Software companies
Archive or delete: the cost of keeping old SaaS data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Whether to archive or delete old data depends on four tests applied in order: legal need, risk, carrying cost and possible value. Delete when no law, contract or hold requires the data and it has little value; archive cheaply when any requirement or credible value exists. Never delete before counsel confirms there is no hold or retention duty.
Key takeaways
- Keeping a SaaS subscription alive for read-only access is often the most expensive way to keep old data.
- Legal and contractual retention needs come first; cost and value decide only among the options that remain.
- Old data carries risk as well as cost, through breach exposure, discovery burden and privacy obligations.
- Possible value includes AI licensing, which depends on rights, linkage and history rather than raw volume.
- A cold archive in company-controlled storage is reversible; deletion is not.
What does it cost to keep old SaaS data?#
Keeping old SaaS data costs more than the storage line suggests, because most of the cost hides in subscriptions, staff time and risk. A help desk kept alive after a migration so agents can look up old tickets is booked as software spend, not as the price of keeping records, so finance rarely sees it as a retention decision.
List every cost before comparing options. The categories below appear in most software companies that have retired a CRM, help desk, wiki or code platform.
| Cost | Where it shows up | Why it is often missed |
|---|---|---|
| Seats kept for read-only access | SaaS invoices | Booked as software spend, not records cost |
| Storage and overage charges | Vendor bills | Bundled into plan pricing |
| Admin time for access, users and security reviews | IT payroll | Never invoiced separately |
| Discovery and data subject requests | Legal fees and staff time | Appears only when a request arrives |
| Security exposure from stale accounts | Insurance and incident response | Probable, not certain, so easy to ignore |
| Cold archive storage | Cloud bill | Usually overlooked as an alternative |
Live, read-only or cold: three ways to keep data#
Kept data sits in one of three tiers, and the cheapest tier that meets the legal need usually wins. A live system keeps full functionality at full cost. A read-only license or reduced plan keeps the original interface and search at lower cost but still depends on the vendor's pricing and policies. A cold archive in your own storage costs least and removes that dependence, at the price of a less convenient interface.
The right tier turns on how often people need the records and how they search them. Records consulted daily belong in a live system; records needed for an audit, a dispute or a one-time review rarely justify more than a cold archive with a good index and a documented schema.
The four tests, in order#
The four tests are legal need, risk, cost and possible value, and the order matters. Legal need can override every other test, risk shapes how data is kept, and cost and value decide between archive and deletion only once the first two are settled.
Each test has a different owner. Counsel answers legal need, security and privacy leads answer risk, finance answers cost, and the business owner of the records answers possible value.
- Legal need: tax and accounting retention, contract terms, regulatory requirements, open disputes and any legal hold. For tax records, the IRS says to keep records that support income, deductions or credits until the period of limitations for that return runs out, generally 3 years, longer in some cases.
- Risk: personal data, confidential customer information, credentials in old records and who can still log in.
- Cost: subscriptions, storage, admin time and the effort of answering requests that touch the data.
- Possible value: operational reuse, analytics, audit support, and licensing records to AI developers where rights allow.
The decision matrix#
The decision matrix turns the four tests into a default action for each system. It does not replace judgment, but it stops the two most expensive errors: paying indefinitely for a tool nobody uses, and deleting records the company was obliged to keep or could have used.
| Legal need | Risk | Possible value | Default decision |
|---|---|---|---|
| Yes | Any | Any | Keep for the required period in a controlled archive; reassess when it ends |
| Unknown | Any | Any | Hold deletion and get a counsel review |
| No | High | Credible | Archive with tight access controls; assess value before any reuse; set a review date |
| No | High | Low | Delete on a documented schedule |
| No | Low | Credible | Move to a cold archive and assess value |
| No | Low | Low | Delete, or keep only a summary, and record the decision |
How to judge possible value without inventing a number#
Possible value can be judged from the shape of the records rather than from a price. Linked records that connect a request to a decision and an outcome, several years of continuous history, human-written reasoning and clear rights all point to credible value; isolated exports with no outcomes point the other way.
The drivers in the SourceX Enterprise Data Value Framework give a CFO a vocabulary for this: uniqueness, domain expertise, human-generated signal, scale, recency, data cleanliness, rights and AI utility raise value, exclusivity raises price, reproducibility reduces value, and preparation cost and privacy burden reduce net value. A CFO does not need a figure to use them; a qualitative rating per system is enough to separate archive candidates from deletion candidates.
Illustrative: a marketing analytics software company retires three tools#
Illustrative: a fictional marketing analytics software company had three legacy systems on its books after a platform consolidation: a help desk it had replaced, a CRM inherited with an acquired product and a self-hosted wiki nobody edited. The CFO ran each through the four tests.
The old help desk had no legal requirement, moderate risk from customer names and credible value, because tickets linked to Jira issues and releases; it was exported to a cold archive and the subscription ended. Counsel found that some CRM records supported customer contracts and invoices, so contract-linked accounts and deals were archived while unconverted leads were deleted on a documented schedule. The wiki was exported and archived cheaply, since it cost little to keep. All three subscriptions ended, and one indexed archive replaced them.
Mistakes that turn a cleanup into a loss#
The costliest cleanup mistake is deleting before an export has been verified. Close behind it is deleting while a legal hold is in place, which may create far larger problems than the storage it saves.
Letting a subscription lapse is a quieter version of the same mistake: it is a deletion decision made by default. Vendors publish what happens after cancellation, and the windows are short. The table summarizes vendor documentation as of October 2026; your own contract may differ, so check it before giving notice.
Two other errors are common. One is assuming the vendor keeps backups you can ask for later. The other is building an archive with no owner, no index and no record of what it contains, which nobody can use when a request finally arrives.
| System | What the vendor documents after cancellation | Implication for the archive decision |
|---|---|---|
| Zendesk | Permanent deletion of service data starts 90 days after cancellation and cannot be reversed | Finish and verify the export before giving notice |
| Salesforce | Data made available for export only if requested within 30 days after termination | Export while licensed; do not rely on the post-termination window |
| HubSpot Sales, Service and Operations Hub | No access to customer data after termination or expiration | Retrieve data before the subscription term ends |
| Atlassian cloud (Jira, Confluence) | Site deactivated 15 days after the period ends; paid-plan data retained 60 days after deactivation | Short reactivation window, not an archive |
| Freshdesk | Account and data permanently deleted 14 days after the subscription end date; exports can take up to 10 business days | Start the export well before the end date |
| Intercom | Cancelling keeps stored data, but it cannot be viewed until the subscription restarts | Paying again is the only route back to the interface |
How SourceX fits into an archive decision#
SourceX can help answer the possible-value test without moving any data. The fit check uses metadata only, such as system names, years of history and record families, and SourceX reviews it against the drivers of the SourceX Enterprise Data Value Framework, giving qualitative ratings rather than a price.
Should the company later license some of those records, the work runs through the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, and the records are licensed, not sold, so ownership stays with the company. SourceX does not take custody of big archives: multi-terabyte datasets remain in the company's own storage or travel on encrypted drives.
Frequently asked questions
Is deleting old data always the lower-risk choice?
Not always. Deletion removes breach and discovery exposure, but deleting records the company must keep, or records under a legal hold, creates its own legal risk. Deletion also removes evidence you may need in a dispute or audit. The matrix puts legal need first for that reason, and counsel signs off before any deletion.
Who should make archive or delete decisions?
Finance usually leads because the costs land there, but the decision needs counsel for legal need, security or privacy leads for risk, and the business owner of the records for value. Record each decision with the system, the tests applied, the outcome, the owner and a review date.
How often should archive decisions be revisited?
Revisit them when a retention period ends, when a system is retired or replaced, after an acquisition, and when the company's plans for its data change. A short annual review of the archive index also catches archives whose owners have left the company.
Does possible AI licensing value justify keeping everything?
No. Possible value is the last of the four tests, and it only applies to records with credible signals: linked requests, decisions and outcomes, several years of continuous history, and rights the company can document. Keeping every system on the chance it might be licensed adds cost and risk; archive the record families that pass the earlier tests and show those signals, and delete the rest on schedule.
What format should a long-term archive use?
Open, documented formats that do not depend on the original vendor: CSV or JSON for records, the original file types for attachments, and a written schema that explains fields, codes and relationships. Keep record IDs and links between records, and test that a sample can be read without the old system.
Sources
- The IRS says to keep records supporting an item of income, deduction or credit until the period of limitations for that return runs out: generally 3 years, with longer periods in specified cases. Source
- Under Zendesk's Service Data Deletion Policy, an automated process that permanently deletes the account's Service Data starts 90 days after the account is canceled or terminated, and once it starts it cannot be reversed. Source
- Under the Salesforce Main Services Agreement, if the customer asks within 30 days after termination or expiration, SFDC makes Customer Data available for export or download; after that period SFDC has no obligation to maintain or provide it. Source
- HubSpot's Product Specific Terms strongly recommend retrieving Customer Data before the Subscription Term ends; for Sales, Service, CMS and Operations Hub subscriptions, HubSpot will not provide any access to Customer Data after termination or expiration. Source
- Atlassian states the site remains accessible for 15 more days after the subscription period ends before deactivation. Source
- After a cloud site is deactivated, data is retained for 60 days for Free, Standard, Premium or Enterprise plans. Source
- Freshworks partner support says Freshdesk permanently deletes the account and its data 14 days after the subscription end date, and advises exporting first because the export can take up to 10 business days. Source
- Intercom says cancelling a subscription does not remove any data and stored information is kept if the customer re-subscribes, but once the subscription has ended the customer cannot see the data until it is restarted. Source
Related resources
- InsightCan a distributor license its pricing and quote history?
- InsightHow to design a data retention policy that keeps records licensable
- InsightLegacy data after system consolidation: keep, archive, license or delete?
- QuestionShould companies sell or license their data?
- QuestionDo AI labs buy legal documents?
- SolutionEnterprise data: the records of how organizations actually work
See if your company qualifies
A short company assessment. No data uploads are needed.