← Back

This is an English courtesy translation for your convenience. The legally binding version is the German original — see the German version.

General Terms and Conditions (GTC) for the SpamProtec service

These General Terms and Conditions apply to the use of the cloud-based email protection service SpamProtec (hereinafter "Service" or "SpamProtec"). They are addressed both to entrepreneurs and to consumers. Wherever a distinction is drawn below between the two groups, this is expressly indicated.

§ 1 Provider, Scope of Application, Definitions

(1) The provider and contracting party is:

MessingerDesign – Philipp Messinger & Werner Messinger GbR
represented by the partners Philipp Messinger and Werner Messinger
Dahmestraße 10
12526 Berlin
Deutschland
Email:
Telephone:
USt-IdNr.: DE332090964

The complete mandatory information pursuant to § 5 DDG (German Digital Services Act) can additionally be found in the legal notice (Impressum) at https://spamprotec.de/impressum.

(2) These GTC apply to all contracts concerning the provision and use of the SpamProtec service concluded between the provider and the customer. The version valid at the time the contract is concluded is authoritative. The provider currently offers the Service exclusively to customers who have their registered office, residence or habitual residence in the Federal Republic of Germany; contracts with customers outside Germany are concluded only by separate agreement.

(3) A consumer is any natural person who concludes the contract for purposes that are predominantly outside their trade, business or profession (§ 13 BGB, German Civil Code). An entrepreneur is a natural or legal person or a partnership with legal capacity that, when concluding the contract, is acting in the exercise of its trade, business or profession (§ 14 BGB). A customer within the meaning of these GTC is both a consumer and an entrepreneur. Text form within the meaning of these GTC is the text form pursuant to § 126b BGB (e.g. email). A durable medium is any medium that enables the recipient to store declarations addressed to them in such a way that they remain accessible and reproducible unchanged (§ 126b sentence 2 BGB), e.g. an email that has been sent or a PDF file transmitted as an attachment; the mere availability for retrieval on the website is not sufficient for this purpose.

(4) Deviating, conflicting or supplementary general terms and conditions of the customer do not become part of the contract unless the provider expressly consents to their validity in text form. This also applies where the provider renders performance without reservation in the knowledge of such terms. This provision is generally only of practical relevance in dealings with entrepreneurs.

§ 2 Subject Matter of the Service and Mode of Operation

(1) SpamProtec is a cloud-based service for protecting email mailboxes against unwanted, fraudulent or harmful messages (in particular spam, phishing, references to malware). For this purpose, the Service connects to the email mailboxes specified by the customer via the IMAP protocol and analyses messages.

(2) Scope of access: Using the access credentials provided by the customer, the Service accesses the connected mailboxes for both reading and writing. Write access includes in particular: reading messages, setting and removing flags (e.g. read/unread), moving messages, creating folders (including technical auxiliary or quarantine folders, which may be visible in the mailbox or – in the optional pre-check mode (paragraph 3) – initially hidden for the purpose of pre-checking), creating new copies when retrieving messages, as well as removing sorted-out or retrieved messages from the respective folder. Depending on the email provider, such removal is technically carried out by copying and deleting; storage in the mailbox's trash folder is not possible in all cases. What is definitively removed in each case is only the source copy that has become superfluous as a result of the move or retrieval; the content of the message is fully retained in the destination or target location (e.g. spam/quarantine folder or inbox). Covered are incoming messages as well as – depending on the configuration chosen by the customer – already existing messages (for the subsequent assessment of the existing stock) and the "Sent" folder (for the recognition of known correspondents). Insofar as technically offered, the customer can control the scope of access (incoming messages only / including existing stock / including "Sent") via the configuration; the scope of functions for each level is set out in the service description (annex pursuant to paragraph 9). By providing the access credentials, the customer ensures the access required for this purpose.

(3) Detected unwanted messages are moved or sorted into a separate spam/quarantine folder that is visible to the customer and remain accessible to the customer there. Depending on the configuration, new messages that have not yet been assessed may be placed for a short time in a separate folder for checking before they first become visible (optional pre-check mode, see § 8 para. 1). The customer can review classifications via the dashboard, retrieve messages as "not spam", and release (allowlist) or block (blocklist) senders. When a message is retrieved, it is placed at the top of the inbox as a fresh copy with the current receipt/delivery date and is generally marked as unread; the previously sorted-out copy is thereby removed from the spam/quarantine folder (depending on the provider, without storage in the trash). The original receipt date stored in the message header is retained; however, the sort order in the inbox may change. This is not intended to destroy the content of desired user data; the retrieval concerns exclusively the copy that the Service itself had previously sorted out, and the message content is retained. For an erroneous deletion or move for which the provider is responsible, the provider is liable pursuant to § 11 paras. 1 to 4. The customer is advised to back up messages that are important to them independently hereof (§ 7 para. 6).

(4) Asynchronous processing / no real-time filtering: The analysis is carried out asynchronously at regular intervals as well as on an event-driven basis. Real-time filtering at the moment a mail arrives is not owed; this also applies in the optional pre-check mode. Messages that have already been delivered can only be assessed at the next processing run; there may therefore be a delay between the arrival of a message and its assessment. The order of magnitude of the usual processing interval is set out in the service description (annex pursuant to paragraph 9). A particular response, processing or latency time is owed only insofar as this is expressly agreed in the respective package.

(5) Detection is carried out in multiple stages by means of rule-based procedures, reputation and authentication checks (including SPF/DKIM/DMARC) as well as through the use of artificial intelligence (AI) procedures for content and context assessment. The consideration of known correspondents (in particular from the "Sent" folder, paragraph 2) and of the allowlist is a probability-based measure that supports detection; it increases the likelihood of a correct classification but does not bring about guaranteed delivery, does not exclude a differing assessment in an individual case (e.g. in the case of sender spoofing or compromised accounts), and does not constitute a guarantee that messages from these senders will never be sorted out. Overall, this is an automated pre-sorting with the possibility of human review and correction by the customer at any time (dashboard, "not spam" function, allowlist/blocklist); a solely automated decision with legal or similarly significant effect within the meaning of Art. 22 DSGVO (GDPR) does not exist. Details concerning data processing, the use of external AI service providers and cross-customer reputation learning are governed by § 9.

(6) System requirements / compatibility: A prerequisite for use is an email mailbox accessible via IMAP with valid access credentials or an application-specific password. The Service depends on the IMAP access of the respective email provider; if a provider blocks third-party access via IMAP or if certain two-factor configurations do not permit an application-specific access, the Service cannot work with that mailbox or can do so only to a limited extent. If a provider does not support the IMAP command for moving (MOVE), the move is technically carried out by copying and subsequently deleting the source message; in this process the source copy – which has become superfluous as a result of the operation – is removed (depending on the provider, without storage in the trash), while the message content is retained in the destination location. In all other respects, the scope of functions is set out in the service description valid at the time the contract is concluded (annex pursuant to paragraph 9) as well as in the booked package.

(7) Further development and modification of the Service: The provider regularly updates and adapts the detection procedures (in particular rule sets and the models used) and provides updates in accordance with § 327f BGB. Modifications that are necessary to maintain conformity with the contract, to safeguard IT security or on account of statutory requirements are permissible at any time. The provider makes modifications to the Service going beyond this vis-à-vis consumers only under the conditions of § 327r BGB, namely only where there is a valid reason, without additional costs for the consumer, and subject to clear and comprehensible information. If such a modification impairs the consumer's access to or usability of the Service more than merely negligibly, the consumer may terminate the contract free of charge within 30 days of receipt of the information or from the time of the modification (whichever is later). The contractually owed core benefit – the reduction of unwanted messages in the connected mailboxes – is retained; the removal of essential functions without replacement is not covered by this right of modification. Modifications of these GTC (contractual terms) are governed conclusively by § 12; modifications of the Service itself vis-à-vis consumers are governed exclusively by this paragraph.

(8) Material note on the mode of operation and the performance owed: SpamProtec is an automated aid for reducing unwanted emails. What is owed is the probability-based, careful reduction of unwanted messages in the connected mailboxes in accordance with the service description (annex pursuant to paragraph 9), not the correct classification of each individual message. A particular detection rate or false-positive rate is promised only insofar as it is expressly quantified in the respective package or in the service description. Complete, error-free detection of all spam, phishing or harmful messages is technically not possible. It can happen both that unwanted messages are not detected (false negative) and that desired messages are erroneously classified as unwanted (false positive). The occurrence of individual false-positive/false-negative results is inherent in the way a probability-based classification works and, as long as the Service operates within the detection quality to be expected under the service description, does not in itself constitute a breach of duty by the provider. Liability remains unaffected where the provider breaches a specific duty of care or the Service falls significantly short of the owed quality; in this respect § 11 applies. This description specifies the subjective requirements for the performance; vis-à-vis consumers, the objective requirements pursuant to §§ 327e, 327g BGB remain unaffected (cf. § 10 para. 2). The Service does not replace the customer's own responsible review of their email traffic.

(9) Service description as an annex: The service description authoritative for the booked package (scope of functions, configurable access levels, order of magnitude of the processing interval, period for the provision of updates, and any expressly quantified key figures) is part of the contract. It is made available to the customer before conclusion of the contract, as an annex, in the versioned form valid at the time the contract is concluded, and is stored on a durable medium together with the contract confirmation (§ 3 para. 5). Authoritative for the owed quality is this version provided at the time the contract is concluded; a mere reference to website content that can be changed at any time is not solely authoritative in this respect.

§ 3 Conclusion of Contract, Incorporation of the GTC, Confirmation

(1) The presentation of the Service on the website does not constitute a binding offer, but an invitation to submit an offer by the customer.

(2) By submitting the order, the customer makes a binding offer to conclude a usage contract. Vis-à-vis consumers, the order is placed via a button that is clearly legible and labelled exclusively with the words "zahlungspflichtig bestellen" ("order with obligation to pay") (§ 312j Abs. 3 BGB). Immediately before the order is placed, the consumer is provided with the information pursuant to § 312j Abs. 2 BGB – in particular the essential characteristics of the Service, the total price including all taxes and price components (gross final price), the term, and the termination conditions including automatic renewal – clearly and in a prominent manner directly above the order button. Also before conclusion of the contract, the consumer is notified in a clearly visible manner that, for the purpose of AI-supported assessment, email contents may be transmitted to external service providers in the USA (§ 9 para. 4).

(3) The contract is concluded upon receipt of the provider's declaration of acceptance (e.g. the contract confirmation) by the customer. If the consumer has requested performance before expiry of the withdrawal period (paragraph 6), the contract is concluded at the latest upon provision of the access credentials or activation of the Service.

(4) Incorporation of the GTC: Before submitting the order, the customer gains reasonable knowledge of the content of these GTC (linking/availability for retrieval) and, by submitting the order, declares their agreement to their validity. The GTC as well as the service description (§ 2 para. 9) and – in dealings with entrepreneurs – the data processing agreement (§ 9 para. 2) are made available to the customer before conclusion of the contract in a form suitable for storage and reproduction (text form/durable medium) and can be retrieved, stored and printed at any time on the provider's website.

(5) Contract confirmation: The provider confirms the contract to the consumer within a reasonable period after conclusion of the contract, at the latest at the start of performance, on a durable medium (§ 312f BGB), namely by active transmission (e.g. by email), not by mere availability for retrieval on the website. In the case of early activation (paragraph 6, § 6), the contract confirmation is transmitted to the consumer immediately after conclusion of the contract and before the start of performance; in this case it also contains the reproduction of the consumer's express consent to the early start as well as their acknowledgement of knowledge regarding the lapse of the right of withdrawal.

(6) Early activation: If the consumer wishes activation before expiry of the withdrawal period, they give, in the ordering process by actively and separately ticking fields that are in each case not pre-selected, (i) their express consent to the start of performance before expiry of the withdrawal period and (ii) confirmation of their knowledge that, upon full performance of the contract, they lose their right of withdrawal and – in the event of withdrawal before that point – owe proportionate value compensation for the performance rendered up to the withdrawal (§ 356 Abs. 5, § 357a Abs. 2 BGB). Immediately adjacent to the double checkbox, the ordering process clearly points out that, by activating before expiry of the 14-day withdrawal period, the consumer loses their right of withdrawal only upon complete performance of the service and, in the case of an earlier withdrawal, must pay proportionate value compensation. In the case of term-bound contracts (in particular annual packages), full performance of the contract occurs only upon expiry of the agreed term; until then the right of withdrawal continues to exist, and any value compensation is calculated pro rata temporis (days in relation to the total term) on the basis of the agreed total price. These declarations are documented. If the consumer does not give these declarations, activation takes place only after expiry of the withdrawal period; no value-compensation or lapse issue then arises.

(7) Information in electronic commerce: The contract text is stored by the provider and made accessible to the customer with the contract confirmation on a durable medium; the customer can additionally retrieve their contract text in the customer account. Before submitting the order, the customer is informed of the individual technical steps leading to the conclusion of the contract, provided with a means of recognising and correcting input errors, and informed about the storage of the contract text and its accessibility (§ 312i BGB in conjunction with Art. 246c EGBGB, Introductory Act to the German Civil Code). The contract language is German.

§ 4 Remuneration, Price Information, Payment Conditions, Invoicing

(1) The amount of the remuneration is determined by the booked package in accordance with the price overview valid at the time the contract is concluded, which in turn states prices in accordance with the German Price Indication Ordinance (Preisangabenverordnung). The price stated vis-à-vis consumers is always the total price including all taxes and price components (gross final price); the statement is made in accordance with the VAT status pursuant to paragraph 2. In the case of subscriptions, the costs incurred per billing period as well as the resulting total charge per year are stated. The authoritative total price is displayed to the consumer clearly and comprehensibly in the ordering process directly above the order button.

(2) VAT status: The provider is subject to standard taxation. All prices stated vis-à-vis consumers are total prices (gross final prices) including statutory value-added tax at the applicable rate (currently 19%). The amounts stated in the ordering process and in the price overview are the final prices to be paid by the customer inclusive of VAT; vis-à-vis entrepreneurs, too, the stated amount is deemed to be a gross price, whereby the VAT contained therein is shown separately on the invoice. The provider's VAT identification number is DE332090964.

(3) SpamProtec is currently offered predominantly in the form of annual packages, which are to be paid in advance for the respective term. In the case of annual packages, the customer is obliged to pay in advance for the entire term; the consumer's right of withdrawal (§ 6) as well as any claims for reimbursement upon early termination of the contract remain unaffected. In the case of annual packages with advance payment, the amount becomes due upon conclusion of the contract; activation takes place – except in the case of an expressly requested early start (§ 3 para. 6) – only after expiry of the withdrawal period, without the consumer thereby incurring any interest disadvantages. In the future, the Service may additionally be offered as an ongoing subscription (e.g. via PayPal) with recurring debits. In the case of subscriptions, the remuneration becomes due in each case in advance for the agreed billing period and is automatically collected via the chosen payment service provider. In all other respects, the remuneration becomes due upon invoicing without deduction and is to be paid within 14 days, unless otherwise agreed.

(4) Payment is made via the payment methods offered in the ordering process. Where external payment service providers (e.g. PayPal) are involved, their terms of use and data protection conditions apply additionally in the relationship between the customer and the payment service provider.

(5) Invoicing: The provider makes available to the customer an invoice for the remuneration in text form (e.g. as a PDF) that contains the information required pursuant to § 14 Abs. 4 UStG (German VAT Act) or – for small-amount invoices up to 250 euros – pursuant to § 34 UStDV (German VAT Implementing Ordinance). The provider shows the statutory VAT separately on the invoice (tax rate and tax amount) and states its VAT identification number. Vis-à-vis entrepreneurs, the provider makes available, upon request, an invoice complying with the statutory requirements and can, in domestic business-to-business dealings, receive electronic invoices within the meaning of § 14 UStG as well as – insofar as legally obliged – issue them (e.g. XRechnung/ZUGFeRD).

(6) If the customer is in default with a payment, the statutory default provisions apply (§§ 286, 288 BGB). Vis-à-vis consumers, default on monetary claims occurs only under the conditions of § 286 BGB, in particular at the latest 30 days after the due date and receipt of an invoice (§ 286 Abs. 3 BGB), where this consequence was specifically pointed out on the invoice. Vis-à-vis entrepreneurs, the default interest rate is nine percentage points above the base interest rate; in addition, the provider may claim a flat rate of 40 euros pursuant to § 288 Abs. 5 BGB, which is to be set off against any damages owed insofar as the damage is based on the costs of legal action (§ 288 Abs. 5 sentence 3 BGB). Vis-à-vis consumers, the default interest rate is five percentage points above the base interest rate. The provider is further entitled, after prior notice and setting a reasonable deadline, to suspend the Service until full receipt of payment, but only in the case of a not insignificant payment arrears and while observing proportionality. A payment arrears is generally not insignificant if the customer is in default with at least two consecutive billing amounts or with an amount equal to at least the fee for one billing period. A suspension does not take place insofar as the customer legitimately withholds or reduces the payment for a reason coherently set out by them, or duly disputes the claim. The right to extraordinary termination remains unaffected.

(7) Price adjustment for ongoing subscriptions: The provider is entitled to adjust the fees for ongoing subscriptions with effect for the future, but exclusively to offset changes in the costs actually incurred by it. Authoritative are in particular changes in the costs for the external AI and cloud/infrastructure service providers used, for licences, energy, as well as for personnel costs directly attributable to the operation of the Service. An increase is permissible only to the extent that these costs have in total actually increased; the percentage fee increase may not exceed the demonstrated percentage rise of the cost items mentioned, and an increase of the profit share is excluded. Upon the customer's request, the provider discloses the calculation basis of the adjustment in a comprehensible form. If the aforementioned costs fall, the provider is obliged to reduce the fees to the same extent (symmetry requirement). An adjustment is made at most once per calendar year. The adjustment is notified to the customer in text form, stating the reason, at least six weeks before it takes effect. The customer has the right to terminate the contract with effect from the time the increase takes effect; this special right of termination is separately pointed out in the notification. In the case of annual packages paid in advance, an adjustment becomes effective only at the next renewal of the contract; in this case it is notified in such good time, at least six weeks before the end of the current term, that the customer can still terminate the contract as of the end of the current term.

(8) Free trial phase: New customers can, in accordance with the respective offer, test the Service once free of charge for seven (7) days. No means of payment is stored for the trial phase; after expiry of the trial phase there is no automatic debit and no payment obligation arises. If the customer does not conclude a paid subscription by the end of the trial phase, the protection pauses after expiry of the trial phase; the connected mailboxes are then no longer filtered until a paid subscription is concluded.

§ 5 Term and Termination

(1) The contract term is determined by the booked package. Annual packages have a term of twelve months from activation.

(2) Vis-à-vis consumers, the contract is extended after expiry of the initial term for an indefinite period. After expiry of the initial term, the contract may be terminated at any time – without being bound to a particular date – with a notice period of one month (cf. § 309 Nr. 9 BGB). The initial term may be terminated with a notice period of one month as of the end of the initial term; otherwise the aforementioned extension for an indefinite period takes effect.

(3) Vis-à-vis entrepreneurs, the contract is extended by twelve months in each case unless it is terminated in text form with a notice period of three months as of the respective end of the term. The provider notifies entrepreneurs in text form in good time, generally about six weeks before expiry of the notice period, of the upcoming end of the term and the extension.

(4) In the case of ongoing subscriptions, the contract may be terminated by consumers at any time as of the end of the current billing period.

(5) The right of both parties to extraordinary termination for good cause remains unaffected. Good cause exists for the provider in particular where the customer, despite a warning, repeatedly or seriously breaches their obligations under § 7.

(6) Terminations require at least text form (e.g. email); a handwritten signature is not necessary. For consumer contracts on a continuing obligation concluded in electronic commerce, the provider makes available a termination button ("terminate contracts here") complying with the requirements of § 312k BGB together with a confirmation page and a termination confirmation in text form, via which the consumer can terminate easily accessibly at any time without logging in.

(7) Consequences of termination for the connected mailboxes: Upon termination of the contract, the provider ceases access to the connected mailboxes and logs out from them. Folders previously created by the Service and messages moved there remain in the customer's mailbox; since the provider no longer has access after termination, moving them back or tidying them up is the customer's responsibility. The provider actively points this out to the customer in the termination/ending process and, at the customer's request, moves the sorted-out messages back into the inbox before deactivation. The customer is advised to change the (application-specific) password used for the Service at the end of the contract (§ 7 para. 3). The return of the data concerning the customer is governed by § 9 para. 7.

(8) Tariff change (upgrade/downgrade): The customer can at any time switch to a higher-value tariff or a larger mailbox tier (upgrade); the upgrade takes effect immediately, and the additional price is charged pro rata for the current billing period. A switch to a lower tariff or a smaller mailbox tier (downgrade) takes effect at the end of the current, already paid billing period; until then the booked scope of performance is retained. A prerequisite for a downgrade is that the number of mailboxes connected at the time it takes effect does not exceed the limit of the target tariff; otherwise the customer must reduce the number of connected mailboxes accordingly before it takes effect.

§ 6 Right of Withdrawal for Consumers

Consumers are entitled to the following statutory right of withdrawal. Entrepreneurs are not entitled to a right of withdrawal. SpamProtec is a digital service within the meaning of §§ 327 ff. BGB; the right of withdrawal, its lapse and the value compensation are therefore governed by § 356 Abs. 5 and § 357a Abs. 2 BGB.

Withdrawal instructions

Right of withdrawal
You have the right to withdraw from this contract within fourteen days without giving any reason. The withdrawal period is fourteen days from the day on which the contract is concluded.

To exercise your right of withdrawal, you must inform us (MessingerDesign – Philipp Messinger & Werner Messinger GbR, Dahmestraße 10, 12526 Berlin, Deutschland, email: , telephone: ) of your decision to withdraw from this contract by means of an unequivocal statement (e.g. a letter sent by post or an email). You may use the attached model withdrawal form for this purpose, although it is not mandatory.

To meet the withdrawal deadline, it is sufficient for you to send the communication concerning the exercise of the right of withdrawal before the withdrawal period expires.

Consequences of withdrawal
If you withdraw from this contract, we must repay to you all payments we have received from you without undue delay and at the latest within fourteen days from the day on which we receive the communication of your withdrawal from this contract. For this repayment, we use the same means of payment that you used for the original transaction, unless expressly agreed otherwise with you; under no circumstances will you be charged any fees for this repayment.

If you requested that the service should begin during the withdrawal period, you must pay us a reasonable amount corresponding to the proportion of the services already provided up to the point at which you inform us of the exercise of the right of withdrawal in respect of this contract, compared to the total scope of the services provided for in the contract. The amount is calculated proportionately on the basis of the agreed total price.

Early lapse of the right of withdrawal
Your right of withdrawal lapses, in the case of a contract for the provision of a digital service not supplied on a physical medium, where we have begun performing the contract, you have expressly consented to us beginning performance before expiry of the withdrawal period, you have confirmed your knowledge that, by your consent, you lose your right of withdrawal upon complete performance of the contract when performance begins, and we have provided you with a confirmation of the contract pursuant to § 312f BGB on a durable medium (§ 356 Abs. 5 BGB).

Supplementary notes on value compensation
In the case of term-bound contracts (in particular annual packages), full performance of the contract occurs only upon expiry of the agreed term; until then your right of withdrawal – even after an early start – continues to exist. In this case, any value compensation is calculated to the exact day and proportionately according to the ratio of the performance rendered up to the withdrawal to the total performance owed (example: for an annual package of 60 euros and withdrawal on the 10th day, the value compensation is approximately 60 euros × 10/365, i.e. around 1.64 euros). No value compensation is to be paid insofar as the conditions of § 357a Abs. 2 BGB are not met, in particular where we have not provided you with the confirmation of the contract pursuant to § 312f BGB on a durable medium or have not obtained your express consent and acknowledgement of knowledge for the early start.

Note on immediate provision: If the consumer wishes the SpamProtec service to be activated and enabled before expiry of the withdrawal period, they are asked separately in the ordering process for their express consent as well as for confirmation of their knowledge of the loss of the right of withdrawal and of the (proportionate) obligation to pay value compensation in the case of an earlier withdrawal (§ 3 para. 6). If the consumer does not give this consent, activation takes place only after expiry of the withdrawal period; in this case no value-compensation or lapse issue arises. The 14-day period begins on the day on which the contract was concluded, regardless of when you receive the contract confirmation.

Model withdrawal form
(If you wish to withdraw from the contract, please complete this form and return it.)

— To: MessingerDesign – Philipp Messinger & Werner Messinger GbR, Dahmestraße 10, 12526 Berlin, Deutschland, email: , telephone:
— I/we (*) hereby withdraw from the contract concluded by me/us (*) for the provision of the following service (*)
— Ordered on (*)/received on (*)
— Name of the consumer(s)
— Address of the consumer(s)
— Signature of the consumer(s) (only for notification on paper)
— Date
(*) Delete as appropriate.

§ 7 Duties and Obligations of the Customer

(1) The customer makes available to the provider, correctly and completely, the access credentials required for setting up the Service (in particular the IMAP access credentials of the mailboxes to be protected) and keeps them up to date.

(2) The customer is obliged to ensure that they are authorised to grant the access credentials and to connect the mailboxes concerned and that no third-party rights conflict. If the customer connects mailboxes whose holders are third parties (e.g. employees), or if the customer processes emails of third parties via the Service, the customer is solely responsible for the data protection admissibility; in particular, they must inform the data subjects pursuant to Art. 13/14 DSGVO, ensure a sound legal basis and – insofar as relevant (e.g. in the case of employee mailboxes) – examine the required involvements (such as of the works council), the confidentiality of telecommunications in the case of permitted private use, as well as the admissibility of reading by an external service (see § 9). The customer connects exclusively mailboxes for which either there is no permitted private use by third parties or, for any capture of private correspondence, an effective legal basis (in particular consent or a works/service agreement) exists. The customer confirms this separately during onboarding. The provider is entitled to refuse or end the connection of a mailbox if there are concrete indications of an evidently inadmissible monitoring or a breach of the confidentiality of telecommunications.

(3) The customer keeps their access credentials for the Service confidential and protects them from access by unauthorised persons. They inform the provider without undue delay if there are indications of misuse. The customer is advised to use, where possible, a separate or application-specific password for the Service and to change it at the end of the contract.

(4) The customer does not use the Service abusively, in particular not to circumvent third parties' protective mechanisms, to send unwanted messages, or in a manner that impairs the availability or integrity of the Service.

(5) Duty to check and monitor: On account of the technical limits of automated classification described in § 2, the customer must review the area sorted out as unwanted and visible to them in the mailbox (spam/quarantine folder) at reasonable intervals appropriate to the respective purpose of use for erroneously sorted-out (false-positive) messages. In the case of business use with reliance on receiving certain messages, more frequent review is advisable. This duty exists exclusively for the spam/quarantine folder created by the Service and visible to the customer. For messages that are initially held back invisibly during an active optional pre-check mode, no duty of review applies to the customer; this duty begins only once the message becomes visible in the mailbox. There is no obligation of daily monitoring vis-à-vis consumers. This is merely an incumbency (Obliegenheit); its breach does not lead to an exclusion of claims, but is to be taken into account within the framework of any contributory fault pursuant to § 254 BGB (§ 11 para. 4).

(6) The customer takes responsibility for making regular backups of their email data appropriate to the risk.

§ 8 Availability, Maintenance, Support, Cooperation of Third Parties

(1) The provider endeavours to achieve high availability of the Service. Vis-à-vis consumers, the Service processes the connected mailboxes on an ongoing basis within the order of magnitude of the processing interval stated in the service description (§ 2 para. 9); real-time filtering to the exact day is not owed (§ 2 para. 4). The objective requirements as to the usual quality pursuant to § 327e BGB remain unaffected; a deviation therefrom vis-à-vis consumers takes place only under the conditions of § 327h BGB (separate notification and express, separate agreement in the ordering process). Vis-à-vis entrepreneurs, a particular availability or processing frequency/latency is promised only insofar as this is expressly agreed in the respective package or in the service description and is defined – including measurement point, measurement period and exceptions; without such an agreement, no particular availability is owed vis-à-vis entrepreneurs, and the provider renders the Service in this respect with the customary care. Any availability metric refers to the ongoing processing of the connected mailboxes (filter runs) or the accessibility of the dashboard, not to the receipt of mail, which is provided independently by the email provider. Insofar as the Service is not operated in the optional pre-check mode, messages are delivered regularly to the customer's mailbox by the email provider independently of the Service; in the event of an outage, only the filtering pauses and is resumed after restoration. If the optional pre-check mode is activated (§ 2 para. 3), the visibility of newly arriving messages may be delayed during a disruption; in such a case the system automatically releases held-back messages after a short time (fail-open).

(2) Not counted towards availability are periods of planned maintenance work, which the provider announces where possible and schedules for low-usage times, as well as outages due to force majeure or due to disruptions that lie outside the provider's sphere of influence.

(3) Support: Support is provided in text form at . The provider endeavours to process fault reports on working days within a reasonable period. A particular response or restoration time is promised only insofar as expressly agreed in the package or in the service description.

(4) The Service depends on interaction with third-party systems, in particular with the customer's email servers or those of their email provider as well as with external service providers (cf. § 9). Disruptions, changes or outages of such third-party systems (e.g. changes to IMAP interfaces, blocks on the part of the email provider) lie, insofar as the provider is not responsible for them, outside its sphere of influence; the provider endeavours to make appropriate adjustments but does not owe any success vis-à-vis third parties. The provider's liability for its own fault, in particular in adapting to changes of third-party systems, is governed by § 11.

§ 9 Data Protection, Allocation of Roles, Commissioned Processing and Use of External AI Service Providers

(1) In the course of providing the Service, the provider processes personal data, in particular the contents, metadata and sender/recipient details of the messages of the mailboxes connected by the customer, as well as the further data stocks described in § 2 para. 2. The controller for the provider's own processing is the provider named in § 1; the core purposes are the defence against spam/phishing/malware and the provision of the Service. The provider's own processing is based on the legal bases named in paragraph 2 (B2C) or in the DPA (B2B); a transmission to external AI service providers in the USA takes place (paragraph 4). Data subjects are entitled to the right to lodge a complaint with a supervisory authority pursuant to Art. 77 DSGVO. The email contents and metadata as well as access credentials stored for the provision of the Service are deleted within 30 days after the end of the contract (paragraph 7). The complete mandatory information pursuant to Art. 13/14 DSGVO (controller, purposes, legal bases, recipients including the provider's own processing infrastructure used for redaction/pseudonymisation with a location in Germany/EU, third-country transfer and transfer mechanism per recipient, storage and deletion periods per data type, data subject rights including the right to complain pursuant to Art. 77 DSGVO) is set out in the provider's privacy policy, available at https://spamprotec.de/legal/datenschutz. The versions published at the addresses named in this paragraph (privacy policy, data processing agreement, sub-processor/recipient list) are authoritative and are to be kept consistent both with one another and with these GTC; the versions provided at the time the contract is concluded are archived in versioned form.

(2) Allocation of roles by customer type:

(3) Duties of the customer as controller: Insofar as the customer is the controller, they are themselves responsible for the lawfulness of the processing (in particular for the existence of a legal basis, for informing the data subjects pursuant to Art. 13/14 DSGVO and – insofar as special categories of personal data pursuant to Art. 9 DSGVO may be affected – for the existence of a permissive provision pursuant to Art. 9 Abs. 2 DSGVO). They also inform the data subjects about the use of the sub-processors named in paragraph 4 and about the third-country transfer to the USA; the provider makes available to them the necessary information (list of sub-processors, safeguards) for this purpose and supports them in a data protection impact assessment to be carried out by them (Art. 28 Abs. 3 lit. f, Art. 35 DSGVO). The customer indemnifies the provider against third-party claims that are based on unlawful processing for which the customer is responsible; the indemnification is limited in amount to the share of causation/fault for which the customer is responsible, and contributory fault of the provider has a claim-reducing effect. This standardised indemnification obligation applies only vis-à-vis entrepreneurs. Vis-à-vis consumers, the statutory claims for damages remain applicable; there is no separate indemnification obligation of the consumer going beyond this. The provider's independent data protection responsibility and official measures directed against it remain unaffected hereby.

(4) Use of AI and external service providers (sub-processors); third-country transfer: For content and context assessment, the provider uses artificial intelligence procedures. In this context, external AI service providers are used whose processing may take place wholly or partly on servers in the United States of America, in particular:

These service providers are engaged: in the B2B relationship – insofar as the respective service provider is contractually engaged as a processor within the meaning of Art. 28 DSGVO – as sub-processors in accordance with the DPA; in the B2C relationship as service providers engaged by the provider. Insofar as a service provider processes transmitted data also for its own purposes (e.g. abuse/security monitoring), the respective role (processor or own controller) is indicated per recipient in the sub-processor/recipient list. The use of the service providers named by name above is part of the contractual core performance; without them the Service cannot be provided. The provider informs the customer about the intended addition or replacement of further sub-processors at least four weeks in advance in text form; this also applies vis-à-vis consumers (B2C). In the B2B relationship, the customer may object to the change within four weeks of receipt of the information. In the event of a justified objection to a new sub-processor, the provider primarily refrains from using the affected sub-processor vis-à-vis the objecting customer; if this is not technically possible, it grants the customer a special right of termination with proportionate reimbursement of fees paid in advance. An objection to the core service providers named by name above entitles the customer exclusively to terminate. Consumers have, in the case of a change disadvantageous to them, a special right of termination with proportionate reimbursement. An always up-to-date list of recipients (with country, concrete transfer mechanism, role and retention status per recipient, including the essential infrastructure/hosting service providers used by the service providers as sub-sub-processors) is maintained at https://spamprotec.de/legal/datenschutz and kept congruent with the privacy policy; the version of this list provided at the time the contract is concluded is authoritative for the content of the contract and is archived in versioned form.

The third-country transfer to the USA is safeguarded by appropriate safeguards within the meaning of Chapter V of the DSGVO. With each US recipient, EU standard contractual clauses (Implementing Decision (EU) 2021/914, Module 2 or 3) have been concluded, which, together with a documented transfer impact assessment and additional technical protective measures (in particular the redaction pursuant to paragraph 5), exist continuously as the basis for the transfer. The authoritative transfer mechanism per recipient is (i) the adequacy decision on the EU-U.S. Data Privacy Framework, insofar as and as long as the recipient is certified in active status (verifiable at data-privacy-framework.gov) and the concrete scope of processing is covered; (ii) otherwise the continuously existing EU standard contractual clauses together with a transfer impact assessment and additional measures. If a certification ceases to apply, the standard contractual clauses concluded in any event apply without further ado; if even their basis is not sound in an individual case, the transmission to the recipient concerned is omitted. The transfer mechanism actually used per recipient is maintained and kept up to date in the privacy policy or the sub-processor/recipient list. In the case of transmission to the USA, there is a residual risk of access by US authorities (in particular under FISA 702 / EO 12333) and of limited legal remedies for data subjects; this risk is countered by the standard contractual clauses, the transfer impact assessment, the redaction (paragraph 5) as well as – in the case of recipients certified under the Data Privacy Framework – by the legal remedy mechanism there (Data Protection Review Court); details are contained in the privacy policy. A copy of the appropriate safeguards or further information can be requested at . The transfer impact assessment is reviewed regularly and adapted to changes in the legal situation. The provider uses the AI service providers engaged – in accordance with the contractual/configuration options available per recipient and the status indicated in the recipient list – in such a way that transmitted contents are not used for training models; retention takes place only to the extent necessary for the provision of the Service and the prevention of misuse. The retention status actually agreed per recipient (including any activated zero-data retention) is maintained in the sub-processor/recipient list. These statements are a service description; a quality resulting therefrom remains owed, but the statements do not establish an independent guarantee within the meaning of § 443 BGB or § 11 para. 1 that would trigger a fault-independent liability going beyond the statutory liability for defects.

(5) Data minimisation and redaction before external transmission: Before a transmission of contents to external AI service providers, personal data is redacted or masked according to the state of the art. This redaction does not operate uniformly, but in a graduated manner: clearly structured identifiers (e.g. email addresses, telephone numbers, IBAN, account/ID numbers) are handled by an upstream protective procedure ("leak gate"), which in this respect closes in an error-oriented manner (fail-closed) and, in the event of a security incident, prevents an unredacted transmission. The recognition of free personal names in running text, by contrast, is carried out on a pattern basis (NER) and is not error-oriented closing (not fail-closed); it is not guaranteed to be complete and can, in particular in the event of a failure of name recognition, lead to residual personal references, the transmission of which is then safeguarded solely by the safeguards pursuant to paragraph 4. A complete exclusion of any personal references in free-text contents cannot be technically guaranteed; incoming messages may also contain special categories of personal data (Art. 9 DSGVO). The redaction is a supplementary, risk-mitigating technical protective measure; it does not replace the transfer safeguard pursuant to paragraph 4, on which the admissibility of the transmission fundamentally rests. Handling of special categories (Art. 9 DSGVO): The Service does not aim at the processing of special categories of personal data; a targeted detection of such data in free text does not take place. Insofar as such data is incidentally contained in message texts, it is treated like other content in accordance with the redaction and processed exclusively for the purpose of network and information security (defence against spam/phishing/malware), limited to the extent strictly necessary for this. Insofar as the provider is itself the controller in the B2C case and an incidental processing of special categories cannot be completely avoided despite redaction, it bases this on Art. 9 Abs. 2 lit. g DSGVO in conjunction with § 22 Abs. 1 Nr. 1 lit. d, Abs. 2 BDSG (German Federal Data Protection Act) (substantial public interest in ensuring network and information security, cf. Recital 49) and limits it to what is strictly necessary for IT security; the appropriate and specific protective measures pursuant to § 22 Abs. 2 BDSG (in particular redaction/leak gate, strict purpose limitation, access restriction, short processing duration) are implemented. The further justification of the permissive provision relied upon is set out in the privacy policy. Insofar as technically offered, the customer can restrict the scope of the external AI processing or deactivate it; for data-sensitive mailboxes, this possibility is offered bindingly insofar as technically feasible. The details and the scope of functions associated herewith are set out in the service description and the privacy policy. For the risks associated with this processing, the provider carries out a data protection impact assessment (Art. 35 DSGVO) and keeps it up to date.

(6) Crowd/reputation learning (provider's own processing): The provider also uses classification results across customers to improve detection for all customers (in particular platform-wide reputation, allow/block assessments on the basis of a swarm consensus). For this purpose, the provider processes reputation characteristics relating to senders (e.g. sender domains, hashed sender identifiers), primarily anonymised/aggregated (to that extent outside the scope of the GDPR) and only subsidiarily pseudonymised; the contents of individual messages or recipient references are not used for this. For the derivation of these reputation characteristics, no separate transmission of contents to the US service providers takes place; insofar as classification results are incorporated, the safeguards of paragraph 4 apply to the underlying content assessment. Insofar as the reputation characteristics have a personal reference, the provider is in this respect its own controller and bases this processing independently on Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in the defence against spam/phishing) on the basis of a documented balancing of interests; this own processing is not based on any authorisation by the customer. Data subjects – including the senders (third parties) – can object to this processing pursuant to Art. 21 DSGVO via the contact address reachable at ; details and the balancing of interests are governed by the privacy policy. The swarm assessment is only a probability-based input variable that remains overridable for each customer by their allow/blocklist and does not constitute an isolated final decision. This own processing is exempt from the commissioned processing pursuant to paragraph 2; in the B2B relationship, the customer additionally acknowledges in the DPA that the provider uses such reputation characteristics for security purposes as its own controller.

(7) Support, notification obligations, deletion and return: The provider supports the customer with suitable technical and organisational measures in fulfilling data subject rights (Art. 15–22 DSGVO) as well as in notification obligations pursuant to Art. 33/34 DSGVO and informs the customer of breaches of the protection of personal data without undue delay, without culpable delay and in such good time that the customer can meet their own notification obligations pursuant to Art. 33 DSGVO; the information contains the details required pursuant to Art. 33 Abs. 3 DSGVO insofar as available. Data subjects – including senders (third parties) – can assert rights of access, deletion and objection (Art. 15, 17, 21 DSGVO) as well as the right to complain pursuant to Art. 77 DSGVO directly vis-à-vis the provider at . After termination of the contract, the provider irreversibly deletes the access credentials of the connected mailboxes stored for the provision of the Service as well as the processed email contents and metadata within 30 days, insofar as no statutory retention obligations conflict; in the B2B relationship, the deletion or return takes place at the customer's choice (Art. 28 Abs. 3 lit. g DSGVO). Exempt from this 30-day period are the reputation characteristics relating to senders processed pursuant to paragraph 6; these are, insofar as personal, stored only for the duration of the security purpose and are, in accordance with paragraph 6, reassessed or deleted at regular intervals. A return of the data concerning the customer in a common, machine-readable format (in particular allow/blocklist and classification history) takes place upon request of any customer before deletion; for consumers, § 327p BGB additionally applies in this respect. The deletion is confirmed in text form upon request. Retention at external AI service providers and reputation data: Transmissions to AI service providers take place without storage going beyond the processing, insofar as zero-data retention is activated per recipient; otherwise the data is retained there only for the period necessary for the prevention of misuse and indicated per recipient in the sub-processor/recipient list. The concrete deletion and retention periods per data type (email contents/metadata, classification history/dashboard data, quarantine folder contents, reputation/learning data) are set out in the privacy policy or the DPA.

(8) Storage of the access credentials / technical and organisational measures: The IMAP access credentials required for the permanent connection are stored encrypted according to the state of the art (e.g. AES-256), since a recurring access to the mailbox requires a repeated login; the storage is therefore technically reversible. The key is kept separately from the database. The technical and organisational measures taken pursuant to Art. 32 DSGVO (in particular encryption at rest and in transit, key management, access and authorisation concept, logging and deletion routines) are documented and set out – in the B2B relationship from the DPA, otherwise from the provider's TOM/security concept, to which the privacy policy refers. Reference is made to the recommendation to use a separate/application-specific password (§ 7 para. 3).

§ 10 Warranty

(1) The provider renders the Service in accordance with the recognised rules of technology. The statutory rights in respect of defects apply, insofar as nothing to the contrary is provided below and insofar as no mandatory consumer protection provisions conflict.

(2) The benchmark for the owed quality is the service description (§ 2 para. 9); this specifies the subjective requirements. Vis-à-vis consumers, the objective requirements pursuant to §§ 327e, 327g BGB (fitness for the customary use, usual quality) remain unaffected; a deviation therefrom takes place only under the conditions of § 327h BGB. The customer takes note that the occurrence of individual false-positive and false-negative results described in § 2 para. 8 is inherent in the way a probability-based, AI-supported classification works and does not in itself constitute a defect, as long as the Service operates in accordance with the service description and with the detection quality described there. A defect exists if the Service falls significantly short of the agreed quality or – vis-à-vis consumers – of the quality usually to be expected under the objective requirements. If the provider breaches a specific duty of care, its liability pursuant to § 11 remains unaffected.

(3) For consumers, the statutory provisions apply without restriction, in particular the provisions on contracts for digital products (§§ 327 ff. BGB) including the update obligation. In the event of defects of the Service, consumers are entitled to the statutory rights pursuant to §§ 327 ff. BGB (in particular subsequent performance, price reduction and termination of the contract); to assert them, a communication to is sufficient.

(4) Vis-à-vis entrepreneurs, the limitation period for claims in respect of defects is one year from the statutory commencement of the limitation period; in the case of continuous provision, this applies for each provision/update period. Exempt from this are claims from the cases named in § 11 paras. 1 and 2 as well as claims for damages on account of intent or gross negligence, on account of injury to life, body or health, under the Product Liability Act, from an assumed guarantee, and on account of fraudulently concealed defects; in this respect the statutory limitation periods apply. Vis-à-vis consumers, the statutory limitation periods remain applicable.

§ 11 Liability

(1) The provider is liable without limitation

(2) Notwithstanding paragraph 1, the following applies: In the case of a slightly negligent breach of an essential contractual obligation (cardinal obligation) – i.e. an obligation whose fulfilment makes the proper performance of the contract possible in the first place and on whose observance the customer regularly relies and may rely – the provider's liability is limited to the typical, foreseeable damage; the unlimited liability pursuant to paragraph 1, in particular for injury to life, body or health as well as in the case of intent and gross negligence, remains unaffected hereby. Typical and foreseeable within the meaning of this limitation is the damage that, according to the ordinary course of events or according to the circumstances known or recognisable to the provider at the time the contract was concluded, was to be expected upon the occurrence of the damaging event (§ 252 BGB). Atypically high consequential damages from individual business transactions not known to the provider are recoverable only insofar as they were foreseeable according to this benchmark. Vis-à-vis entrepreneurs, the liability under this paragraph is additionally limited per damaging event, namely to the typical, foreseeable damage, but at most to the higher of the following two amounts: three times the annual net fee agreed for the contract concerned or 10,000 euros per damaging event. This maximum amount limit applies only insofar as it does not fall below the typical, foreseeable damage; otherwise the limitation to the typical, foreseeable damage remains applicable. This maximum amount limit is to be understood as an independent, severable provision; its possible invalidity leaves the limitation to the typical, foreseeable damage unaffected. Vis-à-vis consumers, no maximum amount limit applies.

(3) Notwithstanding paragraph 1, any liability of the provider going beyond this is excluded. In particular, the provider is not liable in the case of slight negligence for the breach of non-essential contractual obligations.

(4) Clarification on misclassification: The system-inherent occurrence of individual false-positive and false-negative results does not, within the framework of the detection quality to be expected under the service description, constitute a breach of duty by the provider (§ 2 para. 8, § 10 para. 2); the correct classification of each individual message is not owed. If, on the other hand, the Service falls significantly short of the owed quality or the provider breaches a specific duty of care (e.g. through an erroneous move or deletion of a message for which it is responsible), the liability provisions of paragraphs 1 to 3 apply unchanged; even in this case, the liability remains limited to the extent determined there. Insofar as the provider has a documented classification history, it can thereby demonstrate compliance with the owed care. Any contributory fault of the customer (§ 254 BGB), in particular the failure to carry out the reasonable review of the spam/quarantine folder visible to them (§ 7 para. 5), remains unaffected and is to be taken into account in accordance with the statutory provisions; contributory fault is not to be considered insofar as the customer could not review the message concerned – for example during an active pre-check mode – or it was not visible to them.

(5) In the case of a loss of data for which the provider is responsible, liability is limited to the typical restoration effort that would have arisen with regular data backup by the customer appropriate to the risk (§ 7 para. 6); vis-à-vis consumers, this limitation applies only insofar as the consumer has actually failed to carry out a data backup reasonable for them, and is measured solely according to § 254 BGB; an independent liability cap for a loss of data for which the provider is responsible is not established vis-à-vis consumers. Paragraphs 1 and 2 remain unaffected. A loss of data within the meaning of this paragraph is the loss of stored data as a result of technical defects outside the core function of the Service, but not a misclassification dealt with in § 11 para. 4 or an erroneous move or deletion by the Service for which the provider is responsible; for these, exclusively paragraphs 1 to 4 apply.

(6) Insofar as the provider's liability is excluded or limited, this also applies to the personal liability of the provider's legal representatives, employees and vicarious agents.

(7) The foregoing liability provisions apply equally vis-à-vis consumers and entrepreneurs, insofar as no mandatory statutory provisions (in particular § 309 Nr. 7 BGB as well as the provisions on contracts for digital products, §§ 327 ff. BGB) require otherwise; in no case are the rights of consumers that are indispensable under these provisions restricted. Vis-à-vis consumers, the legal remedies of §§ 327 ff. BGB as well as the statutory liability for damages pursuant to §§ 327 ff. BGB in conjunction with the general provisions remain unaffected; insofar as these provide for more extensive liability, this applies. The liability provisions of this § 11 concern claims for damages and reimbursement of expenses and do not restrict the consumer-protecting warranty rights. Mandatory statutory claims, in particular the claim for damages pursuant to Art. 82 DSGVO, are not restricted by the provisions of this § 11.

§ 12 Amendments to these GTC

(1) The provider is entitled to amend these GTC with effect for the future insofar as this is necessary to adapt to a changed legal situation, to supreme court case law, to technical further developments of the Service or to a changed engagement of service providers, and the customer is not thereby unreasonably disadvantaged. This § 12 concerns exclusively amendments to the GTC text (contractual terms). Modifications of the Service itself (scope of performance/functions) vis-à-vis consumers are governed exclusively by § 2 para. 7 (§ 327r BGB).

(2) Essential components of the contract, in particular the nature and scope of the main contractual performances as well as the fees (equivalence relationship), are exempt from the following fiction of consent; they can only be amended by mutual agreement or with the express consent of the customer. Fee adjustments for ongoing subscriptions are governed exclusively by § 4 para. 7.

(3) Non-disadvantageous amendments (fiction of consent): The fiction of consent applies exclusively to amendments that do not disadvantage the customer, namely editorial clarifications without any substantive effect, the implementation of mandatory statutory or supreme court requirements, as well as exclusively beneficial or neutral adjustments. Such amendments are notified to the customer in text form at least six weeks before they take effect. If the customer does not object within six weeks of receipt of the notification, the amendments are deemed to be accepted (§ 308 Nr. 5 BGB). The significance of silence as well as the right to object and the right to terminate are separately pointed out in the notification in a prominent form. If the customer objects in good time, either party may terminate the contract as of the time the amendment takes effect; until then the previous version continues to apply.

(4) Disadvantageous amendments: In case of doubt and in the case of any amendment disadvantaging the customer more than insignificantly, the express consent of the customer is required; without consent the previous version continues to apply. A fiction of consent through silence does not take place in this respect.

§ 13 Final Provisions, Dispute Resolution

(1) The law of the Federal Republic of Germany applies, to the exclusion of the UN Convention on Contracts for the International Sale of Goods. Vis-à-vis consumers, this choice of law applies only insofar as it does not thereby deprive the consumer of the protection granted by mandatory provisions of the law of the state of the consumer's habitual residence.

(2) If the customer is a merchant, a legal person under public law or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from this contractual relationship is the provider's registered office. Vis-à-vis consumers, exclusively the statutory places of jurisdiction apply; mandatory provisions on the consumer place of jurisdiction and on consumer protection at the consumer's habitual residence remain unaffected.

(3) Consumer dispute resolution: The provider is neither willing nor obliged to participate in a dispute resolution procedure before a consumer arbitration board (§ 36 VSBG, German Consumer Dispute Resolution Act). The generally competent body for consumer complaints is the Universal Consumer Arbitration Board of the Center for Arbitration (Allgemeine Verbraucherschlichtungsstelle des Zentrums für Schlichtung e. V., Straßburger Straße 8, 77694 Kehl, www.verbraucher-schlichter.de); the provider does not participate in an arbitration procedure before this body.

(4) Should individual provisions of these GTC be or become wholly or partly invalid or unenforceable, the validity of the remaining provisions is not affected thereby. In commercial dealings, the statutory (default) provision takes the place of the invalid or unenforceable provision; a validity-preserving reduction does not take place. Vis-à-vis consumers, the statutory provision remains applicable; a validity-preserving reduction to the detriment of the consumer does not take place.

As of: June 2026