Commit e3df811c authored by Kristen Tesh's avatar Kristen Tesh
Browse files

Update customer NDA process

parent 0b48fdd5
Loading
Loading
Loading
Loading
+10 −13
Changes for content/handbook/legal/nda.md: 10 added lines, 13 removed lines.
Original line number Diff line number Diff line
@@ -8,24 +8,21 @@ description: "How to send or request an NDA"

## Customer NDAs

Team members with DocuSign access can use this process to send the standard pre-signed GitLab NDA for signature (all Sales team members have DocuSign access).
As of 2026-03-27, all customer NDAs should be sent through Ironclad.

1. Log into DocuSign and select `Use a Template` from the dropdown menu under `Start`.
1. On the left, select `Shared with Me` and locate the `Non-Disclosure Agreement Pre-Signed Template`.
1. Click the template and `Add Selected`.
1. Under `Recipient`, enter the signer's name and email address.
1. Under `GitLab Team Member`, add anyone else who needs to be cc'd on the signed copy, or click the trash icon to delete this row if not needed.
1. Do **not** delete or make any changes to the `GitLab NDA Tracker` fields (this is for the LACA team to track copies of NDAs).
1. Click Send.
1. Upload the fully executed NDA to the customer account in Salesforce.
To initiate the Ironclad workflow:

### Non-Standard Requests
1. Click **Request Support** at the top of your Opportunity in Salesforce.
2. Select **Legal** from the list of teams, and click Next.
3. Select **NDA** as the type of request, and click Initiate Workflow.

For a non-standard NDA, open a [Legal Request](/handbook/legal/customer-negotiations/#how-to-reach-the-legal-commercial-team) in Salesforce.
Follow the **step-by-step instructions** in the [Ironclad NDA Workflow – Process Guide for Requesters](https://docs.google.com/document/d/12UcfqG7Pnt2NbrjwF7OwxSxsyersFINem_qtb3BkOgw/edit?usp=sharing) to determine which option to use.

For a **general overview** of the process, review the [Ironclad NDA Requester Quick Reference](https://docs.google.com/presentation/d/1mtNJxI--HQk6Gk4ZHwaa67LIK2WankFDx92sIhF-_eg/edit?usp=sharing) deck.

## Vendors or Other Third-Party NDAs

The process above is only related to NDAs with customers. If a team member is engaging a new vendor or third party, GitLab's mNDA **must** be executed with them first before sharing any type of confidential information.
The process above is only related to NDAs with customers. If a team member is engaging a new vendor or third party, GitLab's NDA **must** be executed with them first before sharing any type of confidential information.

**Note:** All confidential information shared with third parties must be reviewed and approved by Security Risk and Privacy teams prior to disclosure. This review ensures the data types and sharing methods comply with GitLab's security and data protection requirements. For authorized data sharing guidance, refer to [GitLab's Safe Framework Handbook.](/handbook/legal/safe-framework/)

@@ -36,4 +33,4 @@ To initiate an NDA request with a vendor or third-party:
3. A Vendor Form will automatically be sent through Zip to the vendor contact you enter and provide them a copy of GitLab's [mutual NDA](/handbook/finance/procurement/vendor-guidelines/mutual-non-disclosure-agreement/) via a click-through process.
4. If a vendor has questions about the NDA, they can submit them through the Zip Vendor Form for your review. Zip will guide you through the process for review and escalation to the Procurement and Legal teams as needed.

**Please note that a vendor's request to negotiate NDA terms may delay or impact the opportunity and its intended time frame.** It is recommended that team members encourage the vendor in initial discussions to accept GitLab's standard mNDA when received to not impact the timing or opportunity to do business with us.
**Please note that a vendor's request to negotiate NDA terms may delay or impact the opportunity and its intended time frame.** It is recommended that team members encourage the vendor in initial discussions to accept GitLab's standard NDA when received to not impact the timing or opportunity to do business with us.