Skip to content

Privacy and preparation

Service provider or third party: when a SaaS company cannot license customer data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A SaaS company acting as a CCPA service provider, or as a processor under other state laws, generally cannot license customer data to an AI developer, because it holds that data only to serve each customer under contract. The decision rule: data processed on customers' behalf is theirs to authorize, while your own operational records get a separate review.

Key takeaways

  • Your role is set dataset by dataset: the same company can be a service provider for customer content and a business for its own records.
  • Service provider contracts generally bar using customer personal information outside the contract, and licensing it to an AI developer is a new purpose.
  • Stepping outside the service provider role can turn a customer's disclosure into a sale that neither side planned for.
  • Engineering history, internal documentation and support replies your team wrote are the usual starting point for a SaaS licensing scope.
  • A terms update rarely reaches data already collected, and negotiated DPAs usually take precedence over click-through terms.

What separates a service provider from a third party?#

A service provider processes personal information on a business's behalf, for that business's purposes, under a written contract that limits what the provider may do with it; a third party is anyone else who receives the information. Under the CCPA, the label in your marketing does not decide the role. What you actually do with the data does.

Most other state privacy laws use the controller and processor pair instead. A processor acts on the controller's instructions, and a processor that starts deciding its own purposes for the data can be treated as a controller for that processing. The practical effect is the same: data you hold to run your customers' accounts is governed by their decisions, not yours.

The role is set dataset by dataset. A project management SaaS company is usually a service provider for the tasks, files and comments its customers store in the product, and a business in its own right for its sales pipeline, its engineering history and the internal notes its staff write.

Why does the role decide whether you can license customer data?#

The service provider role decides the question because the contract that creates the role generally forbids the use that licensing requires. Service provider and processor terms typically bar retaining, using or disclosing personal information for any purpose other than the services, prohibit selling or sharing it, and limit combining it with data from other sources.

Licensing customer content to an AI developer is a purpose of your own, for your own benefit. That moves you outside the role for that data. Counsel may then see two problems at once: a breach of the customer contract, and a disclosure the customer never described to its own users, which could be characterized as a sale by the customer, by you, or by both.

Enterprise customers usually add their own layer through negotiated data processing agreements. Those often include audit rights, notice duties for new subprocessors, deletion at termination and indemnities, so a single unauthorized use can surface across many accounts at once.

A decision table for common SaaS record families#

SaaS record families fall on different sides of the line, so sort them before anyone discusses scope. The table shows the usual starting position; contracts and notices can move any row.

Support tickets deserve the closest look. The ticket thread belongs to your support operation, but customers routinely paste their own data into it: exports, screenshots, record IDs and sometimes end-user details. Those embedded pieces remain customer data even inside your helpdesk.

A decision table for common SaaS record families
Record familyUsual roleLicensable without new customer authorization?What decides it
Content customers store in the product: files, messages, recordsService provider or processorGenerally noCustomer contracts and DPAs; each customer would need to authorize
Personal information about your customers' end usersService provider or processorGenerally noYou have no direct relationship with those people
Support tickets customer admins file with youOften your own business recordsSometimes, after reviewConfidentiality clauses, your privacy notice, customer content pasted into tickets
Product telemetry and usage logsMixedSometimes, if free of customer contentWhether logs capture payloads, file names or end-user identifiers
Jira issues, code reviews and release historyYour own recordsUsually yesSecrets, customer names and third-party code inside them
Sales and CRM historyYour own recordsOften, after reviewCustomer confidentiality terms and business contact rules

Does a service-improvement clause change the answer?#

A service-improvement clause usually does not change the answer, because it lets a provider improve its own service, not hand data to an outside developer. Many DPAs, and the CCPA rules for service providers, allow some internal use to build or improve the service under conditions. Licensing to a third party for its model training generally sits outside that permission.

Watch for aggregated or anonymized data clauses in master subscription agreements. Some give the vendor rights to statistics derived from customer data. Read whether the clause allows disclosure to third parties, whether it covers content or only usage metrics, and whether the promised anonymization meets the deidentification standard in the state laws that may apply.

Where the clause is broad, counsel should still weigh how customers understood it. A clause written for benchmarking dashboards is a weak foundation for licensing ticket text or documents to an AI developer. Read these defined terms in the master agreement and DPA side by side.

  • Aggregated data or statistics: does it cover content or only metrics, and may results be disclosed outside your company?
  • Usage data or service data: does the definition reach event payloads, file names or free-text fields?
  • Service improvement: is the permission limited to your own service and to internal use?
  • Deidentified data: does the clause describe the safeguards, public commitment and recipient contracts that state laws may expect?
  • Feedback: this usually covers suggestions customers send you, not the content they store in the product.

Can you change your terms to allow licensing?#

Changing your terms can support licensing of data collected after the change, under conditions, but it rarely reaches data already collected. A retroactive change to permit a materially different use is the riskiest route, and consumer protection law may treat a quiet change as unfair or deceptive.

Negotiated agreements add another limit. Enterprise customers with signed DPAs usually have order-of-precedence clauses that put their DPA above your online terms, so a click-through update does not amend them. Each would need its own signed amendment.

Some vendors build an opt-in program instead: a separate agreement under which a customer chooses to contribute specific data, with defined preparation steps and the right to stop contributing future data. That is a negotiation with each customer, not a terms update.

Illustrative: a workforce scheduling vendor sorts its records#

Illustrative: a fictional workforce scheduling SaaS company sells to restaurant groups and retail chains. Its product stores shift schedules, time-off requests and pay rates for its customers' workers. It runs support in Zendesk, engineering in Jira and GitHub, and sales in Salesforce.

Counsel classifies the product database as service provider data and excludes it entirely, including backups and analytics copies. Support tickets stay in scope only after preparation removes the worker schedules and names that customer admins pasted into them. Jira issues, code reviews and release notes are company records and form the core of the package.

The resulting scope is narrower than the founders first imagined, but every record in it has a clear owner. No customer contract needed amending, and the answers the company gives in customer security questionnaires stayed accurate.

Questions counsel will ask before scoping#

Counsel's first questions map every record family to a role and a contract, so prepare the answers before the first meeting. Most can be answered from the contract repository, the trust center and a short call with the CTO.

  • Which customer contracts and DPAs name you a service provider, processor or subprocessor?
  • Which customers signed negotiated DPAs, and what do their precedence clauses say?
  • Does your master agreement include an aggregated data or usage data clause, and what exactly does it permit?
  • What do your privacy notice, trust center and past questionnaire answers say about AI and model training?
  • Which systems hold customer content, including backups, logs and analytics copies?
  • What deletion or return obligations apply to data from customers who have left?
  • Which state privacy laws may apply to the people named in your own records?

How SourceX handles the service provider question#

SourceX addresses the service provider question in the Rights step of the SourceX five-step transaction, working with the supplier's counsel before any preparation starts. Record families a company holds on its customers' behalf are separated from the company's own operational records, and only the latter move forward unless customers have authorized otherwise in writing.

The decision is recorded in the SourceX Evidence Packet under licensing rights and permitted use, so the supplier, its counsel and the buyer see the same basis for every record family in the package.

Frequently asked questions

Does deidentifying customer data make it ours to license?

Not by itself. Deidentification addresses privacy law, but the customer contract still governs what you may do with data you hold on the customer's behalf. If the contract limits use to providing the service, removing names does not create a new right to license the remaining content to a third party.

What if one customer wants to take part?

A customer can authorize specific data through a separate written agreement that names the purpose, the type of recipient, the preparation steps and what happens if the customer withdraws. That customer's own end users and privacy notices then need review, because the customer becomes the business deciding to disclose.

Do EU customers raise different issues?

They can. Under GDPR, a processor that uses personal data for its own purposes may be treated as a controller for that processing, with its own legal basis and transparency duties. Agreements with EU customers usually restrict purposes tightly, so counsel should review them alongside US state laws.

Is product usage data safe to include?

Usage data can be in scope when it describes how the product behaves and holds no customer content or end-user identifiers. Check event payloads, URLs, file names and free-text fields, which often carry customer content, then check the master agreement for limits on usage data.

Who inside the company should sign off on the role analysis?

The general counsel or outside privacy counsel should own the analysis, with the CTO confirming where each record family lives and customer success confirming which accounts hold negotiated terms. The CEO, as authorized signer, approves the final scope.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify