statutory override that might bear on the deal (auto-renewal statute, data-portability mandate, consumer-protection rule), report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [jurisdiction / rule]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be taggedand should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.[web search — verify]Source attribution. Where the review cites a statute, regulation, or case (e.g., a state auto-renewal law overriding contract terms), tag the citation:,[Westlaw], or the MCP tool name for citations retrieved from a legal research connector;[statute / regulator site]for web-search citations;[web search — verify]for citations recalled from training data;[model knowledge — verify]for citations from the counterparty draft or house files. Citations tagged[user provided]carry higher fabrication risk and should be checked first. Never strip or collapse the tags.verify
SaaS条款(自动续订通知要求、价格上调上限、数据可移植性规定、分包商规则)受管辖地影响——加利福尼亚州、纽约州和欧盟的规则存在显著差异,部分州的自动续订法规会优先于私人合同条款。本次审查将应用中记录的团队立场,该立场基于其中记载的准据法。如果协议选择了不同的准据法,或交易涉及存在法规优先适用的管辖地(例如欧盟用户、加利福尼亚州消费者),请标记出来——书面分析可能无法直接适用。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md禁止无依据补充:如果向配置的法律研究工具(Westlaw或律所平台)发出的研究查询,针对可能影响交易的法规优先适用情形(自动续订法规、数据可移植性规定、消费者保护规则)返回的结果很少或没有,请报告查询结果并停止操作。未经询问,不得通过网络搜索或模型知识填补空白。请说明:“从[工具]返回了[N]条结果。针对[管辖地/规则]的覆盖范围似乎有限。选项:(1) 扩大搜索查询范围,(2) 尝试其他研究工具,(3) 进行网络搜索——结果将标记为,在依赖前应与原始来源核对,或(4) 标记为未验证并停止操作。您希望选择哪一项?”由律师决定是否接受可信度较低的来源。[web search — verify]来源归因:当审查引用法规、规章或案例(例如州自动续订法优先于合同条款)时,请为引用添加标签:从法律研究连接器获取的引用标记为、[Westlaw]或MCP工具名称;网络搜索获取的引用标记为[statute / regulator site];从训练数据中调取的引用标记为[web search — verify];从对方草稿或内部文件中获取的引用标记为[model knowledge — verify]。标记为[user provided]的引用存在较高的伪造风险,应优先核对。切勿移除或合并标签。verify
Load the playbook
加载手册
Which side? Before applying the playbook, determine which side the company is on for this SaaS agreement. Usually obvious: if the counterparty is a SaaS vendor selling you their platform, you're purchasing-side. If you are the SaaS vendor and the counterparty is your customer, you're sales-side. If it's not obvious (a reseller arrangement, a white-label deal), ask: "Which side is [company] on for this agreement — vendor or customer?" Read the matching playbook section ( or ) from the config. Note which side in the output so the reviewer knows which playbook was applied. If the matching side is , stop and tell the user to run before this review can proceed.
### Sales-side playbook### Purchasing-side playbook[Not configured]/commercial-legal:cold-start-interview --side <side>Read first. The general playbook for the matching side (liability, indemnity, termination, governing law) applies fully — run all the standard checks from the vendor-agreement-review skill.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdThen look for a → matching side → section. That's where the team records its positions on auto-renewal notice windows, acceptable price escalators, data export rights, SLA thresholds, subprocessor approval rights, and deprecation notice. This skill does not ship with defaults for these — the right numbers vary by deal size, vendor leverage, and the team's risk tolerance.
## PlaybookSaaS positionsIf doesn't address a SaaS-specific term that comes up in this review, ask:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdYour playbook doesn't cover [term — e.g., "maximum acceptable auto-renewal notice window" or "whether vendor retention of anonymized derivatives is acceptable"]. What's your team's position? I'll add it to.~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md
Record the answer and proceed.
**哪一方?**在应用手册之前,确定公司在本SaaS协议中的立场。通常很明确:如果对方是向您销售平台的SaaS供应商,您属于采购方;如果您是SaaS供应商,对方是您的客户,您属于销售方。如果立场不明确(转售安排、白标交易),请询问:“[公司]在本协议中属于哪一方——供应商还是客户?”从配置文件中读取匹配的手册部分(或)。在输出中注明立场,以便审查者了解应用的是哪份手册。如果匹配的立场为,请停止操作并告知用户先运行,然后才能进行本次审查。
### Sales-side playbook### Purchasing-side playbook[Not configured]/commercial-legal:cold-start-interview --side <side>首先阅读。匹配立场的通用手册(责任、赔偿、终止、准据法)完全适用——执行供应商协议审查技能中的所有标准检查。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md然后查找 → 匹配立场 → 部分。团队在此记录其关于自动续订通知窗口、可接受的价格上调幅度、数据导出权利、SLA阈值、分包商批准权和弃用通知的立场。本技能未提供这些内容的默认值——合理数值因交易规模、供应商影响力和团队风险承受能力而异。
## PlaybookSaaS positions如果未涵盖本次审查中出现的某个SaaS专项条款,请询问:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md您的手册未涵盖[条款——例如“可接受的最长自动续订通知窗口”或“是否允许供应商保留匿名化衍生数据”]。您的团队立场是什么?我会将其添加到中。~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md
记录答案后继续操作。
SaaS-specific overlay
SaaS专项覆盖
For each category below, list what you found in the contract and compare to the team's position in . Do not apply hardcoded thresholds from this skill.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md针对以下每个类别,列出合同中的内容,并与中的团队立场进行比较。请勿应用本技能中的硬编码阈值。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md1. Auto-renewal mechanics
1. 自动续订机制
The single most common way a SaaS deal goes wrong: nobody notices the renewal notice window and we're locked in for another year at a higher price.
Check each element and compare against the team's in :
SaaS positions~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Renewal term length (e.g., same as initial, longer, multi-year auto-convert)
- Notice-to-cancel window (number of days before renewal)
- Notice method (email, written notice to legal, portal-only, certified mail)
- Price on renewal (same, CPI-capped, then-current list, uncapped discretionary)
Extract and record the exact renewal date and the notice window regardless of whether any item is flagged. This feeds the renewal-tracker skill.
SaaS交易最常见的问题:无人注意到续订通知窗口,导致我们被锁定在另一个年度的更高价格中。
检查每个要素,并与中的团队进行比较:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdSaaS positions- 续订期限长度(例如与初始期限相同、更长、自动转换为多年期)
- 取消通知窗口(续订前的天数)
- 通知方式(电子邮件、书面通知法务、仅通过门户、挂号信)
- 续订价格(相同、CPI上限、当前标价、无上限自主定价)
提取并记录确切的续订日期和通知窗口,无论是否有项目被标记。这些信息将提供给续订跟踪器技能。
2. Price escalation
2. 价格上调
Check each element against :
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Annual escalator (fixed %, CPI, uncapped, etc.)
- Usage overage pricing (published rate card, premium rate, unspecified)
- Scope of "fees" (subscription only vs. "additional services" broadly defined)
对照检查每个要素:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- 年度上调幅度(固定百分比、CPI、无上限等)
- 使用超额定价(公布价目表、溢价、未指定)
- “费用”范围(仅订阅费 vs 广义定义的“附加服务”)
3. Data portability and exit
3. 数据可移植性与退出
When (not if) we leave this vendor, can we get our data out? Check each element against :
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Export format (open/standard, proprietary-but-documented, "commercially reasonable")
- Export availability (self-serve anytime, on request during term, only at termination)
- Post-termination access (days available to export after termination)
- Export cost (free, T&M, per-GB or per-record)
- Deletion certification (certified on request, none, vendor retains derivatives)
Vendor retention of "anonymized" or "aggregated" derivatives is a material position — confirm the team's stance in and flag either way.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md当(而非如果)我们更换供应商时,能否导出数据?对照检查每个要素:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- 导出格式(开放/标准格式、专有但有文档说明、“商业合理”)
- 导出可用性(随时自助导出、协议期内按需导出、仅终止时导出)
- 终止后访问权限(终止后可导出的天数)
- 导出成本(免费、工时计价、每GB或每条记录计价)
- 删除证明(按需提供证明、无证明、供应商保留衍生数据)
供应商保留“匿名化”或“聚合”衍生数据是重要立场——请确认中的团队立场,并进行标记。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md4. Uptime and SLA
4. 正常运行时间与SLA
Only matters if the business actually depends on this service being up. If it's a nice-to-have tool, skip this section — don't spend negotiating capital on SLAs for a survey tool.
