IP and trademarks

Startup IP due diligence: can you prove who owns the product?

Paying for code or receiving the files does not always transfer the rights. Build a clear chain of title for contractors, founder libraries, AI-assisted assets and the company's product.

Maciej Lis Maciej Lis Polish attorney-at-law (radca prawny) 01 October 2026 9 min
StartupsIPCopyrightDue diligenceSoftware developmentAI governanceIT contractsInvestmentOpen source

Adapted from the Polish article, originally published on 07 July 2026. The English version was published on 01 October 2026.

The product was built by your team, so the founders assume the company owns it. An investor or enterprise customer then asks who wrote the code, who designed the interface and where the rights were transferred.

The demo works. The contracts do not explain the ownership nearly as well.

Due diligence needs evidence of who created the product, on what terms and which rights the company holds. That chain of title matters to investors and customers across markets. Assignment formalities and the rights acquired depend on the applicable law; the formal requirements explained below are those of Polish copyright law.

What you will learn

  • Why product ownership needs a documented chain of title.
  • What an investor or enterprise customer is likely to ask for.
  • Why paying a contractor does not automatically transfer copyright.
  • What written form and fields of exploitation mean under Polish law.
  • How to separate new product IP, existing libraries, open source and AI-assisted work.
  • What to review before investment or enterprise sales.

In brief

  • A working product can contain rights held by several people or businesses.
  • Delivering files, granting a licence and assigning economic copyright are different acts.
  • A Polish-law copyright assignment requires the prescribed written form to be valid.
  • Define the work, permitted uses, transfer timing and rights needed for further development.
  • Record third-party components, tool accounts and AI use alongside the contracts.

The product includes more than the source code

An MVP often combines a founder’s work, a freelancer’s design, a development company’s code, open-source libraries, AI-assisted materials and components from earlier projects. That can be an effective way to launch. It also creates several ownership questions.

Start with an inventory of the assets: source and object code, documentation, UI and UX, graphics, branding, domains, datasets, configurations and marketing materials. They do not necessarily share one legal treatment, and not every technical item is automatically a copyright work.

The question is whether the company has the rights and access needed for the way it intends to use each asset. It may own some outright, license others and depend on third-party terms for the rest.

What does an IP review uncover?

Typical gaps include:

  • Code created by a contractor without an effective assignment.
  • A designer paid by invoice but no signed transfer agreement.
  • A development contract handing over code without rights broad enough for commercialisation.
  • A clause saying “all rights transfer” without identifying the relevant uses.
  • Product design stored in a founder’s private tool account.
  • Repositories combining product code with a founder’s reusable libraries.
  • Domains registered personally and unclear control of the brand.
  • Unrecorded open-source licences, third-party assets or AI-assisted work.

An investor wants to know whether the asset being financed is genuinely available to the company. An enterprise customer may need assurance that the supplier can license it, maintain it and honour its IP commitments.

Uncertainty can lead to a lower valuation, additional warranties, a condition to repair the documentation, delayed closing or a lost transaction. The term sheet may make those repairs a condition of investment.

Paying the invoice is not the same as acquiring the rights

Distinguish five things: commissioning work, receiving a file, paying for it, obtaining a licence and acquiring economic copyright. They can happen together, but one does not automatically establish all the others.

The company may have paid for code and received the repository while holding only limited permission to use it. A licence adequate for an MVP may not cover later sublicensing, white-label deployment or a sale of the product. The actual agreement and applicable rules determine the position.

Employment and contractor relationships also need to be assessed separately. Polish law has particular rules for employee-created works and computer programs. Do not apply an assumption about employment automatically to a freelance or business-to-business developer.

Why written form matters in Poland

Article 53 of the Polish Copyright Act requires written form for an agreement transferring economic copyright, on pain of invalidity. Evidence that the parties worked together is not necessarily evidence of a valid assignment.

An email exchange, messenger approval, invoice, payment, delivered files or a repository comment can help prove the commission and payment. They do not by themselves establish that the required assignment form was met. For electronic signing, check whether the chosen signature satisfies that form; a generic click-to-accept process should not be assumed equivalent.

If the company needs an assignment from a contractor, secure the correctly executed agreement. If it needs a licence instead, define its scope and check any form requirements for that licence. Do not treat those two routes as interchangeable.

The invoice answers a payment question. The assignment or licence must answer the ownership and use questions.

What work and uses does the agreement cover?

Identify the works or deliverables with enough precision to connect them to the actual project: modules, versions, designs, documents, graphics or other outputs. For work delivered in stages, the schedule or acceptance record can make that link easier to demonstrate.

