Skip to content

Rights and contracts

Can your software vendor refuse to export your data when you leave?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A software vendor can refuse or limit an export when you leave only as far as your contract allows. Read the data ownership, data return, post-termination retention and fee clauses before giving notice of non-renewal, then run and verify a full test export while your account is active and you still have leverage.

Key takeaways

  • For a US business customer, export rights come mainly from the contract, not from a general statute.
  • Customer data ownership does not by itself guarantee a complete export in a usable format.
  • Published post-termination windows vary widely, from a few weeks on written request to no access at all once the term ends.
  • Unpaid fees, an expired retention window and narrow data definitions are the usual grounds for a refusal.
  • The safest time to secure a full export is before notice of non-renewal, while the vendor still wants the renewal.

Which contract clauses decide whether you get your data back?#

Your data return rights are decided by a small set of clauses spread across the order form, the master agreement and sometimes a data processing addendum. Read them as one system: a strong ownership clause can be undercut by a short retention window or an export fee.

Pull the version of each document that actually governs your account. Many vendors update online terms, and the order form may say which version applies.

Weak clauses are easiest to fix at renewal, when the vendor wants the signature. A one-line addition that guarantees a full export with attachments and history, and a stated window after termination, costs the vendor little and can save a difficult negotiation later.

Which contract clauses decide whether you get your data back?
ClauseWhat to look forRed flag
Data ownershipCustomer owns customer data, defined to include all content you enteredDefinition limited to data you uploaded, excluding generated records
Export or data returnExport available during the term and after termination on requestExport only through the product interface, with no post-termination right
Post-termination retentionA stated window to request data before deletionDeletion at termination with no window
FormatCommonly used, machine-readable formats with attachmentsFormat at the vendor's discretion
FeesExport included, or professional services at stated ratesExport available only at fees to be agreed
SuspensionSuspension for non-payment does not remove export rightsSuspension blocks all access, including export
Deletion certificationWritten confirmation once data is deletedNo commitment to delete backups

What do published vendor terms say about data after you leave?#

Published vendor terms show how much the post-termination window varies, from a short request period to no access at all once the term ends. The examples below come from vendors' own terms or help pages as checked for this article; your order form or a negotiated agreement may say something different.

Two patterns stand out. Where a window exists, it usually depends on a written request made in time, so missing the request can mean losing the data even when the window has not closed in practice. And several vendors say plainly that they have no obligation to keep data after the window, which turns a slow export into a permanent loss.

What do published vendor terms say about data after you leave?
VendorWhat its published terms or help pages sayWhat to do before notice
SalesforceUnder the Main Services Agreement, customer data is made available for export if requested within 30 days after termination or expiration; after that, Salesforce has no obligation to keep itRequest in writing, and run the full export before the term ends
HubSpotMarketing Hub Professional and Enterprise customers can request data within 30 days after termination; for other hubs, such as Sales and Service, HubSpot provides no access after terminationTake the full export, including activities, before the term ends
ZendeskAccount data export tools are off by default and must be enabled by contacting support; they are not available on Team plans, where the API is the export routeAsk for export enablement early and test it on real ticket volumes
Atlassian (Jira, Confluence)After a cancelled subscription period ends, the site stays accessible for 15 more days, then data is kept for 60 days on paid plans before permanent deletionBack up projects and attachments before cancelling
FreshdeskFreshworks partner support says the account and its data are deleted 14 days after the subscription end date, and that an export can take up to 10 business daysStart the export weeks before the end date
GreenhouseThe Master Subscription Agreement queues customer data for deletion 90 days after termination, with an export file on request within 30 days at its data migration ratesPull data during the term, when the API route is open

When can a vendor hold back an export?#

A vendor can usually hold back an export when the contract gives it a reason, and the common reasons are predictable. Unpaid invoices are the first: many agreements let the vendor suspend services, and some do not separate export from other services.

The second is timing. If the retention window has passed, the vendor may have deleted the data as the contract required. The third is definitions. Audit logs, field history, attachments, call recordings and outputs created by the vendor's own AI features may fall outside 'customer data' as the contract defines it.

Format disputes are the fourth. A vendor may meet its obligation with a flat export that drops relationships between records, such as which comments belong to which ticket. The contract rarely promises more than the product's standard export unless you negotiated it.

What a complete export should include#

A complete export includes the relationships between records, not just the records. For operational history, the links are what make the archive useful later, whether for a new system, litigation or a data license.

Many native exports skip history, attachments or internal notes, and some limit how far back they reach. Check the vendor's documentation and your plan, then compare record counts in the export against counts in the product before relying on it.

  • Help desk: tickets, every public and internal comment, attachments, field change history, tags and satisfaction ratings.
  • CRM: accounts, contacts, opportunities with stage history, activities, emails, notes and attachments.
  • Field service: customers, sites, estimates, jobs, dispatch notes, technician notes, photos, invoices and warranty claims.
  • Project tools: issues, comments, status history, linked commits or documents, and attachments.
  • Across all systems: user and team tables so authors can be resolved, and custom field definitions.

