Vendor Agreement Red Flags: 6 Clauses Founders Should Check Before Signing

Vendor Agreement Red Flags

A founder we advised last quarter was three months into a critical product launch when her tech vendor started missing every milestone. When we reviewed the agreement, there was no termination for convenience clause only termination for cause, with a 60-day cure period. She was legally required to give the vendor two more months to fix what it had already failed to deliver in three. The launch slipped by a quarter.

The contract was four pages long. Again, this would have been a 45-minute review. So then we returned to the same story, because a founder is rarely sunk by one catastrophic clause. Just a few plain-Jane provisions that merely highlight an issue after the fact, tucked away neatly in a four-page agreement.

Table of Contents

The Four Questions Every Vendor Agreement Should Answer

Before you get into the fine print, there are really only four things a vendor agreement needs to tell you clearly:

  1. Can I exit if the vendor stops performing?
  2. Can I recover meaningful losses if something goes wrong?
  3. Do I actually own what I’m paying the vendor to create?
  4. Can the vendor’s actions expose my business to regulatory or data risk?

If you can’t answer all four with confidence after reading the contract once, that’s your cue to slow down before you sign not after you’ve had a bad quarter.

Vendor agreements are also the contracts founders sign most often and read least carefully. That’s understandable they’re rarely the deal that gets negotiated for weeks like a term sheet or a founders’ agreement. But because they’re vendor-drafted, they’re usually built around the vendor’s risks: limiting the vendor’s liability, protecting the vendor’s tools, controlling how and when the vendor gets paid, and making it hard for you to walk away. That isn’t necessarily unfair on the vendor’s part it’s just not written with your business in mind. A clause that’s commercially standard for the vendor isn’t automatically commercially safe for you.

Here are the six red flags we see most consistently in the vendor and service agreements we review at Meridian and Co and what to do about each one.

The 60-Second Vendor Agreement Test

Before you dive into definitions and boilerplate, run the agreement through these six checks:

Check Question
Exit Can you terminate without proving breach?
Performance Are milestones, SLAs and acceptance criteria measurable?
Money Is your liability proportionate to the commercial risk?
Ownership Do you own the deliverables and IP you’re paying for?
Data Does the vendor have clear contractual data-protection obligations?
Exit handover Must the vendor return your data and assist with transition?

No Termination for Convenience Clause

This is the clause founders miss most and the one that causes the most damage once a vendor relationship starts to break down. Termination for convenience isn’t a default right under Indian law. The Indian Contract Act, 1872 doesn’t imply a general right to walk away from a contract without cause. If your agreement doesn’t expressly include a termination-for-convenience clause, your only legal exit is to prove the vendor committed a defined breach and most agreements give the vendor a cure period before that right even kicks in.

What a healthy clause looks like: either party may terminate on 30 days’ written notice, without needing to give a reason, with clear obligations around data return and handover of deliverables.

What a dangerous clause looks like: termination only for material breach, narrowly defined, after a 60-day notice-and-cure period. That structure runs almost entirely in the vendor’s favour.

What to negotiate

    • A 30-day termination for convenience right
    • Shorter cure periods for critical or repeated breaches
    • Immediate termination rights for repeated SLA failures
    • Clear data return obligations on exit
    • Transition assistance after termination
    • Continued access to essential systems during handover

One-Sided or Poorly Structured Indemnity Clauses

In India the concept of indemnity is governed by sections 124 and 125 of Indian Contract Act, 1872. An indemnity clause is a contractual clause that transfers the financial risk of certain losses from one party to another. In a vendor agreement, it always comes down to who indemnifies whom for what and up to what cap.

The red flag is an agreement that requires you to indemnify the vendor against broad third-party claims including claims arising from the vendor’s own conduct while limiting the vendor’s indemnity obligations to a narrow set of triggers, all capped at a single month’s fees. Watch for:

    • Broad indemnity from you to the vendor for any third-party claim, regardless of fault
    • Vendor IP indemnity that’s expressly subject to the general liability cap, making it commercially worthless
    • Lack of carve-out to liability cap for fraud, wilful misconduct or data breach Unclear survival period of indemnity making it possible that post-termination claims can be made interminably
    • Indemnity survival left unspecified, creating uncertainty about how long post-termination claims can be brought

Since the Digital Personal Data Protection Act, 2023 came into force, indemnification for data protection breaches has become a standard and heavily negotiated part of Indian vendor contracts. If your vendor processes personal data on your behalf, the data breach indemnity needs to sit outside the general liability cap. By putting a ₹50,000-a-month cap, data indemnity becomes a ceiling against which an actual breach could be withstood countless times over.

The clause interaction founders miss

An indemnity can read as strong on paper and still offer almost no real protection if it’s tucked inside a very low liability cap. For example: the vendor indemnifies you for IP infringement, but total liability is capped at ₹50,000 and the IP indemnity is expressly made subject to that same cap. The contract technically has an IP indemnity. Commercially, it may be worth very little against a claim running into several lakhs.

Always read the indemnity clause and the liability cap together, never in isolation.

IP Ownership That Stays With the Vendor

If a vendor is building software, designing assets, writing content, or creating any deliverable for your business, the agreement needs to expressly assign ownership of that work to you. Without an express IP assignment clause, the vendor as the creator retains ownership of the work under Indian copyright law, regardless of how much you’ve paid for it.

Vendors often use “licence to use” language instead of “assigns all IP rights.” A licence can be revoked; an assignment can’t. When the relationship ends, a licence-only clause can leave your core technology, brand assets or campaign creative sitting in the vendor’s name, not yours.

Background IP vs. what you’re actually paying for

It’s worth separating two things the agreement should treat differently:

    • Deliverables built specifically for your business these should generally be owned by, or clearly assigned to, you.
    • The vendor’s pre-existing tools, frameworks, libraries or know-how it’s usually reasonable for these to stay with the vendor, provided you get the rights you need to use them.

A Liability Cap That Makes the Indemnity Worthless

Most vendor agreements cap total liability at one to three months’ fees. For a ₹50,000-a-month vendor, that’s a ceiling of ₹50,000 to ₹1,50,000 on losses that could run far higher in a data breach, a delivery failure, or an IP infringement claim.

The fix isn’t to remove the cap vendors won’t agree to that, and it isn’t always reasonable to ask. It’s to make sure specific high-risk categories sit outside the cap: IP indemnity, data breach liability, and fraud or wilful misconduct should each be carved out. A cap of 100–200% of annual contract value is a commercially reasonable ask for vendors carrying meaningful operational or data risk.

Match the cap to the risk, not a template

Vendor risk Contractual protection to consider
Low-risk administrative service General liability cap
Software development IP indemnity + milestone-based remedies
Customer data processing Data breach carve-out + security obligations
Critical infrastructure Higher cap + business continuity obligations
Regulated or high-value operations Higher cap + specific indemnities + insurance

The goal isn’t necessarily to eliminate the cap it’s to make sure it doesn’t quietly erase the protections you’ve negotiated everywhere else in the contract.

Payment Terms That Violate the MSME Act

If your vendor is a registered Micro or Small Enterprise under the MSME Development Act, 2006, payment terms beyond 45 days are void to that extent by statute regardless of what your agreement says. The Act mandates payment within 45 days of acceptance of goods or services, or within 15 days if there’s no written payment term at all. Delayed payments attract statutory interest at three times the RBI bank rate.

This became a direct tax issue from 1 April 2024. Section 43B(h) of the Income Tax Act, amended effective FY 2024-25, disallows a deduction for payments made to MSME vendors beyond the statutory 45-day window. A 60-day payment clause with an MSME supplier isn’t just an unenforceable contract term it’s a tax disallowance waiting to happen.

Before you finalise the payment clause

  1. Confirm whether the vendor qualifies as a Micro or Small Enterprise
  2. Verify their Udyam registration status
  3. Be clear on what actually counts as “acceptance” of goods or services
  4. Know exactly when the 45-day payment clock starts
  5. Make sure your accounts team is tracking the deadline, not just the contract

The clause and your company’s payment process need to work together one without the other doesn’t protect you.

No Data Protection Obligations for the Vendor

The Digital Personal Data Protection Act, 2023 is now in force, with its provisions being rolled out in phases. If your vendor processes personal data on your behalf user data, customer records, employee information you remain the “Data Fiduciary” in law, and you carry the regulatory exposure for how that data is handled, including by your vendors.

A vendor agreement with no data protection clause doesn’t shield you from that exposure. At minimum, it should require the vendor, as a “Data Processor,” to:

    • Process personal data only on your documented instructions
    • Implement appropriate security safeguards
    • Notify you of any data breach without undue delay
    • Not engage sub-processors without your prior written consent
    • Delete or return all personal data on termination

Minimum vendor data-protection checklist

    • Purpose and scope of processing
    • Documented instructions
    • Security safeguards
    • Breach notification timelines
    • Sub-processor consent
    • Data retention limits
    • Deletion or return of data on exit
    • Access and audit rights, where appropriate
    • Cooperation with regulatory or data-subject requests
    • Post-termination obligations

Any startup handling user data through a third-party vendor a SaaS tool, a marketing platform, a payroll processor needs these obligations written in, not assumed. If the agreement is silent, the liability sits with you, not the vendor.

The Red Flags That Hide Behind the Six

The six issues above cause the most damage, but a handful of quieter provisions are worth scanning for too, because they tend to increase your dependency on the vendor over time:

    • Automatic renewal does the contract renew unless you give notice within a narrow window?
    • Unilateral price increases can the vendor raise fees without your agreement?
    • Subcontracting can the vendor hand off performance to someone else without your approval?
    • Vague acceptance criteria are “deliverables” actually measurable, or open to interpretation?
    • Transition assistance what happens, practically, when you leave?
    • Data portability can you get your information back in a usable format?
    • Insurance does the vendor carry cover appropriate to the risk they hold?
    • Business continuity what happens if the vendor has an outage or shuts down?

Why One Bad Clause Is Rarely the Whole Problem

Red flags tend to travel in groups. A few patterns we see often:

The trapped founder: No termination for convenience, a 60-day cure period, vague performance standards, and a low liability cap together, that’s a founder who can’t exit easily and can’t recover much even if they do.

The IP dependency: A licence instead of an assignment, no source-code handover, no transition assistance you’ve paid for the software, but you still need the vendor to keep using it.

The data exposure. Weak security obligations, no breach notification mechanism, and a liability cap that applies even to data claims a combination that can turn a vendor’s mistake into your regulatory problem.

None of these are single-clause failures. They’re the result of ordinary clauses interacting badly with each other, which is exactly why a full read-through matters more than checking any one provision in isolation.

Conclusion

Before you sign a vendor agreement, you should be able to answer four questions with confidence: Can we exit? Can we recover? Do we own what we’re paying for? Can the vendor expose us to regulatory or operational risk?

If the answer to any of those depends on an ambiguous clause, a low liability cap, a missing obligation, or something buried in the vendor’s standard terms that’s a negotiation point now, not a discovery you want to make later, when a launch has slipped, a breach has surfaced, or a due diligence team is asking who actually owns your product.

The six red flags in this guide aren’t edge cases they show up in most of the vendor agreements we review at Meridian and Co, and they’re the areas we give the closest attention to when drafting or reviewing vendor and service contracts for our clients. Every one of them is fixable at the negotiation stage. Almost none of them are easy to fix once the contract is signed and the problem has already surfaced.

Considering a new vendor agreement, or want an existing one reviewed before you renew? Get in touch with our team for a review.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top

Consult Our Corporate Lawyers Now

Get Legal Gaps Insights in 20-min Free Consultation