Contracts & IP · August 20, 2026 · Ruby Team

The Commercial Contracts a Canadian SaaS Company Actually Needs

Key takeaways: What a SaaS company needs shifts hard at two points — the first paying customer, and the first enterprise customer who wants to negotiate. Most founders sign up for the second stage's paperwork years before they need it, or launch without the first stage's at all.

A pre-revenue SaaS product and one selling five-figure annual contracts to enterprise buyers are, legally, two different businesses. The contracts below map to the stage you're actually at, not the stage you're building toward.

Before your first customer

  • Terms of Service. Governs every user of the product from day one — acceptable use, account termination, liability limits. This is the baseline, not optional even pre-revenue.
  • Privacy Policy. Required under PIPEDA the moment you collect any personal information, including just an email address at signup.
  • Cookie Policy. Covers analytics, session cookies, and any tracking on the marketing site or the app itself.

Once you have paying customers

  • SaaS Agreement. The core contract for a subscription product: billing terms, uptime expectations, data handling, liability caps, and what happens on cancellation. Distinct from the public Terms of Service in that it's the version signed directly with paying business customers, not accepted by a checkbox.

Once an enterprise customer wants to negotiate

  • Master Services Agreement (MSA). Larger customers often won't sign your standard SaaS Agreement as-is — an MSA gives you a negotiable version of the same terms without rewriting your core contract for every enterprise deal.
  • Service Level Agreement (SLA). A measurable uptime and support commitment, usually required before a buyer's procurement or legal team will approve you as a vendor.
  • Data Processing Agreement (DPA). Required whenever the product processes a customer's end-user data — the customer stays accountable for that data under PIPEDA, and the DPA is how your security and breach-notification obligations to them get documented.

What this costs at Ruby

All of the above are flat-fee commercial contracts, reviewed by a licensed Canadian lawyer: Terms of Service and Privacy Policy are each $499, Cookie Policy is $299, and a SaaS Agreement, MSA, SLA or DPA are each $799.

For a closer look at how the MSA, SLA and DPA specifically fit together, see MSA, SOW, or SLA? The commercial contracts Canadian SaaS businesses actually need.

This article is general information about commercial contracts for SaaS businesses and is not legal advice for your specific situation. Contact us to talk through your contracts.

Ready to put this into practice?

Tell us about your matter and a Ruby lawyer will follow up directly.

Ask Ruby