TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 229 Case Study — Corporate

A vendor letter that backfired and cleared the way for an AI policy

A Windsor startup wanted staff using generative AI tools without leaking patient information. A pushy letter from the software vendor ended up making the case for them.

Corporate7 min readWindsor, OntarioBringing AI tools into the business
All Corporate case studies
ClientJacek, an anesthesiologist and startup co-founder, and Agnieszka, who owns a chain of clinics
The issueStaff were pasting scheduling and patient information into public AI chat tools with no policy governing what could go in
ServiceDrafted an acceptable use policy, audited the AI vendor contract, and used the vendor's own letter to renegotiate its terms
ResolutionClear win — the vendor backed down, the contract was renegotiated, and the company adopted a policy every employee could actually follow

The situation

The letter arrived on a Tuesday, addressed to Jacek and copied to Agnieszka. It came from the company behind the AI scheduling assistant their startup had licensed eight months earlier, and it opened by accusing the business of using the tool outside the scope of the agreement. It threatened to suspend access within ten days unless the company signed an amendment giving the vendor broader rights to retain and reuse any data passed through the assistant, including data drawn from the clinic chain that had signed on as an early customer.

Jacek still worked part time as an anesthesiologist, and had co-founded the startup with Dewi, an engineer who led the product team, building AI-assisted scheduling and documentation tools for clinics. Agnieszka owned a chain of clinics across the region and had become the startup's first paying customer, feeding it real appointment and intake data to refine the product. Between the two of them and the rest of the team, the company had grown to the point of managing revenue in the tens of millions across its clinic partnerships, and generative AI tools had crept into daily use well before anyone wrote down rules for them.

Staff drafted patient-facing messages with a public chatbot. Developers pasted error logs, sometimes containing real appointment details, into coding assistants to debug faster. Nobody had decided this was acceptable; it had simply happened, the way most technology adoption happens inside a fast-growing company, one convenient shortcut at a time. The startup had no acceptable use policy, no list of approved tools, and no clear line between what an employee could type into a public AI product and what needed to stay inside the company's own systems.

The vendor's letter forced the question that internal caution had been putting off. If a business partner was willing to threaten suspension over a dispute about data rights, the company needed to know exactly what data it was exposing, through which tools, and under what contractual terms — both with this vendor and with the AI products its own staff had adopted informally. The letter was aggressive, but it was also, as it turned out, a mistake the vendor would come to regret.

The complication

The vendor's letter rested on a claim that the startup had breached the licensing agreement by allowing a third party — the clinic chain — to use the assistant's outputs in ways the contract did not permit. On a first read this sounded serious. On a closer read of the actual contract, it fell apart. The agreement defined authorized use broadly enough to cover exactly what the clinics were doing, and nowhere did it grant the vendor the sweeping data retention rights the proposed amendment demanded.

The vendor had made an early tactical decision that turned out to hand the company its leverage. Rather than raising the data question through a negotiation, or simply proposing a paid upgrade tier that would have addressed its actual commercial interest, it sent a letter that mischaracterized the existing agreement and threatened suspension on a timeline designed to force a signature before anyone could review it carefully. That approach converted what might have been a reasonable request into something closer to coercion, and it left a paper trail showing the vendor knew, or should have known, that its claim of breach did not match the contract's actual terms.

Underneath the vendor dispute sat the real problem: even if the letter's legal claim failed, the underlying question it raised was legitimate. What was the startup actually doing with patient-adjacent data inside AI tools, and could it explain that clearly if a regulator, a clinic partner, or a future investor asked? The answer at that point was uncomfortable. Individual employees were making individual judgment calls about what felt safe to paste into a chatbot, with no consistency and no record of the decision being made responsibly.

Agnieszka's clinics operated under their own confidentiality obligations to patients, and her contract with the startup made her responsible for how her staff's data was handled downstream. If the vendor's overreach had gone unanswered, or if the underlying practice of ad hoc AI use had continued unaddressed, either problem could eventually have become the clinic chain's problem too, not just the startup's.

What we did

  1. Read the actual licensing agreement clause by clause before responding to the vendor, rather than reacting to the letter's framing or its ten-day deadline. This confirmed the authorized-use provision already covered the clinic chain's activity, which meant the vendor's central claim of breach had no basis in the contract as written, and it told us within a day that the company's negotiating position was genuinely strong rather than merely defensible.
  2. Sent a written response rejecting the breach claim and setting out, in plain terms tied to specific contract language, why the described use fell within the license the vendor itself had drafted. This put the vendor on notice that any suspension of service without cause would itself be a breach on its side, which shifted the practical risk of the dispute from the startup, which had done nothing wrong, back onto the vendor.
  3. Flagged the ten-day suspension threat as commercially coercive and noted that the company would treat any wrongful suspension as a serious interruption to services relied on by a client base of clinics, preserving the right to pursue the resulting losses. Naming the threat plainly, rather than simply complying with the deadline out of caution, changed the tone of the vendor's replies within days and signalled the company would not simply absorb pressure it had no obligation to accept.
  4. Used the dispute as the occasion to renegotiate the contract properly instead of simply defending the status quo, since the vendor's own conduct had opened the door to a fuller review of data rights on both sides that the company had not previously prioritized. Waiting for a calmer moment to revisit the contract might never have happened once the immediate pressure passed, so the dispute itself became the practical opportunity to fix terms that needed fixing regardless of who started the argument.
  5. Negotiated narrower, clearer data terms that gave the vendor a defined, limited right to use aggregated and de-identified data for product improvement, while confirming that identifiable patient or appointment data stayed under the startup's and the clinics' control at all times. Precision mattered here specifically because the original agreement's vague language was what had let the vendor claim broader rights in the first place, and vague terms tend to be read expansively by whichever side wants to.
  6. Drafted a company-wide acceptable use policy for AI tools separate from the vendor dispute, listing which AI products staff could use for which tasks, what categories of information could never be entered into a public tool, and where developers needed to route debugging work instead of pasting logs into external chat interfaces. The policy addressed a risk that existed independently of the vendor letter and would have remained even after that specific dispute was resolved, so it could not simply wait.
  7. Delivered a short training session with Dewi and the rest of the leadership team so managers could explain the policy to their staff in plain language, with concrete examples of what was and was not permitted, rather than handing employees a document nobody would read closely. A policy that only exists in a shared drive changes nothing about daily habits; training the people who would actually answer employees' questions gave the rules a real chance of being followed rather than ignored.
  8. Built a review point into future vendor contracts so any new AI tool the company adopted would have its data terms checked against the acceptable use policy before staff started relying on it, closing the same gap that had let this vendor's original agreement go unexamined for eight months. Catching a problematic data clause before signature is materially cheaper than renegotiating it later under the pressure of a threatened suspension, which is exactly what this review point is designed to prevent.

The outcome

The vendor withdrew the breach claim within two weeks of the response and agreed to the narrower data terms without further dispute. The suspension never happened, and the startup kept uninterrupted access to a tool its scheduling operations depended on. The renegotiated contract left the company in a stronger position than before the letter arrived, with data rights defined precisely enough that a similar dispute would be far harder to manufacture in future.

The acceptable use policy addressed the problem the letter had exposed but not caused. Staff now had a short, specific document telling them what could go into which tools, and the ambiguity that had let the practice drift for months was gone. Agnieszka's clinics received a copy of the policy as part of the ongoing relationship, which gave her something concrete to point to when her own staff asked what the startup was doing with their patients' information.

Nothing about this result depended on luck. The vendor's aggressive letter created an opening only because the underlying contract genuinely supported the company's position, and because the response was built on the contract's actual language rather than on indignation. Companies that adopt AI tools quickly and write the rules for them later are common; this one was fortunate that the gap got closed before it caused real harm, not after.

What you can learn from this

  • Read a demand letter against the actual contract before responding to its framing. A confident tone does not make a claim accurate, and the contract's language is what a dispute ultimately turns on.
  • An aggressive or premature legal threat from the other side can hand you leverage, but only if your own position is genuinely sound. Do not count on the other side's mistake to cover a weak underlying case.
  • If staff are already using AI tools informally, write the policy after the fact rather than pretending the gap does not exist. Catching up late is far better than never catching up.
  • Data rights clauses in software contracts deserve the same scrutiny as any other term. Broad, vague language about data use tends to favour whoever drafted the agreement, usually the vendor.
  • A policy only works if people can explain it in one sentence. Train the managers who will pass it on, not just the employees who will be expected to follow it.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →