refactorPARTNERS
All Insights

Security & Compliance

Who Actually Owns Your Client Data?

Refactor Partners||
4 min read

The question every managing partner should be able to answer

If you terminated your AI vendor tomorrow, what would you be left with?

Most firms have never asked. They signed up for a platform, connected it to their practice management system or CRM, fed it months of client history, and moved on. The tool works, so nobody has stopped to check what happens if it stops working, gets acquired, or triples its price at renewal.

We ask this question during every Deep Scan, and the answer is almost always uncomfortable. The workflows live inside the vendor's platform, not the firm's infrastructure. The data that trained the vendor's models, screened the vendor's leads, or scored the vendor's cases sits in a database the firm has read access to, not ownership of. The institutional knowledge your team built over eighteen months of usage is, functionally, a rental.

The contract clause nobody reads

Data ownership language in AI vendor contracts is usually buried past the pricing page, and it is rarely written in the client's favor. Three clauses matter more than any feature comparison:

Data portability. Can you export your full history — not a CSV summary, but the actual records, interaction logs, and derived insights — in a usable format, at any time, without a support ticket?

Model training rights. Does the vendor use your client data, even anonymized, to improve a product they sell to your competitors? Many standard SaaS agreements grant broad rights here by default.

Deletion guarantees. When you terminate, does the vendor actually delete your data from their systems and backups, or does it persist indefinitely under a vague retention policy?

Firms rarely negotiate these terms because they are evaluating AI tools the way they evaluate software: on features and price. That is the wrong lens. You are handing over the operational record of your practice. That decision deserves the same scrutiny as a partnership agreement.

What "no vendor lock-in" actually means

We built our own delivery model around this problem, so we will say it plainly: the Digital Associates we build run inside your existing infrastructure, not inside a proprietary platform you rent from us. Your data stays in your systems. Your workflows are documented and transferable. If you ended the engagement tomorrow, you would keep everything we built.

That is not generosity. It is the only structure that makes sense once you understand what is actually at stake. An automation vendor that locks your data inside their platform is not selling you efficiency. They are selling you a dependency, and dependencies get monetized eventually, usually at the moment you have the least leverage to push back.

The real cost of not owning your stack

The cost of vendor lock-in rarely shows up in year one. It shows up at renewal, when the price doubles and switching means rebuilding eighteen months of workflow logic from scratch. It shows up during due diligence, when an acquirer asks for your operational data and you discover half of it lives in a third-party system you do not control. It shows up during an incident, when you need to know exactly what data a vendor holds on your clients and you realize you never asked.

None of this requires a breach to become a problem. Ordinary business events — a vendor pivot, a price increase, an acquisition, a due diligence request — are enough to expose how little control a firm actually has over its own operational data.

Ask before you sign, not after

Before adopting any AI tool that touches client data, ask three questions: Where does this data physically live? What happens to it if we leave? What rights does the vendor retain over it after we stop paying?

If a vendor cannot answer clearly, that is the answer. The firms that will be running the most resilient operations five years from now are the ones treating data ownership as a design requirement today, not a contract dispute tomorrow.

data ownershipvendor lock-insecurityAI infrastructureprofessional services