Getting started
What happens to your data when a software vendor shuts down or is acquired?
By SourceX Editorial · Updated
Short answer
When a software vendor shuts down, your data generally survives only as long as the export window and contract allow; when a vendor is acquired, your data usually moves with the contract to the new owner, whose terms can change at renewal. Rule: keep a current, complete, tested export of every system of record you could not rebuild.
Key takeaways
- Your contract, not the vendor's goodwill, decides export rights, formats, retrieval windows and deletion after termination.
- An acquisition normally transfers your contract and hosted data to the buyer; renewal is when terms, including AI clauses, tend to change.
- Product sunsets usually come with a migration path that may not carry all of your history.
- A standing export routine for systems of record costs far less than a rushed export during a shutdown.
What happens to your data in each scenario#
What happens to your data depends on whether the vendor closes, sells itself or retires a product. Each scenario gives you different notice, different export options and different leverage.
In every scenario the vendor is usually processing your records rather than owning them, but ownership language helps little if the servers are switched off before you export.
| Scenario | What usually happens to your data | Notice you can expect | Export steps | Protection steps |
|---|---|---|---|---|
| Orderly shutdown | Service ends after a wind-down period; data is deleted after the retrieval window | Whatever the contract promises, sometimes less in practice | Request full exports with attachments at once and verify completeness | Ask for deletion confirmation and keep your own copy |
| Acquisition by another company | Contract and hosted data pass to the acquirer, usually unchanged at first | An announcement, then notices of new terms or subprocessors | Take a fresh full export as a baseline | Review new terms at renewal, especially data use and AI clauses |
| Product sunset after acquisition | Customers are moved to another product or the service ends on a set date | An end-of-life notice with a migration offer | Export full history before migrating, not only what the tool carries | Check what history the new product imports and how long the old one stays readable |
| Insolvency or bankruptcy | Service may stop abruptly; hosted data and customer lists can be treated as assets in a sale | Often short or none | Pull data at the first signs of distress | Know where your data is hosted and who your contacts are |
The contract clauses that decide the outcome#
The contract clauses that decide what happens to your data are the ones about ownership, export, termination and assignment. Most teams read them for the first time during a crisis, when there is no leverage left to change them.
Negotiate these before signing or at renewal. A small vendor serving a niche market may accept a longer retrieval window or a scheduled full export in exchange for a longer term.
- Data ownership: the customer owns customer data, and the vendor's rights are limited to providing the service.
- Export rights: formats, completeness including attachments and audit logs, and whether exports cost extra.
- Post-termination retrieval: how long data stays available after the contract ends or the service stops.
- Deletion: when the vendor deletes data, including backups, and whether it confirms deletion in writing.
- Assignment and change of control: whether the vendor can transfer the contract to an acquirer without your consent.
- Data use: whether the vendor may use your content to improve products or train AI models, and whether renewal changes that.
- Escrow or continuity: any arrangement that gives you access to data or code if the vendor fails.
When the vendor is acquired#
When a vendor is acquired, your data usually stays where it is and your contract continues with a new owner. Change tends to arrive later, through product consolidation, new terms at renewal or a platform migration.
Watch for updated privacy policies, new subprocessors, revised data processing agreements and roadmap announcements that favor the acquirer's own product. Acquirers sometimes bring their own AI programs and add clauses about using customer content to improve them, so read renewal terms closely rather than clicking through.
An acquisition is also the moment to take a full baseline export. If the product is later retired, you will hold your history in a form you control, independent of what the migration tool chooses to carry over.
When the vendor shuts down or fails#
When a vendor shuts down in an orderly way, it typically announces an end date and a period for customers to export, after which data is deleted. When a vendor fails suddenly, service may stop with little warning and the export window may never open.
In insolvency, a vendor's assets can be sold, and the parties and the court have to work out what happens to hosted customer data and the commitments made about it. You will have limited influence over that process, which is why an export you already hold matters more than any claim you might file.
Your own obligations continue. If the vendor held personal information about your customers or employees, you remain the business that collected it, so you may need to confirm deletion and assess any notification duties with counsel.
Is SaaS data escrow worth it?#
SaaS data escrow is worth considering for systems your business cannot run without and cannot rebuild, such as a niche ERP, TMS or industry platform from a small vendor. For mainstream platforms with routine export tools, your own scheduled exports usually do the job.
Traditional escrow held source code, which helps little without the hosting environment and the data. SaaS-oriented arrangements may cover regular data deposits and sometimes the ability to keep the service running for a period after a failure. Check what is deposited, how often, who verifies it and what event releases it.
A standing export routine for systems of record#
A standing export routine treats each system of record as if its vendor could disappear, so a real shutdown becomes an inconvenience instead of a loss. The same routine produces the history you need for migrations, audits and any later reuse of the records.
Export frequency should follow how much new history each system adds and how hard it would be to recreate. A help desk or TMS that captures decisions every day deserves more frequent full exports than a document system that rarely changes.
History can also disappear without any vendor event, through plan limits. Slack, for example, says free workspaces can view only the last 90 days of messages and files and permanently delete content more than one year old. Check each system's retention and archiving behavior as part of the routine, not only its export tools.
- List every SaaS system and mark the ones holding records you could not rebuild.
- Schedule full exports for those systems, including attachments, comments, audit logs and lookup tables.
- Store exports in company-controlled storage with access logging and a retention rule.
- Restore a sample or query each export so you know it is usable.
- Document the schema and custom fields while the people who understand them are still around.
- Watch for warning signs: product freezes, declining support, layoffs, acquisition news or changed terms.
Illustrative: a freight broker's TMS is sunset#
Illustrative: a fictional freight brokerage runs on a niche TMS from a small vendor. The vendor is acquired by a larger competitor, which later announces that the product will be retired and that customers can migrate to its own platform.
The CTO takes a full export right after the acquisition news, including loads, carrier communications, rate confirmations and exception notes, and confirms the export can be queried. When the sunset notice arrives, the migration tool carries only open loads and recent history, so the archive in company storage becomes the only complete record.
During the retirement, the brokerage also reviews that archive for reuse. SourceX's fit check looks only at metadata such as system names, years of history and record families, and if a license proceeds through the SourceX five-step transaction, a large archive stays in the company's own storage or ships on encrypted drives.
Frequently asked questions
Does the acquiring company own my data after the deal?
Generally no. The acquirer steps into the vendor's position under your contract, which usually says the customer owns customer data and limits the vendor's use. What can change is the contract itself at renewal, so read new terms about data use, subprocessors and AI before accepting them.
Can an acquirer use my data to train its AI?
Only as far as your contract and any updated terms allow. Some vendors now include clauses permitting use of customer content to improve services or models, sometimes with opt-outs. Review renewal terms and data processing agreements, and negotiate exclusions for records you may want to license or keep confidential.
What if the vendor's export leaves out attachments or history?
Raise it immediately and in writing, citing your contract's export clause. Ask for an API-based extract, a database export or professional services help. Document what is missing, because gaps discovered after shutdown cannot be fixed, and incomplete exports weaken both continuity and any later use of the archive.
How long should we keep a final export from a retired vendor?
As long as your retention schedule requires for each record type, and no longer for personal information whose purpose has ended. Financial records often have defined retention needs. Other history may be worth keeping for reference or reuse, which is a decision to make deliberately with counsel.
Who should monitor vendor health?
Usually IT or procurement, with input from the business owner of each system. A short periodic review of critical vendors, covering ownership changes, product announcements, support quality and contract dates, is enough to trigger an extra export before trouble arrives.
Sources
- Slack says free workspaces can view and search messages and files from the last 90 days, older content is hidden, and messages and files more than one year old are permanently deleted. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.