Vendor Agreement Checklist for Indian Startups: Payment Terms, IP Ownership, DPDP, GST, Indemnity and Exit Clauses Founders Should Fix Before Scale
Indian startups should not sign vendor agreements only to record price and payment. A good vendor contract should clearly answer what will be delivered, when it will be delivered, who owns the work product…
Direct answer for founders
Indian startups should not sign vendor agreements only to record price and payment. A good vendor contract should clearly answer what will be delivered, when it will be delivered, who owns the work product, what data the vendor can access, what invoice and GST evidence will be provided, what happens when service quality drops, who carries liability, how confidential information is protected, and how the relationship can end without hurting customers or investor diligence.
This matters for SaaS tools, cloud vendors, developers, designers, marketing agencies, manufacturers, contract packers, logistics partners, recruiters, payroll processors, consultants, marketplace enablers, call centres, data processors, accountants and fractional teams. Startups often move fast by trusting vendors informally. That is understandable in the first month. It becomes risky once revenue, personal data, customer commitments, code, inventory or investor money touches the vendor relationship.
Use primary legal sources as the base. The Indian Contract Act, 1872 is the core contract-law statute and is available on India Code: https://www.indiacode.nic.in/handle/123456789/2187?view_type=browse. The Copyright Act, 1957 is relevant for assignment of creative, software, content and design work: https://www.indiacode.nic.in/handle/123456789/1367. Section 31 of the CGST Act covers tax invoices: https://taxinformation.cbic.gov.in/content/html/tax_repository/gst/acts/2017_CGST_act/active/chapter7/section31_v1.00.html. The Digital Personal Data Protection Act, 2023 is available from MeitY: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf.
Why vendor agreements become a founder problem
Vendor risk usually appears in small pieces. A developer says the code can be reused elsewhere. A marketing agency keeps admin access to ad accounts. A logistics partner does not share proof of delivery. A consultant invoices from the wrong GSTIN. A cloud tool stores customer data outside the founder’s visibility. A manufacturer misses specifications but the purchase order has no acceptance process. A recruiter claims placement fees after a candidate exits in three weeks.
Investors and enterprise customers do not treat these as small operational errors. They ask whether the startup controls its IP, customer data, commercial commitments, tax evidence and continuity risk. If the vendor folder is messy, the company looks less mature than its revenue suggests.
Vendor risk map by startup type
| Startup situation | Vendor risk founders should control |
|---|---|
| SaaS or AI product | Cloud, API, support, analytics and data-processing terms must be clean |
| D2C or ecommerce | Contract manufacturing, packaging, warehousing, returns and logistics evidence must reconcile |
| Fintech or lending | Partner contracts, data access, outsourcing, customer communication and security clauses need tighter review |
| Healthtech or edtech | Privacy, consent, content ownership, counsellor or teacher contracts and user-safety escalation matter |
| B2B services | Scope, change requests, IP assignment, milestone acceptance and liability caps decide margin quality |
| Marketplace | Seller, fulfilment, payment, refund, grievance and data-sharing terms must not contradict customer promises |
Clause 2: scope of work and acceptance
The scope should be specific enough that both sides know when work is complete.
| Area | What to write |
|---|---|
| Deliverables | Features, assets, reports, SKUs, campaigns, service hours, support tickets or milestones |
| Quality standard | Specifications, brand guidelines, security requirements, performance levels or acceptance tests |
| Timeline | Start date, milestone dates, review windows and final delivery date |
| Dependencies | What the startup must provide and by when |
| Change requests | How extra work, delays and revised pricing are approved |
| Acceptance | Who signs off, what defects mean, and how rework is handled |
For product or technology work, avoid vague words such as “complete platform” or “full automation” without acceptance tests. For manufacturing, attach specifications, packaging standards and rejection process. For agencies, define channels, monthly outputs, ad-account ownership and reporting format.
Clause 3: payment terms, invoices and tax evidence
Payment clauses should protect cash flow and records.
Founders should check:
- Whether payment is fixed fee, retainer, milestone, usage-based, success-fee or reimbursement-linked.
- Whether GST is included or extra.
- When the tax invoice must be issued.
- Whether TDS applies and how deduction certificates will be handled.
- Whether out-of-pocket expenses need prior approval.
- Whether payment is linked to acceptance, not only delivery.
- Whether disputed invoices can be withheld partly.
- Whether late fees are reasonable and documented.
Do not allow vendors to bill from one GSTIN while the contract names another entity. Keep invoices, purchase orders, approvals, proof of delivery, work completion notes and payment trail together. During diligence, tax teams often compare vendor expense ledgers with contracts, GST invoices, TDS filings and bank statements.
Clause 4: IP ownership and assignment
If the vendor creates code, designs, website pages, pitch decks, videos, trademarks, packaging, reports, datasets, workflows, product documents, content or inventions, the agreement should clearly transfer the relevant rights to the startup.
The founder test is simple: can the startup show an investor that it owns or has the right to use the output after full payment?
Use:
- Written assignment language for copyrightable work.
- Clear treatment of pre-existing vendor tools or libraries.
- Restrictions on reuse of startup confidential information.
- Handover of editable source files.
- Domain, repository, Figma, ad account and cloud-account control.
- Open-source licence disclosure where software is delivered.
- Moral-rights and attribution treatment where relevant.
Payment alone is not always enough. If a contractor built the MVP, the IP clause should be checked before a fundraise, not during the investor counsel call.
Clause 5: confidentiality and business information
A vendor may see pricing, customer lists, product roadmap, investor decks, financial data, source code, ad performance, factory details, supplier terms or employee data. Confidentiality should cover what is confidential, permitted use, who inside the vendor team can access it, survival period, return or deletion on exit, and injunctive relief where appropriate.
Free Weekly Newsletter
Subscribe to BSA startup funding alerts
- Every Sunday, all Indian startup funding alerts in one place
- Monthly funding report on the last day of the month
- Free, concise, founder-focused, and easy to unsubscribe
Get the complete Indian startup funding roundup in your inbox, covering deals, sectors, investor moves, and founder readiness notes from the week.
Built for founders, investors, CFOs, and advisors
No spam. Unsubscribe anytime.
For early-stage startups, the practical issue is access. If an agency has the Meta ad account, a developer has GitHub admin rights, or a consultant has the investor data room link, the contract should match the access reality.
Clause 6: DPDP and data-processing controls
If the vendor handles personal data, add a data-processing schedule. This is not only for large SaaS companies. Recruiters handle candidate data. Payroll vendors handle employee data. Logistics partners handle addresses and phone numbers. Support tools handle customer tickets. Marketing vendors handle leads and campaign lists.
The schedule should cover:
| Item | Founder control |
|---|---|
| Data categories | Names, email, phone, address, KYC, HR, usage logs, support records |
| Purpose | Why the vendor can process the data |
| Access | Who can access data and whether subcontractors are allowed |
| Security | MFA, encryption, limited exports, access logs and deletion |
| Breach | Timeline and content of vendor breach notification |
| Return/deletion | What happens when the contract ends |
| Audit | Right to ask for evidence or security questionnaire responses |
Do not send raw customer exports to vendors without documenting purpose and access controls. This is both a compliance and trust issue.
Clause 7: warranties, indemnity and liability cap
Every vendor agreement should decide who bears risk if something goes wrong.
Important warranties include authority to sign, ability to deliver, non-infringement of third-party IP, lawful data handling, tax compliance, no malware, no bribery, and compliance with applicable laws. Indemnity should cover the high-risk scenarios: third-party IP claims, confidentiality breach, data breach caused by vendor fault, wilful misconduct, fraud, tax non-compliance and bodily injury or property damage where relevant.
The liability cap should be commercial, not accidental. For low-risk creative work, a capped liability may be acceptable. For data processors, mission-critical vendors, manufacturers, payment partners or logistics vendors, founders should ask whether the cap is too low for the real risk.
Clause 8: termination and transition
A startup should be able to exit a vendor relationship without losing business continuity.
Include:
- Termination for convenience with notice.
- Termination for breach with cure period.
- Immediate termination for fraud, data breach, IP misuse or unlawful conduct.
- Handover duties.
- Return or deletion of data.
- Transfer of source files, credentials and documents.
- Survival of confidentiality, IP, payment, dispute and indemnity clauses.
- Support during transition to a new vendor.
Founder mistake: terminating a vendor and then discovering that the vendor controls the website login, product repo, domain, customer templates or ad account.
Documents to keep in the vendor data room
| Folder | Documents |
|---|---|
| Contract | Signed agreement, SOW, purchase order, amendments and renewal notes |
| Approvals | Board, founder, finance or department approval where material |
| Tax | GST invoices, TDS workings, payment proof and reconciliations |
| IP | Assignment, source files, repository transfer and licence disclosure |
| Data | DPDP schedule, security questionnaire, breach records and deletion certificate |
| Performance | Milestone acceptance, SLA reports, defect logs and escalation notes |
| Exit | Termination notice, handover checklist, account transfer and final settlement |
Seven-day vendor cleanup plan
| Day | Action |
|---|---|
| 1 | List all active vendors, consultants, platforms and agencies |
| 2 | Rank them by access to customer data, IP, money, inventory or customer delivery |
| 3 | Pull signed contracts, invoices and payment records |
| 4 | Check IP assignment and source-file ownership for product and creative vendors |
| 5 | Add DPDP and confidentiality controls for data-handling vendors |
| 6 | Fix GST, TDS, purchase order and approval gaps |
| 7 | Create exit checklists for critical vendors |
Sources
- Indian Contract Act, 1872 on India Code: https://www.indiacode.nic.in/handle/123456789/2187?view_type=browse
- Copyright Act, 1957 on India Code: https://www.indiacode.nic.in/handle/123456789/1367
- CGST Act Section 31 on tax invoices: https://taxinformation.cbic.gov.in/content/html/tax_repository/gst/acts/2017_CGST_act/active/chapter7/section31_v1.00.html
- Digital Personal Data Protection Act, 2023 from MeitY: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
FAQ Section
Does every vendor agreement need a detailed contract?
Material vendors should have a written agreement or at least a signed SOW with clear commercial, IP, confidentiality, tax, data and exit terms. Low-value purchases may use purchase orders, but critical vendors need more detail.
Is an invoice enough to prove IP ownership?
Usually no. If the vendor creates code, designs, content or product material, founders should use clear written IP assignment language and retain editable source files.
Should startups add DPDP clauses to vendor contracts?
Yes, where the vendor processes personal data. The clause should cover purpose, access, security, breach notice, subcontractors, deletion and return of data.
What is the biggest vendor-contract mistake founders make?
The most common mistake is signing for speed while leaving scope, acceptance, IP ownership, data access and termination unclear.
What will investors check in vendor diligence?
Investors may check signed contracts, payment terms, GST invoices, IP assignment, data-processing terms, customer-impacting vendors, litigation, termination rights and concentration risk.
Founder / Business Takeaway
Vendor contracts should protect the startup’s product, data, cash flow, tax records and customer delivery. The Best CS Firm In India approach is to make vendor risk visible before the company scales, not after a fundraise or customer dispute forces the issue.
Need expert support?
BSA helps Indian startups review vendor agreements, IP assignment, DPDP clauses, GST records, confidentiality terms, liability exposure and investor data-room readiness.
Need expert support?
BSA supports founders across India with ROC, FEMA, due diligence, fundraising readiness, and company secretarial execution.
