'We'd never let our customers' data be used': how partners should answer

Agree with the instinct, then correct the assumption: a data license usually covers the company's own operational records, not its customers' personal data. Customer personal information and client-owned material are excluded or de-identified under rules agreed before any work starts, customer contracts and privacy promises are checked first, and nothing is shared without a signed agreement.

The honest short answer

The owner is right to protect customers, and most of what AI buyers want does not depend on customer personal data at all. What AI labs and data buyers pay for is the record of how the company works: how a ticket was diagnosed and closed, how a quote became an order, how an exception was escalated and settled. A support ticket keeps its value when the customer's name, email and account number are stripped out, because the troubleshooting steps and the outcome are the useful part.

So the right response is agreement first, correction second. You are not asking the owner to hand over customer information. You are suggesting that a qualified team check whether the company's own operational records can be licensed with customer details excluded or de-identified, under rules the company sets before anything moves.

What a license usually covers, and what stays out

Most qualifying material is internal: staff-to-staff email and chat, CRM pipeline history, support workflows, SOPs, finance and engineering records. Material that belongs to customers, or that is mainly about identifiable people, is excluded or transformed.

Record typeUsually in scope?How customer information is handled
Internal email, Slack or Teams threads between staffOftenCustomer names, contacts and account details are redacted under agreed rules
Support and service ticketsOftenIdentifiers are removed; the problem, the steps taken and the resolution remain
CRM opportunity historyOftenContact fields are stripped; stages, notes and win or loss outcomes remain
SOPs, playbooks, policies and training materialUsuallyLittle or no customer information to begin with
Code, pull requests and issue trackersOftenCustomer configurations, credentials and customer-specific code are left out
Deliverables a customer owns under contractNo, unless the customer agreesKept out of the inventory
Records the company stores or processes on its customers' behalfNoKept out; the customer controls them
Consumer personal data or patient recordsRarelyExcluded unless there is a licensing basis, such as HIPAA de-identification or authorization

The exact redaction and de-identification requirements are agreed with the company before any preparation begins, and nothing is delivered without an executed agreement and the company's authorization. If the owner's real worry is the export step itself, the guide on whether exporting CRM data is safe answers it in an implementation consultant's terms, and what happens after the data is delivered covers the obligations that continue once records change hands.

Which customer documents to check first

Three sets of documents decide what is possible. Read them in this order before anyone commits to a scope.

  1. Customer contracts. Master services agreements, data processing addenda and statements of work often hold confidentiality, data-use and ownership clauses. A clause that gives the customer ownership of deliverables, or bans secondary use of its information, takes that material off the table. The walkthrough of customer contract data use restrictions covers the clauses counsel usually reads.
  2. What the company has promised. Privacy policies, terms of service, security pages and sales decks all count. FTC staff have stated that promises not to use customer data for undisclosed purposes, such as training or updating AI models, are enforceable wherever they appear, including privacy policies, terms of service and promotional materials (FTC Office of Technology, January 2024).
  3. Sector rules. Health information is the clearest case. Under HHS guidance, health information de-identified by either the Safe Harbor method or Expert Determination is no longer protected health information under the HIPAA Privacy Rule (HHS de-identification guidance). Anything short of that needs a separate legal basis or stays out.

Whether customer consent is needed in a particular case is a question for the company's counsel; the page on whether customer consent is needed to license data sets out how that analysis usually runs. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

How to respond in the moment

Keep it short, agree with the principle, and move the conversation from 'our customers' to 'our own records'.

Then match the reply to what the owner is actually worried about.

What the owner saysWhat usually sits behind itA useful reply
Our customers would leave if they found outReputation and trustCustomer personal data is excluded or de-identified, and the company sets the scope and can walk away at any point before signing
Our contracts forbid itA specific clause they rememberThen that material stays out; counsel reads the contracts before any scope is set
We promised never to sell dataA privacy policy or sales commitmentThe promise is checked first and it binds; nothing gets licensed in a way that breaks it
We don't even know what's in thereFear of the unknownA data inventory lists systems and years of history before a single record is shared

What a partner must not do: never offer to look at, export or summarize records to prove the point, never tell the owner their contracts are fine, and never promise which material will be excluded. Those decisions belong to the company and its counsel, working with SourceX.

When the objection is a genuine red flag

Sometimes the owner is describing the business accurately, and the right move is to stop. Treat the objection as a no when:

  • The company's main records are its customers' records, as at many outsourcers, agencies, payroll processors and hosted platforms, and those customers have not agreed.
  • The records are mainly consumer personal data with no licensing basis.
  • The records are mainly patient records or claims, with no HIPAA authorization or de-identification route.
  • Customer contracts broadly prohibit secondary use, and renegotiating them is unrealistic.
  • The company has publicly promised never to use customer data for AI training and is not prepared to honor that by leaving it out.

A no on customer data is not always a no on the company. Internal records that never involved customers, such as month-end close workflows, procurement approvals, internal IT tickets and engineering history, can sometimes stand on their own. If they cannot, park the company and say so plainly; a sponsor's view of reputational risk in portfolio data licensing explains why a clean source matters more than one more deal.

Next step

Settle the customer-data question before the first call with SourceX, not after it. If the company's valuable records are its own, the owner can run the preliminary company fit checker, which needs no contact details, or apply directly at sourcex.si/apply. To receive credit for the introduction, register as a partner first.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a company license support tickets that mention customers by name?

Often, yes, once identifiers are removed. The value of a ticket lies in the problem description, the troubleshooting steps and the resolution, which survive redaction. Tickets that contain regulated information, customer-owned files or details a contract treats as confidential are usually excluded. The company agrees the redaction rules before preparation starts and approves the final scope before anything is delivered.

Does a referral partner need to review customer contracts before making the introduction?

No. Partners make the introduction and share basic fit information, such as headcount, years of operation and the systems the company uses. Reading customer contracts, privacy policies and data processing terms is work for the company and its counsel during qualification. A partner who asks to see contracts or records is stepping outside the role and creating a confidentiality risk for the client.

Is removing names enough to make customer records safe to license?

Not always. Names are the obvious identifiers, but account numbers, email signatures, addresses, free-text notes and unusual combinations of details can still point to a person or a business. That is why de-identification requirements are agreed in writing with the company before work begins, and why some record types are excluded entirely rather than redacted. Health information has its own specific de-identification standard.

What if a customer later asks whether its data was licensed?

The company should be able to answer from its own files: which systems were in scope, what was excluded and which redaction rules applied. Keeping the scope document with the signed agreement makes the answer quick and accurate. If customer information was excluded, the company can say so plainly; if anything customer-related was included in any form, counsel should shape the reply.

Does a business with only B2B customers face the same issue as a consumer business?

Usually less, but not none. B2B records mostly describe business dealings rather than private individuals, yet they still contain contact names and email addresses, and B2B contracts often carry strict confidentiality and data-use terms. Consumer businesses face the added problem that much of their data is personal information, which is a red flag for licensing when there is no lawful basis to use it.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment