Software companies
SaaS shutdown: what you owe customers about their data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In a SaaS shutdown, you owe customers what your contracts and privacy commitments promise: notice, a fair chance to export their data, and deletion across production, backups and sub-processors, usually confirmed in writing. Customer content is theirs. Your own code, internal documents and company records generally stay yours, subject to privacy limits.
Key takeaways
- Shutdown obligations come from the master agreement, the data processing agreement, the privacy policy and applicable privacy law, read together.
- A shutdown notice should state three dates: read-only mode, end of export and deletion.
- Deletion covers backups and sub-processors, and a deletion certificate should say how each was handled.
- Customer content is not yours to keep or license; your own company records generally are, subject to privacy limits.
Where do your data obligations come from?#
Data obligations in a SaaS shutdown come from several documents at once, and the strictest one usually governs. Founders often check the terms of service and miss the data processing agreement or a large customer's negotiated addendum.
Build a single obligations register from these sources, with one row per customer wherever terms differ. The register becomes the shutdown plan and, later, the proof that you followed it.
Where documents conflict, a negotiated addendum usually overrides the standard terms for that customer, and privacy laws that may apply can override both. Note each conflict in the register and resolve it with counsel before the notice goes out.
| Source | What it usually covers | Where to look |
|---|---|---|
| Master agreement or terms of service | Termination notice, data export and return, suspension | Termination and effect-of-termination clauses |
| Data processing agreement | Return or deletion of personal data, sub-processors, certification | End-of-processing and audit clauses |
| Order forms and negotiated addenda | Customer-specific notice, export formats or transition help | Each large customer's signed paper |
| Privacy policy | Promises to end users about retention and transfer | Retention, sale and business transfer sections |
| Security commitments | Secure deletion and media handling | Security exhibits and past questionnaire answers |
| Privacy laws | Individual rights and controller instructions | GDPR, CCPA and other laws that may apply |
The shutdown data checklist#
The shutdown data checklist runs in a fixed order so customers can act before anything is lost. Give every item an owner and a date, and do not start deletion until the export window has closed.
Two items are easy to forget. Prepaid subscriptions may call for refunds of the unused period under your terms, which changes how much cash the wind-down needs, and integrations that push data into customers' other systems should be switched off cleanly so no half-synced records are left behind.
- Confirm the obligations register and flag customers with negotiated terms.
- Send written notice with the read-only date, the export deadline and the deletion date.
- Keep export tools and APIs working through the export window, and test them on the largest tenants.
- Deliver data in the format your contract promises, not the one that is easiest to produce.
- Switch to read-only mode, then stop processing new data.
- Delete customer data from production, replicas, logs, analytics stores and file storage.
- Instruct each sub-processor to delete, and collect written confirmations.
- Let backups expire or destroy them on the schedule you disclosed.
- Issue deletion certificates and file them with the obligations register.
- Close vendor accounts and keep a record of everything that was done.
How long should the export window be?#
The export window should be at least as long as your contracts require and long enough for your largest customer to move. Where contracts are silent, choose a period a reasonable customer could actually use, because a rushed window invites disputes.
Announce the window as calendar dates rather than durations, and repeat it as the deadline approaches. Offer self-serve export for most customers and a named contact for the few with large or complex tenants. Record who exported, when and in which format, since that record answers later claims that data was lost.
If a customer misses the window, check the contract before deleting. Some agreements require a final reminder or a short extension on request, and a written note that the customer declined to export protects you.
What should a deletion certificate state?#
A deletion certificate is a short signed statement telling a customer what was deleted, where and when. It turns an internal process into evidence the customer can file for its own audits.
Do not certify more than you did. A certificate that claims deletion from backups that have not yet expired is worse than one that states the expiry date honestly.
| Element | What to state |
|---|---|
| Scope | The customer account, tenants and data categories covered |
| Systems | Production databases, file storage, search indexes, logs and analytics stores |
| Backups | How backups were handled and when the last copy expires or was destroyed |
| Sub-processors | Which providers were instructed to delete, and their confirmations |
| Exceptions | Anything retained under law or legal hold, and why |
| Method and date | How deletion was performed and the completion date |
| Signer | An officer authorized to sign for the company |
What stays yours after customers leave?#
Your own company records generally stay yours after customers leave, while customer content does not. The line is clearer in principle than in practice, because many company records mention customers.
Start with how your data processing agreement defines customer data. Some definitions cover anything a customer submits to you, including through support channels, which pulls support tickets and uploaded troubleshooting files into the deletion duty; others cover only data processed within the service. The definition, not the system a record sits in, decides which side of the line it falls on.
| Record | Whose it usually is after shutdown | What customers may ask for |
|---|---|---|
| Customer content, uploads and user accounts | The customer's | Export in the promised format, then deletion with a certificate |
| Activity and audit logs for a customer's tenant | Usually the customer's, as part of its data | Inclusion in the export where the contract promises it |
| Support tickets the customer's users filed | Your business records, unless the DPA definition says otherwise | Deletion of personal details on request where privacy law applies |
| Invoices, contracts and payment records | Yours | Copies for their files; you keep originals for tax and audit |
| Aggregated usage statistics | Yours only where contracts allow aggregated or de-identified use | Assurance that no customer can be identified |
| Source code, internal docs and product specs | Yours, subject to contractor and open-source terms | Code release, if an escrow agreement is triggered by the shutdown |
Illustrative: a proposal software startup winds down#
Illustrative: a fictional proposal software startup serving marketing agencies decides to close. Its terms promise notice and an export, and its data processing agreement requires deletion with written confirmation on request.
The founder sends notice with three dates, keeps the PDF and CSV export running, and assigns an engineer to help the two largest agencies migrate. After the deadline, the team deletes tenant data, instructs its email delivery and file storage providers to delete, and sends certificates that state when the last backups expire.
The company keeps its code, Jira history and help desk archive. Before deciding what to do with them, the founder strips customer content from the archive and records which records are company-owned, so any later sale or license starts from a clean rights record.
How SourceX fits into a shutdown#
SourceX looks only at records the company itself controls; customer content is excluded unless a customer chooses to license its own data as a separate supplier. The fit check collects metadata, such as systems, years of history and record families, so nothing is shared while the shutdown is underway.
If company-owned records qualify, the SourceX five-step transaction moves them through Supply, Rights, Preparation, Approval and Delivery, and the SourceX Evidence Packet records the privacy steps alongside your deletion evidence.
Frequently asked questions
Can we sell customer data as part of the shutdown?
Usually not. Customer content belongs to customers, and data processing agreements typically require return or deletion at the end of service. Privacy policies may also limit transfers of personal data. Company-owned records are a separate question, assessed with counsel against your contracts and the laws that may apply.
What if customers never respond to the notice?
Follow the contract: send notice to the addresses it specifies, send reminders and keep proof of delivery. After the export deadline, delete as promised and keep a record that the customer was notified and did not export. Silence does not usually extend your duty to keep hosting.
Do we need to tell regulators we are shutting down?
Most shutdowns do not trigger a regulator notice simply because the company closes, but specific licenses, regulated sectors or a recent data incident can change that. Check whether any registrations, certifications or open inquiries require notice, and ask counsel about the jurisdictions where your users are.
What about data held by our sub-processors?
Your deletion promise usually covers data your sub-processors hold for you, such as email delivery logs, file storage and analytics events. Send each one a written deletion instruction, collect confirmations and list them in the deletion certificate. Close those accounts only after the confirmations arrive.
Can an acquirer take over customer data instead of us deleting it?
Sometimes, if contracts allow assignment, customers are notified or consent, and privacy promises permit the transfer. That route is a sale of the business or its contracts rather than a shutdown, and it carries its own notice requirements. Review it with counsel before committing to deletion.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.