Tag: Commercial Transactions

  • NDA Essentials, Part 1: The Provisions That Actually Get Negotiated

    NDA Essentials, Part 1: The Provisions That Actually Get Negotiated

    The non-disclosure agreement (“NDA”) is the contract most companies sign fastest and read least. It shows up early, it is short, someone calls it standard, and it gets signed so the real negotiation can start. Then, unless you have overriding confidentiality provisions in a later definitive agreement, it governs your business’s confidential information for the next three to five years.

    The takeaway: an NDA is a real contract with real teeth, and about nine provisions in it do all of the work. This discussion covers those nine common provisions at a high level, and each one gets its own post later in this series.

    NDAs come in one of two formats, unidirectional or bidirectional. While it is not unusual to have a vendor or customer provide you with their unidirectional NDA template, I recommend against using such a one-direction NDA unless your business will be disclosing absolutely no confidential information. NDAs in technology and SaaS deals tend to be mutual (bidirectional), as both sides disclose and both sides receive. Every position you take against the other side’s confidential information gets taken against yours, which is why you must stay aware of what restrictions and obligations you are placing on the other party as they are also being placed upon you.

    1. What Counts as Confidential Information

    Two drafting approaches, failing in opposite directions. A marking requirement protects only what is marked as confidential, which is clean on paper and problematic in practice, because people forget to mark a Slack message, a screen share, or a whiteboard photo as confidential. Conversely, a catch-all definition covers anything a reasonable person would understand to be confidential from its nature and the circumstances of disclosure, which protects the discloser and leaves the recipient with no reliable way to know what is restricted.

    2. The Exclusions

    Four carve-outs are standard: information already publicly available through no fault of the recipient, information the recipient already knew free of any duty, information from a third party free of any duty, and information independently developed without use of or reference to what was disclosed. The negotiation is rarely about whether these are present in the NDA. It is about which party carries the burden of proving one of the exclusions, and whether the words “or reference to” survive in the independent-development carve-out.

    Compelled disclosure is where I part company with a lot of forms. A subpoena or regulatory demand often gets drafted as a fifth exclusion, which strips the information of protection the moment a court asks for it. This topic belongs in its own provision as a permitted disclosure: prompt notice where notice is lawful, cooperation in seeking protective treatment, and no more disclosed than the law requires.

    3. The Permitted Purpose

    “Solely to evaluate a potential business relationship between the parties” is one line, and the entire use restriction hangs on it. Draft it too narrowly and your ordinary operations breach the agreement. Draft it too broadly and it’s near unenforceable and useless.

    This clause could matter more than the definition of confidential information and gets a fraction of the attention. The part that is missed by many people is that if the evaluation succeeds and the parties sign an MSA, an NDA limited to evaluating a potential relationship no longer authorizes use of that information to perform the contract. Either the MSA’s confidentiality provision takes over cleanly, or the NDA’s purpose has to cover performance under the later definitive agreement. You must understand the NDA does not exist in a vacuum. It must work with your other agreements. You don’t want conflicting provisions or gaps in coverage.

    4. Who Is Allowed to See Confidential Information

    A need-to-know standard applied to a defined group: employees, affiliates, officers, directors, advisors, contractors, sometimes financing sources. There are two common points of contention; whether affiliates are included and whether those recipients must be bound by written obligations at least as protective as the NDA.

    The provision that makes the rest enforceable is the one making the receiving party responsible for any breach by any party it has communicated your confidential information to, as if it had breached itself. Without it, your remedy could run against an individual contractor instead of the company that handed them the file.

    5. The Standard of Care

    The common standard is reasonable care, and in no event less than the care the recipient uses for its own confidential information of like importance. Both halves matter, because a company with weak internal security has a very low bar for its own information.

    There is a reason to care beyond the contract. State law tends to define trade secrets by the methods used to protect them from public disclosure. For example, information qualifies as a trade secret under the Oklahoma Uniform Trade Secrets Act only if it is “the subject of efforts that are reasonable under the circumstances to maintain its secrecy,” 78 Oklahoma Statutes § 86(4)(b). Your NDAs, and your actual practice under them, are much of what proves that element later. A confidentiality program that exists only in your contract file is not evidence of much.

    6. Two Time Components: Term and Duration

    These are different time components, and confusing them is one of the most common errors in short-form NDAs. The “term” dictates how long new disclosures are covered. The “duration” controls how long the recipient has to protect what was already disclosed. A two-year term with a three-to-five-year survival period is common.

    What commonly gets left out is the trade secret carve-out: obligations as to trade secrets continue for as long as the information remains a trade secret under applicable law. Without a specific trade secret carve-out, a fixed expiration date in your NDA reads as your own agreement that trade secret protection ends on a date certain, an awkward position to hold while arguing you made reasonable efforts to maintain secrecy.

    8. Remedies and Injunctive Relief

    Nearly every NDA states that breach will cause irreparable harm for which money damages are inadequate, and that the disclosing party may obtain injunctive relief without posting a bond. Keep the clause. But do not rely on it as some courts have ruled that where parties have contractually agreed that any breach would constitute irreparable harm, that stipulation without more is insufficient to support an irreparable harm finding. See Dominion Video Satellite, Inc. v. EchoStar Satellite Corp., 356 F.3d 1256 (10th Cir. 2004).

