Docs/Legal

Data you hold for customers

When the data in your systems belongs to your customers, what permission you need, and what we leave out.

Many companies hold data on behalf of their customers. An accounting practice holds its clients' ledgers. A software company holds records its customers entered. The question is whether you are the controller of that data or a processor acting on your customers' instructions.

If you are a processor

When you process data on a customer's behalf, your contract with them usually limits what you can do with it, often to providing the service. In that case you need the customer's written permission to license their data, even after scrubbing.

If you are the controller

When the data is yours, such as your own sales pipeline or your own support tickets, the usual rights review applies. See Rights review.

Mixed systems

One system often holds both. Your CRM may hold your own deals alongside notes about your customers' employees. We help you work out which data falls on which side and leave out anything you do not have permission to license.

How we handle it

  • We read your customer agreements and data processing agreements during the rights review.
  • Where permission is needed, we tell you which customers it covers. You decide whether to ask them.
  • Data you do not have permission for stays out of the dataset. The SDK only pulls the sources and fields you configure.

People in your records who are not your customers

A CRM can hold details of another company's employees. Scrubbing replaces their names, emails and phone numbers with tokens, but the legal question of who gives consent for them is part of the rights review, and we may ask your counsel to sign off.