Photo by Tara Winstead from Pexels
Every time you sign up for a new B2B SaaS tool, you agree to two documents that quietly shape what happens to your data and what you are allowed to do on the platform: the privacy policy (often governed by GDPR) and the acceptable use policy (AUP). Most buyers scroll past both. That is a mistake, because a single clause buried in either document can expose your company to fines, account termination, or data you cannot get back.
TL;DR
- GDPR obligations do not disappear just because you are a business buyer, every SaaS vendor that processes personal data of EU residents must comply, and so must you as a data controller.
- Acceptable use policies define what you can and cannot do on a platform; violations can lead to instant suspension with no refund.
- The two documents overlap in areas like data scraping, automated access, and user-generated content, read them together, not separately.
- Look for red flags such as unlimited data-retention rights, vague "sole discretion" termination clauses, and missing Data Processing Agreements (DPAs).
- Tools like the free Terms Doctor extension can scan both documents in seconds, flag risky clauses, and grade them A-F so you know where you stand before you pay.
Why GDPR still matters when you buy SaaS (not just when you sell it)
Many SaaS buyers assume GDPR is the vendor's problem. In reality, the regulation creates a chain of responsibility. When your team uploads customer email addresses into a project-management tool, your company is the data controller and the SaaS vendor is the data processor. Under Articles 28 and 29 of the GDPR, you must ensure the processor handles that data lawfully, and you need a signed Data Processing Agreement to prove it.
Here is what that means in practice:
- You must verify the vendor's legal basis for processing. If the privacy policy says "legitimate interest" but the tool collects far more data than the service requires, that basis may not hold up under scrutiny.
- You are responsible for data-subject requests. When a customer asks you to delete their data, you need to know whether the SaaS tool actually purges records or merely archives them.
- Cross-border transfers need a mechanism. If the vendor stores data in the US, look for Standard Contractual Clauses (SCCs) or an adequacy decision reference in the privacy policy.
- Breach notification flows through you. The vendor must notify you "without undue delay" (Article 33), but if the privacy policy is silent on breach timelines, you have a gap.
Roughly a third of B2B SaaS vendors still do not prominently link a DPA from their terms of service page. If you cannot find one, ask for it before you sign. No DPA means no documented proof that the vendor will handle personal data according to GDPR requirements, and that gap falls on you as the controller.
Key takeaway: As a SaaS buyer, you share GDPR accountability with every vendor that touches personal data on your behalf, ignorance of their privacy policy is not a defence.
What an acceptable use policy actually controls
An acceptable use policy is the vendor's rulebook for behaviour on their platform. It typically covers:
- Prohibited content, hate speech, malware, copyrighted material uploaded without permission.
- Usage limits, API call caps, storage quotas, fair-use bandwidth thresholds.
- Automated access, whether bots, scrapers, or scripts are allowed (often they are not).
- Account sharing, whether a single licence can be used by multiple team members.
- Reverse engineering, almost universally banned, but the scope varies.
Red flags to watch for in an AUP
- No cure period. A fair AUP gives you a window (often 30 days) to fix a violation before termination. If the policy says "immediate termination," you have zero safety net.
- Broad intellectual-property claims. Some AUPs state that any content you upload becomes available for the vendor to use for "service improvement," which can include AI model training.
- Vague prohibited-use categories. Phrases like "any activity we deem harmful" give the vendor unlimited interpretive power.
- No appeal process. If there is no way to contest a suspension, you are at the mercy of an automated system or a single support agent.
"Most SaaS platforms integrate with external services, such as payment processors, CRMs, or analytics providers.">, Privacy Policy for a SaaS Business: How To Create One
This integration web means that an AUP violation on one platform can cascade. If your payment processor flags your account because the SaaS vendor reported a policy breach, you may lose access to billing infrastructure across multiple tools.
