Bedingungen und Konditionen

General Terms and Conditions

Version 2.1
Effective 08. August 2026

These GTC replace all earlier versions, in particular the version dated 04.03.2021. The version applicable to an existing contract is the version referenced in the respective Order.

1. Preamble

1.1 Traversals Analytics and Intelligence GmbH, Gräfenberger Str. 34, 91080 Uttenreuth, Germany (hereinafter “Contractor”), develops and provides a multi-source data and information fusion platform for the collection, processing, fusion, analysis and visualisation of data from open, commercial and customer-supplied sources (hereinafter “Software”). The Software is provided to professional and institutional customers, in particular public authorities, security and defence organisations, and enterprises. The use of the Software and the provision of supplementary services (“Services”) are subject to these General Terms and Conditions (“GTC”). 

1.2 These GTC govern the provision of the Software as a Service (SaaS) and the associated Services. Deployments in which the Software is installed and operated in the Customer’s own data centre or in a data centre designated by the Customer (“On-Premise Deployment”) are not governed by these GTC. On-Premise Deployments are governed exclusively by the individual agreement between the parties and its annexes. Where an individual agreement expressly incorporates individual provisions of these GTC into an On-Premise Deployment, only those provisions shall apply.

1.3 In the event of conflicts or inconsistencies between contractual documents, the following order of precedence applies: (1) the Order Form or Quotation together with its annexes; (2) the Data Processing Addendum; (3) these GTC; (4) the statutory provisions of German law. A provision of a lower-ranking document applies insofar as it does not conflict with a higher-ranking document.

1.4 These GTC apply exclusively. Terms and conditions of the Customer that conflict with, deviate from or supplement these GTC do not become part of the contract unless the Contractor has expressly consented to their application in text form. This also applies where the Contractor performs the contract without reservation in knowledge of the Customer’s terms and conditions. Sentences 1 and 2 do not apply where the Customer is a public contracting authority and mandatory procurement law requires the application of standardised contractual terms (in particular EVB-IT, VOL/B).

1.5 “Order” means the order form, quotation or contract document signed by both parties which specifies the Software, Services, scope of use and remuneration. “Documentation” means the user and administration documentation for the Software provided by the Contractor in electronic form in its version current at the relevant time. “Authorised User” means a natural person permitted by the Customer to use the Software under Section 2.2. “Customer Data” means all data, content and work results imported into the Software or generated with it by the Customer or its Authorised Users. “Business Day” means Monday to Friday, excluding public holidays at the Contractor’s registered office. “Affiliate” means an affiliated company within the meaning of Sections 15 et seq. AktG.

2. Rights of Use

2.1 Subject to payment of the agreed remuneration, the Contractor grants the Customer the non-exclusive, non-transferable and non-sublicensable right, worldwide and limited to the term of the contract, to use the Software for its intended purpose in accordance with these GTC, the Order and the Documentation. The Customer may only use the Software within the scope of the contractual provisions. The Customer may use the Software only for its own purposes. Use for the Customer’s own purposes includes the use of the Software for the general business or official purposes of the Customer and the processing of Customer Data, including use by Affiliates of the Customer and by third parties acting on the Customer’s behalf and under the Customer’s instructions (for example contractors and consultants), provided the Customer remains responsible for their compliance with these GTC. Use for the Customer’s own purposes does not include making the Software or its functionality available to third parties as a service (service bureau), resale, sublicensing, or any other use for the independent business purposes of third parties.

2.2 The Customer is entitled to have the software used by its own employees or by third parties for its own purposes. The Customer creates a Super-Admin-User-Account during the initial setup. The Super-Admin-User can then create standard user accounts. The Software may be used according to the remuneration model agreed in the respective order. The Customer shall document the respective authorized users. A joint use of the Software by different users under a common user account is excluded. The Customer shall be responsible for the use of the Software by its users and for all damages caused by negligent or intentional breaches of duty by its users.

2.3 Unless otherwise agreed, any rights to the Software and Services provided by the Contractor or developed under this Agreement shall be the sole property of the Contractor. Any rights to any kind of modification, development or improvement of the Software and/or Services made by the Customer are also exclusively owned by the Contractor.

2.4 The Software may contain open source software components. The use of these components is exclusively subject to the corresponding terms of use of the open-source software components which are transmitted and/or referenced within the framework of the open-source software components. No provision of the contract shall affect the rights or obligations of the Customer under the corresponding terms of use of the open-source software components. In the event of contradictions or conflicting provisions of the license terms of the open-source software and the provisions of the contract, the license terms of the open-source software shall take precedence.

2.5 The right to use the Software shall also extend to fixes, patches, developments and updates which the Contractor makes available to the Customer. The right to updates does not include the right to use new/additional products and functionalities which are made available as separate products/modules.

2.6 The contractor provides the Software and detailed documentation of the Software in electronic form.

2.7 Unless otherwise agreed or prescribed by mandatory law or applicable open source software terms of use, the Customer shall not be entitled

  1. to copy the Software beyond what is necessary for use in accordance with the contract, neither in whole nor in part;
  2. to modify, correct, adapt, translate or improve the Software or otherwise create derivative works of the Software;
  3. to rent, lend, sell, license, transfer or otherwise make the Software available to third parties;
  4. to reverse engineer, decompile, disassemble or otherwise attempt to decipher the source code of the Software, either in whole or in part;
  5. circumvent or violate security devices or protection mechanisms contained in or used for the Software;
  6. to take measures that are suitable to cause damage to the Software or the servers of Contractor;
  7. remove, delete, erase, obliterate, modify, conceal, translate, combine, add to or otherwise alter any trademark, documentation, warranty, disclaimer of liability or other rights, such as intellectual property, signs, notices, markings or serial numbers, which are associated with the Software or documentation;
  8. to use the Software in a manner that violates applicable law and/or the rights of third parties;
  9. to publish benchmarks or competitive analyses of the Software, or to use the Software for the development, provision or marketing of a competing software product or competing service; internal evaluation and testing by the Customer for its own procurement, operational or security purposes is permitted, including reporting of the results within the Customer’s organisation and to its supervisory bodies;
  10. to use the Software as the sole and automated basis for decisions which produce legal effects concerning natural persons or which similarly significantly affect them, without meaningful human review by qualified personnel.

3. Customer Obligations

3.1 The Customer shall support the Contractor to a reasonable extent in the performance of the contractual services. The Customer shall provide all cooperation services, information, data, files, materials, which are necessary for the Contractor to fulfill the contractual obligations in advance and without being asked. Should the Customer not cooperate sufficiently and/or cause delay, the Contractor shall not be obliged to fulfill the contractual obligations as long and to the extent that the Contractor is prevented from fulfilling the contractual obligations due to insufficient and/or delayed cooperation by the Customer. The Contractor shall inform the Customer of its insufficient or late cooperation and set a reasonable deadline for subsequent performance. If the Customer nevertheless fails to fulfill its obligations to cooperate, any increases in remuneration, additional expenses (e.g. overtime, cancellation costs, travel expenses) and postponements of deadlines that cannot be avoided by the Contractor shall be borne by the Customer. If the Customer does not provide the required cooperation within a reasonable subsequent period set by the Contractor, agreed dates and deadlines shall be extended by the duration of the delay plus a reasonable restart period. The Contractor may invoice unavoidable additional expenditure actually incurred and evidenced (in particular idle time, cancellation costs and travel expenses) at the rates agreed in the Order. The Contractor’s statutory rights remain unaffected.

3.2 The Customer is responsible for (i) appropriate security processes, tools and controls for systems and networks that interact with the Software, (ii) the provision of alternative processes in the event of lack of availability of the Software, (iii) the determination of whether the technical and organizational measures of data protection and data security provided by the Contractor meet the specific requirements of the Customer, (iv) the appropriate internal training of the users and the provision of internal technical support, (v) the proper and regular backup of all programs and data in the Customer’s own system environment and of all data and work results transferred into or created with the Software, commencing on the start of use of the Software and at reasonable regular intervals thereafter and (vi) the activation and use of multi-factor authentication for all Authorised Users where the Software provides this function, the maintenance of an up-to-date list of Authorised Users, and the protection of access credentials against access by unauthorised persons. 

4. Services

4.1 Unless otherwise agreed, Services shall be invoiced on a time and material basis at the end of the calendar month in which they are provided. Invoicing shall be based on the Contractor’s timesheets. Unless otherwise agreed, reasonable travel expenses will be borne by the Customer and invoiced monthly. Travel expenses shall be invoiced only where the Customer has approved them in advance in text form, and shall be reimbursed at actual cost in accordance with the Contractor’s travel policy or the flat rates agreed in the Order.

4.2 When working on the Customer’s facilities, employees of the Contractor will follow the Customer’s safety instructions and policies. The Customer shall provide any such instructions and policies to the Contractor in advance.

4.3 The Contractor reserves any rights to all work results which are developed in the course of the providing Services to the Customer. This includes in particular software/code, interfaces, methods, processes and templates used, created or modified by the Contractor. The Contractor grants the Customer a non-exclusive, non-transferable right of use for its own purposes in accordance with Section 2.1 of these GTC. Notwithstanding sentences 1 to 3, the Customer retains all rights in its own data, content, know-how, methods and materials which it makes available to the Contractor for the purpose of providing the Services (“Customer Background IP”). The Contractor acquires no rights in Customer Background IP beyond the right to use it for the purpose of providing the Services in accordance with the contract.

4.4 Work results created by the Contractor in the course of providing services to the Customer, in particular customizing or modifying the Software, are not covered by Contractor’s standard support, unless these work results are incorporated into the standard Software. Such work results can also only be used with the version/release of the software current at the time of creation. Each upgrade or update may require additional migration services subject to a fee.

4.5 Changes to the agreed scope of Services shall be agreed in a change request in text form, stating the description of the change and its effects on remuneration, dates and other contractual provisions. Until a change request has been agreed by both parties, the parties shall continue to perform on the basis of the existing agreement. The Contractor may reject a change request where its implementation is unreasonable for the Contractor, in particular for reasons of capacity or technical feasibility. Effort required for the review and costing of a change request may be invoiced at the agreed rates where the review requires more than four (4) hours.

5. Warranties

5.1 Contractor warrants that the Software and the Services shall be provided by Contractor free of defects and, if used as intended, shall essentially comply with the specifications stated in the documentation. The Services shall be performed according to industry standards by experienced personnel.

5.2 The Contractor warrants that the use of the Software by the Customer in accordance with the contract does not infringe the intellectual property rights of third parties.
5.2.1 If a third party asserts a claim against the Customer on the ground that the contractual use of the Software infringes its intellectual property rights, the Customer shall notify the Contractor without undue delay in text form, shall not acknowledge the claim in whole or in part, and shall leave the defence and settlement of the claim to the Contractor, providing reasonable support and the information available to it. The Contractor shall indemnify the Customer against the claims asserted and against the reasonable costs of legal defence.
5.2.2 In the event of such a claim, the Contractor may at its option and at its own expense (i) obtain for the Customer the right to continue using the Software, or (ii) modify or replace the Software so that the infringement ceases, provided the contractually agreed functionality is not materially impaired. If neither option is available on reasonable terms, either party may terminate the affected contract; in this case the Contractor shall refund remuneration paid for the period after the termination takes effect, pro rata temporis.
5.2.3 Sections 5.2.1 and 5.2.2 do not apply where the infringement results from (i) use of the Software in breach of contract, (ii) modification of the Software by the Customer or a third party, (iii) combination of the Software with hardware, software or data not provided or approved by the Contractor, where the infringement would not have arisen without such combination, or (iv) Customer Data or specifications supplied by the Customer.
5.2.4 The Contractor’s liability under this Section 5.2 is limited to the amount stated in Section 9.2, except in the cases of Section 9.1.

5.3 Technical data, specifications and performance data in public statements, in particular in advertising material, do not in any way represent contractual quality specifications for the Software.

5.4 In the event of defects, the Customer’s claims for defects are initially limited to subsequent performance. The Customer shall notify the Contractor in writing of any defects that occur with a description of the defect and request that the defect be remedied. In the event of proven defects, the Contractor shall provide warranty by means of subsequent performance in such a way that the Contractor makes the Software or Service available or provides it again in a defect-free condition or rectifies the defect.

5.5 Subsequent performance is deemed to have failed where the Contractor has not remedied the defect after two attempts at subsequent performance, in each case within a reasonable period set by the Customer, or where subsequent performance is refused, is unreasonable for the Customer, or is impossible. In this case the Customer may terminate the affected contract or reduce the remuneration appropriately. The Contractor shall compensate damage or futile expenditure caused by a defect within the limits of Section 9.

5.6 Claims of the Customer for defects become time-barred twelve (12) months after the statutory commencement of the limitation period. This does not apply to claims under Section 9.1 (Unlimited Liability), to claims arising from maliciously concealed defects, or where mandatory statutory provisions prescribe longer periods.

6. Provision of Software

6.1 The Software is provided as Software as a Service. The Contractor makes the Software available to the Customer for use via the internet in a logically separated tenant, in the version or release current at the relevant time. The Software is not handed over to the Customer for local installation. The Contractor operates the Software in data centres located within the European Union. On-Premise Deployments are governed exclusively by the individual agreement pursuant to Section 1.2.

6.2 The Contractor shall make the Software available with an availability of at least 99.5% per calendar month (“Minimum Availability”), measured at the transfer point between the data centre hosting the Software and the public internet. The Software is available where the Customer is able to log in and access the functions of the Software. The following periods do not count as downtime: (a) planned maintenance within the maintenance window (Saturday 20:00 CET to Sunday 06:00 CET), announced at least five (5) Business Days in advance. If the Contractor falls below the Minimum Availability in a calendar month, the Customer may claim a credit against the monthly remuneration for the Software as follows: availability below 99.5% and at least 99.0% — 5%; below 99.0% and at least 98.0% — 10%; below 98.0% — 15%. Credits must be claimed in text form within thirty (30) days of the end of the affected month. Credits are capped at 15% of the monthly remuneration per calendar month and at 10% of the annual remuneration per contract year. Service credits are the Customer’s sole and exclusive remedy for a failure to meet the Minimum Availability; the right to terminate for good cause and claims under Section 9.1 remain unaffected; (b) urgent security maintenance, announced as far in advance as reasonably possible; (c) unavailability caused by force majeure within the meaning of Section 14.6; (d) unavailability caused by the Customer, its Authorised Users, or systems and networks within the Customer’s sphere of responsibility; (e) unavailability of the public internet or of third-party networks outside the Contractor’s control; (f) unavailability of third-party data sources within the meaning of Section 6.4. Availability is measured by the Contractor’s monitoring systems; the Contractor shall provide a monthly availability report on request. The Minimum Availability does not apply to test, development, staging or evaluation environments.

6.3 The Software processes data by automated means, including statistical methods, machine learning and generative AI models, and generates evaluations, reports, analyses, translations, summaries and recommendations (together “Results”). The quality and accuracy of Results depend in particular on the quality, completeness, timeliness and quantity of the underlying data and on the parameters and queries defined by the Customer. Results may be incomplete, outdated or incorrect. Results are non-binding and do not constitute advice; the Contractor assumes no advisory liability or other liability for Results. The Customer shall subject Results to meaningful human review by qualified personnel before use, and shall not base decisions having legal effect or comparable significance on Results alone. The Customer is responsible for compliance with the legal requirements applicable to it for the use of automated and AI-supported systems, in particular where the Software is used in a field of application classified as high-risk under Regulation (EU) 2024/1689.

6.4 Certain functionalities and use cases of the Software, in particular in connection with the collection of generally/publicly accessible data from various sources on the Internet, are dependent on the availability of the respective sources that are accessed during the collection of the data. Permanent availability cannot be guaranteed for all sources as, for example, data from a particular social network can no longer be collected if the collection is legally or technically impossible or because the terms of use prohibit the collection of data or because an interface/API required for the collection of data is no longer available or no longer available on reasonable terms.

6.5 The Customer shall provide a current version of a common web browser (for example Google Chrome, Microsoft Edge or Mozilla Firefox) for the use of the Software. The Contractor shall state the supported browser versions in the Documentation. The Customer is responsible for the provision and operation of all hardware and operating software and for a secure and sufficiently performant internet connection.

6.6 Unless expressly agreed otherwise, setup/setup and configuration of the Software shall be remunerated according to the hourly rates for services agreed in the contract.

6.7 Software and other work results shall be deemed delivered as soon as they have been made available to the Customer. Services shall be deemed to have been rendered as soon as the respective Service has been completed. Support/maintenance shall be deemed to have been provided on a monthly pro rata temporis basis.

6.8 Unless otherwise agreed, the Software and the Services are not subject to formal acceptance. Where formal acceptance is agreed in the Order, the parties shall agree an acceptance procedure and acceptance criteria in the Order. Acceptance shall be declared in text form; partial acceptance of separable parts of the service is permissible. Acceptance may not be refused on account of insignificant defects. This Section 6.8 does not apply where the Customer is a public contracting authority and mandatory procurement law or the contractual terms prescribed by it (in particular EVB-IT) provide for a different acceptance regime; in that case those provisions apply.

6.9 The Contractor shall be entitled to use subcontractors or other vicarious agents (collectively referred to as “Subcontractors”) to perform the contractual obligations. The Contractor shall ensure that subcontractors are bound by obligations regarding secrecy and data protection in accordance with these GTC. The use of subcontractors shall not affect the Contractor’s contractual obligations towards the Customer. The Contractor shall be liable for any non-performance or improper performance of services by a subcontractor as if it were the Contractor’s own fault.

7. Support

7.1 Support includes assistance and advice to the Customer in solving problems with the use of the Software, including the examination, diagnosis and correction of significant defects and errors in the Software and the provision of bug fixes, corrections, modifications, changes, extensions, upgrades and new versions of the Software (Updates) to ensure the functionality of the Software.

7.2 Support does not extend to problems with or damage to the Software to the extent that such problems or damages are caused by (i) negligence, misuse or improper operation on the part of the Customer; (ii) operation, use of the Software not in accordance with the documentation or failure to comply with the specifications or limitations provided by the Contractor; (iii) modifications to the Software not performed or approved by the Contractor; (iv) acts of third parties; (v) products of third parties; and/or (vi) force majeure.

7.3 For each request/report, the Contractor will, at its sole discretion, prioritize in accordance with the criteria defined below. The Contractor may combine redundant requests/reports by the Customer relating to the same topic into one request/report.

7.4 Support shall be available as defined below under the contact data provided. “Business Day” refers to Monday to Friday, except on public holidays at the headquarter of the Contractor.

AvailabilityOn Business Days 9:00 – 17:00 CET
Telephone+49-(0)9131 92790 0
E-Mailsupport@traversals.com
LanguagesGerman, English
 

(a) Support availability beyond the times stated in Section 7.4, including 24/7 availability, on-call service, a named support contact or shortened response times, may be agreed in the Order against additional remuneration.

7.5 The Contractor shall react to any support requests/reports within the response times defined below. The response time is the time between the first request/report by the Customer (by telephone or electronically) and the first feedback (by telephone or electronically) from the Contractor. Only time intervals during the availability times are relevant for the response time.

PriorityDescriptionResponse Time
1 – Show StopperThe Software is not available at all and the Customer’s business is severely affected3 Hours
2 – CriticalFunctionality of the software not as described and thus significant impairment of the use of the software as a whole8 Hours
3 – MajorFunctionality of the software not as described, other use of the software is not or only insignificantly impaired48 Hours
4 – MinorFunctionality of the software not affected, general question1 Week
 

(a) Where a report classified as Priority 1 or Priority 2 has not been resolved within eight (8) hours (Priority 1) or twenty-four (24) hours (Priority 2) of the first response, the Contractor shall provide the Customer with a status report and, where technically possible and reasonable, a workaround, and shall escalate the matter internally to the responsible technical lead and, where a Priority 1 report persists beyond twenty-four (24) hours, to the management. Until the report is closed, the Contractor shall inform the Customer of the progress of remediation at appropriate intervals, and at least once per Business Day for Priority 1.

7.6 The Contractor attaches the highest importance to fixing bugs as quickly as possible, but it is not possible to generally define specific resolution times in advance, as bugs can have various types and causes. The Contractor will make every effort to fix bugs and malfunctions as quickly as possible and will regularly inform the Customer about the progress of the bug fix.

7.7 The Customer grants the Contractor the right to access its account of the Software and the data processed with the Software to fix bugs.

7.8 The Customer shall designate a support coordinator and at least one deputy in text form and shall keep this designation up to date. Support requests shall be submitted by the support coordinator or the deputy. The Contractor may reject requests from other persons or refer them to the support coordinator.

