Skip to content

Private equity and portfolios

Acquired SaaS customers asking about AI use of their data: how to respond

By SourceX Editorial · Updated

Short answer

When a customer asks if you use their data for AI, answer for that product and that contract, and separate three things: the customer's own content, usage and aggregated data, and the vendor's own operational records. Customer content should never be licensed to outside parties without permission. Confirm the facts per product before sending any template.

Key takeaways

  • Answer per product and per contract, because acquired products rarely share one set of terms.
  • Customer content, aggregated usage data and the vendor's own operational records each need a separate statement.
  • AI features that send customer content to an outside model provider should be named in the answer, usually as a subprocessor.
  • One owner and one approved answer library keep sales, support and security teams from improvising promises.

How should you answer a customer who asks about AI use of their data?#

The answer to a customer asking about AI use of their data should be short, factual and specific to the product and contract that customer holds. Customers are usually asking two questions at once: does an AI feature process my records, and could my records end up training a model that others use.

For a software holding company, the trap is answering at group level. One acquired product may have an AI summary feature built on an outside model provider, another may have no AI at all, and a third may run under a master agreement the founder negotiated years before the acquisition. A group-wide sentence that is true for one product can be false for another.

Vague wording is what turns a routine question into a trust problem. TechCrunch reported on May 17, 2024 that Slack drew user backlash after its privacy principles were found to allow customer data to be used for its machine-learning models unless an organization emailed to opt out; Slack responded that it does not use customer data to train its generative AI large language models. The lesson for a holdco is to say which models, which data and which setting, product by product.

Three kinds of data your answer must separate#

Separating customer content, usage data and the vendor's own records is the core of a good answer, because each starts from a different default position.

The third row needs care. Support tickets are the vendor's record of its own work, but they often contain customer screenshots, exports and pasted data. Treat every ticket as mixed until preparation has removed customer content and personal details.

Three kinds of data your answer must separate
Data typeExamples in a vertical SaaS productDefault position in the answer
Customer contentWork orders, invoices, client lists, files and notes customers enterProcessed only to provide the service; not used to train shared models or licensed without the customer's permission
Usage and aggregated dataFeature usage events, performance metrics, de-identified benchmarksState what the terms allow, how the data is aggregated and that it does not identify the customer
Vendor's own operational recordsInternal engineering tickets, release notes, sales CRM history, support processesRecords the vendor controls; describe any outside use only after customer content is excluded

Facts to confirm per product before you reply#

Confirming facts per product before replying protects the group from a written statement it cannot stand behind. Most of the work is a short checklist the product lead and counsel complete once and update whenever something changes.

If any item comes back unknown, hold the reply and tell the customer when to expect it. A short delay costs little; a confident answer that turns out wrong can become a contract dispute, and it tends to get repeated to other customers before anyone corrects it.

  • Which terms version and master agreement this customer signed, including any negotiated data clauses.
  • Which AI features are live, which are on by default and which this customer has switched on.
  • Which outside model providers or hosts process customer content, and whether they appear on the subprocessor list.
  • What the model provider's contract says about training on and retaining that content.
  • Whether the terms include an aggregated or de-identified data clause, and what it permits.
  • Whether the product has ever shared customer content with a third party other than service providers.
  • Who in the customer's account can switch AI features off, and where.

The response template#

The response template below works as a letter, an email or a security questionnaire answer. Replace the bracketed items with confirmed facts and delete any block that does not apply to the product.

Have counsel approve the template once per product, then let customer success and security teams send it without rewording. Edits should flow back into the master version, not live in individual inboxes.

  • Opening: Thank you for asking how [Product] handles your data in relation to AI. This answer applies to your agreement dated [date] and the current version of our terms.
  • AI features: [Product] offers [feature names]. When you use them, the relevant content is processed by [provider], listed as a subprocessor at [location], only to deliver that feature.
  • Training: We do not use your content to train AI models made available to other customers or third parties, and our provider is contractually restricted from doing so. [Adjust if the terms say otherwise.]
  • Aggregated data: Under [section] of our terms, we may use de-identified, aggregated usage data to operate and improve the service. This data does not identify you or your clients.
  • Controls: Your administrators can switch AI features off in [settings location]. Switching them off stops new content from being sent to [provider].
  • Our own records: Separately, [Company] keeps its own internal engineering and operations records. Any outside use of those records excludes your content.
  • Contact: Further questions can go to [owner], who maintains this answer.

Illustrative: a holdco answers a fleet customer's questionnaire#

Illustrative: a fictional software holding company owns three vertical products bought from their founders: a fleet maintenance system, a pest control scheduling tool and a property management accounting package. A large fleet customer sends a security questionnaire asking whether its maintenance records are used to train AI.

The group COO's team finds that the fleet product's work order summary feature calls an outside model provider, listed as a subprocessor, under a contract that bars training on inputs. The customer's negotiated agreement, signed before the acquisition, has no aggregated data clause, so the team deletes that block rather than citing the standard terms.

The reply goes out with the provider named and the switch-off setting described. The group then adds a product-specific AI section to each product's trust page, so the next questionnaire starts from published answers instead of a search through old contracts.

Keeping answers consistent across acquired products#

Consistency across acquired products comes from one owner, one answer library and a list of events that force an update. The owner is often the group COO's office or a group security lead, with counsel approving any change in wording.

Sales teams need a short version too. A brief spoken answer approved by counsel keeps account executives from improvising promises such as never using any data for anything, which the product's own features may contradict.

Keeping answers consistent across acquired products
EventWhat to update
New AI feature launched in a productThat product's answer, the subprocessor list and the trust page section
Model provider changedSubprocessor notice and the training and retention statements
Terms revised at renewalTemplate blocks that cite sections or versions
New acquisition closesA separate entry for the product with its legacy terms
Customer complaint or incidentAccuracy review of the answer before the next send

How SourceX treats customer content in acquired products#

SourceX treats customer content as excluded by default when a software company licenses records. In the Rights step of the SourceX five-step transaction, the product's customer terms are reviewed before anything is scoped, and records that customers created are left out unless the terms and permissions clearly allow otherwise.

What a vendor can usually consider licensing is its own operational history: engineering issues, code reviews, release notes and support processes, prepared so customer details and personal information are removed. That is the same line the customer answer draws, so the two stay consistent.

Frequently asked questions

Can we say we never use customer data for AI if we offer AI features?

Not accurately. If a feature sends customer content to a model to produce a summary or a suggestion, that is AI processing. The defensible statement is that content is processed to deliver the feature and is not used to train shared models, provided the contracts support it.

Do support tickets count as customer data?

Often in part. The ticket is the vendor's record of its own work, but attachments, screenshots and pasted exports may contain the customer's content and personal details. Treat tickets as mixed records and prepare them before any use beyond service delivery.

What if the previous owner's terms allowed broad data use?

A broad clause in old terms does not make every use wise or welcome. Review what the clause actually covers with counsel, check which privacy laws may apply, and weigh the effect on customer trust. Many groups narrow such clauses at renewal.

Should we update our terms instead of answering case by case?

Do both. Answers handle today's question, and clearer terms reduce tomorrow's. Negotiated agreements change slowly, so the answer library carries the load until renewals bring each customer onto updated language.

Do we need to tell customers if we license our own operational records?

It depends on what those records contain and what your agreements and privacy notice say. If customer content is excluded and personal details are removed, many companies still choose to explain the program in plain language. Review notice obligations with counsel.

Sources

  • TechCrunch reported on May 17, 2024 that Slack drew backlash after its privacy principles allowed customer data to be used to train machine-learning models unless an organization opted out by email, and Slack said it does not use customer data to train its generative AI large language models. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify