Guide · Ownership
Who owns the code of your application?
Paying for an application is not enough to own it. In Canada, the copyright in a program belongs first to whoever writes it; a business gets it automatically only when the code is written by its employees. With a firm or a freelancer, you need a written, signed assignment. This guide explains the rule, then what a small business should require in its contract: the code, the data, the accounts and the domain name.
In short
- A computer program is protected by copyright, just like a book.
- The author is the first owner of the copyright. An employer is for its employees’ work; the client of an independent vendor is not.
- An assignment of copyright is valid only if it is in writing and signed.
- Beyond the code, require the data, the access, the hosting accounts and the domain name in your name.
- This guide explains the rules; for your contract, consult a lawyer.
What does the law say about an application’s code?
Under the Copyright Act, a computer program is a set of instructions meant to be used in a computer, and it is treated as a literary work. The code of your application is therefore protected like a text.
The starting rule is simple: the author of a work is the first owner of the copyright (s. 13(1)). There is one exception: when the author is employed under a contract of service and the work is made in the course of that employment, the employer is the first owner, in the absence of any agreement to the contrary (s. 13(3)).
A development firm or a freelancer is not your employee. In Quebec, the Civil Code calls this relationship a contract of enterprise or for services, in which no relationship of subordination exists between the provider and the client (arts. 2098 and 2099). Our reading of these rules: without a written assignment, the copyright in the code stays with the vendor, even if you paid for the whole project.
Assignment or licence: what is the difference?
The Canadian Intellectual Property Office distinguishes two things. An assignment transfers all or part of your rights to another person. A licence only allows another person to use the work under certain conditions; the owner keeps ownership and their rights.
| Assignment of copyright | Licence to use | |
|---|---|---|
| Owner of the code | Your business | The vendor |
| Change it or have it changed | Yes, by whoever you want | Depending on the licence terms |
| Switch vendors | Yes | Only if the licence allows it |
| Sell the business with the tool | Yes | Depending on the licence terms |
| Required form | In writing and signed by the owner | Depending on the contract |
The law is clear about the form: an assignment is valid only if it is in writing and signed by the owner of the right or by the owner’s duly authorized agent (s. 13(4)). A handshake, a paid invoice or a vague email is not enough.
Then there are moral rights, which protect the integrity of the work and its connection to its author. They can’t be assigned, but the author can waive them in whole or in part, and an assignment of copyright does not by itself waive them (s. 14.1). A complete contract therefore provides for both: the assignment and the waiver.
What should you require in the contract?
- A written assignment of copyright in the code developed for you, on delivery or on payment, along with a waiver of moral rights.
- Access to the source code in a repository (GitHub, GitLab or another) in your business’s name, not just a copy at the end.
- Hosting, database and external service accounts opened in your name, or transferable on request.
- The documentation another vendor would need to take over the work.
- The list of third-party components and their licences.
- The exit terms: timelines, the format in which data is handed over, help with the transition.
An honest clarification: almost every application uses open source components, released under licences that let you use, modify and share them according to their terms. These components don’t belong to you, and that is not a problem; what matters is that their licences allow your use, and that the code written for you is assigned to you. Some licences, called “copyleft”, require modified versions to remain open: your vendor needs to know which ones they are using.
A vendor normally keeps its know-how and its general tools; what should come to you is the application delivered. The line between the two is set out in the proposal. If it stays vague, ask for it to be written down.
What about your data?
The data your teams and your customers enter into the application belongs to you; the contract should say so and set out how you get it back, in what format and within what time. When it contains personal information, Quebec law adds specific obligations. The same question comes up with subscription software, whose code always stays with the vendor: our guide custom application or SaaS software compares the two options.
- Any project to develop or overhaul an information system involving personal information requires a privacy impact assessment, and the system must allow that information to be communicated in a structured, commonly used technological format (s. 3.3).
- Entrusting this information to a vendor requires a written contract that specifies the protection measures, use limited to the contract and destruction at the end (s. 18.3).
- Hosting it or entrusting it outside Quebec requires, before it is communicated, a privacy impact assessment and a written agreement (s. 17).
These obligations remain yours, even when a vendor hosts or processes the data for you: the business that operates the application is accountable for them, and the contract must govern what the vendor does. Choosing where the application will be hosted is part of the contract, not a technical detail to settle later.
The domain name and the accounts
For a .ca domain name, the Canadian Internet Registration Authority (CIRA) speaks of a “registrant”, not an owner: its agreement states that registration creates no property right. What matters in practice is that the listed registrant is the person who can request renewals, transfers and changes. If your vendor registered the domain in its own name, it is the one in control.
How we work
At Kasvu, the application delivered and paid for belongs to the client: the code, the data and the access. The client can do whatever they want with it, with no licence to renew. Documentation and hosting are part of the engagement so the application can evolve with or without us. It is written into our terms of use (section 7) and detailed in each engagement agreement, because a verbal promise is worth nothing under section 13(4).
Whatever vendor you choose, raise the ownership question before you talk price. It is part of the real cost of a project, as our guide on the cost of a custom application explains.
This guide presents general rules and does not replace legal advice. For a specific contract, consult a lawyer.
Before you sign
Let’s talk about your project, and who will own it.
We show you what our proposal provides for the code, the data and the access, and what you should require from any vendor. See our approach to custom applications. The first conversation with François comes with no commitment.
Book a call with FrançoisSources
- Copyright Act (R.S.C. 1985, c. C-42), ss. 2, 13 and 14.1 · updated to September 21, 2026
- Canadian Intellectual Property Office, A guide to copyright · consulted October 7, 2026
- Canadian Intellectual Property Office, assignment and licensing of copyright · consulted October 7, 2026
- Civil Code of Québec, arts. 2085, 2098 and 2099 (LégisQuébec) · updated to August 12, 2026
- Act respecting the protection of personal information in the private sector, ss. 3.3, 17 and 18.3 (LégisQuébec) · updated to August 12, 2026
- CIRA, Registrant Agreement, version 2.3 (s. 3.2) · version 2.2
- Open Source Initiative, open source licences · consulted October 7, 2026
- GNU, “What is Copyleft?” · consulted October 7, 2026
