Definitions and comparisons
Customer data vs usage data vs aggregated data in SaaS contracts
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In most SaaS contracts, customer data is what customers put into the service and belongs to them; usage data is information about how the service is used and is often vendor-controlled; aggregated data combines records so no customer or person is identifiable. Only the exact definitions and permitted-use clauses decide what a vendor may license to an AI buyer.
Key takeaways
- Customer data usually belongs to the customer and may be used only to provide the service, so a vendor can rarely license it.
- Usage data rights often favor the vendor, but definitions vary and some sweep in customer content through logs and event payloads.
- Aggregated or de-identified data clauses often allow vendor use, yet many limit it to improving the vendor's own services.
- A software company's own engineering, support and product records sit outside all three definitions, though support tickets can contain customer content.
- Changing terms going forward does not automatically reach data collected under earlier terms.
How do SaaS contracts define the three kinds of data?#
SaaS contracts usually define customer data as the content and records a customer or its users submit to the service, usage data as information the vendor collects about how the service is used, and aggregated data as information combined across customers so that no customer or individual can be identified. Each term is defined in the agreement itself, and the definitions differ more than the labels suggest.
Some agreements call usage data service data, telemetry or system data. Some define aggregated data, others de-identified data, and some use both with different meanings. A software founder should read the definitions section of the customer terms actually in force, including negotiated enterprise MSAs and older versions still governing long-standing accounts, before assuming where a record family falls.
Who owns each kind, and can it be licensed?#
Ownership and permitted use differ sharply across the three categories, which is why the label on a dataset decides so much. The table summarizes common positions; your own contracts may say something different.
The right-hand column turns on exact wording. A clause letting the vendor use data to improve the services is not the same as a right to provide data to a third party for model training, and many agreements limit vendor use to the vendor's own products.
| Category | Who usually owns it | Typical permitted vendor use | Licensable to an AI buyer by the vendor? |
|---|---|---|---|
| Customer data | The customer | Only to provide, support and secure the service | Rarely; usually needs express customer permission |
| Usage data | Often the vendor; sometimes left undefined | Operate, analyze and improve the service; sometimes broader | Sometimes, if the definition excludes customer content and the clause allows disclosure |
| Aggregated or de-identified data | Often the vendor, once derived | Benchmarks, analytics, product improvement | Sometimes, if third-party sharing is allowed and the stated standard is met |
Clause wording to read before any AI licensing discussion#
The clauses to read before any AI licensing discussion are the definitions, the license grants running in both directions and the confidentiality section. These are the questions counsel will usually work through:
Data processing agreements deserve separate attention. Where the vendor acts as a processor or service provider under laws such as GDPR or CCPA, using personal data for its own purposes may be restricted even if the commercial terms look permissive. Counsel decides which laws reach a given customer relationship.
- Does the customer data definition include outputs, derived data or content the service generates?
- Does the usage data definition exclude customer content, or could logs and event payloads contain it?
- What standard does the aggregation or de-identification clause require, and who decides it is met?
- Is vendor use limited to internal purposes or to improving the services, or does it permit disclosure to third parties?
- Is there an AI or machine learning clause, and does it address third-party models as well as the vendor's own?
- Do the DPA or service-provider terms restrict personal data to processing on the customer's instructions?
- What must be returned or deleted at termination, and does that include derived data?
What sits outside all three definitions#
A software company's own operating records usually sit outside all three contract definitions. Jira issues, GitHub or GitLab history, code reviews, release notes, Confluence or Notion documentation, product decision records and sales activity in Salesforce or HubSpot are created by the company about its own work.
Support records need more care. A Zendesk or Intercom conversation is the vendor's own support record, but the customer may have pasted its data, screenshots or configuration into it. Licensing support history usually means removing customer content and identifiers, and checking whether the customer terms treat support submissions as customer data. Your own vendors' terms point the other way: Intercom's Terms of Service, for example, define Customer Data to include chat and message logs collected through its service, which treats those conversations as the software company's data relative to Intercom, not as Intercom's.
| Record family | Where it usually falls | What to check |
|---|---|---|
| Jira issues, pull requests, code reviews | Company's own records | Customer code or customer names inside tickets |
| Support tickets and chat transcripts | Company's own records with customer content inside | Whether terms treat support submissions as customer data |
| Product analytics events | Usage data | Whether event payloads capture customer content |
| Tenant database records | Customer data | Express customer permission for any third-party use |
| Cross-customer benchmark reports | Aggregated data | De-identification standard and third-party sharing rights |
Mistakes that cause trouble later#
The most common mistake is treating the three categories as fixed industry definitions rather than as words defined in your own contracts. Founders who assume usage data is theirs to license often discover that event payloads capture customer content, or that a large customer's MSA narrowed vendor rights long ago.
- Relying on the current website terms when older or negotiated versions govern most of the data.
- Calling data aggregated because it is summarized, without meeting the contract's de-identification standard.
- Reading a right to improve the services as permission to share with third parties.
- Overlooking restrictions added by DPAs and sub-processor commitments.
- Mixing tenant data into internal analytics tables, which blurs the line between categories.
Illustrative: a self-storage software vendor sorts its data#
Illustrative: a fictional vertical SaaS company sells facility management software to self-storage operators. It holds tenant ledgers and maintenance requests entered by customers, event logs from its web and mobile apps, cross-customer benchmark reports on maintenance response, and its own Jira, GitHub and Zendesk history.
Counsel sorts each family against the current customer terms and the older versions that still govern long-standing accounts. Tenant ledgers and maintenance requests are customer data and stay out. Event logs qualify as usage data only after payload fields holding free text are dropped. The benchmark clause permits internal product use only, so benchmarks stay out too. The engineering and support history becomes the candidate package, with customer content removed from tickets before anything is shared.
Can a SaaS company change its terms to allow AI licensing?#
A SaaS company can usually change its terms going forward, but a change does not automatically reach data collected under earlier terms. How changes take effect depends on the agreement's amendment clause, notice requirements, negotiated contracts that cannot be changed unilaterally and any privacy laws that apply.
Owners considering a change should separate three questions: what the new terms will allow, which customers and which data they will cover, and whether existing data needs customer consent before any new use. Retroactive changes in how data is used can raise customer and regulatory concerns, so this belongs with counsel rather than in a quiet update to the website.
How SourceX scopes SaaS data#
SourceX scopes SaaS packages record family by record family during the Rights step of the SourceX five-step transaction, after Supply and before Preparation, Approval and Delivery. Customer tenant data is excluded unless customers have expressly agreed otherwise, and nothing proceeds until the supplier signs off on the scope.
The SourceX Evidence Packet records the licensing rights relied on for each record family, the permitted use and the privacy record, so the company can show customers and future acquirers which contract terms each license rests on.
Frequently asked questions
Is de-identified customer data still customer data?
It depends on the contract. Some agreements say customer data remains customer data whatever is done to it; others carve out aggregated or de-identified data once a stated standard is met. The definition and the de-identification standard in your terms decide the answer, not the technique used.
Who owns the outputs a SaaS product generates for customers?
Many agreements assign outputs to the customer or treat them as customer data, and others are silent. Silence is not permission. If outputs matter to a licensing plan, read the agreement with counsel and, if needed, clarify the position for future customers.
Do negotiated enterprise contracts override our standard terms?
Usually, for those customers. Enterprise MSAs and DPAs often narrow vendor rights over usage and aggregated data, so a record family licensable under click-through terms may be restricted for your largest accounts. Keep a list of which customers are on which paper.
Can we use customer data to build our own AI features?
Possibly, within what the terms and privacy laws allow, but that is a different question from licensing to a third party. Many terms permit use to provide and improve the service; licensing to an outside model developer usually needs a clearer right or customer consent.
Does usage data include support tickets?
Usually not. Support conversations are typically treated as the vendor's own support records or, in some agreements, as customer data when customers submit content through them. Usage data normally means telemetry such as logins, feature use and performance metrics. Check how your terms classify support submissions before including tickets in any package.
Sources
- Intercom's Terms of Service define Customer Data as data submitted to the Services by or on behalf of the Customer, including data about People such as chat and message logs collected through the Services. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.