Skip to content
← Back to the toolkit
EducationalProcurement

Read a SaaS contract for ownership and exit

Reviews ownership, exit, jurisdiction and change-control clauses so you look for enforceable rights rather than reassuring language.

Prompt for your AI
Provide only the necessary, redacted clauses from the contract, DPA or terms of service: [clauses]. Do not submit confidential terms, personal data, signatures, account details or privileged advice to an external assistant. Use a counsel- or organisation-approved private tool when redaction is insufficient.

Context: organisation and sector [description], service and version [service], deployment and operating model [description], contract identity/version/effective date [details], governance baseline [baseline], customer-control boundary [boundary], applicable regimes to investigate [for example GDPR, NIS2 or sector rules], review date [date]. Do not assume that a named regime applies; flag that for qualified legal review.

Act as a contract reviewer focused on enforceable data-control and exit questions. This is issue spotting, not legal advice. Quote before you interpret, and distinguish supplied text from assumptions.

Assess:
- Possess: durable access to customer data, configuration and evidence; source or escrow rights needed for continuity; data return format, completeness and timing.
- Use: decision authority over access, integrations, partners, operators and changes; subprocessors and jurisdiction; data location versus actual control; unilateral changes to terms, price or location.
- Dispose: termination notice, usable export, transition assistance, supplier-access revocation, supplier-copy deletion, evidence of deletion and continuity if the supplier fails, is acquired or discontinues the service.

For each point, quote the exact clause, state what it appears to permit or require within this scope, identify ambiguity and name the missing evidence. Treat an absent clause as unresolved, not as permission or prohibition. Separately flag data-compliance questions for qualified counsel and data-ethics questions for customer governance; do not invent answers to either.

End with the five clauses that most need clarification or renegotiation before signing, ranked by operational impact, and the evidence that would show each protection works in practice. Do not produce a compliance verdict, sovereignty score, badge or certification. Have qualified counsel review the contract and applicable law before signing.
---
Use the toolkit as a practical way to examine who can possess, use and dispose of data and the software, hardware and organisational arrangements around it. Keep weak points visible instead of hiding them in one overall judgement.
Examine the organisational side through two complementary perspectives. Data compliance covers applicable rules, contracts, policies, authority, duties and supplier commitments. Data ethics asks whether choices are proportionate, fair, transparent and explainable. Governance operates across both.
Keep compliance questions and data-ethics concerns separate. Leave applicability and legal interpretation to qualified counsel, and do not present ethical considerations as a certification or universal verdict.
Scope every conclusion to the described service, deployment, operating model, agreements, customer boundary and date. Separate supplied facts from assumptions and missing or conflicting evidence. Do not produce an overall score, legal or ethical verdict, or certification.
Data handling: do not include personal data, credentials, secrets or confidential contractual, security or architecture details. Redact them and use an approved private or local assistant when redaction is insufficient.
Background and definitions: https://hoist-it.nl/toolkit
Relevant concepts: https://hoist-it.nl/toolkit/exit-clause  https://hoist-it.nl/toolkit/vendor-lock-in  https://hoist-it.nl/toolkit/data-compliance  https://hoist-it.nl/toolkit/data-ethics  https://hoist-it.nl/toolkit/gdpr
Copy this into an assistant of your choice. The links give it context. Replace the [bracketed] parts with your own, and do not paste anything confidential.

Keep going

Related concept

Exit clause

The contractual terms that decide what happens to your data and your access to it, when the arrangement ends, on any terms including the ones you did not choose.

Related concept

Vendor lock-in

The state where switching provider is so costly, slow or contractually blocked that you cannot leave in practice, whatever the contract says you may do.

Copyright 2026HOIST IT. All Rights Reserved