Paying for it does not automatically make it yours
In many jurisdictions, including the UK, copyright in commissioned software can rest with the person who wrote it unless there is a written assignment. Businesses are frequently surprised by this, usually at the worst possible moment.
It rarely becomes a problem while the relationship is good. It becomes a serious problem when you want to change supplier, sell the business, or take the work in-house.
The four things to hold in your own name
- The domain. Registered to your company, with your billing details and access. Domains held by an agency are a recurring cause of avoidable crises.
- Hosting and infrastructure. Your account, your card, with the supplier added as a user you can remove.
- Third-party services — payment provider, email, analytics, model APIs. All in your name.
- The code repository. Your organisation, with the supplier invited. Not the other way round.
The test: if the relationship ended acrimoniously tomorrow, could you continue operating? If the answer requires anyone's cooperation, fix it now while everyone is friendly.
What the contract needs to say
- Assignment of all IP in the deliverables to you on payment, in writing
- A licence for any pre-existing supplier components you will need, and what it permits
- Clarity on open-source components and their licences
- Handover obligations: documentation, credentials, a walkthrough
- What happens on termination, including access to the current state of the work
Open source is fine, unexamined licences are not
Practically all software includes open-source components and that is entirely normal. What matters is that the licences are compatible with what you intend to do, particularly if you will distribute the software or build a product on it.
Ask for a list of dependencies and their licences at handover. It costs a supplier minutes to produce and it is expensive to reconstruct later.
Handover is a deliverable, not a favour
A proper handover includes credentials, documentation of how it is deployed, an explanation of the architecture, and a recorded walkthrough. Specify it as a milestone with payment attached, because a handover requested after the final invoice is a handover that competes with the supplier's next project.
A useful acceptance test: can a competent developer who has never seen the system deploy it from the documentation alone?
If you are already in this position
Do not panic and do not start with a legal letter. Most suppliers will cooperate with a reasonable request to transfer accounts and sign an assignment, particularly if you are still a client.
Ask politely, in writing, with a specific list. Escalate only if you get resistance — and if you do get resistance, that itself tells you the relationship needs to change.