The sixty-second answer
In most contracts you own the records you put into business software, and the vendor holds a limited licence to process them. But ownership is only one of three questions. The others — can you actually extract the data, and who answers for it under Canadian law — matter more in practice.
Three questions that get confused with each other
"Who owns my data" sounds like one question. It is three, and mixing them up is how small businesses end up with a contract that says the right thing and a situation that does not.
Ownership is contractual. It decides who has the legal claim to the records and what the vendor may do with them. It is written down and it is negotiable.
Access is practical. It decides whether you can actually get the records out, in a usable form, on a day when the relationship has gone cold. No clause guarantees this; only a tested export does.
Accountability is statutory. It decides who answers when a customer asks what you hold about them, or when something leaks. In Canada this does not move with the data. It stays with the business that collected the information.
A contract can settle the first. Only you can settle the second. And the third was never yours to give away.
What the contract usually says
Most reputable business software contracts state that the customer retains ownership of customer content, and grant the vendor a licence to host, process, transmit and display that content solely to provide the service. That is the shape you want. Read for four specific things.
Scope of the licence. "Solely to provide the service" is the phrase that matters. A licence broad enough to cover product improvement, analytics across customers, or model training is a materially different agreement, and it should be an explicit choice rather than a default.
Export rights. Look for a right to export in a machine-readable format, at any time, without a fee. If export is described only as something support can help with, that is not a right.
Retention after termination. A stated number of days during which you can still retrieve everything, and a stated fate afterwards. Ambiguity here is the most expensive kind, because it only becomes relevant when you are already leaving.
Deletion on request. The ability to require deletion, and to receive confirmation of it. You need this to meet your own obligations, which is the next section.
Accountability does not transfer
This is the part that surprises owners. If you collect personal information from your customers, PIPEDA's obligations attach to you. Schedule 1 requires that the purposes for collection be identified before or at the time of collection (Principle 2), that collection and use rest on the individual's knowledge and consent (Principle 3), and that information not be used or disclosed for purposes other than those consented to (Principle 5) [1].
Two further principles determine whether your software choice is workable. Principle 8 requires that your policies and practices relating to the management of personal information be made readily available to individuals [1] — which means you have to know what those practices are, including whose servers are involved. Principle 9 provides that on request an individual shall be informed of the existence, use and disclosure of their personal information, be given access to it, and be able to challenge its accuracy and have it amended [1].
Read that last one against the software you actually run. A customer emails asking what you hold. Can you tell them, completely, within a reasonable time? If the answer requires exports from five systems and a search of an inbox, your problem is not the contract. It is the architecture. Our guide to PIPEDA requirements for small businesses works through the obligations in order.
Clause 4.5.3 is the one most often ignored: personal information that is no longer required should be destroyed, erased or made anonymous, and organisations shall develop guidelines and implement procedures to govern that destruction [1]. A vendor cannot do this for you, because only you know what you still need.
Where the data physically sits
Canadian law does not forbid storing personal information outside Canada. What it does is keep the accountability with you wherever the data goes, which turns location into a practical question rather than an ideological one: who can compel access to these records, under whose legal process, and how quickly can you get a straight answer about it?
There is a national dimension here that Parliament has stated in plain terms in a related field. Section 7 of the Telecommunications Act opens by affirming that telecommunications performs an essential role in the maintenance of Canada's identity and sovereignty, and sets out policy objectives including the orderly development throughout Canada of a telecommunications system [6]. The infrastructure that carries a country's business is treated as a matter of sovereignty, not merely of price.
For a small business the practical version is simpler. Ask the vendor where the data sits and who operates the facility. A vendor that answers with a region code and nothing else has told you they do not expect the question. Our article on Canadian-hosted business software covers what the answer should look like.
Ownership means nothing without an exit
The clearest test of ownership is whether you can leave. Not whether you want to — whether you could, this month, with everything.
Domain names are the useful comparison because the rules there are explicit. Under ICANN's Transfer Policy, registered name holders must be able to transfer their registrations between registrars, transfer processes must be clear and concise, a registrar may deny a transfer only in enumerated instances and must give the reason to both the holder and the gaining registrar, and a transfer lock must be removed or an accessible removal method provided within five calendar days [2]. That is what portability looks like when someone has written it down.
Business software has no equivalent regime, so you have to create the equivalent yourself: request a full export during your trial, open it, and confirm it contains history and attachments rather than a list of names. Do that once, before you commit, and again periodically. Our walkthrough on switching business software without downtime covers what to do with the export when the day comes.
Testing what a vendor tells you
Data-handling claims are marketing claims, and Canadian law treats them accordingly. Under the Competition Act, a representation to the public that is false or misleading in a material respect is reviewable, and a representation about the performance or efficacy of a product must be based on an adequate and proper test — the proof of which lies on the person making the representation [3]. If a vendor states a security or reliability figure, asking what supports it is not adversarial; it is the statute's own allocation of proof.
The same discipline applies to anything you send. Canada's Anti-Spam Legislation requires consent, express or implied, before a commercial electronic message and requires prescribed identifying and contact information within it [5]. If your consent records live in a vendor's system, your ability to prove consent depends on your ability to get those records out — which loops back to the export question.
Why this is a small-business problem specifically
As of December 2024 there were 1.10 million employer businesses in Canada, and 1.08 million of them — 98.2 per cent — were small [4]. Almost nobody at that scale has counsel reviewing a software agreement. The realistic defence is not legal review of every contract; it is a short checklist applied consistently: do I own it, can I export it, how long after cancellation, and can they use it for anything else.
Where we sit
Your data in MapleWorkSuite is yours. We hold it to run the apps you have switched on, on Canadian infrastructure operated by a Canadian company, and we will tell you where any specific piece of it sits if you ask. We do not use your customer records for anything other than operating your account.
Export is available in a form you can open without us, because a vendor that makes leaving difficult has told you what they think of their own product. And we will not claim that choosing us makes you compliant — nothing you buy does that. What consolidation does is remove the excuse of not knowing where your data is, which is where most small-business privacy failures actually begin.
If you are auditing this across everything you run, start by listing every system holding customer records. Our guide to how many subscriptions you actually need is built around that same count, and it is usually longer than owners expect.