Check each element against :
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Uptime commitment (percentage, or "commercially reasonable efforts")
- Measurement period (monthly, quarterly, annual)
- Remedy (service credits — how calculated, whether capped, whether sole remedy)
- Scheduled maintenance exclusions (defined window, advance notice, unlimited)
- Credit-as-sole-remedy interaction with the liability cap
仅当业务实际依赖该服务的可用性时才需要关注。如果是锦上添花的工具,请跳过本节——不要为调查工具的SLA花费谈判成本。
对照检查每个要素:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- 正常运行时间承诺(百分比或“商业合理努力”)
- 计量周期(月度、季度、年度)
- 补救措施(服务信用——计算方式、是否有上限、是否为唯一补救措施)
- 计划维护排除项(定义的窗口、提前通知、无限制)
- 信用作为唯一补救措施与责任上限的相互作用
5. Subprocessors
5. 分包商
This is a data protection issue but it's SaaS-specific because the subprocessor list changes over the life of the subscription.
Check each element against :
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Current list (published, on request, unavailable)
- Change notification (advance notice period, or none)
- Objection rights (blocking, notice-and-terminate, notice-only, none)
这是一个数据保护问题,但具有SaaS特殊性,因为分包商列表会在订阅有效期内发生变化。
对照检查每个要素:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- 当前列表(已公布、按需提供、无法获取)
- 变更通知(提前通知期限或无通知)
- 异议权(阻止、通知并终止、仅通知、无异议权)
6. Service changes and deprecation
6. 服务变更与弃用
SaaS vendors change their product. Usually fine. Sometimes they deprecate the thing you bought.
Check each element against :
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- Material adverse changes (right to terminate on material degradation, notice-only, unrestricted)
- Deprecation notice period for features the team relies on
- Feature parity on replacement (same price tier, higher tier)
SaaS供应商会更改其产品。通常没问题,但有时他们会弃用您购买的功能。
对照检查每个要素:
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md- 重大不利变更(因重大降级而终止的权利、仅通知、无限制)
- 团队依赖功能的弃用通知期限
- 替代功能的对等性(相同价格层级、更高层级)
AI and machine learning rights
AI与机器学习权利
AI/ML data rights decision procedure. Don't just check whether an AI training clause exists. The #1 emerging negotiation point in SaaS contracts is structurally more than a one-line existence check. Work through:
- Explicit grant. Does the contract explicitly grant the vendor rights to use Customer Data / Customer Content / Usage Data for AI training, model improvement, or ML development? Purchasing-side: this is usually a NO — customer data training the vendor's models means the customer is subsidizing the vendor's product and possibly leaking competitive information. Sales-side: this is revenue if you get it, reputation risk if you abuse it.
- Implicit grant via policy. Does the contract incorporate the vendor's privacy policy or terms of service by reference? Can the vendor add training rights via a unilateral policy update? Check: "The parties agree to the Provider's Privacy Policy as updated from time to time" is a training-rights grant waiting to happen. Also watch for "service improvement" or "analytics" catch-alls and "usage data" definitions that carve logs/telemetry out of the Customer Data definition so data-use restrictions don't apply.
- Anonymization standard. If the vendor claims it only trains on "anonymized" or "aggregated" data, what's the standard? "Anonymized" without a definition is weak. Does it meet GDPR Recital 26 / HIPAA Safe Harbor / a named standard? Is it reversible?
- Competitive contamination. Does the vendor serve your competitors? If so, training on your data could leak competitive intelligence into outputs your competitors see. Is there a competitive isolation commitment?
- Opt-out scope and durability. If there's an opt-out, does it cover all AI uses or only some? Does it survive renewals and TOS updates? Is it per-user or per-org? Many vendors default to training and offer an opt-out buried in an admin console — check whether the contract makes the default explicit.
- Output ownership. If the SaaS product is itself AI-generated (drafting, summarization, analysis), who owns the outputs? Can the vendor use your outputs as training examples? Check third-party AI subprocessors too — the vendor may send customer data to a third-party LLM (OpenAI, Anthropic, Google) and the subprocessor list / data flow is where that shows up.
- Downstream regulatory chain. Does the vendor's use of your data for AI create regulatory exposure for YOU? EU AI Act deployer obligations, FTC §5 undisclosed data-sharing exposure (see FTC v. Humor Rainbow/OkCupid), state AI laws.
Match each to a playbook position. The practice profile's section should have positions for each. If the agreement is silent on all seven, that's still a finding: "The agreement is silent on AI/ML training rights — request an explicit prohibition or a defined carve-out tied to each of the seven dimensions above."
## AI/ML training rightsAI/ML数据权利决策流程:不要仅检查是否存在AI培训条款。SaaS合同中最热门的新兴谈判点并非简单的单行条款检查。请按以下步骤操作:
- 明确授权:合同是否明确授予供应商使用客户数据/客户内容/使用数据进行AI培训、模型改进或ML开发的权利?采购方:通常应拒绝——客户数据用于训练供应商模型意味着客户在补贴供应商产品,并可能泄露竞争信息。销售方:如果获得此项权利可带来收益,但滥用会带来声誉风险。
- 通过政策隐含授权:合同是否通过引用纳入供应商的隐私政策或服务条款?供应商能否通过单方面更新政策添加培训权利?请注意:“双方同意接受供应商不时更新的隐私政策”相当于潜在的培训权利授权。同时注意“服务改进”或“分析”等概括性条款,以及将日志/遥测排除在客户数据定义之外的“使用数据”定义,这样数据使用限制将不适用。
- 匿名化标准:如果供应商声称仅使用“匿名化”或“聚合”数据进行训练,标准是什么?未定义的“匿名化”效力较弱。是否符合GDPR第26条/HIPAA安全港/指定标准?是否可还原?
- 竞争污染:供应商是否为您的竞争对手提供服务?如果是,使用您的数据进行训练可能会将竞争情报泄露给竞争对手可见的输出中。是否有竞争隔离承诺?
- 退出范围与持久性:如果有退出选项,是否涵盖所有AI用途还是仅部分?是否在续订和服务条款更新后仍然有效?是按用户还是按组织?许多供应商默认进行培训,并在管理控制台中隐藏退出选项——请检查合同是否明确默认条款。
- 输出所有权:如果SaaS产品本身是AI生成的(起草、摘要、分析),谁拥有输出的所有权?供应商能否将您的输出用作训练示例?同时检查第三方AI分包商——供应商可能会将客户数据发送给第三方LLM(OpenAI、Anthropic、Google),分包商列表/数据流会显示这一点。
- 下游监管链:供应商将您的数据用于AI是否会为您带来监管风险?欧盟AI法案部署者义务、FTC第5条未披露的数据共享风险(参见FTC v. Humor Rainbow/OkCupid)、各州AI法律。
将每个步骤与手册立场匹配。实践档案的部分应包含每个步骤的立场。如果协议对所有七个步骤均未提及,这仍然是一项发现:“协议未提及AI/ML培训权利——要求明确禁止或针对上述七个维度定义例外条款。”
## AI/ML training rightsLiability cap decision procedure
责任上限决策流程
The cap amount is the least important part of the cap. Limitation-of-liability is not a single "check against playbook" item. Work through:
-
Direct vs. indirect/consequential damages. Does the cap apply to ALL liability, or only direct damages? A 12-month cap on direct damages with uncapped consequential damages is a completely different position than a 12-month aggregate cap. State both treatments explicitly.
-
The cap base — quote it verbatim. "12-month cap" could mean: (a) fees paid in the 12 months preceding the claim, (b) fees payable in the current 12-month period, (c) fees over the last 12 months of usage, (d) fees under the current order form, (e) total fees ever paid. These can differ by an order of magnitude. Quote the exact language. If ambiguous, flag it: "Cap base is ambiguous —— could mean [X] or [Y]. Confirm before signing."
[the quoted language] -
Cap-carveout interaction. A $100K cap with uncapped indemnity for data breach, IP, and confidentiality is functionally uncapped for the claims that actually arise in SaaS disputes. Enumerate what sits ABOVE the cap (the carveouts), what sits BELOW (what's actually capped), and assess whether the capped surface is meaningful: "The cap covers [general contract breach]. Data breach, IP indemnity, and confidentiality are carved out and uncapped. For this vendor's risk profile, the capped surface is [meaningful / nominal]."
-
Your playbook position per dimension. The practice profile should have positions for: direct cap (multiple of fees), indirect damages (excluded / capped / uncapped), carveout list (what's acceptable above the cap), and cap base (which definition you'll accept). If the playbook has one "standard position" field, note: "Your playbook has a single cap position — consider splitting into direct/indirect/carveouts/base for more precise review."
上限金额是责任上限中最不重要的部分。责任限制并非单一的“对照手册检查”项。请按以下步骤操作:
-
直接损害与间接/后果性损害:上限是否适用于所有责任,还是仅适用于直接损害?针对直接损害的12个月上限加上无上限的后果性损害,与12个月总上限是完全不同的立场。请明确说明两种处理方式。
-
上限基数——逐字引用:“12个月上限”可能指:(a) 索赔前12个月支付的费用,(b) 当前12个月应付的费用,(c) 过去12个月使用产生的费用,(d) 当前订单下的费用,(e) 已支付的总费用。这些可能相差一个数量级。请引用确切措辞。如果存在歧义,请标记:“上限基数不明确————可能指[X]或[Y]。签署前请确认。”
[引用措辞] -
上限例外的相互作用:10万美元上限加上数据泄露、知识产权和保密的无上限赔偿,对于SaaS纠纷中实际出现的索赔而言,实际上相当于无上限。请列举上限之上的内容(例外项)、上限之下的内容(实际受限制的部分),并评估受限制部分是否有意义:“上限涵盖[一般合同违约]。数据泄露、知识产权赔偿和保密属于例外项且无上限。针对该供应商的风险特征,受限制部分[有意义/无实际意义]。”
-
每个维度的手册立场:实践档案应包含以下立场:直接损害上限(费用倍数)、间接损害(排除/上限/无上限)、例外列表(可接受的上限之上的内容)、上限基数(可接受的定义)。如果手册只有一个“标准立场”字段,请说明:“您的手册只有一个上限立场——考虑将其拆分为直接损害/间接损害/例外项/基数,以便进行更精确的审查。”
Jurisdiction delta check
管辖地差异检查
The playbook applies one governing-law preference globally. Enforceability varies materially. Check the SaaS contract's actual governing law against the top divergences before accepting playbook positions at face value:
- Non-solicits/non-competes: Unenforceable in CA (Bus. & Prof. Code §16600). Restricted in many EU jurisdictions. Enforceable with limitations elsewhere.
[jurisdiction — verify] - Auto-renewal: CA GBL §17600-17606, NY GBL §527-a, IL 815 ILCS 601 have specific consumer/B2B notice requirements. Other states vary.
[jurisdiction — verify] - Liability exclusions: EU and UK unfair contract terms rules (UCTA 1977, Consumer Rights Act 2015) constrain consumer exclusions. Some US states limit exclusion of gross negligence or willful misconduct.
[jurisdiction — verify] - Indemnification: Some states void indemnification for the indemnitee's own negligence.
[jurisdiction — verify] - Confidentiality term: Some jurisdictions limit "perpetual" confidentiality to a reasonable period.
[jurisdiction — verify]
When the playbook position conflicts with the contract's governing-law enforceability, flag: "Your playbook prefers [X], but this contract is governed by [Y] law where [X] is [unenforceable / restricted / subject to statutory override]. "
[jurisdiction — verify]手册在全球范围内适用一种准据法偏好,但可执行性差异很大。在接受手册立场之前,请检查SaaS合同的实际准据法与主要差异:
- 禁止招揽/竞业禁止:在加利福尼亚州不可执行(Bus. & Prof. Code §16600)。在许多欧盟管辖地受到限制。在其他地方有限制地可执行。
[jurisdiction — verify] - 自动续订:加利福尼亚州GBL §17600-17606、纽约州GBL §527-a、伊利诺伊州815 ILCS 601有特定的消费者/B2B通知要求。其他州各不相同。
[jurisdiction — verify] - 责任排除:欧盟和英国的不公平合同条款规则(UCTA 1977、消费者权利法2015)限制了消费者责任排除。部分美国州限制排除重大过失或故意不当行为的责任。
[jurisdiction — verify] - 赔偿:部分州会使赔偿方对受赔偿方自身过失的赔偿无效。
[jurisdiction — verify] - 保密条款:部分管辖地将“永久”保密限制在合理期限内。
[jurisdiction — verify]
当手册立场与合同准据法的可执行性冲突时,请标记:“您的手册偏好[X],但本协议受[Y]法律管辖,在该法律下[X]不可执行/受限制/受法规优先适用约束。”
[jurisdiction — verify]Redline granularity
修改粒度
Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.
Default to the smallest edit that achieves the playbook position:
- Replace a word before a phrase. ("twelve (12)" → "twenty-four (24)")
- Replace a phrase before a sentence. ("paid by the Buyer" → "paid and payable by the Buyer")
- Restructure a subclause before replacing the sentence. (Add "(a)" and "(b)" to split a compound condition.)
- Replace a sentence before replacing the clause.
- Only replace a whole clause when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: "We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta."
When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.
尽可能以最小粒度进行编辑。修改稿是谈判工件,而非重写。 wholesale条款替换意味着“我们否决了您的起草”——这具有攻击性,会迫使对方重新阅读整个条款,并丢弃其起草中合理的部分。精准修改——删除一个词、插入一个短语、重组一个子条款——意味着“我们有具体要求”,更易于阅读、理解和接受。
默认采用实现手册立场的最小编辑:
- 先替换单个词,再替换短语。(“twelve (12)” → “twenty-four (24)”)
- 先替换短语,再替换句子。(“paid by the Buyer” → “paid and payable by the Buyer”)
- 先重组子条款,再替换句子。(添加“(a)”和“(b)”拆分复合条件)
- 先替换句子,再替换条款。
- 仅当对方版本与您的立场相差甚远,精准修改比重新起草更难阅读时,才替换整个条款——此时请在传输说明中注明:“我们替换了§8.2而非标记修改,因为变更范围广泛。很高兴为您解释差异。”
如有疑问,选择更细粒度。收到精准修改稿的客户会相信您仔细阅读了内容。收到wholesale替换稿的客户会怀疑您是否阅读过。
Output
输出
Use the vendor-agreement-review memo structure, with a SaaS-specific section added after the standard playbook checks. The vendor-agreement-review memo already carries the privilege header.
Dual severity. Every SaaS-specific finding carries both axes (see CLAUDE.md ):
## Dual severity- Legal risk: 🔴 Critical | 🟠 High | 🟡 Medium | 🟢 Low
- Business friction: 🔴 Blocks deals | 🟠 Slows deals | 🟡 Confuses customers | 🟢 Invisible
Data-exit, auto-renewal, and price-escalation findings are the ones most likely to be 🟢 legal / 🔴 business — the clause is enforceable, but it's the reason a customer can't leave or a renewal surprises finance. Surface those at the business-friction severity, not the legal one.
markdown
undefined使用供应商协议审查备忘录结构,在标准手册检查后添加SaaS专项部分。供应商协议审查备忘录已包含保密页眉。
双重严重性:每个SaaS专项发现均包含两个维度(参见CLAUDE.md ):
## Dual severity- 法律风险:🔴 严重 | 🟠 高 | 🟡 中 | 🟢 低
- 业务摩擦:🔴 阻碍交易 | 🟠 延缓交易 | 🟡 混淆客户 | 🟢 无影响
数据退出、自动续订和价格上调的发现最可能属于🟢 法律风险 / 🔴 业务摩擦——条款可执行,但却是客户无法退出或续订超出财务预期的原因。请按业务摩擦严重性突出显示这些内容,而非法律风险。
markdown
undefinedBottom line
结论
[Can you sign / Need to fight for X first / Walk — one-sentence why]
[可以签署 / 需要先争取X / 放弃——一句话说明原因]
AI and machine learning rights
AI与机器学习权利
[The #1 emerging SaaS negotiation point. Flag: explicit ML training clauses, "service improvement" catch-alls, usage data definitions, output ownership, third-party AI subprocessors, opt-out vs opt-in. If the agreement is silent: "Silent on AI/ML training rights — request explicit prohibition or defined carve-out."]
[SaaS谈判中最热门的新兴点。标记:明确的ML培训条款、“服务改进”概括性条款、使用数据定义、输出所有权、第三方AI分包商、退出 vs 加入。如果协议未提及:“未提及AI/ML培训权利——要求明确禁止或定义例外条款。”]
SaaS-specific findings
SaaS专项发现
Auto-renewal
自动续订
Renewal date: [date]
Notice window: Cancel by [date] ([N] days before renewal)
Renewal price mechanism: [as written]
Playbook fit: [within position / deviation / not addressed]
Flag for renewal-tracker: [yes — and the record the tracker needs]
续订日期:[日期]
通知窗口:需在[日期]前取消(续订前[N]天)
续订价格机制:[原文内容]
手册匹配度:[符合立场 / 偏离 / 未涵盖]
标记给续订跟踪器:[是——并记录跟踪器所需信息]
Price escalation
价格上调
[findings against positions]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md[对照立场的发现]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdData exit
数据退出
[findings — this is the one the business owner should read]
[发现——业务负责人应阅读此部分]
SLA
SLA
[findings, or "Skipped — service is not business-critical per [stakeholder]"]
[发现,或“跳过——根据[利益相关方],该服务对业务非关键”]
Subprocessors
分包商
[findings against positions]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md[对照立场的发现]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdService changes
服务变更
[findings against positions]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdundefined[对照立场的发现]
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdundefinedHandoffs
移交
To renewal-tracker: When you find the renewal date and notice window, hand them off. The renewal-tracker register expects the following fields (see for the full schema):
skills/renewal-tracker/references/renewal-register.yamlyaml
counterparty: [name]
agreement: [title]
signed_date: [ISO date]
initial_term_end: [ISO date]
renewal_mechanism: [e.g., "auto-renew annual"]
notice_period_days: [integer]
cancel_by_effective: [ISO date — initial_term_end minus notice_period_days]
price_on_renewal: [mechanism as written]
annual_value: [integer, if stated]
business_owner: [email, if known]
clm_id: [id if available]
status: activeIf any field is not determinable from the contract or context, leave it out and note which fields were missing so the human can fill them in. , , and are especially likely to need human input.
clm_idannual_valuebusiness_ownerTo escalation-flagger: If any of the SaaS-specific checks hits the team's "never accept" or escalation-trigger list in , the escalation-flagger skill routes it.
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md移交至续订跟踪器:当您找到续订日期和通知窗口时,请将其移交。续订跟踪器注册表需要以下字段(完整架构参见):
skills/renewal-tracker/references/renewal-register.yamlyaml
counterparty: [名称]
agreement: [标题]
signed_date: [ISO日期]
initial_term_end: [ISO日期]
renewal_mechanism: [例如:“auto-renew annual”]
notice_period_days: [整数]
cancel_by_effective: [ISO日期——initial_term_end减去notice_period_days]
price_on_renewal: [原文机制]
annual_value: [整数(如有说明)]
business_owner: [电子邮件(如有)]
clm_id: [ID(如有)]
status: active如果任何字段无法从合同或上下文中确定,请留空并注明缺失的字段,以便人工补充。、和尤其可能需要人工输入。
clm_idannual_valuebusiness_owner移交至升级标记器:如果任何SaaS专项检查触发了中团队的“绝不接受”或升级触发列表,升级标记器技能将进行路由。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdA note on what to fight over
关于争议点的说明
SaaS vendors, especially large ones, negotiate their paper about as willingly as airlines negotiate ticket terms. Pick battles per the team's playbook — the section in should distinguish between terms the team will always push on, terms it fights over only for material deals, and terms it lets slide. If the playbook doesn't draw those lines, ask.
SaaS positions~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdCalibrate based on contract value and switching cost. A $5K/year tool with easy alternatives gets a lighter touch than a $500K/year platform we'll build on top of.
SaaS供应商,尤其是大型供应商,对其合同的意愿几乎与航空公司协商机票条款一样低。请根据团队手册选择争议点——中的部分应区分团队始终会争取的条款、仅针对重大交易争取的条款以及可以忽略的条款。如果手册未明确这些界限,请询问。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdSaaS positions根据合同价值和转换成本调整策略。每年5000美元且易于替代的工具应轻处理,而每年50万美元且我们将基于其构建的平台应重点关注。
Close with the next-steps decision tree
以下一步决策树结束
End with the next-steps decision tree per CLAUDE.md . Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
## Outputs根据CLAUDE.md 中的下一步决策树结束。根据本技能生成的内容自定义选项——五个默认分支(起草X、升级、获取更多事实、观察等待、其他)是起点,而非固定模板。决策树是输出内容,由律师选择。
## Outputs