After three years, the company terminates its contract with the website provider. They part ways amicably; the provider sends the login credentials for the admin panel, and everyone feels like the matter is settled. Three weeks later, emails stop arriving at the company’s addresses, and eventually the domain expires.
No one sabotaged anything. It just turned out that „access to the website“ and „control over the website“ are two different things, and the latter remained exactly where it was.
This is the most common way companies lose ownership of their own website: not through a dispute, but through a misunderstanding about exactly what is being transferred. Let’s go over what a website consists of, who legally owns the code and design, what to request in writing, and the order in which to do so, so that nothing falls through the cracks between the two vendors.
What the „Web“ Actually Is
A website isn’t a single entity, but rather a package of roughly eight separate components, each of which has its own owner, its own account, and its own handover process. That is precisely why the handover is so often only half-done: the vendor, acting in good faith, hands over what they consider to be the website, and the rest doesn’t even occur to them.
This table provides the complete answer to the question of what to monitor. The rest of the article is simply a guide on how to close each row.
| Item | Who typically holds it | What happens if you don't have it |
|---|---|---|
| Domain | Registrar, but it's usually registered under the supplier's name | It expires in a year, and the website and email will go silent overnight |
| DNS Records | Registrar or hosting provider | You cannot redirect your website or emails to another location |
| Web Hosting | Account held in the supplier's name | You won't be able to access the files or the database |
| Website Administration | You, though often only in the role of editor | You don't install, update, or back up |
| Source code | Supplier Repository | New Supplier Is Making Changes Without a Plan |
| Component Licenses | Supplier Accounts | Paid templates and plugins will no longer receive updates |
| Email Accounts | Web hosting, especially from a website | The most immediately apparent and most painful loss |
| Measuring Instruments | Supplier's Google Account | You'll lose historical data that you'll never be able to recover |
Note that only two lines pertain to what is commonly referred to as a website. The rest are accounts and contractual relationships with third parties. And it is precisely in these cases that it matters in whose name they are held.
But first, let's clarify the more uncomfortable question: even if you had all the necessary access, are you allowed to do whatever you want with the website?
Who owns a website if it was built by an agency?
The website belongs to you in the sense that you paid for it. However, the copyright to the code and graphics remains with the person who created them. You are granted a license—that is, permission to use the work—and the scope of that license is defined by the contract.
If the license agreement does not specify anything in particular, the law applies. According to Section 61(1) of the Copyright Act The rule is that for a commissioned work The author granted a license for the purpose specified in the contract, unless otherwise agreed. The purpose of the contract for the company website is to operate the company website, so you are permitted to operate it. Whether you are also permitted to to have another contractor do the work, that is not clear from that sentence alone.
The second paragraph of the same section adds something even more surprising: The author may use the work on commission and grant a license to someone else as well, provided that this does not conflict with your legitimate interests. So your custom-built website might not be entirely yours. That is why it is required to have it set up correctly Web Development Contract and create a new website with a reputable agency that has a proven track record.
Think of it like a rented apartment where you paid for the kitchen. You can live there, but you can't tear down a wall without permission.
There’s usually one more catch here. Although the Civil Code recognizes the right to have the contents of a contract returned after withdrawing from it, free of charge, within a reasonable time, and in a commonly used machine-readable format (§ 2389n et seq.), but this protection is intended for consumers. If you operate a website as a company or a sole proprietor, This does not apply to you and the terms of the contract are the sole determining factor.
In practice, this leads to a single recommendation: before you start addressing anything, find the contract and look for the section on the license. If it doesn't mention the right to modify the work and grant a sublicense to a third party, you'll need to request the changes.
Ten Things to Ask for in Writing
A verbal promise made at the time of handover is worthless, because in six months no one will remember it, and the person who made it may no longer be working at the agency. Send a single email with a numbered list and ask for written confirmation for each item.
- Transfer of the domain holder to your company. Not access to the domain, but change of owner in the registry. After the transfer, request a confirmation and verify it yourself in the public registry. We explain why this is so important in our article on the subject, What Is a Domain Name and How to Choose the Right One.
- Access to DNS Records, or information on where they are stored. Without them, you won't be able to move the website anywhere.
- A hosting account registered in your name. If the website is hosted on a shared agency account, the solution is to move it to a dedicated account web hosting, not a shared password.
- An administrator account in the content management system. Make sure you actually have the highest role, not the editor role. We explain the difference in the article about this, What is a CMS system used for?.
- Complete backup of files and databases as of a specific date, ideally in a format that can be restored anywhere. Be sure to request a backup even if you’re not moving your website anywhere—just to be on the safe side. We explain how to back up your data properly in our article on website backup.
- Source Codes including the history, if any customizations were made.
- List of Paid Licenses including the date by which they are paid and the account to which they are credited. This is the point that is most often overlooked.
- List of Integrations and API Keys: billing system, payment gateway, reservations, newsletter, inventory.
- Transfer of ownership in measuring instruments. You want to be listed as the owner in Google Analytics, Search Console, and Tag Manager because your historical data is stored in those accounts.
- List of email accounts on the domain including where they run and who pays for them.
Ten points may seem like a lot. But a decent vendor can take care of most of them in a single afternoon, because they’re not losing anything. If someone resists, you’ll have learned something useful before you even leave.
Order Matters: What to Do Before You Hand in Your Notice
This is the part where takeovers most often fall through, even though it doesn’t cost a single crown. As soon as you terminate the contract, the negotiating position changes. As long as the relationship continues, addressing your requests is part of normal cooperation. After that, it’s a favor.
- First, make a list—not a decision. Go through the table above and write down for each row whether you have it or don't know. The „I don’t know“ column is the important one, because that is exactly what will determine how long the handoff will take.
- Ask for an advance payment while the project is still in progress. It's a common request; it won't raise any suspicion, and Keep the deposit with you in person, not just „somewhere on a server.“.
- Take care of the domain first. The transfer of ownership takes a few days, and this is the only item for which you If the deadline passes, the website may be taken offline. Be sure to check the expiration date as well.
- Only then should you announce the end of the collaboration. In the notice, include a list of items to be handed over and Please suggest a specific date, say 30 days.
- Arrange for an overlap. Ideally, a month when the new supplier already has access and the old one is still responding to inquiries. That month is the least expensive part of the entire process.
- Conclude the handover with a report. All you need is a table with columns for "Item," "Date Received," and "By.". Both parties should sign it, so that it is clear what has not yet been finalized.
If your notice has already been submitted and you only then realize what you're missing, it's not a lost cause. Just be prepared for the fact that it will take longer and you'll have to beg for it.
Our Experience: Three Things That Most Often Disappear During a Handover
When we take over a website from another vendor, three specific problems keep cropping up. None of them stem from bad faith, and all three can be prevented by asking a single question at the right time.
Email Accounts on a Company Domain
Emails are usually tied to a domain but run on a different server than the website. When a website is moved, the DNS records change, and emails stop coming through without anyone noticing on the first day.
Specifically: Before you move anything, ask for A list of the domain's MX records and a list of all mailboxes, including aliases and forwarding rules. Then send yourself a test message from an external address and make sure it arrives. It takes ten minutes and will save you a day of panic.
Licenses for Paid Components
Premium templates, search plugins, fonts, stock photo libraries. These are typically purchased through the agency’s account, often under a volume license for all of its clients. When you leave, your website won’t disappear, but updates will stop coming, and that is a security issue that will become apparent in six months.
Request a list in the following format Name, Version, Valid Until, Account Holder. For each item, decide whether to purchase a license for yourself or replace the component. It’s much cheaper to make this decision consciously now than under pressure after your website has been compromised.
Undocumented custom modifications
Almost every older website contains custom code that someone wrote but didn't document anywhere: an integration with the billing system, shipping calculations, or an exception for a specific category. A new developer isn’t aware of these and only discovers them when they accidentally break them.
Ask your outgoing supplier to A half-hour call with notes, in which we'll go over what isn't standard on the website. This is the least expensive half-hour of the entire takeover process. If you're also planning to migrate the website to a different domain, be sure to review the steps in the article about that, How to Move a Website Without Losing Search Rankings.
What to Do During the First Week After Taking Over
It doesn't end with the handover. The old vendor still has access that no one has revoked, and this isn't a matter of trust but of security: forgotten accounts are the most common way for an outsider to gain access to the website.
- Browse users in the admin panel and delete or demote accounts that are no longer in use. Especially those with administrator privileges.
- Change Your Passwords for hosting, the database, FTP, and administration. Enter new passwords into the company's password manager, not into the spreadsheet.
- Regenerate the API keys to the payment gateway, invoicing, and other integrations.
- Check the sender of emails from the website, that is, whether the forms are sending inquiries to your address rather than to the former administrator's address.
- Verify that the backup is running and that the restore really works. A backup you've never tried to restore is just a file.
- Check ownership in the measurement tools and set your own access permissions as the owner.
There is one exception worth considering: don’t revoke the former vendor’s access until the overlap period has ended. Otherwise, something might break on the first day, and the person who knows how to fix it won’t be able to access the website.
Frequently Asked Questions
Who owns a website if it was created by an agency?
By law, to the agency. By paying, you acquire a license to use the work, not the copyright. The copyright remains with the creator. According to Section 61 of the Copyright Act, the author has granted a license for the purpose specified in the contract, unless otherwise agreed, so you are permitted to operate the website. However, the right to allow another vendor to make changes to it must be expressly stated in the contract. Be sure to review your contract, though, it may be stated differently there.
What if the supplier refuses to hand over the access credentials?
First, send a written request with a specific list and deadline, as most cases are resolved at this stage. If the domain is registered to a service provider and they refuse to transfer it, contact the registrar and have proof ready that you’ve paid for it—typically old invoices or the email address where you receive expiration notifications. In disputed cases, it’s best to consult a lawyer, because unlike with consumers, there’s no legal safeguard requiring companies to release the data.
How long does it take to take over a website?
With the willing cooperation of both parties, it takes roughly two to four weeks. The most time-consuming part is usually transferring the domain holder and tracing accounts that no one claims. If the provider isn’t responsive, expect it to take months, since the process involves going through the registrar and the hosting company.
Will I lose my search rankings if I switch agencies?
Simply changing the provider has no effect on search rankings, because Google doesn’t care who manages the website. The risk arises only when the website’s address, URL structure, or hosting provider changes at the same time. In that case, follow the migration guidelines, especially regarding the careful redirection of old URLs.
Can you take over a website that wasn't built by your agency?
Yes, at Apador, we routinely take over websites from other providers, and we always start the same way: by mapping out the site’s architecture and creating a backup—only then do we begin working on the code. Before making any changes, we’ll let you know what condition the website is in and whether it’s worth fixing or rebuilding from scratch. If the latter option is better, we’ll tell you right away.
Summary
Changing web service providers is not a technical problem, but an organizational one. The website consists of eight separate components, and the handover typically involves only two of them.
Three things will determine the outcome. Solve it the domain first, because only that service can shut down the website. Request a deposit and a list of accesses even before termination, as long as it's a normal part of the collaboration. And make sure to overlap month, in which the new supplier is already operating and the old one is still responding.
The rest is just a matter of a single afternoon's work, if you get to it in time.
Are you unsure of exactly what belongs to your website and where to find it? Contact us and we'll walk you through it step by step on your website before you start making any changes.
We'll take over your web
We'll map out the site's architecture, create a backup, and tell you exactly what condition the website is in.





