Important Notice: This English version is a non-binding translation of the original German General Terms and Conditions (AGB). The legally binding version is the German text. In case of discrepancies, the German version shall prevail.
Version 2.4, effective 1 October 2026. It replaces version 2.3 of 22 July 2026. Existing customers will be notified in text form at least 14 days before it takes effect in accordance with Section 13.2; until 1 October 2026 version 2.3 continues to apply to them and can be requested at info@conbool.com. New are the provisions on email archiving, continuity, awareness, and 365 backup (Sections 2.10 to 2.13, 6.10 to 6.13, 12.10 to 12.13) as well as the revised liability provisions in Sections 12.1 and 12.6.
§ 1 Scope
1.1 These General Terms and Conditions (hereinafter “GTC”) apply to all contracts between Conbool GmbH (hereinafter the “Provider”) and its customers (hereinafter the “Customer”) for the use of the Conbool platform, in particular the modules SecureMail, MailGuard, SecureFiles, Disclaimer/Signature Manager, DMARC Reports, email archiving, continuity (email continuity), awareness, and 365 backup, as well as all related services and additional components (e.g., message portal, Outlook add-in). Which modules are available to the Customer depends on its booking and the licence configuration derived from it; the mention of a module in these GTC does not in itself give rise to a claim to its provision. The Provider offers the solution both as a SaaS-based variant (Software-as-a-Service) and as an on-premise variant (for installation on the Customer’s systems).
1.2 The Customer’s deviating terms and conditions shall not be recognized unless the Provider expressly agrees to their applicability in writing.
1.3 These GTC apply exclusively to businesses within the meaning of § 14 BGB (natural or legal persons acting in the exercise of their commercial or self-employed professional activity). The services are not directed at consumers (§ 13 BGB).
§ 2 Subject Matter of the Contract
The Provider provides the Customer with a Conbool platform which may include functions such as email cryptography, spam protection, file transfer, signature management, DMARC reporting, compliant email archiving, emergency access to incoming messages, security awareness training, and the backup of Microsoft 365 content. The Customer may choose between a SaaS-based solution and an on-premise variant. Which modules and functions are actually available to an individual Customer depends on its booking and licence configuration. The exact services and technical details are set out in the service description: https://conbool.com/service-description.
2.1 SaaS Solution
- In the SaaS variant, the software is provided exclusively via a remote data connection; there is no physical delivery.
- The Provider provides the Customer with storage space on a data server to store, view, and process the data required to use the service. The Provider undertakes to implement appropriate measures against data loss and unauthorized access by third parties.
- The Customer remains the owner of all data stored on the servers and may request its return at any time.
2.2 On-Premise Solution
- In the on-premise variant, the Provider grants the Customer a license to use the software on the Customer’s own infrastructure. Installation and operation of the software are the sole responsibility of the Customer unless a maintenance agreement has been expressly concluded.
- The Customer is prohibited from reverse engineering, disassembling, or decompiling the software unless expressly permitted by law.
2.3 Rights of Use
- The Provider grants the Customer a simple, non-exclusive, non-transferable right to use the agreed services during the term of the contract within the scope of the service description:
- In the SaaS variant, the software remains on the Provider’s servers; there is no physical delivery.
- In the on-premise variant, the software is installed on the Customer’s systems in accordance with the license terms; all rights remain with the Provider unless otherwise agreed contractually.
- Passing on, sublicensing, or providing the services to third parties for remuneration is not permitted without the Provider’s prior written consent.
- The granting of contractual rights of use is subject to the suspensive condition of full payment of the remuneration owed.
2.4 Updates and Further Development
- The Provider is entitled to regularly update and further develop the software in order to implement technical improvements or legal requirements.
- In the SaaS variant, updates are carried out automatically by the Provider; the Customer will be informed of material changes in due time with at least 14 days’ notice.
- In the on-premise variant, the Provider makes updates available within the scope of a concluded maintenance agreement.
2.5 Subcontractors
The Provider is entitled to engage subcontractors, but remains responsible to the Customer for full performance of the contract.
2.6 Certificate Services (MPKI)
- The Provider enables the Customer to connect an existing MPKI of the Customer or to use certificate services via certification authorities mediated or integrated by the Provider.
- Customer MPKI: If the Customer uses its own MPKI, the Customer bears sole responsibility for configuration, policies, application and approval processes, identity verification, issuance, renewal, blocking, and revocation of certificates. The Provider merely provides technical interfaces and does not owe any legal or substantive review of the Customer’s certificate policies.
- MPKI obtained via the Provider: If the Customer obtains certificate services via the Provider, the terms and conditions of the respective certification authority shall also apply, including its Certificate Policy (CP) / Certification Practice Statement (CPS). Decisions of the certification authority regarding verification, issuance, rejection, suspension, or revocation are outside the Provider’s sphere of influence.
- The Customer shall ensure that all information and evidence required for certificate applications are correct, complete, and up to date, and shall cooperate without undue delay in any re-validations.
- The Customer shall protect private keys and, where applicable, cryptographic carriers from unauthorized access. Unless a separate escrow service has been agreed, restoration of lost private keys is excluded.
- The Customer consents that, as part of certificate applications, personal data may be transmitted to the respective certification authority. The Customer declares that it has taken note of and accepts the certificate policies (CP/CPS) of the respective certification authority. Consent is given expressly for each MPKI order, electronically or in writing.
- In the event of suspected misuse, legal violations, or policy violations, the Provider is entitled to temporarily block the technical connection to certificate services and to request the Customer to remedy the situation.
2.7 Outlook Add-in and Third-Party Platform Integrations (e.g., Microsoft 365/Outlook)
- If contractually agreed, the Provider provides the Customer with an Outlook add-in (e.g., “Signature Manager/Disclaimer Add-in”) which—depending on configuration and permissions—can insert or display signatures/disclaimers client-side in email drafts.
- Use of the add-in may require integration of third-party platforms (in particular Microsoft 365/Outlook and, where applicable, Microsoft Graph/Entra ID). Functionality may depend on the availability, technical specifications, policies, and changes of these third-party platforms.
- Where provision of the add-in takes place via marketplaces/stores or third-party administration portals, the respective third-party terms and conditions shall apply in addition. The Provider does not owe that the store/platform terms and conditions remain unchanged on a permanent basis.
2.8 SecureFiles
Conbool provides SecureFiles as a function for secure large file transfer and reception. Files are processed according to the Direct-Client-to-R2 principle, meaning files are uploaded directly from the Customer’s device to encrypted object storage without passing through the Provider’s application server. The recipient downloads the file directly from storage. SecureFiles supports four modes: Secure Send, Secure Inbox, Public Link with caps, and Shared Pool. The availability of specific modes depends on the Customer’s license configuration.
2.9 DMARC Reports
Conbool provides DMARC Reports as a module for automated collection, evaluation, and visualization of DMARC aggregate reports (RUA) and forensic reports (RUF). Reports are processed exclusively within the Customer’s Conbool tenant. Based on the collected data, Conbool issues policy recommendations. These recommendations are non-binding advice. The decision to set a DMARC policy (e.g., changing from p=none to p=quarantine or p=reject) is the Customer’s sole responsibility.
2.10 Email Archiving
- With the email archiving module, Conbool provides audit-proof storage of incoming and outgoing emails. Capture takes place via the source configured by the Customer, in particular the journal of its mailbox system, the mail flow of the gateway, or an import of existing holdings.
- The Provider supplies the technical means of retention. The statutory retention obligation itself, in particular under §§ 147 AO, 257 HGB, rests solely with the Customer and remains with the Customer even where it is technically outsourced to the Provider. The Provider does not owe any particular outcome under tax, commercial, or regulatory law, nor recognition of the archive by an authority or auditor in an individual case.
- Immutability is provided in two storage classes, which are indicated in the product:
- Standard. Retention is enforced in software: archived messages are locked against modification, the deletion run refuses deletion before the retention period expires, and the audit trail is secured against undetected manipulation by a hash chain whose head is regularly written as a seal outside the database into the object storage (immutable in the Compliance storage class). There is no object lock at the storage target in this class.
- Compliance. In addition, the storage target holds each object immutable until the retention period expires (object lock). This class requires a storage target with a verified object lock; it is only indicated where the Provider has actually measured the lock at the target.
- The storage location and the subcontractor used in each case are set out in the Service Description and in Annex 1 to the Data Processing Agreement. A distinction applies:
- Storage targets operated by the Provider. In addition to the default target, the Provider offers further storage targets which it operates itself and which the Customer may choose. They are named as subcontractors in Annex 1 to the Data Processing Agreement and come into use once the target has been set up for the tenant. The Provider is liable for them in accordance with Section 12.1 as for its own fault.
- Storage targets provided by the Customer. Where the Customer uses its own S3-compatible storage target, it is itself responsible for its operation, location, availability, backup, and configuration; such a target is not a subcontractor of the Provider.
- Section 5.5.3 governs the consequences of contract termination, and Section 10.9 the fee for custody beyond that point.
2.11 Continuity (Email Continuity)
- With continuity, Conbool provides access to incoming messages independently of the Customer's mailbox system so that the Customer can continue to read and reply during an outage of its mailbox system. After the outage ends, the messages accepted in the meantime are delivered on.
- Continuity requires that the Customer's mail flow runs via the Provider's gateway. It covers only messages that actually reach the Provider during the outage; by its nature, continuity cannot provide messages that are delivered directly to the failed system or whose senders abandon delivery.
- Continuity is a bridging access and not a replacement for the Customer's mailbox system. It reproduces neither its full range of functions nor its existing data.
2.12 Awareness
- With awareness, Conbool provides a module for conducting phishing simulations, for subsequently training the employees concerned, and for evaluating the results.
- The simulations send test messages on the Customer's behalf to the recipient groups determined by the Customer. The Customer determines the selection of recipients, timing, templates, and scope.
- The Provider supplies training content and reports. It does not owe any particular learning, behavioural, or detection rate, nor recognition of the reports as evidence by an authority, auditor, or insurer in an individual case.
2.13 365 Backup
- With 365 backup, Conbool provides a module for the scheduled backup of content from Microsoft 365 and for restoring individual items. The scope of the sources that can be backed up is set out in the Service Description.
- The backup takes place exclusively via the interfaces provided by Microsoft and depends on their availability, permission grants, throttling, and changes. Content and item types that these interfaces do not release, or do not release in full, cannot be backed up.
- 365 backup is a backup and not archiving within the meaning of Section 2.10. In the storage tiers with an object lock, the backups are written immutably at the storage target; a change of tier applies only to future backups. 365 backup does not provide gapless, audit-proof retention within the meaning of §§ 147 AO, 257 HGB and does not replace the email archiving module.
- Deletion at the customer's request is carried out per protection unit, that is per mailbox, per archive mailbox, per group mailbox, per OneDrive, per SharePoint list, per Microsoft Team, per Teams chat, per Planner plan, and per directory extract from Microsoft Entra ID. 365 backup does not delete individual data subjects from within an existing protection unit; the reason and details follow from the Data Processing Agreement.
§ 3 Conclusion of Contract
- The contract is concluded by the Customer’s acceptance of an offer made by the Provider or by use of the service.
- The Customer warrants that all information provided during registration is complete and correct.
§ 4 Trial Phase of the Service
4.1 General Rule
- The Provider grants the Customer the right to test the service on a non-binding basis and free of charge as described in the service description. The trial phase serves solely for product evaluation; commercial use is prohibited.
- Trial accounts are limited to one registration per natural person/company.
4.2 Contract Formation During the Trial Phase
- The trial phase begins upon the Customer’s acceptance of the offer.
- There is no entitlement to a trial phase. The Provider reserves the right to refuse the trial phase or terminate it early for the following reasons:
- suspicion of abusive use (e.g., multiple registrations, automated bot use, sharing of access credentials)
- violations of § 6 (in particular security and usage obligations)
- technical impossibility of provision (including server outages, maintenance, force majeure pursuant to § 12.5)
- evident criminal acts (e.g., attempted fraud, data manipulation)
4.3 End of the Trial Phase
- The trial phase ends automatically after expiry of the number of days granted in the service description, without requiring termination.
- All Customer data will be deleted no later than 72 hours after the end of the trial phase in accordance with § 5.5, unless statutory retention obligations apply.
§ 5 Term and Termination
5.1 Term
5.1.1 SaaS Solution
- Unless otherwise agreed, the contract is concluded for a minimum term of 12 months. After the minimum term expires, the contract automatically renews for successive 12-month periods unless terminated in due time.
5.1.2 On-Premise Solution (Rental License)
- The license for the on-premise solution is granted exclusively as a time-limited rental license. The minimum term is 12 months unless otherwise agreed.
- After the minimum term expires, the rental license automatically renews for successive 12-month periods unless terminated in due time.
- Upon expiry of the contract term, the right to use the software automatically lapses unless the contract is extended.
5.2 Notice Periods
5.2.1 SaaS Solution
- Either party may terminate the contract with three months’ notice to the end of the respective contract term unless different notice periods have been agreed individually.
5.2.2 On-Premise Solution (Rental License)
- Either party may terminate the rental license contract with three months’ notice to the end of the respective contract term unless different notice periods have been agreed individually.
5.3 Extraordinary Termination
The right to extraordinary termination for cause remains unaffected. Cause exists in particular if:
- the Customer is in default with payment of a due amount despite reminder and reasonable grace period;
- the Customer breaches material contractual obligations, in particular the terms of use;
- insolvency proceedings are opened over the Customer’s assets or opening is rejected due to lack of assets;
- in the on-premise solution: the Customer violates license terms (e.g., reverse engineering or distribution of the software).
5.4 Form of Termination
- Any termination must be made in text form (e.g., email) or in writing, unless expressly agreed otherwise.
5.5 Consequences of Contract Termination
After termination, Customer data will either be deleted or returned to the Customer in accordance with Section 4(9) of the Data Processing Agreement (https://conbool.com/dpa).
5.5.1 SaaS Solution
Upon termination, the Customer’s access to the SaaS service is deactivated and all stored data is deleted, unless statutory retention obligations apply or otherwise agreed. The Customer is responsible for downloading or otherwise securing all required data prior to contract end.
5.5.2 On-Premise Solution (Rental License)
Upon expiry of the contract, the right to use the software automatically lapses; the Customer is obliged to fully remove the software and delete all copies. The Provider reserves the right to implement technical measures to deactivate the software after expiry of the contract.
5.5.3 Email Archiving
- By way of derogation from § 5.5.1, the retention obligation for messages archived via the Email Archiving module does not end with the contract. The retention period configured by the Customer applies to them; it regularly follows from Sections 147 of the German Fiscal Code (Abgabenordnung, AO) and 257 of the German Commercial Code (Handelsgesetzbuch, HGB) and may extend several years beyond contract end.
- Before contract end, the Customer shall choose between the following options and communicate the choice in text form:
- Return and deletion. The Provider makes the archive holdings available to the Customer for retrieval in a common, machine-readable format. After confirmed complete retrieval, the Provider deletes the holdings in accordance with paragraph 5. Upon return, the Provider's technical custody ends; from that point the retention obligation rests solely with the Customer (Section 2.10 paragraph 2). No fee under paragraph 3 applies to this option.
- Continued custody by the Provider. The Provider continues to hold the archive until the respective retention period expires. For this period, the Customer retains read access to the archive, including search and export. New messages are no longer archived.
- For continued custody, the Customer owes the fee for archive storage at the rate applicable at the time of contract termination in accordance with the price list then in force. The storage actually occupied is decisive. As no new messages are added after contract end and expired messages are deleted on an ongoing basis, the occupied storage, and thus the fee, decreases over time. Fees for user licenses cease upon contract end.
- If the Customer makes no choice under paragraph 2 by contract end, the Provider continues to hold the archive. The Provider shall inform the Customer in text form of the choice and of this consequence no later than one month before contract end. The Customer may switch to return at any time; the fee then ends with the month following complete return.
- Messages archived under the tariff with verified object lock are technically protected against deletion until the respective lock period expires. This period is no more than twelve months from the last extension. A deletion request by the Customer is carried out for such messages upon expiry of the lock period. The Provider points out this property before the tariff is booked; it is the purpose, not a side effect, of audit-proof archiving.
- Deletions under this section are logged. The Customer may retrieve the log until deletion is complete.
5.6 Special Rules for MPKI Terms
- Terms and renewals of certificates obtained via the Provider are governed exclusively by the conditions of the respective certification authority and are independent of the term of the SaaS or on-premise contract.
- Termination of the contract with the Provider does not affect existing certificates. The Customer bears any fees of the certification authority until the respective expiry or effective termination vis-à-vis the certification authority.
§ 6 Customer Obligations
6.1 General Obligations
The Customer undertakes:
- to use the service only in compliance with applicable laws and in accordance with the contractual provisions and the Provider’s instructions;
- to keep access data such as passwords secure and protect them from unauthorized third-party access;
- not to send, store, or process unlawful content via the email system, in particular no content that
- violates applicable law or third-party rights,
- is pornographic, glorifies violence, discriminatory, or constitutes incitement of hatred,
- violates personal rights or calls for criminal acts.
6.2 Responsibility for Content
- The Customer is solely responsible for the content of emails sent, received, or stored via the service, as well as for all data processed with the service.
- The Provider does not monitor content and assumes no liability for its legality.
6.3 Use of the Message Portal and Disclosure to Third Parties
- The Customer may make messages stored in the message portal accessible to third parties only via the security mechanisms provided by the Provider (e.g., password protection, temporary links).
- The Customer must ensure that a data protection legal basis exists for disclosure to third parties. The Customer is obliged to fulfill all relevant information obligations pursuant to Arts. 13 and 14 GDPR vis-à-vis affected third parties, e.g., by providing notices upon first access.
- In case of suspected abusive use of access, the Customer must immediately take appropriate measures to block access.
- Responsibility for content, legality, and access sharing remains entirely with the Customer.
6.4 Security Obligations
- The Customer undertakes to protect all systems and devices in accordance with current IT security standards (e.g., firewalls, antivirus software, regular updates).
- The Customer must not take any measures that could impair the security or functionality of the service (e.g., overloading or unauthorized access).
6.5 Special Obligations for On-Premise Solutions
- When using the on-premise solution, the Customer is solely responsible for operating the software in its IT infrastructure and for compliance with all applicable data protection and security regulations.
- The Customer undertakes to perform regular backups of its data and to ensure these are available independently of the installed software.
- The Customer must implement security measures such as firewalls and antivirus software to prevent unauthorized access to the software.
6.6 Compliance with Legal Requirements
- The Customer shall ensure that all statutory requirements for data processing within its company are complied with, including obligations towards third parties such as authorities or data subjects.
6.7 Additional Obligations When Using the Disclaimer/Signature Manager and Outlook Add-in
- The Customer is responsible for the substantive correctness, up-to-dateness, and legal permissibility of the signatures/disclaimers used (e.g., mandatory information, data protection notices, advertising content), as well as for selecting the use cases (e.g., which recipient groups, languages, exceptions).
- The Customer warrants that it holds all necessary rights to embedded assets (e.g., logos, images, fonts, files) and that their use does not infringe third-party rights.
- The Customer shall ensure that all necessary technical prerequisites for the use of third-party integrations (e.g., Microsoft 365/Outlook, Entra ID, connectors) are met, in particular required administrative approvals (e.g., consent), roles/permissions, and configurations.
- The Customer is obliged to configure settings and permissions according to the principle of data minimization and to activate only those data flows necessary for the intended purpose.
- The Customer is responsible for ensuring that internal policies (e.g., works council, compliance, IT security) cover use of an add-in and the associated processing.
6.8 Obligations when using SecureFiles
The Customer is solely responsible for the content of uploaded files and for the correct configuration of recipients and caps (download count, expiry, IP allowlist). When using the “Public Link” mode, the Customer bears sole responsibility for the lawful distribution of the provided content. When using the “Secure Inbox” mode, the Customer must ensure that external uploaders are informed about data protection requirements prior to upload. When using out-of-band password delivery, the Customer is responsible for the secure transmission of the password.
6.9 Obligations when using DMARC Reports
The Customer is responsible for the correct DNS configuration of the DMARC policy and the associated rua/ruf tags. Conbool receives DMARC reports on behalf of the Customer and processes them exclusively for the purposes set out in § 2.9. The Customer is aware that DMARC forensic reports may contain email header information of third parties and shall ensure that the processing of such data is covered by a suitable legal basis.
6.10 Obligations When Using Email Archiving
- The Customer sets up the capture source completely and keeps it complete. In particular, it is responsible for ensuring that the journal of its mailbox system captures all mailboxes and message paths subject to retention, and that new mailboxes, domains, and forwardings are kept up to date. The Provider can only archive what is fed to it.
- The Customer sets the retention periods. It is responsible for ensuring that these correspond to its statutory obligations and reviews them when the legal situation or its business operations change.
- At reasonable intervals, but at least once a year, the Customer checks whether the archive holdings are complete and whether search and export function. It notifies the Provider of any discernible gaps without undue delay in text form.
- The Customer creates and maintains the procedural documentation required for its process. The Provider supplies the technical particulars of its module for this purpose but does not owe documentation of the Customer's process.
- The Customer is responsible for the employment-law and data-protection prerequisites of archiving, in particular the involvement of the employee representative body and the handling of private use of business mailboxes.
6.11 Obligations When Using Continuity
- The Customer keeps the users, access paths, and delivery addresses stored for continuity up to date and ensures that its employees know how to reach the access in an emergency.
- The Customer acknowledges that continuity is only effective for as long as its mail flow runs via the Provider's gateway, and that a change to its MX records or transport path removes that effect.
6.12 Obligations When Using Awareness
- The Customer is responsible for the permissibility of the simulations within its organisation, in particular the involvement of the employee representative body, the information of employees, and the data-protection basis for processing participation and click data.
- The Customer sends simulations exclusively to recipients for whom it is responsible. Sending to third parties without their involvement is prohibited.
- The Customer ensures that the sender addresses, domains, and brands used for the simulation do not infringe the rights of third parties.
6.13 Obligations When Using 365 Backup
- The Customer sets up the connection to Microsoft 365, grants the required permissions, and maintains them. Withdrawn, expired, or restricted permissions result in backups not running or running only in part.
- At reasonable intervals, but at least once a year, the Customer checks whether the backup runs succeed and whether items can be restored. The Provider supplies reports and a restore function for this purpose, as well as instructions in the documentation describing how such a check is carried out.
- The Customer is responsible for selecting the sources and mailboxes to be backed up and for the retention period of the backups.
§ 7 Provider Obligations
7.1 General Obligations
- The Provider ensures that the service is provided with a high level of availability (see § 11).
- The Provider undertakes to comply with all data protection requirements under the GDPR and has provided a Data Processing Agreement (https://conbool.com/dpa) as part of these GTC.
7.2 Security and Incident Notification
- The Provider will inform the Customer without undue delay if security incidents occur that affect personal data (e.g., personal data breaches pursuant to Art. 33 GDPR).
- The Provider undertakes to take all necessary measures to contain a security incident and to support the Customer in fulfilling any reporting obligations towards supervisory authorities or data subjects.
7.3 Special Obligations for SaaS Solutions
- The Provider provides storage space on a server and undertakes to implement appropriate measures against data loss and unauthorized third-party access.
- The Provider informs the Customer in due time about planned maintenance or changes to the service.
7.4 Special Obligations for On-Premise Solutions
- When using the on-premise solution, the Provider provides installation instructions and technical documentation.
- Updates or patches are provided by the Provider in accordance with the maintenance agreement.
7.5 Special Notes on the Outlook Add-in
- Within the scope of the contract, the Provider provides the technical availability and updating of the add-in in accordance with the service description.
- However, the Provider does not warrant compatibility of the add-in with all third-party environments, policies, client versions, or add-in restrictions; in the event of material third-party changes, the Provider will endeavor to make reasonable adjustments insofar as economically and technically feasible.
§ 8 Setup and Configuration
8.1 General Rule
- Setup and configuration of the Conbool platform are generally the Customer’s responsibility and are not part of the Provider’s services under the main contract.
- The Provider provides the Customer with comprehensive documentation and support materials to facilitate independent setup.
8.2 Additional Services
- Upon request, the Customer may purchase setup and configuration as an additional paid service from the Provider.
- For the on-premise variant, the Provider may, upon request, support installation and integration into the Customer’s IT infrastructure. This service is billed separately.
8.3 Customer Responsibility (On-Premise)
- The Customer bears sole responsibility for installation, configuration, and operation of the software in its IT infrastructure unless additional services by the Provider have been agreed.
- The Customer undertakes to meet all technical requirements as set out in the provided documentation.
§ 9 Data Protection and Data Security
9.1 General Data Protection Rules
- The Provider processes personal data exclusively in accordance with the GDPR and has provided a Data Processing Agreement (https://conbool.com/dpa) pursuant to Art. 28 GDPR.
- Logs are maintained exclusively for troubleshooting and security monitoring and can be made available to the Customer upon request. All stored logs are deleted after no later than 90 days unless statutory retention obligations apply.
9.2 Confidentiality and Access
- The Provider generally processes emails in a streaming manner and stores content only where technically required for certain functions (e.g., display in the message portal, SecureFiles, email archiving, quarantine). Access to stored content takes place exclusively in encrypted form and in compliance with applicable data protection standards. Customer certificates and private keys are stored encrypted. Passwords are stored exclusively as hash values. Technical access to plain text by the Provider is not possible.
- In support cases, the Provider may—with the Customer’s express consent—temporarily access metadata to diagnose and remedy technical issues.
- External recipients who access messages via the message portal receive GDPR-compliant information about data processing upon first access. The Provider provides the technical means for this information obligation (e.g., banner or notice text).
9.3 Subcontractors
- Subcontractors used by the Provider are listed in the DPA and meet the requirements pursuant to Arts. 44 et seq. GDPR.
- Changes to subcontractors will be communicated to the Customer at least 14 days before their use, in writing or in text form.
9.4 Logging
- The Provider maintains logs relating to mail flow and cryptographic operations used. These logs serve exclusively for troubleshooting and security monitoring and can be made available to the Customer upon request.
- Logs do not contain email content or other personal data unless technically necessary (e.g., email addresses, technical status information).
9.5 Particularities for Add-ins and Third-Party Platforms
- Where the Outlook add-in is executed in third-party environments (e.g., Microsoft 365/Outlook), parts of the processing take place within the third party’s technical sphere and under its terms.
- The Provider processes data in connection with the add-in (e.g., template retrievals, technical event data) only insofar as necessary for service provision, troubleshooting, and security, and otherwise in accordance with the DPA.
§ 10 Remuneration and Payment Terms
10.1 General Rule
- The Customer undertakes to pay the agreed fee for the contractual services plus statutory VAT.
- Unless otherwise agreed, remuneration is based on the price list valid at the time of contract conclusion. Current prices are available in the customer area or upon request.
10.2 Payment Methods
10.2.1 SaaS Solution
- Remuneration for SaaS licenses is payable exclusively in advance on an annual basis. The billing period is 12 months.
- Payments are made by credit card, SEPA direct debit, bank transfer, or via the payment service provider Stripe, unless another payment method is expressly agreed.
10.2.2 On-Premise Solution
- Remuneration for on-premise rental licenses is payable annually in advance. The billing period is 12, 24, or 36 months.
10.3 Price Adjustments
- The Provider is entitled to adjust prices once per year at its reasonable discretion pursuant to § 315 BGB in order to reflect changes in cost factors relevant to pricing, in particular:
- operating costs (e.g., data centers, hardware, technical services),
- license costs (e.g., software licenses),
- personnel and energy costs as well as fees or taxes imposed by public authorities.
- Any price adjustment is limited to the extent of changes in the cost factors and may result in price increases or decreases. Cost reductions are taken into account to the same extent as cost increases.
10.4 Notice and Right of Termination in Case of Price Adjustments
- The Provider will notify the Customer of any price change at least eight weeks prior to its effective date in text form (e.g., email).
- In the event of a fee increase, the Customer has the right to terminate the contract without observing a notice period effective at the end of the current contract period. Fees paid in advance for the current period remain unaffected.
10.5 Late Payment
- The Customer is in default if it fails to pay a due amount within 30 calendar days after receipt of the invoice to the Provider’s account (§ 286(3) BGB).
- The Provider will remind the Customer of the outstanding payment in writing or text form (e.g., email) and set a grace period of at least 10 calendar days.
- If payment is still not made despite reminder and grace period, the Provider will, in a second reminder with an additional grace period of 14 calendar days, expressly point out the imminent deactivation of the service.
- From the time of default, the Provider is entitled to:
- charge default interest of up to 9 percentage points above the base interest rate (§ 288(2) BGB, business-to-business);
- temporarily deactivate the contractual service (e.g., access to the customer account, software, or service) if the Customer was informed of deactivation in the second reminder and/or the grace period in the second reminder (14 days) has expired without success.
- Deactivation will be lifted without undue delay as soon as the Customer has fully paid all due amounts. Deactivation does not release the Customer from its payment obligation.
- If the Customer remains in default for more than 60 days or there is a particularly serious default, the Provider is entitled to terminate the contract without notice (§§ 314, 323 BGB).
- The assertion of further claims for damages (e.g., judicial or extrajudicial collection costs) remains expressly reserved.
10.6 Chargebacks
The Customer bears in full any costs arising from chargebacks for which the Customer is responsible.
10.7 Costs for MPKI
- If the Customer uses a Customer MPKI, the Customer bears all resulting costs in full. This includes in particular fees for identity verification, issuance, renewal, revocation, OCSP or CRL, smartcards or security tokens, shipping, HSM capacity, and other charges of the bodies used by the Customer.
- If the Customer obtains certificate services via the Provider, the Customer bears all fees and charges of the certification authority, including any price changes. The Provider may pass these costs on to the Customer as pass-through items.
- Certification authority fees are payable independently of software use. Refunds of already incurred CA fees are excluded unless the certification authority provides for a refund.
10.8 Overuse, True-Up, and Blocking
- Overuse occurs if the actual number of active users or mailboxes exceeds the number licensed under the contract.
- Usage is counted quarterly based on the active users or mailboxes for which at least one productive processing event occurred during the respective quarter.
- The Customer is obliged to immediately cease the overuse or to purchase the corresponding number of additional licenses.
- The Provider is entitled to invoice additional licenses by way of a true-up. The fee for additional licenses becomes due from the beginning of the calendar month in which the overuse first occurred, at the latest from the time the Provider identifies the overuse, in each case pro rata until the end of the current contract period.
- The Provider will inform the Customer of the identified overuse and grant a period of 10 business days to remedy. If the Customer fails to remedy within this period, the Provider may technically restrict or suspend the affected excess use insofar as this is necessary to ensure license compliance.
- A subsequent reduction of usage within the current contract period does not entitle the Customer to any refund of already invoiced additional licenses.
- To verify license compliance, the Provider is entitled to conduct a license audit once per year based on usage data available to the Provider. Upon request, the Customer shall cooperate to a reasonable extent, in particular by providing an up-to-date user and/or mailbox list. The Customer’s trade and business secrets shall be protected.
- The Provider’s rights under § 10.5 (Late Payment) and § 12 (Liability) remain unaffected.
10.9 Fee for Custody after Contract End
- If archive holdings are held beyond contract end pursuant to § 5.5.3, the fee for archive storage is invoiced monthly in advance. The remaining fees of the terminated contract cease to apply.
- The Customer shall maintain a valid means of payment for the duration of the custody. If the Customer is in default with the custody fee for more than 60 days, the Provider may demand return of the archive holdings pursuant to § 5.5.3 paragraph 2; in this case the Provider is not obliged to continue holding the archive free of charge.
§ 11 Availability and Support
11.1 Service Availability
11.1.1 SaaS Solution
- The Provider warrants availability of the SaaS service of 99.9% on an annual average at the transfer point.
- The availability warranty does not cover:
- planned maintenance announced to the Customer at least 48 hours in advance and, where possible, performed outside normal business hours;
- force majeure events (e.g., natural disasters, power outages);
- disruptions caused by the Customer or the Customer’s IT infrastructure;
- impairments caused by certification authorities, MPKI services, OCSP/CRL infrastructures, trust store changes, or MPKI policies set by the Customer;
- impairments caused by third-party platforms (e.g., Microsoft 365/Outlook, store/policy changes) insofar as they are outside the Provider’s control.
11.1.2 On-Premise Solution
- For the on-premise solution, the Provider does not warrant availability, as operation and maintenance are the Customer’s responsibility.
- The Provider provides updates and patches in accordance with the maintenance agreement to ensure the functionality of the software.
11.2 Maintenance and Troubleshooting
11.2.1 SaaS Solution
- Critical incidents will be qualified and handled within four hours after receipt of the incident report during business hours. The Provider will endeavor to resolve the incident as quickly as possible.
- For less critical incidents, the Provider will endeavor to remedy them within a reasonable period of time.
- Maintenance activities may require the Provider to access the Customer’s configuration; the Customer must grant permission for such access.
11.2.2 On-Premise Solution
- The Provider offers support for critical incidents only within the scope of the agreed maintenance agreement.
- Remedying incidents may require interventions in the Customer’s IT infrastructure; the Customer is obliged to grant the Provider access for this purpose.
- Maintenance activities may require the Provider to access the Customer’s configuration; the Customer must grant permission for such access.
11.3 Support Services
11.3.1 General Support Rules
- The Provider offers support via email or ticket system with a guaranteed response time of 48 hours on business days.
- Support requests can be submitted via the channels specified in the customer area.
11.3.2 Phone Support (Enterprise Customers Only)
- Phone support is not part of the standard support services and can only be used under a separate enterprise agreement.
11.3.3 Limitations
- The Provider is not obliged to provide support for problems caused by improper use or modifications to the software by the Customer.
§ 12 Liability
12.1 General Liability Provisions
- The Provider shall be liable without limitation for damages caused by intentional misconduct or gross negligence on the part of the Provider or its vicarious agents, as well as for damages arising from injury to life, body, or health.
- In cases of slight negligence, the Provider shall only be liable for damages resulting from the breach of essential contractual obligations. Essential contractual obligations include, in particular, ensuring contractual availability in accordance with Section 11, safeguarding personal data pursuant to Art. 32 GDPR, as well as the general provision of the contractually agreed main services and system functions in accordance with the Service Description, but not the achievement of a specific security-related outcome in each individual case unless an express guarantee has been assumed. Liability in cases of slight negligence shall be limited to damages that were typically foreseeable at the time the contract was concluded, and in amount to no more than the total of the fees paid by the Customer for the two years preceding the damaging event. If the contractual relationship existed for a shorter period, the amount shall be extrapolated to two years on the basis of the fees paid up to that point.
- The Provider shall not be liable for indirect damages, consequential damages, or loss of profit unless such damages are attributable to intentional misconduct or gross negligence, or concern the breach of essential contractual obligations to the extent permitted by law (Section 309 No. 7 BGB).
- Liability under the German Product Liability Act shall remain unaffected.
- For the loss of data the Provider shall be liable, notwithstanding the preceding paragraphs, only up to the amount of damage that would also have occurred had the Customer made regular backup copies appropriate to the risk. This limitation does not apply to data in the email archiving and 365 backup modules, whose very purpose is retention by the Provider; Sections 12.10 and 12.13 apply in that respect.
- The Provider selects and monitors its subcontractors, in particular data centre and storage service providers, with due care. It is responsible for their fault as for its own pursuant to § 278 BGB; the liability limitations of this Section 12 apply to such fault in the same way as to the Provider's own fault. A storage or target system provided or designated by the Customer itself does not qualify as a subcontractor.
- The Provider shall not be liable for delays in the delivery or processing of emails caused by technical issues outside the Provider’s sphere of influence.
12.2 Special Liability Provisions for MailGuard / Protection Functions
12.2.1 Purpose of the MailGuard Functions
The functions provided by the Provider as part of MailGuard serve the risk-based detection, assessment, filtering, marking, quarantining, sanitization, rewriting, or other handling of potentially harmful, unwanted, fraudulent, or policy-violating emails, attachments, files, links, QR codes, and comparable content.
12.2.2 No Specific Success Owed in Individual Cases
The Provider does not owe complete, error-free, or continuously successful detection, classification, blocking, sanitization, neutralization, or prevention of all spam, phishing, malware, fraud, business email compromise, social engineering, zero-day, or other attacks, content, or delivery events.
The provision of the MailGuard functions does not constitute a guarantee of the achievement of a specific security-related outcome in any individual case.
12.2.3 Possible Misclassifications and Technical Limitations
In particular, it cannot be excluded that
a) harmful, unwanted, or fraudulent messages or content may pass through, be detected late, or be incorrectly classified despite the protection mechanisms in use,
b) legitimate messages or content may in individual cases be incorrectly marked, delayed, rewritten, sanitized, quarantined, rejected, or blocked,
c) inspections cannot be carried out, or cannot be carried out completely, due to technical, content-related, or format-related limitations, in particular in the case of encrypted, damaged, password-protected, nested, unusually structured, or otherwise only partially analyzable content,
d) the results of reputation, link, QR, file, malware, DLP, heuristic, AI/ML, or other inspection mechanisms may be incomplete, delayed, inaccurate, or unavailable in individual cases.
12.2.4 Shared Responsibility and Security Obligations of the Customer
MailGuard does not replace an appropriate multi-layered security concept of the Customer, in particular not endpoint protection, patch and vulnerability management, multi-factor authentication, data backup, user awareness, organizational control measures, quarantine review, or proper policy configuration.
12.2.5 Exclusion in the Event of Causes Within the Customer’s or Third Parties’ Sphere
To the extent that damage is wholly or partly attributable to the fact that
a) the Customer has deactivated, restricted, or improperly configured protection functions,
b) customer-side thresholds, policies, exceptions, approvals, whitelists, blacklists, routing, delivery, or DLP rules enabled or contributed to the incident,
c) third-party information, third-party infrastructures, or third-party platforms were unavailable, delayed, or faulty, or
d) the Customer failed to review, implement, or follow up warnings, logs, quarantine events, notices, or recommended measures, or failed to do so in a timely manner,
the Provider shall not be liable for this unless the Provider acted intentionally or with gross negligence.
12.2.6 Application of the General Liability Provisions
In all other respects, the Provider shall only be liable for damages in connection with MailGuard in accordance with this Section 12.
12.3 Liability for Sharing Messages with Third Parties via the Message Portal
- If the Customer makes messages accessible to third parties via the message portal, the Customer bears sole responsibility for the selection, timing, and legal permissibility of such disclosure.
- The Provider is not liable for access by unauthorized third parties resulting from insufficient access protection, incorrect configuration, or misuse by the Customer or third parties.
- Subject to § 12.1, the Provider’s liability is limited exclusively to technical defects in access control or data encryption insofar as the Provider is responsible for such defects.
12.4 Data Protection and Joint and Several Liability
- The Provider is liable towards data subjects pursuant to Art. 82 GDPR only if it violates obligations imposed on it under the GDPR or lawful instructions of the Customer.
- The Provider is released from liability if it can prove that it is not responsible in any way for the circumstance that caused the damage.
- In the event of a data protection violation, the Provider and the Customer are jointly and severally liable towards data subjects pursuant to Art. 82(4) GDPR.
- Internally, each party bears responsibility for violations within its sphere of responsibility:
- The Customer shall indemnify the Provider against third-party claims arising from unlawful use of the service by the Customer (e.g., unlawful content in emails).
- Conversely, the Customer may request indemnification from the Provider if the Provider is solely responsible for the violation.
12.5 Exclusion of Liability in Case of Force Majeure
- The Provider is not liable for damages or service failures caused by force majeure events (e.g., natural disasters, strikes, official orders, power outages, or cyberattacks), provided the Provider takes all reasonable measures to mitigate damage without undue delay. Cyberattacks qualify as force majeure only if the Provider can demonstrate that it complied with current security standards.
12.6 Rules Specific to the Operating Model
- SaaS Solution
- The Provider ensures that subcontractors act in compliance with the GDPR and informs the Customer about their use.
- Where the Provider uses third parties to render the service, in particular data centre, cloud, or storage service providers, these are its vicarious agents; the Provider is liable for their fault, including the loss or deletion of data within their sphere, in accordance with Section 12.1 as for its own fault. For disruptions originating in the sphere of third parties whom the Provider does not use to perform its obligation, in particular the Customer's third-party platforms, certification authorities, and sending or receiving external systems, the Provider is liable only in the event of its own breach of duty.
- The Provider is liable for decisions and services of certification authorities and for damages resulting from Customer MPKI configurations only in accordance with § 12 and only in the event of its own breach of duty.
- On-Premise Solution
- The Provider assumes no liability for damages or disruptions caused by improper installation, configuration, or use by the Customer.
- The Provider is also not liable for security vulnerabilities or system failures due to missing updates or insufficient security measures on the Customer’s side.
12.7 Additional Liability/Warranty Notes for Add-ins, Templates, and Third-Party Platforms
- The Provider is liable for malfunctions, restrictions, or outages caused by changes, policies, security measures, or disruptions of third-party platforms (e.g., Microsoft 365/Outlook, store/admin center, API limits) that are outside the Provider’s control only in accordance with § 12.1 and only in the event of the Provider’s own breach of duty.
- The Provider does not warrant the legal validity, completeness, or suitability of signatures/disclaimers created or provided by the Customer. The Customer remains responsible for content and legal compliance.
- Where the Outlook add-in accesses drafts client-side, display and insertion may depend, inter alia, on client versions, add-in policies, local settings, and network conditions; the liability standards of this § 12 apply accordingly.
12.8 Liability for SecureFiles
The Provider is not liable for damages arising from the Customer’s accidental sharing of a file via a public link, from incorrect cap configuration, or from disclosure of the out-of-band password to unauthorized persons. In the event of proven data loss due to a breach of duty attributable to the Provider, § 12.1 (general liability limitation) applies. The Provider does not guarantee the uninterrupted detection of malware in uploaded files; the malware scan prior to release is an additional protective layer and does not replace endpoint security.
12.9 Liability for DMARC Reports
Conbool provides policy recommendations based on the collected reports. These recommendations are non-binding advice and do not replace the Customer’s own risk assessment. The Provider is not liable for damages arising from implementation of a recommendation, in particular not for email loss due to a DMARC policy set too strictly by the Customer. The Provider is further not liable for evaluation errors resulting from incomplete or incorrect reports from recipient servers.
12.10 Liability for Email Archiving
- The Provider owes retention of the holdings fed to it in accordance with the Service Description and the periods set by the Customer. It does not owe completeness of the holdings where the cause lies in the Customer's capture source, in particular incomplete journal configuration, mailboxes or domains not kept up to date, a bypassed mail path, or incomplete import holdings (Section 6.10).
- The Provider does not owe any particular outcome under tax, commercial, or regulatory law. The Provider is liable for disadvantages suffered by the Customer as a result of the assessment of its archive by an authority, auditor, or court only where the objection rests on a breach of duty for which the Provider is responsible.
- In the Standard storage class, immutability is enforced in software and secured by a hash chain whose head is regularly written as a seal outside the database into the object storage (immutable in the Compliance storage class); there is no object lock at the storage target (Section 2.10 paragraph 3). The Provider indicates the storage class in effect in the product. The Provider is not liable for disadvantages arising from the Customer not having booked a storage class with a verified object lock.
- For the loss of archived messages for which the Provider is responsible, it is liable in accordance with Section 12.1. The limitation to the restoration effort under the Customer's own backup does not apply here.
- Where the Customer uses its own storage target, the Provider is not liable for loss, unavailability, or alteration of data attributable to its operation, configuration, termination, or shutdown.
12.11 Liability for Continuity
- Continuity is a bridging access. The Provider does not owe a complete reproduction of the failed mailbox system, nor the capture of all messages addressed to the Customer during an outage.
- The Provider is not liable for messages that do not reach it during the outage, in particular because they are delivered directly to the Customer's mailbox system, because the sending server abandons delivery, or because the Customer has changed its mail path.
- For damages arising from delayed or incomplete onward delivery after the outage ends, the Provider is liable in accordance with Section 12.1.
12.12 Liability for Awareness
- The Provider does not owe any particular learning, behavioural, or detection rate, nor the success of awareness-raising in an individual case. Awareness does not replace a multi-layered security concept on the part of the Customer.
- The Customer alone is responsible for the selection, timing, content, and recipient group of the simulations and for their permissibility under employment and data protection law within its organisation (Section 6.12). The Customer indemnifies the Provider against third-party claims based thereon.
- The Provider is not liable for the reports provided being recognised as evidence by an authority, auditor, or insurer.
12.13 Liability for 365 Backup
- The Provider owes the performance of the backup runs in accordance with the Service Description, but not the complete backup or restorability of all content. Scope and completeness depend on Microsoft's interfaces and requirements (Section 2.13 paragraph 2).
- The Provider is not liable for failed, incomplete, or delayed backups where the cause lies in missing, withdrawn, or restricted permissions, in throttling or changes by Microsoft, or in a configuration changed by the Customer.
- For the loss of backed-up content for which the Provider is responsible, it is liable in accordance with Section 12.1. The limitation to the restoration effort under the Customer's own backup does not apply here.
- 365 backup does not relieve the Customer of the obligation to check restorability at reasonable intervals (Section 6.13 paragraph 2). If it fails to do so, any damage resulting therefrom shall be taken into account pursuant to § 254 BGB.
12.14 NIS‑2 Support
If the Customer is subject to the obligation to comply with NIS‑2 requirements, the Provider shall support the Customer within the scope of the supply chain duty under § 30 NIS2UmsuCG in connection with legitimate compliance inquiries. Security‑relevant incidents affecting the Customer will be communicated in addition to the GDPR notification within the time limits prescribed under NIS‑2.
§ 13 Amendments to the GTC
13.1 Amendment Reservation
The Provider reserves the right to amend these GTC if this is necessary
- due to statutory/official requirements,
- to adapt to technical or economic developments, or
- to extend/differentiate the scope of services.
13.2 Notification and Consent
- The Customer will be informed of changes at least 14 days before they take effect by email. Changes are deemed approved if the Customer does not object in writing before they take effect.
- In the event of a change, the Customer has the right to terminate the contract in text form without observing a notice period effective at the time the change becomes effective.
- In the case of legally mandatory changes (e.g., new data protection requirements), consent is deemed granted if the Customer continues to use the service after the changes take effect. This also applies if the change exclusively benefits the Customer.
§ 14 Final Provisions
- Governing law
This contract is governed by German law to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG). - Place of jurisdiction
For all disputes arising out of or in connection with this contract, the place of jurisdiction shall be Hamburg, insofar as legally permissible. - Severability clause
Should individual provisions of these GTC be or become invalid or unenforceable, the validity of the remaining provisions shall remain unaffected. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision whose effects come closest to the economic purpose pursued by the contracting parties with the invalid/unenforceable provision. - Contract language
The contract language is German. If these GTC are translated into another language, the German version shall prevail in case of doubt.