Customer contract data use restrictions to check before licensing company records

Customer contract data use restrictions usually decide what a company can license. Before licensing records for AI training, counsel should read each customer agreement's definitions, confidentiality, data use, aggregated-data, ownership and return-or-destroy clauses, keep customer-owned information out of scope, and check privacy promises. The contract text controls, and this is general information, not legal advice.

The short answer

Customer contract data use restrictions usually decide what a company can license. Many B2B agreements limit a provider's use of customer information to performing the services, so anything that counts as the customer's data or confidential information is generally out of scope for an AI-training license unless the customer agrees. What remains, the company's own records of how it does its work, is often licensable after redaction. The controlling text is each contract, so the answer turns on the definitions and use clauses in the agreements the company actually signed.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

What the law adds on top of the contract

The contract is the starting point, but several public rules affect how it is read and what else counsel must check.

  • Privacy promises are enforceable. FTC staff wrote in January 2024 that a company's promises not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether made in a privacy policy, terms of service, promotional materials or a marketplace listing.
  • Quiet changes can be a problem. A February 2024 FTC staff post warned that adopting more permissive data practices, including AI training, and telling consumers only through a surreptitious, retroactive change to terms or a privacy policy may be unfair or deceptive. Both posts are staff guidance, not rules.
  • Service provider contracts limit purpose. Under California's CCPA, Civil Code section 1798.100, a business that discloses personal information to a service provider or contractor must have a written agreement limiting its use to specified purposes. A company acting as a service provider should assume licensing is not one of those purposes unless the agreement clearly says otherwise.
  • Ownership follows authorship and contract. Under 17 U.S.C. 201, copyright vests in the author, the employer owns works made for hire, and rights can be transferred in whole or in part. A company can license specific rights in material it owns while keeping others, but material its customers created remains theirs.

The clauses counsel reads, one by one

ClauseLanguage to look forWhat it can restrictWhat to confirm
Definitions'Customer Data', 'Confidential Information', 'derived from'Can sweep in notes, tickets and outputs about the customerWhether internal work records about the customer fall inside
Use restriction'solely to perform the Services'Any use beyond delivering the servicesWhether an exception covers analytics, improvement or other purposes
Aggregated or de-identified data'to improve the Services' versus 'for any lawful purpose'Ranges from internal improvement only to broad reusePurpose limits, the de-identification standard and any right to disclose to third parties
AI and machine learning'shall not use Customer Data to train'Training use by the provider or anyone it shares withWhether it reaches licensing to third parties
Ownership and work product'all Deliverables are the property of Customer'Deliverables and sometimes working draftsWhich files are deliverables and which are internal working records
Return or destroy'upon termination, return or destroy'Copies kept after the relationship endsWhether data was destroyed and certified, and what archives remain
Survival'shall survive termination'Old contracts that still bindSurvival periods for confidentiality in expired agreements
Data processing addendumProcessor or service provider termsPersonal information about the customer's peoplePurpose limits and sub-processor rules
Publicity and names'shall not use Customer's name'Customer identities in a datasetWhether redaction removes names and identifying details

How it plays out in common situations

SituationWhat to checkTypical outcome to confirm with counsel
SaaS company with an aggregated-data clauseThe purpose words and any third-party disclosure rightA clause limited to improving the service rarely covers licensing to others
MSP or IT services firm with years of ticketsWhether tickets are the customer's confidential informationTickets describing customer environments may be out; internal runbooks may be in
Agency or consultancyWork product and IP assignmentClient deliverables out; internal methods and templates may be in
Contact center or BPOWho owns recordings and transcripts under each client contractOften client-owned, so out without client consent
The company as its vendors' customerVendors' confidentiality termsIts own records stay its own; vendors' price files and confidential materials come out
Expired agreementsSurvival and return-or-destroy clausesConfidentiality may still apply years later
Consumer-facing terms and privacy policyWhat users were told about data useA promise not to use data for AI training holds

For contact centers, see who owns call recordings at a contact center or BPO. For a closer reading of confidentiality wording, the guide to confidentiality clause use restrictions goes clause by clause.

The three-bucket sort

Once the clauses are read, sort the company's records into three buckets before anything is priced.

  1. Company-owned: internal SOPs, internal email and chat about how work is done, project plans, code the company owns and finance records of its own operations. Usually in scope, subject to redaction.
  2. Customer-owned: customer data, customer confidential information, deliverables assigned to customers and recordings that belong to clients. Out of scope unless the customer consents in writing.
  3. Mixed or derived: tickets that describe customer systems, CRM notes about customers and aggregated metrics. These need clause-by-clause review and are often included only after customer identities and confidential details are removed.

SourceX agrees de-identification and redaction requirements with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization. The page on how company data is anonymized before AI licensing explains that step. Data that belongs to someone else, used without that party's consent, is a red flag that stops a deal.

Disclosure and consent good practice

  • Build a contract register by template. Companies often sign a handful of standard forms plus some negotiated paper, so reading the templates first saves time.
  • Where a customer's data would add real value, ask for written consent to a specific, described dataset rather than a general permission.
  • Do not amend customer terms or a privacy policy retroactively to permit AI training without clear notice.
  • Keep a record of what was excluded and why, and reflect exclusions in the data inventory before pricing.
  • Tell the licensee what was excluded so expectations match the delivery.

Questions to ask your counsel

  • Which of our customer templates define customer data broadly enough to cover our internal work records?
  • Does any aggregated-data clause permit disclosure to third parties, and for what purposes?
  • Which expired agreements still carry confidentiality obligations?
  • Do any agreements or data processing addenda make us a service provider or processor for the data in question?
  • What have our privacy policy and marketing materials promised about AI training?
  • Which customers, if any, are worth asking for consent?

The martech audit checklist helps gather the vendor-side contracts, and the guide to vetting whether an AI data licensing offer is legitimate covers what to ask the licensing platform itself.

If you are counsel and want to refer the client

Lawyers who would receive a referral reward for introducing a client should check their own state's professional conduct rules first. The ABA's Model Rules of Professional Conduct include Rule 1.5 on fees, Rule 1.8 on specific conflicts with current clients, Rule 5.4 on professional independence and Rule 7.2 on communications about a lawyer's services. Each state adopts its own version, so the text where you are licensed controls.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. The reward is never deducted from what the company receives.

Next step

Read the three most-used customer templates against the clause table, then sort the records into the three buckets and compare the result with the who qualifies baseline. If the company has enough of its own records to matter, register as a partner to make the introduction, or have the company apply directly at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a company use customer data to train AI or license it for training?

Only if its customer agreements and privacy commitments allow it, which many B2B agreements do not without the customer's consent. Contracts commonly limit use of customer information to performing the services, and FTC staff have said promises not to use data for model training are enforceable. This is general information, not legal advice; counsel should read the actual agreements.

Does an aggregated data clause let a company license to AI developers?

It depends on the words. A clause allowing aggregated or de-identified data to be used to improve the provider's services is narrow and may not reach disclosure to third parties. A clause permitting use for any lawful purpose is broader, but de-identification standards, confidentiality terms and privacy promises still apply. Counsel should read the clause together with the definitions.

Do confidentiality obligations end when a customer contract expires?

Not necessarily. Many agreements say confidentiality survives termination, for a fixed number of years or indefinitely, and return-or-destroy clauses may have required the company to delete customer information when the relationship ended. Retained copies of a former customer's data can be the riskiest records to license, so check survival and return-or-destroy terms before including anything from expired accounts.

Are internal emails about a customer the customer's data?

Sometimes. If the contract defines confidential information or customer data broadly, internal messages that repeat customer details may fall inside it. Messages about the company's own process, staffing or methods usually sit outside. Mixed records are often included only after customer names and confidential details are removed under redaction rules agreed before any work begins.

Does a company need every customer's consent before licensing?

No, not if customer-owned information stays out of scope. A company can license only its own internal records and exclude or redact anything that belongs to customers. Consent becomes necessary when the company wants to include a specific customer's data, and it should then be in writing and tied to a clearly described dataset.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment