Portability, tested early
Exporting your data
Run one on your first afternoon, when there is nothing in it that matters. That is the only time you can safely find out whether it works.
Why this page exists
The feature whose value is entirely in a day that has not happened yet
Almost nobody evaluates export properly when choosing a system, and it is completely understandable. You are deciding whether to start using something, and how easy it is to stop feels like the least interesting question available.
It is also the question that matters most, because it is the one you cannot revisit. Every other shortcoming can be worked around, tolerated or fixed by changing supplier. The ability to change supplier is the thing that makes all of that true, and if it turns out to be missing you discover it at the exact moment you have the least room to act.
So here is the recommendation, and we would give it about any supplier rather than specifically about us. Run an export on the first afternoon, before there is anything in the system worth losing. You learn what it actually produces, you learn that it works, and it costs ten seconds while the stakes are nothing.
What to look at when you do
Open it. Can you read it without our software? Are the fields recognisable? If you handed it to somebody and asked them to rebuild your customer list, could they?
Those three questions separate a real export from a technical compliance with the word. A file in a proprietary format that only the supplier's tools can read satisfies a sentence on a website and helps nobody.
Diligence
Six questions worth asking any supplier holding your customer list
The middle column is not hypothetical. All six are common answers in this industry.
| The question to ask any supplier | The answer that should worry you | Ours |
|---|---|---|
| Is export available on the free plan? | It is available on paid plans. | Every plan, including free, including after you stop paying. |
| Does it cost anything? | There is a data extraction fee. | Nothing, at any time, without asking. |
| How long does it take to arrange? | Raise a support request and we will come back to you. | You run it yourself. There is nothing to arrange. |
| What format is it in? | Our own format, which our tools can read. | A format that opens without our software. |
| Does it include the files? | Documents are available separately on request. | Included. |
| Does it include the history? | Current records are exported. | Timelines, lost opportunities, consent history and the audit trail. |
There are six more of the same kind on the customers page, which is written for somebody weighing an unproven supplier and puts the questions before the reassurance. Import, export and search describes the same machinery from the product side.
Contents
What is actually in it
Everything you hold, in a format that opens without our software.
- Relationships
- Every person and organisation, with their types, fields, custom fields and the connections between them, including the dates on those connections.
- Timelines
- The events on each record in order: notes, stage changes, messages, consents, appointments, matters, everything that was written as it happened.
- Leads and opportunities
- Including the ones that were lost, with the reasons and the stage history, which is the part most likely to be missing from any other system's export.
- Consent records
- Every consent and withdrawal with its date, channel and source. This is the part you will need if you ever have to answer what someone had agreed to on a particular day.
- Tasks and appointments
- With their owners, dates and completion, against the records they were attached to.
- Module records
- Matters, projects, invoices, payments, credit notes, contracts and campaigns, for any module your plan carries. They are included even if the module has since been removed from your plan.
- Files
- The documents you uploaded, as files, not as links to somewhere that will stop working.
- The audit trail
- Who changed what and when. It is evidence, so it comes with you.
The value of a portability promise is entirely in whether it works on the day you have decided to leave, and that is the worst possible day to find out.
Which is why it is free on every plan, and why we would rather you tested it on your first afternoon than on your last.
Producing the file
Running an export
The full export
From the organisation settings, if your role permits it. There is nothing to arrange with us, no request to raise and no approval on our side. It is generated on request rather than being a nightly extract, so what you get is the state at the moment you asked.
It is not limited by your plan's allowances. An organisation that dropped from a paid plan to Free holding more relationships than Free permits still exports all of them. Limits apply to adding more, never to taking things out.
Exporting one list
Any list or saved view exports as it stands, with the rows and columns you built. This is the one most people use day to day: if you have constructed the question in the product, the answer should come out in the shape you built rather than as a generic dump you filter again in a spreadsheet.
On a schedule
There is no scheduled export today, so this is a habit rather than a feature. Once a month or once a quarter, run one and keep it somewhere we do not control. Cloud storage you own, or a machine in your office.
This is the single most valuable continuity control available to you as a customer of any small supplier, because it is the only one that does not depend on the supplier still being there. We would recommend it even if we were considerably larger than we are.
Reading it
What to do with the file once you have it
An export you have never opened is a file you hope is correct. Twenty minutes turns it into something you know.
Open it, on the first afternoon
Not because we expect it to be wrong. Because the only time you can safely find out what an export produces is when you do not need it to work, and that time is now rather than on the day you have decided to leave.
The formats open in a spreadsheet and in any programming language without our software. That is the property that makes it portability instead of a feature, and it is worth confirming with your own eyes.
Check the four things that matter
Are your relationships there, with the fields you actually use? Are the connections between them there, with their roles and dates? Are your notes and timeline entries there? Are the files there, and can you match them to the records they belong to?
Those four cover almost everything anyone needs from an export. If any of them is not what you expected, that is worth telling us about immediately rather than discovering later.
Keep one somewhere we do not control
This is the whole point of the exercise. A copy on your own storage, on a schedule you set, is the answer to the question every buyer should ask a supplier of our size, and it is entirely in your hands rather than dependent on anything we do.
We would give the same advice about any small supplier, including ourselves. It is not a comment on our intentions, it is arithmetic about risk.
Do it again periodically
Quarterly is plenty for most organisations. The value is not the individual file, it is that a current copy always exists, and the habit is what produces that instead of any single export.
What an export is not
It is not a report. There is no interface for exporting a chosen subset with chosen columns, because a partial export is exactly the thing that turns out to be missing something on the day it matters. You get everything you are allowed to reach, which for an owner is everything and for somebody without the grant for sensitive records is everything else with a count in the manifest of what was held back, and filtering afterwards is a spreadsheet problem rather than a portability one.
It is also not a subject access response. Subject access tooling is in the product on every plan and it answers about one person, which is what a request asks for. The export answers about everyone, so somebody reaching for it with a clock running has taken on the much harder job of removing the everybody first.
Backup is not export
An export is not a backup, and which one you need depends on the difference
Most readers arrive holding words borrowed from disaster recovery. They are close enough to be useful and wrong in precisely the places that decide what you should do.
- Backup
- Something we run, that you never see, whose purpose is to put your organisation back the way it was after something went wrong here. Thirty days of point in time recovery, then backups ageing out on their own schedule. You cannot hold it, read it or take it anywhere. An export is the opposite on all three counts, and worse at the one thing a backup is for.
- Archive
- A copy kept because someone may ask, rather than because you intend to use it. An archive has a retention period attached to it by someone who decided. Three years of exports in a shared folder with no rule against them is not an archive, it is an accumulation.
- Snapshot
- The word people reach for, and the accurate one. What you get is the state at the moment you asked, not last night and not a rolling feed. Two exports taken an hour apart will differ if anybody was working in between, and neither of them is wrong.
- Restore
- Putting the file back and having your organisation as it was. That is a recovery operation and it is not what export is for. The relationship data goes back in through the import because it is in the shape the import reads. The rest of the file is readable rather than reloadable.
- Portability
- The obligation this exists to satisfy, and narrower than it sounds. Portability means getting your data out in a form somebody else can read. It does not mean the next supplier will accept it without work, and no supplier can honestly promise you that part.
- Manifest
- The top of the file, carrying a count for every table and what your organisation was entitled to. It is what turns a file you hope is complete into a file you can check, because counting lines and comparing them against the manifest is something you can do without us.
- One line per record
- Not a spreadsheet. Each record is its own line, which is why the file can be read by any programming language, handled a line at a time rather than loaded whole, and opened in a plain text editor when it has grown past what other applications will look at.
- Complete
- Complete means everything, rather than everything you chose. There is no interface for picking tables or columns, so the word needs no qualifying, and the cost is a file that is larger and less convenient than a tidy list would have been.
The question that separates the two
Somebody deletes four hundred records on a Thursday afternoon and nobody notices until Monday. What you want is Thursday morning back, with everything that legitimately happened since Thursday morning still there. That is recovery. It covers a window rather than a filing cabinet, and an export cannot give it to you. Putting a file from three weeks ago back over the top would undo three weeks of correct work in order to undo one mistake.
Now the other case. You have decided to leave, or the supplier has, or someone senior asks what happens if this product cannot be reached on Monday morning. Recovery is no use in any of the three, because every one of them assumes the thing doing the recovering is still there. That is what an export is for, and it is why we would rather you kept one somewhere we do not control.
The honest cost of keeping the distinction
One word covering both would be more convenient and would mislead. Suppliers who describe an export as a backup are usually not lying. They are letting a reader assume something the file cannot do, and the assumption gets discovered on the day it is being relied on, by someone who no longer has time to find out they were wrong.
So the export here is worse at restoring than a backup and better at everything a backup cannot do. You need both. One of them we run and it is ours. The other one you run and it is yours, which is the entire point of it.
What the file is, physically
One file, and it is worth a sentence on what is inside it, because there are two halves and the records cannot carry the documents. The button marked export everything as one file gives you a single archive holding both: the records as one plain text file, and the files themselves beside it. A manifest at the top of that text file carries a count for every table and what your organisation was entitled to, then one line per record after it. Nothing about that is clever, and the plainness is deliberate: a format anyone's developer can read on a Tuesday afternoon without telephoning us is worth considerably more than a format that is elegant.
The two halves are also offered on their own, because the records are what most people want most of the time and they are small enough to open on any machine, while the documents can be very large. Taking all of it is one button and taking either half is another.
It also makes checking the file arithmetic rather than trust. Count the lines belonging to a table, compare that against the number the manifest claims, and you have verified the thing everyone assumes about an export and almost nobody tests.
We run the same check ourselves. Every night an export is read back line by line and the counts its manifest claims are compared against the rows the file actually contains, because an export that writes cleanly and cannot be read back is the failure that stays hidden until the day someone needs it.
When the assumption fails
Six situations where an export behaves differently from the tidy version in your head
None of these is exotic. All six follow from how the product is built, and each of them surprises somebody the first time it happens.
The export you took last month still contains somebody you have since erased
New exports do not include records erased under a data protection request, because erasure means removed rather than hidden. The file you took before the request arrived is a different matter entirely. It sits on your storage, it is your copy, and nothing we do reaches it. What you owe the person who asked is set out by the Information Commissioner's Office rather than by us, since your organisation is the controller of those records.
That is not a gap in the product. It is the ordinary consequence of holding your own copy, and it would be true of any supplier who gave you one. What it does mean is that an erasure request has a second half that belongs to you: finding the exports that predate it and deciding what happens to them. Few exports in one known place makes that a five minute job. Many exports, everywhere, makes it an afternoon of guessing.
Someone is working while it runs
It is generated on request, so what you get is the state at the moment you asked rather than a picture of a quiet system. If a colleague saves a note while the file is being assembled, whether that note appears in it depends on when the note landed.
For the purpose an export serves this does not matter, and we would rather say so plainly than imply a guarantee we have not made. If you are taking an export specifically because you are about to do something irreversible, take it when no one is working. That is a scheduling decision rather than a setting, and it is yours.
A module you have stopped paying for
Modules are bought separately from plans, and stopping one does not empty it. The records that module wrote stay in the export, so an organisation that ran projects for a year and then stopped still exports every project it created.
This is deliberate, and it is the version of the rule that costs us rather than you. The alternative, where the data you are able to take out shrinks the moment your bill does, turns a portability promise into a lever. A lever is exactly the thing this page exists to say we are not holding.
The person who ran the last one has left
An export is run by a person holding a role, and the file goes wherever that person put it. When they leave, the role goes with whatever process you use for that. The file does not, because the file was never in the product to begin with.
Ask the question now rather than then. If your last three exports live on a laptop that goes home with somebody in April, you do not have a continuity control, you have a person. Storage the organisation itself owns fixes this and costs nothing but the decision.
Two organisations, one person, one habit
There is one database per organisation, so there is one export per organisation. Someone who belongs to a charity and to its trading subsidiary runs two exports and gets two files, and neither file contains a line from the other.
That separation is the same one that stops either organisation reading the other's records, so it is not an inconvenience we could remove without removing something better. What it does mean is that a quarterly habit has to happen twice, and the one people forget is always the smaller organisation.
Nobody has signed in for six months
A free organisation no one signs into is treated as dormant. Its administrators are written to at six, seven and eight months, each time offering a complete export, and at twelve months the organisation is closed rather than deleted: a final notice, then thirty days in which an owner can sign in, export, or simply reopen it.
Those letters exist because deleting quietly on a timer is the one routine operation capable of destroying someone's only copy of their data, and we would rather write three letters than run that. If one arrives, the right response is to run the export in the minute you finish reading it. The common response, which is to file the letter and mean to look at it, is how organisations lose things no one intended to take from them.
The letters exist instead of a cheaper mechanism because of an argument we lost with our own arithmetic, written up in what a free plan costs. It is the clearest example on this site of a database decision arriving on a customer's doormat.
A copy of your customer list on storage we cannot see is the only continuity control that survives us failing. It is also, and at the same time, a copy of your customer list.
Which is why the rest of this page is about custody rather than about the button that produces the file.
What you decide
The moment the file exists, custody of your customer list is entirely yours
Running an export is the easy half. The half nobody writes down is where the file then lives, who may open it, and how long you keep the ones you no longer need.
Where it lives, and whether that is somewhere you actually control
The point of the exercise is a copy in a place that does not depend on us. A downloads folder is not that place. Neither is an email to yourself, which puts your entire customer list into the one system most likely to be read by someone who should not be reading it.
Storage your organisation already trusts with its accounts is usually right. The test is short: if the person who set it up left tomorrow, could someone else still reach it? A continuity control that depends on one individual's personal account is not a continuity control, it is the same risk wearing different clothes.
Who may open it, which is a shorter list than who may run it
Inside the product, roles decide what someone sees, and sensitivity can keep particular records away from particular people. The file carries one of those two and not the other. Sensitivity survives: whoever runs the export gets the records marked sensitive only if they hold the grant to reach them, and where they do not, those rows, the files attached to them and the audit entries about them are left out and the manifest says how many were left out, so the file never passes itself off as complete when it is not.
Roles do not survive. Everything else is one flat export, in one file, with no notion of who owned what or which team it belonged to, so the moment it lands on a drive the whole office can browse, every scoping decision you made carefully is undone for anybody who thinks to look.
This is not an argument against exporting. It is an argument for putting the file where the people who could already see the records can see the file, and no wider than that.
How long you keep the old ones
An export is personal data, held by you, under the same rules as everything else you hold. Those rules are the Data Protection Act 2018 and the UK GDPR alongside it, and they do not stop applying because the file is on a drive rather than in a product. A folder containing three years of quarterly exports is three years of former customers, withdrawn consents and people who have since asked to be forgotten, kept for no stated reason by no one in particular.
Pick a rule and write it down. Keep the last two and delete the rest is a rule. Keep everything is not a rule, it is what happens when no one chooses. The rule matters more than the number in it, because a rule survives the person who set it and a habit does not.
Whether you are keeping it for continuity or for evidence
These two want opposite things. Continuity wants one current file and nothing else, because an out of date copy of a customer list is worse than no copy at all. Evidence wants the file from the date something was true, and never wants it overwritten.
Most organisations need the first and believe they need the second. If you genuinely need the second, what you want is almost always far narrower than a whole export: what one person had agreed to on one day, which is held in the product as a consent record with its date, channel and source, and which does not need a file on a drive in order to be true.
Whether anyone would notice a copy going missing
Ask it out loud once, in front of the people who would have to answer. If the answer is no, that is worth learning now rather than afterwards, and it is fixed by the same decision as the first item on this list: fewer copies, in one place, that the organisation instead of a person owns.
We are not going to pretend this part is ours to solve. We can make the file free, complete and quick to produce. Where it goes next is outside anything we can see or control, and that is simultaneously the value of the feature and the cost of it.
Export questions
Asked about exporting
Do I need permission to export?
You need a role that permits it, which is a decision your organisation makes. You do not need permission from us, there is nothing to raise with support, and there is no approval step on our side. If your role permits it, you run it.
Is it really free on the free plan?
Yes, at any time, including after you have stopped paying for a paid plan. Export is a portability commitment rather than a feature. A promise you can only test after you have paid is not a promise, and the point at which you would find out is the point at which it is too late to matter.
What if I have more data than the plan allows?
Export is not limited by your plan's allowances. If you dropped from a paid plan to Free holding more relationships than Free permits, everything is still exported. The limits apply to adding more, never to getting things out.
How long does it take?
It is generated on request instead of being a nightly extract, so it takes as long as your data takes to assemble. For most small organisations that is seconds to a couple of minutes.
Can I export just one thing?
Yes. A saved view exports as it stands, with the same rows and the same columns you built, and so does the plain list underneath it: relationships, enquiries, opportunities, matters, quotations, tasks and invoices all carry the button. Matters were the one list that did not, and now do. All of this is separate from the full export and is what most people use day to day.
Does the export include records that were deleted?
Deleted records that are still recoverable are included and marked as deleted. Records that were erased under a data protection request are not, because erasure means removed rather than hidden, and an export that quietly returned erased people would defeat the entire purpose of the erasure.
Can I import an export back into Consonas?
The relationship data, yes, because it is in the same shape the import reads. A full round trip restoring every timeline event into a fresh organisation is not something we would claim works cleanly, and if that is your requirement you should test it rather than take a sentence on a page for it.
What should I actually do with it?
Run one on your first afternoon, when there is nothing in it, so you know what it produces. Then run one periodically and keep it somewhere we do not control. That is sensible with any supplier, it costs nothing here, and it is the only continuity control that stays entirely in your hands.
Is the export a backup?
No, and treating it as one is the mistake this page most wants to prevent. A backup puts your organisation back the way it was. An export gives you a readable copy of what was in it. If what you need is the state of last Tuesday afternoon with everything since Tuesday still intact, that is point in time recovery rather than a file on your own storage, and putting an old export back over the top would undo three weeks of correct work in order to undo one mistake.
How large is it, and will it open?
For an organisation of the size this product is built for, small enough that the question does not arise. The file holds one record per line rather than one enormous structure, so anything can read it a line at a time, and a plain text editor will still open it on the day a spreadsheet application refuses.
Two of us each ran one. Do we now have two copies of everything?
Yes, and that is a custody question instead of a product question. Each export is a complete copy of your customer list, and how many exist is a number only you can know. Decide where exports live before you need one, so that the answer is a place instead of whichever laptop happened to be nearest.
Does one export cover both of our organisations?
No. There is one database per organisation, so there is one export per organisation, and someone who belongs to both runs it twice. That separation is the same one that stops either organisation reading the other's records, so it is working as intended even on the occasions it is inconvenient.
We are on the free plan and no one has signed in for months. What happens?
A free organisation nobody signs into is treated as dormant. Its administrators are written to at six, seven and eight months, each time offering a complete export, and the ordinary deletion process begins at twelve months with its own notice and grace period. The letters exist because deleting quietly on a timer is the one routine operation capable of destroying someone's only copy. If one arrives, run the export in the minute you read it rather than filing the letter and meaning to.
What if something I expected is not in the file?
Tell us, with the record and what you expected to find. That is the most useful message this help centre produces, because an export that is quietly incomplete is a promise that fails on the single day it is being tested. It is also the whole argument for opening the file on your first afternoon rather than on your last.
Run one now
Before there is anything in it that matters, so that you find out what it produces while finding out costs nothing.
Three people, a thousand relationships, no card and no time limit.