Vendor Lock In: Five Design Choices That Trap You
Two hours. That is what an Airtable attachment download link is guaranteed to be worth: "we will ensure that download URLs stay active for at least 2 hours after receiving them." The same documentation says what that means for anyone exporting a base — "We recommend downloading any attachments from the links in the exported CSV file before those links expire" (Airtable attachment URL behavior, checked 20 August 2026).
There is nothing hostile in that decision. Permanent public URLs to customer files are a security problem, and expiring them is the obvious fix. But download the CSV on a Friday, plan to fetch the files on Monday, and that column is a list of dead addresses. The repair is another export, which requires an account that still works — which is exactly the thing you were in the middle of giving up.
Lock-in mostly looks like that. Not a clause, not a trap, just an ordinary engineering decision whose cost is paid by someone on their way out and therefore never shows up in the product's own feedback loop. Five of these compound. Below they get names, along with what detects each one while you are still choosing. No product is being scored here and the five are not a league table. The vendors named appear because each publishes the relevant behaviour in its own words at a URL you can open and check against the date on this page — which is close to the opposite of a recommendation, since a company that documents a hard limit plainly is easier to write about than one that documents nothing at all.
Choice one: the export is a feature, and features sit on tiers
Data goes in on any plan. Getting it back out at full fidelity frequently does not.
Notion's export help page is specific about where those lines fall. Switching on "Include subpages" when exporting a page as PDF is described as available if you are on a Business Plan or Enterprise Plan. A Form view of a database cannot be exported at all, and the page suggests exporting from Table view instead. And the answer it gives to a member who cannot find the export option in the menu is that on an Enterprise workspace, a workspace or teamspace owner may have switched on a Disable export setting under Settings, then Security (Notion, export your content, checked 20 August 2026).
That last one is worth sitting with, because the constraint is not the vendor at all — and it is not necessarily even at the top of your own organisation, since a teamspace owner can set it for a single teamspace. The export button can be absent for a reason nobody at the vendor can see and nobody at your own company remembers choosing.
The tier version of this shows up again in messaging tools, where which conversations you may export depends on the plan you are on rather than on who owns the messages; the detail for one product is in what a Slack export actually contains on each plan.
Ask: on the exact plan I am buying — not the one above it — what can I export, and can an admin setting take that away?
Choice two: shipping the picture instead of the wiring
The second pattern is a format question, and it is the one people misread most often, because a file did arrive and it did open.
Notion offers three export formats: PDF, HTML, and "Markdown & CSV". Under that third option the help page states that a full page database comes out as a CSV file, with Markdown files for the pages inside it. A CSV is defined by RFC 4180 as records and fields — no types, no schema, no way to express that one row points at a row in another table. So a relation between two tables can only arrive as text that happens to match a name. Rebuild from that file and you are re-deriving the links by string matching, hoping no two records were ever called the same thing.
PDF and HTML lose more, in a way that is easier to forgive because it looks so complete. They carry the rendering: the layout, the column order, the way it appeared on screen the day you pressed the button. What they cannot carry is the structure underneath, which is the part another system needs.
The question that separates these is narrow: which format preserves relations and field types? If there is a JSON or NDJSON path, the structure survives the move. If the answer is CSV, HTML and PDF, it does not, however complete the file looks when you open it.
Choice three: handing over addresses instead of bytes
Pattern three is the Airtable behaviour at the top, generalised: the export contains references to your files rather than the files. Two hours for Airtable attachment URLs. Notion's whole-workspace export arrives as an emailed download link that "will expire after 7 days." Slack's JSON export contains file links rather than files.
Different products, different windows, same shape — and the consequence is a hidden dependency between two tasks people naturally schedule apart. The export job and the file-retrieval job feel like separate items on a list. They are not. The second one has a timer that started when the first one finished, and every one of those timers is shorter than the gap between "we exported everything" and "we got round to checking it."
Which is why counting rows is not verification. Open three attachments from the export, at random, on a machine that is not signed in to the vendor. If they open, the bytes are yours. If a login screen appears, what you have is a bibliography.
Ask: does the export bundle contain the files themselves, and how long is any link inside it valid for?
Choice four: a logic layer nobody gave a file format
Records are the easy part. What takes months to rebuild is everything configured on top of them: automations, permission schemes, custom views, approval routing, notification rules.
Two published examples show how differently this gets handled inside the same broad category of product. Jira automation exports what Atlassian now calls flows to a JSON file, and that file can be imported into another Jira site — but the documentation attaches a condition to almost every part of that sentence. You must be a global administrator to run it in either direction. The JSON file must be 5MB or smaller. All imported flows arrive disabled and have to be enabled by hand. Import and export work only for one-to-one moves, not for consolidating several instances into one. And for a Server-to-Cloud migration Atlassian states there is "a strong chance" that data specific to your instance, such as statuses, issue types and custom fields, will not map correctly and those flows will need reconfiguring; Cloud-to-Cloud it describes as more likely to succeed, which is not the same thing as reliable (Atlassian, import and export Jira automation flows, checked 20 August 2026). HubSpot's workflow export produces something different in kind: a spreadsheet describing your workflows plus images of the individual workflows, and the documentation notes those exports do not include performance data or the workflow's history (HubSpot, export your content and data, checked 20 August 2026).
One of those is a definition that another instance of the same vendor's product can execute, under conditions. The other is a description of what you built, which a person reads. Neither carries your logic to a competitor — the JSON is a Jira file, useful between Jira sites and nowhere else — so this is not one vendor being more open than the other. What differs is what you are holding on day one of a rebuild: a file to correct, or a document to retype. Both are knowable before you commit.
Ask: if I export my automations and permissions, is the result executable, readable, or a picture?
Choice five: nobody owns the inventory, so you do
The fifth choice is the quietest, because it is an absence rather than a limit. There is no single button that produces everything, and no published list of what "everything" contains.
HubSpot's export documentation is organised the way most are: by category. CRM records, files, blog content, workflows, users, audit logs, account activity history — each a separate job you have to know to run. Nothing is hidden. But completeness depends entirely on you being able to enumerate every object type your account accumulated over four years, including the ones created by an integration nobody remembers installing.
This is where an exit gets expensive without anyone doing anything wrong. The forgotten object type is discovered three weeks after cancellation, by the person who needed it.
Worth putting in writing, then: is there one published list of every category of data my account holds? The next section is about the only place that question has been made compulsory to answer.
The regulation that turns choice five into a document
There is a legal instrument that speaks directly to several of these patterns, and it is useful as a source of vocabulary even where it does not bind your particular contract.
The EU Data Act — Regulation (EU) 2023/2854, which applies from 12 September 2025 — gives its Chapter VI to switching between data processing services. Article 23 says providers "shall not impose and shall remove pre-commercial, commercial, technical, contractual and organisational obstacles" that inhibit customers from, among other listed things, "porting the customer's exportable data and digital assets" to a different provider or to their own infrastructure.
Article 25(2) then lists what the contract has to contain, and four of its points land directly on the patterns above. Point (a) fixes a "mandatory maximum transitional period of 30 calendar days" for the switch itself. Point (d) sets a maximum notice period for initiating it "which shall not exceed two months". Point (g) requires "a minimum period for data retrieval of at least 30 calendar days" beginning after that transitional period ends. And point (e) — the direct answer to choice five — requires "an exhaustive specification of all categories of data and digital assets that can be ported during the switching process, including, at a minimum, all exportable data". Article 26(b) adds a reference to an up-to-date online register listing the data structures and formats in which that exportable data is available. Article 29 withdraws switching charges on a timetable: reduced charges permitted from 11 January 2024, and from 12 January 2027 none at all (Regulation (EU) 2023/2854, EUR-Lex, checked 20 August 2026).
Scope is where care is needed, and it pulls in both directions. Article 1(3)(f) applies the regulation to providers of data processing services "irrespective of their place of establishment, providing such services to customers in the Union", which reaches further than the location of your own company suggests. Pulling the other way is the definition. Article 2(8) describes a "data processing service" as a digital service enabling "ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources" — language written with cloud infrastructure in view, and considerably less obvious in its application to a seat-priced application that happens to run in a browser. Nothing above should be read as a claim that the specific products named are inside that definition, or that they are outside it. Where a particular product sits, and whether your own agreement is caught, is a determination for counsel with the contract in hand.
What survives regardless of jurisdiction is the shape of the questions. A vendor that publishes an exhaustive list of exportable categories and a register of formats has answered choices two, three and five in writing, and that page can be read before anything is signed — whether it exists because a regulation compelled it or because somebody decided it was decent practice. Where the equivalent language sits in a contract you have already signed is covered in reading a SaaS agreement for exit terms in fifteen minutes.
What to have in hand before the signature
None of this requires a trial account or a technical evaluation. Every one of the five has a documentary answer, and a vendor that cannot produce the document has told you something by failing to produce it.
One artefact is worth more than all the rest: a sample export file from a real account. Not the help page, not a screenshot of the export screen — the actual ZIP. Ten minutes inside it settles choices two and three together, because you can see for yourself whether the relations survived and whether the attachments are files or addresses. Most vendors will produce one during a sales conversation if asked directly, and the ones that will not have answered a slightly different question.
The rest is reading, and it is quick. The export help page for the exact tier being quoted, checked separately for whether an administrator toggle can take the capability away. The vendor's own documentation searched for automation export or rule export, which comes back as one of three things: an executable file, a readable spreadsheet, or silence. A written list of exportable categories, which for a provider serving EU customers may already exist as a published register. And the billing shape alongside all of it, because the cost of leaving is the export problem plus whatever the contract keeps you paying for regardless — the seat-count half of that arithmetic is in why your SaaS bill is higher than the pricing page says.
A tool that scores badly on all five can still be the right choice. Sometimes it is the only product that does the job, and the honest position is to buy it while knowing the exit will cost real money and real weeks. What the five questions buy is not avoidance. It is knowing the number before it is charged to you, at the one moment you still have the leverage of not having signed.
Verified against Airtable, Notion, Atlassian and HubSpot documentation, and against the text of Regulation (EU) 2023/2854 on EUR-Lex, on 20 August 2026. The attachment-URL window comes from Airtable's attachment URL behavior page; the formats, plan tiers and Disable export setting from Notion's export your content page; the flow-export conditions from Atlassian's import and export Jira automation flows; and the workflow-export contents from HubSpot's export your content and data. Every Article quoted here was read in the EUR-Lex text of the Data Act.
Help pages get rewritten without a changelog and capabilities move between plan tiers, so the date above is the shelf life of this page rather than decoration — the tier named in a claim is part of the claim, and a limit quoted from a Business plan page says nothing about Enterprise. Four vendors are named for one reason throughout: each publishes the behaviour described in its own words at a stable URL. A vendor absent from this page has not thereby passed anything, and a vendor quoted here is not being marked down for being quotable. None of this is legal advice on a specific agreement. Corrections go through the contact page, and a corrected claim is re-read against its source before the verification date moves.
Frequently asked questions
Is vendor lock-in something vendors do deliberately?
Usually it does not need to be. Every pattern described here has a straightforward justification: expiring attachment links reduce the risk of a sensitive file being reachable by anyone holding an old URL, CSV exists because everything can open it, and gating a full-workspace export behind an administrator role stops one departing employee walking out with the company. Each decision is defensible alone. The cost only appears when five of them stack, and it lands on the customer rather than on the vendor, so nothing in the product's own feedback loop ever surfaces it.
Does the EU Data Act mean my vendor has to let me leave for free?
Article 29 of Regulation (EU) 2023/2854 states that from 12 January 2027 providers of data processing services 'shall not impose any switching charges on the customer for the switching process', with reduced charges permitted in the window from 11 January 2024 until that date. Two limits matter before you rely on it: Article 29(4) refers to standard service fees and early termination penalties as separate things from switching charges, and the duty attaches to a 'data processing service', which Article 2(8) defines as a digital service enabling 'ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources'. That wording was drafted with cloud infrastructure in view, and how far it reaches toward an ordinary seat-priced application is not a question this page can settle for any particular product. Put it to counsel rather than inferring it.
What is the single most useful question to ask before signing?
Ask the vendor to name the format their export produces and send you a sample file from a real account. Not a screenshot of the export screen, not a help-centre page: an actual file. The gap between 'yes, we have a full export' and a ZIP containing three CSVs and a folder of links is where most of the surprise lives, and a sample answers it in ten minutes. Article 26(b) of the Data Act pushes in the same direction by requiring providers in scope to point customers at an up-to-date register of the data structures and formats in which exportable data is available.
If a tool has an API, am I safe?
Partly. An API usually solves fidelity, in that you can read fields the screen export flattens, but it does not solve rate limits, pagination cost, attachment retrieval, or the fact that a token belonging to a cancelled account stops working at the same moment the account does. Treat an API as a way to get a better copy while you still have a live login, not as a reason to postpone the export until after the cancellation goes through.