
Data ownership: Who owns chat history, logs, and any user-generated data stored by the client or via connected services? Typically:
End-user data you generate (your messages, files) is owned by the organization or the user, depending on the deployment.
The vendor may claim rights to aggregated, de-identified telemetry or logs for product improvement, subject to privacy terms.
Data residency and localization: Where is data stored (local devices vs. cloud storage, regional data centers)? Are there options to choose a data region.
Data portability: What formats are supported for exporting data (e.g., plaintext or JSON exports of chat history, server logs, or configurations).
Data access controls and permissions: How can you control who within your organization can access exported data,Are there role-based access controls (RBAC) for data retrieval.
Renewal terms: Auto-renewal frequency, notice period for non-renewal, price renewal terms (e.g., price holds, increases, or CPI-based adjustments).
Cancellation rights: Notice requirements, minimum term commitments, early termination penalties, data return/destruction obligations upon cancellation.
Data return and deletion: Timelines and methods for exporting data prior to cancellation; any post-cancellation access windows; obligations to delete stored data.
Transfer rights: Ability to transfer licenses to another division or entity within the organization, if applicable.
Service continuity and transition assistance: Availability of data migration assistance, knowledge transfer, and onboarding for a transition to another vendor or platform.
Industry standards and frameworks: Look for alignment with common standards such as GDPR (EU/EEA data protection), CCPA/CPRA (California), HIPAA (if handling health-related data and in applicable use cases), SOC 2 Type II, ISO 27001, CSA STAR, and others relevant to your industry.
Security controls: Encryption in transit and at rest, key management, access controls, incident response planning, vulnerability management, third-party audits, and penetration testing.
Data processing and sovereignty: DPA presence, subprocessors list, data transfer mechanisms (SCCs/UK Addenda for EU data transfers), and data residency options.
Audit rights: Your rights to conduct or request independent security audits, and vendor cooperation for audits.
Breach notification: Timeframe and process for notifying you of a data breach.