Every piece of software you buy is a decision about where your company’s data lives. That sounds dramatic. It is not. When you sign up for a scheduling tool, a CRM, or an AI assistant, you hand a working copy of your customer information to a company you met three weeks ago through a demo and a free trial.
Most small businesses sign these agreements the same way: click accept, enter a card, move on. We understand why. The tool solves a real problem today. But a short conversation before you sign can save a very long one later. One note before we go further: this article is general information, not legal advice. Contract language has real legal consequences, and an attorney should review any agreement covering your customer data before you sign it.
Where Your Data Actually Goes
When you buy software, your data almost never sits in one tidy place. The vendor stores it. The company hosting the vendor’s servers stores it. Their backup provider holds copies. Their support ticket system holds whatever your team pastes into a support request. Their contract developers may touch the database during a maintenance window.
Those other companies have a name in contract language: subprocessors. A subprocessor is a company your vendor hires to help deliver the service to you, and your data goes wherever they go. This is not sinister. It is how modern software gets built, and no vendor of any size builds everything themselves. But it means the security question is never only about the vendor whose logo is on the invoice. In its business guidance on hiring service providers, the Federal Trade Commission advises companies to ask contractors detailed questions before awarding work, including how they will secure the company’s data, who will have access to it, and how they train their employees.
The Seven Questions Worth Asking Every Vendor
You do not need a legal department to ask good questions. You need a short list you use every time, so you compare vendors on the same terms instead of on whoever gave the better demo. Here is ours.
- What data do you collect from us? Not just what we type in. What else gets captured: attachments, email content, call recordings, device details, usage logs. A vendor who has never considered the question has never considered your data.
- Where is it stored? Which country, which cloud provider, and whether backups live somewhere else. If they cannot tell you, they may not know, and that is worth knowing.
- Who at your company can see it? Can support staff read customer content, is that access logged, and can an engineer chasing a bug open our records. There is usually a legitimate answer. You want it stated in writing.
- Do you use subprocessors, and can we see the list? Serious vendors publish this and update it when it changes. Ask whether you get notified before a new one is added.
- What happens to our data when we terminate? How long is it kept, in what form, and does deletion reach the backups. Immediate deletion and a ninety day grace period are both defensible. Silence is not.
- How and how fast do you notify us of a breach? You want a commitment to tell you, a rough timeframe, and a named contact. If the answer is a status page update, you will find out when your customers do.
- Can we export everything in a format we can use? A spreadsheet of contact names is not an export when the value sits in the attachments and the history. Test the export during your trial, not during your exit.
Why the Answers Belong in Writing
A sales representative on a call is trying to close a deal. They are not lying to you, usually. They are answering from memory, about a product built by a team they do not sit with, under terms written by lawyers they have never met. Six months later nobody remembers what was said on a Tuesday afternoon video call.
The Federal Trade Commission puts this bluntly in its guidance for businesses, writing that data security is too important to relegate to a vague “let’s just shake on it” deal and advising companies to insist that appropriate security standards are part of their contracts. The same guidance notes that security cannot be a “take our word for it” arrangement. The National Institute of Standards and Technology gives similar advice to organizations adopting AI tools, recommending well defined contracts and service level agreements that spell out content ownership, usage rights, quality standards, and security requirements.
In practice, “in writing” does not require a custom contract. Send a short email after the call summarizing what you were told and ask the rep to confirm it. Save the vendor’s security page, subprocessor list, and data terms as PDFs with the date you downloaded them. Read the sections covering data use, retention, and termination. Vendor terms change, so recheck them at renewal instead of assuming last year’s answers still hold.
You Have Less Leverage Than a Big Company. Ask Anyway.
Here is the honest part. You are not going to negotiate custom contract language out of a vendor charging thirty dollars per user per month. Their terms are the same for everyone, and the sales rep genuinely cannot change them. Anyone who tells a fifteen person company otherwise is selling something. That does not make the questions pointless. It changes what they are for.
- A vague answer is still an answer. A vendor who replies in two business days with links to published documentation is a different kind of company than one who goes quiet. You learn something either way.
- Published terms are your leverage. You cannot negotiate the contract, but you can read it and pick the vendor whose standard terms are already reasonable. Comparison is the leverage a small company actually has.
- Shrink the data instead of the contract. If the terms are mediocre but the tool is great, limit what goes into it. Not every system needs full customer records.
- You can still walk. The underrated option. There is almost always a second vendor, and walking away over bad data terms gets easier the earlier you do it.
A Process That Fits a Small Team
None of this works if it takes an afternoon per purchase. Keep it to twenty minutes. Send the seven questions by email before you buy, save whatever comes back in one shared folder, and add the tool to a running list of every system holding company data.
That last list matters more than people expect, because the software nobody reviewed is usually the software nobody knows about. We covered that in our piece on shadow IT and the risks hiding inside your own organization. If you are weighing whether this care is worth it at your size, our take on why cybersecurity is no longer optional for mid-sized businesses covers the reasoning.
The Bottom Line
Your customers gave you their information. They did not give it to your scheduling app, your CRM, or the AI tool somebody started using last month. You are the one they will call when something goes wrong, which makes the questions yours to ask.
Ask the seven questions. Get the answers in writing. Accept that you will not change the contract, and use what you learn to choose better, scope smaller, or walk away. And to say it once more, because it matters: this is general information, not legal advice. Have an attorney review the actual contract terms before you commit your customer data to any vendor.
If you are evaluating a new system and want a second set of eyes on where your data would end up, that is the kind of work we do for businesses across Denton County. We will help you ask the right questions, read what comes back, and decide whether the tool is worth the exposure. Contact us today.
Sources:
- Federal Trade Commission, Stick with Security: Make sure your service providers implement reasonable security measures
- Federal Trade Commission, Start with Security: A Guide for Business
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
Comments are closed