Where GDPR and the AUP overlap
These two documents are not isolated silos. Several clauses sit at the intersection of data protection law and platform rules:
| Topic | GDPR angle | AUP angle |
|---|---|---|
| Data scraping | Processing personal data without a lawful basis | Violates automated-access restrictions |
| User-generated content | May contain personal data of third parties | Must comply with content guidelines |
| Data retention | Must be limited to what is necessary | Vendor may retain data "indefinitely" for abuse prevention |
| Sub-processors | Must be disclosed and contractually bound | AUP may forbid you from auditing sub-processor use |
| AI training on your data | Requires explicit consent or legitimate interest | AUP may grant a broad licence to "improve services" |
Step-by-step: how to review both documents before you buy
Follow this process every time you evaluate a new B2B SaaS tool:
- Find the documents. Look for links labelled "Terms of Service," "Privacy Policy," "Acceptable Use Policy," and "Data Processing Agreement" in the website footer. If any are missing, that is already a red flag.
- Run an automated scan. Install the free Terms Doctor extension and visit the vendor's site. The extension automatically locates the terms page, runs 101 consumer-protection checks, and assigns an A-F grade. Pay attention to any red-flag highlights around data retention, arbitration, and content licensing.
- Check the DPA. Open the Data Processing Agreement (or request one). Confirm it names the specific sub-processors, specifies data-transfer mechanisms for cross-border flows, and includes breach-notification timelines.
- Read the AUP enforcement section. Search for words like "sole discretion," "immediate," "without notice," and "no refund." These phrases signal high-risk termination clauses.
- Map data flows. List every type of personal data your team will put into the tool (customer emails, employee names, IP addresses). Cross-reference with the privacy policy's stated purposes and retention periods.
- Negotiate before you sign. Enterprise plans often allow you to redline specific clauses. Even on self-serve plans, emailing the vendor's legal team with specific concerns sometimes yields written clarifications that function as side letters.
- Set a review calendar. Terms change. Use Terms Doctor's change-tracking feature to get notified when the vendor updates their policies, so you are never caught off guard.
B2B SaaS GDPR & AUP Compliance Checklist
Your progress is saved automatically in your browser.
Common mistakes buyers make
Even experienced SaaS buyers fall into these traps:
- Assuming SOC 2 equals GDPR compliance. SOC 2 is a security framework, not a data-protection regulation. A vendor can be SOC 2 certified and still lack a valid DPA or lawful transfer mechanism.
- Ignoring the AUP because "we are a normal company." AUPs are enforced by automated systems. A spike in API calls during a data migration can trigger a bot-detection rule and lock your account.
- Relying on the vendor's marketing page instead of the actual policy. Marketing pages say "GDPR compliant" in bold. The privacy policy may tell a different story, for example, retaining anonymised data indefinitely or sharing aggregated data with advertising partners.
- Not checking sub-processor lists. Your vendor may be compliant, but their sub-processor in a non-adequate jurisdiction may not be. Under GDPR, the chain of responsibility extends to every entity that touches the data.
How Terms Doctor helps you stay compliant
You do not need to be a lawyer to catch the worst clauses. The free Terms Doctor browser extension, available for Chrome, Edge, Brave, Opera, and Vivaldi, does the heavy lifting:
- Automatic ToS discovery: visit any SaaS website and the extension finds the terms page for you.
- 101 consumer-protection checks: from forced arbitration and auto-renewal traps to AI-training clauses and data-retention red flags.
- A-F grading: a single letter grade tells you at a glance whether the terms are buyer-friendly or full of hidden risks.
- Change tracking: get alerted when a vendor quietly updates their policies so you can re-evaluate before the new terms take effect.
Frequently Asked Questions
Additional Resources
- Privacy Policy for a SaaS Business: How To Create One - Laws like GDPR and CCPA require clear, accessible policies. A policy builds trust, protects reputation, and enables third-party integrations.
- GDPR for SaaS Companies | Complete Compliance Guide - This page provides a full GDPR compliance blueprint for SaaS providers, including data mapping, user rights, DPIAs, consent, international transfers, logging,
- A Plain English Guide to GDPR & Data Privacy For SaaS ... - This is a primer on GDPR compliance (General Data Protection Regulation). I will cover some definitions, practical considerations, and ...
