Photo by Tara Winstead from Pexels

Every time you sign up for a new B2B SaaS tool, you agree to two documents that quietly shape what happens to your data and what you are allowed to do on the platform: the privacy policy (often governed by GDPR) and the acceptable use policy (AUP). Most buyers scroll past both. That is a mistake, because a single clause buried in either document can expose your company to fines, account termination, or data you cannot get back.

TL;DR

  • GDPR obligations do not disappear just because you are a business buyer, every SaaS vendor that processes personal data of EU residents must comply, and so must you as a data controller.
  • Acceptable use policies define what you can and cannot do on a platform; violations can lead to instant suspension with no refund.
  • The two documents overlap in areas like data scraping, automated access, and user-generated content, read them together, not separately.
  • Look for red flags such as unlimited data-retention rights, vague "sole discretion" termination clauses, and missing Data Processing Agreements (DPAs).
  • Tools like the free Terms Doctor extension can scan both documents in seconds, flag risky clauses, and grade them A-F so you know where you stand before you pay.
0
Consumer-protection checks in Terms Doctor

Why GDPR still matters when you buy SaaS (not just when you sell it)

lawyer reviewing contract
Photo by Mikhail Nilov from Pexels

Many SaaS buyers assume GDPR is the vendor's problem. In reality, the regulation creates a chain of responsibility. When your team uploads customer email addresses into a project-management tool, your company is the data controller and the SaaS vendor is the data processor. Under Articles 28 and 29 of the GDPR, you must ensure the processor handles that data lawfully, and you need a signed Data Processing Agreement to prove it.

Here is what that means in practice:

  1. You must verify the vendor's legal basis for processing. If the privacy policy says "legitimate interest" but the tool collects far more data than the service requires, that basis may not hold up under scrutiny.
  2. You are responsible for data-subject requests. When a customer asks you to delete their data, you need to know whether the SaaS tool actually purges records or merely archives them.
  3. Cross-border transfers need a mechanism. If the vendor stores data in the US, look for Standard Contractual Clauses (SCCs) or an adequacy decision reference in the privacy policy.
  4. Breach notification flows through you. The vendor must notify you "without undue delay" (Article 33), but if the privacy policy is silent on breach timelines, you have a gap.
B2B SaaS vendors that mention a DPA in their terms
0%

Roughly a third of B2B SaaS vendors still do not prominently link a DPA from their terms of service page. If you cannot find one, ask for it before you sign. No DPA means no documented proof that the vendor will handle personal data according to GDPR requirements, and that gap falls on you as the controller.

Key takeaway: As a SaaS buyer, you share GDPR accountability with every vendor that touches personal data on your behalf, ignorance of their privacy policy is not a defence.

What an acceptable use policy actually controls

business compliance meeting
Photo by Sora Shimazaki from Pexels

An acceptable use policy is the vendor's rulebook for behaviour on their platform. It typically covers:

  • Prohibited content, hate speech, malware, copyrighted material uploaded without permission.
  • Usage limits, API call caps, storage quotas, fair-use bandwidth thresholds.
  • Automated access, whether bots, scrapers, or scripts are allowed (often they are not).
  • Account sharing, whether a single licence can be used by multiple team members.
  • Reverse engineering, almost universally banned, but the scope varies.
The danger is in the enforcement language. Many AUPs grant the vendor "sole discretion" to suspend or terminate your account for any violation, real or perceived, without prior notice and without a refund. If your entire team relies on that tool, a sudden lockout can halt operations.

Red flags to watch for in an AUP

  • No cure period. A fair AUP gives you a window (often 30 days) to fix a violation before termination. If the policy says "immediate termination," you have zero safety net.
  • Broad intellectual-property claims. Some AUPs state that any content you upload becomes available for the vendor to use for "service improvement," which can include AI model training.
  • Vague prohibited-use categories. Phrases like "any activity we deem harmful" give the vendor unlimited interpretive power.
  • No appeal process. If there is no way to contest a suspension, you are at the mercy of an automated system or a single support agent.
"Most SaaS platforms integrate with external services, such as payment processors, CRMs, or analytics providers."
>, Privacy Policy for a SaaS Business: How To Create One

This integration web means that an AUP violation on one platform can cascade. If your payment processor flags your account because the SaaS vendor reported a policy breach, you may lose access to billing infrastructure across multiple tools.

Where GDPR and the AUP overlap

person reading legal document laptop
Photo by https://kaboompics.com/ from Pexels

These two documents are not isolated silos. Several clauses sit at the intersection of data protection law and platform rules:

TopicGDPR angleAUP angle
Data scrapingProcessing personal data without a lawful basisViolates automated-access restrictions
User-generated contentMay contain personal data of third partiesMust comply with content guidelines
Data retentionMust be limited to what is necessaryVendor may retain data "indefinitely" for abuse prevention
Sub-processorsMust be disclosed and contractually boundAUP may forbid you from auditing sub-processor use
AI training on your dataRequires explicit consent or legitimate interestAUP may grant a broad licence to "improve services"
Reading the privacy policy without the AUP, or vice versa, gives you an incomplete picture. A vendor's privacy policy might promise GDPR compliance, but the AUP could quietly grant them rights that undermine those promises (for example, using uploaded data to train machine-learning models under a "service improvement" clause).

