Gitlab hero border pattern left svg Gitlab hero border pattern right svg

The GitLab Legal Team

Welcome to GitLab Legal!

We are glad you are here! Meet our team

1. Quick Questions

You can reach out to the Legal Team on the #legal Slack chat channel. The legal Slack chat channel is reserved for everyday legal questions that can be answered in informal communication. It is not for requests that require legal advice, deliverables, discussion of confidential information.

Please do not share confidential information on Slack that is not meant for the entire company to see, and do not use it to seek legal advice.

2. Requests with Deliverables

If you are making a request that requires some sort of deliverable, please use the list below to determine how you should reach out. If you are unsure where your non-Slack request fits, refer to no. 5 below.

How do I request the services I need?

1. Vendor Contracts

If you are looking for a new vendor, need an NDA for a new vendor, or need review of a vendor contract, these services are now handled by the Procurement Team. Legal will be brought in by Procurement for escalations only. Please see the Procurement Page for more information on the Vendor Management Process. Once a Vendor NDA and/or Contract has been completed, it should be uploaded by the requestor into our contract management database tool ContractWorks. If you need a license, you will need to submit an Access Request.

A presentation overview of the process to engage GitLab Legal can be found HERE

A video tutorial can be found HERE

3. Requests for Insurance Certificate

If you need an insurance certificate (other than for worker's compensation) you can send an email request directly to our insurance broker at ABD. You will need to include contact information for the customer seeking to be added to the certificate and any other specific requirements relating to the coverage. If you require an insurance certificate for worker's compensation email: with the same information.

For a summary of GitLab's insurance coverage please refer to this link.

4. Requests Relating to Any Kind of Intellectual Property (Patents, Copyrights, Trademarks, Etc.)

If you have any questions or requests relating to the intellectual property rights of GitLab or any third party, including (but not limited to):

send all requests to the Legal email address.

For all other requests that are not Customer related, but require a deliverable such as assistance with questionnaires, internal operation matters, or compliance questions, please use the private Legal Issue Tracker by submitting your request to the Legal email address. This will send your request to the Private Legal Issue Tracker using GitLab's Service Desk functionality. Through the legal issue tracker, you will not be able to access the issue itself, but instead will be updated regarding the status of your request through email. Please be sure to include sufficient detail regarding your request, including time-sensitive deadlines, relevant documents, and background information necessary to respond. Please note that ONLY the Executive and Legal team will have access to the Legal Issue Tracker in order to maintain the confidentiality and privilege of any issues that may be discussed within the Legal Issue Tracker. For more information on Attorney-Client Privilege, see the General Topics and FAQs below.

Contract Templates

General Topics and FAQs

1. The Attorney-Client Relationship in the United States

This discussion is limited to U.S. practices because currently our team members only communicate with U.S. practicing attorneys. As we continue to grow globally we will update this and expand how privilege applies in other jurisdictions.

What is the Attorney-Client Privilege?

Attorney-Client Privilege is a law that has been adopted in each of the states of the U.S in some form. Generally, the law protects communications between clients and their attorneys for the purpose of seeking legal guidance and advice. The information is not protected if it is available from another source. Therefore, information cannot be placed under the protections of Attorney-Client privilege simply by telling your attorney or copying your attorney on a communication. In addition, the underlying facts are also not protected, only the opinions and analysis of the facts, and discussions thereof, with the attorney. The privilege belongs to the client, and therefore, can only be waived by the client.

What is Work Product?

Work Product is a U.S. doctrine in which an attorney’s notes, observations, thoughts, and research prepared by, or at the direction of an attorney, in anticipation of litigation, are protected from being discoverable during the litigation process.

What is the purpose of these Privileges?

The purpose of the Attorney-Client and Work Product privileges is to allow clients to speak freely with their attorneys and encourage full disclosure so they can receive accurate and competent legal advice without the fear of having their attorney compelled to testify against them and disclose the information shared by the client.

Who do these Privileges Apply to at GitLab?

There is not one uniform answer that covers all jurisdictions in the U.S.

A minority number of states apply the Corporate Group Test. This test is quite restrictive and only allows for the protection of corporate communications to the corporation's controlling executives and managers.

A more commonly used test is the Subject Matter Test. Instead of looking at the roles of the employees involved, this test looks at the subject matter of the employees’ communications. The test will look to see if the employee was instructed to discuss the subject matter with the attorney should be protected and if the subject matter of that communication relates to the performance by the employee of the duties of his or her employment.

A slightly modified version of the Subject Matter Test called the Upjohn Test is also widely used. Under the Upjohn Test the privilege is applied only if the following criteria are satisfied:

The Supreme Court case which established the Upjohn Test is also important because it resulted in the Upjohn Warning which is a procedure in which a company’s attorney explains that he or she does not represent the employee individually, but instead represents the interests of the company. This is important to note because a company can waive its privilege at any time, meaning the company could choose to disclose information the attorney received from a covered employee in confidence for use as evidence in a legal proceeding in order to protect the company from liability.

The Subject Matter Test and Upjohn Test are the most commonly used tests. More information about the tests can be found HERE

2. Litigation Holds

What is a Litigation Hold?

A litigation hold is the process a company uses to preserve all forms of relevant evidence, whether it be emails, instant messages, physical documents, handwritten or typed notes, voicemails, raw data, backup tapes, and any other type of information that could be relevant to pending or imminent litigation or when litigation is reasonably anticipated. Litigation holds are imperative in preventing spoliation (destruction, deletion, or alteration) of evidence which can have a severely negative impact on the company's case, including leading to sanctions.

Once the company becomes aware of potential litigation, the company's attorney will provide notice to the impacted employees, instructing them not to delete or destroy any information relating to the subject matter of the litigation. The litigation hold applies to paper and electronic documents. During a litigation hold, all retention policies must be overridden.

Important Pages Related to Legal

Performance Indicators

Triage and assign issues in the legal issue tracker to the appropriate legal team member within 24 hours of receipt, during regular business hours

All suspicious transactions are cleared, actioned, or escalated <= 1 Business Day

All suspicious transactions are cleared, actioned or escalated within 1 business day. This is tracked in Visual Compliance.

Annually review policies to ensure compliance with applicable laws, update accordingly and communicate with business = 100%

Over a rolling 12 months all policies to be reviewed and updated to be within compliance as documented on the Compliance Strategy Overview for the particular time period. All updates are communicated with business.

Audit Open Source License compliance with policy = 100%

On a monthly basis audit all new open source licenses to ensure compliance with the policy after each release. Ensure proper license types are being used

Ensure all federal government submissions, representations, and certifications are audited and accurate = 100%

Verify all federal government submissions, representations and certifications are reviewed and accurate.

Ensure all fully executed vendor contracts are in ContractWorks = 100%

Administer, maintain, and manage ContractWorks by ensuring all fully executed vendor contracts are uploaded with terms, and that all fields are complete. This will be measured on a monthly basis and the target is 100%.

Ensure all fully executed sales contracts are in the Salesforce = 100%

Administer, maintain, and manage Salesforce by ensuring all fully executed sales contracts are uploaded with terms, and that all fields are complete. This will be measured on a monthly basis and the target is 100%.

Ensure protections over corporate trademarks = 100%

File annual registrations and respond to challenges to intellectual property rights throughout the year based on registration dates of trademarks. This is tracked in Marcaria

Negotiation Cycle Average Days per Quarter <= 90 days

Average number of days on a quarterly basis in “Negotiating” of 90 days or less. This is contingent upon the updated SFDC Legal operations model. There will be a report that shows when a contract negotiation begins, and when it is closed.

Number of Opportunities closed by Contract Manager(s) per Quarter >= 66

The average number of Opportunities (with contracting needs) closed per quarter to be equal or greater than 66, with annual total of 264 per Contract Manager. This is contingent upon the number of contracts brought forward by the sales team.

Percentage of contract negotiations per quarter <=15%

This is calculated by taking the number of opportunities closed per quarter by Contracts Managers divided by the total number of opportunities closed per quarter. In the future this will be tracked in Salesforce.

Response times to initial requests for review <= 24 business hours

Monthly average response time within 24 business hours in the future this will be tracked in Salesforce for all Contract Managers.

‘Turn-Around’ times on received red-lines <= 72 business hours

Monthly average red-lines / legal answer(s) within 72 business hours in the future this will be tracked in Salesforce for all Contract Managers. This is contingent on type of Agreement (MSA vs. NDA).

Vendors and applicable commercial partners agree to Partner Code of Ethics = 100%

Strive for 100% compliance on vendors and applicable commercial partners agreeing to Partner Code of Ethics. This will be audited by Internal Audit.