Skip to content

Software companies

What does 'service improvement' mean in SaaS terms for AI training?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A service improvement clause in SaaS terms lets the vendor use customer data to maintain and improve its own service, such as fixing bugs or tuning features. It rarely supports licensing records to a third-party AI developer, because that use serves someone else's product. Read it with the definitions, DPA and confidentiality terms before relying on it.

Key takeaways

  • Service improvement wording is usually read as a purpose limited to the vendor's own service, not a general right to share.
  • Training models that power the vendor's own features is a closer fit than licensing records to an outside developer, though both depend on drafting.
  • The DPA, confidentiality clause, negotiated amendments and privacy statements can narrow what the main terms appear to allow.
  • A software company's own internal records, such as code reviews and engineering discussions, do not depend on this clause at all.

What does service improvement mean in SaaS terms?#

Service improvement in SaaS terms means the vendor may use customer data, or data about how customers use the product, to maintain, troubleshoot and enhance the service it provides to those customers. Typical wording permits use 'to provide, maintain and improve the Services' and sits in a data use or license grant section.

The phrase predates generative AI. It was written to cover debugging, performance monitoring, usage analytics and feature planning. Whether it also covers training machine learning models is now a live question, and drafting has split: some vendors add express AI language, while others still rely on the older phrase.

The reach of the phrase turns on the surrounding definitions. Services usually means the vendor's subscription product described in the order form, and Customer Data is often defined broadly to include anything customers upload or create. Read together, the clause permits use of customer data for that defined product.

Does service improvement wording cover AI training?#

Service improvement wording may cover training models that power features inside the vendor's own product, depending on drafting and what customers were told, but it rarely covers licensing customer records to a third-party AI developer. Licensing serves the developer's model and the developer's customers, which is a different purpose from improving the subscribed service.

Purpose language is read in context, and outcomes depend on facts. Counsel will look at whether training is within what customers would reasonably expect, whether one model is shared across many customers, and whether outputs could expose one customer's information to another.

The decision rule most counsel start from is simple. If records would leave the vendor's control and be used to build someone else's product, service improvement language is not a basis to rely on. New, express permission is.

Why is the phrase getting more scrutiny now?#

The phrase is getting more scrutiny because customers now read broad data use language as a possible AI training permission, and their reactions can be fast. In May 2024, TechCrunch reported that Slack drew user backlash after its privacy principles were found to allow customer data to train its machine-learning models unless an organization emailed Slack to opt out. Slack responded that it does not use customer data to train its generative AI large language models.

That episode turned on general machine-learning wording, not a third-party license, yet it still forced a public clarification. Procurement teams now ask vendors directly whether customer data trains any model, and enterprise customers increasingly negotiate explicit limits into their order forms.

For a vendor, that scrutiny changes the commercial calculation. Even where a reading of the clause is defensible, relying on it can cost renewals and add security questionnaire rounds that slow new sales. Clear, specific language usually costs less over time than an argument about what an older phrase meant.

Clause comparison: what common data use wording usually supports#

Common data use wording supports quite different activities, and the table shows how counsel often reads each pattern. The right-hand column is a starting point for analysis, not a conclusion about any particular contract.

The aggregated-data row causes the most confusion. A clause allowing use of aggregated statistics does not usually turn individual support tickets, documents or messages into the vendor's property, even after names are removed.

Clause comparison: what common data use wording usually supports
Typical wordingWhat it usually supportsThird-party AI licensing?
To provide and maintain the ServicesHosting, processing, support and securityNo
To improve the ServicesDebugging, analytics and feature work on the vendor's productRarely
To develop new products and servicesBroader internal product work, sometimes new offeringsUnclear; usually read as internal
Aggregated and de-identified data for any purposeStatistics and benchmarks that identify no customerPossibly for aggregates; rarely for underlying records
To train models that power features of the ServicesTraining the vendor's own in-product modelsNo; limited to the vendor's features
To license to third parties for AI training, with customer opt-inThe described use, within its stated scopeYes, within that scope

Which other documents can narrow the clause?#

Other contract documents can narrow a service improvement clause, and they often control when they conflict with the main terms. A vendor should read the full stack of documents before relying on any single sentence.

A negotiated amendment with a large customer can override the standard terms for that account. Vendors with many such amendments need an account-by-account view before starting any AI program that touches customer data.

  • Data processing agreement: often limits processing to the customer's documented instructions, which may exclude new purposes.
  • Confidentiality clause: may treat customer data as confidential information that cannot be disclosed beyond approved subprocessors.
  • Order forms and negotiated amendments: enterprise customers frequently add no-AI-training or no-secondary-use language.
  • Privacy policy and trust pages: public statements about data use create expectations regulators may hold the vendor to.
  • Subprocessor list: a new recipient of customer data usually needs to appear there, with notice to customers.
  • State privacy law terms: where customer data includes personal information, some US state privacy laws may limit a service provider's own use of it to the contracted purposes, so counsel checks them alongside the contract.

Illustrative: a vendor's counsel tests the clause#

Illustrative: a fictional vendor of project accounting software for engineering firms is asked whether it could license records for AI training. Its click-through terms allow use of customer data to provide, maintain and improve the Services.

The general counsel reads the clause alongside the DPA, which limits processing to customer instructions, and finds several enterprise amendments with no-secondary-use language. Her conclusion is that customer timesheets, invoices and project budgets cannot be licensed under the existing terms.

The company instead scopes its own records: support conversations with customer names removed, Jira issues, code review history and internal product documentation. A separate opt-in idea for customer data is parked until counsel drafts a standalone agreement.

What should general counsel check before relying on the clause?#

General counsel should check six points before relying on a service improvement clause for any AI use, because each one can change the answer. The checks work for a vendor reviewing its own terms and for a customer reviewing a vendor's.

The version history check matters most for long-lived products. Records from earlier years were collected under whatever terms applied then, and a later amendment does not automatically reach them.

What should general counsel check before relying on the clause?
CheckWhy it matters
How Services and Customer Data are definedSets whose product and which records the clause reaches
Whether training benefits only the vendor's productThird-party benefit moves the use outside improvement
DPA processing instructionsMay limit purposes more tightly than the main terms
Negotiated amendments and order formsLarge accounts often prohibit AI training or secondary use
Version history of the termsOlder records may carry older, narrower limits
Public statements about data usePrivacy, marketing and trust pages shape expectations

How SourceX treats service improvement clauses#

SourceX treats service improvement clauses as insufficient on their own for licensing customer records to third parties. During the Rights step of the SourceX five-step transaction, the supplier's counsel and SourceX map each record family to the contract that governs it.

Most software suppliers start with records they create themselves, such as engineering history and resolved support cases with customer details removed. The rights conclusion for each package is documented in the SourceX Evidence Packet alongside provenance, permitted use, the privacy record and release authorization.

Frequently asked questions

If our terms allow use to improve the Services, can we fine-tune our own model on customer data?

Possibly, if the model only powers features of your product and customers would reasonably expect that use. Counsel will also weigh your DPA, enterprise amendments, privacy statements and whether one customer's data could surface in outputs for another. Many vendors add express AI language rather than relying on the older phrase.

Does removing customer names make records licensable under the clause?

Usually not. De-identification reduces privacy risk but does not change the purpose limitation. If the clause permits use to improve your own service, licensing de-identified records to a third party is still a different purpose, so it typically needs separate permission.

Can we rely on wording about developing new products and services?

That wording is broader, but it is usually read as covering the vendor's own new offerings. Licensing records to an outside developer could be framed as a new service, yet customers and regulators may see it differently. Treat it as a question for review, not a settled permission.

Do these clauses affect internal records like Slack or Jira?

No. Service improvement clauses govern customer data and usage data. Records your company creates internally, such as engineering discussions, code reviews and internal documentation, depend on your own policies, employee notices and any third-party content inside them, not on customer terms.

Should we add express AI training language to our terms now?

If you plan any AI use of customer data, express language is clearer than relying on service improvement wording. Changes should apply going forward, be clearly noticed and be backed by consent for existing data where required. Changing terms safely has its own steps, covered in a separate guide.

Sources

  • TechCrunch reported on May 17, 2024 that Slack drew user backlash after its privacy principles were found to allow customer data to be used to train Slack's machine-learning models unless an organization emailed Slack to opt out, and Slack responded that it does not use customer data to train its generative AI large language models. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify