What a software company owes its customers
The contracts, privacy laws, AI rules and security duties that apply to a SaaS company selling to businesses in the US and Europe, explained in plain English, with how Falrow meets each one.
Reviewed 6 October 2026
This guide explains the law in general terms so you can ask better questions. It is not legal advice for your situation, and laws change: the date above is when we last checked it. Questions about how Falrow applies it: bas@falrow.com.
1.The documents every software company needs
A business selling software as a service (SaaS) does not need a single licence to operate. What it needs is a set of documents that each answer to a specific law or a specific customer expectation. Missing one rarely stops a sale on day one; it stops the sale when a customer's procurement or security team asks for it, or it becomes the thing a regulator points at after a complaint.
| Document | Why you need it | Driven by | Ours |
|---|---|---|---|
| Terms of Service (or Master Agreement) | Sets the commercial deal: what the customer gets, what they may not do, who owns what, the liability cap, and which law governs. | Contract law; without it, courts fill gaps with defaults that rarely favour either side | Terms of Service |
| Data Processing Addendum (DPA) | A contract the law requires whenever you process personal data for a customer. Enterprise buyers will not sign without one. | GDPR Art. 28; UK GDPR; CCPA regulations § 7051; Virginia, Colorado, Connecticut and other state laws | DPA |
| Privacy Policy | Tells people what you collect about them as a company, why, for how long, and their rights. | GDPR Art. 13–14; CCPA; CalOPPA; other state laws; FTC Act § 5 | Privacy Policy |
| Subprocessor list | Customers must be able to see and object to the vendors who touch their data. | GDPR Art. 28(2) and (4); CCPA § 7051(b) | Subprocessors |
| Security measures (TOMs) | Annex II of the EU transfer clauses must describe your technical and organisational measures in specific terms. | GDPR Art. 32; SCCs Annex II; state reasonable-security laws | Security |
| Acceptable Use Policy | Lets you act against abuse without arguing about whether the Terms covered it. | Contract law; DSA Art. 14 (terms must describe content restrictions) | Acceptable Use |
| Cookie notice | Explains device storage and, if anything is non-essential, collects consent before it is set. | ePrivacy Directive Art. 5(3); UK PECR | Cookie Notice |
| AI terms | Clarify who owns output, who is responsible for checking it, and whether customer data trains models: the first three questions every buyer asks now. | EU AI Act Art. 4 and 50; customer procurement | AI & Agent Terms |
| Switching and export information | EU customers have a statutory right to leave and take their data with them. | EU Data Act Chapter VI (Art. 23–31) | Switching & Data Export |
| Legal notices | Company identity, a contact point for authorities, and how to report illegal content or copyright claims. | EU DSA Art. 11–12 and 16; US DMCA § 512 | Legal Notices |
An uptime commitment (SLA) is the one common document Falrow does not publish yet. During a private beta, promising an uptime figure we cannot yet measure would be dishonest. It will arrive with general availability.
2.Controller or processor: the question everything else depends on
Privacy law gives different jobs to the party that decides why personal data is used (the controller, or "business" in California) and the party that handles it on someone else's behalf (the processor, or "service provider"). A SaaS company is both, for different data:
- For the content customers put in the product, such as tickets, client records and meeting notes, the customer is the controller and the software company is its processor. The customer decides what goes in; the provider may use it only to run the service. That relationship is what the DPA governs.
- For its own website visitors, sign-up forms, user accounts, security logs and invoices, the software company is the controller. That is what its Privacy Policy covers.
Getting this split right matters. A provider that uses customer content for its own purposes, for example to train a model or to market to the people in it, stops being a processor for that use and takes on all of a controller's duties, usually without a legal basis to do so. That is why our Terms and DPA say plainly that we do neither.
3.GDPR: why a Delaware company follows European law
The EU General Data Protection Regulation applies to a company outside the EU when it offers services to people in the EU (Article 3(2)). A US software company with European customers, or even European users inside a US customer's workspace, is in scope. The UK has a near-identical UK GDPR, and Switzerland its own FADP.
What it requires of a SaaS provider, in practice:
- A legal basis for each use of personal data. For a business tool these are mostly contract and legitimate interests, not consent.
- Transparency (Art. 13–14): a privacy notice that says what, why, how long, who receives it, transfers, and rights.
- Processor contracts (Art. 28) with the content the law lists: instructions, confidentiality, security, subprocessor rules, assistance, deletion, audits.
- Security appropriate to the risk (Art. 32), and breach notification to the authority within 72 hours, and to affected people when the risk is high (Art. 33–34). A processor must tell its customer without undue delay so the customer can meet that 72-hour clock.
- Records of processing (Art. 30), and impact assessments for high-risk processing (Art. 35).
- Data subject rights: access, correction, deletion, portability, objection, generally within one month.
- A representative in the EU (Art. 27) for non-EU companies, unless processing is only occasional and low risk.
Fines reach €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious breaches, and €10 million or 2% for breaches of processor and security duties.
4.Moving data out of Europe
Personal data may leave the EU only to a country the European Commission has found adequate, or with safeguards. The United States has a partial adequacy decision, the EU-US Data Privacy Framework, which covers only US companies that self-certify to it. Everyone else uses the Standard Contractual Clauses (SCCs): a fixed text the Commission adopted in 2021, which the parties may not change but must complete with annexes describing the transfer, the security measures and the subprocessors.
The UK uses an addendum to the same clauses (the IDTA Addendum), and Switzerland accepts the SCCs with small adaptations. Exporters must also assess whether the destination country's laws, especially on government access, would undermine the clauses, and add measures where needed.
How Falrow handles it: workspace data is hosted in the EU, so most processing never leaves it. Where data does reach the US (AI requests, email delivery, support access), our DPA incorporates the SCCs, the UK Addendum and the Swiss terms, so a customer needs no separate signature.
5.US privacy law: a patchwork of states
There is no general federal privacy law in the United States. Instead:
- California's CCPA (as amended by the CPRA) applies to for-profit businesses that do business in California and meet one threshold: annual revenue above about US$26.6 million (adjusted for inflation every two years), buying, selling or sharing the data of 100,000 or more California residents or households, or earning half their revenue from selling or sharing personal information. It gives residents rights to know, delete, correct and opt out, and it reaches business contacts and employees, not only consumers.
- About twenty other states, including Virginia, Colorado, Connecticut, Texas, Oregon and New Jersey, have comprehensive privacy laws with similar rights and thresholds based mostly on the number of residents whose data is processed. Delaware's own Personal Data Privacy Act took effect on 1 January 2025 and applies at 35,000 Delaware residents.
- Service provider contracts. Even when a software company is below the thresholds, its customers often are not, and the law requires them to have specific contract terms with their vendors. California's regulations list ten. A SaaS company that cannot offer these terms loses those customers. Our DPA includes all of them.
- The FTC Act. The Federal Trade Commission treats a broken privacy or security promise as a deceptive practice. That is the strongest reason to say only what is true in a privacy policy, and to keep it current.
- Breach notification. All fifty states require notice to affected residents after a breach of certain personal data, with deadlines that range from "without unreasonable delay" to 30 days.
- Children. COPPA applies to services directed at children under 13. Business software should say it is not for children, and mean it.
Spring Digital Commerce LLC is currently below the CCPA and Delaware thresholds. We follow the same rules anyway: our customers need us to, and it is cheaper to build it in from the start than to retrofit it.
6.The EU AI Act
The AI Act regulates AI systems by risk, and like the GDPR it applies to non-EU companies whose AI systems are used in the EU. It is arriving in stages:
| Date | What applies |
|---|---|
| 2 February 2025 | Bans on prohibited practices (Art. 5), such as social scoring and emotion recognition at work. AI literacy duty (Art. 4): staff who operate AI must understand it. |
| 2 August 2025 | Duties for providers of general-purpose AI models, such as the companies behind Claude or GPT. |
| 2 August 2026 | Transparency duties (Art. 50): tell people when they interact with an AI system, mark AI-generated content, and disclose deepfakes and AI text published on matters of public interest. Systems already on the market have until 2 December 2026 for machine-readable marking. |
| December 2027 / August 2028 | High-risk system duties, postponed by the 2026 Digital Omnibus agreement from their original August 2026 date. |
Provider or deployer? The company that builds an AI system and puts it on the market is its provider; the business that uses it is a deployer. A SaaS company that builds AI features into its product is the provider of those features. A customer that uses them, for example to write summaries it sends to its own clients, is a deployer, with its own (lighter) duties.
Where Falrow sits. Its AI features help plan software work: they are not in any high-risk category, use no prohibited practice, and interact with people inside a business tool. The duties that apply are AI literacy and Article 50 transparency, which we meet by labelling AI-detected requests, marking agent changes by the door they came through, and requiring a person to act on AI proposals before they become work. The AI & Agent Terms set this out.
Fines reach €35 million or 7% of worldwide turnover for prohibited practices and €15 million or 3% for most other breaches.
7.The EU Data Act: the right to leave
Since 12 September 2025, Chapter VI of the EU Data Act requires providers of "data processing services", which includes SaaS, to remove obstacles to customers switching to another provider or to their own infrastructure. It applies to non-EU providers with EU customers, and it overrides contract terms that say otherwise.
- The contract must let the customer switch at any time with no more than two months' notice, followed by a transition of up to 30 days (extendable once by the customer) during which the service continues.
- It must list exhaustively which data can be exported and which internal data is excluded, give at least 30 days to retrieve data afterwards, and guarantee erasure once the switch is done.
- The provider must publish its export formats and interfaces, offer open interfaces free of charge, and tell customers where its infrastructure is and how it protects data against unlawful government access (Art. 28 and 32).
- Switching charges may cover only direct costs until 12 January 2027, and are prohibited from then on.
In practice this ends long lock-in contracts for EU customers. Our Switching & Data Export page is the published information the Act requires, and our Terms give every customer, not only EU ones, the right to leave on those terms.
8.The Digital Services Act
The DSA regulates "intermediary services", which includes hosting services that store content at a user's request. A SaaS product that stores customer content is a hosting service in the legal sense, even when nothing is public. Since 17 February 2024 every hosting service with EU users must:
- name a single point of contact for authorities and for users (Art. 11–12);
- if it has no EU establishment, appoint a legal representative in the EU (Art. 13);
- describe in its terms any restrictions on content and how they are enforced (Art. 14);
- offer a notice-and-action mechanism for reporting illegal content (Art. 16); and
- give a statement of reasons when it restricts a user's content or account (Art. 17).
The heavier duties, such as transparency reports and complaint systems, apply to online platforms that disseminate content to the public, and small companies are exempt from most of them. Falrow's Legal Notices and Acceptable Use Policy cover the duties above.
10.Security duties and incident reporting
No single law prescribes a software company's security controls, but many require "appropriate" or "reasonable" security and then judge it after an incident: GDPR Article 32, California's reasonable-security statute (Civ. Code § 1798.81.5), New York's SHIELD Act and the FTC's enforcement practice. Enterprise customers translate the same expectation into questionnaires and, later, requests for SOC 2 or ISO 27001 reports.
Two EU laws often come up and mostly do not apply to a small SaaS company. NIS2 covers medium and large entities in listed sectors. The Cyber Resilience Act covers products with digital elements, such as installable software and connected devices; pure SaaS is outside it unless it is the remote processing component of such a product.
What matters most in practice: encrypt in transit and at rest, control and log access, keep backups you have actually restored, have an incident plan, and notify customers fast enough that they can meet their own 72-hour GDPR deadline. Our commitments are on the Security page.
11.Other rules worth knowing
- Accessibility. The European Accessibility Act (from 28 June 2025) covers consumer-facing services such as e-commerce and banking; business-to-business software is largely outside it, and microenterprises are exempt. In the US, websites are regularly the subject of lawsuits under the Americans with Disabilities Act. Building to WCAG 2.2 AA is the practical standard either way.
- Business customers only. Selling only to businesses keeps a SaaS company outside most consumer protection law: the EU 14-day withdrawal right, consumer auto-renewal statutes and unfair-terms rules for consumer contracts. That only holds if the terms and the sign-up flow make clear the service is for business use.
- Copyright. To rely on the DMCA safe harbour, a US provider must designate an agent with the US Copyright Office (renewed every three years) and act on valid notices.
- Export controls and sanctions. US law restricts providing services to sanctioned countries and listed persons. Terms should prohibit it and sign-up should not knowingly allow it.
- Marketing email. CAN-SPAM governs commercial email in the US (an opt-out and a postal address in every message); in the EU and UK, marketing email to individuals generally needs consent. Transactional email, such as invitations and security notices, is exempt from both.
- Taxes. US states tax SaaS differently, and remote sellers can owe sales tax once they pass a state's economic nexus threshold. EU VAT on business-to-business services is usually handled by reverse charge.
- Recording calls. Many US states, including California, require every participant's consent to record a conversation. A product that imports call recordings or transcripts should make its customers responsible for that consent, and remind them of it.
12.What this means for you as a Falrow customer
For the data you put into Falrow, you are the controller. These are the things the law expects of you that Falrow cannot do for you:
- Tell your team that Falrow is used, including that Slack messages in connected channels are read to find requests, and link them to our Privacy Policy for their account data.
- Get recording consent before importing meeting recordings or notetaker transcripts, where the law requires it.
- Check your client contracts allow you to use service providers like us for their information, and list Falrow among your own subprocessors if you have such a list.
- Keep out data Falrow is not built for: health data, payment card numbers, government ID numbers and other special categories.
- Review AI output before it becomes a commitment, and disclose AI-written text where Article 50 of the AI Act requires it of you as a deployer.
- Manage access: remove people who leave, give agents the narrowest scope that works, and revoke connections you no longer use.