Lead generation contracts get negotiated forwards: what we will do, how fast, what counts as a result. Almost nobody negotiates backwards — what happens on the day it ends and you want your pipeline machinery back.
Buyers forget that question until it is expensive. By then you have given notice, and the things you assumed were yours live in someone else’s account. Our guide to evaluating AI setter vendors raises it as one of six; this is the long version.
The short answer: In a well-drafted lead generation agreement the buyer owns their data and outputs — contact records, transcripts, recordings, message threads, consent and opt-out evidence — and the vendor owns its method: prompt libraries, playbooks and internal tooling. Phone numbers, sender IDs and A2P registrations are the trap, because they sit in the vendor’s telco account and take days to weeks to move. Settle all three categories in the contract, before you sign.
This page is general information about contract and regulatory concepts, not legal advice. Ownership and liability depend on your own agreement and jurisdiction — get your own advice before you rely on any of it.
Who owns the data when you work with a lead generation agency?
There is no default answer. Ownership of the data, the outputs and the tooling is whatever your contract says, and if the contract is silent, the practical answer is whoever has the login. Possession is not ownership, but on the last day of a notice period it behaves like it.
So the question is not “is my data mine?” It is: which assets can I get back, in what format, in how many days — and which must I rebuild?
Asset by asset: what transfers and what does not
| Asset | Who typically owns it | What to negotiate before signing |
|---|---|---|
| Contact records you supplied | You | Export format, timeframe, and whether the vendor deletes its copies. |
| Enriched fields (mobile appends, firmographics, verification status) | Contested — often the vendor or its data supplier | Name the fields. Some enrichment is licensed from a third party and cannot be sublicensed. |
| Conversation transcripts (SMS, chat, voice) | You, if you say so | Full threads with timestamps and the agent side, not just inbound replies. |
| Call recordings | You, if you say so | Audio plus usable metadata, and a destruction schedule. |
| Consent evidence and the suppression list | You — and the consent obligation stays with you regardless | Mandatory re-importable export on a fixed clock. The one that hurts most. |
| Prompts, scripts, agent configuration | Usually the vendor | You keep the scripts approved for your account; they keep the library behind them. |
| Qualification model / scoring logic | Usually the vendor | The criteria in plain English, so a new operator can reproduce the standard. |
| Phone numbers used for outbound | The vendor’s telco account | Porting rights, and no disconnection while a port is pending. |
| Sender ID (AU) / A2P brand and campaign (US) | The vendor or its aggregator | Register in your own name where possible; otherwise plan re-registration time. |
| CRM integration and field mapping | Shared: connector theirs, mapping yours | A written field-mapping document, refreshed at exit. |
| Dashboards and reporting history | Usually the vendor’s platform | A raw export of the underlying activity, not a PDF of the charts. |
The suppression list is the sleeper
If you must lose one thing here, lose the dashboards. Lose the suppression list and you have a compliance problem, not an inconvenience. Everyone who replied STOP, unsubscribed or complained sits on it. Rebuild outbound without it and you will contact them again, from a clean-looking database that gives no warning.
The ACMA’s guidance on avoiding sending spam states that under the Spam Act, “it’s up to you to prove that you have a person’s consent”, and that you should “Keep a record when a person gives express consent, including who gave the consent, when and how.” It also states that under the Spam Act every commercial message must contain an unsubscribe option that honours a request within 5 working days and is functional for at least 30 days after the message is sent, and that even where someone else sends your marketing messages for you, you must still have consent from each person who will receive them.
On the ACMA’s reading, that consent obligation sits with the business whose marketing is sent, and it is not discharged by a vendor holding the evidence on your behalf. The same page also lists helping, encouraging or being knowingly concerned in a breach among the things that break the spam rules, so a vendor is not necessarily outside the frame either. Either way, the consent trail and the opt-out record are the artefacts you cannot leave behind.
Transcripts and recordings
Transcripts are the most under-valued asset here: the raw record of what your market objects to, in your buyers’ own words. Ask for full threads, both sides, timestamped. The common half-measure exports only inbound replies, which strips out what prompted them.
