Software companies
Who owns usage data and telemetry in a B2B SaaS contract?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In most B2B SaaS contracts the customer owns its customer data, while the vendor claims usage data, telemetry and service data about how the product is used and runs, usually with limits. The definitions clause decides ownership, not the label. A vendor can generally license only what the contract assigns to it or lets it use beyond the service.
Key takeaways
- Customer data is the content customers put into the product; usage data and telemetry describe activity around that content.
- A broad definition of non-personal usage data can quietly sweep in customer content, which customers and courts may read against the vendor.
- Event payloads, error logs and search queries often contain customer content even when they are labeled telemetry.
- Personal data inside telemetry, such as user IDs and IP addresses, keeps its privacy obligations whatever the contract calls it.
- Map each field in a usage dataset to a contract definition before deciding it can be licensed.
Usage data, telemetry and service data defined#
Usage data, telemetry and service data are related contract terms for information the product generates as customers use it, as opposed to the content customers put into it. Contracts define them differently, and the definition in your MSA governs, but the terms below show how they are commonly drawn.
| Term | What it usually covers | Usual ownership position | Where disputes start |
|---|---|---|---|
| Customer data or customer content | Records, files, messages and fields customers enter or upload | Customer owns; vendor has a license to provide the service | Rarely contested |
| Usage data | Who used which feature, when, how often, and in what sequence | Vendor claims ownership or broad use rights | Definitions that include anything collected through the service |
| Telemetry | Technical signals such as latency, errors, device and browser details | Vendor claims ownership | Error logs and payloads that copy customer content |
| Service data | Operational records of running the platform, such as job logs and capacity metrics | Vendor claims ownership | Logs that record record titles or file names |
| Aggregated data | Statistics combined across customers so no customer or person is identified | Vendor owns, often with a no-identification condition | Whether small groups or AI training count as aggregation |
| Derived data and outputs | Scores, classifications or summaries computed from customer data | Often unaddressed | Whether derivation strips the customer's rights |
Why the definitions clause decides ownership#
The definitions clause decides ownership because the operative grant usually says the vendor owns usage data as defined, and nothing more. If the definition covers data about the use of the service, the vendor's claim is limited to activity information. If it covers all data collected through the service other than customer data, the boundary depends on how narrowly customer data is defined, and that is where many disputes begin.
Broad definitions of non-personal usage data are a frequent target in procurement negotiations. Enterprise customers often push for language that usage data excludes customer content and is used only to operate, secure and improve the vendor's own services, which would leave no room for licensing it to a third party.
Privacy law adds a separate layer. User IDs, IP addresses and device identifiers in telemetry may be personal data or personal information under laws such as GDPR and CCPA, and a vendor's contractual ownership does not remove obligations that attach to that information.
Sample wording: vendor-owned or customer-owned#
Sample clause wording makes the ownership positions concrete. The patterns below are illustrative paraphrases for discussion with counsel, not drafting templates, and each one changes what a vendor could later license.
| Position | Illustrative wording pattern | Effect on licensing |
|---|---|---|
| Vendor-owned, broad | Provider owns all Usage Data and may use it for any lawful purpose, provided it does not identify Customer or any individual | Strongest basis, if the data truly excludes customer content |
| Vendor-owned, AI expressly permitted | Provider may use de-identified Usage Data and Aggregated Data to develop and train AI models and may license it to third parties for that purpose | Clearest basis for third-party AI licensing |
| Vendor license, limited purpose | Provider may use Usage Data solely to provide, secure and improve the Services | Little or no basis for third-party licensing |
| Customer-owned | Usage Data generated by Customer's users is Customer Data | Treat as customer content; needs customer permission |
What a SaaS vendor can usually license#
A SaaS vendor can usually license usage records only after separating the activity skeleton from any customer content riding along with it. Event names, timestamps, feature paths, workflow step sequences and performance metrics tend to sit on the vendor side. Free text, file names, record titles and field values copied into event payloads tend to sit on the customer side.
Before deciding, sample the actual data rather than the schema. A column called properties or payload in a product analytics table often contains whatever the front end sent, including search terms users typed.
- Pull a sample of raw events and logs from the warehouse, not just the event catalog.
- Tag each field as activity, technical, customer content or personal data.
- Map each tag to the definition in your current MSA, and to older MSA versions still in force.
- Strip or exclude fields tagged as customer content unless customer permission exists.
- Pseudonymize user and account identifiers, and assess re-identification risk for small accounts.
- Document the mapping so a licensee and an auditor can follow it.
Disclosing telemetry licensing to customers#
Disclosing telemetry licensing keeps the vendor's practice consistent with what customers were told. Check the privacy policy, the trust center, the data processing addendum and any security questionnaire answers already given to customers, since a statement that usage data is never shared with third parties can contradict a planned license.
Where the current definition is too narrow, the cleaner route is a revised usage data clause at renewal that names AI training and third-party licensing expressly. That is slower than reinterpreting old wording, but it avoids a dispute with the customers whose trust the product depends on.
Illustrative: a field service SaaS vendor reads its own paper#
Illustrative: a fictional software vendor serving elevator maintenance contractors holds years of product events in its data warehouse, showing how dispatchers assign jobs, reschedule visits and close work orders. Its MSA says the vendor owns usage data, defined as data about the use of the services.
The general counsel samples the events and finds that the close-work-order event carries the technician's free-text notes and the building address. Event names, step sequences, timestamps and durations fit the usage data definition. The notes and addresses are customer data.
The company decides to license only the stripped event stream, with account and user IDs pseudonymized, for workflow sequence modeling. It adds an aggregated data clause naming AI training to its renewal paper so future versions of the dataset rest on express language.
How SourceX reviews usage data rights#
SourceX reviews usage data in the Rights step of the SourceX five-step transaction, field family by field family, against the contract definitions actually in force. The mapping, the exclusions and the pseudonymization method are recorded in the SourceX Evidence Packet under licensing rights, permitted use and the privacy record.
Value is assessed separately using the SourceX Enterprise Data Value Framework. Raw click streams are usually less useful than workflow sequences tied to outcomes, such as a job that was rescheduled and then closed, so the rights review and the value review together decide what goes into a package.
Frequently asked questions
Is telemetry personal data?
It can be. Telemetry that includes user IDs, IP addresses, device identifiers or precise timestamps tied to a person may be personal data under GDPR or personal information under CCPA and similar laws. Whether it is depends on the fields and on how easily they can be linked to an individual, which counsel assesses for each dataset.
Does owning aggregated data let us license raw usage logs?
Usually not. Aggregated data clauses typically cover statistics combined across customers so no customer or person is identified. Raw event logs are row-level records. Licensing them generally needs a usage data clause that covers row-level use, or further processing that genuinely aggregates or de-identifies them.
Can customers demand deletion of usage data when the contract ends?
That depends on the contract. Many MSAs require deletion of customer data at termination but let the vendor keep usage data. If your usage data definition is broad enough to overlap with customer data, a customer may argue the deletion duty applies to it too.
Do free trial and self-serve users change the analysis?
They sign clickwrap terms rather than negotiated MSAs, which often give the vendor broader usage data rights. Privacy obligations still apply to individual users, and older versions of the terms may govern data collected under them, so keep a record of which terms version each account accepted.
Should we tell customers before licensing usage data?
Telling customers is not always legally required, but it is often wise, and some contracts or privacy notices may require it. At minimum, make sure nothing the company has already said in its privacy policy, trust center or security questionnaires contradicts the plan.
Related resources
- QuestionIs selling company data legal?
- QuestionHow are data licensing payments made?
- InsightCan law firms sell their data to AI companies?
- InsightSelling contracts and legal documents to AI companies: what to know
- InsightCan I sell legal briefs and memos to AI companies?
- SolutionData licensing: granting defined rights to use your data
See if your company qualifies
A short company assessment. No data uploads are needed.