8. Payment

8.1 Unless otherwise agreed in the Order, remuneration for the provision of the Software shall be invoiced annually in advance. Invoices are payable within thirty (30) days of the invoice date, net and without deduction. Unless otherwise agreed, the statement of a purchase order number on the invoice is not a condition of the payment obligation. Invoices to public contracting authorities shall be issued electronically in accordance with the applicable statutory requirements, in particular in the XRechnung format.

8.2 In the event of late payment, default interest shall accrue at the statutory rate. Where the Customer is in default of payment of an undisputed and due invoice by more than thirty (30) days, the Contractor may temporarily suspend the Customer’s access to the Software until payment has been made, after prior warning in text form setting a further grace period of at least ten (10) Business Days. The Contractor shall not suspend access on account of invoice amounts which the Customer has disputed in good faith and in text form. Suspension does not release the Customer from its payment obligations.

8.3 All prices are net prices in euro and exclusive of value added tax and of other taxes, duties and charges. Value added tax shall be added at the statutory rate applicable at the time of performance where it is incurred. For supplies to customers established in another member state of the European Union who provide a valid VAT identification number, the reverse charge procedure under Article 196 of Directive 2006/112/EC applies where its conditions are met; the Customer is responsible for the accuracy of the information it provides and shall notify the Contractor without undue delay of any change. Where the Customer is required by law to withhold tax on payments, the Customer shall provide the Contractor with the corresponding tax certificates without undue delay, and the parties shall cooperate in applying any applicable double taxation agreement.

8.4 Price adjustment. For contracts with a term of more than twelve (12) months and upon each renewal, the Contractor may adjust the remuneration with effect from the start of the next contract year, at the earliest twelve (12) months after the start of the contract and not more than once within any twelve-month period. The adjustment may not exceed the percentage change in the consumer price index for Germany published by the Federal Statistical Office between the month of the last price determination and the month three months before notification, and is capped at five (5)% per adjustment. The Contractor shall notify the Customer of the adjustment in text form at least three (3) months before it takes effect. Where the adjustment exceeds three (3)%, the Customer may terminate the contract with effect from the date on which the adjustment takes effect by giving notice in text form within six (6) weeks of receipt of the notification; the Contractor shall draw attention to this right in the notification.

9. Liability

9.1 Unlimited Liability: The Contractor is liable without limitation a) in the event of willful conduct or gross negligence; b) within the scope of a guarantee taken over by the Contractor; c) in the event that a defect to our Services is maliciously concealed; d) in case of an injury to life, body or health; and e) according to the German Product Liability Law.

9.2 Liability for Breach of Cardinal Duties: Unless the Contractor is liable under Section 9.1, where material contractual duties (“cardinal duties”) — duties the fulfilment of which makes the proper performance of the contract possible in the first place and on the fulfilment of which the Customer may regularly rely — are breached through slight negligence, the Contractor’s liability is limited to the foreseeable damage typical for this type of contract. In such cases the Contractor’s aggregate liability for all damaging events occurring within one contract year is limited to the remuneration paid or payable by the Customer for the Software and Services in the twelve (12) months preceding the event giving rise to liability, subject to a minimum of EUR 50,000. For loss of data under Section 9.4, aggregate liability within one contract year is limited to fifty (50)% of that amount. The Order may provide for a different cap; a cap agreed in the Order prevails.

9.3 Liability for Breach of Non-Cardinal Duties: Unless the Contractor is liable in accordance with Section 9.1 (“Unlimited Liability”) above, if contractual duties which are not cardinal duties (as defined in Section 9.2) are infringed due to slight negligence, any liability for damages shall be excluded.

9.4 Liability for Loss of Data: If the Customer violates its obligation to properly back up data, the Contractor is liable according to this Section 9 for loss of data limited to the amount of damages that would have occurred even if the Customer had properly and regularly backed up the data.

9.5 Exclusion of Liability: Unless the Contractor is liable in accordance with Section 9.1 (“Unlimited Liability”) above, the Contractor is not liable a) for any damages, loss, costs or expenses you might incur from using, or your inability to use, the results of the Software and/or Services for any particular purpose; and b) for any damages, loss, costs or expenses you might incur due to any delay, a temporary interruption or non-availability of the Software and/or Services.

9.6 Scope: Except for liability in accordance with Section 9.1 (“Unlimited Liability”) above, the above limitations of liability shall apply to all claims for damages, irrespective of the legal basis, including claims for tort damages. The above limitations of liability also apply in the case of claims for a party’s damages against the respective other party’s employees, agents or bodies.

10. Confidentiality

10.1 Each of the parties undertakes to use all information received within the scope of the cooperation of the parties which (a) is marked “confidential” or “secret” or with an equivalent indication or is orally designated as confidential; (b) is to be regarded as confidential due to its content; or (c) is derived from confidential information which has been made available (hereinafter collectively “Confidential Information”); exclusively for the purposes of the fulfillment of the contract, to treat Confidential Information confidentially and to protect Confidential Information from being disclosed to unauthorized third parties. This confidentiality obligation shall be imposed on all persons entrusted with the fulfillment of the contract.

10.2 Excluded from the confidentiality obligation shall be information which (a) is publicly accessible or subsequently became publicly accessible or was already known to the other party at the time of conclusion of the contract; (b) was developed independently and autonomously by the other party; (c) was disclosed to the other party by a third party not subject to a confidentiality obligation or (d) must be disclosed due to statutory provisions or official or court orders (in which case the affected party shall be informed immediately).

10.3 The obligations under this Section 10 continue for five (5) years after the end of the contract. For information which constitutes a trade secret within the meaning of the German Trade Secrets Act (GeschGehG), and for information classified under the applicable rules on the protection of classified information, the obligations continue for as long as the need for protection persists.

10.4 Each party shall protect the other party’s Confidential Information by appropriate confidentiality measures within the meaning of Section 2 no. 1 lit. b GeschGehG, applying at least the same degree of care as it applies to its own confidential information of comparable importance and in no case less than reasonable care. On termination of the contract or on request, each party shall return or destroy the Confidential Information received and shall confirm this in text form. This does not apply to copies which must be retained on the basis of statutory retention obligations or which are contained in routine backups; such copies remain subject to this Section 10 until they are deleted.

11. Customer Data

11.1 As a technical service provider, the Contractor stores content and data for the Customer. The Customer undertakes to the Contractor not to process any illegal content and data and/or content and data that infringe the rights of third parties with the Software and not to use any programs containing viruses or other malicious software in connection with the Software. In particular, the Customer undertakes not to use the Software to offer or in connection with illegal services or goods.

11.2 The Customer is solely responsible for all content and data processed and/or used by the Customer or its users as well as the legal positions that may be required for this. The Contractor does not take note of contents of the Customer or its users and does not monitor the contents used with the Software.

11.3 In this context, the Customer undertakes to indemnify the Contractor against all liability, damages and costs, including possible and actual costs of legal proceedings, if claims are made against the Contractor by third parties, including employees of the Customer, as a result of alleged acts or omissions of the Customer. The Contractor shall notify the Customer of the claim and, to the extent legally possible, give the Customer the opportunity to defend itself against the asserted claim. At the same time, the Customer shall immediately provide the Contractor with all information available to the Customer on the facts of the case which are the subject of the claim. Any further claims for damages of the Contractor shall remain unaffected.

11.4 As between the parties, all Customer Data remains the property of the Customer. The Contractor acquires no rights in Customer Data beyond the rights of use necessary to provide the Software and Services in accordance with the contract and the Customer’s instructions. On termination of the contract, Section 10 of the Data Processing Addendum applies to the return and deletion of Customer Data.

11.5 The Contractor shall not use Customer Data to train, fine-tune, evaluate or otherwise develop AI models, and shall not make Customer Data available to third parties for such purposes. Where the Software uses AI models of third-party providers, the Contractor shall ensure by contract that those providers do not use Customer Data for training purposes either; the Contractor shall name the third-party providers used on request. The use of aggregated and anonymised usage and metadata in accordance with Section 12.2 remains unaffected.

12. Data Protection

12.1 Protected is personal data of users of the Software (surname, first name, e-mail address, telephone number, access credentials stored in hashed form) and personal data relating to the use of the Software (log data). These personal data are processed by the Contractor as the controller in order to enable the users to use the Software. With regard to the rights of the persons concerned and other information duties in this respect, reference is made to the Privacy Policy on the Contractor’s website.

12.2 The Contractor may access the Customer’s tenant only to the extent necessary to (i) remedy a defect or malfunction reported by the Customer, (ii) avert an imminent threat to the security or integrity of the Software, or (iii) fulfil a statutory obligation. Access is limited to the personnel required for that purpose in accordance with the need-to-know principle, is logged, and the log is made available to the Customer on request. Except in the cases of (ii) and (iii), the Contractor shall inform the Customer in advance. The Contractor may collect and evaluate system and metadata relating to the use of the Software (in particular performance, error and security data) in order to identify and remedy defects, produce statistical analyses and further develop the Software; personal data shall be anonymised for this purpose. This Section 12.2 does not apply to On-Premise Deployments.

12.3 In the course of using the Software, the Customer may process personal data. The Customer is the controller of such personal data and the Contractor is a processor. Such data processing is subject to the Data Processing Addendum attached as Appendix 1. The Data Processing Addendum shall be part of the contract and is expressly incorporated into the contract by the parties.

13. Term

13.1 The term of each order is defined in the respective order form. Every order may be terminated by either party at any time in the event of a material breach of contract by the other party if the breach of contract is not remedied within 30 days. This period shall commence from the date of delivery of the written notification of the material breach of contract. The Contractor may terminate an order without notice at any time if the Customer is dissolved or liquidated or takes steps to do so and/or if the Customer becomes insolvent or bankrupt.

13.2 The term of each Order is specified in the respective Order. Unless otherwise agreed in the Order, the initial term is twelve (12) months from provision of the Software and is automatically renewed for successive periods of twelve (12) months unless terminated by either party by notice in text form given three (3) months before the end of the then-current term.
13.3 Either party may terminate the contract with immediate effect where the performance of the contract becomes unlawful or subject to authorisation under export control or sanctions law and the necessary authorisation is not granted, is revoked, or is not granted within a reasonable period, or where a party or its beneficial owner becomes subject to sanctions. Claims for damages arising from such termination are excluded. Remuneration already paid for services not yet rendered shall be refunded pro rata temporis.

14. Miscellaneous

14.1 This contract is governed by the law of the Federal Republic of Germany, to the exclusion of the United Nations Convention on Contracts for the International Sale of Goods (CISG) and to the exclusion of the conflict-of-law rules of private international law. In the event of disputes arising from this contract, the parties shall first endeavour to reach an amicable settlement. Where this is not possible, the exclusive place of jurisdiction is Erlangen, Germany, provided the Customer is a merchant, a legal person under public law or a special fund under public law. The Contractor is also entitled to bring proceedings at the Customer’s general place of jurisdiction. Mandatory statutory places of jurisdiction remain unaffected.

14.2 The Contractor may name the Customer as a reference customer and use the Customer’s name and logo for that purpose in marketing materials, including on its website and social media channels, only with the Customer’s prior consent in text form. Consent may be given in the Order and may be revoked at any time with effect for the future. Customers from the public security, defence, intelligence and law enforcement sectors shall not be named as references, and no reference shall be made to the existence of a contractual relationship with them, without express prior written consent given in each individual case.

14.3 Notices under this contract require at least text form within the meaning of Section 126b BGB. Notices of termination and declarations of objection under Section 14.4 require text form; the parties may agree written form in the Order. Notices take effect on receipt. Each party shall notify the other without undue delay of any change to the notice addresses given in the Order.

14.4 The Contractor may amend these GTC where this is necessary owing to changes in statutory provisions or case law, changes in the relevant market, business or technical environment, or the introduction of new functions, and where the amendment is reasonable for the Customer taking the Contractor’s interests into account. Amendments affecting the main obligations of the contract — in particular the scope of services and remuneration — to the detriment of the Customer are excluded from this provision; such amendments require the Customer’s express consent. The Contractor shall notify the Customer of the amendment in text form at least two (2) months before it is due to take effect and shall separately draw attention to the right of objection and its consequences. The Customer may object in text form within six (6) weeks of receipt of the notification. If the Customer objects, the contract continues on the previous terms until the end of the current contract term; the Contractor may then terminate the contract with effect from the end of that term. If the Customer does not object within the period, the amendment takes effect on the date stated. This Section does not apply where the Customer is a public contracting authority and the amendment would conflict with mandatory procurement law.

14.5 These GTC are created in English. When a German translation is issued, the English version prevails in the event of discrepancies. Translations into other languages, including automated translations provided on the Contractor’s website, are for information only and are not legally binding.

14.6 Neither party is liable for delays or failures in performance caused by circumstances beyond its reasonable control, in particular natural disasters, war, terrorism, armed conflict, epidemics and pandemics, labour disputes not affecting its own operations, sovereign acts, failures of energy or telecommunications supply, and large-scale cyber attacks on third-party infrastructure. Affected obligations are suspended for the duration of the event and to the extent affected; agreed dates are extended accordingly. The affected party shall notify the other party without undue delay and shall use reasonable efforts to mitigate the effects. Where the event lasts longer than three (3) months, either party may terminate the affected contract in text form; remuneration paid for services not yet rendered shall be refunded to the Customer pro rata temporis. Payment obligations for services already rendered remain unaffected.

14.7 Should individual provisions of these GTC be or become invalid or unenforceable, the validity of the remaining provisions remains unaffected.

14.8 Neither party may assign the contract or individual rights arising from it to third parties without the prior written consent of the other party; consent may not be unreasonably withheld. The Contractor may assign the contract to an Affiliate or in connection with the transfer of the business unit concerned, subject to notification to the Customer; where the assignment is unreasonable for the Customer, the Customer may terminate the contract with immediate effect within four (4) weeks of the notification. Section 354a HGB remains unaffected.
14.9 Set-off and retention. The Customer may set off against claims of the Contractor only with claims that are undisputed or have been finally determined by a court, or that are in a synallagmatic relationship with the Contractor’s claim. The Customer may exercise a right of retention only on the basis of claims arising from the same contractual relationship.

Appendix 1:

Data Processing Addendum

1. General

The Contractor provides its intelligence platform as Software as a Service (SaaS) to the Customer. With the Software the Customer can collect and process data, including, but not limited to personal data as defined under the applicable data protection laws.

Under the contract on the provisioning of the Software (“Main Contract”), the Contractor may process personal data on instruction of the Customer.

As part of the Main Contract, this Data Processing Addendum (“DPA”) specifies the obligations of both parties to comply with the applicable data protection laws, in particular the requirements of the European General Data Protection Regulation (“GDPR”).

2. Scope of Application

The Contractor shall process personal data on behalf and on instruction of the Customer. The parties agree that for the purposes of this DPA the Customer shall be the Controller and the Contractor shall be the Processor (“Controller” and “Processor” shall have the meaning as defined by the GDPR). The subject-matter of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects are specified in the Main Contract and in Annex 1 to this DPA. The term of this DPA depends on the term of the Main Contract.

3. Compliance with Instructions

3.1 The Contractor may only process personal data within the scope of the order and the documented instructions of the Customer. The instructions shall initially be specified in the Service Agreement and may then be changed, supplemented or replaced by the Customer in text form. Verbal instructions are to be confirmed by the Customer immediately in text form.

3.2 If the Contractor is obliged to process personal data in accordance with the law of the Union or the Member State to which the Contractor is subject, the Contractor shall inform the Customer thereof in writing prior to the respective processing, unless the law prohibits such information for important reasons of public interest. In the latter case, the Contractor shall inform the Customer immediately as soon as this is legally possible.

3.3 The Contractor shall inform the Customer without delay if it is of the opinion that an instruction violates applicable laws. The Contractor may suspend the implementation of the instruction until it has been confirmed or amended by the Customer.

3.4 The Contractor may use data concerning the use of the software by the Customer in anonymized form for the purposes of optimizing the software, user experience and for security-relevant evaluations. The Customer hereby issues a corresponding instruction for the corresponding anonymization.

4. Technical and Organisational Measures

4.1 The Contractor undertakes towards the Customer to comply with the technical and organisational measures required to comply with the applicable data protection regulations. This includes in particular the provisions of Art. 32 GDPR.

4.2 The status of the technical and organisational measures existing at the time of conclusion of this DPA is documented in Annex 2 to this DPA. The parties agree that changes to the technical and organisational measures may be necessary in order to adapt to technical and legal circumstances. The Contractor reserves the right to change the security measures taken, but it must be ensured that they do not fall below the contractually agreed level of protection. 
The Customer may at any time request an up-to-date overview of the technical and organisational measures taken by the Contractor.

5. Data Subject Rights

5.1 The Contractor shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III (in particular access, correction, blocking or deletion). To the extent that the assistance of the Contractor is necessary for the protection of rights of data subjects by the Customer, the Contractor shall take the necessary measures according to the instructions of the Customer. Taking into account the nature of the processing, the Contractor shall, insofar as possible, assist the Customer by appropriate technical and organizational measures to enable the Customer to fulfill its obligations to respond to data subject requests.

5.2 The Contractor may only provide information to third parties or to data subjects with the prior consent of the Customer. It shall forward requests addressed directly to the Contractor to the Customer without undue delay.

6. Other Obligations of the Contractor

6.1 The Contractor shall inform the customer immediately, at the latest within 48 hours, if it becomes aware of violations of the protection of personal data processed on behalf of the Customer.

The Contractor shall notify the Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware, of any breach of the protection of personal data processed on behalf of the Customer. The notification shall contain the information available at the time in accordance with Art. 33(3) GDPR and shall be supplemented as further information becomes available. Where the information cannot be provided in full at the same time, it may be provided in stages without undue further delay. 

6.2 The Contractor shall support the Customer in preparing and updating the records of processing activities regarding the data processing performed by the Contractor on behalf of the Customer, and, if necessary, in carrying out a data protection impact assessment. All necessary information and documentation must be made available to the Customer immediately upon request.

6.3 If the Customer is subject to an audit by a supervisory authority or other parties or if a data subjects requests to exercise its rights against the Customer, the Contractor undertakes to support the Customer to the necessary extent insofar as the personal data processed on behalf of the Customer is affected.

6.4 The persons employed by the Contractor for the processing have committed themselves in writing to confidentiality, have been made familiar with the relevant provisions of all relevant data protection laws and are continuously appropriately instructed and monitored with regard to the fulfilment of data protection requirements.

6.5 The Contractor shall support the Customer in complying with the obligations set out in Articles 32 to 36 GDPR, taking into account the type of processing and the information available to the Contractor.

6.6 The Contractor designated a Data Protection Officer. The Contractor’s Data Protection Officer is Christian Schmoll (Tel.: +49 (0)89 4622 7322, E-Mail: schmoll@lucid-compliance.com). In case of questions or concerns regarding data protection, the Customer can contact the Contractor’s Data Protection Officer at any time directly.

7. Rights and Obligations of the Customer

7.1 The Customer shall be responsible for assessing the lawfulness of the data processing and for safeguarding the rights of data subjects.

7.2 The Customer shall be entitled to monitor and audit compliance with the provisions on data protection and the contractual agreements at the Contractor to a reasonable extent itself or by third parties, in particular by obtaining information and inspecting the stored data and data processing programs. The Contractor shall, as far as necessary and possible, provide access and insight to the persons entrusted with the inspection. The Contractor is obliged to provide necessary information, to demonstrate procedures and to provide evidence which is necessary for the performance of an inspection. Inspections at the Contractor’s premises shall be carried out without avoidable disruptions to its business operations. Unless otherwise indicated for urgent reasons to be documented by the Customer, inspections shall take place after reasonable advance notice and during business hours of the Contractor and not more frequently than every 12 months.

The Contractor may fulfill the Customer’s right of inspection by providing current certifications or audit reports from independent third parties (in particular ISO/IEC 27001 certificates, BSI C5 attestations or SOC 2 reports) together with a completed security questionnaire, where these adequately evidence compliance with the obligations under this DPA. An on-site inspection may be conducted where the documentation provided is not sufficient to demonstrate compliance, where there are concrete indications of a breach, or where a supervisory authority so requires. Inspections take place after reasonable prior notice of at least four (4) weeks, during the Contractor’s business hours and without avoidable disruption to its operations, and not more than once every twelve (12) months, unless there is specific cause.

8. Subprocessors

8.1 The Contractor may only use subprocessors with the consent of the Customer. The Customer consents to the usage of subprocessors according to the List of Sub-Processors in Annex 3 to this DPA. The List of Sub-Processors also defines the process for future changes of subcontractors.

8.2 The Contractor must carefully select its subprocessors and check before using them that they can comply with the agreements made between the Customer and the Contractor. In particular, the Contractor shall check that all subcontractors have taken the necessary technical and organisational measures to protect personal data in accordance with Art. 32 GDPR.

8.3 Services which the Contractor uses with third parties as a pure ancillary service in order to carry out its business activities shall not be considered sub-processing in the context of this DPA. This includes, for example, cleaning services, pure telecommunications services without concrete reference to services provided by the Contractor for the Customer, postal and courier services, transport services and security services.

8.4 The usage of subprocessors shall not affect the Contractor’s contractual and data protection obligations towards the Customer. The Contractor shall be liable for any acts or omissions of its subprocessors as if they were its own acts or omissions.

9. Data Transfer to Third Countries

The Contractor processes personal data on behalf of the Customer exclusively within the European Union or the European Economic Area. Where processing in a third country is necessary in an individual case, it shall only take place on the basis of an adequacy decision under Art. 45 GDPR or on the basis of appropriate safeguards under Art. 46 GDPR (in particular the standard contractual clauses adopted by the Commission), following a transfer impact assessment and, where necessary, supplementary measures. The current transfer situation is set out in the list of sub-processors. Automated translation and AI-based analysis functions are performed on models operated by the Contractor within the EU or on the Customer’s own infrastructure; no content is transferred to third-country translation services.

10. Deletion and Return of Personal Data

10.1 Copies of the personal data processed on behalf of the Customer shall not be made without the knowledge of the Customer, except for backup copies that are necessary to guarantee proper data processing, as well as data which are necessary with regard to compliance with statutory retention obligations.

10.2 Upon termination of the Main Contract or earlier upon request by the Customer, the Contractor shall hand over the data to the Customer or delete such data in accordance with the requirements of applicable data protection laws and regulations.

10.3 Documentations which serve as proof of the orderly and proper data processing shall be stored by the Contractor beyond the end of the contract in accordance with the respective retention periods.

11. Miscellaneous

11.1 If the data of the Customer processed by the Contractor should be endangered by measures of third parties (e.g. by seizure or confiscation), by insolvency proceedings or by other events, the Contractor shall inform the Customer immediately. The Contractor shall notify the creditors without delay of the fact that the data are processed on instruction of a third party.

11.2 Ancillary agreements must be made in writing. Should individual parts of this DPA be invalid, this shall not affect the validity of the remaining provisions of the DPA.

Annex 1 to the Data Processing Addendum

Details of the Data Processing

1. Subject-matter, Nature and Purpose of the Processing

The Contractor provides its intelligence platform to the Customer. The Customer might use the Contractor’s intelligence platform to collect and process personal data.

In this case, the Customer is the controller, as defined in the GDPR, and the Contractor is a processor, as defined in the GDPR.

If applicable, the personal data is processed for the purpose of performing the services of the Contractor agreed in the Main Contract.

2. Categories of Data Subjects

The personal data processed on instruction of the Customer, if any, concern the following categories of data subjects:

Customers may submit personal data to the Software and/or collect personal data with the Software, the extent of which is determined and controlled by the Customer in its sole discretion.

The personal data may include, but is not limited to, personal data relating to the following categories of data subjects:

Personal data of customers, prospective customers, marketing addressees, suppliers, employees, applicants, etc. of the Customer may be subject of the data processing, provided that the Customer imports them into the Contractor’s intelligence platform.

In the context of the various use cases of the intelligence platform, for example in the collection of generally/publicly accessible personal data in social media listening/monitoring, vendor risk management or in the context of compliance checks, the collection and processing of personal data may also affect Internet users who use social media and other websites, e.g. blogs, etc., and publish content there that identifies them as a natural person.

3. Types of Personal Data

The personal data processed on instruction of the Customer, if any, relates to the following categories of data:

When processing personal data that the Customer imports into the intelligence platform, the categories of personal data that the Customer imports into the intelligence platform are affected.

When collecting and processing personal data within the scope of the various use cases of the intelligence platform, for example when collecting generally/publicly accessible personal data for social media listening/monitoring, vendor risk management or within the scope of compliance checks, the categories of data affected are those that are collected within the scope of the searches and/or analyses defined by the Customer, in particular names, user names, user IDs, social media IDs (e.g. Twitter handle), contact data (such as e-mail addresses), published content (if a personal reference exists or can be established) and other content and information published and/or exchanged via social media and other websites, e.g. blogs.

4. Special Categories of Personal Data

Personal data that the Customer imports into the intelligence platform may contain special categories of personal data (e.g. health data), depending on the type of data the Customer imports into the intelligence platform.

Personal data collected in the context of the use of the intelligence platform may contain special categories of personal data depending on the use of the intelligence platform by the Customer or the searches defined by the Customer (e.g. definition of specific search queries to collect generally/publicly accessible personal data in social media).

5. Duration of Processing

Personal data will be processed for the duration of the Main Contract.

Annex 2 to the Data Processing Addendum:

Technical and Organizational Measures

1. Confidentiality

1.1 Physical Access Control

Hosting/Data Center:

The Software is operated in data centres within the European Union. The data centres used and their operators are set out in the list of sub-processors (Annex 3). The operators are certified in accordance with ISO/IEC 27001 and, where applicable, BSI C5; the technical and organisational measures of the respective operator are documented in its own security documentation, which the Contractor shall make available to the Customer on request. In the case of On-Premise Deployments, the physical access control measures for the data centre are the responsibility of the Customer; this Annex 2 then applies only to the Contractor’s own systems.
Office Space:

The Contractor’s offices are located in an office building in Uttenreuth, Germany. The access to the office building and to the Contractor’s offices is closed day and night. Only the landlord and the tenants of the office rooms have access to the office building. A locking system is used, which is managed by the landlord. However, each tenant of the office building has the possibility to manage the keys handed over and to grant and withdraw access rights. This is managed by the Contractor’s personnel department.

Key allocation and key management is carried out according to a defined process, which regulates the granting or withdrawal of access rights to rooms both at the beginning and at the end of an employment relationship.

Access authorizations are only granted to an employee if this has been requested by the respective superior and/or the human resources department. When granting authorizations, the principle of necessity is taken into account.

Visitors are only granted access to the office building and then to the office rooms after the doors have been opened by the reception.

Each visitor is recorded in a visitor book and then accompanied by the receptionist to his or her respective contact person.

Visitors are not allowed to move freely in the office rooms without escort.

1.2 System Access Control

Access to IT systems requires personal user accounts assigned by administrators on the documented request of the responsible manager. Authentication is performed via a central identity provider (Keycloak) with multi-factor authentication, which is mandatory for all accounts with access to customer data and for all administrative accounts; a hardware- or app-based second factor is used (RSA ID Plus). Passwords must be at least twelve (12) characters long; for privileged accounts at least sixteen (16). Passwords are checked against known compromised-credential lists. Time-based forced password changes are not applied, in line with BSI IT-Grundschutz ORP.4 and NIST SP 800-63B; passwords are changed where there is a suspicion of compromise. Passwords are stored using a salted, computationally intensive hash function. Failed login attempts are logged; after repeated failed attempts, rate limiting is applied and the account is locked. Remote access is exclusively via encrypted connections and via the Contractor’s Zero Trust access layer.

1.3 Data Access Control

Authorizations for the Contractor’s IT systems and applications are set up exclusively by administrators.

Authorizations are always assigned according to a strict need-to-know principle. Only those staff members who support and/or maintain data, applications or databases or are involved in the development are granted access rights to data, applications and/or databases, subject to a corresponding request for authorization for an employee by the competent supervisor/manager.

Contractor implemented a role-based authorization concept with the possibility of differentiated assignment of access authorizations, which ensures that employees receive access rights to applications and data depending on their respective area of responsibility and, if necessary, on a project basis.

The destruction of data media and paper is carried out by a service provider who guarantees proper destruction.

Employees are generally prohibited from installing unauthorized software on IT systems.

All server and client systems are regularly updated with security updates.

1.4 Separation Control

All IT systems used by the Contractor for customers are multi-client capable. The logical assignment of the data processed on behalf of a customer to the respective customer and thus the logical separation of the data is always ensured.

1.5 Pseudonymization & Encryption

Encryption:
Data is encrypted in transit using TLS 1.2 or higher; data at rest is encrypted at storage level, and secrets and Kubernetes resources are encrypted using a KMS v2 provider with keys under the Contractor’s control. 

Logging and audit trail: 

Security-relevant events and administrative actions are logged in a tamper-evident manner and retained for ninety (90) days. 

Vulnerability management: 

Container images and dependencies are scanned automatically; critical vulnerabilities are remediated within seven (7) days, high within thirty (30) days. 

Penetration testing: 

An external penetration test is carried out at least annually; a management summary is made available to the Customer on request. 

Incident response: 

A documented incident response process with defined roles, escalation paths and notification deadlines is in place and is tested at least annually. 

Business continuity: 

Backup, restore and disaster recovery procedures are documented and their restoration is tested at least semi-annually.

2. Integrity

2.1 Input Control

Every entry, modification and deletion of personal data processed by the Contractor on behalf of the Customer is recorded.

Employees are obliged to always work with their own accounts. User accounts may not be shared or shared with other persons.

2.2 Transfer Control

A transfer of personal data, which is carried out on behalf of the Contractor’s customers, may only take place to the extent agreed upon with the Customer or to the extent necessary to provide the contractual services for the Customer.

All employees who work on a customer project are instructed regarding the permissible use of data and the modalities of data transfer.

As far as possible, data will be transmitted to recipients in encrypted form.

The use of private data carriers is prohibited for the Contractor’s employees in connection with customer projects.

The Contractor’s employees are regularly trained on data protection topics. All employees are obliged to handle personal data confidentiality.

3. Availability and Resilience

All data in the Software is secured against accidental or willful destruction or loss by a backup strategy (online/offline; on-site/off-site) and reporting procedures. The import of backups is tested regularly.

All data centers have an uninterruptible power supply. All server systems are subject to monitoring, which immediately triggers reports to an administrator in the event of malfunctions.

The Contractor implemented a disaster recovery and business continuity plan.

4. Order Control

The Contractor’s Software is hosted in the European Union.

The Contractor designated a Data Protection Officer.

The Contractor enters into contracts in accordance with the requirements of the applicable data protection laws with every subprocessor. Every contractor is diligently audited prior to the commencement of data processing and regularly on an ongoing basis.

5. Privacy by Design and Privacy by Default

At Traversals Analytics and Intelligence GmbH, it is ensured that the principle of necessity is already taken into account during the development of the Software. The type of data collection using the Intelligence Platform and the data categories to be collected can be individually adapted and managed by the Customer.

The Contractor’s Software supports the input control by a flexible and adaptable audit trail, which allows an unchangeable storage of changes to data and user authorizations.

Authorizations on data or applications can be set flexibly and granularly.

6. Procedure for Regular Testing, Assessing and Evaluating

The Contractor implemented a comprehensive data protection management system, including detailed policies on data protection and information security.

A Data Protection and Information Security Team has been established to plan, implement, evaluate and adjust measures in the area of data protection and information security. All implemented measures and all policies are regularly evaluated and adjusted with regard to their effectiveness.

In particular, it is ensured that data protection incidents are recognized by all employees and are reported to the Data Protection and Information Security Team without undue delay. The Data Protection and Information Security Team will immediately investigate every incident. If data is affected that are processed on instruction of customers, it is ensured that the respective customers are informed about the type and extent of the incident immediately.

Annex 3 to the Data Processing Addendum:

List of Sub-Processors

The Contractor uses the following sub-processors to provide the services under the Main Contract:

Sub-ProcessorServices/Processing OperationsLocation of Data ProcessingAppropriate Safeguards
Google Ireland Limited (Ireland)Hosting of the Software (Google Cloud Platform), E-Mail-Processing and Storage, Website & Application AnalyticsEUStandard Contractual Clauses (SCC)
 Hetzner Online GmbH (Germany) Hosting and Infrastructure EU Standard Contractual Clauses (SCC)
Cloudflare Germany GmbHNetworking Security, CDN, Zero Trust AccessEU with US FallbackStandard Contractual Clauses (SCC) + Supplementary Measures
RSA Security LLCMulti-Factor AuthenticationEUStandard Contractual Clauses (SCC)
Sinch Germany GmbHTransactional EmailEUStandard Contractual Clauses (SCC)

Contractor may replace sub-processors or appoint suitable and reliable additional sub-processors as follows:

The Contractor shall inform the Customer by electronic means (via the Software and/or by email) reasonably in advance (at least 30 days) of granting access to personal data to a sub-processor (except for Emergency Replacements as defined below) of any changes to the List of Sub-processors.

If the Customer has a legitimate, material reason to object to Contractor’s use of a new sub-processor, Customer shall notify Contractor thereof in writing within 7 days after receipt of the information.

If Customer does not object during such time-period, the new sub-processor(s) shall be deemed agreed and consented to by the Customer.

If the Customer objects to the use of a new sub-processor, the Contractor shall take reasonable steps to address the objections raised by the Customer. If such steps are not sufficient to eliminate the Customer’s reasonable objections, either the Customer or the Contractor may terminate the Main Contract with immediate effect to the extent that it relates to services which require the use of the proposed new sub-processor, without bearing liability for such termination.

“Emergency Replacement” refers to a sudden replacement of a sub-processor where such change is outside of the Contractor’s reasonable control (such as if the sub-processor ceases business, abruptly discontinues services to the Contractor, or breaches its contractual duties owed to the Contractor). In such case, the Contractor will inform the Customer of the replacing sub-processor as soon as possible and the process to formally appoint the replacing sub-processor defined above shall be triggere