Skip to content

Getting started

Who sees your data during a licensing process?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

During a data licensing process, only a few named people see your records, and access widens in steps you approve. The intermediary sees metadata at the fit check. A buyer's evaluators see a prepared sample you approved, under a confidentiality agreement. The licensee's named team receives the full dataset only after a signed license.

Key takeaways

  • Access widens in steps: metadata first, then an approved sample, then the licensed dataset.
  • Every stage should name who sees what, under which signed agreement, before anything moves.
  • People who handle full records during preparation should be few, named and bound by confidentiality.
  • You can decline specific buyers and decide when your company's name is disclosed.

Who sees what at each stage#

Who sees your data depends on the stage, and access should widen only after a decision you make. The table shows a typical sequence for licensing operational records to AI developers.

Two patterns matter. Each step widens access only after an approval, and the agreement that governs each step is signed before the step begins, not after.

Who sees what at each stage
StageWhat is visibleWho sees itGoverning agreement
Fit checkMetadata: systems, record families, years of history, known restrictionsYour team and the intermediaryIntermediary terms, plus a mutual NDA if you want one
Buyer interestA dataset description, often without your company nameProspective buyersIntermediary terms with buyers; an NDA before any detail
SampleA small prepared sample you approvedNamed evaluators at one buyerNDA plus evaluation terms
PreparationFull in-scope records during redaction and reviewYour staff and named preparation reviewersServices agreement and confidentiality terms
DeliveryThe final approved datasetThe licensee's named teamSigned license agreement
After the termNothing newNo one, once deletion is confirmedDeletion and certification clauses

Who inside your own company needs to see it#

Inside your company, the people who see the records should be those who already handle them, plus the few who must approve the license. That usually means the CEO or owner, the CTO or IT lead who runs exports, counsel, and the head of the function that created the records, such as support or operations.

Keep the group small and named. Exports should land in a restricted folder rather than a shared drive, and the people reviewing samples should be the ones who know which customers or projects need to be excluded.

Directors, investors and lenders usually need to know about the license but do not need to see records. Give them the scope, the exclusions and the approval request rather than samples. That keeps the circle of people who have read actual customer conversations or job notes as small as possible.

What the intermediary sees, and what it should not need#

An intermediary sees metadata at the start and, if you proceed, may handle full records during preparation under a written agreement. It should not need standing access to your live systems, admin credentials or records outside the agreed scope.

Human review is part of preparation for a reason. Automated detection helps, but the documentation for Presidio, an open-source PII detection tool, warns that there is no guarantee it will find all sensitive information. So a small number of trained reviewers will look at records before release, and you should know who they are.

Ask any intermediary these questions before you share anything beyond metadata.

  • Which named people or roles will see records, and are they bound by confidentiality?
  • Where are records stored during preparation, and can they stay in our own storage?
  • Which subcontractors or tools, if any, process the records?
  • How are personal and confidential details removed, and who checks the result?
  • How and when are working copies deleted, and do we get written confirmation?

What a buyer sees before and after signing#

A buyer sees a description first, a sample second and the licensed dataset only after signing. The description covers record types, systems, date range, languages, the fields included and what was excluded. Your company name can often be held back until you agree to disclose it, though a serious buyer will need to know the supplier before it signs.

The sample is the most sensitive moment, because real records go to a party that has not yet committed. Keep it small, prepare it to the same standard as the final dataset, and cover it with evaluation terms that forbid training on it and require deletion if the buyer does not proceed.

After signing, the license defines who at the buyer may access the dataset, the security they must apply, the permitted uses, any ban on redistribution and what happens at the end of the term.

The agreements that control access#

Five agreements typically control who sees your data, and each covers a different relationship. A missing one is a gap in the chain, so check that each exists before the stage it governs.

The right form of each agreement depends on the records, the parties and the laws that may apply, which counsel assesses deal by deal. Ask for the drafts early, because the order in which they are signed matters as much as their content.

The agreements that control access
AgreementBetweenWhat it controls
Intermediary engagement termsYour company and the intermediaryConfidentiality, scope of work, handling of records
Mutual NDAYour company and a prospective buyerUse and disclosure of anything shared before a license
Evaluation or sample termsYour company and the buyerNo training on samples, deletion if the buyer passes
Data processing termsParties handling personal dataInstructions and safeguards where personal data remains
License agreementYour company and the licenseePermitted use, named access, security, redistribution, deletion

Illustrative: a SaaS founder maps who saw what#

Illustrative: a fictional construction project management software company is considering licensing its Intercom conversations and Linear issues. The founder's worry is simple: a competitor or a large customer hearing about the project before any decision is made.

The founder asks for a written access map before starting. At the fit check, only system names, years of history and record families leave the company. Buyers see a description of vertical SaaS support and engineering records, without the company name. One buyer asks for a sample, so the head of support reviews a small de-identified set, the founder approves it, and the buyer signs evaluation terms first.

Once the license is signed, the dataset goes from the company's own storage to the licensee's named team. At every step the founder can point to who saw what and which agreement applied, and no customer or competitor learns of the project.

How SourceX controls access#

SourceX shares nothing during the initial assessment; the fit check collects metadata, not files. The supplier signs off on any sample and on the final release, as on every other step of the SourceX five-step transaction (Supply, Rights, Preparation, Approval and Delivery).

Large datasets stay in the seller's own storage or ship on encrypted drives, and SourceX never hosts multi-TB datasets. The release authorization in the SourceX Evidence Packet gives a written record of who approved each release, and SourceX's own rights in a deidentified dataset are set out in the signed supplier agreement.

Frequently asked questions

Will buyers know my company's name?

Not at first if you prefer. A dataset can be described without naming the supplier during early buyer interest. Before signing a license, a buyer will usually need to know the supplier to complete its own diligence, so agree in advance when and to whom the name is disclosed.

Can a buyer train a model on our sample?

It should not be allowed to. Evaluation terms should limit the sample to assessing the dataset, forbid training on it and require deletion if the buyer does not proceed. Ask for those terms in writing before any sample leaves your company.

Can we refuse specific buyers?

Yes. You can exclude named companies, such as competitors or customers, or whole categories of buyer. Write the exclusion list down at the start so the intermediary never shares even a dataset description with a party you have ruled out.

Do our employees need to know about the licensing process?

Only those who handle exports, review samples or approve the license need to know at the start. A wider internal announcement can wait until a decision is made, and it should explain that records are licensed with personal details removed, not sold.

What proof do we get that copies were deleted?

Ask for written deletion confirmation from the intermediary for working copies after delivery, and from any buyer that evaluated a sample but did not proceed. At the end of a license term, the license itself should require the licensee to delete and certify.

Does the intermediary keep a copy after delivery?

It should not need to. Ask how long working copies are kept, whether any copy is retained for support or dispute purposes, how such a copy is secured and when it is deleted. Get the answer in the engagement terms rather than in an email.

Sources

  • Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify