Definitions

For the purpose of these Terms of Use, the following terms shall have the meanings set forth below:

  • "Provider": Telekom IT GmbH, DevTools Department, operator of MagentaCICD
  • "MagentaCICD": The standardized CI/CD platform comprising GitLab, Artifactory, and related tools
  • "User": Any employee, contractor, or authorized third party granted access to MagentaCICD
  • "Account Owner": The individual responsible for a GitLab group or project, accountable for access control and compliance
  • "Repository Content": All code, documentation, data, and other materials stored in GitLab repositories
  • "Personal Data": Any information relating to an identified or identifiable natural person, as defined in applicable data protection laws
  • "Service": The provision of MagentaCICD and all related functionalities, tools, and documentation
  • "Terms of Use": These terms and conditions, as amended from time to time

§ 1 General Information

The ICTO-20567 (CICD Solutions) comprises the platform MagentaCICD and is provided by Deutsche Telekom IT GmbH, DevTools Department.

The group guidelines and regulations on data protection and data security of Deutsche Telekom AG apply.

§ 2 Works Council Approval

The platform MagentaCICD has a KBR (Konzernbetriebsrat - Group Workers Council) approval. The regulations of KBV IT-Systems apply. The platform MagentaCICD may not be used for individual performance and behavioral monitoring.

§ 3 Purpose

MagentaCICD is the standardized CI/CD platform for development teams within Deutsche Telekom AG. The platform comprises GitLab Ultimate as its primary component, integrated with JFrog Artifactory for artifact management, and complemented by additional sub-services including PlantUML for diagramming, Shields.io for badges, Yopass for secure secret sharing, and other developer tools.

MagentaCICD is accessible through the CI/CD Portal located at https://devops.telekom.de, which serves as the main landing page for the platform. The Portal provides:

  • Discovery and documentation of all MagentaCICD services
  • Links to additional developer tools and resources relevant to Deutsche Telekom development teams
  • Self-Service capabilities allowing users to manage their accounts, project access, and resource configurations
  • Administrative tools for project owners and account managers

The data recorded during use of MagentaCICD is used exclusively for traceability, quality assurance, and system operations. Any form of collection, monitoring, or analysis of user behavior, actions, or activities for purposes other than troubleshooting, maintaining regular operation, and system security is prohibited. This includes, but is not limited to, individual performance monitoring or behavioral surveillance.

GitLab Repository Visibility

MagentaCICD repositories are created with "internal" visibility by default, which grants read access to all employees of Deutsche Telekom AG. External contractors and third parties do not receive automatic read access to internal repositories. Users and project owners may restrict repository visibility to "private" at any time, limiting read access to only explicitly designated members of the project or group. Users bear responsibility for ensuring that repository visibility settings comply with data protection and data security requirements.

The comment fields used in GitLab are to be used exclusively for commenting on content and work progress, not for social communication or off-topic discussions.

MagentaCICD offers code sharing and collaboration as a service. To support secure code sharing, all content stored in MagentaCICD must comply with Deutsche Telekom AG data protection and data security requirements. Users must ensure visibility settings ("internal" or "private") and content restrictions align with the sensitivity and classification of stored materials.

§ 4 Use of Tools and Integrations in MagentaCICD

GitLab Integrations

GitLab/Jira Integration: Information from GitLab may not be used in Jira for performance and behavioral monitoring. When using this integration, each GitLab user must have access to the appropriate Jira instance.

GitLab/Chat Tool Integration (WebEx Teams and Slack): Users in each chat room must be composed exclusively of members of the respective development team.

Artifact Management

Artifactory & Edge Nodes: Edge nodes are the responsibility of customer projects. The customer must demonstrably ensure that:

  • Necessary software updates are carried out
  • Security requirements and data protection rules are complied with
  • Edge nodes are included in the PSA procedure if part of the production environment

Code Quality & Metrics

SonarQube: All members of a GitLab group activated for SonarQube get full access to SonarQube projects regardless of their GitLab role (guest/reporter/developer/etc.).

DORA Metrics: DORA metrics can be used for quality assurance at the GitLab project level. Performance and behavior monitoring using DORA metrics is not allowed.

  • Project Comparability: DORA metrics are used on a project-specific basis. Projects are not comparable due to their structure, requirements, and operational situation. No comparison between individual projects is permitted. Trend analysis at higher aggregation levels can provide information on quality development of organizational units.

  • Quality Assurance: DORA metrics enable quality assurance on GitLab project level. Development teams should define appropriate target values at the GitLab project level, depending on project structure, requirements, PI and sprint planning, and operational situation.

GitLab Web IDE Marketplace: The GitLab Web IDE allows developers to extend their environment through the Web IDE Extension Marketplace. By using the Marketplace, users agree to comply with all internal security policies.

Extensions are installed and used at the user's own risk. To the maximum extent permitted by applicable law, MCICD shall not be liable for any damages, data loss, security breaches, or unauthorized access caused by third-party extensions, including but not limited to malicious code, data exfiltration, or system compromise. Users assume all responsibility for extension selection, installation, and usage. MCICD reserves the right to disable, block, or remove the Marketplace or specific extensions if they become unsafe, non-compliant with security requirements, or violate these Terms of Use.

§ 4a GitLab Repository Storage Guidelines and Acceptable Use Policy

GitLab repositories are provided exclusively for source code management and collaborative software development. The following guidelines define acceptable and unacceptable usage:

Prohibited Activities - What is NOT allowed in GitLab repositories:

  • Secrets, credentials, API keys, authentication tokens, passwords, private keys, or sensitive authentication information
  • Large files or binary assets exceeding 100 MB per file or repository sizes exceeding reasonable development project limits
  • Database backups, snapshots, or persistent data storage
  • Frequent automated commits or batch operations used to simulate database or data storage functionality
  • General file storage, archival purposes, or backup activities unrelated to active software development
  • Malware, ransomware, or code intended to compromise system security
  • Illegal content or content that violates applicable laws

Compliant Alternatives:

  • Store large files and binary assets using Git LFS (Large File Storage)
  • Use dedicated services for database backups and persistent data storage
  • Maintain secrets in secure secret management systems (e.g., HashiCorp Vault, AWS Secrets Manager)
  • Use cloud storage solutions for file archival and backup purposes

Enforcement and Consequences

Violations of this Acceptable Use Policy will result in enforcement action according to the following tiered approach:

  1. First Violation: Provider issues written notice and grants 14-day remediation period. User must remove non-compliant content and demonstrate compliance.

  2. Repeated Violations: Provider may suspend repository access and project-level functionality for 7-30 days, pending remediation and user's formal acknowledgment of compliance.

  3. Severe Violations: Provider may immediately suspend or terminate account access without prior notice in cases of: (i) malware or security threats, (ii) illegal content, (iii) intentional repeated violations after warning, or (iv) activities causing material harm to the Service.

Users may submit appeals of enforcement actions via support ticket to devops@telekom.de within 14 days of suspension notice. Appeals will be reviewed by Provider management and a determination issued within 7 business days.

Project owners are responsible for ensuring their team members comply with these storage guidelines and acceptable use policies. Account owners must conduct regular audits of repositories to verify compliance.

§ 5 Data Protection and Data Security

SDSKs (security and data protection concept) were created and released for MagentaCICD on the basis of the PSA procedure:

MagentaCICD: Privacy: Category C Security: Category A Data privacy class: internal

For the services provided (repositories, storage), the user must comply with the Group-wide data protection and data security guidelines, which depend on the respective protection class. For all data of the "internal" and "confidential" protection class, the user is responsible for compliance with the above-mentioned specifications.

Data in higher protection classes is not permitted. In general, no personal data must be stored (e.g. such as test data based on customer-related productive data), regardless of the protection class.

GDPR and Data Protection Compliance

Users acknowledge that as "data controllers" (as defined under GDPR and applicable data protection laws), they are solely responsible for ensuring lawful processing of any personal data stored in MagentaCICD. Users must:

  • Establish a lawful basis for processing (consent, contract, legal obligation, vital interests, public task, or legitimate interests)
  • Maintain documentation of data processing activities (processing agreements, retention policies)
  • Implement appropriate technical and organizational security measures
  • Respond to data subject requests (access, deletion, portability, rectification) within required timeframes
  • Report data breaches to supervisory authorities and affected parties as required by law

The Provider shall not be liable for users' failure to comply with data protection regulations. Provider reserves the right to audit repositories for data protection compliance and may suspend accounts found in violation of GDPR or applicable data protection laws.

Magenta CICD has the classification D3.

Operational model of production environment is DE3 with the inclusion of colleagues from Deutsche Telekom Digital Labs (DEM-23600).

The "need-to-know" principle applies to the stored content in accordance with the data protection rules. Content may only be stored for business purposes.

The user acknowledges that in order to ensure stability, temporary data (e.g. workspaces of build agents) will be checked regularly and permanently removed if necessary.

§ 6 Your Responsibilities as a User of MagentaCICD

Acceptance of Terms

By accessing and using MagentaCICD, you explicitly acknowledge and agree to these Terms of Use in their entirety. Your acceptance is confirmed through: (i) initial system login, (ii) continued use of the Service, and (iii) acceptance of any updated Terms upon notification. You further acknowledge responsibility for: (i) compliance with all applicable laws and regulations, including GDPR and data protection requirements; (ii) the lawfulness of all content stored in your repositories; and (iii) adherence to the Acceptable Use Policy outlined in these Terms.

Account Security and Responsibility

Your account is personal and may only be used by yourself. You are solely responsible for maintaining the confidentiality of your credentials, including user name (domain account), access tokens, SSH keys, and passwords. You must:

  • Protect credentials from unauthorized access by third parties
  • Not share or transmit credentials via email, chat, or unsecured channels
  • Never store credentials or tokens in Git repositories or any publicly accessible location, this includes repositories that are configured with the 'Private' visibility level.
  • Immediately notify devops@telekom.de of any suspected unauthorized access or credential compromise

You are solely liable for all activities conducted through your account, including data upload, modification, deletion, and integration configuration. The Provider shall not be responsible for unauthorized access resulting from your failure to protect credentials, though the project-internal transfer of machine keys and service accounts is permitted provided appropriate security measures remain in place.

Repository Content Responsibility

Deleted projects cannot be restored. Projects or groups deleted by users cannot be recovered. You acknowledge this irreversible action and must exercise extreme caution when deleting repositories or groups.

The respective user is responsible for the lawfulness, accuracy, and compliance of all content and data stored in MagentaCICD. You warrant that you have obtained all necessary rights, consents, and authorizations to store such content. You agree to indemnify and hold harmless the Provider from any claims, damages, or costs arising from your content or use of the Service.

Secret Scanning and Remediation Obligations

MagentaCICD uses GitGuardian to perform centralized scans for secrets within content stored on the platform. If GitGuardian notifies a user of a suspected secret exposure, that user must react without undue delay and must:

  • Review and triage the finding in GitGuardian
  • Determine whether the finding is a true positive or false positive
  • Immediately rotate, revoke, or otherwise remediate any confirmed exposed secret
  • Remove or otherwise contain the exposed secret in the affected content where technically required

Intentional disregard of a GitGuardian notification relating to a confirmed true positive finding constitutes an intentional harmful action against Deutsche Telekom. In such cases, the Provider may immediately terminate the relevant account without prior notice. All GitGuardian findings are reported to Deutsche Telekom Security GmbH. Where intentional harmful action is identified, the user's line manager may be informed and the incident may lead to an official warning letter by the employer.

§ 7 Owner Obligations in MagentaCICD

As owner you are responsible for the assignment and maintenance of the roles/rights of the assigned users. The authorizations must be checked regularly. External employees and partners of the Deutsche Telekom Group may only use the system after appropriate registration and approval. This may only be done on an individual basis. The necessity for NDAs (non disclosure agreements) must be checked and, if necessary, ensured on the project side. An owner or superuser can set up additional owners. The new owner added in this way must be informed of their obligations as owner.

Owners must also ensure that users in their groups and projects are aware of and comply with the GitGuardian secret scanning and remediation obligations. Confirmed true positive secret findings must be addressed without undue delay.

GitLab also has owners of groups and projects. They are managed independently within Gitlab.

The regular check of the Internet access as well as the renewal of the client certificates is also part of the project obligations.

§ 8 Service Availability, Maintenance Windows, and Service Level Agreement

Changes and Modifications

The Provider reserves the right to modify, update, or discontinue features, tools, and platform functionality at its discretion. Modifications that do not materially affect service functionality will be implemented with notification at the discretion of the Provider. For material changes that significantly increase user obligations or substantially reduce service capability, the Provider shall provide 30 days' notice by posting the updated terms on the MagentaCICD documentation site. Continued use of the Service after the notice period constitutes acceptance of the modifications. Users who do not accept modifications may request account termination.

Maintenance Windows

The Provider reserves the right to schedule maintenance windows and emergency maintenance as necessary for security updates, system stability, and platform operations. Scheduled maintenance will be announced in advance. In emergency situations requiring immediate action to protect system security or prevent data loss, the Provider may perform maintenance without prior notice.

The following maintenance windows are pre-reserved for offline changes; the Provider reserves the right to perform system maintenance during these periods after reasonable announcement:

Maintenance window MagentaCICD for changes with downtime:

GitLab (and corresponding tools): Every Tuesday, 18:00-20:00 German time; Downtime of up to two hours for general updates and maintenance

GitLab (and corresponding tools): Every 1st Sunday, 08:00-20:00 German time; Downtime of 12 hours for major updates and maintenance

JFrog Platform (Artifactory): During working days, 06:00-08:00, 17:00-20:00, 22:00-23:59 German time; Downtime of up to 30 minutes

Magenta-Trusted-Registry (MTR): Every day, 06:00-07:00 or 22:00-23:59 German time; Downtime of up to 30 minutes

CICD Solutions Login: Every day, 22:00-06:00 German time; Downtime of up to 30 minutes

Service Level Agreement

The Provider targets 99% uptime for MagentaCICD, calculated on a monthly basis, excluding scheduled maintenance windows listed above and emergency maintenance necessitated by security threats. Uptime is defined as the Service being available and responsive to user requests.

The Provider shall not be liable for any damages, losses, or claims arising from service downtime, whether scheduled or unscheduled, except as explicitly provided in a separate, signed SLA agreement between the Provider and specific User organizations.

Temporary outages, performance degradation, or partial service unavailability does not constitute breach of these Terms unless the outage: (i) exceeds 8 consecutive hours of unscheduled downtime in any 30-day period, or (ii) occurs more than three times in any 30-day period outside scheduled maintenance windows.

§ 9 User Accounts

If no existing account is found, a MagentaCICD user account is automatically created with the first login. Every application of MagentaCICD creates a local account for the user, which is connected via Single-Sign-On. Accounts that are inactive for 90 days are automatically deactivated.

If a user is not longer present in one of the central identity systems of Deutsche Telekom (EMEA1/2, ZAM, and Collaboration Network), his account will automatically be blocked. Unblocking is always possible via service desk requests when writing to devops@telekom.de.

Accounts blocked for 30 days or deactivated for 365 days will be deleted automatically.

§ 10 Security Incidents and Breach Notification

Incident Response and Notification

The Provider maintains incident response procedures to address security breaches, unauthorized access, data loss, and system compromise affecting MagentaCICD. Upon discovery of a security incident that may compromise user data, the Provider shall:

  • Conduct a prompt investigation to determine scope and nature of compromise
  • Notify affected users and relevant supervisory authorities as required by applicable law (GDPR Article 33-34)
  • Provide incident details including: nature of incident, affected data, likely consequences, and recommended mitigation steps
  • Offer reasonable assistance to affected users in meeting their legal notification obligations

Users acknowledge that investigation of security incidents may require Provider access to user account data, repository contents, and system logs. Users waive any privacy objections to such investigation to the extent necessary to identify and remediate security issues.

For suspected misuse or policy violations, the Provider may: (i) monitor user activity, (ii) access repository contents and logs, (iii) preserve evidence, and (iv) terminate service access to prevent ongoing harm, all without prior notice where circumstances warrant immediate action.

§ 11 Compliance and Support

The Provider may audit repositories to verify compliance with these Terms of Use. Users shall cooperate with audit requests and provide access or documentation as needed.

For support requests, questions, or policy violations, contact devops@telekom.de.

§ 12 Liability and Warranties

MagentaCICD is provided as an internal tool for Deutsche Telekom employees. Users assume responsibility for the lawfulness and security of their own content stored in the Service. The Provider is not liable for damages arising from user misuse, data loss caused by user actions, or third-party content and extensions.

§ 13 Data Management

You retain all intellectual property rights in content you create and store in MagentaCICD. The Provider retains all rights to MagentaCICD software and documentation.

Users may request export of their repository data in standard formats. Contact devops@telekom.de for data export requests.

§ 14 Account Termination

The Provider may revoke access if these Terms are violated or to ensure system security. Users may request account termination by contacting devops@telekom.de. Upon termination, repository data will be retained for 30 days for export, then deleted.

§ 15 General Provisions

These Terms of Use are governed by the laws of the Federal Republic of Germany. If provisions of these Terms are found invalid, the remaining provisions remain in effect. The Provider reserves the right to modify these Terms with 30 days' notice posted on the MagentaCICD documentation site.

§ 16 Contact and Support

For questions, support requests, or to report policy violations, contact devops@telekom.de.

These Terms of Use constitute the entire agreement between you and the Provider regarding MagentaCICD. Continued use of the Service following notice of Term modifications constitutes acceptance of changes.