Software companies
Customer data deletion obligations when your company shuts down
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
When a SaaS company shuts down, its customer agreements and DPAs usually require it to let customers export their data, delete every copy it holds, including sub-processor copies, and confirm deletion on request. The rule: customer data goes back and then gets deleted; only company-owned records and data the contracts expressly let you keep can be considered for licensing.
Key takeaways
- Deletion duties at shutdown come from customer agreements, DPAs, the privacy policy and trust center, and privacy laws that may apply.
- The usual order is notice, export window, deletion across production, backups and sub-processors, then written confirmation.
- Customer content does not become licensable because the company is closing; the obligations travel with the data.
- Company-owned records such as Jira issues, code reviews and internal documentation are reviewed separately and may be preserved.
- A deletion log and sub-processor confirmations answer customers, auditors and any later buyer of assets.
What does a closing SaaS company owe customers for their data?#
A SaaS company that shuts down usually owes customers three things for their data: a fair chance to export it, deletion of the copies it holds, and confirmation that deletion happened. Those duties come from the customer agreement and the DPA, and they do not lapse because revenue stopped or the team left.
Founders often treat deletion as the last chore before dissolution. It works better as the first workstream, because it decides what the company must hand back, what it may keep and which records are even eligible for a later sale or license.
Obligations matrix: where deletion duties come from#
Deletion duties at shutdown come from several layers of paper and law, and each layer answers a different question. The matrix shows what each one usually requires and what to check before writing the shutdown plan.
For each customer, the strictest applicable term wins. A customer on a negotiated DPA may be owed a deletion certificate and a specific sequence that the standard terms never mention.
| Source | What it usually requires | What to check |
|---|---|---|
| Customer agreement or terms of service | Export access after termination, then deletion or return | Termination clauses, any stated export window, post-termination retention, notice terms |
| Data processing agreement | Return or deletion of personal data when the services end, passed down to sub-processors | Who chooses return or deletion, whether certification is required, how backups are handled |
| Privacy policy and trust center | Whatever the company publicly promised about retention, deletion and transfers in a business sale | The version in force when the data was collected, and any promise not to sell or share |
| Privacy laws that may apply | Service provider limits, deletion handling and, for some data, notices | Which state laws, GDPR or sector rules reach the data, assessed with counsel |
| Customers' own obligations | Flow-down terms customers needed for their regulators or auditors | Business associate agreements, security addenda, audit rights |
In what order should customer data be handled?#
Customer data should be handled in a fixed order: notify, open exports, stop collection, delete, then confirm. Swapping any two steps is how shutdowns produce angry customers and disputed obligations.
Give the whole sequence one owner, usually the CTO or the last senior engineer, with counsel approving the customer notice and the wording of any certificate.
- Step 1: confirm the shutdown date and who has authority to act, the board or a wind-down officer.
- Step 2: send customers written notice with the export method, the deadline and a support contact.
- Step 3: keep self-serve export working, and offer assisted exports for large or complex accounts.
- Step 4: stop new data collection, product analytics and marketing tracking.
- Step 5: delete production data, file storage, search indexes, warehouses and backups in a documented sequence.
- Step 6: instruct sub-processors to delete and collect their confirmations.
- Step 7: issue deletion certificates where contracts require them, and keep the deletion log.
Where do forgotten copies of customer data hide?#
Forgotten copies of customer data hide in the systems around the product rather than in the production database. Deleting the main database while copies survive elsewhere leaves the company short of its own DPA.
Check data warehouses and BI extracts, error-tracking and logging tools that capture request payloads, support attachments in Zendesk or Intercom, onboarding files in shared drives, staging databases seeded from production and developer laptops. Engineering systems need a look too: test fixtures and seed files in GitHub sometimes contain real customer records copied years ago.
Backups need their own decision. Some DPAs let backups expire on their normal cycle rather than be purged at once, but a closing company may not keep paying for storage long enough for that cycle to finish, so plan an explicit deletion date instead.
Vendors keep their own clocks after cancellation. Microsoft's Trust Center, for example, says it keeps customer data in a limited-function account for 90 days after a cloud subscription ends, then deletes it, including cached and backup copies, within a further 90 days for in-scope services. Ask each sub-processor for its post-cancellation timeline and a written confirmation, rather than assuming that cancelling an account deletes the data at once.
What may a closing company keep, and what might it license?#
A closing company may keep records it owns and records the law requires it to retain, and it may consider licensing only what its contracts let it use beyond the service. Everything else follows the deletion plan.
Support tickets usually split across rows. The customer's messages are customer data, while internal notes, macros and the linked engineering fix are company records. Decide that split before deletion runs, because cancelling a help desk deletes the internal side as well.
| Record category | Typical position at shutdown | Licensing possibility |
|---|---|---|
| Customer content in the product | Make exportable, then delete | Not available |
| Personal data processed for customers | Delete, including sub-processor copies | Not available |
| Usage data the contract assigns to the vendor | May be retained if the contract and privacy policy allow | Possible after a review of the definitions |
| Aggregated statistics allowed by contract | May be retained within the clause's purpose | Only if the purpose and recipients fit |
| Internal engineering, product and operating records | Company-owned; keep as needed | Often the main candidate once customer fragments are removed |
| Financial, tax and employment records | Retain for required periods | Generally not licensed |
Mistakes that turn a shutdown into a dispute#
The mistakes that turn a shutdown into a dispute mostly come from speed. A rushed handover, a short export window or an export tool that breaks under load generates complaints even when the contract technically allows the timeline.
- Announcing the shutdown before the export path works at full volume.
- Cancelling the cloud account or help desk before customers have finished exporting.
- Treating customer data as a company asset in an asset sale or a license.
- Deleting internal records along with customer data and losing what the company owns.
- Skipping sub-processor confirmations, then being unable to certify deletion.
- Letting the privacy policy promise one thing while the wind-down plan does another.
Illustrative: a field inspection software company closes#
Illustrative: a fictional field inspection software company decides to wind down. Customer inspection reports and photos sit in a Postgres database and S3 buckets, a Snowflake warehouse holds analytics extracts, Zendesk holds support history, and Jira and GitHub hold engineering work.
Counsel sorts customers by agreement. Most are on standard terms with an export period followed by deletion, while a few enterprise customers negotiated DPAs that require certification. The team ships a bulk export, emails every account admin and runs assisted exports for the largest accounts. After the window closes, it deletes production storage, the warehouse, staging copies and backups, then collects confirmations from its email, logging and support vendors.
Before Zendesk is cancelled, the team exports internal notes and macros separately from customer messages. The board then reviews Jira issues, pull request reviews and internal docs as company-owned records that may be assessed for licensing, with customer bug report text stripped out.
How SourceX approaches shutdown records#
SourceX approaches shutdown records by separating what must be returned and deleted from what the company owns, before any system is switched off. The fit check collects metadata only, such as systems, years of history and known restrictions, so nothing is shared while deletion duties are still being mapped.
If a package proceeds, the Rights step of the SourceX five-step transaction checks it against customer agreements and DPAs, and the SourceX Evidence Packet records provenance, permitted use, the privacy record and release authorization from whoever holds authority after the shutdown.
Frequently asked questions
How long do customers get to export their data?
As long as the contract says, and a reasonable period where it says nothing specific. Read the termination and data return clauses for each customer tier. Where the paper is silent, counsel will usually recommend a window long enough for large customers to finish, announced in writing with a firm end date.
Who signs deletion certificates once staff have left?
Someone with authority for the company, usually an officer, the wind-down officer or a person the board appoints. Plan this before engineers leave, because the signer needs a deletion log, sub-processor confirmations and a clear description of what was deleted and when.
Can a buyer of the company's assets take customer data?
Sometimes, but only within what the contracts, the privacy policy and applicable laws allow, and customers may have rights to object or terminate. A buyer that continues the same service is a different case from a buyer that wants the data for another use. In the 2015 RadioShack bankruptcy, the FTC recommended that customer data not be sold as a standalone asset and go only to a buyer in substantially the same line of business that agreed to honor the privacy policy. Counsel assesses this deal by deal.
Does a litigation hold override deletion duties?
A legal hold can require keeping specific records even when a contract calls for deletion. Counsel sets the scope, and the held records stay restricted, documented and out of any licensing package. Everything outside the hold continues through the normal deletion plan.
Should we tell customers if we plan to license company records?
If the package holds only company-owned records with customer content removed, many companies still mention it in shutdown communications to avoid surprises. If anything derived from customer data is involved, check the contracts first; telling customers does not by itself create a right to use their data.
Sources
- When a cloud subscription ends or expires, Microsoft keeps customer data in a limited-function account for 90 days, then disables the account and deletes the data, including cached and backup copies, within 90 days after the retention period ends for in-scope services. Source
- In May 2015 the FTC recommended that RadioShack customer data not be sold as a standalone asset and be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.