Skip to content

Systems and records

Aggregated and usage data clauses: what vendors can do with your data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An aggregated or usage data clause lets a software vendor use data about how you use its service, and often combined or de-identified versions of your records, for its own purposes. Its reach depends on four definitions: usage data, aggregated, de-identified and purpose. Narrow each one at signing or renewal, and have a written fallback ready when the vendor refuses.

Key takeaways

  • Usage data clauses cover data about how you use a service; aggregated and de-identified data clauses can reach your content itself.
  • The definitions of usage data, aggregated, de-identified and purpose decide a clause's reach more than its heading.
  • Vendor rights in aggregated data often survive termination, so exporting and deleting at exit may not end the vendor's use.
  • An admin setting that turns off AI training helps, but settings change with the product; the contract is what holds the vendor to it.
  • Vendor rights over your records can affect what you may promise in your own data license, so review them before any licensing talk.

What aggregated and usage data clauses allow#

Aggregated and usage data clauses give a software vendor rights in data that is not plainly customer data, so it can operate, secure, improve and sometimes market its service. Usage data usually means logs and metrics about how the service is used: logins, feature clicks, performance and errors. Aggregated or de-identified data clauses go further, because the raw material can be your records themselves, combined with other customers' records or stripped of identifiers.

Most clauses pair the grant with a promise that the result will not identify you or any individual. That promise is the heart of the clause, and its wording varies widely. Some vendors commit to a recognized de-identification standard and a ban on re-identification; others say only that the data will be anonymous.

Vendor AI features have raised the stakes. A clause written for product dashboards can be read, after a terms update, to cover model training unless the contract limits purpose.

Five clause patterns and how far each reaches#

Five clause patterns cover most of what a general counsel will see in vendor paper. The pattern matters more than the label at the top of the clause, so classify each clause by what it lets the vendor do, not by what it is called.

Five clause patterns and how far each reaches
PatternTypical wording, in substanceWhat the vendor can doConcern level
Service metadata onlyVendor may collect usage data about the service; usage data excludes customer contentMonitor, secure, bill and improve the productLow
Aggregated statisticsVendor may combine customer data with other customers' data into statistics that identify neither customer nor individualsBenchmarks and product analytics across its customer baseLow to moderate
De-identified data for any purposeVendor owns de-identified data derived from customer data and may use it for any lawful purposeBuild and license datasets drawn from your recordsHigh
Derived data and insightsVendor owns derivatives, insights and models created from use of the serviceKeep outputs and learned patterns after you leaveHigh
AI and model improvementVendor may use customer data to train, test and improve models and featuresTrain models on your content, sometimes for all customersDepends on scope and opt-out

Four definitions to read before the grant#

Four definitions decide whether a clause stays narrow: usage data, aggregated, de-identified and purpose. Read them before the grant language, because the grant is usually broad and the definitions do the limiting.

Then check the supporting terms. A survival clause can keep the vendor's rights alive after termination. A change-of-terms clause can let the vendor update online terms incorporated by link. A data processing agreement may restrict personal data more tightly than the main agreement, and an order-of-precedence clause decides which wins.

  • Usage data: does the definition expressly exclude customer content, files, inputs and outputs, or only say it concerns the service?
  • Aggregated: must your data be combined with data from many customers, or can a single customer's records count once totaled or summarized?
  • De-identified: does the vendor commit to a recognized standard, technical controls and a ban on re-identification, covering both your company and individuals?
  • Purpose: is use limited to providing and improving the service you buy, or open to any lawful purpose, including licensing to third parties?

Negotiation asks and fallbacks#

Negotiation works best when each ask has a fallback ready, because many vendors will not change a clause shared across their whole customer base. The goal is to keep your content and your customers' personal data out of uses you did not buy.

Raise these points at renewal or during a new purchase, when the vendor wants the signature. Record every agreed change in the order form or an addendum, because a sales email does not amend the master agreement.

Negotiation asks and fallbacks
Your first askFallback if the vendor refuses
Usage data excludes all customer content, files, inputs and outputsContent may be processed only transiently, for security and troubleshooting
Aggregated data must combine many customers and identify noneWritten confirmation that no output identifies your company, your customers or individuals
No vendor ownership of de-identified data derived from your contentUse limited to the vendor's own service, with no sale or license to third parties
No training of AI models on your contentTraining only for features delivered to you, with an admin opt-out the contract honors
No unilateral changes to data-use termsAdvance notice of changes, plus a right to terminate and export without penalty
Vendor rights end at terminationRights limited to aggregates created before termination, with no new derivation afterward

Why vendor rights matter if you license your own records#

Vendor rights matter when you license your own records because a license usually includes promises about control and prior use. Buyers commonly want written assurance that the supplier controls the records and can license them, plus disclosure of any existing grants that overlap. A vendor's broad right in de-identified data is one such grant.

The overlap is rarely fatal, but it should be known. If a help desk, CRM or project platform vendor can build datasets from your records, say so in diligence rather than have it discovered later. Your own customer contracts and privacy notices matter too: a vendor clause that allows something your customer agreements forbid creates a gap that you, not the vendor, may have to answer for.

A review checklist for your vendor stack#

A review checklist for the vendor stack turns clause reading into a repeatable task that legal, IT and procurement can share. Start with the systems that hold the most customer content, not the largest contracts.

  • List every system that holds customer content or internal records: help desk, CRM, project platform, ERP, call recording, chat and AI meeting notes.
  • Collect the documents that govern each one: master agreement, order form, data processing agreement, AI addendum and any online terms incorporated by link.
  • Save a dated copy of each set of online terms, because those pages change.
  • Mark each clause by pattern: service metadata, aggregated statistics, de-identified data for any purpose, derived data or AI training.
  • Check admin settings for AI and data-sharing toggles, and record their current state.
  • Put upcoming renewals on a negotiation calendar, and record each ask and outcome in the contract register.

Illustrative: a 3PL reviews its TMS and help desk terms#

Illustrative: a fictional third-party logistics company runs a hosted TMS, a help desk and a CRM. Its general counsel reviews all three before a renewal cycle. The help desk terms limit usage data to service metadata and offer an AI opt-out that the order form references. The CRM uses aggregated statistics language with a stated de-identification standard.

The TMS terms are the problem: the vendor owns de-identified shipment data derived from customer records and may use it for any lawful purpose. At renewal, counsel asks for no vendor ownership of derived data. The vendor refuses but accepts the fallback: use limited to its own benchmarking and product, no sale or license to third parties, and written notice before any change. The company records the outcome in its contract register and flags the TMS records for extra review before any future licensing discussion.

How SourceX looks at vendor data clauses#

SourceX reviews vendor data clauses in the Rights step of the SourceX five-step transaction, for the systems that hold records a supplier is considering for licensing. Clauses that grant a vendor broad rights are flagged for the supplier's counsel rather than resolved by SourceX.

Where a package proceeds, the licensing rights section of the SourceX Evidence Packet notes the systems the records came from and any vendor terms that bear on them, so the supplier's approval rests on a documented review.

Frequently asked questions

Is aggregated or de-identified data still personal data?

It can be. Privacy laws such as GDPR and the CCPA set their own tests for when data stops being personal, and data a vendor calls de-identified may not meet them if it can be linked back to people. Whether a vendor's practice meets a given law is assessed with counsel for your situation.

Can a vendor change these clauses during the contract?

Sometimes. Many SaaS agreements incorporate online terms by link and let the vendor update them, often with notice. Check the change-of-terms clause, whether updates apply mid-term or only at renewal, and whether you can terminate if a change is material. Keep dated copies of the terms in effect when you signed.

Does turning off an AI setting override the contract?

Not by itself. An admin setting controls how the product behaves today, while the contract defines what the vendor may do. If the setting is your main protection, ask for the order form or an addendum to reference it, so a later product change cannot quietly remove it.

Do these rights survive after we leave the vendor?

Often, for data already aggregated or de-identified. Survival clauses commonly keep those rights alive after termination, and deletion obligations may cover only customer data as defined. Ask for the rights to stop at termination or, as a fallback, for no new derivation once your data is returned or deleted.

Who in the company should own this review?

General counsel or outside counsel should own the clause reading, with procurement keeping the contract register and IT confirming admin settings. The business owner of each system should confirm what records it actually holds, because the risk depends on content, not on the size of the contract.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify