Terms
This Agreement is between Nestrand Technologies Limited, RC 9834714, registered office 36 Hassan Street, Lagos, Nigeria (“Licensor”, “we”, “us”) and the individual or organisation that accepts it (“you”, “Customer”). It governs your use of the Ritele software. You accept it by clicking to accept, or by installing, running or otherwise using the Software, whichever happens first. If you accept on behalf of an organisation, you confirm you are authorised to bind it, and “you” means that organisation.
1. Definitions
1.1“Software” means the Ritele application supplied in object-code form as a container image or binary, together with its documentation and any updates we make available to you.
1.2“Environment” means one deployment of your systems observed by the Software — production, staging, and so on. Each Environment is counted separately against your entitlements.
1.3“Component” means one node on the system map: a service, database, cache, queue, topic, or external endpoint that the Software resolves from the signals you route to it.
1.4“Instrumented Service” means a Component that reports spans to the Software under its own service name. Databases, caches, queues, topics and external endpoints are Components but not Instrumented Services, and do not count against an entitlement.
1.5“Licence Key” means a cryptographically signed token issued by us that states your entitlements and an expiry date.
1.6“Free Tier” means use of the Software without a Licence Key, on the terms in clause 3.1. “Paid Tier” means use under a valid Licence Key.
1.7“Telemetry Data” means the traces, spans, metrics and logs you route to the Software, and everything the Software derives from them — including component names, dependency maps, saturation readings and scenario results.
1.8“Usage Ping” means the single daily outbound message described in clause 9.
1.9“Architecture Review” means the optional feature that sends a question and supporting context to a language model, through our gateway or at an endpoint you configure, as described in clause 8.
2. Licence granted
2.1We grant you a non-exclusive, non-transferable, worldwide licence to install, run and use the Software on infrastructure you own or control, for your own internal business purposes, within the limits of your tier, for as long as this Agreement is in force.
2.2Your affiliates may use the Software under your licence and within your entitlements. You remain responsible for their compliance with this Agreement as if their acts were your own.
2.3Your contractors and service providers may operate the Software on your behalf, on infrastructure you control, provided they use it only for your benefit and you remain responsible for their compliance.
2.4No rights are granted other than those stated expressly. We reserve all rights not expressly granted.
3. Tiers and entitlements
3.1The Free Tier is free of charge and is not time-limited. It is limited to what the free plan on our published price list states: 1 environment, 20 services, 30 days of history, 10 hosts and 1 notification channel. A limit on services counts Instrumented Services only. The Software enforces these limits itself, at the values in force when the release you are running shipped; clause 3.4 governs changes to them.
3.2Paid Tier entitlements — Environments, Instrumented Services, hosts, retention periods for history and metrics, notification channels and features — are those stated in your Licence Key and in the order it was issued against. Where the two differ, the Licence Key governs what the Software will do and the order governs what you are owed.
3.3When you reach a limit, the Software stops adding beyond it and tells you so. It does not silently discard, sample or degrade data you have already collected.
3.4We may change Free Tier limits for new releases on 90 days’ notice published in the documentation. A release you are already running is unaffected; you are never obliged to upgrade.
4. Licence Keys and how they are verified
4.1A Licence Key is an Ed25519-signed token. The Software verifies its signature and expiry date locally, against public keys compiled into the release you are running. There is no licence server, no activation call and no revocation list to fetch. Verification works fully air-gapped.
4.2Because verification is offline, we have no technical means to withdraw a Licence Key once issued, and we do not claim one. An issued Key remains valid until the expiry date it states. We may decline to issue or renew Keys, including on termination under clause 17.
4.3Releases carry two accepted public keys so that signing keys can be rotated without interrupting existing installations. The signing key is held as a secret in the environment of the service that issues Licence Keys, and every Licence Key it signs is recorded, with the fingerprint of the key that signed it, before the Key is issued.
4.4Licence Keys are our confidential information. You must not publish, share or sell a Key, or use one issued to another party.
4.5When a Licence Key expires, the installation continues to run and reverts to the Free Tier. Nothing is deleted at the moment of expiry and your data is never locked or held to ransom. Free Tier retention applies from then on, so history older than that window is pruned as it ages out in the normal way — export anything you need first. We aim to notify you at least 30 days before expiry using the contact details on your order.
5. What you must not do
5.1You must not sublicense, rent, resell, or make the Software available to any third party as a hosted or managed service.
5.2You must not circumvent, disable or tamper with tier limits, Licence Key verification, or the mechanisms that enforce them, or run the Software using a Key you are not entitled to.
5.3You must not remove, obscure or alter any proprietary notice in the Software.
5.4You must not copy, decompile, disassemble or reverse engineer the Software, except to the extent that applicable law expressly permits it despite this restriction, and then only after you have asked us for the information you need and we have failed to supply it within a reasonable time.
6. Inspection and verification you are entitled to
6.1Nothing in clause 5 restricts you from observing what the Software does on your own infrastructure. You may monitor, log, packet-capture, firewall and egress-filter it however you wish, and you may run security scanning and penetration testing against your own installation without asking us.
6.2You may publish factual findings about the Software’s network behaviour, resource use and performance. We do not require pre-approval and we do not impose confidentiality on the results.
6.3If you believe you have found a security vulnerability, we ask that you report it to security@ritele.io and give us a reasonable opportunity to fix it before publishing the details. This is a request, not a condition of your licence.
7. Your data
7.1Telemetry Data stays on your infrastructure. Subject only to clauses 7.6 and 8, we do not receive it and the Software does not transmit it anywhere. This is not a policy commitment we ask you to take on trust — it is verifiable under clause 6.
7.2The Software stores Telemetry Data for the retention period you configure, either in an embedded store in its data directory (the /data volume) or in a Postgres and ClickHouse database you provide. Deleting the data directory deletes an embedded store; data in a database you provide is deleted there. Metrics are computed from every span received. Traces are sampled before they are stored: every trace with an error and every trace marked for documentation is kept, and so is 1% of the rest by default, a rate an administrator can change in Settings. Log lines the Software reads from a Loki an administrator connects are masked as they are read and are not stored; the queries it sends to that Loki are all it sends there. Nothing is mirrored or forwarded elsewhere, except as clauses 7.6 and 8 describe.
7.3The Software connects to one of your databases, caches or message brokers only when you add a receiver configuration for it to the Software’s bundled collector. The credential for that connection is supplied through that collector’s environment; the Software does not store it and does not return it through its interface. If you run the receiver in a collector of your own and route its readings to the Software instead, the Software holds no such credential.
7.4As between us, you own all Telemetry Data and all outputs the Software produces from it. We claim no licence over any of it.
7.5If Telemetry Data contains personal data, you are its controller. While Architecture Review is disabled, or is configured to an endpoint we do not operate, we never receive Telemetry Data and so are not a processor of it. If you enable Architecture Review in managed mode, or point it at an endpoint we operate, we process what you send for that purpose only, and a data processing agreement applies — ask us for one. Clause 9 covers the separate, minimal data we receive in every case.
7.6Notifications send nothing until an administrator of your installation adds a notification channel. Sign-in is on by default and each person has one role, viewer, editor or administrator; only an administrator can add a channel. If you turn sign-in off with RITELE_AUTH=off, there are no accounts and RITELE_ROLE is the one role of everyone who can reach port 8080; unset, that role is administrator, so anyone who can reach the port can add a channel. Once one is added, the Software sends messages about health issues to the destination saved for that channel and to nowhere else — for a PagerDuty or Opsgenie channel, that provider’s service for the region you choose — and stops when the channel is removed. A message carries an Environment’s name, an issue’s title and its reason with the readings behind it, a Component’s name and domain, the status of its checks, timestamps and, where you have set the address of your installation, a link to it; it never carries span attributes, metric labels, request URLs, request headers or user identifiers. We operate no such destination and receive nothing sent to one. Where the destination is operated by a third party, your relationship with that party governs what it does with what you send.
8. Architecture Review
8.1Architecture Review ships switched off and does nothing until you enable it. It and the notification channels in clause 7.6 are the only features that send anything derived from Telemetry Data beyond your network. Clause 7 describes what happens while neither is in use, which is the default.
8.2When you enable it, the question you ask and the supporting context needed to answer it — which may include component names, dependency relationships and metric readings — are sent to one destination: our Architecture Review gateway, unless you configure an endpoint of your own, in which case they go to that endpoint and nowhere else. In managed mode the request is authenticated with your Licence Key, so the gateway knows which licensee is asking.
8.3If you configure an endpoint of your own, you choose it. It may be a model running inside your own network, in which case nothing Architecture Review sends leaves your network. If you point it at a third-party provider, your relationship with that provider governs what they do with what you send, and you are responsible for satisfying yourself about it.
8.4When Architecture Review runs in managed mode, which is its default once you enable it, it sends to a gateway we operate. Enabling Architecture Review is always your choice, and it ships switched off. While you use managed mode, clause 7.5 applies and we process what is sent only to answer it and to count your use against your entitlement. Apart from that gateway and the receiver of the Usage Ping, we operate no hosted component of the Software.
9. The Usage Ping
9.1By default the Software sends one HTTPS request per day to installs.ritele.io. Its entire payload is: a random install identifier, the release version, a count of Environments, a true/false flag for whether a Licence Key is applied, and — where one is applied — the subject of that Licence Key. There is nothing else in it.
9.2The install identifier is a random value generated on first start and stored in the installation’s own database. It is not derived from your hostname, hardware, network addresses, Licence Key, organisation or any other identifying information. Reset the data volume, or use a new database, and a new identifier is generated.
9.3The Usage Ping never carries Telemetry Data, component or service names, hostnames, addresses, contact details, Licence Key contents, error reports, feature usage or timings of any kind. On a licensed installation it does carry the subject of your Licence Key, which identifies you to us; on the Free Tier it carries nothing that identifies you.
9.4We use it only to count installations and the releases in use. The install record — the identifier, the release version and the counts — is kept for as long as we run the service; it exists nowhere else in our systems, is joined to nothing, and identifies nobody. Where a Licence Key subject has been reported it is joined to your customer record, and it stays joined while the installation keeps pinging. Thirteen months after an installation last contacts us, the subject is cleared from that record and the installation is anonymous again.
9.5You can switch it off by setting RITELE_USAGE_PING=false. Air-gapped installations need do nothing: the request fails silently, is not retried within the day, and nothing is queued or buffered.
9.6If the payload ever changes, we will publish the change with a new disclosure version number on our website before a release containing it ships. Any expansion of the payload is a material change to this Agreement and clause 19.3 applies.
10. Fees, invoicing and tax
10.1Fees for Paid Tiers are those stated on your order. They are charged per organisation for the entitlements stated, not per user and not by metered usage.
10.2Unless your order says otherwise, invoices are payable within 30 days of issue. We may charge interest on overdue amounts at the statutory rate.
10.3Fees are exclusive of VAT and any other applicable taxes and duties, which you pay in addition where they apply.
10.4Fees are non-refundable once a Licence Key has been issued, except where your order states otherwise, where clause 14.2 or clause 15.1 applies, or where a refund is required by law.
10.5We may change our prices for future terms on 60 days’ notice before your renewal date. Prices for a term you have already paid for do not change.
11. Third-party and open-source components
11.1The Software includes third-party open-source components. A complete notices file listing them and their licences is distributed with the Software.
11.2Those components are licensed to you under their own terms, not under this Agreement. Where their terms conflict with this Agreement in respect of those components, their terms prevail.
12. Intellectual property
12.1We and our licensors own the Software and all intellectual property rights in it. This Agreement licenses the Software; it does not sell it.
12.2Clause 7.4 governs your data and the outputs produced from it. Nothing in this clause 12 qualifies your ownership of them.
12.3If you send us suggestions or feedback, we may use them without restriction or obligation to you. You are under no obligation to send any, and we will not identify you as the source without your permission.
13. Confidentiality
13.1Each party may receive information from the other that is marked confidential or would reasonably be understood to be confidential. Each party will protect the other’s confidential information with at least the care it applies to its own, and use it only to perform this Agreement.
13.2This does not apply to information that is or becomes public through no fault of the recipient, was already lawfully known to the recipient, is independently developed without reference to it, or is lawfully received from a third party.
13.3A party may disclose the other’s confidential information where required by law or a regulator, giving the other party as much notice as it lawfully can.
13.4These obligations continue for three years after this Agreement ends, and indefinitely for anything that is a trade secret.
14. Warranties and disclaimers
14.1Each party warrants that it has the authority to enter into this Agreement.
14.2For Paid Tiers, we warrant that for 90 days from the date your Licence Key is issued the Software will perform materially in accordance with its documentation. If it does not, tell us; we will use reasonable efforts to correct it, and if we cannot within a reasonable time we will refund the fees you paid for the unexpired part of the term. That is your sole remedy for breach of this warranty.
14.3Except as stated in clause 14.2, and to the fullest extent permitted by law, the Software is provided “as is”. We exclude all implied warranties and conditions, including satisfactory quality, fitness for a particular purpose and non-infringement.
14.4The Software models and predicts the behaviour of your systems. Predictions, saturation estimates, scenario results and Architecture Review answers are estimates, are stated with their uncertainty, and are not guarantees. You remain responsible for your own operational decisions.
14.5The Free Tier is provided free of charge and entirely as is, with no warranty of any kind.
15. Indemnities
15.1We will defend you against any third-party claim that the Software as supplied infringes that party’s intellectual property rights, and pay damages finally awarded or agreed in settlement, provided you notify us promptly, let us control the defence, and give us reasonable cooperation. If such a claim is made or looks likely, we may procure the right for you to continue using the Software, modify it so it is no longer infringing, or terminate the affected licence and refund the fees you paid for the unexpired term.
15.2Clause 15.1 does not apply to claims arising from modification of the Software by anyone other than us, its combination with anything we did not supply where the claim arises from the combination, or use outside this Agreement.
15.3You will indemnify us against third-party claims arising from your use of the Software in breach of clause 5, and from the content of Telemetry Data you route to it.
16. Limitation of liability
16.1Nothing in this Agreement limits or excludes either party’s liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited or excluded.
16.2Subject to clause 16.1, neither party is liable for loss of profits, revenue, anticipated savings, business, goodwill or data, or for any indirect or consequential loss, however arising.
16.3Subject to clause 16.1, each party’s total liability arising out of this Agreement is limited to the fees you paid in the 12 months before the event giving rise to the claim. Where you are using the Free Tier and have paid nothing, our total liability is limited to £100.
16.4Clauses 16.2 and 16.3 do not limit our liability under clause 15.1, or either party’s liability for breach of clause 13.
16.5Each party must take reasonable steps to mitigate its loss.
17. Term and termination
17.1This Agreement starts when you accept it and continues for as long as you run the Software.
17.2Either party may terminate on 30 days’ written notice if the other commits a material breach and has not cured it within that period.
17.3We may terminate immediately on written notice if you breach clause 5 or clause 4.4.
17.4You may stop using the Software at any time. Stopping use of the Free Tier ends this Agreement. Stopping use of a Paid Tier does not entitle you to a refund except as stated in clause 10.4.
17.5On termination you must stop using the Software and destroy your copies of it. Your Telemetry Data is on your own infrastructure and is unaffected. We hold none of it to return or delete: managed Architecture Review keeps nothing beyond a request in flight, and what we retain is the record of your Licence Key and the count of reviews used against it.
17.6Clauses 1, 5, 6, 7, 10, 11, 12, 13, 14.3, 14.4, 14.5, 15, 16, 17.5, 18 and 19 survive termination.
18. Compliance, export control and sanctions
18.1Each party will comply with applicable law in performing this Agreement, including anti-bribery, anti-corruption, export control and sanctions law.
18.2You confirm you are not located in, and will not use or export the Software to, any territory subject to comprehensive trade sanctions, and that you are not a person or entity designated on any applicable sanctions list.
19. General
19.1This Agreement is governed by the law of the Federal Republic of Nigeria, and each party submits to the exclusive jurisdiction of the Nigerian courts.
19.2This Agreement, together with your order, is the entire agreement between us about the Software and replaces anything said or written before. Neither party relies on any statement not set out in it, but nothing excludes liability for fraudulent misrepresentation.
19.3We may change this Agreement for future releases. Changes apply to a release when you install it. If you do not accept a change, do not install that release; the version you accepted continues to govern the version you are running. Where a clause requires notice of a material change, we publish the new version, and the change list, at least 30 days before a release carrying it ships.
19.4Neither party may assign this Agreement without the other’s consent, except that either may assign it in full to a successor to substantially all of its business, on notice.
19.5If any provision is held unenforceable, it is modified to the minimum extent necessary to make it enforceable, or severed if it cannot be, and the rest is unaffected.
19.6A delay or failure to enforce a right is not a waiver of it, and a single or partial exercise does not prevent further exercise.
19.7Notices to us must be sent to legal@ritele.io. Notices to you will be sent to the contact details on your order, or for Free Tier users, published in the documentation.
19.8Neither party is liable for failure to perform caused by events beyond its reasonable control, other than an obligation to pay.
19.9Nothing in this Agreement creates a partnership, joint venture or agency between the parties.
19.10A person who is not a party to this Agreement has no right to enforce any of its terms.