Terms of service

Last updated 27 August 2026

These terms govern use of GitSearch, a service provided by [FILL IN — registered company name, e.g. BlueGrid d.o.o.], trading as BlueGrid.io. They form a contract between us and the company whose account you use.

GitSearch is offered to businesses only. It is not available to consumers, and by accepting these terms you confirm you are acting for a business.

1. Definitions

  • Account — the workspace belonging to your company, identified by a domain.
  • User — a named individual permitted to sign in to your Account.
  • Profile — a record about a GitHub user that GitSearch has collected from GitHub's public API.
  • Customer, you — the company that holds the Account.

2. What we provide

GitSearch lets your Users search public GitHub profiles, view the results, and export them. We provide it on a subscription basis for the term agreed in your order.

The service depends on the GitHub API, which is operated by a third party and subject to its own rate limits and terms. GitHub caps any single search at 1,000 results and limits how many requests we may make per hour. We build around those limits but we cannot remove them, and we are not responsible for changes GitHub makes to its API, its data, or its terms.

3. Accounts, users and access

Each Account is locked to an email domain. Users can only be invited with addresses on that domain, unless we add a specific exception at your request. You are responsible for who you invite, for the actions of your Users, and for keeping credentials confidential. Tell us immediately at [FILL IN — contact@bluegrid.io] if you believe an account has been compromised.

User accounts are named and personal. Sharing one login between several people is not permitted.

We may suspend an Account or a User immediately where we have reasonable grounds to believe these terms are being breached, where continued use threatens the security or availability of the service, or where a payment is materially overdue. We will tell you why.

4. Acceptable use

You must not, and must not permit your Users to:

  • use the service or the data it returns for anything other than legitimate recruitment and talent research;
  • send unsolicited bulk email or messages that breach applicable marketing, anti-spam or data protection law in the recipient's country;
  • use profile data to build a competing dataset or a data brokerage product, or resell, sublicense or publish it;
  • attempt to circumvent rate limits, scrape the interface, automate access outside the features we provide, or reverse engineer the service;
  • combine profile data with other sources in order to create profiles that reveal special categories of data under Article 9 GDPR, or use it to discriminate unlawfully; or
  • ignore a request from a data subject that we pass on to you.

Your use of the data must also comply with GitHub's Terms of Service and its Acceptable Use Policies, including the restriction on using information from GitHub to send unsolicited bulk communications. [FILL IN — counsel should confirm the current wording of GitHub's information-usage restrictions and align this clause with it.]

5. Data protection

Each of us is an independent controller for the personal data of the GitHub users whose profiles appear in the service: we for our collection and storage, you for what you do with the data after you view or export it. Our privacy policy describes our side.

For the personal data of your own Users, which we process to run your Account, we act as your processor. Our data processing agreement sets out those terms and forms part of this contract.

You must give the people you contact the information Article 14 GDPR requires when you first approach them, including where you obtained their details. You must honour objections and erasure requests in respect of your own copy of the data. If a data subject asks us to delete their profile, we will do so and will pass their objection to you where they identify you.

6. Repository email discovery

The optional feature that extracts email addresses from public commit metadata is disabled unless you ask for it. Enabling it increases your exposure under the GDPR and under GitHub's terms, because an address published for code attribution is being used for a different purpose. You accept that risk for your own processing when you ask us to enable it, and you confirm you have recorded your own legitimate interest assessment for it.

7. Fees and payment

Fees, the billing period and any usage limits are those in your order form. Unless stated otherwise, fees are exclusive of VAT and other taxes, invoices are payable within [FILL IN — proposed 14] days, and late payment carries statutory default interest. [FILL IN — confirm pricing model, currency, and whether the reverse charge applies for EU business customers.]

8. Availability and support

We aim to keep GitSearch available but do not commit to a service level unless one is agreed in writing in your order form. We may take the service down for maintenance and will give reasonable notice for planned work where we can. Support is provided by email at [FILL IN — contact@bluegrid.io] during Serbian business hours. [FILL IN — agree an SLA and response times, or state explicitly that none is offered.]

9. Intellectual property

We own the software, the interface and everything we create for the service. You get a non-exclusive, non-transferable right to use it during your subscription. You own the searches and exports you produce, subject to the rights of the people the data is about. Profile data itself is not owned by either of us; it belongs to the individuals it describes and is published by GitHub.

10. Warranties and disclaimers

We provide the service with reasonable skill and care. Beyond that, and to the fullest extent the law allows, GitSearch is provided as is. We do not warrant that search results are complete, current or accurate: the data comes from GitHub, may be out of date by up to the profile cache lifetime, and reflects only what each person has chosen to publish. Nothing here excludes liability that cannot lawfully be excluded.

11. Liability

Neither party is liable for indirect or consequential loss, loss of profit, or loss of anticipated savings. Our total liability arising out of or in connection with this contract in any twelve month period is limited to the fees you paid in that period. This limit does not apply to death or personal injury caused by negligence, fraud, or liability that cannot be limited by law. [FILL IN — confirm the cap is commercially acceptable and enforceable in both Serbia and Germany.]

12. Term, termination and what happens to data

The contract runs for the term in your order form and renews unless either of us gives notice. Either party may terminate for material breach that is not remedied within 30 days of written notice.

On termination your Users lose access. We delete your Account data — Users, invitations, search history and audit records — within [FILL IN — proposed 90] days, except where we must keep records for tax or legal reasons. Profile records are not yours and are not deleted with your Account; they remain in the shared database subject to our retention rules and any individual's deletion request.

Export your data before the end of the term. We will help if you ask during the notice period.

13. Changes to these terms

We may change these terms on [FILL IN — proposed 30] days' notice by email to your Account administrators. If a change materially disadvantages you, you may terminate without penalty before it takes effect.

14. Governing law and jurisdiction

This contract is governed by the law of [FILL IN — Serbia, or Germany if that is commercially preferable for EU customers], and the courts of [FILL IN — Belgrade, Serbia] have exclusive jurisdiction. The United Nations Convention on Contracts for the International Sale of Goods does not apply. [FILL IN — counsel should advise which choice is more defensible against EU business customers and whether arbitration would be preferable.]

GitSearch uses only strictly necessary cookies — to keep you signed in, to protect forms against cross-site request forgery, and to remember that you have read this notice. No analytics, no tracking, no third parties. Cookie policy.