Use a field-level rights and purpose review to assess telemetry before considering external AI use or a data license.

Start here

Does any of this sound familiar?

  • Your product records events such as feature activation, workflow completion, errors, or time between steps.
  • Telemetry may include account IDs, device identifiers, user behavior, or signals derived from customer content.
  • A proposed AI use would move data beyond service operations, product analytics, or the purpose described to users.

Dashboard summaries may look anonymous while event rows retain account IDs, timestamps, device details, or behavioral patterns. Aggregation can reduce exposure, but events may identify people or reveal confidential use. Storage control does not settle customer, user, or third-party rights.

Treat telemetry as a governed data flow. Define whether the goal is evaluation, training, benchmarking, or analytics. An aggregate or purpose-built task may suffice; a historical event stream is different and often more intrusive.

Not ready to share a single file? You don't have to.

Take the 3-question fit check

The problem

Collection permission and licensing permission are different questions

A service contract may allow events for operations or product improvement without permitting external training or licensing. Events may derive from customer content or an integration governed by another provider's terms. Rights vary by region and data subject.

A law granting access to connected-product data may not cover every usage log. Scope matters, and personal-data protections remain relevant. Hashing or removing direct identifiers does not itself anonymize records or resolve contract restrictions.

If the purpose changes, revisit the permissions before the pipeline changes.

The solution

Run a telemetry purpose-and-rights review

Bring product analytics, privacy, engineering, security, and counsel together before discussing external transfer or licensing.

DataSupply partners only with labs that meet its top 0.01% credibility standard. We help assess whether a qualified buyer may be a fit and negotiate terms that reflect the data's potential value, including exclusivity where relevant. We also help you work through diligence questions about rights, privacy, security, and compliance, then present a high-level inventory of permitted records, not the dataset. Fit is specific to each situation; no buyer or value is guaranteed.

What to inventory before any buyer conversation

  • Map events and their sources Document event names, fields, identifiers, collection point, user relationship, integrations, retention, and purpose. Trace aggregates to source fields; flag sensitive events.
  • Compare the proposed use with commitments By region and customer type, review contracts, disclosures, legal basis, IP terms, and vendor restrictions. Check compatibility with stated purpose and whether notice, permission, or exclusion is needed.
  • Choose the minimum useful representation Consider aggregates, authored workflows, or evaluation tasks before event histories. Set cohort and rare-event rules, access, retention, deletion, audit logs, and re-identification review. Record exclusions and approval.

Set the boundaries before discussing access.

Specify purpose, recipients, security, retention, deletion, re-identification and onward-transfer limits, derivatives, audits, and breach response. Get local advice and establish authorization before sharing regulated or confidential data.

What could make a permitted example useful?

A documented signal may answer a product question, but broad telemetry does not prove value or licenseability. Rights, representativeness, quality, minimization, and review effort affect feasibility; no buyer or return is guaranteed.

A practical first step.

Inventory one event family, fields, purpose, and retention without copying rows. Ask privacy and counsel to classify proposed use before sharing a sample.

datasupply.ai can discuss possible fit and buyer questions without receiving your dataset. You decide whether to pursue any introduction. No buyer, license, or payment is guaranteed.

Documented example / what it proves

The EU Data Act distinguishes access rights from personal-data authority

Regulation (EU) 2023/2854, the EU Data Act, sets rules for access to and use of data within its scope. It says that where a user is not the data subject, the Act creates no legal basis to provide personal data to a third party and gives no new right to use personal data generated by a connected product or related service. Read EUR-Lex, Regulation (EU) 2023/2854 (Data Act).

An access framework does not erase personal-data rights. A SaaS company must determine whether its product and dataset fall within the Act; it is not a blanket rule for all telemetry.

The important limit: The Regulation is a legal framework with a defined scope, not proof of a closed data license, blanket permission to sell usage logs, or a substitute for jurisdiction-specific legal analysis.

Where might your own organization stand?

Take the private fit check

Quiz / Your next step

What is the source and permitted purpose of your usage data?

Classify the telemetry before deciding whether an AI use or external license is possible.

01 What kind of records do you have?
02 What do you know about the rights?
03 Where are you in the process?

This check stays in your browser. If you choose to apply, your answers are included when you submit the application.

No fee for the initial conversation or introduction. We may be compensated by a buyer if an introduction becomes a partnership. No buyer, license, or payment is guaranteed. Review any proposed deal with your own legal and security advisers.