Under Polish law, an assignment or licence covers the fields of exploitation expressly listed in it. These are the specified ways of using the work, rather than a general promise that “everything belongs to the customer”. Computer programs have their own statutory framework, so use clauses suited to software as well as the other assets.

For a digital business, assess the rights needed to reproduce, distribute, host, make available, modify and integrate the relevant work. Also consider customer deployments, SaaS delivery, development versions, white-label arrangements and marketing uses. The drafting should reflect the asset and business model, rather than apply the same list to a logo, software and documentation.

When do the rights transfer?

The agreement should identify the transfer event. It might be payment, acceptance, a signed acceptance record, delivery of a specified output or another agreed mechanism.

This matters in sprint-based or phased development. The startup needs to know whether it obtains the rights after each paid stage, after acceptance or only at the end of the entire project. The company may already be using work commercially while the contractual transfer event has not occurred.

Keep acceptance records and payment evidence where they can be matched to the relevant deliverables. A signed framework contract is useful, but it may not establish that every later module has passed through its transfer process.

Can the company modify, license and transfer the product?

Further development needs permission appropriate to the work and intended changes, including adaptation rights where relevant. Check the ability to refactor, integrate, fork, create enterprise versions and approve modifications by other suppliers.

The company should also understand its ability to grant licences or sublicences, move rights within a group, contribute them to a company or sell the product. Rights already owned and rights held under a licence need separate treatment. A restriction in an upstream licence can affect what the startup may promise downstream.

Under Polish law, economic copyright is distinct from the author’s moral rights. An “all rights” formula does not remove the need to assess the applicable rules and permissions.

Separate pre-existing IP from new product work

A founder or supplier may bring libraries, frameworks, templates, snippets and know-how used across several projects. Not everything in the repository needs to become exclusively owned by the startup.

Identify:

  • IP created specifically for the product.
  • Pre-existing founder or contractor components.
  • Open-source components and their licences.
  • Third-party tools and assets.
  • Know-how and materials retained by the supplier.
  • Components licensed to the startup rather than assigned.

This protects both sides. The company can show what it owns and what it may use, while the supplier avoids unintentionally giving away reusable components. Record dependencies and licence conditions so that future distribution or deployment does not rely on memory.

Record AI-assisted assets and permitted tool use

AI tools may contribute code, graphics, text, documentation, test data or configurations. An assurance that the vendor permits commercial use does not settle every ownership or infringement question about the output.

Agree which tools may be used, whether customer data or code can be entered, who reviews the result and where use is recorded. Identify whether generated materials enter the shipped product or only assist the work. Check the relevant tool terms and the rights position for the actual material rather than promise exclusive copyright indiscriminately.

For tools processing personal or confidential data, ownership is one part of the assessment. Our AI vendor and GDPR checklist covers the data flows, contract and exit questions.

Copyright documentation does not restore access to a private repository or transfer a domain account. Review repositories, domains, design tools, cloud accounts and administrative permissions alongside the contracts.

The company should be able to identify the authorised account holder, retain the required access and continue the product if a founder or supplier leaves. Coordinate that work with the founders agreement and leaver arrangements.

A practical IP checklist before due diligence

  • Can each important asset be traced to its creator and contract?
  • Have assignments been executed in the required form?
  • Are the relevant works and permitted uses identified, including fields of exploitation where Polish law applies?
  • Is the transfer date clear, with the necessary delivery, acceptance or payment evidence?
  • Does the company have the rights needed for modification and further development?
  • Can it grant the licences or sublicences required by the business model?
  • Are repositories, domains and accounts controlled by the right entity?
  • Are open-source and third-party components recorded with their terms?
  • Is AI use documented and the output reviewed?
  • Are reusable founder or supplier materials distinguished from company IP?
  • Do the arrangements fit the corporate and investment documents?
  • Can the team provide the evidence promptly to an investor or customer?

A few uncertain answers do not mean the product is unusable. They identify where to repair the chain of title before the uncertainty reaches negotiations.

Keep this work alongside development. A small startup does not need a corporate data room on day one, but it should be able to explain who created the product, on what terms and which rights it holds.

For help with Polish copyright assignments, licences and product ownership before investment or enterprise sales, see our startup legal services and software contract services, or contact us about the IP review.

Sources and further reading

Maciej Lis

Maciej Lis

Polish attorney-at-law (radca prawny)

IT and SaaS contracts, technology law, GDPR, information security and AI compliance.

View author profile
Back to Insights

Need to clarify rights to your product, code or brand?

We review IP, contracts, licences and risks that come up in sales, investment and due diligence.

Book a free consultation

If the link does not open your email app, write directly to kontakt@lis.legal or copy the address.