Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

United States software delivery: write the IP, privacy and overnight acceptance terms first

A US company buying software from a remote team should settle three things before the build: a written assignment of the intellectual property, privacy terms that make the supplier a service provider under laws such as the CCPA, and an acceptance rhythm that uses the time difference instead of fighting it. Everything else in the proposal depends on those terms.

Submit a project Explore custom engineering

Reviewed by David Nguyen (CEO) · Updated 28 Sep 2026 · 10 min read

star

OutsourcingVN is operated by Netbase JSC, so this guide is written by a supplier that sells to US buyers. It draws on a long-running engagement for a US software company and on official US references your counsel should read. The guides index lists the other market guides.

Contents

What changes when a US buyer works with a remote team?

The engineering is the same as for any market. The contract, the privacy terms and the calendar are what a US buyer needs to get right.

  • Ownership does not transfer by default. The US Copyright Office's circular on works made for hire explains that software commissioned from an independent contractor generally does not qualify as a work made for hire, and that a written agreement or assignment is what moves ownership. Without one, the author may keep the copyright.
  • Privacy law is set largely by states. The California Attorney General's CCPA page lists consumer rights to know, delete, correct and opt out of the sale or sharing of personal information, and notes that consumers send requests to the business, not to its service providers. Your supplier's job is to make those requests easy to carry out.
  • The overlap is short. In US daylight time, 8:00 in New York is 19:00 in Hanoi and 8:00 in San Francisco is 22:00. A late-afternoon Pacific call lands in the Hanoi early morning. Plan a short daily overlap and let the remaining hours run in sequence.

Netbase clients are in the United States, Europe and Asia-Pacific, and most projects come from clients outside Vietnam, so the contract terms below are routine rather than exceptional.

What does a long-running US engagement look like?

The closest published example is a multi-tenant cloud ERP delivered as SaaS for a US software company, which is not named. Since 2020 Netbase has worked as its offshore development and managing partner. Phase one ran from 2020 to 2023 for agency SMEs and covers CRM, real-time messaging, HR, a knowledge base, custom fields and workflows, work and project management and API integrations. The multi-tenant cloud ERP SaaS record describes the scope and stack.

Two lessons carry over. First, a US product company keeps ownership of its roadmap and product decisions while the remote partner manages delivery, so decision rights belong in the contract. Second, a multi-year engagement outlives any single statement of work: IP assignment, access and handover terms must cover every module, not only the first release.

Netbase has also delivered product personalisation on client print stores for print-commerce clients in several countries, the United States among them. That list describes a delivery footprint, not a local presence.

Which contract terms matter most?

Read this table with your counsel. It lists what to write down, not legal advice on how to word it.

Term What to write down Why it matters to a US buyer Netbase's registered position
IP assignment An express assignment of custom code, designs and documents on payment, and a list of pre-existing components Commissioned software is not automatically yours For custom development the client owns the IP created for it; Netbase productized modules and products are licensed, not transferred
Privacy role The supplier acts only on your instructions, does not sell or share personal information and helps you answer consumer requests Keeps the supplier inside a service-provider role Netbase's compliance practices are GDPR alignment for data privacy in Europe, HIPAA-aligned methodologies for healthcare data handling, and CCPA compliance for clients with U.S. customer bases
Security controls Named controls, access for named people, and incident notice times Your customers and insurers will ask Security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request
Contract shape Fixed scope after discovery, or milestones with acceptance at each Decides who carries the risk of changing requirements Covered in the fixed-scope versus milestone contracts guide
Exit Repository, credentials, documentation and a transition period Protects you if the relationship ends Covered in the handover and exit guide

The CCPA wording above is Netbase's practice for clients with US customers. It is not a certification and does not make your organisation compliant; your own obligations stay with your counsel. The IP ownership guide goes deeper on assignment clauses and open-source components.

How do you set up an overnight acceptance rhythm?

An 11- to 15-hour gap between Hanoi and the mainland United States can shorten feedback loops if hand-offs are written well.

  1. Fix one overlap slot

    Choose a daily or three-times-weekly 30-minute call in the US morning or late afternoon, with a named decision-maker present.

  2. End each US day with written acceptance notes

    Log defects and questions with steps to reproduce, the expected result and the priority, so the team can act without waiting for a call.

  3. Deliver a build before the US morning

    The team fixes and deploys to staging during its day, with release notes stating what changed and what to retest.

  4. Keep an escalation path for blockers

    Agree who can be reached outside the overlap for a production incident, and how quickly.

  5. Accept by increment

    Sign off each increment against written criteria rather than saving acceptance for the end, so disagreements surface while they are cheap.

The time-zone collaboration guide covers overlap windows in more detail, including daylight-saving changes.

Worked scenario: a deletion request in a multi-tenant product

A US SaaS company sells to agencies, some with California customers. An agency's end customer asks for their personal information to be deleted.

The request reaches the SaaS company, which is the business under the law. Its support lead logs it and asks engineering to find every place the person's data sits: the CRM record, message history, uploaded files, backups and any analytics exports.

Because the scope included a deletion procedure from the start, the remote team has already built an administrator action that deletes or anonymises one person's records across modules, writes an audit entry and excludes the record from future exports. Backups follow the documented retention rule. The support lead confirms completion to the customer within the timeframe counsel set. No remote developer needed to browse production data to carry it out; the action was tested in staging with synthetic records during acceptance.

Where that procedure is missing, the same request becomes an emergency ticket that someone has to work through by hand, overnight, in a database.

Which questions should you ask a supplier?

  • IP. Will you sign an express assignment of custom work, and which pre-existing components would you license instead?
  • Privacy role. How do you support access, deletion and correction requests, and who on your team can see production personal data?
  • Rhythm. Which overlap slot do you propose for our time zone, and what do we receive in writing at the end of each of your days?
  • Continuity. If the engagement runs for years, how are new modules brought under the same IP, security and handover terms?
  • Evidence. Which company-level statements can you put in writing, and which controls will we test ourselves during acceptance?

What usually goes wrong?

  • No written assignment. Signal: diligence for a funding round or acquisition finds that the code's ownership is unclear. Owner: the buyer's counsel.
  • Consumer requests handled by hand. Signal: deletion or access requests pile up as support tickets. Owner: the product owner, who should put a request procedure in scope.
  • Calls used for everything. Signal: decisions wait a day for the next meeting. Owner: the buyer's product lead, who should decide in writing between calls.
  • Acceptance saved for the end. Signal: a long list of disputed items in the final weeks. Owner: both sides, through increment sign-off.

How this guide is sourced and where it stops

This guide uses the California Attorney General's CCPA page and the US Copyright Office circular on works made for hire, both accessed on 2026-09-29, together with Netbase delivery records and company statements approved in the OutsourcingVN claim register. It is written for founders, technology leaders and procurement leads preparing a US brief. It does not decide which federal or state laws apply to you; your counsel does. Netbase JSC's head office is in Hanoi, Vietnam, and it is the company's only office, so US projects are delivered remotely, and Netbase delivery communication is in English.

Plan the next step for your project

Common questions

It depends on your revenue, how many California residents' records you handle and how much of your revenue comes from selling personal information; the Attorney General's page sets out the thresholds. Other states have their own privacy laws, so ask counsel which apply and write the answer into the scope.

Whoever the contract says, which is why the assignment clause matters. For custom development the client owns the IP created for it, and pre-existing productized modules are licensed. Ask for both positions in writing before the first line of code.

Yes, with a short fixed overlap and written hand-offs. When defects are logged clearly in the US afternoon, the team can fix them and deploy to staging before the next US morning, so each review cycle takes one night instead of waiting for a meeting.

The supplier's written controls, an access matrix for your project, a data processing agreement and the results of the security tests you run during acceptance. Company-level statements describe the supplier, not the product it builds for you. The data security and compliance guide lists the controls worth requesting.

Fixed scope fits when discovery has produced agreed requirements with acceptance criteria; milestones fit when later stages depend on what early stages reveal. The UK guide shows how assurance packs work in another jurisdiction, and the Singapore guide how phases split a long redevelopment.

Plan the first release

Bring your draft contract terms, the personal data the product will hold, your preferred overlap slot and the names of your product, security and legal owners. Custom Product Engineering is the service for a bounded build, global delivery explains how remote delivery is organised, and the methodology explains how this page's statements are recorded. OutsourcingVN is Netbase's own outsourcing-services platform: submit a project with your US time zone and first milestone, and a person will reply with a proposed overlap slot and the discovery questions to settle.

Custom product engineering for a bounded release outcome Custom product engineering for a bounded release outcome

One defined release of your product, built to named outcomes and handed over with acceptance evidence.

Learn More
line

Tell us what you want to build or automate.

Submit a project