Step-by-step: how to review both documents before you buy

GDPR and Acceptable use policy: compliance notes for B2B SaaS process
Figure 1: GDPR and Acceptable use policy: compliance notes for B2B SaaS at a glance.

Follow this process every time you evaluate a new B2B SaaS tool:

  1. Find the documents. Look for links labelled "Terms of Service," "Privacy Policy," "Acceptable Use Policy," and "Data Processing Agreement" in the website footer. If any are missing, that is already a red flag.
  2. Run an automated scan. Install the free Terms Doctor extension and visit the vendor's site. The extension automatically locates the terms page, runs 101 consumer-protection checks, and assigns an A-F grade. Pay attention to any red-flag highlights around data retention, arbitration, and content licensing.
  3. Check the DPA. Open the Data Processing Agreement (or request one). Confirm it names the specific sub-processors, specifies data-transfer mechanisms for cross-border flows, and includes breach-notification timelines.
  4. Read the AUP enforcement section. Search for words like "sole discretion," "immediate," "without notice," and "no refund." These phrases signal high-risk termination clauses.
  5. Map data flows. List every type of personal data your team will put into the tool (customer emails, employee names, IP addresses). Cross-reference with the privacy policy's stated purposes and retention periods.
  6. Negotiate before you sign. Enterprise plans often allow you to redline specific clauses. Even on self-serve plans, emailing the vendor's legal team with specific concerns sometimes yields written clarifications that function as side letters.
  7. Set a review calendar. Terms change. Use Terms Doctor's change-tracking feature to get notified when the vendor updates their policies, so you are never caught off guard.

B2B SaaS GDPR & AUP Compliance Checklist

Your progress is saved automatically in your browser.

Common mistakes buyers make

Even experienced SaaS buyers fall into these traps:

  • Assuming SOC 2 equals GDPR compliance. SOC 2 is a security framework, not a data-protection regulation. A vendor can be SOC 2 certified and still lack a valid DPA or lawful transfer mechanism.
  • Ignoring the AUP because "we are a normal company." AUPs are enforced by automated systems. A spike in API calls during a data migration can trigger a bot-detection rule and lock your account.
  • Relying on the vendor's marketing page instead of the actual policy. Marketing pages say "GDPR compliant" in bold. The privacy policy may tell a different story, for example, retaining anonymised data indefinitely or sharing aggregated data with advertising partners.
  • Not checking sub-processor lists. Your vendor may be compliant, but their sub-processor in a non-adequate jurisdiction may not be. Under GDPR, the chain of responsibility extends to every entity that touches the data.
Quick test: Search the vendor's privacy policy for the phrase "legitimate interest." If it appears more than three times without specific justification for each use, the vendor may be over-relying on this legal basis, a common GDPR weak spot that Terms Doctor flags automatically.

How Terms Doctor helps you stay compliant

You do not need to be a lawyer to catch the worst clauses. The free Terms Doctor browser extension, available for Chrome, Edge, Brave, Opera, and Vivaldi, does the heavy lifting:

  • Automatic ToS discovery: visit any SaaS website and the extension finds the terms page for you.
  • 101 consumer-protection checks: from forced arbitration and auto-renewal traps to AI-training clauses and data-retention red flags.
  • A-F grading: a single letter grade tells you at a glance whether the terms are buyer-friendly or full of hidden risks.
  • Change tracking: get alerted when a vendor quietly updates their policies so you can re-evaluate before the new terms take effect.
Install it once, and every SaaS purchase decision gets a built-in compliance sanity check. Remember, automated checks are not legal advice, but they are an excellent first filter before you involve your legal team.

Frequently Asked Questions

If the tool processes any personal data of EU residents on your behalf, yes. Under GDPR Article 28, a Data Processing Agreement must be in place between the controller (you) and the processor (the vendor). This applies even to tools that seem low-risk, like analytics dashboards or email-scheduling apps, if they handle names, email addresses, or IP addresses.
It depends on the AUP's enforcement language. Many vendors reserve the right to suspend or terminate accounts "at sole discretion" and "without prior notice." Fairer policies include a cure period, typically 15 to 30 days, during which you can fix the violation. Always check for this before committing to a paid plan.
Yes. GDPR applies to any organisation that processes personal data of individuals located in the EU, regardless of where the organisation itself is based (Article 3). If you use a SaaS tool to manage EU customer data, both you and the vendor must comply.
There is no fixed schedule, but major vendors update their terms one to four times per year. Changes often coincide with new feature launches, regulatory shifts, or acquisitions. Using Terms Doctor's change-tracking feature ensures you are notified promptly so you can review updates before they take effect.
No. The A-F grade is an automated assessment based on 101 consumer-protection checks. It highlights potential red flags and gives you a quick overview of how buyer-friendly a set of terms is. For binding legal decisions, especially around GDPR compliance, consult a qualified attorney who can review the specific context of your data processing activities.

Additional Resources