Skip to content

Software companies

Who owns the content of a support ticket: the customer or the software vendor?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Support ticket data belongs to neither side outright. The customer usually owns the text and files it submitted, the software vendor usually owns its agents' replies and internal notes, and the help desk platform holds a copy without owning it. The practical rule: the further a ticket moves into the vendor's troubleshooting, the more of it the vendor controls.

Key takeaways

  • Three questions sit behind ticket ownership: who wrote each part, what the contracts allow, and who holds the copy.
  • Customer-written text and attachments usually stay under the customer's rights and the vendor's limited license to use them for support.
  • Agent replies and internal notes written by employees generally belong to the vendor, though agents routinely paste customer details into them that need redaction.
  • Help desk fields that mark each comment as public or internal, and each author as agent or end user, make the split workable in an export.

Who owns a support ticket: the customer or the vendor?#

A support ticket is owned in parts, not as a whole: the customer controls what it wrote and attached, and the software vendor controls what its own staff wrote. That answer comes from three separate questions that are easy to blur together: authorship, contract permission and custody.

Authorship asks who wrote each comment. Contract permission asks what the customer agreement, privacy notice and confidentiality terms let the vendor do with each part. Custody asks where the record sits, which for most software companies is a help desk such as Zendesk or Intercom that stores tickets on the vendor's behalf.

A licensing decision needs all three answers. Owning the words in an agent reply does not help if the reply quotes the customer's confidential configuration, and holding the export does not create ownership of anything.

In practice, the definition of customer data in the terms of service often settles the hardest cases. A definition limited to content the customer submits leaves agent replies and notes with the vendor; a definition that covers everything submitted to or generated through the support channels pulls the whole ticket under the customer's control.

Customer text, agent replies and internal notes compared#

The three main ticket components differ on every question that matters for reuse. The comparison below reflects common B2B software terms; individual agreements can move any cell, so treat it as the default to test against your own contracts.

Customer text, agent replies and internal notes compared
QuestionCustomer-written textAgent repliesInternal notes
Who wrote itThe customer's employee or end userThe vendor's support staffThe vendor's support and engineering staff
Usual rights holderThe customer or the writer's employerThe vendor, when written by employeesThe vendor
What limits reuseTerms of service license, confidentiality, privacy lawCustomer content quoted inside the replyCustomer details pasted in from logs or calls
Affected by deletion on terminationUsually yesSometimes, if the contract treats the whole ticket as customer dataRarely, unless customer data is embedded
Typical licensing treatmentExcluded, or included only with clear rights and redactionIncluded after redactionIncluded after redaction

Why the vendor's share of a ticket grows as it is worked#

The vendor's share of a ticket grows with every step of troubleshooting. A ticket opens with the customer's description of a problem, but by resolution it often holds agent diagnosis, internal notes, an escalation to engineering, a linked Jira issue, a pull request and a release note, all written by the vendor.

That vendor-authored trail is often what AI developers value most, because it shows how a problem was diagnosed and fixed rather than just how it was reported. It is also the part the vendor is most likely to control, which is why support-to-fix histories are often the strongest candidate in a software company's archive.

The customer's opening message can often be replaced by structured fields the vendor created, such as product area, severity and root cause tags. Those fields preserve the problem's shape without carrying the customer's own words.

Tickets with more than two parties#

Some tickets involve rights holders beyond the vendor and its direct customer, and each adds a layer to the analysis. These are the patterns to look for before scoping a ticket export.

When a ticket falls into one of these patterns, the simplest default is to keep only the vendor-written components and drop the rest. That loses little, since the troubleshooting trail usually carries the value, and it avoids negotiating with parties who never signed the vendor's terms.

  • Reseller or partner tickets: a channel partner files on the customer's behalf, and the partner agreement may set its own confidentiality terms.
  • End-user tickets in B2B2C products: the writer is the customer's own client, which adds another rights holder and usually more personal data.
  • Integration tickets: messages quote another vendor's error output or documentation, which belongs to that vendor.
  • Outsourced agents: replies written by a contractor's staff belong to the vendor only if the services agreement assigns work product.
  • Merged and forwarded tickets: email chains pasted into a ticket can carry third parties' messages and signatures.

How to split a ticket export by author and visibility#

Splitting a ticket export works best when it relies on fields the help desk already records rather than on text parsing. Most help desks mark each comment as public or internal and record whether its author is an agent, an end user or an automated rule; check your platform's export format and API documentation for the exact field names.

Use those fields to route each comment into a bucket: customer text, vendor replies, internal notes and automation. Then review the vendor buckets for pasted customer content, because agents routinely copy error messages, account names and configuration excerpts into replies. Redaction is what turns a vendor-owned reply into a licensable one.

Watch for side conversations, bot replies and comments created by email forwarding, which some platforms attribute to the agent who forwarded them even though the text came from the customer.

Illustrative: an e-commerce platform vendor splits its Intercom archive#

Illustrative: a fictional e-commerce platform vendor serving independent merchants has years of Intercom conversations linked to Jira issues. Its general counsel finds that merchant messages often include their own shoppers' names and order details, while agent replies and notes explain checkout, tax and shipping configuration fixes.

The vendor excludes merchant messages and attachments, keeps agent replies and internal notes after redaction, and keeps the linked Jira issues and code changes. Conversations filed by agency partners on behalf of merchants are dropped, because the partner agreement restricts reuse. The resulting package shows each problem through the vendor's tags and each resolution through the vendor's own words.

Checklist before treating ticket content as licensable#

The checklist below turns the ownership split into decisions a support operations lead and counsel can sign off together. Work through it once per contract generation, not once per ticket.

  • Read the customer terms for the license the vendor receives in submitted content and the purposes it covers.
  • Check the privacy notice and DPA for statements about secondary use or AI training.
  • Confirm that outsourced support agreements assign agents' work product to the company.
  • Pull the exclusion list of customers with no-training clauses and drop their tickets entirely.
  • Separate vendor-written replies and notes from customer messages and attachments using help desk fields.
  • Plan redaction of personal and customer-identifying details in every component that stays in scope.

How SourceX approaches support ticket rights#

SourceX reviews support records component by component in Rights, the second stage of the SourceX five-step transaction, before Preparation begins. The SourceX Evidence Packet then records which components were licensed, the rights relied on for each, the redaction applied in the privacy record and the supplier's release authorization.

Frequently asked questions

Does the help desk vendor have any rights in our tickets?

Help desk platforms generally process ticket content on the subscriber's behalf and do not take ownership of it. Their terms may still allow limited uses, such as service analytics or optional AI features, so review the platform's current terms and your admin settings before relying on that assumption.

Do we own replies written by an AI chatbot in our help desk?

Bot replies raise their own authorship questions, because text generated with little human input may receive little or no copyright protection under US law. The vendor usually controls them contractually, but they show the bot's behavior rather than human expertise, so it is sensible to separate them from agent replies in any package.

Can a customer's deletion request remove agent replies too?

It can, depending on the contract. Some agreements define customer data broadly enough to include the whole ticket, while privacy laws may require deleting personal data wherever it appears, including in replies. Vendor-written content with no personal data is more likely to survive a deletion request.

Are support call recordings treated like written tickets?

The ownership logic is similar, but recordings add voice data and recording consent rules that may apply in some states. Transcripts of calls carry both parties' words in one stream, so splitting them by speaker and redacting personal details takes more care than written tickets.

Does a premium support contract change who owns the replies?

Usually not. Premium support changes service levels, not authorship. Some enterprise agreements do treat deliverables, such as custom configuration guides written for the customer, as customer property, so check for work product clauses in high-touch support contracts.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify