
Technology companies develop products, business models, and processes that are constantly evolving. Legal issues rarely arise in isolation: contracts, data protection, cloud usage, software and licensing rights, platform structures, and the use of artificial intelligence are all intertwined. In our Tech, SaaS & AI Companies practice area, we focus on the legal framework for digital products and scalable business models.
Products change faster than contracts
Tech companies develop their products iteratively. Features, pricing models, integrations, and technical dependencies are constantly changing. Legal documentation must therefore be designed in such a way that it can evolve alongside the product and does not have to be rewritten from scratch every time a technical change is made.
Scalability Raises New Legal Issues
What works for a small number of pilot customers can become legally complex as the company expands internationally. Standardized contracts, data protection processes, licensing models, and internal governance must be designed in such a way that they remain resilient even as the customer base grows and new markets are entered.
Technology and the Law Are Intertwined
For SaaS, cloud, and AI products, the legal assessment depends heavily on the technical architecture. Key factors include what data is processed, which providers are involved, how systems communicate with one another, and which party exercises what level of control over data and functions.
AI Raises Additional Governance Issues
The use of artificial intelligence raises additional questions regarding transparency, accountability, data protection, rights to data and content, model usage, and internal control mechanisms. To date, Switzerland has no overarching, specific AI legislation; AI applications are primarily governed by existing areas of law and sector-specific regulations. However, regulatory developments are underway. For companies with ties to the EU, the EU AI Act may also be relevant.
SaaS and software models require clear provisions regarding scope of services, availability, usage rights, updates, support, liability, and termination. Equally important are issues related to data usage, data export, and exit. In standardized models, the SaaS agreement, terms and conditions, service level agreements, data processing agreement (DPA), and data protection documentation should be aligned with one another.
Digital products are often based on cloud infrastructure and specialized third-party providers. This creates dependencies in terms of hosting, data processing, security, and availability. Contracts should therefore address not only prices and services, but also sub-outsourcing, audit and oversight rights, incident management, data locations, and exit scenarios.
Tech companies often process customer, usage, and telemetry data across multiple systems and countries. Key considerations include transparency, data processing, international data transfers, the division of roles between data controllers and data processors, and privacy by design. For companies operating internationally, the GDPR may also apply in addition to the Swiss Data Protection Act (DSG).
For software and AI products, contracts should clearly define the rights pertaining to source code, models, documentation, and further developments, as well as the rights of use that are granted. Other relevant factors include open-source components, third-party licenses, rights to training and input data, and contractual provisions regarding generated content.
Companies must understand what AI systems they are developing, procuring, or deploying, and what risks are associated with them. This includes internal responsibilities, approvals, data protection, transparency, vendor vetting, documentation, and guidelines for employees. For EU-related activities, classification under the EU AI Act may also be required.
Platforms and digital ecosystems often connect multiple user groups, providers, and technical service providers. From a legal perspective, it is particularly important to clarify who provides which services to whom, how responsibilities are allocated, and what rules apply to content, payments, account suspensions, or third-party providers.
We start by examining how the product actually works. We look at user groups, data flows, technical dependencies, the sales model, and the role of external providers.
Not every legal issue needs to be fully resolved before the initial launch. What matters most is identifying regulatory and economically significant risks early on and prioritizing legal work appropriately.
Terms and Conditions, SaaS agreements, Data Processing Agreements (DPAs), service level agreements, privacy notices, and internal policies should be consistent with one another and reflect the actual product process.
As new markets, enterprise customers, AI capabilities, or additional vendors emerge, legal requirements also change. Documentation and governance should therefore be updated regularly.
Companies are increasingly integrating generative AI into development, support, marketing, and internal processes. This raises questions about confidential information, personal data, rights to inputs and outputs, and internal approvals.
As the use of AI increases, a single AI policy is often no longer sufficient. Responsibilities, risk categories, vendor reviews, approvals, and documentation requirements must be integrated into the existing governance framework.
Larger customers are increasingly setting detailed requirements regarding data protection, security, business continuity, audit rights, and sub-processors. For SaaS providers, a consistent contractual, data protection, and governance structure is therefore a key component of scalability.
As soon as products are offered across borders, additional requirements related to data protection, AI, contract law, or sector-specific regulations may come into play. The legal structure should therefore make it clear early on which markets require special adjustments.
We consider not only contract clauses, but also product logic, data flows, and technical dependencies.
Legal structures should be designed to work not only for the next contract, but also to support growth and standardization.
SaaS, the cloud, and AI intersect with contract law, data protection, and governance. We ensure these areas are aligned.
We help structure AI risks and establish governance in a way that ensures it remains practical within the organization.
Not every legal issue is equally important. We prioritize issues based on the risks and implications they pose for the product and the business.
Tech products are constantly evolving. That's why we also provide support for the ongoing adaptation of contracts, policies, and governance.