Wind-downs and transitions
Owning the data vs having the right to license it: the wind-down distinction
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A company that holds data does not automatically have the right to sell or license it. Owning the accounts, servers and files is one question; permission to let a third party use the content is another, shaped by customer contracts, NDAs, privacy notices and employee expectations. In a wind-down, sort records into yours, shared, customer-owned and NDA-bound before offering any.
Key takeaways
- Possession and ownership of records do not settle whether the company may license their content.
- Sort every record family into company-controlled, shared, customer-owned or NDA-bound before scoping a license.
- Confidentiality obligations usually survive a wind-down, so dissolution does not free NDA-bound information.
- De-identification addresses personal information but not a counterparty's confidential business information.
- Unclear rights are a reason to exclude or preserve records, not a reason to proceed.
Why holding data is not the right to license it#
Holding data is not the right to license it, because ownership of a record and permission to use its contents come from different sources. A company usually owns its accounts, its exports and the compilation of records it built, while the information inside may still be governed by promises made to customers, partners, employees and users.
The distinction gets sharper in a wind-down. Directors are trying to recover value quickly, the people who negotiated the original contracts may be gone, and it is tempting to treat everything on the company's systems as company property. A rights review is the step that separates what the company can license from what it merely holds.
The rights matrix#
The rights matrix sorts records by who controls their use. Most archives contain all four categories, often inside the same system, so the sorting happens by record family and sometimes by field rather than by tool.
| Category | Typical records | Who controls use | Usual treatment in a license |
|---|---|---|---|
| Company-controlled | Internal playbooks, engineering discussions, process docs, internal review notes | The company, subject to employee notices | Candidate for licensing after privacy preparation |
| Shared | Support tickets, CRM histories, project threads with customers | The company and counterparties, per contract and privacy notice | Licensable in de-identified form if contracts allow |
| Customer-owned | Customer uploads, client deliverables, customer code, hosted customer data | The customer, under service agreements | Excluded unless the customer consents |
| NDA-bound | Partner pricing, diligence materials, prospect documents received under NDA | The disclosing party | Excluded; de-identification usually does not cure it |
Where the limits come from#
The limits on licensing come from documents the company signed or published, and a rights review reads each type. Gathering them is often the slowest part of a wind-down review because they sit in different places and some were signed by people who have left.
SaaS vendor terms usually settle only the company-versus-vendor question. Linear's terms say the customer owns all right, title and interest in its User Submissions, Section 8.4 of one version of the GitLab Subscription Agreement says the customer retains its rights in Customer Content, and Dropbox's terms say "Your Stuff is yours." None of that tells you whether a customer, partner or employee whose information sits in those records has agreed to its use by a third party. Vendor terms can also restrict how data leaves the tool: according to a Hunton Andrews Kurth client alert, Slack's API terms effective May 29, 2025 prohibit bulk exporting through its APIs and using such data in large language models.
- Master service agreements and order forms, especially use, confidentiality and data ownership clauses.
- Data processing addenda that limit processing to providing the service.
- NDAs with partners, prospects, investors and potential acquirers.
- Privacy notices and terms of service, in every version that applied while records were collected.
- Employee handbooks and notices about monitoring and the use of company systems.
- SaaS vendor terms, which may limit how exported data or API access can be used.
- Open-source licenses on code, and any third-party code inside repositories.
Email is the hardest archive to clear#
Email is the hardest archive to clear because one mailbox mixes every rights category. A single thread can hold internal reasoning, a customer's confidential plans, a partner's pricing under NDA, a lawyer's advice and an employee's personal matter.
Most wind-down reviews either exclude email entirely or license only narrow, well-defined slices, such as internal-only threads within one team, after filtering out external participants and legal communications. Privileged communications need particular care, since disclosure can waive privilege and that call belongs to counsel.
Does a wind-down change who holds the rights?#
A wind-down does not erase the obligations attached to records. Confidentiality clauses commonly survive termination, privacy promises follow the data, and dissolution generally leaves existing obligations in place during the winding-up period.
What a wind-down does change is who exercises the company's rights. Officers act under board authority before dissolution; after filing, authority is generally limited to winding up; in an assignment for the benefit of creditors, the assignee acts; in bankruptcy, the debtor or trustee acts under court supervision. Each of them takes the records subject to the same restrictions.
Asset sales add one more layer. If the company sells contracts or a business line, the buyer may receive rights in related records that limit what the company can license afterward, so read the purchase agreement before scoping.
How to run a rights review in a wind-down#
A rights review in a wind-down follows the records rather than the contracts. Start with the record families worth licensing, then pull only the documents that govern them, which keeps the review proportionate when legal budgets are tight.
| Step | What to collect | Outcome |
|---|---|---|
| Name the record families | Systems, date ranges and record types | The scope of the review |
| Map counterparties | Customers, partners and vendors appearing in the records | A list of agreements to read |
| Read the governing terms | MSAs, DPAs, NDAs, privacy notices and employee notices | A rights category for each record family |
| Decide treatment | Carve-outs, de-identification needs and consents | The licensable scope |
| Record the result | Who reviewed, what was excluded and why | Evidence for the board and the licensee |
Illustrative: a recruiting firm sorts its records#
Illustrative: a fictional technical recruiting firm is winding down after its founders retire. Its Bullhorn ATS holds candidate profiles and placement histories, its email holds job orders and fee discussions with client companies, and its shared drive holds interview guides and sourcing playbooks the team wrote.
The rights review sorts the archive. Interview guides and sourcing playbooks are company-controlled. Placement workflows are shared and could be licensed only as de-identified process records. Candidate profiles and resumes are excluded because they center on personal data, and client job orders sent under confidentiality terms are NDA-bound and excluded.
The firm licenses a narrow package of company-controlled playbooks and de-identified workflow records, and documents the review so the board and the licensee can see why everything else stayed out.
How SourceX handles the rights step#
SourceX places the rights review second in the SourceX five-step transaction, after Supply and before any Preparation work. The supplier, or its trustee, assignee or authorized officer, approves the resulting scope, and nothing is prepared from records the review excluded.
The SourceX Evidence Packet records licensing rights and permitted use alongside provenance, the privacy record and release authorization, so the basis for each inclusion and exclusion travels with the package.
Frequently asked questions
Does removing names solve the NDA problem?
Usually not. De-identification addresses personal information, but an NDA protects a counterparty's confidential business information, such as pricing, plans or technical details, which can remain recognizable after names are removed. NDA-bound content is normally excluded rather than redacted.
Do we need customer consent to license support tickets?
It depends on the customer contracts and the privacy notice. Some agreements permit use of de-identified or aggregated data; others restrict use to providing the service. Counsel reads the terms by customer group, and consent is one option when the terms are restrictive.
Do NDAs survive dissolution?
Confidentiality obligations commonly survive termination of the underlying relationship and are generally not cancelled by dissolution. The survival period depends on each agreement's terms. Treat NDA-bound information as restricted throughout the wind-down unless counsel concludes otherwise.
Who decides when a contract is ambiguous?
Counsel advises and the authorized signer decides, usually with board approval for the license as a whole. When a clause is genuinely unclear, the conservative choice is to exclude those records or ask the counterparty for consent. Ambiguity resolved in the company's favor without documentation is a risk for both parties.
Can we license aggregated statistics instead?
Aggregated statistics often raise fewer rights questions, because they do not reproduce individual records or confidential details. Contracts can still restrict aggregate use, so check them. For AI developers, though, aggregates are usually less useful than prepared records that show the work itself.
Sources
- Linear's Terms of Service state that, except for the limited rights granted, Customer will own all right, title and interest in and to the User Submissions. Source
- Section 8.4 of the GitLab Subscription Agreement (version GLSA_01.12.26 v8) states the customer retains all right, title and interest in and to Customer Content, subject to a limited license to GitLab. Source
- Dropbox's Terms of Service state 'Your Stuff is yours' and give Dropbox no rights to it except the limited rights needed to offer the Services. Source
- According to Hunton Andrews Kurth, Slack API Terms effective May 29, 2025 prohibit bulk exporting of data accessible through Slack's APIs, creating persistent copies or archives, and using such data in large language models. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.