Skip to content

AI uses for records

Can software vendors delete your history after you cancel?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Software vendors can usually delete your history after you cancel, once a post-termination window passes; published terms range from no access after the end date to 30 or 60 days, or a year of read-only access. Your contract decides, so read the termination, data return and deletion clauses and export complete history before giving notice.

Key takeaways

  • Deletion after cancellation is a standard SaaS term, and data processing terms often require it.
  • Published windows differ widely: some vendors give no access after the end date, others 30 or 60 days, and one accounting platform a year of read-only access.
  • Read the order form, master agreement, DPA and help-center documentation together, because deletion terms are often split across them.
  • A vendor's deletion schedule does not end your own tax, litigation or contractual retention duties.
  • Signature and renewal are the best moments to negotiate a longer retrieval window or a fuller export.

The short answer: usually yes, after a window#

Software vendors can usually delete your history after you cancel, once the retrieval window in your contract or documentation closes. Deletion at the end of a subscription is a standard term rather than a vendor overstep, and data protection terms often require the vendor to delete or return personal data when services end.

What varies is the detail: how long you can still sign in or request an export, whether access is read-only during that period, what the export includes, whether assisted exports carry a fee, and when backup copies are purged. The practical question for counsel is not whether deletion can happen but when, and what the company must take before it does.

What major vendors' published terms say#

Major vendors' published terms confirm that deletion after cancellation is the norm, but the windows differ enough that each system needs its own date. The table summarizes what each vendor's agreement or help documentation said at the time of writing.

Treat these as defaults, not your terms. Negotiated order forms can extend or shorten them, plans and purchase channels differ, and vendors revise help pages without notice, so read the version tied to your own agreement.

What major vendors' published terms say
VendorAccess after the end dateWhat happens to the data
Salesforce (Main Services Agreement)Data made available for export if the customer asks within 30 days after termination or expiryAfter 30 days, no obligation to keep it; copies deleted or destroyed unless legally prohibited
HubSpot (Product Specific Terms)Marketing Hub Professional and Enterprise: access or copies on written request within 30 days; other Hubs: no access after terminationNo obligation to maintain the data after that point
Microsoft 365 business subscriptionsFor most offers, 30 days expired, then 90 days disabled, when only admins can access and back up dataMight be deleted after 90 days and deleted no later than 180 days after cancellation; durations vary by purchase channel
Google WorkspaceHelp page warns that users' data will be deleted and cannot be restoredDeletion can take up to 90 days
Atlassian cloudSite stays accessible for 15 days after the paid period ends, then is deactivatedData kept 60 days on Free, Standard, Premium or Enterprise plans, then permanently deleted
QuickBooks OnlineRead-only period of one year in which data can still be exportedPlan and verify the export inside the read-only year
BQE COREData stays in CORE for 60 days but cannot be accessedDeleted after 60 days unless an extraction or backup was arranged in advance
IntercomCancelling does not remove data, but it cannot be viewed until the subscription restartsDeleting a workspace removes all data permanently within 14 days of confirmation
Slack (Customer Terms)Not specified as a number of days in the clauseSlack may delete all Customer Data after subscriptions end, unless legally prohibited

Where the deletion terms actually live#

Deletion terms usually live in several documents at once, and the documents do not always agree. Collect the full set for each system before you give notice.

If a negotiated order form changes the standard terms, it often controls, but each agreement sets its own order of precedence. Find the clause that says which document wins before relying on any single one.

  • Order form or quote: the term, renewal date and any negotiated exit terms.
  • Master subscription agreement or terms of service: termination, suspension and data return clauses.
  • Data processing agreement: deletion or return of personal data at the end of services.
  • Security exhibit or trust documentation: backup retention and secure disposal practices.
  • Help-center or admin documentation: the actual export tools, formats and account closure steps.
  • Privacy policy: what the vendor keeps about your users after closure, such as billing records.

Why deletion is often required, not just allowed#

Deletion is often required because vendors process your customers' and employees' personal data on your behalf, and data processing terms commonly oblige them to delete or return it when the service ends. GDPR, the CCPA and other state privacy laws may apply, depending on whose data is involved and where those people are.

That cuts against asking a former vendor to keep everything indefinitely after you leave. If you need history preserved, the cleaner path is to export it into storage you control, under your own retention schedule, rather than relying on the vendor's goodwill or its backups.

Clause redlines for general counsel#

Clause redlines let general counsel and privacy leads fix exit risk while the vendor still wants the business, at signature or renewal. The table pairs wording that commonly creates risk with a position worth requesting.

Ask for each change in the order form rather than in an email from the account team, so it binds the vendor at renewal, and keep the signed version with the vendor's then-current DPA and help documentation.

Clause redlines for general counsel
ClauseWording that creates exit riskPosition to request
Termination and expiryAccess ends on the termination date with no transition periodA defined period of continued access after expiry, with its start date stated
Data retrievalData provided on request, with no deadline for the vendor to respondSelf-service export for a defined window, plus a response time for assisted exports
Export scope and formatCustomer Data exported in the vendor's standard formatMachine-readable export with attachments, comments, history, audit logs and record IDs intact
DeletionVendor may delete after termination at its discretionWritten notice before deletion, a stated schedule for production and backups, and certification on request
SuspensionVendor may suspend or delete for nonpaymentData preserved and exportable while an invoice dispute is open
Usage and derived dataBroad rights to aggregated or de-identified data that survive terminationLimits on what is retained after termination and for what purpose
Transition assistanceNot mentionedAssisted export available at a rate agreed in advance

Your own retention duties continue after the vendor deletes#

Your own retention and preservation duties continue after a vendor deletes your data, because the obligation to keep records sits with the company, not with its software provider. A vendor's deletion schedule is never a reason to let records go.

Tax records are the clearest case. The IRS says to keep records supporting income, deductions or credits until the period of limitations for that return runs out, generally three years and longer in some situations, and Rev. Proc. 98-25 treats records held in an automated accounting system as records that must be retained while they may be material to tax administration. Cancelling an accounting or ERP subscription without a complete export can leave the company short.

Litigation is the other. If a dispute is pending or reasonably anticipated, relevant records in the system may need to be preserved, and a vendor's routine deletion after cancellation may not excuse a failure to keep them. Before giving notice, confirm the points below with counsel.

  • No legal hold or anticipated dispute covers records held in the system.
  • Tax, employment and industry retention periods for those records, and whether the planned export satisfies them.
  • Customer contracts that require you to keep, return or delete their data at the end of a relationship.
  • Who will own the exported archive, where it is stored and when it may be deleted.
  • Whether exported history may later be reused, including for licensing, under vendor terms and customer contracts.

Illustrative: a consulting firm retires its project platform#

Illustrative: a fictional operations consulting firm is replacing the cloud project and time-tracking platform it has used for most of its history. When the renewal notice arrives, the managing partner asks the general counsel whether the firm's engagement records will survive the switch.

Counsel pulls the order form, the subscription agreement, the DPA and the vendor's admin documentation. Together they show a short read-only period after expiry, a self-service export that omits comments and file versions, and an assisted export offered for a fee. Because one client engagement is in a fee dispute, counsel also asks that its records be preserved in full before any notice is given.

The firm extends the subscription briefly, runs the assisted export, checks that projects, tasks, comments and timesheets still link, and stores the result in its own cloud storage under its retention schedule. Client deliverables remain under each engagement letter's confidentiality terms, so the firm tags those folders, while internal proposals, staffing plans and project reviews are logged separately as firm-owned records.

How SourceX approaches vendor-held history#

SourceX starts with rights when history sits in a vendor's platform. During Rights, the second stage of the SourceX five-step transaction, the vendor's terms are read alongside customer contracts to confirm whether the company can export and license the records, and large exports stay in the company's own storage rather than being hosted by SourceX.

When a system is about to be retired, preserve the history first, in the company's own storage and under its retention policy. The SourceX fit check then works from metadata about that export, such as record types and date coverage, and nothing is shared unless the company later approves a package.

Frequently asked questions

Can a vendor keep anonymized or aggregated data after we cancel?

Some agreements let vendors keep usage statistics or de-identified, aggregated data after termination, for purposes such as improving the service. Read the data use and license clauses for that permission, and ask what is retained, in what form and for what purpose. Negotiate limits at renewal if the answer is broader than expected.

Do backups count as deleted data?

Vendors typically delete production data first and let backups expire on their own rotation, so copies can persist for a while after deletion. The security documentation or DPA usually describes this. If timing matters, ask for the backup cycle and a written confirmation once deletion is complete.

What happens to our data if the vendor shuts down?

That depends on the agreement and the circumstances of the shutdown. Some contracts promise notice and an export opportunity, but a failing vendor may not honor that in practice. Regular exports of critical history to your own storage are the only protection fully in your control.

Does exporting our data mean we can license it?

Not automatically. Holding a copy of your data and being allowed to reuse it for licensing are separate questions; vendor terms, customer contracts and privacy notices all matter. Review the export and use provisions with counsel before treating exported records as licensable.

Should we cancel before or after exporting?

Export first, verify the files, then give notice. Cancellation can start a clock that limits access, and some vendors restrict exports after notice. Leave enough time to retry a failed or incomplete export and to request an assisted export if self-service tools fall short.

Sources

  • Under the Salesforce Main Services Agreement, if the customer asks within 30 days after termination or expiration, SFDC makes Customer Data available for export; after that 30-day period SFDC has no obligation to maintain it and will delete or destroy all copies unless legally prohibited. Source
  • For Marketing Hub Professional and Enterprise, HubSpot gives temporary access or copies of Customer Data on written request within 30 days after termination; for other Hub subscriptions HubSpot will not provide any access to Customer Data after termination or expiration. Source
  • Microsoft's business subscription lifecycle for most offers runs Active, Expired (30 days), Disabled (90 days, when only admins can access and back up data), then Deleted; data might be deleted after 90 days and will be deleted no later than 180 days after cancellation. Source
  • Google's cancellation help page warns that users' Google Workspace data will be deleted and cannot be restored, and that deletion can take up to 90 days. Source
  • After a cancelled Atlassian subscription period ends, the site stays accessible for 15 more days and is then deactivated; data is retained 60 days for Free, Standard, Premium or Enterprise plans, then permanently deleted. Source
  • Intuit support content says QuickBooks Online data can still be exported while a cancelled account is within its one-year read-only period. Source
  • When a BQE CORE subscription ends, data stays in CORE for 60 days but cannot be accessed, and is then deleted unless an extraction or backup copy was arranged in advance. Source
  • Intercom says cancelling a subscription does not remove any data, but once the subscription has ended the customer cannot see the data until it is restarted. Source
  • Intercom says deleting a workspace permanently deletes all of its data and the workspace is deleted within 14 days of confirmation. Source
  • Slack's Customer Terms of Service say that after a workspace's subscriptions end, Slack may, unless legally prohibited, delete all Customer Data; no fixed number of days is stated in this clause. Source
  • The IRS says to keep records supporting an item of income, deduction or credit until the period of limitations for that return runs out, generally 3 years, with longer periods in specified cases. Source
  • Rev. Proc. 98-25 treats machine-sensible records in a taxpayer's automatic data processing system as records that must be retained so long as their contents may become material to tax administration. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify