Website Ownership and the Handover Process

A website is not a single asset. The domain, hosting, source files and content are parts that must be handled separately, and their ownership is independent of each other. Not clarifying this distinction from the start is the source of the most common problems at the agency-change or handover stage.
Who owns my website?
A website consists of four separate parts, and their ownership is independent: the domain, the hosting account, the source files and the content. The domain must in all cases be registered in the business's own account; if it's registered in the agency's account, that's the biggest risk item when the relationship ends. Content and data always belong to you.
The four parts of a site
| Part | What it does | Who should hold it |
|---|---|---|
| Domain | The site's address (e.g. yourcompany.com) | Always the business's own account |
| Hosting | The server the site runs on | In the business's name, access can be shared |
| Source files | Design and code | Should be delivered to the business |
| Content and data | Texts, images, form records | The business |
Agreements made without knowing this distinction cause problems later. The most common example: the domain has been opened in the agency's own account, and when the business relationship ends the business can't access its own address.
The domain: not up for negotiation
Your domain is your brand. The search ranking built up over years, the address printed on your business cards, your email addresses — all depend on it.
How do you check whose name it's registered in? You can see the registration details with domain lookup tools; but since most registrations are under privacy protection, what really decides it is who owns the account at the registrar. Check whether you can log in to that account.
You can see your domain's registration and expiry dates with the Domain Lookup tool.
What to do if the agency opened it? Request a transfer. Domain transfer is a standard operation: the registrar gives you a transfer code, and you move it to your own account. This takes a few days and usually extends the domain's term by a year.
The worst case: a domain left with someone who can't be contacted. When it expires it's released and someone else can take it. So don't postpone the check.
Hosting: you must have access
The hosting account should be in your name, or at least you must be able to access the admin panel. Otherwise you can't get your site's files when you change agency.
What to ask for during handover:
- Hosting panel username and password
- FTP/SFTP details
- Database access details
- Admin access to the email accounts
Email is especially important: if your corporate email sits on the same server, losing the hosting means losing your correspondence history too. If a migration is needed, the IMAP Migration tool transfers while preserving the folder structure.
Source files: what will be delivered must be written from the start
In practice there are two different approaches here, and both are legitimate:
Full delivery. Design sources and code are given to you; you can continue with another team. This is the standard in corporate projects.
Usage rights. The agency rents you the infrastructure it developed; the source code isn't delivered. Common in models using a ready-made platform, and it can be lower cost.
The problem is that which one applies is never discussed at all. If it's not in the contract, the parties expect different things when the job ends. A single sentence at the quote stage is enough: "Will the source files be delivered at the end of the project?"
Content and data are always yours
Your texts, product photos, customer form records and membership data, if any, belong to you. These must be exportable.
It also matters for KVKK: you are the controller of the personal data you collect via forms. Where this data is kept, who can access it, how long it's retained — you need to know these.
Handover checklist
When moving to a new team or clarifying the current situation:
- Domain registration account in the business's name and I have the login details
- Domain expiry date known, auto-renewal on
- I have hosting panel access
- FTP and database details received
- I have admin access to the email accounts
- Source files received (if in the contract)
- Admin panel administrator account in my name
- Google Search Console and analytics accounts linked to my account
- I own the Google Business Profile
- SSL certificate and its renewal defined
- I have a site backup
The last item is often skipped: ask for a full backup of the site during handover. If something turns out to be missing later, that's your only fallback.
Google accounts are part of the handover too
Search Console and analytics accounts are often opened under the agency's own Google account. That's practical at initial setup but causes problems at handover: years of accumulated data history stay in that account.
The right way is to set up these services with the business's own Google account and give the agency user permissions. That way permissions are removed when needed, and the data history stays with you.
The same applies to the Google Business Profile, and there the situation is more critical: if someone else owns the profile, you can't manage your business's map listing.
When starting work with a new agency
Questions to ask on day one about the site you're taking over:
- Which platform does the site run on?
- When was the last backup taken, where is it kept?
- Which plugins/services are paid and when do they renew?
- Is there a known security vulnerability or an unupdated component?
- Is anything on the site not working (forms, payment, integrations)?
The answers to these questions reveal the real state of the inherited work from day one.
Frequently asked questions
Does the agency have to hand over the source code? If the contract says so, yes. If it doesn't, a difference of interpretation arises between the parties; so clarify it from the start.
What do I do if the agency won't transfer the domain? Contact the registrar. If you can document that the domain was registered on behalf of your business, registrars usually run a dispute process.
Will moving the site to another hosting affect my ranking? Not if the addresses don't change. A short outage may occur during the move; planning the DNS switch with a low TTL reduces it.
Does the site stop working during a handover? Not when planned correctly. The site is set up on the new server, tested, then the pointer is switched.
If you don't know today who holds these four parts, don't wait for your paths to part with the agency to find out. Logging in to the registrar and verifying the account is yours takes ten minutes.
What to ask for during handover
The items that must be received in an agency change are clear. Listing them from the start saves the process from turning into a negotiation:
- Access to the domain registration account or the transfer code.
- The hosting account and server access details.
- A backup of the site files and database.
- The admin panel administrator account.
- Third-party accounts in use: analytics, search console, ad accounts, email sending service.
- Design source files, if specified in the contract.
Which of these items will be handed over must be written in the contract at the start of the project. When discussed later, problems arise because the parties understood different things.
Is the source code always handed over
No, and this alone is not a sign of bad faith. If the agency has an infrastructure it developed itself and uses for several customers, its source code is usually licensed, not handed over. What matters is that this was clearly written from the start.
By contrast, content, data and the domain belong to the business in all cases. If there's a dispute over these three, the contract was set up wrongly from the start.
You can see your domain's registration details with the Domain Lookup tool.