Skip to content

Software companies

SaaS shutdown: what you owe customers about their data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In a SaaS shutdown, you owe customers what your contracts and privacy commitments promise: notice, a fair chance to export their data, and deletion across production, backups and sub-processors, usually confirmed in writing. Customer content is theirs. Your own code, internal documents and company records generally stay yours, subject to privacy limits.

Key takeaways

  • Shutdown obligations come from the master agreement, the data processing agreement, the privacy policy and applicable privacy law, read together.
  • A shutdown notice should state three dates: read-only mode, end of export and deletion.
  • Deletion covers backups and sub-processors, and a deletion certificate should say how each was handled.
  • Customer content is not yours to keep or license; your own company records generally are, subject to privacy limits.

Where do your data obligations come from?#

Data obligations in a SaaS shutdown come from several documents at once, and the strictest one usually governs. Founders often check the terms of service and miss the data processing agreement or a large customer's negotiated addendum.

Build a single obligations register from these sources, with one row per customer wherever terms differ. The register becomes the shutdown plan and, later, the proof that you followed it.

Where documents conflict, a negotiated addendum usually overrides the standard terms for that customer, and privacy laws that may apply can override both. Note each conflict in the register and resolve it with counsel before the notice goes out.

Where do your data obligations come from?
SourceWhat it usually coversWhere to look
Master agreement or terms of serviceTermination notice, data export and return, suspensionTermination and effect-of-termination clauses
Data processing agreementReturn or deletion of personal data, sub-processors, certificationEnd-of-processing and audit clauses
Order forms and negotiated addendaCustomer-specific notice, export formats or transition helpEach large customer's signed paper
Privacy policyPromises to end users about retention and transferRetention, sale and business transfer sections
Security commitmentsSecure deletion and media handlingSecurity exhibits and past questionnaire answers
Privacy lawsIndividual rights and controller instructionsGDPR, CCPA and other laws that may apply

The shutdown data checklist#

The shutdown data checklist runs in a fixed order so customers can act before anything is lost. Give every item an owner and a date, and do not start deletion until the export window has closed.

Two items are easy to forget. Prepaid subscriptions may call for refunds of the unused period under your terms, which changes how much cash the wind-down needs, and integrations that push data into customers' other systems should be switched off cleanly so no half-synced records are left behind.

  • Confirm the obligations register and flag customers with negotiated terms.
  • Send written notice with the read-only date, the export deadline and the deletion date.
  • Keep export tools and APIs working through the export window, and test them on the largest tenants.
  • Deliver data in the format your contract promises, not the one that is easiest to produce.
  • Switch to read-only mode, then stop processing new data.
  • Delete customer data from production, replicas, logs, analytics stores and file storage.
  • Instruct each sub-processor to delete, and collect written confirmations.
  • Let backups expire or destroy them on the schedule you disclosed.
  • Issue deletion certificates and file them with the obligations register.
  • Close vendor accounts and keep a record of everything that was done.

How long should the export window be?#

The export window should be at least as long as your contracts require and long enough for your largest customer to move. Where contracts are silent, choose a period a reasonable customer could actually use, because a rushed window invites disputes.

Announce the window as calendar dates rather than durations, and repeat it as the deadline approaches. Offer self-serve export for most customers and a named contact for the few with large or complex tenants. Record who exported, when and in which format, since that record answers later claims that data was lost.

If a customer misses the window, check the contract before deleting. Some agreements require a final reminder or a short extension on request, and a written note that the customer declined to export protects you.

What should a deletion certificate state?#

A deletion certificate is a short signed statement telling a customer what was deleted, where and when. It turns an internal process into evidence the customer can file for its own audits.

Do not certify more than you did. A certificate that claims deletion from backups that have not yet expired is worse than one that states the expiry date honestly.

What should a deletion certificate state?
ElementWhat to state
ScopeThe customer account, tenants and data categories covered
SystemsProduction databases, file storage, search indexes, logs and analytics stores
BackupsHow backups were handled and when the last copy expires or was destroyed
Sub-processorsWhich providers were instructed to delete, and their confirmations
ExceptionsAnything retained under law or legal hold, and why
Method and dateHow deletion was performed and the completion date
SignerAn officer authorized to sign for the company

What stays yours after customers leave?#

Your own company records generally stay yours after customers leave, while customer content does not. The line is clearer in principle than in practice, because many company records mention customers.

Start with how your data processing agreement defines customer data. Some definitions cover anything a customer submits to you, including through support channels, which pulls support tickets and uploaded troubleshooting files into the deletion duty; others cover only data processed within the service. The definition, not the system a record sits in, decides which side of the line it falls on.

What stays yours after customers leave?
RecordWhose it usually is after shutdownWhat customers may ask for
Customer content, uploads and user accountsThe customer'sExport in the promised format, then deletion with a certificate
Activity and audit logs for a customer's tenantUsually the customer's, as part of its dataInclusion in the export where the contract promises it
Support tickets the customer's users filedYour business records, unless the DPA definition says otherwiseDeletion of personal details on request where privacy law applies
Invoices, contracts and payment recordsYoursCopies for their files; you keep originals for tax and audit
Aggregated usage statisticsYours only where contracts allow aggregated or de-identified useAssurance that no customer can be identified
Source code, internal docs and product specsYours, subject to contractor and open-source termsCode release, if an escrow agreement is triggered by the shutdown

Illustrative: a proposal software startup winds down#

Illustrative: a fictional proposal software startup serving marketing agencies decides to close. Its terms promise notice and an export, and its data processing agreement requires deletion with written confirmation on request.

The founder sends notice with three dates, keeps the PDF and CSV export running, and assigns an engineer to help the two largest agencies migrate. After the deadline, the team deletes tenant data, instructs its email delivery and file storage providers to delete, and sends certificates that state when the last backups expire.

The company keeps its code, Jira history and help desk archive. Before deciding what to do with them, the founder strips customer content from the archive and records which records are company-owned, so any later sale or license starts from a clean rights record.

How SourceX fits into a shutdown#

SourceX looks only at records the company itself controls; customer content is excluded unless a customer chooses to license its own data as a separate supplier. The fit check collects metadata, such as systems, years of history and record families, so nothing is shared while the shutdown is underway.

If company-owned records qualify, the SourceX five-step transaction moves them through Supply, Rights, Preparation, Approval and Delivery, and the SourceX Evidence Packet records the privacy steps alongside your deletion evidence.

Frequently asked questions

Can we sell customer data as part of the shutdown?

Usually not. Customer content belongs to customers, and data processing agreements typically require return or deletion at the end of service. Privacy policies may also limit transfers of personal data. Company-owned records are a separate question, assessed with counsel against your contracts and the laws that may apply.

What if customers never respond to the notice?

Follow the contract: send notice to the addresses it specifies, send reminders and keep proof of delivery. After the export deadline, delete as promised and keep a record that the customer was notified and did not export. Silence does not usually extend your duty to keep hosting.

Do we need to tell regulators we are shutting down?

Most shutdowns do not trigger a regulator notice simply because the company closes, but specific licenses, regulated sectors or a recent data incident can change that. Check whether any registrations, certifications or open inquiries require notice, and ask counsel about the jurisdictions where your users are.

What about data held by our sub-processors?

Your deletion promise usually covers data your sub-processors hold for you, such as email delivery logs, file storage and analytics events. Send each one a written deletion instruction, collect confirmations and list them in the deletion certificate. Close those accounts only after the confirmations arrive.

Can an acquirer take over customer data instead of us deleting it?

Sometimes, if contracts allow assignment, customers are notified or consent, and privacy promises permit the transfer. That route is a sale of the business or its contracts rather than a shutdown, and it carries its own notice requirements. Review it with counsel before committing to deletion.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify