Back to the blog
SaaSDataPrivacy

SaaS and your data: the dossier the company builds on you

September 03, 2026·6 min read·Diego Horvatti

A journalist asked McDonald's for a copy of his own data in the loyalty app. Back came a 515-page PDF. Every coupon opened, every notification ignored, time, city, device, plus an internal note saying he was a customer who "will never leave". He just wanted a cheaper Happy Meal.

Now turn the lens around. Your company uses SaaS too. Several. And each one of them is building a similar dossier, except about your customers, and you are the one who answers for it. The discussion about SaaS and data almost always stops at the monthly price. The real cost sits somewhere else.

What your SaaS keeps that you don't even know about

Do a quick exercise. List the tools your company uses today. CRM, email platform, website chat, ERP, scheduling tool, shared spreadsheet, that satisfaction survey app somebody signed up for in 2023 and nobody cancelled.

Now answer: where does the data from each one live? Who has access? What happens if you cancel tomorrow?

Most managers freeze on the second question. That's not a character flaw, it's the product design. SaaS is sold on how easy it is to get in. Nobody demos the exit door.

What these tools usually pile up quietly:

  • Full interaction history for every contact, including what they didn't do
  • Website behavior data tied to email and phone number
  • Backups in regions you never picked
  • Records of people who asked to be deleted two years ago

That last point is the one that hurts most. Privacy law gives customers the right to request deletion. If the data is spread across six tools and you only wiped it from one, the request wasn't fulfilled. It was staged.

Why idle data is a liability, not an asset

There's a comfortable belief that data is always good. Keep everything, one day it'll be useful. Software vendors love that idea, because a bigger plan costs more.

In practice, data you don't use carries three costs:

Risk cost. It leaks, the problem is yours. The customer complains to you, not to the SaaS vendor. And the regulator knocks on your door, not theirs.

Decision cost. A dirty, duplicated database makes reports lie. Then the team stops trusting the numbers and goes back to deciding on gut feel. I've seen this at a company with a very expensive CRM: the sales team kept a parallel spreadsheet because "everything in the system is wrong".

Dependency cost. The longer the data lives only in there, the more expensive it gets to leave. That's why the price goes up in year three and you pay it.

Data you don't use is not an asset. It's a stockpile of problems with a monthly rent.

The thing almost nobody checks: the way out

Before I sign up for any tool, I ask one thing. How do I get everything out of here?

If the answer is "there's a CSV export", great, but keep pushing. CSV of everything or just the main table? Does it include attachments? Does it include conversation history? Is there an API to pull it on a schedule, or is it a manual button that spits out one file at a time?

A common case: a support tool that exports contacts beautifully and doesn't export the content of the conversations. You leave with the list of names and lose three years of context. Technically they delivered what they promised.

Run that test in the first month, not the last. Export everything while the database is still small and see what comes out. It's half an hour of work that gives you an honest answer about the vendor.

How to do the inventory without turning it into a six-month project

You don't need consultants or a committee. You need a spreadsheet and about two hours.

  1. Pull the corporate card statement for the last twelve months and flag every recurring software charge. You'll find subscriptions nobody remembers.
  2. For each tool, note four columns: what personal data it holds, who in the company accesses it, how you export it, and whether it's still in use.
  3. Cancel what isn't used. Before cancelling, export.
  4. For the ones that remain, review who has access. A former employee with an active login is the classic.

Step 1 alone usually pays for the whole exercise. What I typically find at a small company is three to five ghost subscriptions, somewhere between R$ 200 and R$ 900 a month thrown away.

Step 4 is the most tedious and the most important. Access is the real vector. It's not a movie hacker, it's the 2024 intern account still open with admin permission.

Where AI comes in and where it makes everything worse

Now there's a new layer. Almost every SaaS shipped an AI feature in the last year, and in a good share of them the default is to use your content to train the model. Sometimes there's a switch to turn it off. It's almost never off by default.

It's worth opening the settings of your three main tools today and looking for something like "product improvement", "data sharing" or "model training". It's one click that changes quite a lot.

On the other side, AI also solves a real problem here. Good automation pulls data out of silos and puts it somewhere you control. A simple flow that copies the important CRM records into a database of your own, every day, gives you independence without having to switch tools. It's not sexy, it's safe.

The rule I follow with clients: the tool can belong to a third party, the copy of the data always belongs to the company.

What to do on Monday

You don't need to overhaul anything. Start small and concrete:

  • Pick the tool that holds the most customer data and export all of it this week. Store the file somewhere you control.
  • List who has access to it and cut what's left over.
  • In the settings, turn off AI training if the option exists.
  • Write down what you found in the spreadsheet. That's already your inventory.

Repeat with the second tool next month. In six months you'll have a map most companies your size don't have.

The McDonald's journalist didn't uncover anything illegal. He uncovered something worse: a company that knew more about his habits than he did, and that was certain he would never leave. That much confidence on the other side of the table is usually a sign somebody isn't reading the contract.

If you want to build this kind of control without turning it into a giant project, that's exactly the kind of thing I do day to day: mapping the tools, automating the copies and putting the data where it should be. Take a look at how I work.

LinkedIn summary

A journalist asked McDonald's for a copy of his own data. He got back a 515-page PDF.

Every coupon opened, every notification ignored, time, city, device. Plus an internal note saying he was a customer who "will never leave".

Now turn the lens on your company. Every SaaS you use is building a similar dossier about your customers. And the one who answers for it is you, not the vendor.

The conversation about SaaS almost always stops at the monthly price. The real cost sits somewhere else: data you don't use is not an asset, it's a stockpile of problems with a monthly rent.

Before I sign up for any tool I ask one question: how do I get everything out of here? If the answer takes a while, that's already the answer.

Write down the name of the tool that holds the most customer data you have. Do you know how to export all of it today?

#GDPR #SaaS #DataManagement #Automation #DigitalTransformation