Sample Prompts for AI Blueprint (Mini) for Lawyers

Model Answers — CloudFlow SaaS Agreement Review

Reference outputs for the five-prompt demo sequence, showing the standard of analysis Mini should reach on the test contract: full risk review, GC briefing, negotiation email, clause-by-clause playbook, and a final judgment call. All clause references are to the CloudFlow Enterprise SaaS Agreement dated 1 September 2026.

Test contract | Sample Prompts
1 · Risk Review 2 · GC Briefing 3 · Negotiation Email 4 · Playbook 5 · Judgment Test
1
Pre-Signature Risk Review
Acting for Meridian Retail Solutions (Customer)
Model answer

Executive summary

Do not sign in current form. The agreement is professionally drafted but heavily vendor-weighted at every pressure point that matters for this deal. The three structural problems are: (1) CloudFlow's total liability — including for data loss, security incidents, and confidentiality breaches — is capped at roughly USD 105,000 (three months of fees, Cl. 15.3) against a ~USD 1.35M contract processing personal and payment-related data, while Meridian's own core exposures are uncapped (Cl. 15.4); (2) Meridian grants a worldwide, irrevocable, perpetual licence over Customer Data extending to machine-learning training and "other business purposes," surviving termination (Cl. 7.2, 7.3, 12.3, 21.4); and (3) exit and renewal mechanics (15-day export window, list-price auto-renewal via the Order Form, a 30-day non-renewal notice window) create severe practical lock-in. There are also at least four internal inconsistencies between the main body and the schedules, one of which — renewal pricing — is resolved against Meridian by the order-of-precedence clause (Cl. 27.9). All of this is negotiable; none of it should survive negotiation unchanged.

A. Internal inconsistencies (main body vs schedules)

  1. Availability: 99.9% vs 99.5%. Cl. 6.1 commits to 99.9% monthly uptime, but Schedule 3 ¶1 and ¶3 define the commitment and all service credits by reference to 99.5%. Under Cl. 27.9 the main body ranks above Schedule 3, but because Cl. 6.1 expressly says availability is "measured and calculated as described in Schedule 3," a court or tribunal would likely hold that credits only trigger below 99.5% — meaning the platform can be down ~3.6 hours/month with no remedy at all, versus the ~43 minutes implied by 99.9%.
  2. Data export: 15 days vs 30 days. Cl. 21.3 gives a 15-day post-termination export period; Schedule 5 ¶1 gives 30 days. The main body prevails over Schedule 5 under Cl. 27.9, so the prudent operating assumption is 15 days — an extremely short window for 25 TB of documents and 1,200 users' records.
  3. Breach notification: 10 business days vs 72 hours. Cl. 9.4 allows notification within 10 business days after CloudFlow (in its own judgment) "confirms" an incident; Schedule 4 ¶3 requires notice without undue delay and within 72 hours where there is likely risk to data subjects. Here the conflict runs in Meridian's favour: Schedule 4 ranks above the main body (Cl. 27.9(b)). But the two standards use different triggers ("confirms" vs "becoming aware"), and CloudFlow controls the confirmation determination — the ambiguity will be exploited in a live incident. Meridian has statutory breach-reporting obligations under Indian law that a 10-business-day vendor clock cannot accommodate.
  4. Renewal pricing: negotiated adjustment vs list price. Cl. 5.5 reads like a notice-based fee adjustment at renewal; Schedule 1 ¶4 (the Order Form) says renewal pricing is CloudFlow's then-current list price "as notified in the renewal invoice." Because the Order Form ranks first under Cl. 27.9(a), the list-price term prevails. Combined with the auto-renewal trap (below), Meridian can be re-priced at renewal with no cap and no exit.

B. Tiered findings

Tier ACould justify delaying signature

  1. Liability cap of 3 months' fees, expressly covering data and security failures (Cl. 15.3). The cap explicitly sweeps in loss of Customer Data, Security Incidents, and breaches of the privacy (Cl. 8), security (Cl. 9), and confidentiality (Cl. 10) clauses, and even CloudFlow's IP indemnity (Cl. 14). Practical impact: a breach exposing 1,200 employees' data plus customer and payment-related records could generate regulatory penalties, notification costs, and claims far exceeding USD 105,000, with everything above that amount landing on Meridian. Meanwhile Cl. 15.4 uncaps Meridian's liability for payment, use restrictions, confidentiality, and its indemnity — the asymmetry, not the cap itself, is the deal-breaker.
  2. Perpetual, irrevocable data-use licence including ML training (Cl. 7.2, 7.3, 11.3, 12.3). CloudFlow may analyse, modify, and create derivative works from Customer Data for "product improvement, machine-learning development, and other reasonable internal business purposes," may use prompts and uploaded content to train AI systems, may use unnamed "third-party technology providers" for AI Features, and retains De-identified Data (defined only by CloudFlow's internal standards) forever (Cl. 21.4(b),(d)). For a customer whose data includes commercially sensitive records and personal data, this is an uncontrolled outbound data channel dressed as a licence.
  3. Customer indemnity covering first-party losses and regulatory fines, with vendor-controlled defence at our cost (Cl. 14.5, 14.6). The indemnity covers losses "suffered or incurred by any CloudFlow Indemnitee" — not just third-party claims — including fines, penalties, and regulatory sanctions arising from Customer Data or any Authorised User's conduct, and extends to regulator investigations. CloudFlow chooses counsel and controls settlement at Meridian's cost. Read with Cl. 15.4(d), this is uncapped.
  4. Exit lock-in (Cl. 21.3, 21.4; Schedule 5). 15 days to export 25 TB in "then-standard formats" only, with an express disclaimer of completeness and usability, chargeable fees for any real migration help, deletion rights immediately after, and indefinite retention of derived and de-identified data. There is no termination for convenience (Cl. 20.4) and no meaningful refund on most vendor-initiated terminations (Cl. 21.2) — indeed vendor termination for breach accelerates the remaining year's fees as a debt.
  5. Order-of-precedence and unilateral policy updates (Cl. 27.9, definition of "CloudFlow Policies"). The Order Form outranks the negotiated body (delivering the list-price renewal term), online policies prevail on "operational matters," and CloudFlow may update those policies with effect from publication. Anything Meridian negotiates in the main body can be partially eroded from a webpage.

Tier BMust fix before signing

  1. Auto-renewal trap (Cl. 19.2): non-renewal notice is valid only if given between 150 and 120 days before term end — a 30-day window buried in the term clause; a notice outside the window "shall be of no effect." Missing the window locks in 12 more months at list price (see A.5).
  2. Mid-term unilateral price increases (Cl. 5.6): fees can rise on 30 days' notice for hosting costs, FX, inflation, changes in law, or usage profile, with a termination right only for a single CPI-linked increase above 15%. There is effectively no budget certainty even inside the fixed 3-year term.
  3. Fee acceleration on vendor termination (Cl. 21.2): if CloudFlow terminates for breach — including the vague "reputational harm" ground in Cl. 20.1(c) — the balance of the year's fees falls due immediately with no refund.
  4. Suspension rights (Cl. 18): immediate, potentially unnotified suspension on suspicion-based grounds including "reputational harm," fees continuing throughout, no maximum duration, restoration only when CloudFlow is satisfied.
  5. Security commitments (Cl. 9.1–9.4): "commercially reasonable" safeguards with no named framework (no ISO 27001 / SOC 2 commitment), material detail left in internal policies CloudFlow can change, no right to penetration-test or audit reports, and the breach-notification problems in A/§3 above.
  6. Subprocessor mechanics (Cl. 8.3): changes by website update with no push notice, a 10-day objection window Meridian must discover for itself, CloudFlow's option to simply terminate the affected service instead of resolving an objection, and subprocessor responsibility expressly "subject to Clause 15" — i.e., inside the 3-month cap.
  7. Asymmetric termination (Cl. 20): CloudFlow may terminate immediately on multiple grounds including suspected illegality and commercial impracticality; Meridian may terminate only for uncured material breach of two clauses (6.1, 9.1) after a 45-day cure period and formal invocation of Cl. 20.2.

Tier CNegotiate if possible

  1. Acceptance mechanics (Cl. 3.2–3.5): 5-business-day window, deemed acceptance on any productive use, rejection notices invalid unless exhaustively detailed, unlimited vendor cure cycles, no refund path. Seek 15 business days, remove deemed acceptance by use during agreed UAT, and add a termination/refund right after two failed cure attempts.
  2. Service credits (Cl. 6.2–6.4; Schedule 3): sweeping exclusions, sole-remedy language, 15-day claim deadline, 10% monthly cap (max ~USD 3,500/month). Resolve the 99.9/99.5 conflict, raise the cap, and add a termination right for chronic failure (e.g., three consecutive months below target).
  3. Audit and regulatory cooperation (Cl. 17): written Q&A only, remote review only if legally compelled, at Meridian's cost including CloudFlow's fees, with broad refusal rights and no response deadlines. Indian regulators (and Meridian's enterprise customers) will expect more.
  4. Confidentiality asymmetry (Cl. 10.3, 10.6, 10.7): CloudFlow may share Meridian's confidential information with investors and deal counterparties; injunctive relief is spelled out only for CloudFlow; Meridian's information gets 3 years' protection while CloudFlow's trade secrets are protected indefinitely. Customer Data confidentiality should be perpetual and mutual injunctive relief express.
  5. Assignment and publicity (Cl. 24, 27.5): CloudFlow assigns freely (including to an acquirer — potentially a Meridian competitor) while Meridian needs consent even for internal restructuring; logo/name use is on by default via a buried opt-out in General Provisions that contradicts the mutual-consent tone of Cl. 23.1.
  6. Dispute resolution (Cl. 26): SIAC arbitration in Singapore is defensible for a Singapore vendor, but claimant-funds-fees front-loads Meridian's cost of complaining, and court access for injunctions/debt is drafted for CloudFlow only (Cl. 26.4). Make interim-relief court access mutual.
  7. Warranties (Cl. 13.3, 13.5): the sole remedy is repair/re-perform on 30 days' notice, with CloudFlow able to exit by part-year refund; disclaimers cover fitness, results, AI accuracy, and third-party compatibility. Acceptable shape, but the warranty-claim notice period and CloudFlow's unilateral "not practicable" exit need tightening.

Tier DAcceptable as-is

Singapore governing law and SIAC arbitration in principle; the mutual exclusion of indirect loss (Cl. 15.2) subject to carve-out fixes; net-30 payment terms; the AUP concept (subject to freezing the version); force majeure (Cl. 27.1); insurance clause existence (Cl. 16 — though minimum coverage amounts should be specified); implementation scope and milestones in Schedule 2; support tiers and response targets in Schedule 3 ¶4.

C. Proposed replacement positions (Tier A/B)

  • Cl. 15.3–15.4: General cap at 12 months' fees; a super-cap of 3x annual fees (or a fixed USD 2M) for breaches of Cl. 8–10 and Security Incidents; caps and the consequential-loss exclusion made mutual, applying equally to Meridian's indemnity.
    "CloudFlow's aggregate liability shall not exceed the Fees paid or payable in the twelve (12) months preceding the event, save that for breach of Clauses 8, 9 or 10 or any Security Incident, such liability shall not exceed three (3) times such amount. The limitations in this Clause 15 apply equally to each Party, including to liability under Clause 14."
  • Cl. 7.2 / 12.3: Licence limited to providing, securing, and supporting the Services; ML training and "other business purposes" deleted or made opt-in; de-identification defined against a recognised standard with a no-reidentification covenant; licence terminates with the Agreement.
    "CloudFlow shall not use Customer Data, prompts, or Outputs to train or improve any generalised model except with the Customer's prior written opt-in, and shall not disclose Customer Data to any third-party AI provider not listed in Schedule 4."
  • Cl. 14.5–14.6: Restrict to third-party claims; delete fines/penalties and first-party losses; exclude claims arising from CloudFlow's breach or Security Incidents; give Meridian control of its own defence.
  • Cl. 19.2 / Sch. 1 ¶4: Renewal by mutual agreement, or auto-renewal with non-renewal notice "at any time up to 60 days before term end" and renewal increases capped at 5% or CPI, whichever is lower; delete list-price language from the Order Form.
  • Cl. 5.6: Delete mid-term increases entirely, or confine to documented third-party pass-through costs capped at 3% per year with a termination right for any increase.
  • Cl. 21.3 / Sch. 5: 90-day export window; exports in agreed machine-readable formats with reasonable assistance included in fees; certified deletion of all copies (including backups on cycle expiry, max 90 days) with a written deletion certificate; delete the acceleration sentence in Cl. 21.2.
  • Cl. 9 / Sch. 4: Commit to ISO 27001 certification and annual SOC 2 Type II reports provided on request; single notification standard of 48 hours from awareness of any confirmed or reasonably suspected incident affecting Customer Data; security changes not to degrade any measure listed in Schedule 4.
  • Cl. 8.3: 30 days' advance email notice of new subprocessors; unresolved objection gives Meridian a termination-plus-refund right for affected services; CloudFlow fully liable for subprocessors as for its own acts.
  • Cl. 18 / 20: Suspension only for material AUP/security violations or 30-day payment default, with prior notice where lawful, scope-limited, fee abatement after 5 days, and a matching termination-for-material-breach right for Meridian covering any material obligation, plus termination for convenience on 90 days' notice with pro-rata refund.
  • Cl. 27.9: Main body prevails over all schedules and policies except where an Order Form expressly amends a named clause; policy updates effective only on 30 days' notice and never to reduce Meridian's rights or increase its obligations.

D. Findings vs assumptions

Document findings: every clause citation, the four inconsistencies, the cap arithmetic (USD 420,000 / 4 = USD 105,000), the 30-day renewal-notice window, the 15-day export period, and the precedence analysis are taken directly from the text.

Assumptions I am making: (i) contract value of ~USD 1.35M assumes the full 3-year term at unchanged fees plus implementation; (ii) I assume Meridian is a "Data Fiduciary" under India's DPDP Act 2023 with its own breach-notification and processor-contract obligations — the agreement's Singapore-law framing does not displace those; (iii) I assume the 25 TB / 1,200-user scale from Schedule 1 reflects actual intended usage; (iv) I assume no side letter or negotiated Order Form amendments exist beyond Schedule 1 ("Special terms: None"); (v) the enforceability of the fee-acceleration and uncapped-indemnity provisions under Singapore penalty and unconscionability doctrine is untested — I flag risk, not certainty of outcome.

2
One-Page Briefing for the General Counsel
CloudFlow SaaS Agreement — signature decision
Model answer

TO: General Counsel  ·  RE: CloudFlow SaaS Agreement — recommend holding signature  ·  DATE: Pre-signature review

Bottom line: This contract, as drafted, puts almost all of the risk of a USD 1.35M, three-year deal on us. Five issues individually justify delaying signature. All five are standard negotiation asks for a deal this size, and none should cost us the relationship.

1. If they lose our data, their maximum liability is about USD 105,000 (Cl. 15.3). The vendor's total liability — explicitly including data loss, security breaches, and confidentiality failures — is capped at three months of fees. Our liability to them, by contrast, is uncapped for the things most likely to bite us. A single serious breach involving our 1,200 employees' data or customer records would cost us multiples of their cap, and we would absorb the difference.

2. We are granting them our data forever (Cl. 7.2, 12.3, 21.4). The licence is worldwide, irrevocable, and survives termination. It lets them use our documents, transactions, and even our staff's AI prompts to train their models and for undefined "business purposes," and to keep "de-identified" copies indefinitely under a standard only they define. We cannot tell our own customers their data is protected while this stands.

3. We indemnify them for their own regulatory fines (Cl. 14.5). The indemnity we give is not limited to third-party claims — it covers losses the vendor itself suffers, including fines and penalties, arising from our data or anything any of our 1,200 users does. They control the defence with their lawyers, at our cost, and this obligation is uncapped.

4. Getting out is designed to be painful (Cl. 19.2, 21.3, Sch. 1 ¶4). The contract auto-renews unless we give notice inside a single 30-day window (150–120 days before term end); miss it and we're locked in for another year at their then-current list price — the Order Form overrides the friendlier-looking clause in the main agreement. On exit we get 15 days to export three years of data, in their format, with no promise it will be complete or usable, and paid help only.

5. The document contradicts itself in their favour (Cl. 27.9 and four conflicts). Uptime is 99.9% in the body but 99.5% where credits are actually calculated; export is 15 days in one place, 30 in another; breach notice is 72 hours in one schedule, 10 business days in the body. Their precedence clause plus a right to update online policies unilaterally means the version we sign is not the deal we'll live under.

Recommendation: Do not sign. Authorise us to send the negotiation letter (attached) seeking: a 12-month liability cap with a 3x super-cap for data/security, mutual application; removal of AI-training and perpetual data rights; a third-party-claims-only indemnity; a 60-day standard non-renewal notice with capped renewal pricing; and a 90-day assisted exit. Decision needed from you: approval of these five positions as our mandate, and confirmation of our walk-away points per the playbook, by end of week to hold the vendor's proposed go-live date.

3
Negotiation Email to Vendor's Counsel
Firm, commercially constructive, preferred + fallback per issue
Model answer

Subject: CloudFlow / Meridian — Enterprise SaaS Agreement: proposed revisions before signature

Dear Counsel,

Thank you for the draft agreement. Meridian is enthusiastic about the CloudFlow platform and we are keen to sign on a timeline that protects the 90-day go-live target. To get there, we need movement on a defined set of issues. In each case we set out our preferred position and, where we have flexibility, a fallback.

1. Liability (Cl. 15.3–15.4). A cap of three months' fees — roughly USD 105,000 on a USD 1.35M engagement — cannot apply to loss of our data, Security Incidents, or confidentiality breaches, while our own exposure remains uncapped. Preferred: a mutual general cap of 12 months' fees, with a super-cap of three times annual fees for breaches of Clauses 8–10 and Security Incidents. Fallback: a two-times super-cap, provided the caps apply mutually, including to Clause 14.5.

2. Data use and AI training (Cl. 7.2, 7.3, 12.3, 21.4). We are placing employee, customer, and payment-related data on your platform. Preferred: the licence is limited to providing, securing, and supporting the Services; ML-training, "other business purposes," and post-termination rights are deleted; de-identification is defined to a recognised standard with a no-reidentification covenant; third-party AI providers are listed in Schedule 4. Fallback: training on a strictly opt-in, workspace-by-workspace basis, off by default.

3. Customer indemnity (Cl. 14.5–14.6). As drafted it covers your first-party losses and regulatory fines and puts your counsel in charge at our cost. Preferred: third-party claims only, excluding anything arising from CloudFlow's breach or a Security Incident, with each party controlling its own defence. This one we regard as a drafting correction rather than a commercial ask.

4. Renewal and pricing (Cl. 5.5, 5.6, 19.2; Schedule 1 ¶4). The 150–120-day notice window, list-price renewals via the Order Form, and open-ended mid-term adjustments are incompatible with our budgeting. Preferred: non-renewal on notice any time up to 60 days before term end; renewal increases capped at the lower of 5% or CPI; Clause 5.6 deleted. Fallback: Clause 5.6 confined to documented third-party pass-through costs, capped at 3% per annum, with a termination right.

5. Exit and deletion (Cl. 21.2–21.4; Schedule 5). Preferred: a 90-day export window in agreed machine-readable formats with reasonable assistance included; certified deletion of all copies within 90 days thereafter; the fee-acceleration sentence in Clause 21.2 removed. Fallback: 60 days, with assisted export at a pre-agreed capped rate.

6. Security, breach notice, and consistency (Cl. 6.1, 9.4; Schedules 3–5; Cl. 27.9). We need one uptime figure (please confirm 99.9%), one notification standard (48 hours from awareness), annual SOC 2 Type II reports on request, 30 days' notice of new subprocessors, and a precedence clause under which the signed agreement prevails over online policies. We assume the internal inconsistencies between the body and Schedules 1, 3, 4 and 5 are unintended and can be conformed at the same time.

None of these positions is unusual for an enterprise deployment of this size and data sensitivity, and we do not expect them to affect your commercial return. Could we schedule a call this week — Thursday or Friday — to work through the mark-up? We will circulate a redline in advance.

Kind regards,
Counsel for Meridian Retail Solutions Private Limited

4
Clause-by-Clause Negotiation Playbook
Tier A and Tier B issues — opening / fallback / walk-away
Model answer
Issue (clauses)Opening positionAcceptable fallbackWalk-away pointExpected counter → our response
Liability cap
15.3, 15.4
Mutual 12-month cap; 3x super-cap for Cl. 8–10 breaches and Security Incidents; carve-outs apply to both parties. 2x super-cap for data/security, provided caps are mutual and cover Cl. 14.5. Any cap on data/security below 1x annual fees, or any one-way uncapped customer exposure. "Our pricing assumes this risk allocation" → then price the super-cap: we will consider a modest fee uplift or higher insurance evidence in lieu; we will not self-insure their platform failures.
Data licence & AI training
7.2, 7.3, 11.3, 12.3, 21.4(b),(d)
Licence limited to service delivery/security/support; delete training, "business purposes," and survival; defined de-identification + no-reidentification covenant; named third-party AI providers. Training strictly opt-in per workspace, off by default; de-identified retention allowed only under the defined standard. Any default right to train on our data or send it to unnamed third-party AI providers. "Everyone signs this; it improves the product" → enterprise peers routinely get no-training terms; offer anonymised telemetry (Usage Data) as the compromise, not content.
Customer indemnity
14.5, 14.6
Third-party claims only; delete fines/first-party losses; exclude claims caused by CloudFlow breach or Security Incidents; we control our defence. Retain AUP/IP-in-our-data indemnity, capped at the mutual general cap. Indemnifying their regulatory fines or first-party losses in any form. "Standard protection against customer content" → we accept the concept; the drafting overshoots it, and mirrored drafting proves the point.
Renewal & pricing
5.5, 5.6, 19.2, Sch. 1 ¶4
Notice any time up to 60 days pre-expiry; renewal increase ≤ min(5%, CPI); delete Cl. 5.6 and Sch. 1 list-price term. 90-day notice with vendor reminder obligation at 120 days; Cl. 5.6 limited to documented pass-through, ≤3%/yr, with termination right. The 150–120-day trap window, uncapped list-price renewal, or uncapped mid-term increases. "We need cost protection over 3 years" → that is what the CPI-linked fallback gives them; open-ended repricing inside a fixed term is not cost protection, it is an option against us.
Exit & deletion
21.2–21.4, Sch. 5
90-day export, agreed formats, assistance included; certified deletion of all copies ≤90 days after; delete fee acceleration in 21.2; add termination for convenience on 90 days' notice with pro-rata refund. 60-day export; assisted export at capped pre-agreed rates; backups purged on ≤90-day cycle with certificate; keep no-convenience if refunds fixed. 15-day export, indefinite retention rights, or fee acceleration surviving. "Backups can't be selectively deleted" → accepted; that is why the fallback is cycle-based expiry plus a certificate, which their own Sch. 5 ¶3 already gestures at.
Security & breach notice
9.1–9.4, Sch. 4 ¶3
ISO 27001 maintained; annual SOC 2 Type II on request under NDA; single standard: notice ≤48h from awareness of confirmed or reasonably suspected incidents affecting Customer Data; no degradation of Sch. 4 measures. 72h from awareness (matching their own Sch. 4), executive summaries of pen tests annually. Vendor-controlled "confirmation" trigger or 10-business-day clock — we cannot meet DPDP Act timelines under it. "Report distribution is a security risk" → NDA + watermarked summaries is market standard; refusal signals absence of the reports.
Suspension & termination
18, 20, 21.2
Suspension only for material security/AUP violations or 30-day payment default, notice first where lawful, scoped, fees abate after 5 days; mutual termination for material breach of any obligation. Keep security-ground immediacy; delete "reputational harm" and "commercially impractical"; cap suspension at 30 days then either party may terminate with refund. Suspicion-based suspension with continuing fees and no outer limit, or "reputational harm" as a termination ground. "We must protect the platform" → the fallback preserves exactly that; the deleted grounds protect their brand, not the platform.
Precedence & policies
27.9, "CloudFlow Policies" defn.
Main body prevails over schedules and all policies; Order Form amends only expressly named clauses; policy updates on 30 days' notice, never reducing our rights; AUP frozen as at signature date attached as exhibit. Operational policies may evolve but any material adverse change gives a termination right. Online policies or the Order Form silently overriding negotiated terms. "We can't run one platform under bespoke policies" → we are not asking for bespoke operations, only that the signed contract beats the website.
Subprocessors
8.3
30 days' email notice; unresolved objection = termination + refund for affected services; full liability for subprocessor acts. 14 days' notice via subscribed mailing list; liability as for own acts but within the (new) caps. Website-only notice with a discover-it-yourself objection window. "List changes too often" → a mailing list costs nothing; their current 10-day objection right already presumes we monitor it.
Bargaining chips We can concede: Singapore law/SIAC seat (keep, but make interim-relief court access mutual — Cl. 26.4); a case study under Cl. 27.5 with pre-approval rights, offered as a sweetener once data terms land; net-30 → net-45 is our ask to trade away; acceptance-window extension (Cl. 3) can be traded down to 10 business days; we can accept the 99.5% credit threshold if the chronic-failure termination right is added.
5
Judgment Stress Test
"They won't move on the liability cap or the data-use licence. Should we sign?"
Model answer

No — not on those two terms as they stand. Renewal notice and exit assistance were real issues, and getting them is progress, but they are the cheapest concessions on the table: they cost CloudFlow nothing until year three. The two points they are refusing to move are the two that define who bears the catastrophic risk in this deal, and both cut against the stated premise of the engagement — that protection of confidential and personal data is critical.

Here is the practical arithmetic. With the cap intact, our maximum recovery for a platform-caused data breach is about USD 105,000 (Cl. 15.3). Our realistic downside from a breach affecting 1,200 employees plus customer and payment-related records — DPDP Act penalties, notification and remediation costs, customer contract claims, and the uncapped indemnity we owe them under Cl. 14.5 — is an order of magnitude larger. Signing means self-insuring their security failures while paying them USD 1.35M for the privilege. The data-use licence compounds it: even a flawless security record doesn't protect us if our data is, by contract, flowing into their models and unnamed third-party AI providers irrevocably and forever (Cl. 7.2, 12.3, 21.4). That is not a risk that materialises rarely; it operates every day of the term.

What I would do instead of walking away immediately: make one final, narrow offer that reframes both issues as insurance rather than drafting. (1) On liability: keep their 3-month general cap if they insist, but carve out a super-cap of 2x annual fees for Security Incidents and Cl. 8–10 breaches, backed by evidence of their cyber policy under Cl. 16 — this converts the ask from "change your risk model" to "stand behind your insurance," which vendors can often accept when a headline cap change is politically impossible internally. (2) On data: accept the licence for service delivery in full, but require training/product-improvement use to be off by default with an opt-in toggle, which their own Cl. 12.1 workspace controls suggest is technically trivial. If they refuse both of those, the refusal itself is information: it tells you the training right and the risk transfer are core to their business model, not drafting inertia — and that this vendor is the wrong home for this data.

If the business insists on proceeding anyway, the minimum conditions I would attach are: written confirmation (email suffices) that AI-training features will be disabled for our tenant; a certificate of their cyber insurance with limits; go-live restricted to non-sensitive workflows for the first six months while a parallel exit plan is maintained; and a diarised non-renewal notice for the earliest possible window. But be clear-eyed: those are mitigations of a bad allocation, not fixes. My recommendation remains that we do not sign while both terms stand. Assumption flagged: I am treating the business value of this specific platform as replaceable — if there is genuinely no substitute vendor, that changes the leverage analysis, not the risk analysis.