Vendor Agreement Checklist for Indian Startups: SLA, Indemnity, DPDP, IP, Exit and Payment Clauses
A vendor can move your startup faster, but a weak vendor agreement can move your risk even faster.
Direct answer
A vendor agreement is not admin paperwork. It decides who owns the work, who protects customer data, who pays for failure, how service levels are measured and how cleanly the startup can exit.
Founders should read vendor contracts with the Indian Contract Act, 1872, the Digital Personal Data Protection framework, and sector-specific regulator guidance in mind. The Best CS Firm In India approach is direct: do not give vendors operational access until the contract, data, IP and exit record are clean.
Start with vendor risk tiering
| Vendor type | Main risk | Extra clause to add |
|---|---|---|
| Cloud, SaaS or IT vendor | Data, uptime, security and lock-in | SLA, data processing, breach notice, exit support |
| Marketing or design agency | IP ownership and brand misuse | IP assignment, portfolio-use consent, confidentiality |
| Manufacturer or hardware vendor | Quality, delay and defects | Inspection, warranty, rejection, liquidated damages |
| Recruitment or HR vendor | Candidate data and fee disputes | Data deletion, replacement terms, non-solicit boundaries |
| Finance, payments or compliance vendor | Regulatory and customer-impact risk | Audit rights, regulator cooperation, incident escalation |
Vendor agreement clauses founders should not skip
- Scope: define deliverables, exclusions, dependencies and acceptance process.
- SLA: define uptime, turnaround time, support window, severity levels and credits.
- Payment: connect invoices to milestones, usage, purchase orders or delivery evidence.
- Confidentiality: protect product plans, customer data, financials and investor information.
- DPDP/data: define processing purpose, access controls, breach notice, deletion and sub-processors.
- IP: assign custom work to the company and disclose pre-existing tools or templates.
- Indemnity: cover IP infringement, confidentiality breach, data misuse, wilful misconduct and legal non-compliance.
- Exit: require handover, data export, access revocation and transition support.
DPDP and customer-data checklist
If a vendor touches customer, employee, investor or founder personal data, the contract should say what data is shared, why it is shared, how long it is retained, who can access it, whether sub-vendors are used, what happens after termination and how fast incidents must be reported.
Operational checklist before giving access
| Step | Question to answer | Evidence |
|---|---|---|
| Commercial approval | Who approved cost, scope and timeline? | Email, purchase order or board/management note |
| Security approval | What systems and data will the vendor access? | Access matrix and security questionnaire |
| Legal approval | Are SLA, IP, confidentiality, indemnity and exit covered? | Signed agreement and annexures |
| Finance setup | Are GST, TDS, invoice and withholding terms clear? | Vendor master, tax documents and payment terms |
| Exit plan | How will data and work product return to the startup? | Exit checklist and handover clause |
Mistakes founders should avoid
- Using a vendor’s one-sided template without checking data, IP and exit clauses.
- Giving admin access before contract signature.
- Letting agencies reuse startup designs or code without permission controls.
- Ignoring GST, TDS and invoice documentation at onboarding.
- Missing a practical incident-notice timeline for data or security events.
Founder / Business Takeaway
Vendor risk is not solved by trust. It is solved by scope, access discipline, service levels, data controls and clean exit rights. Build one vendor onboarding checklist and use it before every new vendor gets live access.
Free Weekly Newsletter
Subscribe to BSA startup funding alerts
- Every Sunday, all Indian startup funding alerts in one place
- Monthly funding report on the last day of the month
- Free, concise, founder-focused, and easy to unsubscribe
Get the complete Indian startup funding roundup in your inbox, covering deals, sectors, investor moves, and founder readiness notes from the week.
Built for founders, investors, CFOs, and advisors
No spam. Unsubscribe anytime.
Suggested internal links
FAQ
What clauses must Indian startup vendor agreements include?
They should cover scope, SLA, fees, confidentiality, data handling, IP, audit rights, indemnity, liability, termination and exit support.
Should startups use the same vendor agreement for all vendors?
No. Different vendors create different risks, so the clauses should change by vendor type and access level.
What evidence should founders keep after onboarding?
Keep contracts, scope documents, purchase orders, invoices, access logs, data records, approvals and exit confirmations.
