GeoInsights Site Selection Third-party data and software attribution notices. GENERATED FILE — do not hand-edit. python -m app.siteselect.baseline.licence_report --write-notice is the only thing that should write this file. It is rendered from `backend/app/siteselect/baseline/attribution.py`, the registry the application itself serves at `GET /api/v1/attribution`, and `tests/test_attribution.py` fails if the two drift. Editing here instead of there produces two public statements of one obligation, which is how this file previously came to describe geoBoundaries as CC BY-SA 2.0 while the code and the staged data both said ODbL-1.0. Why this is a tracked repo file rather than a downloaded artifact ---------------------------------------------------------------- It used to be neither. Foursquare's `NOTICE.txt` arrived with the OS Places extract and was left in `pipelines/data/raw/foursquare_places/`, which `.gitignore` excludes wholesale — correct for multi-gigabyte licensed parquet, wrong for the one file the licence requires us to redistribute. Apache-2.0 §4(d) requires the NOTICE to travel with every derivative work we distribute, so it cannot live only in a gitignored cache on one developer's disk, and it cannot depend on an ingest having been run. ================================================================================ Foursquare OS Places — Apache-2.0 ================================================================================ Source: https://huggingface.co/datasets/foursquare/fsq-os-places Licence: Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) Version: dt=2025-02-06 Used in: staging.stg_foursquare_places Required credit line: © Foursquare Labs, Inc. Foursquare OS Places, licensed under the Apache License 2.0. Reproduced verbatim from the release's NOTICE.txt: Copyright 2024 Foursquare Labs, Inc. All rights reserved. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. Note: Apache-2.0 §4(d) requires the NOTICE itself to be redistributed, not merely a credit line — see notice_text. ================================================================================ OpenStreetMap — ODbL-1.0 ================================================================================ Source: https://www.openstreetmap.org/copyright Licence: Open Database License 1.0 (https://opendatacommons.org/licenses/odbl/1-0/) Version: Overpass API live query; Geofabrik gcc-states-latest.osm.pbf Used in: staging.stg_osm_pois, staging.stg_osm_roads, staging.stg_osm_junctions, staging.stg_osm_transit_stops Share-alike: YES — derived columns carry a downstream obligation and must stay separable (DATA_STRATEGY §9). Required credit line: © OpenStreetMap contributors, ODbL 1.0 ================================================================================ Overture Maps Foundation — places — CDLA-Permissive-2.0 ================================================================================ Source: https://overturemaps.org/ Licence: Community Data License Agreement — Permissive 2.0 (https://cdla.dev/permissive-2-0/) Version: release 2026-07-22.0, theme=places Used in: staging.stg_overture_places Required credit line: © Overture Maps Foundation Note: The places theme is CDLA-Permissive-2.0 on the extract we hold. This is *not* transferable to the buildings theme — see overture_buildings. ================================================================================ Overture Maps Foundation — buildings — ODbL-1.0 ================================================================================ Source: https://docs.overturemaps.org/guides/buildings/ Licence: Open Database License 1.0 (https://opendatacommons.org/licenses/odbl/1-0/) Version: release 2026-07-22.0, theme=buildings Used in: staging.stg_overture_buildings Share-alike: YES — derived columns carry a downstream obligation and must stay separable (DATA_STRATEGY §9). Required credit line: © Overture Maps Foundation; contains data © OpenStreetMap contributors (ODbL) Note: Share-alike, despite the theme commonly being assumed permissive. Building-derived columns must stay tagged and separable in source_flags (§9 trap #2). Earlier runs are recorded in the ledger under CDLA-Permissive-2.0, before the per-extract check existed. ================================================================================ WorldPop — CC-BY-4.0 ================================================================================ Source: https://www.worldpop.org/ Licence: Creative Commons Attribution 4.0 International (https://creativecommons.org/licenses/by/4.0/) Version: Global 2000-2020, SAU, 2020, 100 m (unconstrained) Used in: staging.stg_worldpop_agesex Required credit line: WorldPop (www.worldpop.org), School of Geography and Environmental Science, University of Southampton — Global High Resolution Population Denominators Project. Licensed CC BY 4.0. Note: Unconstrained product: the age/sex shares are spatially constant across the AOI and must never be presented as a differentiator between hexes. ================================================================================ Kontur Population — CC-BY-4.0 ================================================================================ Source: https://data.humdata.org/dataset/kontur-population-dataset Licence: Creative Commons Attribution 4.0 International (https://creativecommons.org/licenses/by/4.0/) Version: kontur_population_SA_20231101 Used in: staging.stg_kontur_population Required credit line: Kontur Population Dataset, © Kontur (kontur.io), CC BY 4.0 ================================================================================ GHSL — Global Human Settlement Layer — EC-JRC-Free ================================================================================ Source: https://ghsl.jrc.ec.europa.eu/ Licence: European Commission JRC free reuse (GHSL) (https://eur-lex.europa.eu/eli/dec/2011/833/oj) Version: R2023A, GHS-BUILT-S, epoch 2020, 100 m, Mollweide (ESRI:54009) Used in: staging.stg_ghsl_builtup Required credit line: European Commission, Joint Research Centre (JRC): Global Human Settlement Layer GHS-BUILT-S and GHS-POP, release R2023A (epoch 2020, 100 m, Mollweide) ================================================================================ geoBoundaries — SAU ADM2 (administrative boundaries) — ODbL-1.0 ================================================================================ Source: https://www.geoboundaries.org/ Licence: Open Database License 1.0 (https://opendatacommons.org/licenses/odbl/1-0/) Version: gbOpen SAU ADM2 @ 9469f09 Used in: staging.stg_gastat_districts Share-alike: YES — derived columns carry a downstream obligation and must stay separable (DATA_STRATEGY §9). Required credit line: Boundaries © geoBoundaries (gbOpen, SAU ADM2), derived from OpenStreetMap contributors — © OpenStreetMap contributors, ODbL 1.0 Note: Share-alike. Upstream label says CC BY-SA 2.0; the operative licence is ODbL 1.0 via OpenStreetMap. Riyadh district (ADM3) polygons do not exist in this release, which is why the district-level baseline columns are deferred rather than approximated. ================================================================================ GASTAT — Saudi General Authority for Statistics — Saudi-Open-Data ================================================================================ Source: https://www.stats.gov.sa/ Licence: Saudi Open Data Licence (https://open.data.gov.sa/en/pages/termsofuse) Version: Saudi Census 2022 (via RCRC open-data portal) Used in: staging.stg_gastat_districts Required credit line: General Authority for Statistics (GASTAT), Saudi Census 2022; republished by the Royal Commission for Riyadh City open-data portal under the KSA Open Data Licence Note: Redistribution terms under the Saudi Open Data Licence are an open §9 checklist item and need a KSA-side legal read: the terms page is behind the same F5 WAF that blocks open.data.gov.sa to non-KSA clients. ================================================================================ SREM — Saudi Real Estate Market (Ministry of Justice) — Saudi-Open-Data ================================================================================ Source: https://srem.moj.gov.sa/ Licence: Saudi Open Data Licence (https://open.data.gov.sa/en/pages/termsofuse) Version: Dashboard/GetAreaInfo transactions extract Used in: staging.stg_srem_transactions, staging.stg_district_land_value Required credit line: Ministry of Justice — Saudi Real Estate Market (البورصة العقارية), Saudi Open Data Licence Note: Same Saudi Open Data Licence review item as GASTAT — still open, and composition does not close it. Composed into land_value_sqm by SS-1-14 (baseline.compose_land_value) as the median of each district's monthly prices over a trailing 12-month window. Two caveats travel with every value and belong here too: the figure has DISTRICT granularity stored per hex, and the geography that places it on hexes is the `ksa_districts` layer, whose provenance is NOT established. Crediting SREM for these values is correct; treating the column as cleared for redistribution is not, until `ksa_districts` is resolved. ================================================================================ KSA district boundaries (user-supplied, provenance unverified) — unknown ================================================================================ Source: file:pipelines/data/raw/districts/districts_ksa.geojson Licence: Unknown — provenance not established Version: user-supplied GeoJSON, 3,732 features, no version identifier Used in: staging.stg_ksa_districts, staging.stg_district_h3, staging.stg_district_srem_bridge ⚠️ PROVENANCE NOT ESTABLISHED — this dataset arrived with no licence, no attribution and no upstream URL. It is staged for evaluation only and is NOT cleared for redistribution, for a shipped column, or for client-facing display. It is listed here because we hold it, not because we are entitled to use it. Required credit line: District boundaries: source unverified. Supplied without attribution or licence; provenance not established. Not cleared for redistribution or client-facing display. Note: ⚠️ NEEDS REVIEW BEFORE ANY USE BEYOND STAGING. No attribution, licence text or upstream URL accompanied this file. The property schema (district_id / city_id / region_id / name_ar / name_en) resembles Saudi National Address / SPL lineage but that is a resemblance, not a provenance. This layer supplies the geography that lands land_value_sqm on hexes and it carries NO population field — it is a district polygon layer, not a district census, so SS-1-04 census calibration and the ±5% district exit gate remain unevaluable and the banking and clinic profiles must keep refusing to score. SS-1-14 has since composed land_value_sqm through these polygons, and SS-1-08 composed the modelled affluence_index on top of that column, which it requires; both widened the exposure and resolved none of it. Withdrawing the layer means NULLing those two columns — `compose_land_value`'s reset path and `compose_affluence.ODBL_DROP_SQL` do exactly that, and no third column reads this geography. PROVENANCE RESEARCH (see provenance_candidates): the file is now traced, by measurement, to a public GeoJSON whose own README says it was scraped from the Saudi National Address portal. That identifies the lineage and closes NOTHING — the stated licence is a software copyleft over data the publisher did not own. The question is still open and this entry still carries UNKNOWN_PROVENANCE. The layer's third and most visible consumer is not a column at all: district NAMES, which every client-facing deliverable prints. That exposure is now gated on the `district_names_cleared` capability (`baseline.clearance`), default False, so a deliverable renders reference ids and coordinates instead of names and stays releasable while this item is open. ================================================================================ H3 — Uber hierarchical hexagonal grid (h3-pg) — Apache-2.0 ================================================================================ Source: https://h3geo.org/ Licence: Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) Version: h3 4.5.0 / h3_postgis 4.5.0 Used in: region_baseline_h3 Required credit line: H3 © Uber Technologies, Apache License 2.0 Note: Software, not data: Apache-2.0 applies to the H3 library that generates the cell identifiers. Listed because every row of the baseline is keyed by one, and the ledger records it as a source. ================================================================================ Unified POI inventory (in-house) — inherits ODbL-1.0 ================================================================================ Built in-house from: foursquare_places, overture_places, osm Tables: staging.poi_unified Share-alike: YES — inherited from an upstream, and it does not dilute with row share. No credit is owed to this table; credit is owed to what is inside it: © Foursquare Labs, Inc. Foursquare OS Places, licensed under the Apache License 2.0. © Overture Maps Foundation © OpenStreetMap contributors, ODbL 1.0 Note: Measured membership at the time of writing: 174,416 rows carrying a Foursquare source, 41,414 Overture, 14,288 OpenStreetMap. The 14,288 are why the whole table inherits ODbL-1.0 and share-alike. ================================================================================ Normalized brand register (in-house) — inherits ODbL-1.0 ================================================================================ Built in-house from: foursquare_places, overture_places, osm Tables: staging.poi_brand Share-alike: YES — inherited from an upstream, and it does not dilute with row share. No credit is owed to this table; credit is owed to what is inside it: © Foursquare Labs, Inc. Foursquare OS Places, licensed under the Apache License 2.0. © Overture Maps Foundation © OpenStreetMap contributors, ODbL 1.0 Note: Brand keys are derived from names, domains and wikidata ids carried on the unified POIs, so the brand register inherits exactly what the spine does. ================================================================================ POI counts and brand presence on the baseline grid (in-house) — inherits ODbL-1.0 ================================================================================ Built in-house from: foursquare_places, overture_places, osm Tables: region_baseline_h3 Share-alike: YES — inherited from an upstream, and it does not dilute with row share. No credit is owed to this table; credit is owed to what is inside it: © Foursquare Labs, Inc. Foursquare OS Places, licensed under the Apache License 2.0. © Overture Maps Foundation © OpenStreetMap contributors, ODbL 1.0 Note: This is the lane where the obligation becomes visible outside staging, so it logs the inherited ODbL-1.0 rather than the `derived` sentinel — and every cell it writes carries "share_alike": true in source_flags, which is what §9.2 separability is checked against. ================================================================================ GADM — deliberately absent ================================================================================ GADM is the first result for 'admin boundaries', it is excellent, and its licence prohibits commercial redistribution (DATA_STRATEGY §1, licence trap #1). It is registered in `base.LICENCES` only so that constructing a Provenance against it raises ForbiddenLicenceError. It is not credited here because crediting it would imply we use it.