diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index c3a6b2d3..18335bb2 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -32,6 +32,13 @@ Optional profiles tested: - [ ] ocr - [ ] distributed +## Contributor License + +- [ ] The `license/cla` check passes, or DataFog has documented a written + agreement/exemption for every contributor to this pull request. Any + historical contribution has a separate signed ratification, assignment, + or license documented privately. + ## Notes For Reviewers Mention API changes, migrations, warnings, or release-note needs. diff --git a/.gitignore b/.gitignore index cf11a42c..0d8a55fe 100644 --- a/.gitignore +++ b/.gitignore @@ -60,6 +60,9 @@ docs/* !docs/Makefile !docs/make.bat !docs/optional-surfaces.rst +!docs/cla-policy.md +!docs/cla-administration.md +!docs/cla-historical-ratification.md !docs/agents/ !docs/agents/** !docs/audit/ diff --git a/CLA.md b/CLA.md new file mode 100644 index 00000000..07558f81 --- /dev/null +++ b/CLA.md @@ -0,0 +1,196 @@ +# DataFog Individual Contributor License Agreement + +Version 1.0 + +Thank you for your interest in contributing to open-source projects managed by +DataFog, Inc. ("DataFog," "we," "us," or "our"). + +This Individual Contributor License Agreement (the "Agreement") documents the +rights granted by individual contributors to DataFog. It is a legally binding +agreement, so please read it carefully before accepting it. + +This Agreement covers contributions to public software, documentation, and +other open-source projects owned or managed by DataFog, including projects in +the [`DataFog` GitHub organization](https://github.com/DataFog) that reference +this Agreement (collectively, the "Projects"). You need to accept this Agreement +only once unless DataFog publishes a new version and asks you to accept it. +Acceptance is prospective: this Agreement applies only to Contributions You +Submit on or after the Effective Date. It does not grant rights in, or +otherwise govern, Contributions submitted before that date. Historical +Contributions require a separate signed historical ratification, intellectual +property assignment, or license that identifies the covered work; a later +acceptance of this Agreement is not that separate agreement. + +To accept this Agreement, follow the electronic signing instructions presented +by DataFog's designated signing workflow. The signing record will be associated +with your authenticated account. + +If an employer or another entity owns or controls the rights in your +Contribution, do not accept this individual Agreement on that entity's behalf +unless you have authority to do so. Contact +[`legal@datafog.ai`](mailto:legal@datafog.ai) for the entity contribution +process. + +## 1. Definitions + +"You" means the individual who Submits a Contribution to us. + +"Contribution" means any work of authorship that is Submitted by You to us in +which You own or assert ownership of the Copyright. + +"Copyright" means all rights protecting works of authorship owned or controlled +by You, including copyright, moral, and neighboring rights, as appropriate, for +the full term of their existence, including any extensions controlled by You. + +"Material" means the software, documentation, or other work that we make +available to third parties as part of a Project. After You Submit a +Contribution, it may be included in the Material. + +"Submit" means any form of electronic, verbal, or written communication sent to +us or our representatives for the purpose of discussing or improving a Project, +including communications through source-code control systems and issue trackers +managed by or on behalf of us. Communications conspicuously marked or otherwise +designated in writing as "Not a Contribution" are excluded. + +"Submission Date" means the date on which You Submit a Contribution to us. + +"Effective Date" means the date You electronically accept this Agreement. + +"Historical Contribution" means a Contribution You Submitted before the +Effective Date. + +"Media" means any portion of a Contribution that is not software. + +## 2. Grant of Rights + +### 2.1 Copyright License + +For each Contribution to which this Agreement applies, You retain ownership of +the Copyright in Your Contribution and have the same +rights to use or license the Contribution that You would have had without +entering into this Agreement. + +To the maximum extent permitted by applicable law, You grant to us a perpetual, +worldwide, non-exclusive, transferable, royalty-free, irrevocable license under +the Copyright covering the Contribution, with the right to sublicense those +rights through multiple tiers of sublicensees, to reproduce, prepare derivative +works of, modify, display, perform, and distribute the Contribution as part of +the Material, subject to Section 2.3. + +### 2.2 Patent License + +For each Contribution to which this Agreement applies, and for patent claims, +including method, process, and apparatus claims, that You own, control, or have +the right to grant now or in the future, You grant to us a +perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable +patent license, with the right to sublicense through multiple tiers of +sublicensees, to make, have made, use, sell, offer for sale, import, and +otherwise transfer the Contribution and the Contribution in combination with +the Material or portions of that combination. This license applies only to the +extent that exercising the licensed rights infringes those patent claims and is +subject to Section 2.3. + +### 2.3 Outbound Licensing + +If we include Your Contribution in Material, we may license the Contribution +under any license, including copyleft, permissive, commercial, or proprietary +licenses. As a condition of exercising this right, we also agree to license the +Contribution under the license or licenses that we were using for the Material +on the Submission Date. + +We may license Media in a Contribution under the license used for the relevant +Project, a Creative Commons license, or another license that permits use of the +Media with the Project. + +### 2.4 Moral Rights + +If moral rights apply to the Contribution, to the maximum extent permitted by +law, You waive and agree not to assert those rights against us, our successors +in interest, or our direct or indirect licensees. + +### 2.5 Our Rights + +You acknowledge that we are not obligated to use Your Contribution and may +decide whether to include it in a Project. + +### 2.6 Reservation of Rights + +You reserve all rights not expressly licensed under this Section 2. + +## 3. Your Representations + +You confirm that: + +1. You have the legal authority to enter into this Agreement. +2. You own, or have sufficient authority to license, the Copyright and patent + claims covering the Contribution as required to grant the rights in Section 2. +3. The grant of rights in Section 2 does not violate rights You have granted to + third parties, including Your employer. If Your employer or another entity + may own rights in Your Contribution, You have obtained permission to make the + Contribution or that entity has completed DataFog's entity contribution + process. +4. Each Contribution is Your original creation, except for third-party material + that You clearly identify along with its source and applicable license or + other restrictions. +5. You will notify us of any facts or circumstances You become aware of that + would make these representations inaccurate. +6. If You are under eighteen years old, You will contact DataFog before + accepting this Agreement and will follow any guardian-approval process + required by DataFog. + +## 4. Disclaimer + +EXCEPT FOR THE EXPRESS REPRESENTATIONS IN SECTION 3, THE CONTRIBUTION IS +PROVIDED "AS IS." TO THE MAXIMUM EXTENT PERMITTED BY LAW, YOU DISCLAIM ALL +EXPRESS OR IMPLIED WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS +FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. TO THE EXTENT A WARRANTY +CANNOT BE DISCLAIMED, IT IS LIMITED TO THE MINIMUM DURATION PERMITTED BY LAW. + +## 5. Consequential Damage Waiver + +TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, YOU WILL NOT BE LIABLE FOR +LOST PROFITS, LOST ANTICIPATED SAVINGS, LOST DATA, OR INDIRECT, SPECIAL, +INCIDENTAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES ARISING OUT OF THIS AGREEMENT, +REGARDLESS OF THE LEGAL OR EQUITABLE THEORY ON WHICH THE CLAIM IS BASED. + +## 6. Miscellaneous + +1. This Agreement is governed by the laws of the State of Delaware, excluding + its conflict-of-law provisions. The United Nations Convention on Contracts + for the International Sale of Goods does not apply. +2. This Agreement is the entire agreement between You and us concerning Your + Contributions and supersedes prior agreements or understandings concerning + those Contributions, except for a separate written agreement that DataFog + has documented as governing a specific Contribution. +3. If You or we assign rights or obligations under this Agreement to a third + party, that third party must agree in writing to abide by this Agreement. +4. A failure by either party to require performance of a provision in one + situation does not waive the right to require performance later. +5. If a provision is found void or unenforceable, it will be replaced to the + extent possible by an enforceable provision closest to its original meaning, + and the remaining provisions will continue in effect. +6. Electronic acceptance through DataFog's designated CLA service constitutes + Your signature. The electronic record identifies the Agreement version, Your + authenticated GitHub identity, and the time of acceptance. +7. Acceptance of this Agreement does not amend, ratify, assign, or license any + Historical Contribution. Any rights in a Historical Contribution must be + documented in a separate written agreement signed by the relevant rights + holder and DataFog. + +## Contact + +DataFog, Inc.
+1209 Orange St.
+Wilmington, DE 19801, USA
+[`legal@datafog.ai`](mailto:legal@datafog.ai) + +## Template attribution + +This Agreement is adapted from the Harmony Individual Contributor License +Agreement (HA-CLA-I), Version 1.0, with Outbound License Option Five selected. +The Harmony template is licensed under the +[Creative Commons Attribution 3.0 Unported License](https://creativecommons.org/licenses/by/3.0/). +DataFog modified the template to identify the parties and Projects, support +electronic acceptance, clarify third-party submissions and entity-owned work, +and align the governing law and contact information with DataFog's published +terms. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6e7e416e..0a861c29 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -121,6 +121,24 @@ By submitting a pull request, you license your contribution under the project [license](LICENSE). You also affirm that you authored the contribution or have the right to submit it under the project license. +For a new external contribution intended to be covered by DataFog's CLA, each +contributor must accept the [DataFog Individual Contributor License +Agreement](CLA.md) before submitting it, unless DataFog has documented another +written agreement covering the contributor and contribution. The CLA applies +prospectively from its acceptance date; accepting it later does not silently +cover an earlier submission. Existing historical work requires a separate +signed ratification, assignment, or license, or must be replaced or isolated. +You retain copyright ownership; the CLA grants DataFog, Inc. broad, +non-exclusive copyright and patent rights, including the ability to use the +contribution in open-source, commercial, and proprietary distributions while +continuing to offer it under the project's license in effect when it was +submitted. + +If an employer or another entity owns or may own your contribution, contact +[`legal@datafog.ai`](mailto:legal@datafog.ai) before signing or submitting it. +See the [CLA policy](docs/cla-policy.md) for signing, exemptions, and entity-owned +contributions. + ## Contributors Thanks to early contributors including: diff --git a/docs/cla-administration.md b/docs/cla-administration.md new file mode 100644 index 00000000..0c365fa0 --- /dev/null +++ b/docs/cla-administration.md @@ -0,0 +1,90 @@ +# CLA Administration Runbook + +This runbook describes the rollout and ongoing administration of DataFog's +Contributor License Agreement (CLA). The legal text and interim contribution +records should receive later legal review when available, especially before +relying on them for a material ownership or relicensing decision. + +## Signing workflow + +Use the designated CLA or electronic-signature workflow approved by DataFog's +counsel. Keep the provider choice and implementation details separate from the +legal meaning of the agreement. The reviewed [`CLA.md`](../CLA.md) in this +repository is the source text for the published agreement. Treat each +substantive text change as a new agreement version and determine whether +contributors must sign again. + +## Pilot rollout + +1. Obtain legal approval for `CLA.md`, including the entity name, Delaware law, + patent grant, and Outbound License Option Five. +2. Publish the approved `CLA.md` through the designated signing workflow and + link it to `DataFog/datafog-python`. +3. Configure exemptions only for verified DataFog personnel and trusted bot + accounts. At minimum, review Dependabot, Renovate, release automation, and + any account that commits generated changes. +4. Open a pull request from a non-member test account and verify that the + workflow requests acceptance, ties the record to the authenticated account, + exposes a reviewable pass/fail result, and rechecks newly added authors. + Confirm that the acceptance timestamp is earlier than the test submission. +5. In branch protection for `dev`, require the workflow's coverage check when + available. Apply the rule to administrators if the policy is intended to be + non-bypassable. +6. Verify bot and internal-member pull requests pass using documented + exemptions. +7. Merge the policy change only when the signing flow, prospective-date check, + and required coverage check have all been tested. + +## Organization rollout + +DataFog currently uses GitHub Free, so organization-wide rulesets are not +available. Repeat the following for every active public repository: + +1. Confirm its license, default branch, and contribution guide. +2. Add links to the organization CLA and CLA policy. +3. Enable the designated signing workflow using the same agreement version. +4. Protect the default branch and require the workflow's coverage check before + merge. +5. Test an external pull request and an exempt bot pull request. +6. Record the repository, protected branch, activation date, agreement version, + exemptions, and test pull request in the rollout inventory. + +If DataFog upgrades to GitHub Team or Enterprise, replace per-repository status +configuration with an organization ruleset targeting the default branches of +the covered public repositories. + +## Historical contributions + +The public CLA is prospective and does not cover a contribution submitted +before the contributor accepted it. Before relying on broader rights for +historical code: + +1. inventory historical commits and pull requests by non-DataFog contributors; +2. distinguish original contributions from mechanical or third-party changes; +3. identify the actual rights holder and any employer or entity owner; +4. prepare a separate written historical ratification/IP assignment/license + that lists the covered project, files, commits, pull requests, or other + submissions; and +5. obtain signatures from DataFog and every required rights holder, or replace + or isolate code where coverage cannot be obtained. + +The repository's [historical ratification template](cla-historical-ratification.md) +is an interim starting point only. It is not an executed agreement and must not +be used as evidence of coverage until completed and signed. If an existing +advisor or contractor agreement covers the work, use a signed scope-confirming +addendum instead of duplicating it with a historical ratification. + +## Records and continuity + +- Export the signature and agreement-version records at least quarterly and + after every agreement update. +- Store exports in access-controlled company storage, not in a public + repository, and do not publish a public contributor-status list. +- Keep at least two DataFog administrators able to manage the integration and + its signing workflow. +- Review exemptions quarterly and remove stale accounts. +- Re-run the external-contributor test after changes to the CLA integration, + branch protection, repository ownership, or default branch. +- Document any manual entity CLA, contract-coverage confirmation, historical + ratification, or special authorization in the same access-controlled legal + record system. diff --git a/docs/cla-historical-ratification.md b/docs/cla-historical-ratification.md new file mode 100644 index 00000000..ac94dbef --- /dev/null +++ b/docs/cla-historical-ratification.md @@ -0,0 +1,150 @@ +# Historical Contribution Ratification, IP Assignment, and License + +> **Interim template only — not an executed agreement.** Complete the +> placeholders, confirm the actual rights holders, and obtain all required +> signatures before relying on this document. Keep completed copies private and +> obtain legal review later, especially before a material ownership or +> relicensing decision. + +This Historical Contribution Ratification, IP Assignment, and License +("Agreement") is entered into as of **[DATE]** by and among: + +- **DataFog, Inc.**, a Delaware corporation ("DataFog"); +- **[INDIVIDUAL CONTRIBUTOR FULL LEGAL NAME]**, located at **[ADDRESS]** + ("Contributor"); and +- **[ENTITY FULL LEGAL NAME]**, a **[JURISDICTION AND ENTITY TYPE]**, if any, + located at **[ADDRESS]** ("Entity Owner"). If no entity owns or controls any + covered rights, write **[NONE]** and delete the Entity Owner signature block. + +## 1. Purpose and historical scope + +The parties intend this separate Agreement to document rights in Contributions +that were submitted before acceptance of DataFog's public Individual +Contributor License Agreement. The public CLA does not retroactively cover +those Contributions. This Agreement covers only the work specifically listed +in **Schedule A** and no other work is included by implication. + +Schedule A must identify, as applicable: + +- Project and repository: **[PROJECT / REPOSITORY / BRANCH]** +- Covered submission period: **[START DATE]** through **[END DATE]** +- Files, documentation, or other materials: **[EXPLICIT FILE OR MATERIAL LIST]** +- Commits: **[FULL COMMIT SHA — SUBJECT / TITLE — DATE]** +- Pull requests or issues: **[NUMBER AND URL — TITLE — DATE]** +- Other submission identifiers: **[EXPLICIT LIST OR NONE]** + +The parties should attach additional pages if needed. A contributor name, +repository, or date range alone does not expand the covered scope beyond the +items expressly listed above. + +If an existing advisor, contractor, or consulting agreement already covers the +work, use a signed amendment or scope confirmation to that agreement instead +of duplicating it here. This template is for historical work that is not +already covered by a written agreement. + +## 2. Ownership and authority representations + +Each signatory represents, as to the rights and Contributions within that +signatory's responsibility, that: + +1. it has authority to enter into this Agreement; +2. it owns or controls the rights it assigns or licenses below, or has obtained + all permissions necessary to grant them; +3. no employer, client, joint author, assignee, or other entity has a superior + or conflicting claim, except as disclosed here: **[DISCLOSURES OR NONE]**; +4. the listed Contributions are original to the relevant rights holder except + for third-party material identified here with its source and applicable + terms: **[THIRD-PARTY MATERIAL OR NONE]**; and +5. the rights granted below do not knowingly violate a prior assignment, + license, confidentiality obligation, or other restriction. + +If Entity Owner is listed, Contributor represents that Entity Owner owns or +controls the applicable rights, and Entity Owner represents that Contributor +is authorized to make the representations and sign on its behalf. If another +person or entity owns any listed right, that rights holder must be added as a +party and sign this Agreement. + +## 3. Rights granted or assigned + +Choose one rights option and delete the unused options before signature. For an +interim self-managed contribution confirmation, Option B is the default because +it is consistent with DataFog's public CLA. Use Option A only if the parties +intentionally want to transfer ownership. + +### Option A — Assignment + +Contributor and, if applicable, Entity Owner hereby assign to DataFog all of +their right, title, and interest in the Copyright and other assignable +intellectual-property rights in the Contributions listed in Schedule A, +including the right to sue for past, present, and future infringement, to the +extent permitted by law. **[COUNSEL TO COMPLETE ANY EXCLUSIONS, CONSIDERATION, +MORAL-RIGHTS LANGUAGE, OR REQUIRED LOCAL-LAW TERMS.]** + +### Option B — License + +Contributor and, if applicable, Entity Owner grant DataFog a perpetual, +worldwide, non-exclusive, transferable, royalty-free, irrevocable license, +with the right to sublicense through multiple tiers, under the Copyright and +any patent claims covering the Contributions, to reproduce, prepare derivative +works of, modify, display, perform, use, make, have made, sell, offer for sale, +import, and distribute the Contributions listed in Schedule A, including as +part of open-source, commercial, or proprietary materials. To the maximum +extent permitted by law, Contributor waives and agrees not to assert applicable +moral rights against DataFog and its licensees. + +### Option C — Other approved treatment + +**[OTHER AGREED ASSIGNMENT, LICENSE, CONFIRMATION, OR LIMITATION.]** + +## 4. No broader ratification + +Except for the rights expressly assigned, licensed, or confirmed above, each +party reserves its rights. This Agreement does not cover unlisted commits, +pull requests, files, or other Contributions, and it does not waive a claim or +approve third-party material unless expressly stated in the completed version. + +## 5. Governing terms + +This Agreement is governed by Delaware law, excluding its conflict-of-law +provisions. It is the entire agreement concerning the Contributions listed in +Schedule A and may be signed in counterparts and electronically. A separate +written agreement that DataFog has documented as governing a specific +Contribution remains controlling for that Contribution. + +## Schedule A — Covered historical Contributions + +| Type | Identifier / URL / full SHA | Project or repository | Date | Files or scope | Notes | +| -------------------------------- | --------------------------- | --------------------- | ---------- | -------------- | ----------- | +| **[commit/PR/issue/file/other]** | **[VALUE]** | **[VALUE]** | **[DATE]** | **[VALUE]** | **[VALUE]** | +| **[add rows as needed]** | | | | | | + +## Signatures + +By signing, each signatory confirms that it has reviewed the completed +Agreement and is signing only for the party and rights stated below. + +**DataFog, Inc.** + +Signature: ____________________________________ Date: **[DATE]** + +Name: **[PRINTED NAME]** + +Title: **[TITLE]** + +**Contributor** + +Signature: ____________________________________ Date: **[DATE]** + +Name: **[PRINTED FULL LEGAL NAME]** + +Email: **[EMAIL]** + +**Entity Owner, if applicable** + +**[ENTITY FULL LEGAL NAME]** + +Signature: ____________________________________ Date: **[DATE]** + +Name: **[PRINTED NAME]** + +Title and authority: **[TITLE / AUTHORITY]** diff --git a/docs/cla-policy.md b/docs/cla-policy.md new file mode 100644 index 00000000..a07b1f60 --- /dev/null +++ b/docs/cla-policy.md @@ -0,0 +1,116 @@ +# Contributor License Agreement Policy + +DataFog uses a Contributor License Agreement (CLA) to keep the origin and +licensing of external contributions clear across its open-source projects. + +## What contributors grant + +Contributors keep ownership of their work. By signing the +[DataFog Individual Contributor License Agreement](../CLA.md), an individual +grants DataFog, Inc. a broad, non-exclusive copyright and patent license. The +agreement allows DataFog to: + +- continue distributing the contribution under the open-source license in use + by the project when the contribution was submitted; +- use and sublicense the contribution in other open-source, commercial, or + proprietary distributions; and +- maintain, enforce, and evolve the project without seeking a new signature for + each contribution. + +The CLA does not transfer copyright ownership to DataFog. + +## Coverage and signing + +An individual must accept the current CLA before submitting a contribution +that is intended to be covered by it. The CLA's effective date is the +acceptance date; submitting first and signing later does not silently create +retroactive coverage. A new signature may be required if DataFog publishes a +new agreement version. + +An individual should accept the CLA only if they own the contribution or have +authority to grant the rights in it. If an employer or another entity owns or +may own the work, use the entity-owned or contract-covered workflow below. + +Maintainers must not merge an external contribution unless the individual CLA +was accepted before submission, another written agreement covers the specific +contribution, or a separate historical ratification/IP assignment/license has +been signed and documented. A workflow status is evidence of process, not a +substitute for checking who owns the work. + +## Contributor and maintainer workflow + +### Individual-owned contribution + +1. The contributor reviews and accepts the current CLA through DataFog's + designated signing workflow before opening the pull request or otherwise + submitting the contribution. +2. The contributor identifies third-party material and applicable restrictions + in the pull request. +3. The maintainer confirms that the acceptance record predates the submission, + verifies any third-party notices, and records the agreement version and + acceptance date in the private CLA records. +4. The maintainer merges only after the coverage check passes. + +### Entity-owned contribution + +1. The contributor tells the maintainer before submission or merge if an + employer or other entity owns or may own the contribution. +2. The maintainer pauses the merge and contacts + [`legal@datafog.ai`](mailto:legal@datafog.ai) for the entity contribution + process. +3. The entity, through an authorized representative, signs the applicable + entity CLA or other written authorization before the contribution is merged. +4. The maintainer records the entity, signatory authority, covered project or + contribution, agreement version, and dates privately; an individual CLA is + not treated as covering entity-owned work unless the written agreement says + so. + +### Contract-covered contribution + +1. The contributor identifies any employment, contractor, consulting, or other + intellectual-property agreement that may cover the contribution. +2. The maintainer obtains confirmation from DataFog's authorized legal or + administrative contact that the agreement covers the relevant rights and + project. Do not request or store more confidential contract text than is + necessary to verify coverage. +3. The maintainer records the agreement reference, rights holder, covered + scope, and confirmation date in private records and marks the pull request + as covered under that agreement. + +For an active advisor or contractor relationship that is being updated, use a +short signed interim IP addendum before continuing new or deferred work. The +addendum should identify the prior, current, and future service scope, the +effective date, any pre-existing or third-party material, and the rights +holder. Fold it into the amended or restated service agreement later. Do not +require the individual CLA for work covered by the service agreement, but do +not treat an unsigned agreement discussion as coverage. + +### Contribution submitted before CLA acceptance + +The public CLA does not retroactively cover a prior submission. Before merge, +DataFog must either obtain a separate signed historical ratification/IP +assignment/license from the relevant rights holder, or replace or remove the +uncovered material. The [historical ratification template] +(cla-historical-ratification.md) is an interim starting point only and must not +be treated as executed until completed and signed. + +## Agreement and signature records + +The agreement is versioned. DataFog retains or exports records sufficient to +identify the signer, agreement version, acceptance time, authenticated account, +and the covered project or contribution where needed. Store these records, +entity authorizations, contract-coverage confirmations, and historical +ratifications in access-controlled private company storage. Do not publish a +contributor signature list, public coverage roster, private contract text, or +historical ratification in the repository. + +Requests concerning a signature record or the CLA should be sent to +[`legal@datafog.ai`](mailto:legal@datafog.ai). + +## Existing contributions + +Existing contributions remain governed by the licenses and agreements in effect +when they were submitted. If DataFog needs broader rights to an existing +external contribution, it must obtain those rights through a separate signed +historical ratification/IP assignment/license from the relevant rights holder, +or replace or isolate the contribution.