Transparency in SaaS: why denial costs you more
A client messaged me on a Sunday asking if his scheduling system "sent data somewhere". He had seen a story about TVs collecting information on who was watching, and the manufacturer replying on video that it was all misinformation. His doubt wasn't technical. It was simple: how would he know? And that's the question people most often skip when hiring anything. Transparency in SaaS isn't a pretty badge in the site footer, it's your ability to verify what you were told.
Because the problem with the LG case isn't the data collection itself. It's the shape of the answer.
What happened, in two lines
News reports pointed out that the devices collected more user data than people imagined. The company went public saying the accusation was false.
That's it. An accusation with evidence on one side, a denial with no evidence on the other. And the consumer in the middle, picking who to believe based on vibes.
Why "that's a lie" is the worst possible answer
Denying is fast and cheap. That's why it's tempting. But denial has a structural problem: it doesn't close the subject, it just pushes it forward.
When a company answers a technical fact with an institutional statement, it's changing the ground. It left "here's what the device sends" and went to "trust me". Anyone paying attention notices right away. And anyone who isn't paying attention walks away with a nagging doubt that never quite goes.
The answer that closes the subject is boring and specific. Something like: the device sends these fields, to this address, at this frequency, and you turn it off here. Nobody applauds. But nobody doubts it either.
Trust isn't declared. It's proven with a document, a version and a date.
That goes for a TV manufacturer and it goes for your CRM vendor.
This has more to do with your business than it looks
You probably don't manufacture electronics. But you run your business on top of six, eight, twelve third-party tools. Each one with access to something of yours.
The CRM has your customers' phone numbers. The email tool has your entire list. The support system has the conversation history, which is where people type national ID numbers, addresses and sometimes far more sensitive things. The ERP has your revenue. The shared spreadsheet nobody remembers creating has who knows what.
Now the uncomfortable part: under privacy law, the one who answers for your customer's data is you. The vendor is the processor, you are the controller. If they leak it, the person comes looking for you. The regulator comes looking for you. The vendor sends out a note saying they take security very seriously.
I've seen a company find out, in the middle of an incident, that it had no idea where its data was hosted. It found out at the same time as the angry customer on the phone.
How to demand transparency from a vendor without being a pain
You don't need to audit anyone. You need answers in writing. If the vendor replies fast and with a document, great sign. If they reply with adjectives, yellow flag.
Send these questions by email, not by chat. You'll want the record later.
- Where does the data physically live? Country and provider. "In the cloud" is not an answer.
- Who inside your company can see my customers' data? Is that access logged?
- Do you use my data to train models, generate benchmarks or anything aggregated? If so, can it be turned off?
- If I cancel tomorrow, how do I export everything and how long until you delete it?
- What was your last security incident and what changed after it?
That last one is my favorite. Every company with more than three years on the road has had some kind of scare. Anyone who says they've never had anything is either very new, or not looking, or lying. None of the three is reassuring.
And there's a detail almost nobody uses: under privacy law, a person can request confirmation of processing and access to their own data. The full answer has a deadline, 15 days in Brazil. Make that request yourself, as if you were a customer, to your own system. It's the most honest test there is. If your operation can't answer within 15 days about you, it won't be able to answer about anyone.
The screenshot test
There's a lazy and very effective way to assess transparency: see if you can screenshot it.
A clear policy turns into a screenshot. "Data lives in São Paulo, on provider X, with daily backups and 30 days of retention" fits in one image and settles an argument. Meanwhile "we adopt market best practices in compliance with current legislation" proves nothing and won't even help you defend yourself later.
Apply this to your own company. Open your privacy page right now. Does it answer where the data lives, how long it stays and how a person deletes it? Or is it a text someone copied from another site in 2021 that nobody has read since?
If it's the second option, you're in the same place as the manufacturer in that video. You just haven't had the journalist show up yet.
"But I don't have time for this"
You do, and it's less than it looks. One afternoon gets you a first version.
Make a simple table with four columns: tool, what data it touches, where it's hosted, who in your company has a login. Fill it in with what you already know. Things will be missing, and the gap itself is valuable information.
Then send the five questions above to the three vendors that touch customer data. It doesn't have to be all of them. The three most critical ones cover 80% of the risk.
Finally, put a review on the calendar every six months. Not because someone is going to audit you, but because tools come and go all the time and nobody tells legal.
This isn't bureaucracy. It's the difference between answering a customer in ten minutes with a document and answering in three days with "we're looking into it".
The part that gives you a competitive edge
Here's my strong opinion: transparency became a sales argument and almost nobody noticed.
Most companies still treat privacy as a cost, a checkbox to avoid fines. Meanwhile, customers got suspicious. They've seen a flashlight app asking for contact access, they've seen a TV listening to conversations, they've seen an AI assistant learning from a document it shouldn't have. They arrive at your proposal with their guard up.
Whoever puts a page in the commercial proposal saying exactly where the data lives, who accesses it and how it leaves, gains an edge no competitor copies quickly. Because copying it means actually getting your house in order.
It's the same reason a restaurant with a glass kitchen feels safer. It's not that the food is better. It's that nobody puts glass in the kitchen if they have something to hide.
If you want to build that data map and don't know where to start, or you suspect your operation has more tools with access than it should, this can be sorted out in a short conversation. Tell me how your operation works today.
LinkedIn summary
A client asked me on a Sunday if his system "sent data somewhere". His doubt wasn't technical: it was how to find out. When a company answers a technical fact with "that's a lie", it doesn't close the subject. It just swaps evidence for "trust me". And trust isn't declared. It's proven with a document, a version and a date. That goes for a TV manufacturer and it goes for your CRM vendor, because under privacy law the one who answers for your customer's data is you, not them. Quick test: open your privacy page right now. Does it say where the data lives, for how long, and how a person deletes it? If you can't screenshot it, it won't even hold up in your own defense. If you don't know how many tools have access to your customers' data today, that's a great place to start the conversation. #DataPrivacy #SaaS #LGPD #Technology #RiskManagement