Skip to content

Software companies

Can a unilateral terms update bind enterprise customers on signed MSAs?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Usually not. A unilateral terms update rarely binds an enterprise customer on a signed MSA, because the amendment clause typically requires a signed writing and the order-of-precedence clause ranks the negotiated agreement above online terms. Vendors that want new data rights, such as AI training, generally need a signed amendment, a new order form or an opt-in addendum.

Key takeaways

  • Amendment, precedence and entire agreement clauses usually decide whether an online terms update reaches a signed MSA.
  • Policies incorporated by URL, such as acceptable use or support policies, are the main route by which online edits reach enterprise contracts.
  • FTC staff warned in February 2024 that adopting more permissive data practices through a surreptitious, retroactive terms change may be unfair or deceptive.
  • Signed amendments at renewal and opt-in AI addenda are slower but durable routes to new data rights.
  • Records your company creates itself, such as engineering issues and code reviews, usually do not depend on any customer terms change.

The short answer: the signed contract usually controls#

The signed contract usually controls because enterprise MSAs are built to resist unilateral change. Most contain an amendment clause requiring changes in a writing signed by both parties, an entire agreement clause that excludes other terms, and an order-of-precedence clause that ranks the MSA and order forms above any online terms.

Some vendors say so publicly. Zoom's blog on its 2023 terms change explained that updates to its online terms do not affect customers who buy under separate contracts, such as enterprises and regulated education and healthcare customers. That is the ordinary result wherever a negotiated agreement exists.

Courts decide these questions under state contract law and the exact wording, so outcomes vary. Use this page as a framework for reading your contracts, and have counsel review any update you plan to rely on.

Three clauses that decide the question#

Three clauses decide most cases: the amendment clause, the order-of-precedence clause and the entire agreement clause. A fourth, incorporation of online policies by reference, decides most of the exceptions, and the notice clause decides whether a change was even communicated properly.

Three clauses that decide the question
ClauseTypical wordingEffect on a unilateral update
Amendment or modificationChanges only by a written instrument signed by both partiesOnline updates generally do not amend the MSA
Order of precedenceMSA and order forms prevail over online terms and policiesConflicting online terms give way to the negotiated agreement
Entire agreementThe MSA is the complete agreement and supersedes other termsTerms outside the listed documents are excluded
Incorporation by referenceNamed policies apply as updated from time to timeChanges to those policies may apply, often within limits
NoticeHow and where formal notices must be sentA banner or release note may not count as notice

When a policy incorporated by URL can change#

A policy incorporated by URL can change when the MSA says it applies as updated from time to time, which is the main route by which online edits reach enterprise customers. Acceptable use policies, support policies, security documentation and sometimes data processing terms are incorporated this way.

Well-drafted MSAs limit that route. Common protections say updates may not materially reduce security or service levels, may not expand the vendor's rights in customer data, or take effect only at renewal. A vendor that places new AI training rights in a linked policy is testing those limits, and customer counsel watches for exactly that move.

Check where the data use language lives. If the MSA defines permitted use of customer data in its own body, a change to a linked policy generally cannot override it under the precedence clause.

What happened when vendors expanded data rights quietly#

Several well-known vendors that expanded data rights through terms updates retreated after public backlash, even where the legal position was arguable. In August 2023, after criticism of earlier changes, Zoom added a sentence to its terms saying it would not use audio, video or chat customer content to train its AI models without consent.

In July 2025, WeTransfer revised updated terms that had been due to take effect in August, removing language about using uploaded content to improve machine learning models and stating that it does not train AI on customer content. Regulators have noticed the pattern: in February 2024, FTC staff wrote that a company adopting more permissive data practices, such as using consumer data for AI training, and disclosing it only through a surreptitious, retroactive terms change may be engaging in unfair or deceptive practices.

The FTC post addresses consumers, but many SaaS products serve small businesses on click-through terms, and enterprise buyers read the same headlines. The trust cost of a quiet change often exceeds the value of the right it was meant to add.

A general counsel's checklist before relying on an update#

A general counsel's checklist before relying on an update should test each customer segment separately, because negotiated MSAs, reseller paper and click-through terms behave differently. The output is a short memo per segment stating whether the change applies and why.

  • Sort customers by contract type: negotiated MSA, standard order form with online terms, reseller agreement, or click-through only.
  • For each MSA, read the amendment, precedence, entire agreement and incorporation clauses.
  • Find where data use and AI terms live: the MSA body, the DPA, an order form or an online policy.
  • Check whether any customer negotiated a no-training or no-aggregation clause.
  • Confirm what notice the contract requires and through which channel it must be sent.
  • Decide whether the change would touch data already collected; retroactive use carries the most risk.
  • Record the decision and its contract basis for each segment.

Better routes to new data rights#

Better routes to new data rights trade speed for certainty. Each one gets the customer's agreement, which is what makes the right durable when a customer's counsel or a future acquirer reviews it.

Better routes to new data rights
RouteBest forWatch-outs
Signed amendment at renewalEnterprise customers on negotiated MSAsTakes negotiation time; expect requests for limits
New order form or MSA versionCustomers moving to a new product or planOlder data may stay under the old terms
Opt-in AI or data addendumFeatures that need customer data to improveLow uptake if the benefit to customers is unclear
Click-through update with clear noticeSelf-serve customers without negotiated termsConsumer-protection scrutiny for retroactive or hidden changes
Company-created records onlyProjects that do not need customer data at allCustomer content inside tickets still needs removal

Illustrative example: a WMS vendor wants a slotting model#

Illustrative: a fictional vendor of warehouse management software for third-party logistics providers wants to train a slotting recommendation feature on customers' pick and putaway history. Its enterprise customers sign negotiated MSAs, while smaller customers accept online terms.

The general counsel finds that every negotiated MSA requires signed amendments and ranks itself above online terms, and several large customers negotiated no-training clauses. The company drops the idea of a terms update, offers an opt-in data addendum at renewal with a plain description of the feature, and applies it only to data created after signature.

Separately, when the board asks about licensing records to an outside AI developer, the company scopes only its own engineering issues, code reviews and support history. Those records need customer details removed but no change to any customer's terms.

How SourceX handles customer terms in a licensing review#

SourceX reads a software vendor's customer terms during the Rights step of the SourceX five-step transaction to confirm which records the vendor may license. Customer data is generally excluded, and SourceX does not rely on unilateral terms updates to bring it into scope.

Each package that proceeds carries a SourceX Evidence Packet covering provenance, licensing rights, permitted use, a privacy record and the release authorization. Together they show a buyer, or a worried customer, the contract basis for every record in the package.

Frequently asked questions

Does continued use after notice count as acceptance for enterprise customers?

Usually not where the MSA requires signed amendments. Continued use can show acceptance in some click-through relationships, depending on the notice given and the governing law, but a negotiated amendment clause generally overrides that argument. Courts look at the specific wording, so counsel should review before you rely on it.

What if a customer's admin clicked through new terms at login?

A click by a customer's admin may not bind the company to terms that conflict with a signed MSA, especially where the precedence clause ranks the MSA first or the admin lacked authority to amend contracts. Many MSAs say exactly this. Review the clause and avoid using login prompts as a substitute for amendments.

Can we change our privacy policy instead of the contract?

A privacy policy describes practices; it rarely grants a vendor new rights against an enterprise customer's contract. If the MSA or DPA limits use of customer data, a privacy policy change will not lift that limit. It can, however, create new public commitments that you must then honor.

Should new data terms apply to data we already hold?

Applying new terms to previously collected data is the riskiest form of any change, and the FTC staff post specifically flagged retroactive changes in the consumer context. Most vendors apply new data rights only to data created after agreement, which also makes consent easier to obtain.

Sources

  • Zoom's blog says it made the no-training statement explicit in an August 2023 update to its online terms, and that updates to the online terms do not affect customers who buy directly under separate contracts, such as enterprises and regulated education and healthcare customers. Source
  • On August 7, 2023, after backlash over March 2023 changes to its terms, Zoom added to Section 10.4 of its Terms of Service the sentence: "Notwithstanding the above, Zoom will not use audio, video or chat Customer Content to train our artificial intelligence models without your consent." Source
  • In July 2025, after user backlash, WeTransfer revised updated Terms of Service that were due to take effect on August 8, 2025, removing language referring to using uploaded content to improve machine learning models, and stated that it does not use customer content to train AI models (reported by the BBC). Source
  • On February 13, 2024, FTC staff published 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive'. It warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify