These General Terms and Conditions (“Terms”) apply to all contracts for the provision of the “Talveo” software and its software products and related services between
(the “Provider”) and the customer.
The Provider’s services are directed exclusively at entrepreneurs within the meaning of § 14 German Civil Code (BGB), legal entities under public law and special funds under public law. No contract is concluded with consumers within the meaning of § 13 BGB. By placing an order, the customer confirms that it is acting in the course of its commercial or independent professional activity.
These Terms apply exclusively. Deviating, conflicting or supplementary terms of the customer do not become part of the contract unless the Provider expressly agrees to their application in text form. This applies even where the Provider performs without reservation in knowledge of such terms.
The presentation of services on the website does not constitute a binding offer but an invitation to submit an offer.
By submitting an order, the customer makes a binding offer. The contract is concluded once the Provider confirms the order in text form or provides access to the software.
The contract text is stored by the Provider. These Terms are available at any time at lumosx.de/en/agb-en.
The Provider provides the customer with the Talveo software as a web-based application (Software as a Service) for use over the internet. The specific scope of services follows from the applicable product description and the order confirmation.
Talveo identifies and assesses vulnerabilities in the customer’s systems. Depending on the product booked, this includes in particular:
In particular, the Provider does not owe:
Responsibility for the information security of its systems remains with the customer. Talveo replaces neither an information security management system nor the customer’s own organisational and technical safeguards.
The Provider is entitled to develop and adapt the software on an ongoing basis, provided the contractually owed scope of services is not materially reduced.
The customer warrants that, for all targets it enters for assessment – in particular IP address ranges, host names, domains and web applications – it either
and that any necessary third-party consents – for example from hosting providers, data centre operators or cloud providers – have been obtained.
The customer shall indemnify the Provider against all third-party claims arising from the customer having systems assessed for which no authorisation existed. The indemnity extends to the costs of a reasonable legal defence.
The Provider is entitled to refuse or abort assessment orders without prior notice where there are concrete indications that authorisation is lacking.
The customer undertakes to:
Where the customer fails to meet these obligations, the Provider is not responsible for resulting impairments of the service.
For the term of the contract the customer receives a non-exclusive, non-transferable and non-sublicensable right to use the software within the agreed scope for its own business purposes.
The customer is not entitled to make the software available to third parties for use, whether for consideration or free of charge, to reproduce, modify or reverse-engineer it, or to circumvent security mechanisms, unless mandatory statutory provisions permit this (§§ 69d, 69e German Copyright Act remain unaffected).
Use is limited to the systems of the customer and of affiliated companies within the meaning of § 15 German Stock Corporation Act. Use for the provision of services to third parties (“managed service”) requires a separate agreement.
The customer may use reports and analyses freely within its own organisation and towards auditors, insurers and clients.
The prices shown at the time of ordering apply. All prices are net, plus statutory VAT.
Remuneration for the selected term is payable in advance. Access is activated upon receipt of payment; where payment is made against invoice, access is activated upon conclusion of the contract.
Invoices are payable in full within 14 days of the invoice date. In the event of late payment the Provider is entitled to charge default interest at the statutory rate (§ 288 (2) BGB) and, following prior notice, to suspend access until payment is made. Suspension does not affect the payment obligation.
The customer may set off only against counterclaims that have been finally determined by a court, are undisputed or have been acknowledged by the Provider.
The contract is concluded for the term selected at the time of ordering (12, 24 or 36 months) and begins upon provision of access.
The contract does not renew automatically. It ends on expiry of the selected term without notice of termination being required. Access to the platform and to the products booked ends at the same time. Continued use requires a new order.
The Provider will normally notify the customer before the term expires. There is no entitlement to such notification.
The right of either party to terminate for cause remains unaffected. Cause exists for the Provider in particular where the customer breaches Section 4 (authorisation to scan) or is in default of payment of more than two monthly instalments.
Notice of termination requires text form (§ 126b BGB); email is sufficient.
The customer can export reports and scan results at any time while the contract is running. The customer is responsible for exporting data it wishes to retain before the term expires; there is no entitlement to access after the term has ended.
The Provider stores the customer’s data for up to twelve months after the contract ends, so that the data is still available if the customer places a new order within that period and in order to handle any claims arising from the contractual relationship. Thereafter the data is deleted, unless statutory retention obligations require longer storage. The customer may request earlier deletion at any time.
The Provider targets availability of the platform of 99% on an annual average, measured by access to the web interface.
The following do not count as downtime:
The reachability of the customer’s systems and the operation of the locally installed agent fall within the customer’s responsibility.
Where the Provider processes personal data on behalf of the customer in the course of providing the services, it does so exclusively on the customer’s documented instructions. The provisions of this Section 10 constitute the data processing agreement pursuant to Art. 28 GDPR between the parties. By accepting these Terms the agreement is concluded; no separate document is required.
Subject matter and duration: provision of the Talveo software for the term of the contract. Nature and purpose: identification and assessment of vulnerabilities in the customer’s systems. Type of data: host names, IP addresses, operating system and software information, and any user names contained therein. Categories of data subjects: the customer’s employees and other users of the systems assessed.
The Provider undertakes to process the data only for the purposes of the contract, to bind persons authorised to process the data to confidentiality, to implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, to support the customer in responding to data subject requests and, on request, to provide the information necessary to demonstrate compliance with these obligations. Sub-processors are engaged only where necessary for the operation of the platform; the Provider shall inform the customer of any intended change and the customer may object for good cause.
Scan data is processed and stored exclusively on servers located in the Federal Republic of Germany.
Credentials for target systems stored by the customer are encrypted for the respective agent. The Provider cannot read these credentials in plain text.
Both parties undertake to treat the other party’s confidential information as confidential for an unlimited period and to use it only for the purposes of the contract. Confidential information includes in particular all scan results, vulnerability reports and network information of the customer.
This obligation does not apply to information that is publicly known, was developed independently, or must be disclosed by law.
The customer will be named as a reference only with its prior consent in text form.
The Provider warrants that the software will materially conform to the applicable service description during the term of the contract.
The provisions of German tenancy law (§§ 535 et seq. BGB) apply to the provision of the software. Strict liability for defects existing at the time the contract is concluded under § 536a (1) alt. 1 BGB is excluded.
The customer shall report defects without undue delay in text form and shall support the Provider to a reasonable extent in isolating them.
Insignificant impairments of usability do not give rise to warranty claims. The occurrence of individual false positives is deemed insignificant in particular.
The Provider is liable without limitation
In the case of slightly negligent breach of a material contractual obligation – an obligation whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the customer may regularly rely – liability is limited to the foreseeable damage typical of this type of contract, and in any event to the net remuneration paid by the customer in the twelve months preceding the event giving rise to the damage.
Liability for slight negligence is otherwise excluded.
The Provider is in particular not liable for damage arising because
The above provisions do not entail any change in the burden of proof to the customer’s detriment.
Events of force majeure that materially impede or prevent performance by the Provider release it from its obligation to perform for the duration of the disruption. These include in particular natural disasters, war, civil unrest, official orders, epidemics and pandemics, large-scale failures of telecommunications networks or energy supply, and industrial action.
Where the disruption lasts longer than two months, either party is entitled to terminate the contract.
The Provider may amend these Terms with effect for the future where this is necessary to adapt to changes in the law, case law, or technical or economic conditions, and where the customer is not unreasonably disadvantaged as a result.
Amendments will be notified to the customer in text form at least six weeks before they take effect. If the customer does not object within six weeks of receipt, the amendments are deemed accepted. The Provider will draw specific attention to this consequence in the notification. In the event of an objection, either party is entitled to terminate the contract with effect from the date the amendments take effect.
The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
The exclusive place of jurisdiction for all disputes arising out of or in connection with this contract is – where the customer is a merchant, a legal entity under public law or a special fund under public law – the Provider’s registered office. The Provider is also entitled to bring proceedings at the customer’s general place of jurisdiction.
Amendments and additions to this contract require text form. This also applies to any amendment of this clause.
Should any provision of these Terms be or become invalid, the validity of the remaining provisions remains unaffected. The statutory provisions replace the invalid provision.