Private equity and portfolios
Integrating data policies after an add-on acquisition
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Integrating data policies after an add-on acquisition means aligning privacy notices, AI use rules, retention schedules and vendor terms without rewriting the promises attached to records the add-on already holds. Old records stay governed by the terms they were collected under, while new policies apply going forward. Tag every record set by source entity from the first week.
Key takeaways
- Records collected under the add-on's privacy notice generally stay bound by that notice's promises after closing.
- Tag record sets by source entity and the policy version in force at collection before merging any systems.
- Freeze automated deletion in the add-on's systems until retention schedules and legal holds are reconciled.
- Check the add-on's vendor AI settings early, because defaults nobody chose may already allow training on its records.
- A platform's combined history is licensable slice by slice, so keep a rights note for each source entity.
Which data policies need integrating after an add-on?#
The data policies to integrate are the ones that decide what the combined company may do with records: privacy notices, the AI use policy, the retention schedule, vendor terms, employee notices and customer contract templates. Security policies matter as well, but they usually follow the platform's IT integration and have their own owner.
Collect all of them in the first weeks, including the versions that applied in earlier years. A privacy notice updated recently says nothing about what customers were promised when older records were collected, and the add-on's staff may not know where earlier versions live. Old contract attachments, signed order forms and archived copies of the website often fill the gap.
- Website and customer privacy notices, including the past versions in force when older records were collected.
- Employee handbook sections on monitoring, email, chat and call recording.
- The AI use policy, or the absence of one, and the AI tools staff already use.
- The retention schedule and any legal holds in place at closing.
- Vendor agreements for every system holding records, including AI feature terms.
- Customer contract templates and the negotiated data clauses of large accounts.
Why old policies still govern old records#
Old policies still govern old records because the promises a company made when it collected information travel with that information. Publishing the platform's privacy notice on the add-on's website changes what applies to records collected from then on; it generally does not rewrite what earlier customers or employees were told.
Regulators have flagged the risk. In February 2024, FTC staff warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Treat any plan to use the add-on's historical records in a new way, internally or through licensing, as a question for counsel, assessed against the terms in force at collection.
The practical control is tagging. Every record set that moves into a platform system should carry its source entity and the policy version it was collected under, so later decisions can filter on both.
The first-100-days policy checklist#
The first-100-days policy checklist groups the work into three windows. The order matters more than the exact dates: collect and freeze first, then decide, then publish.
| Window | Policy area | Action | Owner |
|---|---|---|---|
| Days 1-30 | Retention | Pause automated deletion in add-on systems and record any legal holds | Platform CFO with counsel |
| Days 1-30 | Privacy notices | Archive every past and current version with the dates each was in force | Platform counsel |
| Days 1-30 | Vendor terms | List systems, contract owners, renewal dates and AI feature settings | Platform IT lead |
| Days 1-30 | AI use | Inventory AI tools in use and pause unreviewed connections to customer records | Add-on general manager |
| Days 31-60 | Retention | Map the add-on's record families to the platform schedule and note conflicts | Platform CFO |
| Days 31-60 | Vendor terms | Decide which contracts to keep, migrate or end, each with an export plan | Platform IT lead |
| Days 31-60 | Customer contracts | Flag accounts with negotiated data, confidentiality or AI clauses | Platform counsel |
| Days 61-100 | Privacy notices | Publish the aligned notice for records collected going forward | Platform counsel |
| Days 61-100 | AI use | Roll out the platform AI policy with short training for add-on staff | Add-on general manager |
| Days 61-100 | Employee notices | Issue updated handbook sections and record acknowledgments | Platform HR lead |
Harmonize now or keep separate for a while?#
Not every policy should merge on the same timeline. The record type and the promises already made decide whether the add-on adopts the platform policy at once or runs in parallel for a period.
| Policy | Harmonize quickly when | Keep separate for now when |
|---|---|---|
| Privacy notice | Both companies serve similar customers and collect similar data | The add-on made specific promises, such as never sharing customer data |
| Retention schedule | Record families and regulations match | A legal hold or contract requires longer retention at the add-on |
| AI use policy | Nearly always, for new use going forward | Historical records carry tighter promises, which still apply to them |
| Vendor terms | The add-on moves onto platform systems soon | A long contract runs on and the vendor's AI settings can be locked down |
| Customer contracts | Contracts renew onto the platform template | Large accounts negotiated their own data clauses |
Vendor terms and AI features at the add-on#
Vendor terms deserve early attention because AI features in help desks, CRMs, call platforms and field service software can process records under defaults nobody at the add-on chose. Some vendors' terms allow use of customer data to improve their models unless an admin opts out; others rule it out. The answer sits in each contract and each admin console, so check both rather than assuming.
Record what you find: the setting, the date and the person who changed it. That record matters later for privacy compliance and for any licensing conversation, because a buyer of records will ask whether the same records were already made available to another AI developer.
Rights inherited from acquired contracts#
A buy-and-build platform assembles a deeper combined history with each add-on, which can make its records more interesting to AI developers. Rights, however, arrive slice by slice. Each add-on's records carry its own customer contracts, privacy notices and vendor terms, and the acquisition agreement may add restrictions or transition obligations of its own.
Plan for scoped licensing from the start. Keep a rights note per source entity and expect that a combined package may leave some add-ons out entirely. Scoping by entity lets the clear slices move forward without waiting for the most restricted one.
Illustrative: an engineering platform absorbs a surveying firm#
Illustrative: a fictional civil engineering platform acquires a land surveying firm as its third add-on. The surveying firm runs projects in BQE Core, keeps field data and plats on a file server, and uses an AI notetaker on client calls.
In the first month the platform pauses the file server's automated cleanup, archives the surveying firm's past privacy notices, and finds the notetaker storing transcripts under the vendor's default settings. The add-on's general manager pauses the notetaker until the platform's AI use policy applies. Counsel flags two municipal clients whose contracts restrict any reuse of project records.
By day 100 the surveying firm's records sit in the platform archive tagged by source entity. When the platform later screens its combined project history for licensing, the two municipal clients' records drop out automatically and every remaining slice carries its own rights note.
How SourceX works with integrated platforms#
SourceX treats each source entity inside a platform as a separate slice in the Rights step of the SourceX five-step transaction. The entity and policy-version tags this checklist creates let the rights review run from metadata and the governing documents, with no records shared during the initial assessment.
When a combined package proceeds, the SourceX Evidence Packet records which entities' records are included, the licensing rights for each, and release authorization from the correct signer.
Frequently asked questions
Should the add-on adopt the platform's privacy notice on day one?
Usually not on day one. Archive the add-on's current and past notices first, then publish an aligned notice once counsel has compared the two. The new notice governs records collected afterward and does not change what earlier customers were told, so rushing it gains little and can create inconsistent promises.
What if the add-on never had an AI use policy?
Treat it as a finding, not a failure. Inventory the AI tools staff already use, pause any that connect to customer records without reviewed terms, and apply the platform policy with short training. Keep a record of what was in use before the policy, since it may matter in later diligence.
Who leads data policy integration at a platform?
Platform counsel usually leads, with the CFO owning retention, the IT lead owning vendor terms, and the add-on's general manager owning adoption among staff. The operating partner tracks progress through the integration plan. One named lead keeps policy work from falling between legal, finance and IT.
Can we combine add-on records into one dataset for licensing?
Operationally, yes, but licensing should treat each source entity separately for rights. Some add-ons' records may be fully licensable, others partly, and some not at all. Entity tags let a package include the clear slices without waiting for the hardest one to be resolved.
Sources
- On February 13, 2024, FTC staff published 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive', warning that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo I need customer consent to license support tickets?
- InsightDo former employees have to consent before a closed company licenses their messages?
- InsightCan HVAC and plumbing companies license technician helmet-camera footage?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.