OdinTask field-service app OdinTask ODINTASK · GUIDE
data ownership

Backup and Owning Your Business Data: 9 Questions to Ask

9 July 2026 · 9 min · data ownershipbackupsoftware contractsgdprfield service software

Backup and owning your business data comes down to nine questions you ask a supplier before you put ten years of job history into their system: can I export everything, in what format, how fast, does it include the photos and PDFs, what happens the day I cancel, how long do you keep my data after that, where is it stored, who else can read it, and what exactly do you back up? Get the answers in writing. If the answer to "can I export everything" is a demo of a CSV button, ask what that button does not include. And be clear on the second half: a cloud supplier's backup protects them from a server dying. It does not protect you from your own mistakes, a billing lapse, or the supplier going away. Those need your own copy.

Why the export clause matters more than the feature list in 2026

The first wave of trades firms went cloud around 2014-2016. A lot of one-to-twenty person firms now have a decade of material sitting in someone else's database: quotes, invoices, job cards, inspection protocols, before-and-after photos, signed documents, price files, time records.

Two years in, switching cost you a weekend. Ten years in, the data is the business. It is your defence when a customer disputes work from 2019. It is what your accountant needs. In Sweden, accounting records must be kept for seven years after the end of the calendar year they relate to (bokföringslagen 1999:1078, 7 kap.). In the UK it is six years for VAT records, in New Zealand seven, in Australia five. Note the mismatch: your legal retention duty outlives most software contracts, and you are the one on the hook, not your supplier.

So the question stopped being "does it have a good planner". It is "if this company is bought, doubles its price or shuts down, do I walk out with everything intact, and how long does it take".

The nine questions to ask any supplier

Send these by email. Email creates a record. A sales call does not.

1. Can I export everything myself, without asking you?

The right answer is yes, from inside the product, any time, without raising a ticket. A migration that depends on the supplier's goodwill is not an exit — it is a negotiation you conduct after you have already told them you are leaving.

2. What format, and does it include the relationships?

CSV or Excel per table is the floor. What people miss is the joins. An invoice CSV is worth little if nothing says which job it belonged to, and a photo dump is worth little if the filenames are IMG_4821.jpg with no job reference. Ask: do exported rows carry stable IDs, and do child records carry the parent ID? PDFs should come out as actual PDFs, not links back into a system you have cancelled.

3. What is not in the export?

The highest-yield question of the nine, because no sales page answers it. Common gaps: photos and attachments, customer chat threads, audit trails on signed documents, custom form templates, price-list history, and time-clock stamps. Ask for a list. If they cannot list it, they have not thought about it.

4. How fast, and is there a size limit?

Ask for a real number for a firm your size. Ten years of job photos for a five-van firm is realistically 20-200 GB. If the export runs in the background and arrives as a link, ask how long the link lives. "You can export" and "you can export 180 GB within 48 hours of asking" are different promises.

5. What happens on the day I cancel?

Three very different outcomes: the account goes read-only for a period and you can still export; it locks immediately and you must ask them to run an export for you; or data is deleted on a schedule. Get the period in writing, in days. Thirty days read-only is a reasonable ask.

6. How long do you hold my data after that, and can I have it deleted on request?

You want both ends: enough grace to get your copy out, and a clean deletion afterwards on your say-so. Under GDPR Article 28, a processor must delete or return personal data at the end of the service at the controller's choice. That clause belongs in the contract, not just in the regulation.

7. Where does the data physically live, and who are the sub-processors?

Ask for regions, not marketing copy. "EU" is fine; "the cloud" is not. Then ask for the sub-processor list — the suppliers behind the supplier: hosting, email delivery, error monitoring, AI providers. Every serious vendor publishes this. If yours does not, that tells you something.

8. Who at your company can read my customer records, and is that logged?

Support engineers need access to fix things. That is normal. What you want is access that is bounded and audited, not access that is denied to exist.

9. What does your backup actually cover, and have you restored one recently?

Two numbers matter here, and they have names. RPO (recovery point objective) is how much data you lose in a disaster — if backups run nightly, up to 24 hours of it. RTO (recovery time objective) is how long you are down. Ask for both. Then ask the follow-up that separates the serious from the rest: when did you last test a restore? An untested backup is a hypothesis.

What backup actually means when the system is cloud-based

This is where most trades firms are quietly exposed. Your supplier's backups are designed for one failure mode: their infrastructure breaking. Point-in-time recovery genuinely works for that scenario. It does not cover the ones that actually happen to small firms.

What goes wrongDoes the supplier's backup save you?What does
Their server or region failsYes. This is the case backups are built for.Nothing needed from you
Office manager bulk-deletes 400 customers in March, you notice in JuneUsually no. Backups roll off, and restoring overwrites three months of good work.Your own periodic export
Card expires, account suspended, data purged after the grace windowNo. A policy outcome, not a failure.Your own copy, plus billing alerts
Supplier is acquired, sunset, or triples the priceNo.Your own copy, plus an export clause
Account compromised, records alteredPartly, if you catch it inside the retention window.Two-factor, audit trail, your own copy

Read the middle three rows again. In every one of them, the supplier's systems worked perfectly and you still lost your data. Backup is not one thing. Their backup is availability insurance. Your export is ownership.

A backup routine a small firm will actually do

Anything needing monthly discipline from a busy owner gets abandoned by month four. So keep it to this.

The GDPR point everyone gets backwards

People assume GDPR guarantees they can get their business data back. It does not, and the distinction matters.

Article 20, data portability, is a right belonging to individuals over their own personal data. Your firm is the controller; the software supplier is the processor. Article 20 gives your customer a right against you. It gives you nothing against your supplier.

What does help you is Article 28: the processor agreement, called personuppgiftsbiträdesavtal (PUB-avtal) in Sweden and a data processing agreement in the UK. It must specify sub-processors, security measures and what happens to personal data when the contract ends. Ask for it before signing and read the deletion-or-return clause. It is usually one paragraph, and it is the most commercially important paragraph in the document.

Note what it still does not cover: your job photos, protocols, price lists and variation notes. Most of that is not personal data at all. Its only protection is the export terms you agreed to. Which is why you ask the nine questions.

Red flags in a supplier's answers

None of these on its own means the product is bad. Several of them together means you are renting your own history.

Where OdinTask sits on this

We would rather you asked us these questions than not. In OdinTask you export your customers, price-list articles and suppliers to a spreadsheet yourself from the admin area — no ticket, no add-on charge — and re-import them the same way. Invoices, quotes and inspection protocols generate as PDFs you keep. Data is hosted in the EU. The reason to build it that way is simple: a system you can leave is a system you can trust. There is a 14-day free trial at signup, plans are on the pricing page, and more practical guides are on the blog.

The one-line version

Ask the nine questions before you sign, not while you are leaving. Export everything four times a year, keep two copies in two places, and open one file a year to prove the archive is real. The supplier's backup keeps their servers honest. Your export keeps your business yours.

FAQ

Does a cloud supplier's backup mean I don't need my own?

No. Their backup protects against their infrastructure failing, which is one scenario. It rarely helps if a staff member bulk-deletes records and you notice three months later, if your account is suspended over a lapsed card, or if the supplier shuts down or is acquired. In all of those the supplier's systems worked perfectly and you still lost data. Keep your own quarterly export.

What should a full data export actually contain?

Customers, jobs, quotes, invoices, suppliers, price lists, time records and inspection protocols as CSV or Excel, each row carrying stable IDs so you can rebuild the relationships between them. Plus PDFs of anything signed or sent, and photos as real files with a job reference in the filename or an index alongside. Then ask the supplier what the export does not include. That list is the useful one.

Does GDPR guarantee I can get my business data back from a supplier?

No, and this is widely misunderstood. Article 20 data portability is a right individuals hold over their own personal data, so it gives your customer a right against you, not you a right against your software supplier. What helps you is the Article 28 processor agreement, which must state whether personal data is deleted or returned at the end of the contract. Your job photos and protocols are covered by neither, only by your export terms.

How often should a small trades firm export its data?

Quarterly is the realistic floor: the first working day of January, April, July and October. Also export before any big change, such as a price-list import, a bulk edit, a staff departure or a plan downgrade, because those are when data disappears. Keep the export covering each closed financial year for as long as your accounting rules require: seven years in Sweden and New Zealand, six in the UK, five in Australia.

What happens to my data if I cancel my subscription?

It depends entirely on the contract, so get it in writing, in days, before you sign. The three patterns are read-only access for a grace period, an immediate lock that forces you to ask them for an export, or deletion on a schedule. Thirty days read-only is a reasonable ask. Confirm separately that you can require deletion afterwards, which the Article 28 processor agreement should cover.

What are RPO and RTO, and why should I ask about them?

RPO, recovery point objective, is how much data you lose in a disaster. With nightly backups that is up to 24 hours of work. RTO, recovery time objective, is how long you are offline while they restore. Ask a supplier for both as numbers, then ask when they last tested an actual restore. An untested backup is a hypothesis, not a backup.

One system for your field-service business

Booking, quotes with ROT, scheduling, an offline app, time tracking and invoicing — in your own brand.

Try OdinTask free