Skip to content

Software companies

Licensing data that contains your customers' end-customer information

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Licensing data that contains your customers' end-customer information requires permission at every link of a three-party chain: your company, your business customer and the individuals your customer serves. In most vertical software products those end customers never agreed to anything with you, so their details are usually removed, or the records excluded, before any license.

Key takeaways

  • A business customer can only grant rights it holds, and it rarely holds the right to send its clients' details to an AI developer.
  • End customers usually saw only your customer's privacy notice, which seldom mentions the software vendor's own uses.
  • Names, contact details, payment data, attachments and records about minors are usually excluded outright.
  • Company-created records such as support tickets and engineering history remain licensable once incidental end-customer details are removed.
  • If a record's value depends on knowing who the end customer is, it stays out of scope.

What is the rights chain in a B2B2C product?#

The rights chain in a B2B2C product runs through three parties: your company, your business customer and the individuals your customer serves. Vertical software for salons, fitness studios, auto repair shops, property managers and home services companies holds records about all three at once.

Each link was formed under different paper. Your customer signed your subscription agreement and DPA. The end customer, if they agreed to anything, accepted your customer's privacy notice or booking terms, which almost never mention the software vendor's own uses. You may never have had a direct relationship with them at all.

  • Your company: usually a processor or service provider for end-customer data, acting for the business customer.
  • Your business customer: usually the controller or business that collected the data and answers to the individual.
  • The end customer: the person whose name, contact details, appointments, purchases and messages sit in your database.

Why your customer's permission is usually not enough#

Your customer's permission is usually not enough because a business can only grant rights it holds, and it rarely holds the right to send its clients' details to an AI developer. Even a signed AI training addendum from a business customer leaves the end-customer link of the chain untested.

Privacy laws may apply at that link: the CCPA and other US state privacy laws, GDPR for any end customers in Europe, and sector rules where records touch health details, financial accounts or children, where COPPA may matter. Which laws apply depends on where the people are and what the records contain, and is assessed deal by deal with counsel.

There is also a practical test. If an end customer would be surprised to learn that an outside AI developer's model learned from their appointment notes, the permission is probably too thin to rely on, whatever the contract says.

What is usually excluded or de-identified#

End-customer details are usually excluded or de-identified before any license, with the treatment depending on how identifying and how sensitive each element is. The table shows common elements in vertical software and a typical starting treatment.

Automated detection is a starting point, not a finish line. The open-source Presidio project, a toolkit for finding personal data in text, warns in its documentation that automated detection offers no guarantee of catching every sensitive item and that other safeguards are needed. Free-text notes need human review on top of any scan.

What is usually excluded or de-identified
ElementWhere it appearsUsual treatment
Names, phone numbers, emails, addressesBookings, invoices, message threads, remindersRemoved or replaced with consistent placeholders
Free-text notes about the individualAppointment notes, technician notes, chat messagesReviewed; excluded where notes describe health, family or money
Payment detailsPayment records and card numbers pasted into messagesExcluded entirely
Photos, voice and attachmentsUploaded images, voicemails, signed formsUsually excluded
Records about minorsYouth programs, family accountsExcluded
Per-person behavior historyVisit frequency, purchase history by clientAggregated across many people or excluded
Your customer's business identityBusiness names, staff names, locationsRemoved unless the customer has agreed otherwise

What can still be licensed?#

What can still be licensed is mostly what your own team created: support tickets between your staff and your business customers, engineering history, product decision records and documentation. These records describe how the software and its customers' businesses work without depending on any one end customer's identity.

End-customer details still slip into them. A salon owner pastes a client's name and phone number into a support ticket; a bug report quotes a booking record to reproduce an error. Those incidental details are removed during preparation, and tickets where the end customer is the real subject are excluded.

A useful decision rule: if the value of a record depends on knowing who the end customer is, it stays out. If the value lies in the workflow, the reasoning or the fix, and the person can be removed without losing that, it may be in scope.

Illustrative: a salon booking software company scopes a license#

Illustrative: a fictional salon and spa booking software company is asked whether its records could support an AI developer building scheduling and customer service agents. Its database holds appointment logs, client notes, text reminders and payment records for the clients of every salon it serves, alongside its own Zendesk, Jira and GitHub history.

Counsel excludes all client-level appointment, note and payment content, since salon clients agreed only to their salon's terms. A proposed de-identified dataset of booking event sequences is dropped after review finds the salons' notices could not support it. Support tickets from salon owners stay in scope once client names and phone numbers are removed, together with engineering issues and code review threads.

The resulting license covers records the company's own staff created. No salon client data leaves the product, and the scoping decisions are written down for the buyer and for the company's own customers.

Who has to sign off#

Sign-off for a license near end-customer data involves more people than an ordinary records license, because part of the risk sits with your customers. Line these approvers up before preparation starts.

Write the decision down for your customers too. A short statement that end-customer records are excluded, and that incidental details are removed from company records, answers the question most business customers will ask once they hear about a license.

  • General counsel or outside privacy counsel, for the rights chain and the laws that may apply.
  • The product or engineering owner of each system, to confirm where end-customer fields live, including free text.
  • Customer success leadership, for accounts with negotiated data terms or riders.
  • The security lead, who controls how exports are pulled, where working copies sit and who can open them.
  • The authorized signer for the supplier entity, who approves the final scope.

How SourceX handles end-customer data#

SourceX handles end-customer data by leaving it out unless the full rights chain is documented. In the SourceX five-step transaction, the Rights step maps the chain for each system, and the Preparation step removes incidental end-customer details from company-created records before the supplier reviews samples.

The SourceX Evidence Packet records what was excluded, what was de-identified and why, alongside provenance, licensing rights, permitted use and release authorization. The supplier approves every step, and the initial fit check collects only metadata.

Frequently asked questions

Does our DPA let us de-identify end-customer data for our own use?

Some DPAs let the vendor create de-identified or aggregated data, but many limit processing to providing the service. Read the processing purposes and any clause on anonymized data closely, and remember that de-identification is itself processing, so it needs a basis in the contract before it happens.

What if our customers' end customers are businesses, not individuals?

Privacy law matters less, but the rights chain still applies. Your customer's own customers may have confidentiality terms covering orders, pricing or project details, and your customer cannot waive those for them. Expect to remove business names and commercial terms and to exclude records where the end business is identifiable from context.

Can we ask end customers for consent directly?

Rarely in practice. You usually have no direct relationship or contact channel, and reaching out without your customer's involvement could breach your agreement with them. A consent program would normally run through your customers, which adds cost and complexity that few licenses justify.

Are screenshots attached to support tickets a problem?

Often, yes. Customers attach screenshots to show a problem, and those images frequently display end-customer names, schedules or balances. Text scanning does not read images reliably, so attachments are usually excluded from a license or reviewed by hand, while the ticket text itself is kept after de-identification.

Does aggregation solve the end-customer problem?

It can reduce it. Counts and patterns pooled across many people and many businesses, with small groups suppressed, carry far less identifying detail than row-level records. Aggregated outputs are also less useful for most AI training, so aggregation tends to suit benchmarks better than licenses.

Sources

  • Presidio's own documentation warns that because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and that additional systems and protections should be employed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify