What We Learned Reviewing 2,300 Vendor Contracts
We looked at anonymized patterns across every contract processed on Conlegie this year. A few findings surprised even us.
8 min read
Every contract that runs through Conlegie's review engine produces a set of flags, tied to a clause category and a severity. Individually, that's just a redline for one customer. In aggregate, stripped of anything identifying, it's a dataset about what actually goes wrong in commercial contracts — not what legal textbooks say goes wrong, but what shows up in real vendor paper, real SOWs, and real customer agreements from companies with 10 to 500 employees.
We pulled the anonymized numbers across roughly 2,300 contracts processed on the platform through the first half of this year. A few patterns were exactly what you'd expect. A couple weren't.
Finding 1: Liability and indemnification gaps dominate, but not evenly
Across all flagged contracts, issues in the liability and indemnification categories accounted for close to a third of all high-severity flags — unsurprising, since these are the categories with the highest financial downside. What was less expected: contracts under €25,000 in annual value were, proportionally, more likely to carry an uncapped indemnification clause than contracts above €100,000. Our working theory is that larger deals get more scrutiny by default — more stakeholders touch them — while smaller contracts get rubber-stamped precisely because the dollar amount seems too small to justify a careful read. The risk in the clause doesn't scale down with the deal size, even though the attention paid to it does.
Finding 2: Auto-renewal terms are getting shorter, not longer
We expected notice windows to cluster around 30 or 60 days, roughly evenly. Instead, 15-day notice windows showed up nearly as often as 30-day ones, particularly in marketing, martech, and data-tooling vendor agreements — categories where subscription-style pricing and fast-moving product roadmaps seem to push vendors toward tighter renewal terms. For buyers, this is a quiet trend worth knowing about: the operational discipline required to track renewal dates has gotten harder over the same period that renewal terms have gotten less forgiving.
Finding 3: Data protection gaps cluster by company stage, not industry
We assumed data-protection flags — personal data referenced without DPA terms — would cluster in obviously data-heavy industries: healthtech, adtech, HR software. They did show up more there, but the strongest predictor turned out to be company stage, not sector. Contracts from companies in their first 18 months after founding were flagged for missing data-processing terms at roughly twice the rate of companies past that mark, regardless of industry. Our read: DPAs are usually the first "grown-up" legal document a company adopts, and there's a lag between the moment a startup starts handling real customer or employee data and the moment its contract templates catch up.
Finding 4: The cleanest contracts weren't the longest ones
We half-expected contract length to correlate with quality — more pages, more careful drafting. It didn't, at least not linearly. The lowest-risk-score contracts in our dataset (a mix of mutual NDAs and balanced MSAs, largely from companies with dedicated legal ops functions) were often shorter than average, not longer. They tended to favor plain, specific language — stated caps, stated notice periods, stated remedies — over long defensive boilerplate. The correlation we did find was with specificity: contracts that stated a number (a cap, a day count, a percentage) instead of a vague standard ("reasonable," "as needed," "promptly") scored measurably lower on risk, category for category.
What this means if you're reviewing your own contracts
- Don't let deal size determine review depth — the riskiest clauses don't get smaller with the contract value.
- If you haven't checked your notice periods recently, do it now; the norm has been quietly shrinking.
- If your company has grown past its first year or two, your data-processing terms are the most likely thing to have fallen out of date.
- When redlining, replace vague standards with specific numbers wherever you can — it's the single strongest signal of a well-negotiated contract we found in the data.
We'll keep publishing these when the sample size gets large enough to say something new. If there's a specific pattern you'd want us to look at, our team reads everything that comes in through the contact page.