Skip to content

Rights and contracts

Third-party content inside licensed records: attachments and embedded documents

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Third-party content inside licensed records, such as vendor manuals attached to tickets, articles pasted into chat or files customers uploaded, belongs to someone else and should be filtered out before delivery. The workable rule: license the text your own people wrote, drop attachments and embedded documents by default, and limit the non-infringement warranty to records the company authored.

Key takeaways

  • Attachments, vendor documentation, pasted articles, images and embedded files are third-party content even when they sit in your own systems.
  • Drop whole file types first, then strip quoted and forwarded text, then sample by hand.
  • A placeholder that records only the file type keeps conversations readable after an attachment is removed.
  • Narrow the non-infringement warranty to records your personnel authored and the filters you applied.
  • A notice-and-replace process turns a stray third-party file into a fix instead of a breach.

What counts as third-party content in company records?#

Third-party content is any material inside your records that someone outside the company created and still holds rights in. It arrives quietly: a supplier's datasheet attached to a purchasing thread, a consultant's report linked from a wiki page, a screenshot of another vendor's dashboard in a support ticket.

Messages your customers wrote in a ticket are also authored by outsiders, but they are usually handled through the customer contract and privacy review rather than this filter. The categories below are the ones that most often carry someone else's copyright, license terms or confidentiality.

  • Email attachments: contracts, quotes, spec sheets and reports sent by customers, vendors and advisers.
  • Vendor documentation: manuals, datasheets, installation guides and release notes in shared drives or wikis.
  • Quoted publications: news articles, analyst reports and paywalled research pasted into Slack, Teams or email.
  • Images: stock photos, screenshots of other software, product photos and marketing images.
  • Customer uploads: files and logs customers attached to support tickets or portals.
  • Embedded documents: Google Docs, design frames and videos embedded in Confluence or Notion pages.
  • Purchased materials: industry standards, training courses and templates bought under a license.
  • Open-source code: libraries and snippets inside repositories, each under its own license.

Why outside material creates risk in a data license#

Outside material creates risk on three fronts: copyright in the work itself, the contract terms under which you received it, and confidentiality owed to the sender. A vendor manual may be free to download and still carry terms limiting its use; a consultant's report may be confidential under the engagement letter.

The fourth front is your own warranty. Buyers ask suppliers to promise that the data does not infringe third-party rights, and a single folder of embedded vendor PDFs can turn that promise into exposure.

Provenance standards reflect the issue. The Data & Trust Alliance's Data Provenance Standards include, in their Use group, elements for the license to use and for copyright, patent and trademark status, which is the kind of metadata a careful buyer expects a supplier to be able to answer.

Exclusion checklist by content type#

The exclusion checklist sets a default for each content type and leaves room for counsel to bring material back case by case. Defaults are deliberately strict, because removing a file costs little while defending one can cost a great deal.

Two record families need a closer look than the table suggests. Wiki pages often mix staff writing with pasted vendor instructions in the same paragraph, and code review threads sometimes quote documentation from outside projects at length. Both pass a file-type filter, so they depend on the text-level steps below.

Exclusion checklist by content type
Content typeWhere it usually sitsDefault treatment
Email and ticket attachmentsMail archives, help desks, CRMExclude; keep a placeholder noting the file type
Vendor manuals and datasheetsShared drives, wikis, ERP item recordsExclude
Pasted articles and reportsChat, email, wiki pagesRemove long quoted passages; keep the staff discussion around them
Screenshots and imagesTickets, chat, documentationExclude by default
Embedded documents and videosConfluence, Notion, SharePoint pagesExclude embeds; keep page text written by staff
Forwarded outside emailsMail threadsExclude the forwarded body unless reviewed
Purchased standards and coursesEngineering and training foldersExclude
Open-source codeRepositoriesReview licenses; exclude vendored libraries

How to filter third-party content at scale#

Filtering at scale combines rules that catch most material automatically with sampling that catches what the rules miss. The order matters: remove whole file types first, then work inside the text.

Keep the filter log. A list of which rules ran, on which systems, and what the sample review found is the evidence behind any warranty you give.

