Nobody picks bad software on purpose. It gets chosen in a hurry, usually because the old way had just fallen over, and it works. Three years later the business runs on it: every customer, every job, every quote, every note about who wanted what and when. Then the renewal comes through with a price rise, or a better product appears, or the supplier is acquired and the roadmap turns into something you did not sign up for — and you discover that the decision you thought you were making annually was actually made once, in a hurry, three years ago.

This is vendor lock-in, and it is not really a technology problem. It is a commercial one.

Lock-in is not the contract

Owners tend to look at the notice period. That is almost never the binding part. A twelve-month term with three months' notice is an inconvenience. What actually holds you in place is the distance between the data being in there and the data being usefully somewhere else.

That distance hides in four places, and only the first is obvious.

The export itself. Most tools have a download button. What comes out is very often the current state — a list of customers as they stand today — and not the history. The quotes you did not win, the notes on why a job was priced the way it was, the timeline of who said what: all of it lives in the interface and none of it appears in the file.

The attachments. Photographs of completed work, signed job sheets, PDFs of quotes, uploaded certificates. These usually sit in the supplier's storage, referenced by an internal identifier. A spreadsheet export gives you the reference and not the file, which means the export is technically complete and practically useless.

The relationships between records. A flat file tells you that a customer exists and that an invoice exists. It frequently does not tell you which job that invoice belonged to, or which of six site addresses the work was done at. Rebuilding those links by hand is where migrations actually go wrong.

Everything built on top. Your accountant's process, the automation that posts new enquiries into a spreadsheet, the booking link on your website, the way your team has learned to do things. None of that is data. All of it has to be rebuilt.

What leaving actually costs

Illustrative figures, but they are the ordinary shape of it. A twelve-person firm pays £89 a month for the system that holds its customer and job records — £1,068 a year, entirely reasonable, nobody has ever questioned it.

Moving is quoted at £2,400 by the new supplier for a managed migration. Beyond that, someone internally spends around 40 hours checking, re-keying and reconnecting the things the migration could not carry, which at a fully loaded internal cost of £25 an hour is another £1,000. Both systems run in parallel for six weeks so nothing is lost, adding roughly £130. Call it £3,500 to escape a £1,068-a-year subscription, plus the disruption, plus the errors nobody finds until November.

That is why people stay. And it is why the renewal letter is written the way it is.

A subscription price tells you what the software costs. The export button tells you what it will cost to stop.

A supplier that knows leaving costs you £3,500 has enormous room to raise the price and still be the rational choice. Put the annual fee up by £500 and staying is obviously cheaper for at least seven years. That is not a conspiracy; it is just what pricing power looks like when switching costs are high. The same dynamic runs through the subscription trap that quietly kills small business margins and through the equipment lease that renewed itself for another three years. Different products, identical mechanism: a decision that was never scheduled to be reviewed.

The five questions to ask before you sign

All of these are answerable in a fifteen-minute call, and a supplier who is cagey about any of them has told you something useful.

Can I export every record type, including history and attachments, in a documented format, myself, without raising a support ticket? Note the parts of that sentence people skip.

Is there an API, and is it included in the plan I am actually on rather than the enterprise tier? An interface you can pull structured history from is worth considerably more than a one-off download.

What happens to my data if I stop paying? There is a large difference between a read-only period of several months and a thirty-day deletion timetable, and it is written down somewhere.

Does the contract say the data is mine? Most reputable suppliers say so plainly. The ones that do not are worth a second read.

Can my accountant or bookkeeper get their own access without paying for a full seat? A tool that forces everything through you becomes a bottleneck long before it becomes a lock-in problem.

Then do the thing almost nobody does: run a full export during the free trial. Not in month thirty when you are annoyed — on day two, while the supplier still wants your business. If the export is a mess while they are trying to win you, it will not be better later.

If you are already in

Most businesses reading this are past the point of asking questions, and there is still a lot you can do.

Export monthly to storage you control, and keep the last twelve. It costs nothing, and it converts a total dependency into a partial one. Keep the genuinely critical lists — customers, prices, supplier terms — maintained somewhere outside the tool as well, even if that is only a spreadsheet you update quarterly. It feels like duplication right up until the week you need it.

Time any move to a natural break rather than a moment of anger: a year end, a quiet quarter, the point where you were going to review processes anyway. And when the renewal arrives, do the work of getting one genuine alternative quoted. You may not move. But a supplier who knows you have looked prices differently from a supplier who knows you have not.

Tier your dependency

The answer is not to avoid software, which would be absurd, nor to run everything on things you host yourself, which is a job you do not want. It is to be deliberate about which systems you would struggle to survive losing.

Systems of record — accounting, the customer list, payroll, anything holding an obligation to a person — need the export tested and the questions asked. Systems of convenience, like a design tool or a scheduling app, matter far less; if one disappeared tomorrow you would be irritated for an afternoon.

Most small businesses hold three or four systems of record and about twenty of convenience, and they apply exactly the same amount of diligence to both, which is usually none. Spending an hour on the three that matter is the whole of the fix. While you are in there, it is also the natural moment to sort the data protection job everyone puts off, because the two questions — what data do we hold, and where does it actually live — are the same question.

Common questions

Do I legally own the data I put into a supplier's software?

Your right to it comes from the contract, not from data protection law, and that is a distinction worth understanding. UK GDPR gives individuals a right to portability of their own personal data; it does not give your business a general right to extract its records from a supplier. What governs that is the service agreement, which is why the ownership clause and the termination clause are the two paragraphs worth reading properly. Reputable suppliers state plainly that the customer owns its data and set out what happens on termination. Where a contract is silent or vague on both points, treat that as a commercial risk rather than a legal technicality.

What should I actually do with an export once I have one?

Store it somewhere you control that is not the same system, and check it opens. An export nobody has ever opened is a comfort blanket rather than a backup, and the moment you discover the attachments are missing should not be the moment you need them. Keep a rolling set — twelve monthly files is plenty for most small businesses — so you can go back if something was deleted or corrupted months ago without anyone noticing. Do not email them to yourself. Put them in the same storage you would use for accounting records, with the same access controls, because they contain the same kind of personal data.

Is having an API always better than a download button?

Usually, but not automatically. An API lets you pull data on a schedule, including history and relationships, which is exactly the material a flat export tends to lose. That makes it more valuable in principle. In practice it only helps if it is included in your plan, documented well enough that an ordinary developer can use it in a day, and covers the record types you care about rather than just the tidy ones. Plenty of small business tools advertise an API that turns out to be read-only for two entities. Ask which records it covers and whether attachments are included before treating it as an escape route.

Can a supplier delete my data if I stop paying?

Yes, and many will after a stated period, which is why the termination clause matters more than the notice period. A common arrangement is a read-only or reactivation window of thirty to ninety days after the subscription lapses, followed by deletion. Some suppliers charge for a final data extract once the account is closed, which is a fee you can negotiate away at signing far more easily than at exit. The practical rule is to run your final full export before you cancel, not after, and to confirm in writing what the deletion timetable is so the date is not a surprise.