Who Owns the Code, Domain, and Design After a Website Project?

The company should control its critical accounts and understand exactly which work is assigned, licensed, or supplied by a third party.

Who Owns the Code, Domain, and Design After a Website Project? — Troiana insight cover

In short

The company should register and control the domain, hosting, analytics, CMS, repository, and other critical accounts. Contracts should assign agreed rights to custom code, design files, copy, and original media after payment, while listing third-party software, fonts, stock assets, and platforms that remain licensed under separate terms.

Ownership is not one question

A website combines accounts, custom work, company data, and third-party licences. “You own the website” is too vague to protect any of them.

Resolve ownership and access before signing, with qualified legal advice where the rights are important. This guide identifies the operational questions; it is not a substitute for reviewing the contract under the applicable law.

The domain

The company should be the registrant and control the registrar account. The agency can manage DNS through delegated access.

Check:

  • company name and current contact details;
  • renewal payment method;
  • multi-factor authentication;
  • recovery email under company control;
  • more than one trusted administrator;
  • documented DNS records before a move.

Do not allow the domain to remain in a former employee's or supplier's personal account. Domain control can determine whether email and the public site continue operating.

Hosting and deployment

Prefer an account owned by the company, with the agency invited as a user. If the agency resells managed hosting, the agreement should explain data location, backups, access, exit, and what happens if the relationship ends.

The handover should include deployment configuration, environment ownership, recovery instructions, and any services billed separately.

Custom source code

The contract should state when rights to custom code transfer or what licence the client receives. Common conditions include full payment and exclusions for pre-existing agency tools or open-source components.

Clarify:

  • repository access during the project;
  • rights to modify and appoint another developer;
  • pre-existing code retained by the supplier;
  • reusable generic components;
  • open-source licences;
  • documentation and build instructions;
  • treatment of unpaid or disputed work.

“Source code included” is not enough if the company cannot build or deploy it without a private supplier account.

Design source files

Final exported images are not the same as editable Figma or other source files. State which files are delivered, whether third-party libraries are included, and whether fonts or stock assets can be transferred.

The company normally needs enough source material to maintain the system, create new pages, and appoint another qualified designer without reconstructing the project.

Content, data, and media

The company should control its copy, product data, customer submissions, analytics, and original media, subject to contracts with creators and privacy obligations.

Confirm rights for:

  • commissioned photography, illustration, video, and copy;
  • employee and customer images;
  • testimonials and case studies;
  • datasets and user-generated content;
  • migrated content whose origin is unclear.

Payment for production does not automatically resolve every person's or asset's rights.

Third-party software and assets

Most websites include things nobody can transfer as custom property:

  • open-source frameworks and packages;
  • CMS platforms and plugins;
  • hosted services;
  • typefaces;
  • stock photography, icons, or video;
  • maps, search, analytics, email, and payment services.

Create a licence register with product, account owner, permitted use, renewal, cost, and exit impact. A “lifetime” agency licence may not cover a client after handover.

Accounts and data that must remain under company control

  • domain and DNS;
  • hosting and CDN;
  • code repository;
  • CMS administrators;
  • analytics and tag manager;
  • Search Console;
  • consent platform;
  • email and form delivery;
  • payment, ecommerce, booking, or CRM;
  • monitoring and backups;
  • app-store or identity-provider accounts where relevant.

Invite suppliers with named users and appropriate roles. Shared credentials make accountability and offboarding harder.

The pre-signing clause checklist

Ask the contract to make these points explicit:

  1. deliverables covered;
  2. transfer or licence trigger;
  3. custom work versus pre-existing material;
  4. third-party licences and costs;
  5. moral-rights or attribution requirements where applicable;
  6. source-file and repository delivery;
  7. account ownership and access;
  8. data export and deletion;
  9. termination and handover assistance;
  10. portfolio and publicity permissions;
  11. confidentiality;
  12. responsibility for client-supplied assets.

Handover acceptance checklist

  • [ ] Domain and DNS administrators verified
  • [ ] Hosting and billing under agreed ownership
  • [ ] Repository cloned and build tested
  • [ ] Deployment and rollback documented
  • [ ] CMS administrators and roles verified
  • [ ] Design sources delivered
  • [ ] Original media and copy sources delivered
  • [ ] Licence register complete
  • [ ] Analytics, search, forms, and integrations transferred
  • [ ] Backups and restore instructions available
  • [ ] Shared access removed or rotated
  • [ ] Open issues and maintenance responsibilities recorded

Test the handover before the final emergency, not after the supplier has become unavailable.

Common questions

Does paying for a website mean I own the code?

Not automatically in every contract or jurisdiction. The agreement should state what rights transfer after payment, what remains licensed, and what third-party code keeps its own terms.

Should the agency own my domain?

No. The company should control the registrar account and invite the agency to manage DNS as needed. Keep renewal and recovery details under company control.

Do I own the website design files?

Only if the agreement includes them or grants the required rights. Specify editable source files, component libraries, fonts, stock assets, and any third-party design resources.

Can an agency reuse code from my website?

The contract should distinguish business-specific custom work from generic, pre-existing, or open-source components. Reuse rights depend on the agreed terms.

What if the agency hosts everything in its own account?

Require a documented exit: export formats, migration assistance, timing, cost, backups, DNS change, and data deletion. Better still, keep critical services in company-owned accounts where practical.

Have something worth building right?