Skip to content

Private equity and portfolios

Integrating data policies after an add-on acquisition

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Integrating data policies after an add-on acquisition means aligning privacy notices, AI use rules, retention schedules and vendor terms without rewriting the promises attached to records the add-on already holds. Old records stay governed by the terms they were collected under, while new policies apply going forward. Tag every record set by source entity from the first week.

Key takeaways

  • Records collected under the add-on's privacy notice generally stay bound by that notice's promises after closing.
  • Tag record sets by source entity and the policy version in force at collection before merging any systems.
  • Freeze automated deletion in the add-on's systems until retention schedules and legal holds are reconciled.
  • Check the add-on's vendor AI settings early, because defaults nobody chose may already allow training on its records.
  • A platform's combined history is licensable slice by slice, so keep a rights note for each source entity.

Which data policies need integrating after an add-on?#

The data policies to integrate are the ones that decide what the combined company may do with records: privacy notices, the AI use policy, the retention schedule, vendor terms, employee notices and customer contract templates. Security policies matter as well, but they usually follow the platform's IT integration and have their own owner.

Collect all of them in the first weeks, including the versions that applied in earlier years. A privacy notice updated recently says nothing about what customers were promised when older records were collected, and the add-on's staff may not know where earlier versions live. Old contract attachments, signed order forms and archived copies of the website often fill the gap.

  • Website and customer privacy notices, including the past versions in force when older records were collected.
  • Employee handbook sections on monitoring, email, chat and call recording.
  • The AI use policy, or the absence of one, and the AI tools staff already use.
  • The retention schedule and any legal holds in place at closing.
  • Vendor agreements for every system holding records, including AI feature terms.
  • Customer contract templates and the negotiated data clauses of large accounts.

Why old policies still govern old records#

Old policies still govern old records because the promises a company made when it collected information travel with that information. Publishing the platform's privacy notice on the add-on's website changes what applies to records collected from then on; it generally does not rewrite what earlier customers or employees were told.

Regulators have flagged the risk. In February 2024, FTC staff warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Treat any plan to use the add-on's historical records in a new way, internally or through licensing, as a question for counsel, assessed against the terms in force at collection.

The practical control is tagging. Every record set that moves into a platform system should carry its source entity and the policy version it was collected under, so later decisions can filter on both.

The first-100-days policy checklist#

The first-100-days policy checklist groups the work into three windows. The order matters more than the exact dates: collect and freeze first, then decide, then publish.

The first-100-days policy checklist
WindowPolicy areaActionOwner
Days 1-30RetentionPause automated deletion in add-on systems and record any legal holdsPlatform CFO with counsel
Days 1-30Privacy noticesArchive every past and current version with the dates each was in forcePlatform counsel
Days 1-30Vendor termsList systems, contract owners, renewal dates and AI feature settingsPlatform IT lead
Days 1-30AI useInventory AI tools in use and pause unreviewed connections to customer recordsAdd-on general manager
Days 31-60RetentionMap the add-on's record families to the platform schedule and note conflictsPlatform CFO
Days 31-60Vendor termsDecide which contracts to keep, migrate or end, each with an export planPlatform IT lead
Days 31-60Customer contractsFlag accounts with negotiated data, confidentiality or AI clausesPlatform counsel
Days 61-100Privacy noticesPublish the aligned notice for records collected going forwardPlatform counsel
Days 61-100AI useRoll out the platform AI policy with short training for add-on staffAdd-on general manager
Days 61-100Employee noticesIssue updated handbook sections and record acknowledgmentsPlatform HR lead

Harmonize now or keep separate for a while?#

Not every policy should merge on the same timeline. The record type and the promises already made decide whether the add-on adopts the platform policy at once or runs in parallel for a period.

Harmonize now or keep separate for a while?
PolicyHarmonize quickly whenKeep separate for now when
Privacy noticeBoth companies serve similar customers and collect similar dataThe add-on made specific promises, such as never sharing customer data
Retention scheduleRecord families and regulations matchA legal hold or contract requires longer retention at the add-on
AI use policyNearly always, for new use going forwardHistorical records carry tighter promises, which still apply to them
Vendor termsThe add-on moves onto platform systems soonA long contract runs on and the vendor's AI settings can be locked down
Customer contractsContracts renew onto the platform templateLarge accounts negotiated their own data clauses

Vendor terms and AI features at the add-on#

Vendor terms deserve early attention because AI features in help desks, CRMs, call platforms and field service software can process records under defaults nobody at the add-on chose. Some vendors' terms allow use of customer data to improve their models unless an admin opts out; others rule it out. The answer sits in each contract and each admin console, so check both rather than assuming.

Record what you find: the setting, the date and the person who changed it. That record matters later for privacy compliance and for any licensing conversation, because a buyer of records will ask whether the same records were already made available to another AI developer.

Rights inherited from acquired contracts#

A buy-and-build platform assembles a deeper combined history with each add-on, which can make its records more interesting to AI developers. Rights, however, arrive slice by slice. Each add-on's records carry its own customer contracts, privacy notices and vendor terms, and the acquisition agreement may add restrictions or transition obligations of its own.

Plan for scoped licensing from the start. Keep a rights note per source entity and expect that a combined package may leave some add-ons out entirely. Scoping by entity lets the clear slices move forward without waiting for the most restricted one.

Illustrative: an engineering platform absorbs a surveying firm#

Illustrative: a fictional civil engineering platform acquires a land surveying firm as its third add-on. The surveying firm runs projects in BQE Core, keeps field data and plats on a file server, and uses an AI notetaker on client calls.

In the first month the platform pauses the file server's automated cleanup, archives the surveying firm's past privacy notices, and finds the notetaker storing transcripts under the vendor's default settings. The add-on's general manager pauses the notetaker until the platform's AI use policy applies. Counsel flags two municipal clients whose contracts restrict any reuse of project records.

By day 100 the surveying firm's records sit in the platform archive tagged by source entity. When the platform later screens its combined project history for licensing, the two municipal clients' records drop out automatically and every remaining slice carries its own rights note.

How SourceX works with integrated platforms#

SourceX treats each source entity inside a platform as a separate slice in the Rights step of the SourceX five-step transaction. The entity and policy-version tags this checklist creates let the rights review run from metadata and the governing documents, with no records shared during the initial assessment.

When a combined package proceeds, the SourceX Evidence Packet records which entities' records are included, the licensing rights for each, and release authorization from the correct signer.

Frequently asked questions

Should the add-on adopt the platform's privacy notice on day one?

Usually not on day one. Archive the add-on's current and past notices first, then publish an aligned notice once counsel has compared the two. The new notice governs records collected afterward and does not change what earlier customers were told, so rushing it gains little and can create inconsistent promises.

What if the add-on never had an AI use policy?

Treat it as a finding, not a failure. Inventory the AI tools staff already use, pause any that connect to customer records without reviewed terms, and apply the platform policy with short training. Keep a record of what was in use before the policy, since it may matter in later diligence.

Who leads data policy integration at a platform?

Platform counsel usually leads, with the CFO owning retention, the IT lead owning vendor terms, and the add-on's general manager owning adoption among staff. The operating partner tracks progress through the integration plan. One named lead keeps policy work from falling between legal, finance and IT.

Can we combine add-on records into one dataset for licensing?

Operationally, yes, but licensing should treat each source entity separately for rights. Some add-ons' records may be fully licensable, others partly, and some not at all. Entity tags let a package include the clear slices without waiting for the hardest one to be resolved.

Sources

  • On February 13, 2024, FTC staff published 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive', warning that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify