Wind-downs and transitions
Preserve records before you cancel SaaS subscriptions: a shutdown order of operations
By SourceX Editorial · Updated
Short answer
To preserve records before cancelling SaaS subscriptions, follow a fixed order: freeze deletions, secure admin access before layoffs, export and verify each system, assess what to keep, delete or license, and only then cancel, with identity, email and the domain last. Cancelling in the wrong order is how most shutdown records are lost.
Key takeaways
- Sequence matters more than speed: freeze, secure access, export, assess, then cancel.
- Secure admin accounts and recovery codes before the people who hold them leave the company.
- Deleting a user in a productivity suite can remove that user's mailbox and files unless ownership is transferred first.
- Cancel in reverse dependency order, keeping single sign-on, email and the domain until every other export is verified.
The order of operations at a glance#
The order of operations runs in five phases, and each system passes through all of them before its cancel date. The table works as a register: one row per system, one owner per row, and a retention window confirmed from the vendor's own terms rather than memory.
Build the register from the accounts payable ledger and the company card statements, not from memory. Tools bought on individual cards, free plans that still hold records and integrations installed by former employees rarely appear on an IT list, and they are where unexpected records surface.
| System | Owner | Export method | Retention window | Cancel when |
|---|---|---|---|---|
| Help desk (Zendesk, Intercom) | Support lead | Native export or API, with attachments | Confirm in vendor terms for your plan | After export is verified and the assessment is decided |
| CRM (Salesforce, HubSpot) | Sales operations | Full data export plus files and activity history | Confirm in vendor terms | After export is verified and customer obligations are met |
| Issue tracker and code (Jira, GitHub) | Engineering lead | Project export and repository clones with full history | Confirm in vendor terms | After linked issues and reviews are verified |
| Chat (Slack, Teams) | IT or operations | Workspace export at the highest level the plan allows | Confirm in vendor terms | After export and channel review |
| Docs and files (Confluence, Notion, Google Drive) | IT or operations | Space exports, ownership transfer, bulk download | Confirm in vendor terms | After all user files are transferred |
| Finance and payroll | Controller | Reports and ledgers on the accountant's list | Confirm in vendor terms and retention law | After the custodian holds required records |
| Identity, email and domain | IT lead | Mailbox exports and directory export | Confirm in vendor terms | Last, after every other row is closed |
Phase one: freeze deletions and map dependencies#
Phase one stops anything that deletes records automatically while the plan is built. Retention policies in email and chat, auto-archive rules in help desks and offboarding scripts that remove accounts can all destroy records quietly during a wind-down.
Map dependencies at the same time. Single sign-on controls access to most tools, integrations break when their source system closes, and password resets for every vendor arrive at company email addresses. Any system that other systems depend on gets cancelled late.
Phase two: secure admin access before layoffs#
Phase two secures admin access before the people who hold it leave, because a lost login is harder to recover than a cancelled subscription. In many companies a single engineer or office manager is the only admin for several systems.
- Add a second company-controlled admin to every system that holds records.
- Move multi-factor authentication off personal phones to company-held devices or a shared vault.
- Record billing owners and the card or invoice each subscription runs on.
- Check auto-renewal dates so no plan renews into a long term or lapses unnoticed.
- Transfer file ownership before deleting any user account in Google Workspace or Microsoft 365.
Phase three: export and verify#
Phase three exports each system and verifies the export against the live system before anything else happens. Verification is the step most often skipped, and it is the one that catches missing attachments, truncated history and broken links between records.
Check record counts by year, open a sample of exported records next to the originals, confirm that attachments and comments came through, and make sure the identifiers that link systems survive, such as ticket numbers referenced in Jira issues or CRM account IDs on invoices. Store exports in company-controlled storage with access limited to named people.
Prefer each vendor's own export features over third-party tools that pull data through APIs. According to a Hunton Andrews Kurth client alert, Slack's API terms were changed effective May 29, 2025 to prohibit bulk exporting of data through its APIs and creating persistent copies or archives, so an archiving app that worked in the past may no longer be a permitted route.
Phase four: assess before you decide#
Phase four assesses each export before the cancel decision, because three different obligations meet here: records the law requires you to keep, records contracts require you to delete or return, and records that may be worth licensing.
Apply the rules in the order shown. A legal or contractual obligation always outranks a licensing opportunity.
| Finding | Decision |
|---|---|
| Required by tax, employment or corporate law | Keep with a named custodian |
| Customer data under a return or deletion clause | Return or delete, and confirm in writing |
| Records under a litigation hold | Keep unchanged until counsel releases the hold |
| Company-controlled operational history with outcomes | Hold for a licensing assessment |
| Personal files and duplicates with no purpose | Delete under the retention schedule |
What vendors say happens to data after cancellation#
Vendor terms on data after cancellation range from immediate loss of access to a long read-only window, which is why the register needs each vendor's own wording rather than an assumed grace period. The examples below come from vendor terms and help pages as published; policies change, so re-check them before setting a cancel date.
Two patterns matter most. Some vendors cut off access at termination even if the data sits on their servers for a while longer, and some charge or require a written request from the account owner for a full backup. Both are easy to handle before cancellation and hard to handle after.
| Vendor | What its terms or help pages say | What to do before cancelling |
|---|---|---|
| HubSpot | For Sales, Service, CMS and Operations Hub subscriptions, no access to customer data after termination or expiration; retrieval before the term ends is strongly recommended | Take the full CRM export, including activity history, before the term ends |
| Slack | After subscriptions end, Slack may delete all customer data; no fixed number of days is stated | Run the workspace export while the plan is active |
| Pipedrive | No access after cancelling; a closed paid account is scheduled for permanent deletion within 180 days | Export deals, activities and notes before closing the account |
| BQE CORE | Data stays for 60 days after cancellation but cannot be accessed, then is deleted unless an extraction or backup was arranged; a CSV backup is available for a fee on the owner's written request, typically in 1 to 3 working days | Request the backup in writing well before the cancel date |
| Jobber | Cancelling preserves the account and allows re-subscribing to retrieve information; permanently closing is final | Cancel rather than permanently close until exports are verified |
| monday.com | Data is kept by default after cancellation, but deletion of inactive accounts is reserved at any time | Treat the window as unreliable and export first |
Phase five: cancel in reverse dependency order#
Phase five cancels systems in reverse dependency order, with the most connected systems last. Standalone tools go first once their rows are closed; help desks, CRMs and trackers follow; chat and file storage come next; single sign-on, email and the domain go last.
Keep the domain registered and email forwarding active for a period after everything else is gone. Vendors send deletion confirmations, final invoices and account notices to company addresses, and a lapsed domain can let someone else receive them.
Cancel payment methods after the subscriptions they fund, not before. A card closed early turns a planned cancellation into a failed payment, and some vendors suspend or delete accounts on non-payment faster than on a normal cancellation.
Illustrative: an engineering firm sequences its shutdown#
Illustrative: a fictional structural engineering firm is closing after its principals retire. Its records span Deltek Vantagepoint for projects and billing, Procore for RFIs and submittals, Bluebeam sessions for markups, and Microsoft 365 for email and files.
The original plan cancels everything at month end and deletes staff accounts as people leave. The operations manager instead freezes deletions, adds a second admin to each system, and exports Procore and Bluebeam history with attachments first. The assessment separates client deliverables, which stay with the firm's records custodian under its professional obligations, from internal review comments and RFI resolution histories, which are held for a licensing assessment.
Microsoft 365 and the domain stay active until the final exports are verified and the custodian confirms receipt.
Where SourceX fits in the sequence#
SourceX fits into phase four. A metadata-only fit check covering systems, years of history and record families tells the company whether any exports are worth holding for licensing, and nothing leaves the company at that stage.
If a package proceeds, the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery) works from the verified exports rather than the live systems, so subscriptions can close on the planned schedule.
Frequently asked questions
What if a subscription renews in the middle of the wind-down?
Decide before the renewal date whether the system is still needed. If its export is not yet verified, a short renewal or a cheaper plan may cost less than losing the records. If the export is complete, cancel before renewal and keep proof of the cancellation.
Can we downgrade instead of cancelling?
Sometimes, and it can buy time. Check what a downgrade does to data access first, because some lower plans restrict exports, history or attachments, which defeats the purpose. Downgrade only after the full export is taken, or confirm the lower plan keeps what you need.
Who should own the subscription register?
One person with authority, usually the COO, head of operations or IT lead, should own it, with each row assigned to a system owner. The register owner signs off each cancellation, which stops well-meant cost cutting from closing a system early.
What about work done in personal accounts?
Ask staff before they leave which personal tools held company work, such as personal Dropbox folders, notes apps or personal email. Have them move company files to company storage and confirm deletion of their copies. These records are often missed and cannot be recovered later.
How long do vendors keep data after cancellation?
It varies by vendor and plan, and some delete quickly. Read each vendor's terms and help documentation, record the window in the register, and treat any unconfirmed window as already closed when you plan the export.
Should we tell vendors we are closing?
Usually yes, once exports are verified. Some vendors offer extended read-only access or help with bulk exports when a customer is winding down, and telling them can prevent surprise renewals. Ask in writing and keep the response with the register.
Sources
- HubSpot's Product Specific Terms strongly recommend retrieving Customer Data before the Subscription Term ends; for Sales, Service, CMS and Operations Hub subscriptions, HubSpot will not provide any access to Customer Data after termination or expiration. Source
- Slack's Customer Terms of Service say that after a workspace's subscriptions end, Slack may, unless legally prohibited, delete all Customer Data; no fixed number of days is stated. Source
- Pipedrive says a closed paid account and its data are scheduled for permanent deletion within 180 days of closure, and the customer has no access after cancelling. Source
- BQE says data stays in CORE for 60 days after cancellation without access, then is deleted unless an extraction or backup was arranged; a CSV backup is available for a fee on the owner's written request, typically in 1 to 3 working days. Source
- Jobber says cancelling preserves the account and lets you re-subscribe to retrieve information, while permanently closing an account is final. Source
- monday.com keeps data available by default after cancellation but cannot guarantee this indefinitely and reserves the right to delete data from an inactive account at any time. Source
- According to Hunton Andrews Kurth, Slack API Terms effective May 29, 2025 prohibit bulk exporting of data accessible through Slack's APIs, creating persistent copies or archives, and using such data in large language models. Source
Related resources
- InsightInsolvency professionals' guide to AI-era data assets
- InsightLender consent before licensing company data: what credit agreements say
- InsightConversation intelligence vendors: can you train on or license customer calls?
- SolutionTurn the data your company already creates into a licensing asset
- SolutionOperational data: the step-by-step record of how work gets done
- IndustryBPO & contact centers data
See if your company qualifies
A short company assessment. No data uploads are needed.