Steps to take before giving notice of non-renewal#

The steps before notice of non-renewal matter most, because your leverage drops once the vendor knows you are leaving. Run them early enough that a failed test export can still be fixed by negotiation.

  • Read the order form, master agreement and any data addendum, and note the retention window.
  • Inventory the objects you need, including attachments, history and audit logs.
  • Run a test export and verify completeness against record counts in the product.
  • Ask the vendor in writing to confirm the full export scope, format and post-termination window.
  • Negotiate transition assistance or a read-only period if the standard export falls short.
  • Schedule the final export before the account ends, and keep a written record of what was exported, when and by whom.
  • Store the export in storage your company controls, with access limited to named people.
  • Give notice only after the export plan is confirmed.

Illustrative: an HVAC contractor retires its old field service system#

Illustrative: a fictional HVAC and plumbing contractor is moving from an older field service platform to a new one. Its contract allows export through the product during the term, says nothing about attachments and deletes data at termination.

Before giving notice, the COO runs a test export and finds it covers customers and invoices but not technician notes, job photos or callback history. She asks the vendor in writing for a full export. The vendor offers it as a paid professional services project, and the contractor accepts before the renewal date passes.

The final export includes job histories with notes, photos and linked invoices. The contractor stores it in its own encrypted storage, migrates what the new system needs and keeps the full archive under its retention schedule.

What to do if the vendor still refuses#

If the vendor still refuses, escalate in writing and cite the clauses that support your request. Ask for the specific reason, because the answer shows whether the issue is fees, definitions or timing, each of which has a different fix.

Bring in counsel before the account closes. Workarounds such as automated scraping may breach the vendor's terms, and dispute resolution clauses may set out notice steps you have to follow. Outside the US, rules on switching between cloud services, such as those in the EU Data Act, may add rights that a US contract alone does not give.

Why exports matter for data licensing, and how SourceX helps#

Exports matter for data licensing because the operational history in a retiring system is often the most valuable part of a company's records. Once a vendor deletes it, no license is possible.

SourceX starts with the Supply step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The fit check collects metadata only, such as system names and years of history, and large archives stay in the company's own storage. Whether vendor terms allow exported records to be licensed is checked in the Rights step.

Frequently asked questions

Can we demand a particular export format?

Only if the contract gives you that right. Without a format clause, a vendor can usually meet its obligation with the product's standard export. If you need relationships preserved or attachments included, negotiate it at renewal or as part of a transition services request.

Does the vendor have to delete our data after we leave?

Many contracts and data processing addenda require deletion after a retention window, sometimes with exceptions for backups and legal holds. Ask for written confirmation of deletion, and make sure your final export is complete before that window closes.

Can we keep a read-only account instead of exporting?

Some vendors keep an account recoverable for a period after cancellation or offer reduced archive plans. These can bridge a migration, but they keep your history in the vendor's hands and on its terms, and the recovery period eventually ends. A verified export in your own storage is more durable.

Do vendor terms allow us to license exported records?

Often, if the terms say the customer owns its data and the records are your own operational history. The export route matters too: some API and developer terms restrict using data pulled through the API to train AI models, as HubSpot's updated developer terms and, according to a Hunton Andrews Kurth alert, Slack's 2025 API terms do. Review those terms before planning any license.

What about data created by the vendor's AI features?

Summaries, classifications and suggestions generated by a vendor's AI features may be defined as vendor output rather than customer data. Check the definitions, and export what you are allowed to before the account ends.

Who in the company should own the export?

Usually the COO or IT lead who owns the system, with the business owner of each record family confirming what is needed. Finance should confirm that invoices are paid so a fee dispute cannot block access, and counsel should review the vendor correspondence before any final notice is sent.

Sources

  • Salesforce makes Customer Data available for export if requested within 30 days after termination or expiration, then has no obligation to maintain it. Source
  • HubSpot Marketing Hub Professional and Enterprise have a 30-day written-request window after termination; other hubs get no access to Customer Data after termination. Source
  • Zendesk data exports must be enabled by contacting support and are not available on Team plans, which can export through the REST API. Source
  • After a cancelled Atlassian subscription period ends, the site stays accessible 15 days, then data is retained 60 days on paid plans before permanent deletion. Source
  • Freshdesk permanently deletes the account and data 14 days after the subscription end date; an export can take up to 10 business days. Source
  • Greenhouse queues Customer Data for deletion 90 days after termination and provides an export on request within 30 days at its data migration rates. Source
  • HubSpot's updated Developer Terms restrict using data accessed through HubSpot APIs to train AI or machine learning models. Source
  • Hunton Andrews Kurth reports Slack API terms effective May 29, 2025 prohibit bulk export of API data and its use in large language models. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify