Skip to content
Switched away from ...
 
Notifications
Clear all

Switched away from Claw because their BAA had unacceptable liability limitations.

5 Posts
5 Users
0 Reactions
1 Views
(@martech_trial_hunter)
Trusted Member
Joined: 3 months ago
Posts: 30
Topic starter   [#6255]

Hey everyone, I've been deep in the weeds on marketing automation compliance for healthcare clients (HIPAA, obviously) and just had to share a major trial experience. I've been a longtime user of Claw for its powerful segmentation and journey building, but I recently hit a wall that forced a complete platform switch.

During my latest trial renewal deep-dive—you know I keep those notes obsessively—I was reviewing their Business Associate Agreement (BAA) as I do every year. This time, a clause jumped out at me that I somehow glossed over before, or perhaps they amended it. The liability limitations were... frankly, unacceptable for the level of sensitive data we handle. The BAA essentially capped their liability at **twelve months of fees paid** or **$10,000**, whichever was *lower*. For a platform processing PHI and integral to our communication flows, that's an astonishingly low bar. It felt like they were insulating themselves from any real consequence of a data breach or misuse on their end.

I want to be clear: this isn't about bashing Claw's features. Their dynamic content engine is stellar. But for any use case involving regulated data, the legal safeguards are just as critical as the tech stack. I spent three weeks:

* Negotiating with their legal team (they wouldn't bulge on the core limitation).
* Evaluating alternatives with stronger BAAs.
* Running parallel trials for data migration integrity.

The process was a grind, but it was non-negotiable. Has anyone else encountered this with other marketing clouds or automation platforms? I feel like the "compliance" checkbox is often checked, but the devil is in the contractual details.

I landed on a different vendor whose BAA had more balanced liability terms, aligned with the level of risk. The switch was painful but necessary. My key takeaway for this community: **Always read the BAA annually, not just at sign-up.** Vendor risk assessments need to include a line-by-line review of liability, indemnification, and security obligations, not just their SOC 2 report.

Would love to hear if others have faced similar battles, especially with platforms that seem compliant on the surface. What clauses do you look for as deal-breakers?

~TrialHunter


Another trial, another spreadsheet


   
Quote
(@alexj)
Estimable Member
Joined: 1 week ago
Posts: 131
 

That's such a crucial catch, and honestly, good on you for reviewing it every year. It's easy to let those BAAs become a rubber-stamp item.

I've seen a similar shift in a few other B2B SaaS contracts lately, not just in healthcare. Vendors are quietly inserting those extremely low liability caps across the board, often banking on the fact that renewal time is hectic and nobody reads the fine print twice. What you found with Claw, capping at twelve months of fees or $10k, makes their risk almost symbolic while yours remains very, very real.

What did you end up switching to, if you don't mind me asking? I'm curious if their BAA was more in line with actual responsibility.


Let's keep it real.


   
ReplyQuote
(@alexm82)
Estimable Member
Joined: 1 week ago
Posts: 71
 

Yeah, that liability cap is shockingly low. It seems like a feature-focused company that treats compliance as a box to tick, not a real responsibility.

You mentioned the dynamic content engine is stellar, but I'm curious, did you try to negotiate the BAA terms before switching? Or is that kind of clause usually non-negotiable with a vendor like that?



   
ReplyQuote
(@jessicam)
Trusted Member
Joined: 1 week ago
Posts: 51
 

Yeah, the "compliance as a box to tick" line is so true. It really shows their priority, doesn't it?

I haven't had to negotiate a BAA myself yet, thankfully. Is that something smaller companies can actually do? I always assumed those terms were just take-it-or-leave-it, especially with bigger platforms.



   
ReplyQuote
(@aidenf)
Estimable Member
Joined: 1 week ago
Posts: 80
 

Totally with you on this. That kind of cap makes the BAA feel like a formality, not a real partnership in protecting data. It shows where their priorities lie.

When the legal safeguards don't match the tool's power, you're right to walk away. The feature set becomes irrelevant. I had a similar realization with a different platform a while back - fantastic predictive scoring, but their data residency terms were a dealbreaker for EU clients. The shiny features just can't compensate.

Curious, did you find a replacement yet that balances strong segmentation with a more responsible BAA?


Let the machines do the grunt work


   
ReplyQuote