  • Drop attachments and binary files by type before text processing, leaving a placeholder such as attachment removed: PDF.
  • Exclude folders and spaces that hold vendor documentation, purchased standards or archived marketing material.
  • Strip quoted reply chains and forwarded bodies from email by detecting reply and forward headers.
  • Flag long passages that match published text or sit next to a link to an outside site, and remove the quoted block.
  • Remove vendored dependency directories from repositories and keep license files for the rest.
  • Review a sample from each record family by hand, and widen the rules wherever outside text slipped through.

Scoping the non-infringement warranty#

The non-infringement warranty should describe what the supplier actually controls: the records its people wrote and the filters it applied. Broad wording that covers every byte in the delivery makes the supplier answer for material it never authored and may not know is there.

A buyer is more likely to accept narrower wording when the supplier can show the filter log and the exclusion list. The warranty then describes something the supplier demonstrably did.

Scoping the non-infringement warranty
Warranty wordingSupplier exposureNarrower alternative
The data does not infringe any third-party rightsCovers every byte, including material the supplier never authoredSupplier has the right to license records its personnel authored
Supplier owns all data deliveredUntrue for any record with embedded outside materialSupplier owns or has rights to license the records in the agreed scope
Uncapped indemnity for infringement claimsOpen-ended cost for one stray attachmentIndemnity tied to breach of the narrower warranty, subject to the cap
No remedy processEvery slip becomes a breachNotice, removal and replacement process for flagged material

Illustrative: an architecture firm strips its submittals#

Illustrative: a fictional architecture and engineering firm keeps RFIs, submittals and review comments in Procore, marked-up sheets in Bluebeam and internal discussion in Teams. Submittals arrive packed with manufacturer product data, subcontractor shop drawings and consultants' calculations.

The managing principal and counsel agree on a rule: the firm licenses the questions, review comments and responses its staff wrote, and every submittal attachment comes out. Shop drawings, product data and consultant reports are replaced with placeholders naming the document type, and long passages quoted from codes and standards in RFI responses are cut back to a reference.

The warranty in the license covers firm-authored text and the agreed filters. The archive stays useful because the reasoning of each review survives even where the document under review does not.

How SourceX handles outside material#

SourceX treats third-party content as a Rights question first and a Preparation task second within the SourceX five-step transaction, which runs Supply, Rights, Preparation, Approval and Delivery. The rights review identifies which record families carry outside material; preparation applies the filters the supplier approved.

The SourceX Evidence Packet records provenance and licensing rights for each record family, with permitted use, the privacy record and release authorization, so the scope of any warranty matches a documented process.

Frequently asked questions

Is a short quote from an article inside a Slack message a problem?

Short quotes inside a staff discussion carry less risk than whole articles, but whether a particular use is fair use is uncertain and fact-specific. Most suppliers remove long quoted passages and keep the discussion, which preserves the reasoning without depending on that question.

Should attachment filenames be kept?

Filenames can reveal customer names, project names or personal details, so they need the same privacy review as the text. A placeholder that records only the file type, such as attachment removed: spreadsheet, usually keeps enough context.

Does open-source code in our repositories need special handling?

Yes. Each library or snippet carries its own license, and some licenses attach notice or sharing conditions to redistribution. Most suppliers exclude vendored dependencies and third-party directories entirely, keep the code their engineers wrote, and record which license files were present in the repositories that remain in scope.

Can we license documents a contractor or consultant wrote for us?

Only if the engagement gave the company those rights. Under US copyright law, a commissioned work is a work made for hire only in a short list of statutory categories and only under a signed written agreement, so most consultant reports and contractor documents belong to the company only if the contract assigns them. Some engagements grant just a license to use deliverables for the project, so check each agreement first.

What happens if third-party material is found after delivery?

A well-drafted license includes a notice and replacement process: the buyer reports the material, stops using it and the supplier delivers a corrected file. Without that process, every slip can be framed as a breach of warranty.

Do customer-uploaded logs and files count as third-party content?

Yes. Files customers attached to tickets were created by them and may hold their confidential information or personal data. They are excluded by default, while the support agent's written diagnosis around them can usually stay after privacy preparation.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
  • Copyright Office Circular 30 explains that a work made for hire arises either when an employee creates the work as part of regular duties, or when a work in certain statutory categories is specially ordered or commissioned under an express written agreement; contractor work outside those categories needs an assignment. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify