Who owns your agency’s data? A plain guide to data ownership in agency software
On paper, your agency almost always owns its data. In practice, what matters is control: where it lives, who can read it, who holds the keys and how easily you can take it with you.
On this page
The short answer: in most agency software contracts, your agency keeps ownership of the content you put in, and the vendor receives a licence to store and process it so the service works. That is the paper position. The practical position is different, because ownership you can’t exercise is not worth much. Control comes down to five things: where the data lives, who can read it, who holds the keys to your backups, how easily you can get everything out, and what happens when you leave.
This guide walks through each of those in plain words, so you can judge any tool you use today, including ours.
Ownership versus control: the gap that matters#
Most terms of service contain a sentence along the lines of “you retain all rights to your content”. That is a good start, and it is normal. What the same terms then grant the vendor is where the detail lives.
What contracts usually say
Read the definitions section first. Look for how the contract separates your content (tasks, messages, files, client records) from things the vendor calls usage data, service data or aggregated data. The first is normally yours. The second is often claimed by the vendor, and the wording decides whether it includes anything that could identify you or your clients.
Then look for three clauses: what the vendor may use your content for (running the service only, or also improving products, training models or marketing), who else processes it (usually a list of sub-processors), and what happens to it after cancellation (a deletion period, or silence).
Where control actually comes from
Control is practical, not legal. You have it when you can answer yes to questions like these: can I download everything myself, today, without asking? Are my files in an account I own? Could I restore last week’s data without the vendor’s help? If the vendor disappeared tomorrow, what would I still have?
TipAsk “what would we still have if this tool vanished overnight?” for every tool you pay for. The answers are usually more useful than the terms of service.
The five layers of your agency’s data#
“Our data” is too broad to reason about. Split it into five layers and each one gets easier to judge.
| Layer | What is in it | The question to ask | A good answer |
|---|---|---|---|
| Workspace records | Tasks, messages, client records, invoices, timesheets | Is our data kept apart from other customers, and can we export all of it? | A separate database per customer, and a full self-serve export |
| Files | Videos, designs, documents, voice notes, contracts | Where do files physically live, and in whose account? | In storage the agency owns and pays for |
| Backups | Nightly copies of the workspace | Who holds the key that opens them, and do we get a copy? | Encrypted, a copy with you, and ideally a key only you hold |
| Client-facing identity | Portal, emails, links your clients see | Whose brand do clients see, and does the vendor ever contact them? | Your logo, colours and domain; the vendor never contacts your clients |
| Money and keys | Payment accounts, AI keys, integrations | Does client money or your AI usage run through the vendor? | Clients pay into your own account; AI runs on your own key |
Most tools are strong on one or two layers and quiet on the rest. That is fine as long as you know which is which.
Your clients’ data is not only yours#
A lot of what sits in agency software is personal data about other people: your clients’ staff, their customers, leads from their campaigns, people who appear in footage. Under privacy laws such as the EU and UK GDPR, the client is usually the controller of that data and your agency is usually a processor acting on its instructions. Every tool you put that data into then becomes part of the chain, often called a sub-processor.
That has two consequences. First, your clients may reasonably ask where their data goes and who can see it, and “it’s in a few apps” is not an answer that survives a security questionnaire. Second, your ability to export and delete data on request is not a nice-to-have: clients may need it to answer their own customers. Our GDPR checklist for agencies goes into the roles and contracts in more detail.
Lock-in: how to spot it before you sign#
Lock-in rarely looks like a locked door. It looks like friction that only shows up on the way out. The common signs:
- Export on request. If you have to email support for an export, it will be slow at exactly the moment you need it fast.
- Partial exports. Tasks export, but comments, attachments or history don’t. Check what is actually in the file.
- Files in the vendor’s storage. Leaving means downloading every file one project at a time, and re-linking them somewhere else.
- Proprietary formats. Data you can download but not open anywhere else is only half yours.
- Silence on deletion. If the terms don’t say when your data is deleted after you cancel, assume it isn’t on any schedule.
- Client-facing branding you don’t control. If your clients know the tool by its name, not yours, moving them is harder.
None of these is a reason to avoid a tool on its own. Together, they decide how expensive it is to change your mind.
How Crewqo approaches ownership#
We built Crewqo around the five layers above, so here is how each one works, in the same plain terms.
- Workspace records. Every agency gets a database of its own, not rows in a shared one. See separate databases on our security page.
- Files. Files go straight into storage you connect: Google Drive, OneDrive or SharePoint, Dropbox, any S3-compatible bucket, or your own server over WebDAV. No permanent copy is kept on our servers. More on your own storage.
- Backups. Nightly backups are encrypted and kept for 30 days, and a copy goes to your storage. Turn on your own backup key and we can’t open them. See encrypted backups.
- Client-facing identity. Your logo, colours and web address on the client portal. We never contact your clients.
- Money and keys. Invoices carry your own Stripe or PayPal link, and AI runs on your own OpenAI, Gemini or OpenRouter key.
To be clear about the limits: your live workspace runs on Crewqo’s servers, so the app can read it in order to show it to you, like any web app. You can export everything at any time, and if you cancel, we delete your workspace and the backups we hold within 30 days. The Why Crewqo page sets out the full list of promises.
A data ownership checklist for your current tools#
Take your three most important tools and run each through this list. It takes about twenty minutes per tool.
Data ownership check, per tool
What to do this month#
- Do one real export. Pick your project tool and export everything. Open the files. Note what is missing.
- Move files out of personal accounts. Anything living in a founder’s or freelancer’s personal drive should move to an agency-owned account. Our guide to choosing storage for agency files helps you pick where.
- Ask your vendors three questions. Where are our files? Who holds the backup key? What happens to our data when we cancel? The vendor question template has the full set.
None of this needs a lawyer or a new tool. It needs an afternoon and the willingness to look.
Frequently asked questions
Does my agency own the data it puts into SaaS tools?
Usually yes: most terms say you keep ownership of your content and give the vendor a licence to host and process it. Check how the terms define usage or aggregated data, which vendors often keep, and what the vendor may use your content for.
Who owns data about my clients’ customers?
In privacy terms, your client is usually the controller of that data and your agency processes it on their behalf. You don’t own it in any practical sense: you look after it, use it only as instructed and must be able to return or delete it.
What is the quickest way to test for vendor lock-in?
Do a full export today and try to open it elsewhere. Then check where your files physically live and whether the terms state a deletion period after cancellation. Those three checks catch most lock-in.
Can Crewqo see my data?
Your live workspace runs on Crewqo’s servers, so the app can read it to show it to you, like any web app. We don’t look at workspace contents unless you ask for help or the law requires it. Files go to your own storage, and with your own backup key turned on we can’t open your backups. See Security & data.
Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.