    The damages disclaimer is also worth your consideration. If your NDA waives indirect, incidental, and consequential damages, look hard at what is left, because loss from disclosure of confidential information is very often exactly the category just waived. Accept a broad waiver, lose your injunction, and you are holding an agreement with no effective remedy in it.

    9. The Residual Clause

    Most common in enterprise and SaaS forms, and the provision people are most likely to sign without reading. A residuals clause lets the receiving party use information retained in the unaided memory of individuals who had authorized access. In a technical evaluation, that covers a great deal.

    It is not automatically unacceptable, and it is sometimes necessary, since you cannot ask an engineer to forget an architecture. If you accept one, narrow it: unaided memory only, no intentional memorization, no license under any patent or copyright, no use to develop a competing product, and customer data, pricing, and source code excluded outright.

    Also Worth Thinking About

    • No license, no warranty as to accuracy or completeness, and no obligation to proceed with any transaction. Three sentences that keep an evaluation from turning into an implied deal.
    • The Defend Trade Secrets Act notice, 18 U.S.C. § 1833(b)(3), when the agreement is with an employee or an individual contractor. Omit it and you cannot recover exemplary damages or attorney fees under the DTSA against that person.
    • Governing law and venue, which decide how much the nine provisions above are actually worth to you.

    The Fastest Way to Get This Wrong

    Sign the counterparty’s form because it is only four pages. Length has nothing to do with risk here. Four pages that give away your permitted purpose, your remedies, and your residuals will cost you more than forty pages of a well-built MSA. Read your own template against these nine provisions and find out which side of each one you are on.

    Part 2 of this series will discuss the definition of confidential information: marking requirements, catch-all standards, the oral-disclosure follow-up nobody actually performs, and how to write a definition your own team can follow.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey to discuss your company’s specific confidentiality agreements.

  • MSA, SOW, or Both? Structuring SaaS Commercial Contracts Correctly

    MSA, SOW, or Both? Structuring SaaS Commercial Contracts Correctly

    Most SaaS companies eventually end up with some combination of a Master Services or Subscription Agreement (“MSA”) and a Statement of Work (“SOW”), often without ever deciding on purpose which document is supposed to do what. That usually happens by accident: an early customer needed a signed contract fast, so a single document covered everything, and each deal since has been a variation on that first one. It works until it doesn’t, usually right when a dispute or a new professional-services engagement exposes the gaps. Some companies call the SOW an Order Form or Commercial Agreement. Still others designate an SOW for professional services only and use a separate Order Form or Commercial Agreement for product purchases or subscriptions. For simplicity, this post uses “SOW” to refer to all of these documents, regardless of what your company calls them.

    What an MSA Actually Does

    The MSA is the overall governing document for the relationship. It sets the terms that should stay constant across every engagement with a given customer: limitation of liability, indemnification, intellectual property ownership and license grants, confidentiality, term and termination, and terms dictating how disputes get resolved. It also incorporates or references other supporting documents that carry the operational detail, typically a Data Processing Agreement (“DPA”) for personal data handling and a Service Level Agreement (“SLA”) for uptime and support commitments. Once an MSA is signed, it should not need to be renegotiated every time the relationship changes (i.e. additional services/products are added, or a subscription is renewed, etc.).

    What an SOW Actually Does

    The SOW carries the deal-specific detail: scope of work, deliverables, timeline, fees, and any engagement-specific assumptions or acceptance criteria. A well-drafted SOW does not restate liability caps, indemnification, or IP ownership; it incorporates the MSA by reference and leaves those terms where they belong. That separation is what lets a SaaS company add a new project, a new module, or a new phase of implementation without reopening the entire contract.

    When You Need Both

    If the product involves a recurring subscription plus periodic professional services, onboarding, custom integration work, implementation, or training, you need both documents. The MSA governs the relationship and the risk allocation; each SOW governs a discrete piece of work under that umbrella. This structure lets you sign a new SOW in days instead of weeks, because the terms that actually take time to negotiate are already settled.

    When a Single Order Form Is Enough

    Not every deal needs a freestanding SOW. A self-serve subscription with no custom implementation or professional services can often be handled with an MSA plus a short order form specifying the plan, term, and price. Reserve the full SOW structure for engagements that involve actual scoped work, deliverables, or a project timeline.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring problems show up again and again:

    1. An SOW that includes its own liability or indemnification language that conflicts with the MSA, creating ambiguity about which terms actually control.
    2. An SOW signed for an early pilot or proof of concept with no MSA in place at all, so there is no governing framework once the relationship expands.
    3. No order-of-precedence clause specifying which document controls if the MSA and an SOW conflict, which turns a drafting oversight into a battle of contracts with no clearly stated winner. Most well-drafted MSAs default to the MSA controlling unless the SOW expressly says otherwise, so state that default in your own template rather than leaving it for a judge to decide.

    A Note on Execution

    All 50 states are covered by the federal ESIGN Act, and each state also has its own laws recognizing electronic signatures and records as legally effective, so executing MSAs and SOWs through AdobeSign, DocuSign or a similar platform is enforceable. However, that is not a substitute for good contract structure. A clean order-of-precedence clause and clear incorporation-by-reference language matter regardless of how the documents get signed.

    A Practical Starting Point

    Review your current templates for three things: a clear order-of-precedence clause, proper incorporation of the DPA and SLA by reference rather than restating their terms, and a standard SOW template that pulls its liability and IP terms from the MSA rather than reinventing them each time. Getting this structure right once saves renegotiation on every deal after.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific contract structure.