Customer Data in Your Own Hands: Journey and Privacy

Every step in your customer journey generates data. Where it lands, who owns it, and what Europe and open source do and don't solve here.

← back to home

Pillar 01 // Ownership
customer-data-ownership.md

$ trace --data=customer-journey --question=where-does-it-live --who=owner

Customer Data in Your Own Hands: journey and privacy

Every step in your customer journey generates data, and at most companies that data sits spread across five vendors without anyone having an overview. This piece walks that journey one question per step: where does this land, whose name is on the account, and can you leave without losing everything.

DD DataDrift Digital August 9, 2026 8 min

The question "where is my customer data" usually gets answered at the vendor level. In our CRM, in email, in accounting. That's an inventory of tools, not an answer to the question.

The useful answer follows the customer journey, because that's what generates the data. At each moment something is created, it lands somewhere, and someone is formally the owner. Those three rarely line up with what you'd expect.

01 / the journeyWhat data is created where?

Five moments, from first contact to completion. At each one, the question is where it lands.

01First contact. Name, company, what they're looking for. Created on your website or in your inbox. Often lands in a form tool you picked six years ago.
02Conversation. What they actually want, what they tried before, what their budget does. This is the most valuable data of the entire journey and it usually lands nowhere.
03Proposal. What you're offering and under what terms. Lands in a document tool, sometimes with a signing service attached.
04Delivery. Files, reports, hours, correspondence. Spread across the project environment, inbox and disk.
05Follow-up. Invoices, evaluations, everything you keep to be able to look back later. Lands in accounting and the rest nowhere.

There's also a shadow copy at every step, and it's almost always forgotten in this kind of inventory. An export in someone's downloads folder. A shared folder with old quotes. A mailbox going back twelve years with every file still sitting in it. Those copies fall under the same rules as the original, and in a data breach they're usually the source.

Look at steps 2 and 5. Those are the two where the most value is created and where it's least structurally recorded. That's no coincidence: they're also the two steps without a required form.

02 / ownershipWhat does "in your own hands" actually mean?

Not that you host everything yourself. But that the accounts are in your name and that you can leave.

That distinction matters more than it sounds, because it's where a lot of service arrangements get sticky. There's a difference between data sitting with a vendor on your contract, and data sitting in an environment that an intermediary manages for you. In the first case, nothing changes when the collaboration ends. In the second case, something has to be arranged, and that's exactly the moment you have the least negotiating position.

The test isn't where it's located. The test is what happens on the day you leave.

We therefore apply a separation that's worth asking any provider about: the client owns the accounts and the data, the builder owns the build layer they deliver. Anyone who notices in that conversation that no clear answer comes has already got their answer. The full breakdown of that question is in who owns it when it works.

03 / locationWhy Europe matters

Because it determines which court has jurisdiction and which government can get access.

Additional requirements apply to personal data leaving the EU, and those requirements have gotten stricter in recent years. In practice it comes down to two questions: which country are the servers in, and which jurisdiction does the parent company fall under. Those two are not the same, and the second is almost never asked.

What this means for you depends on what you process. If you work with ordinary business contact details, it's a point of attention. If you work with health data, records of vulnerable people, or personnel data, it's a design requirement, not a preference. Explored further in keeping data in Europe and in how safe is customer data in an AI system.

04 / open sourceWhat it solves and doesn't

Open source solves the exit problem. It doesn't solve the privacy question.

That distinction gets structurally blurred in sales conversations, so to be sharp about it. Open software means the source code is public and that you can, in principle, run it yourself. That lets you switch vendors without losing your data, and it lets you have what happens checked. That's real value, and it's why we build in that direction.

But: where you run it determines the privacy, not the license. Open software on a US server is still data on a US server. And open source says nothing about the quality of your own setup, your passwords, or your access rights. That remains work someone has to do.

01It solves: being locked into one vendor, and not being able to verify what happens under the hood.
02It doesn't solve: where the servers are, who has access, and whether your setup is sound.

Which parts of our own stack are open and which aren't is listed on the stack page. We think a provider should be able to answer that question without first having to consult internally.

05 / the testSix questions to ask

Ask every party that's going to do something with your customer data, preferably before anything is signed.

  • Whose name are the accounts in? Not who manages them, but who is contractually the customer with that vendor.
  • What happens on the day I stop? Concretely: which file do I get, in what format, and how long does that take.
  • Which country are the servers in, and where is the parent company based? Two questions, not one.
  • Who can access my data and how is that logged? Ask about the logging, not the promise.
  • Is there a data processing agreement? If personal data flows through it, that's a legal requirement, not a formality.
  • How long is what retained? Unlimited retention isn't a luxury, it conflicts with the principle that you don't keep data longer than necessary.

Ask them in writing. Not because a conversation is unreliable, but because an answer on paper still exists later, even after the account manager who gave it has moved on somewhere else.

We publish our own answers to those questions in the privacy statement. Not because it's required, but because it's the only way to keep ourselves sharp about them.

A provider that finds these six difficult hasn't thought about it. That, by itself, is the answer.

Frequently asked questions
What does keeping customer data in your own hands mean?+
That the accounts with your vendors are in your name and that you can leave without losing anything. Not that you host everything yourself. The difference between data sitting with a vendor on your contract and data in an environment managed for you by an intermediary only becomes clear on the day the collaboration ends, and that's when you have the least negotiating position.
Where in the customer journey does most data get created?+
In the conversation and in the follow-up. Those are also precisely the two moments that are least structurally recorded, because there's no required form attached. First contact, proposal and delivery usually do land somewhere, though often spread across three tools.
Does my customer data need to be in Europe?+
Additional requirements apply to personal data leaving the EU. How heavily that weighs depends on what you process: for ordinary business contact details it's a point of attention, for health data, records of vulnerable people, or personnel data it's a design requirement. Always ask two things: which country are the servers in, and which jurisdiction does the parent company fall under.
Does open source solve my privacy question?+
No. Open source solves being locked into one vendor and makes what happens verifiable. Where the software runs determines the privacy, not the license: open software on a US server is still data on a US server. And the quality of your own setup and access rights remains work someone has to do.
Do I need a data processing agreement?+
If an external party processes personal data for you, yes. That applies to customer data and certainly to personnel data. It should also specify where the data physically resides, who can access it, and how long it's retained. Unlimited retention shouldn't be in there.
What do I ask a provider about ownership?+
Six things: whose name the accounts are in, what happens on the day you leave and in what format, which country the servers are in and where the parent company is based, who can access the data and how that's logged, whether there's a data processing agreement, and how long what is retained. A party that finds these questions difficult hasn't thought about it.
30 minutes, free, no sales pitch

Do you know, for every step of your customer journey, where the data lands?

Schedule a conversation

We'll walk through your customer journey and name, per step, where it lands and whose name it's under. If it turns out you've got it well arranged, you'll hear that, and from then on you'll know for certain instead of probably.

→ Schedule a conversation (30 min)

This text was produced with AI assistance and reviewed and approved by a human before publication.