The prompt, the script and the config
Here reasonable people disagree, and buyers are sometimes unfair to vendors. A mature prompt library is real intellectual property: years of failed openers, patterns that surfaced only across many accounts, guardrails written after something went wrong. A vendor declining to hand over its whole framework is not automatically in bad faith — it is protecting what makes it worth hiring. Our page on cross-account learning covers how that layer is built.
The workable middle ground is a three-way split:
- Your data and outputs are yours. Records, transcripts, recordings, consent evidence, results.
- The vendor’s method is the vendor’s. Frameworks, libraries, internal tooling, models.
- Account-specific artefacts go to you. The scripts, qualification criteria and offer language deployed on your campaign describe your business, even if the machinery behind them stays.
A vendor refusing the third is telling you switching costs are its retention strategy. A buyer demanding the first two in full is asking a specialist to hand over its business.
Phone numbers, sender IDs and A2P registrations
Numbers can usually be ported, but not instantly and only while they are live. The ACMA’s guidance on porting your phone number states that porting a mobile number usually takes 3 hours, that telcos generally complete ports of individual local numbers within 8 to 15 days, and that more complex ports of more than one local number can take up to 30 days. It also states that only active numbers can be ported: a disconnected number goes into quarantine for 6 to 12 months and you no longer have rights to use it. So the clause that matters is not that the vendor will port — it is that they will not disconnect first.
Branded SMS identities attach to an account rather than to you. Under Australia’s SMS Sender ID Register, businesses register through a participating telco or message provider, and the ACMA’s guidance on registering a sender ID states that “You can only authorise telcos by registering your sender ID via that telco.” Change providers and you have to register again through the new one — see SMS sender ID registration in Australia.
The US equivalent is A2P 10DLC. Twilio’s A2P 10DLC documentation states that “Anyone sending SMS/MMS messages over a 10DLC number from an application to the US must register for A2P 10DLC”, with a brand and campaigns registered through its console or API. Where a vendor registered you as its customer under its own account, that vetting sits there — see A2P 10DLC registration for outbound SMS in the USA. Register in your own entity’s name where you can; where you cannot, treat re-registration as a real switching cost.
Integrations, mappings and the scoring model
The connector is generally the builder’s; the field mapping is the piece to claim in the contract, because it describes how your business records a lead. Same with the qualification model: you will not get the scoring implementation, but you should get the criteria in writing. Without them a new operator books a different kind of meeting and conversion moves for reasons nobody can explain.
What the instruments actually say
General information only, not legal advice, and not exhaustive. Confirm your own obligations with your adviser and against the current text of each instrument linked below.
Australia. Under the OAIC’s Australian Privacy Principles, APP 11 states that an APP entity “must take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure”, and that an entity has obligations to destroy or de-identify personal information in certain circumstances. APP 12 covers access requests by individuals and APP 13 covers correction — requests that can land on data your vendor holds and you cannot see.
Europe. Article 28(3)(g) of the GDPR requires the processor contract to provide that the processor, “at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data”.
United States. Several state privacy laws create analogous downstream duties. Under California Civil Code § 1798.105(c)(3), a service provider or contractor must cooperate with the business in responding to a verifiable consumer request “and at the direction of the business, shall delete, or enable the business to delete” personal information about the consumer. Write the process into the contract anyway — a statutory duty is not an export procedure.
Wider consent and record-keeping duties sit in our AI outbound compliance checklist; what enterprise security teams ask is answered in data privacy and AI sales agents.
Put this in the contract
Nine clauses. None are unusual, and a vendor acting in good faith will agree to most.
- Ownership split, explicit. Buyer owns data and outputs; vendor owns method; account artefacts named individually.
- Export scope. Contacts, enriched fields or their exclusions, transcripts, recordings, consent evidence, suppression list, activity history.
- Format. Machine-readable and re-importable. A PDF report is not an export.
- Clock. Days from termination notice, not “promptly”.
- Cost. Included, or a stated capped fee. Unpriced export work is where exits stall.
- Numbers. Porting cooperation, and no disconnection while a port is pending.
- Registrations. Who holds the sender ID or A2P brand and campaign, and what help you get.
- Deletion. What is destroyed or de-identified, on what schedule, with written confirmation.
- Survival. All of it survives termination, including for cause.
Test it cheaply: ask for a full export in month two, while everyone is friendly. If it arrives complete and on time, the clause is real. If it takes three weeks and arrives as screenshots, you have learned something at no cost — the logic behind designing a pilot that can fail.
Why this is not abstract
For some businesses the database is the business. In commercial real estate and mortgage broking — two categories we have worked in, with Colliers and with Sam Tajvidi at 121 Brokers — the contact history and the record of who said no, and when, is the accumulated asset. A campaign rebuilds in a month; ten years of opt-out evidence does not.
Across 50,769+ AI-booked sales appointments since 2017 and 1M+ leads generated, the pattern is consistent: buyers who handle vendor transitions well wrote the exit down at the start, when it was a conversation instead of a negotiation.
What we do on exit, plainly
Under our agreement, you own your data. Your contact records, conversation transcripts, call recordings and your suppression and consent evidence are yours, and you get them back in a standard, re-importable format when you leave. We own our method — our prompt library, frameworks and internal tooling stay with us.
That is the whole position. To test it against your procurement requirements, book a call and bring the clause list.
Frequently asked questions
Who owns the leads a lead generation agency generates for me?
Whatever your contract says. There is no default that hands generated leads to the buyer, so if the agreement is silent you are relying on goodwill and on who controls the system of record. Specify that contact records, conversation history and outcomes are your property, licensed to the vendor only to run your campaign, and exported to you on termination.
Can a vendor keep my data after the contract ends?
It depends on the contract and the jurisdiction. Under the GDPR, Article 28(3)(g) requires the processor agreement to provide that the processor, at the choice of the controller, deletes or returns all the personal data after the end of the provision of services, and deletes existing copies unless law requires storage. In Australia, APP 11 includes obligations to destroy or de-identify personal information in certain circumstances. You still need a written deletion schedule: the instrument sets the obligation, the contract sets the process.
Can I take my phone numbers with me?
Usually, if they are still active and the vendor cooperates. The ACMA says porting a mobile number usually takes 3 hours, individual local number ports generally complete within 8 to 15 days, and complex multi-number ports can take up to 30 days. Disconnected numbers cannot be ported and sit in quarantine for 6 to 12 months, so the contractual point is timing: no disconnection while a port is in progress.
What about my SMS sender ID or A2P 10DLC registration?
Those generally do not move with you. Australian sender IDs are registered through a participating telco or message provider, and the ACMA is explicit that you can only authorise telcos by registering your sender ID via that telco, so changing provider means re-registering. US A2P 10DLC brand and campaign registrations sit in the account that submitted them, often the vendor’s. Budget the lead time into any switch.
Is it unreasonable to ask for the vendor’s prompts and scripts?
Asking for the entire library usually is. That is the vendor’s accumulated method and often the reason it outperforms a tool you could buy yourself. Asking for the scripts, objection handling and qualification criteria used on your account is reasonable: those describe your offer and your buyers. Draw the line there and most vendors will agree.
See if we’re a fit
A few quick questions. If it’s a fit, our live calendar loads on the next screen. If it isn’t, we’ll point you to free resources instead β you won’t have to sit through a sales call to find out.
We get paid a performance fee equivalent to 10–20% of the sales we help you generate.
Are you OK with that?
If you’re not willing to pay 10–20% as a performance fee, are you happy to pay a $4,000+ per month retainer?
Check If You Qualify π
How many leads per month do you currently get?
What’s your current advertising spend or marketing budget (Meta, Google, SEO, etc.)?
What’s the average sale worth to you over that customer’s lifetime?
Given your business currently gets less than 10 leads per month, we’d need to do much more groundwork to set up end-to-end sales systems. Are you OK with a $2,000/mo retainer to do so? (no lock-in)
What’s your work email?
Hey! We might be able to add $100k+ / mo... Enter your email to choose a time!
We’re probably not the right fit — yet
Our model is pay-on-performance — we only win when you’re making sales, and it works best alongside an active marketing engine with advertising budget to get seen. Booking a call now would waste your time, and we’d rather be straight with you.
Grab the free stuff instead — it’s the same playbook we use:
Read the growth blog · Lead-gen FAQ
When the timing’s right, come back — the calendar will be waiting.
