These terms of service (the “Terms”) govern access to and use of the CodeQuay platform, provided by arimaslab srl. You accept them by ticking the dedicated box when you create an account or subscribe to a paid plan; the accepted version, the date, the IP address and the browser used are recorded. This is version 1.0.
1. Provider and definitions
The service is provided by arimaslab srl, VAT no. IT02039300666, share capital €10,000 fully paid-up, registered office Via Tiburtina snc, 67061 Carsoli (AQ), Italy, email info@arimaslab.com (the “Provider”). In these Terms:
- Service: the CodeQuay platform (git repositories over HTTPS and SSH, web console, API, issues, merge
requests, CI/CD with CodeQuay Actions, package registries, Pages and the other features available in the plan),
reachable at
git.codequay.it, and the support included in the plan; - Customer: whoever creates an account or subscribes to a plan, for themselves or for the organization they represent; User: every person who uses the Service with an account, including as an invited member of a Customer's space;
- Space: an organization or a User's personal space, to which a plan applies; Owner: a person with the owner role in an organization, or the holder of a personal space;
- Customer Content: everything the Customer and its Users upload to or generate in the Service (code and git history, issues, comments, wikis, packages, pipeline artifacts and logs, secrets, configurations);
- DPA: the data processing agreement (GDPR Article 28); Agreement: these Terms, the DPA and any order form or custom contract.
2. Conclusion of the Agreement
- The Agreement is concluded when the Provider creates the account after the Customer has ticked the box accepting the Terms and the DPA. Subscribing to a paid plan requires accepting them again, by the Owner who starts the payment, for the Space concerned.
- Whoever accepts on behalf of an organization declares that they have the authority to bind it: in that case the Customer is the organization. Users must be of legal age and able to enter into contracts.
- The Terms and the DPA can always be consulted on this website, with their version number and date, and can be saved or printed. A custom contract (for example for the Sovereign plan) prevails over the Terms where it expressly departs from them.
3. Professionals and consumers
- The Free plan is available to anyone, including for personal projects. Paid plans are reserved for those acting for purposes relating to their trade, business, craft or profession: whoever subscribes to one declares that they act for such purposes and provides the billing details of the business or professional.
- If the User is a consumer within the meaning of Italian Legislative Decree no. 206 of 6 September 2005 (Consumer Code), all the rights that the law grants them and that cannot be excluded or limited by contract remain unaffected, including the protections on the conformity of digital services and the consumer's forum (section 23). The clauses of these Terms that limit the Provider's liability, provide for an indemnity or allow unilateral changes apply to consumers only to the extent permitted by those rules.
- Consumers can stop using the Service and ask for their account to be closed at any time, free of charge (section 19). If a consumer nevertheless subscribes to a paid plan, the mandatory rules of the Consumer Code apply, including the right of withdrawal in the cases and within the time limits they provide.
4. The Service
- The features of the Service are described on this website and in the console documentation. The Provider may update and improve them; it does not substantially reduce the essential features of a paid plan during a period already paid for, except for security or legal reasons.
- Features marked “Coming soon”, preview or experimental are not a commitment as to date or manner of release and may change or be withdrawn.
- Some features are enabled only by the Customer's choice and use third-party services, such as the AI review of merge requests (section 14). The Sovereign plan, with a dedicated instance in the EU or on the Customer's premises, is governed by a custom contract.
5. Plans, prices and usage
- The plans are Free, Team, Business and Sovereign. Prices are in euros, excluding VAT, per user per month or per year, and are published on the Pricing page: those in force when you subscribe or renew apply. Summary as of the date of this page, from the same source as the Pricing page:
| Plan | Price (excluding VAT) | Included storage | Minutes a month on CodeQuay runners | Minutes beyond the allowance | Dedicated runner managed by us | Support |
|---|---|---|---|---|---|---|
| Free | €0 | 5 GB | 2,000 | Not included | Not included | Documentation |
| Team | €6 per user per month, or €60 per user per year (2 months free) | 50 GB | 3,000 | €0.005 per minute | €29 a month or €290 a year | |
| Business | €18 per user per month, or €180 per user per year (2 months free) | 250 GB | 25,000 | €0.005 per minute | €29 a month or €290 a year | Priority |
| Sovereign | Custom quote | Custom | Custom | Custom | Custom | Dedicated, with a named contact |
- Monthly or annual billing. Paid plans are paid every month or, where offered, every year; with annual billing the price of twelve months equals 10 monthly payments (2 months free), on the conditions shown on the Pricing page. Minutes beyond the allowance are always billed monthly.
- Seats. You pay one seat for each active person with access to the Space (member of the organization, of one of its projects or repositories, or holder of the personal space). Disabled accounts, pending invitations and the bots of access tokens do not count. When members change, the amount is recalculated pro rata by day and the difference goes on the next invoice; on annual billing, seats added during the year are invoiced at once, pro rata until the end of the period.
- CI/CD minutes. Every plan includes minutes per month on the runners managed by the Provider, which reset on the first day of the month. On the Free plan, once the included minutes are used up, jobs on the Provider's runners stop until the following month. On the Team and Business plans, minutes beyond the allowance are pay as you go, at the per-minute price on the Pricing page, up to the monthly spending cap set by the Owner: the cap starts at zero, so without the Owner's choice there is no charge for extra minutes. Jobs on the Customer's own (self-hosted) runners use no minutes.
- Dedicated runner. On the Team and Business plans the Owner can ask for a dedicated runner managed by the Provider: the Provider activates it on request and it costs the monthly or annual fee shown on the Pricing page, billed with the subscription for as long as it stays active.
- Storage. Every plan includes storage per Space. Beyond the quota, pushes that add data and new uploads are refused with a clear message until the storage used is back under the quota; existing content is not deleted.
- Price changes. Price changes are notified to Owners at least 30 days in advance and apply from the first billing period after the notice expires. Those who do not accept them can cancel the plan before they apply (section 7).
6. Billing and payments
- Payments are handled by Stripe, with Stripe Checkout and the Stripe portal: card, PayPal, Apple Pay, Google Pay and SEPA bank transfer, according to the methods available at the time of payment. The Provider never sees or stores the details of cards and other payment instruments. On request, and by agreement with the Provider, a Space can pay by invoice and bank transfer, by the due date shown on the invoice.
- The subscription has a monthly cycle that starts on the first day of the month: the first period is calculated pro rata. Seats and the dedicated runner are paid in advance for the period; extra minutes are billed as used on the invoice that follows.
- VAT and other taxes are added where due, based on the billing details and VAT number provided by the Customer, who is responsible for their accuracy. Invoices are available in the console, under Settings → Plan and payments.
7. Renewal, plan changes and cancellation
- Paid plans renew automatically at the end of each period (month or year), on the conditions then in force, until the Customer cancels them.
- The Owner changes plan from the console; moving to a higher plan takes effect at once, with a pro rata amount.
- Cancellation is done from the console, under Settings → Plan and payments → Manage payment and invoices, at any time, and takes effect at the end of the period already paid for. Amounts for the current period are not refunded, except as provided by law or by these Terms.
-
At the end of the period the Space goes back to the Free plan: repositories and other Customer Content stay intact
and the limits of the Free plan apply (section 5). The Customer can export its data at any time: repositories with
git clone --mirror(full history, branches and tags), everything else through the API and the console.
8. Non-payment
- If a payment fails, the Owners receive an email and a notice in the console. From then on a 14-day grace period runs, during which the plan stays active and Stripe retries the charge; the Customer can update the payment method or pay the invoice.
- If the amount is still unpaid at the end of the grace period, the subscription ends and the Space goes back to the Free plan, with its limits. Customer Content is not deleted for non-payment. Overdue amounts remain due; between businesses, late payment interest under Italian Legislative Decree no. 231 of 9 October 2002 applies.
9. Accounts and security
- Every account is personal: it belongs to one person, who provides true and up-to-date details. Automations use access tokens, not people's accounts.
- Users keep their credentials safe (passwords, passkeys, authenticator apps, SSH keys, tokens) and are responsible for what happens with them. The Service offers passkeys, two-factor authentication and tokens with a mandatory expiry: the Provider recommends using them. Any suspected unauthorized access must be reported without delay to security@codequay.it.
- Owners decide who accesses their Spaces and with which roles, and are responsible for the permissions they grant and the integrations they configure (webhooks, mirrors, self-hosted runners, deployment environments).
10. Acceptable use
The Customer and its Users do not use the Service to:
- host or distribute malware, or code designed to harm systems, data or people, or to access third-party systems without authorization; attack, probe or overload the Service or third-party systems without authorization;
- host or disseminate unlawful content, including content that infringes intellectual property rights, trade secrets, confidentiality or third parties' personal data;
- use CI/CD resources for purposes unrelated to developing, testing and releasing software, in particular for cryptocurrency mining, distributed computing on behalf of others, or proxying or anonymizing traffic;
- send spam or unsolicited communications, including through notifications, invitations or webhooks;
- circumvent quotas, plan limits, security or isolation measures, including by opening several accounts or Spaces to multiply free resources.
- Secrets. The Service checks pushes and blocks those that contain recognizable credentials (private keys, cloud access keys, tokens): the check helps but does not replace the Customer's care. The Customer must not keep secrets in code and, if it publishes one, revokes and replaces it.
- Measures. In case of a breach, or of a concrete risk to the security of the Service, of other customers or of third parties, the Provider may, proportionately: stop jobs and pipelines, refuse pushes, make content inaccessible or remove it, limit or suspend accounts and Spaces. It informs the Customer of the measure and its reasons, unless urgency or the law prevents it, and lets the Customer remedy where possible. Serious or repeated breaches are grounds for termination (section 19).
- Notices. Anyone can report content they consider unlawful to info@arimaslab.com, stating the content and the reasons; security vulnerabilities are reported to security@codequay.it. The Provider handles notices in accordance with Regulation (EU) 2022/2065 on digital services, insofar as it applies.
11. Customer Content
- Customer Content remains the Customer's (or its licensors'). The Provider does not acquire ownership of it.
- For the term of the Agreement and the deletion period in section 19, the Customer grants the Provider a non-exclusive, royalty-free, non-transferable licence limited to what is needed to provide the Service: storing, copying (backups included), processing, indexing for search, running the configured pipelines, showing content to authorized Users and transmitting it to the DPA's sub-processors and to the destinations configured by the Customer. The Provider does not sell Customer Content, does not use it for advertising and does not use it to train artificial intelligence models.
- Content the Customer chooses to make public (for example public snippets or public Pages sites) is visible to anyone.
- The Customer warrants that it holds the rights needed for Customer Content, including compliance with third-party software licences, and that processing it under the Agreement does not infringe others' rights.
12. Personal data
For the personal data in Customer Content and in its Users' accounts, the Customer is the controller and the Provider is the processor: the DPA applies and forms an integral part of the Agreement. The Provider processes, as an independent controller, the data needed for billing and its own legal obligations, and the data of website visitors, as described in the privacy policy.
13. Availability, maintenance and support
- The Provider uses professional diligence to keep the Service available and secure: nightly backups, restores tested every week, automated checks and monitoring with alerts. No SLA is offered at present: the Provider does not guarantee an availability percentage and does not grant service credits, unless agreed otherwise in a custom contract.
- Maintenance and updates may make the Service temporarily unavailable. The Provider schedules them to reduce their impact and, where possible, announces them; urgent security work may take place without notice.
- Support depends on the plan: documentation for the Free plan, email for Team, priority support for Business, a dedicated contact for Sovereign. Response times are not guaranteed, unless agreed in a custom contract. Security reports are welcome on any plan.
14. Third-party services and integrations
At the choice of the Customer or the User, the Service connects to third-party services: sign-in with Google, Microsoft, Apple, LinkedIn or the organization's identity provider, import and mirroring to GitHub, webhooks, self-hosted runners, AI review (active only on repositories where the Customer enables it), payments with Stripe. Those services have their own terms, which the Customer accepts directly with their providers; the Provider is not responsible for their availability or conduct, without prejudice to its obligations regarding the sub-processors under the DPA.
15. Intellectual property
- The Service, the software, the documentation, and the CodeQuay name and logo belong to the Provider or its licensors. For the term of the Agreement, the Customer receives a non-exclusive, non-transferable right to use the Service in accordance with these Terms.
- Decompiling or copying the software of the Service is not allowed, except to the extent the law expressly permits it. Open source components remain governed by their own licences.
- Suggestions and proposals sent to the Provider may be used freely to improve the Service, with no obligation to whoever sent them.
16. Warranties
The Provider warrants that the Service substantially matches the description on the website and in the documentation and that it is provided with professional diligence. Beyond that, and to the extent permitted by law, the Service is provided “as is” and “as available”: the Provider does not warrant that it is error-free or uninterrupted, or that it is fit for particular purposes of the Customer not stated in the description. The Customer remains responsible for assessing whether the Service meets its own obligations, regulatory ones included. Warranties that the law grants to consumers on a mandatory basis are unaffected.
17. Limitation of liability
- The Provider is not liable for indirect or consequential damages, loss of profit, loss of business opportunities or goodwill.
- For paid plans, the Provider's total liability to the Customer, for all events in a year, does not exceed the amounts paid by the Customer for the Space concerned in the 12 months before the event that caused it. For the Free plan, offered free of charge, the Provider is liable only for wilful misconduct or gross negligence.
- These limitations do not apply in case of wilful misconduct or gross negligence (Article 1229 of the Italian Civil Code), to personal injury and in the other cases in which the law does not allow liability to be limited; they do not apply to consumers beyond what the Consumer Code allows. Liability for the processing of personal data also remains governed by the DPA and by Article 82 GDPR.
18. Indemnity
A Customer acting as a professional indemnifies the Provider against third-party claims, and the related reasonable costs, arising from Customer Content or from use of the Service in breach of these Terms or of the law by the Customer or its Users. The Provider informs the Customer of the claim without delay and allows it to take part in the defence.
19. Term, withdrawal and data deletion
- The Agreement is for an indefinite term; paid plans last for the billing period and renew as provided in section 7.
- The Customer may withdraw at any time: by cancelling paid plans (effective at the end of the period) and by asking for the account to be closed and the data deleted through the contact page or at privacy@codequay.it.
- The Provider may withdraw with at least 30 days' notice to the Owners; for a paid plan, withdrawal takes effect no earlier than the end of the period already paid for. It may also terminate the Agreement with immediate effect, by written notice, in case of a serious or repeated breach of section 10, false account details, or use of the Service that exposes the Provider, other customers or third parties to a concrete risk.
- At the end of the Agreement, access to the Service ends. For 30 days the Customer may ask for help exporting its data; then, as provided in section 6 of the DPA, Customer Content is deleted from production systems within 30 days of the end of the Service or of the request, whichever is later, and disappears from the encrypted backups through their normal rotation, within 12 months at the latest. Data the law requires to be kept (for example tax records) and the audit log within the limits of the DPA remain.
- Amounts accrued until the end of the Agreement remain due. Sections 11 (for the deletion period), 15, 17, 18, 19 and 23 continue to apply after the end of the Agreement.
20. Notices
The Provider communicates with the Customer at the account's email address and, for matters concerning a Space, at the Owners' addresses, as well as through notices in the console. The Customer writes to the Provider at the addresses in section 25. The Customer keeps its email address up to date.
21. Changes to the Terms
- The Provider may change these Terms for justified reasons: changes in the law or in the guidance of the authorities, evolution of the Service, security, new features or plans. Each version has a number and a date, shown at the top of the page.
- Changes are notified by email and with a notice in the console at least 30 days before they take effect. From the effective date the console asks you to accept the new version before continuing; use of the Service with tokens and git is not interrupted.
- Those who do not accept the changes may withdraw without penalty before they take effect (section 19); for a paid plan, the previous version continues to apply until the end of the current period. Changes required by law or needed for security may take effect earlier; changes that are solely to the Customer's benefit take effect at once. Changes to the DPA follow its section 9.
22. Force majeure
Neither party is liable for a failure to perform caused by events beyond its reasonable control (for example widespread failures of networks or of energy and infrastructure providers, large-scale cyber attacks, orders of the authorities, natural disasters), for as long as they last and to the extent they prevent performance. Payments for the Service already provided remain due.
23. Governing law and jurisdiction
- The Agreement is governed by Italian law.
- Disputes with Customers acting as professionals fall within the exclusive jurisdiction of the court of the place where the Provider has its registered office (Carsoli, AQ).
- Disputes with consumers fall within the jurisdiction of the court of the consumer's place of residence or domicile (Article 66-bis of the Consumer Code); a consumer resident in another country of the European Union keeps the protection of that country's mandatory rules.
24. Final provisions
- The Agreement is the entire agreement between the parties on the Service and supersedes previous understandings on the same subject. In case of conflict, the following prevail, in this order: the custom contract, the DPA (for the protection of personal data), these Terms.
- If a clause is invalid or unenforceable, the others remain valid. Failure to exercise a right is not a waiver.
- The Customer may not assign the Agreement without the Provider's written consent. The Provider may assign it to a company of its group or to a successor in the business relating to the Service, informing the Customer.
- These Terms are drawn up in Italian; the English version is a courtesy translation and, in case of discrepancies, the Italian version prevails.
- Pursuant to Articles 1341 and 1342 of the Italian Civil Code, a Customer acting as a professional specifically approves the clauses of sections 7 (automatic renewal), 8 (non-payment), 10 (measures and suspension), 17 (limitation of liability), 18 (indemnity), 19 (withdrawal and termination), 21 (changes) and 23 (jurisdiction).
25. Contacts
- Information, contracts and notices of unlawful content: info@arimaslab.com
- Personal data and DPA: privacy@codequay.it
- Security and vulnerabilities: security@codequay.it
- Contact form: contact page