Guide
Questions to Ask Before Buying a Data Platform
Buying a data platform is easy to get wrong, because the painful parts usually only show up two or three years in, when leaving becomes expensive. These are the questions worth asking upfront. Ask them of us too.
Ownership and exit
1. If we stop paying you tomorrow, what happens to our data?
The most important question on this list. Ask for the specific answer, not the reassuring one. Is it deleted, frozen, held for a grace period, or exportable indefinitely? Get it in writing.
2. Can we export everything, including history and attachments?
Many exports cover current records but quietly drop audit history, file attachments, or the relationships between tables. An export you cannot rebuild from is not really an export.
3. What format does the export come in, and could another supplier use it?
A proprietary format that only the vendor's own tooling reads is a lock in mechanism regardless of what the contract says about ownership.
4. Who legally owns the data, and who owns the derived data?
Most contracts say you own your data. Fewer are clear about aggregated, de-identified or derived datasets, and whether the vendor may use those for benchmarking, product development or model training.
5. Whose cloud account is it in?
There is a real difference between the vendor hosting your data on their infrastructure under their terms, and the system running in an account your organisation holds. Both are legitimate. Know which one you are buying.
Cost over time
6. What does this cost in year three, not year one?
Ask about per seat scaling, storage tiers, and what happens when your headcount or record count grows. Introductory pricing is not a forecast.
7. What is the cost of the things that are not included?
Implementation, data migration, training, integrations and support are frequently priced separately from the licence.
8. What would it cost us to leave?
Export fees, professional services to extract data, and the internal cost of rebuilding reporting somewhere else. Ask an existing customer who has left, if you can find one.
Security and residency
9. Where is the data physically stored, and where are the backups?
Backups sometimes live in a different jurisdiction to the primary data. So do support teams who may have access.
10. Who at the supplier can see our data, and is that logged?
Support staff usually need some access. The question is whether it is minimised, logged, and visible to you.
11. What security claims can you actually evidence?
There is a meaningful difference between an independently audited certification, a self assessment, and a marketing page. Ask which one you are being shown, and be suspicious of anyone unwilling to distinguish them.
12. What is the incident process if something goes wrong?
Who tells you, how fast, and what are they obliged to do. A supplier who has never thought about this will show it in the answer.
Governance and AI
13. Is our data used to train any AI model?
Ask explicitly, and ask whether that covers subprocessors and any AI features added in future. A "no" that only applies to today's product is not a "no".
14. Can access rules reflect our governance, not just generic roles?
For organisations with community, cultural or ethics-driven access requirements, generic admin/editor/viewer roles are often too blunt. Ask whether the model can express what your governance actually requires.
15. What happens if the supplier is acquired?
Terms of service, pricing and data handling commitments can all change with ownership. Ask what survives a change of control.
Using this on us
These questions are not rhetorical, and several of them are ones we would answer imperfectly. We are a small practice, our security posture is self assessed rather than independently audited, and we do not offer a 24/7 helpdesk. If any of those are dealbreakers for your organisation, a larger established platform may genuinely serve you better, and our comparison page tries to be honest about where that is true.
Want a second opinion?
Send us the answers you got.
If you have asked a supplier these questions and want a read on the answers, that is a conversation we are happy to have whether or not it leads anywhere for us.
Email hello@databytesai.com.au