Skip to content

Getting started

Your software vendor wants to use your data for its AI: should it pay you?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A software vendor that wants to use your data to train its AI should give you something in return when the use goes beyond running your own account. Separate AI features you benefit from directly from training on models sold to all customers, then ask for an opt-out, firm limits, pricing credits or a fee for the broader rights.

Key takeaways

  • Processing your data to deliver AI features to your account is part of the service; training vendor-wide models is closer to a data license.
  • Vendor AI rights usually arrive through updated terms, addenda, admin toggles or click-throughs rather than a negotiation.
  • Your customer contracts and privacy notices may limit what you can let a vendor do with records you hold.
  • Broad, perpetual vendor rights can reduce what the same records are worth to another buyer later.
  • Record each vendor decision and who approved it, because acquirers and auditors will ask.

What is your vendor actually asking for?#

A software vendor asking to use your data for its AI is usually asking for one of three rights: to process your data with AI models to deliver features to your account, to use your data to improve models that serve all its customers, or to use aggregated or de-identified versions of your data in its own products. The first is a service; the second and third are closer to a data license.

These requests rarely arrive as a negotiation. They appear in updated terms of service, an AI addendum, a new admin toggle or a click-through when someone enables a feature. The person who clicks is often an administrator, not the owner or counsel, and the change may apply to years of records already in the system.

What recent vendor terms and disputes show#

Recent vendor terms and disputes show that AI training rights are often set by a default, a toggle or a terms update, and that public pushback has led several vendors to narrow them. The examples below are drawn from vendors' own documents and dated press reports; terms change, so read the current version for any system you use.

The pattern for an owner is simple: find the setting, find the clause, and record what you decided. Enterprise agreements can differ from the self-serve terms, as GitHub's exclusion of its Customer Agreement customers shows.

  • HubSpot: its knowledge base describes an AI model training switch that controls whether HubSpot uses an account's customer data to train its AI models.
  • GitHub: its Terms of Service (Section J) grant a license to use AI-feature inputs and outputs to train models, with an opt-out in account settings; customers under a GitHub Customer Agreement or volume licensing agreement are excluded from that training license.
  • Zoom: in August 2023, after backlash over earlier changes, Zoom added a sentence to its terms saying it will not use audio, video or chat customer content to train its AI models without consent.
  • Slack: in May 2024 TechCrunch reported backlash over privacy principles that let customer data train Slack's machine-learning models unless an organization emailed to opt out; Slack said it does not use customer data to train its generative AI large language models.
  • FTC staff: in February 2024 they warned that quietly adopting more permissive data practices, such as AI training, through retroactive terms changes may be unfair or deceptive.

Decision table: what you give up and what to ask for#

The decision table sorts common vendor requests by what you give up and what is reasonable to ask in return. The right answer depends on how sensitive the records are and how much the vendor's wider product benefits from them.

Decision table: what you give up and what to ask for
What the vendor asks forWhat you give upWhat to ask in return
AI features for your account, no trainingLittle beyond normal processingWritten confirmation that no training occurs and a list of model providers
Training models that serve all customersYour records shape a product your competitors may useAn opt-out, or a fee or credits if you opt in
Aggregated or de-identified data usePatterns of your business, even without namesA defined de-identification standard and a ban on re-identification
Human review of your data by vendor staffConfidential records seen by people outside the companyLimits on who reviews, for what purpose and under what confidentiality
Rights that survive terminationControl after you leave the vendorDeletion of data and derived data on exit, with a certificate
Exclusive or first-look rights to your dataFreedom to license elsewhereDecline, or price it as exclusivity

When should the vendor pay you?#

A vendor should pay, in fees, credits or other concessions, when your records improve a product it sells to others and the rights it wants are broad, long-lived or cover human-generated records that reflect your expertise. Using your data only to serve your own account is part of the service you already pay for.

The SourceX Enterprise Data Value Framework names the traits that make records valuable: uniqueness, domain expertise, human-generated signal, scale, recency, data cleanliness, rights and AI utility. A field service company's diagnosis notes or a software firm's escalation threads score well on several of those, and a vendor that trains on them is taking something with value.

Broad rights granted to a vendor can also reduce what the same records are worth to another buyer, who may care whether they already sit inside a competing product. That cost is invisible on the day the terms change, which is why it belongs in the decision.

Can you grant those rights at all?#

Whether you can grant those rights depends on your own contracts and notices, not only on the vendor's terms. Records in your help desk or CRM often contain your customers' confidential information, and customer agreements may limit how it is used or shared.

Check customer contracts for confidentiality and data-use clauses, your privacy notices for what you told individuals, and employee notices for internal chat and email. If those limit reuse, agreeing to vendor training could put you in breach even though the vendor's terms allow it.

Internal chat and email are a common blind spot. Slack channels and shared inboxes hold employee personal details, customer names and pricing discussions in free text, which is hard to de-identify after the fact and easy to hand over through a single workspace setting.

How to negotiate vendor AI data use#

Negotiating vendor AI data use starts with knowing which vendors hold your most valuable records and what each has asked for. A short, repeatable process keeps the decisions consistent across systems.

Smaller customers often assume they have no leverage, but opt-outs and written confirmations are frequently available on request even when pricing is fixed. Renewal is the natural moment to ask for more, such as a de-identification standard or deletion terms.

  • List the vendors that hold operating records: help desk, CRM, field service, ERP, project management and chat.
  • Read each vendor's current AI terms, addenda and admin settings, and note the date you reviewed them.
  • Turn off training settings you have not decided to allow, and confirm the change in writing where the vendor offers that.
  • Send your questions: what data is used, for which models, who else receives it and what happens on exit.
  • Decide vendor by vendor whether to opt out, accept with limits or opt in for compensation.
  • Record each decision with the person who approved it, so a future acquirer or auditor can see it.

Illustrative: a plumbing company answers its platform's AI update#

Illustrative: a fictional plumbing and HVAC company runs dispatch, estimates and invoices on a field service management platform. The platform's updated terms add a right to train AI models on customer job data to improve features for all users, with the opt-out placed in admin settings.

The owner wants the platform's new AI scheduling assistant but not a general training right over years of technician diagnosis notes. The company opts out of training, confirms in writing that the scheduling feature still works for its own account, and asks for a de-identification standard covering any aggregated use. The platform agrees to the opt-out and the standard, and the company keeps the option to license its job histories through a separate, documented deal.

How SourceX looks at vendor AI requests#

SourceX treats a vendor's request to train on customer records as a data transaction like any other: it involves rights, preparation, approval and delivery, even when the delivery happens through an integration. Data should be licensed on agreed terms rather than given away by default, and the company keeps ownership.

When a company wants to license records on its own terms, the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery gives it a documented path, and a SourceX Evidence Packet records what was licensed and for what use. Keeping vendor training rights narrow preserves that option.

Frequently asked questions

Can a vendor already be training on our data without asking?

Possibly, if the terms you accepted allow use of customer data to improve services and the vendor reads that to include AI training. The only way to know is to read the current terms, check admin settings and ask the vendor in writing. Terms change, so record when you last checked.

Will opting out of training break the vendor's AI features?

Usually not. Many vendors separate account-level AI features from training on customer data, so features can keep working after an opt-out. Ask the vendor to confirm which features depend on training rights before you decide, and get the answer in writing.

Is de-identified or aggregated use harmless?

Lower risk, but not harmless. Aggregated data can still reveal how your business prices, schedules or resolves problems, and weak de-identification can sometimes be reversed. Ask for a written standard, a ban on re-identification and a limit on combining your data with other sources.

Who inside the company should own these decisions?

The CEO or owner should decide on training rights, because they affect company value and future licensing. The COO or IT lead knows which systems hold what, and counsel reviews customer contracts and notices. Many companies give one person the job of tracking vendor AI terms across systems.

What if we are leaving the vendor anyway?

Check what the terms say about your data after termination before you leave. Export what you need, request deletion of your data and any derived data, and ask for written confirmation. If the vendor holds training rights that survive termination, that is the clause to negotiate, ideally before the renewal or exit notice goes out.

Sources

  • HubSpot's knowledge base says customers can use an AI model training switch to control whether HubSpot uses their account's customer data to train its AI models. Source
  • GitHub's Terms of Service (Section J) grant GitHub a license to use AI-feature inputs and outputs to train AI models, which users can opt out of in account settings, and customers under a GitHub Customer Agreement or volume licensing agreement are excluded. Source
  • On August 7, 2023, Zoom added to its Terms of Service: "Zoom will not use audio, video or chat Customer Content to train our artificial intelligence models without your consent." Source
  • TechCrunch reported on May 17, 2024 that Slack drew backlash after its privacy principles allowed customer data to train its machine-learning models unless an organization emailed to opt out, and Slack said it does not use customer data to train its generative AI large language models. Source
  • On February 13, 2024, FTC staff warned that adopting more permissive data practices such as AI training through a surreptitious, retroactive change to terms of service may be unfair or deceptive. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify