What Your Licence Actually Grants (and Takes)
Clicking "I agree" used to mean accepting some sensible usage rules. These days it can mean handing over your data, your content, and your rights in ways that weren't on your radar. Here's what to look for before you sign.
Ash Youssef
· 8 min read
I'm not a lawyer. What follows is not legal advice. But I've read enough end user licence agreements and terms of service recently to know that most business owners haven't, and that is starting to matter a lot more than it used to.
Clicking "I agree" used to feel like a formality. The agreement said, roughly: you can use this software, don't copy it, don't resell it, and don't do anything illegal with it. Reasonable. Easy to ignore.
Those agreements have quietly changed. The things you are agreeing to now are different in kind, not just in length.
Three things that shifted without much fanfare
The big changes cluster around three areas: data ownership, AI training rights, and what happens to your work when you stop paying. Each one is worth looking at separately.
Your data inside the product
When you put your client records, your documents, your notes, or your business processes into a SaaS tool, something subtle happens: that data now lives on someone else's infrastructure, governed by their terms.
Most reputable tools make clear that you own your data. The question is what they can do with it. Terms often grant the vendor a broad licence to use your data to "provide, improve, and develop" the service. That sounds innocuous. In practice it can include using patterns from your usage, your inputs, or your outputs to train internal models, benchmark the product, or build new features.
The key phrase to look for is whether the licence they take is "royalty-free, sublicensable, and worldwide." If it is, they can share it with partners or use it in ways that go beyond running your account.
AI training rights
This is the one that has changed most visibly in the last two years. Tools that touch your content, whether that is a writing assistant, a design platform, a customer support product, or a CRM with AI features, have started including explicit clauses about using your content to train AI models.
Some services default you into this and require you to opt out. Some reserve the right even if you opt out, for "aggregated and anonymised" data. Some enterprise tiers exclude training by default, while the standard plan does not. The pricing page won't tell you this. The terms will.
Adobe faced significant backlash in June 2024 when users noticed updates to its terms and feared the language could permit broad use of their content, including for generative AI training. Adobe denied that it trained its generative AI on customer content and updated the terms to make that explicit, but the episode illustrated how easy it is to miss a material change until the internet notices for you.
OpenAI, Notion, Canva, and most productivity-AI tools have all had similar moments where their terms provoked scrutiny. Each handled it differently. The point is not that these companies are acting in bad faith. It is that the terms reflect genuine business interests that may not align with yours.
What you can access when you stop paying
This one gets less attention but it is potentially the most damaging for small businesses.
With traditional software, you bought a licence. The product lived on your machine. If you stopped paying for upgrades, you kept what you had.
Subscription SaaS works differently. When you cancel, your access typically stops immediately or at the end of the billing period. Your data may be held for a grace period (30 to 90 days is common) and then deleted. Some tools let you export before deletion. Some do not make that easy. Some charge for export at scale.
If your business processes, client history, or critical documents live only inside a single platform with no export habit, you are one cancelled subscription or one company shutdown away from losing years of work.
What to actually look for
You don't need to read every word of every EULA. You do need to know which clauses to search for. Here is a working checklist for any tool that touches sensitive business data or content you care about.
- Data ownership: Does the agreement confirm you own your data? Or is ownership ambiguous?
- The licence they take: What rights do they claim over your inputs and outputs? Look for "royalty-free," "sublicensable," and "worldwide." Broad licences are not automatically bad, but you should know they exist.
- AI training opt-out: Is there one? Is it available on your plan? Do you have to action it manually?
- Data on cancellation: How long is the grace period? Can you export everything? Is there a cost to do so?
- Change of control: What happens to your data if the company is acquired? Does the acquirer inherit the same obligations?
- Terms update notice: How much notice do they give before material changes take effect? Thirty days is a reasonable minimum. Some terms say "we may update at any time."
The enterprise tier question
Many of the most aggressive clauses in standard terms disappear at enterprise pricing. Data processing agreements (DPAs) become available. AI training exclusions kick in. Export and portability commitments appear.
If you are running a small business on the standard plan of a major platform, you are almost certainly on less favourable terms than larger clients. That is not a conspiracy. It is just how tiered software pricing works.
The practical implication: if a tool is deeply embedded in how your business operates, it is worth asking the vendor directly what data commitments are available at your tier, and whether a DPA is on offer even if you are not enterprise-sized. Some will. Some won't. Knowing the answer is better than assuming.
The AI-specific wrinkle
One thing worth understanding about AI training clauses specifically: even if a vendor says your data won't be used to train models, the agreement often distinguishes between "your" model (trained on your data, for your account) and their foundation model (trained on aggregated signals from the whole user base).
Anonymised, aggregated usage patterns are almost always fair game, though GDPR sets a high bar for what counts as true anonymisation. The question is how broadly "anonymised" is defined and what those patterns include. There is no universal answer. But if you are feeding a tool proprietary research, client strategy documents, or commercially sensitive information, it is worth understanding what the aggregation clause actually covers.
A practical starting point
You don't need to audit every tool you use this week. A sensible first pass:
- List the tools that hold your most sensitive or irreplaceable data.
- Search each vendor's help centre for "data ownership," "AI training," and "data retention on cancellation." Most decent vendors have a plain-English page on this now.
- Check whether a DPA is available and whether you have signed one.
- Start a regular export habit for anything critical, even if you have no intention of leaving.
None of this requires a lawyer for the initial review. Where you do want legal input is if you are signing a custom enterprise agreement, handling personal data at scale under GDPR, or in a sector with regulatory obligations around data handling.
How AI with Ash can support you
If you are building AI workflows into your business, the tools you choose and the terms you accept become part of your operational infrastructure. Getting that layer right from the start is a lot easier than unpicking it later. When I work with clients on agent and automation builds, part of that work is making sure the stack choices are ones they can actually live with long-term.
If you want a clear-eyed conversation about how this applies to your setup, book a call and we'll work through it together.