This English version is a courtesy translation. Only the German version is legally binding.
§ 1 Scope
(1) These General Terms and Conditions (Allgemeine Geschäftsbedingungen, the "Terms") apply to all contracts between Legado Management UG (haftungsbeschränkt), Hauptstraße 46, 15936 Dahme/Mark, Germany (the "Provider"), and its customers (the "Customer") for the use of the software-as-a-service solution GxP-Desk, including the trial access, the application programming interface (API) and support.
(2) The offering is directed exclusively at businesses (Unternehmer) within the meaning of Section 14 BGB. Contracts with consumers (Section 13 BGB) are excluded.
(3) Different terms proposed by the Customer apply only to the extent that the parties agree to incorporate them. Individually agreed provisions and the statutory rules governing conflicting standard terms remain unaffected.
(4) Individually agreed provisions take precedence under Section 305b BGB. Otherwise, the Order Form or accepted quote, the service description and these Terms apply in that order. In matters of processing on behalf of the Customer, the DPA takes precedence over other standard terms. Mandatory statutory rights, in particular those under § 10, are not restricted by this order of precedence.
(5) Users are the natural persons to whom the Customer grants access to GxP-Desk, including third parties acting on its behalf such as consultants or auditors. Customer Data means all data that the Customer or its Users enter, upload or generate in GxP-Desk. Text form means the form under Section 126b BGB (Textform); email is sufficient.
§ 2 Conclusion of contract and trial access
(1) The Customer may register online for a free trial. The trial agreement is concluded when the account is activated following email verification, provided the contractual terms, including the DPA, have first been supplied and agreed; the registering person must be authorised to represent the Customer. Before the contract is concluded, the Provider supplies the agreed contractual terms, including the switching provisions, in a form that can be stored and reproduced.
(2) The trial period is 14 days from activation. The trial access is limited, in particular to a maximum of 15 Users, one tenant and a limited number of systems, and includes a demo workspace with sample data. The contract for the trial access ends upon expiry of the trial period without notice of termination being required and does not automatically convert into a paid contract. There is no entitlement to an extension. The trial access serves evaluation purposes, not productive use, in particular not the keeping of GxP-relevant records.
(3) After the trial ends, access switches to read-only mode. If no paid contract is concluded, the Provider deletes the data from active systems after a reasonable period for deciding whether to continue and for retrieving data, and no later than six months after the trial ends; it deletes the data earlier at the Customer's request. Before the planned deletion, it gives timely notice of the opportunity to have data returned. Section 12 of the DPA governs Customer Data and backups; mandatory switching and retrieval rights under § 10 are not shortened.
(4) Paid contracts are concluded through a quote or Order Form issued by the Provider in text form and accepted by the Customer in text form. Before conclusion, the Provider supplies the incorporated Terms, DPA and switching provisions in a form that can be stored and reproduced. Information on the website is not a binding offer.
§ 3 Provider's services
(1) The Provider makes GxP-Desk available as software-as-a-service via the internet; the scope results from the plan, the Order Form and the service description. The Provider does not owe provision of the software for installation.
(2) The point of delivery (Übergabepunkt) is the internet exit of the data centre used by the Provider. The Customer is responsible for the connection up to that point and for its own IT equipment, in particular an up-to-date web browser.
(3) The Provider may develop the services further to the extent necessary for specific security reasons, to comply with changed mandatory legal requirements or to maintain technical functionality, and provided the change is reasonable for the Customer. The agreed essential functions, level of protection and suitability for the agreed purpose are preserved. Other detrimental changes to the agreed scope of services require agreement. Section 4 on assessing changes in the GxP context remains unaffected.
(4) Changes under paragraph 3 with more than minor detrimental effects are announced in text form at least six weeks in advance, explaining the reason, effects and necessary cooperation. If immediate implementation is required for mandatory security or legal reasons, the Provider informs the Customer without undue delay and assists with assessing the effects. If the change substantially impairs use in accordance with the contract and no reasonable remedy is available, the Customer may terminate the affected services, or the contract if those services cannot be separated, with effect from the change date; where implementation is immediate, it may terminate promptly upon becoming aware of the change. Prepayments for the period thereafter are refunded pro rata. Statutory rights relating to defects, damages and termination remain unaffected.
(5) Additional service levels, such as an availability percentage or recovery times, apply only if agreed. Agreed support services and response times remain due. Whether maintenance or disruptions are excluded when calculating a service-level metric depends on the specific agreement; statutory performance and defect rights are not excluded as a result.
(6) Where possible, the Provider carries out planned maintenance causing more than insignificant interruptions outside usual business hours (Monday to Friday, 8:00 to 18:00 German time) and announces it in good time. Urgent maintenance, for example to close security vulnerabilities, is permitted at any time; the Provider informs the Customer of it without undue delay.
(7) The Provider provides support to the extent of the plan or Order Form, at least by email to info@gxpdesk.app. The Site plan provides for an email response time of 24 hours on working days; Network includes priority support and a named Validation Manager. Response times refer to the first qualified response, not resolution; different individually agreed provisions remain controlling.
(8) The Provider creates encrypted full backups of Customer Data with every deployment of a new software version on the same production server in Germany; there is no daily backup schedule or off-site copy. These backups serve to restore operations and replace neither archiving nor the Customer's exports under § 6(5).
(9) The Provider may engage third parties; the DPA governs sub-processors and processing locations.
§ 4 Customer's regulatory responsibility (GxP)
(1) GxP-Desk supports computer system validation; responsibility for complying with the GxP requirements applicable to the Customer remains with the Customer. The Customer is in particular responsible for:
- risk-based validation of its use against the applicable requirements, such as EU GMP Guidelines Annex 11 and 21 CFR Part 11, drawing on suitable guidance such as GAMP 5, including assessment of new releases;
- the qualification and, where applicable, audit of the Provider as a supplier;
- the content recorded and its subject-matter review and approval;
- roles, permissions, segregation of duties and the design of approval and signature workflows;
- standard operating procedures (SOPs) and the training of its Users;
- compliance with retention periods, including their configuration in the application and timely exports;
- required notifications to authorities, for example the certification to the US Food and Drug Administration (FDA) under 21 CFR 11.100(c) that its electronic signatures are the legally binding equivalent of handwritten signatures.
(2) The Provider supports the Customer by
- providing documentation and materials supporting validation, for example templates from the Validation Library, to the extent of the plan;
- giving timely information about material changes and their known potential effects on validation and data integrity to enable a risk-based assessment; urgent security and legal changes under § 3(4) remain permissible;
- reasonably cooperating in the Customer's supplier qualifications and audits after agreeing on date and scope; frequency and costs may be governed in the Order Form.
(3) The application supports the Customer's regulatory processes without giving a blanket guarantee that its use is validated or compliant. The Provider remains obliged to supply the agreed functions, their suitability under the contract, and agreed documentation and assistance. The Customer's responsibility for its processes and validation does not exclude the Provider's own obligations, defect liability or liability under § 13. GAMP 5 provides guidance; the applicability of EU GMP Annex 11 and 21 CFR Part 11 depends on the Customer's particular use.
§ 5 AI functions
(1) GxP-Desk offers optional AI-assisted functions (the "AI Functions"). They are only active if an administrator of the Customer connects a supported AI provider using the Customer's own API key (bring your own key). AnythingLLM also permits the connection of a locally operated model. The AI Functions can be deactivated at any time.
(2) The Customer contracts directly with the selected AI provider; that contract governs, in particular, its data use, retention, training and fees. The Provider transmits prompts and relevant document content from the tenant on the Customer's documented instructions. Under these conditions, the AI provider is not the Provider's sub-processor. The Customer is responsible for selection, engagement and the legal basis; the Provider remains bound by its own obligations under the DPA and Art. 28 and Art. 44 et seq. GDPR. An instruction alone does not replace a third-country transfer mechanism.
(3) AI results are suggestions and may be incorrect or incomplete. Before using them, particularly in GxP-relevant documents, the Customer has them reviewed and approved by a person with the appropriate professional responsibility. No general guarantee is given for the substantive accuracy of every AI result. The obligation to supply the AI function in accordance with the contract, defect rights and liability under §§ 12 and 13 remain unaffected.
(4) The Provider does not train AI models with Customer Data. Inputs, context and results are stored in an AI log for traceability.
(5) When using the AI features, Users interact with an AI system; the results are AI-generated. Each party fulfils the transparency obligations applicable to its actual role under Art. 50 of Regulation (EU) 2024/1689. The Provider remains responsible for its applicable obligations, in particular clear information no later than the first direct interaction and, where required, machine-readable marking of synthetic outputs. The Customer fulfils the deployer obligations applicable to its use, for example when publishing certain AI-generated content.
§ 6 Customer's obligations
(1) The Customer keeps access credentials and API keys secret. User accounts are personal and must not be shared. The Customer reports any suspected misuse without undue delay.
(2) The Customer manages its Users, grants permissions on a need-to-have basis, revokes them without undue delay when the authorisation ceases and complies with the limits of its plan. It ensures that its Users comply with these Terms.
(3) The Customer must not upload unlawful content, content infringing third-party rights or malicious software. It indemnifies the Provider against valid third-party claims to the extent arising from unlawful use for which the Customer is responsible, including necessary and reasonable defence costs. Any contributory responsibility of the Provider is taken into account. The Provider gives notice without undue delay, allows the Customer to participate in the defence and does not admit claims or enter into settlements without its consent; consent must not be unreasonably withheld.
(4) Security tests, penetration tests and load tests as well as automated vulnerability scans require the Provider's prior consent in text form; activities in accordance with the coordinated disclosure policy are exempt. Circumventing security mechanisms, attempting to access third-party data and reverse engineering the software are prohibited unless permitted by law (Sections 69d, 69e of the German Copyright Act, UrhG). The API may only be used within the scope of the API documentation and the defined usage limits, in particular rate limits.
(5) The Customer exports Customer Data it needs for archiving and retention purposes at risk-appropriate intervals using the export functions and retains it under its own responsibility; GxP-Desk is not an archive for the period after the end of the contract.
(6) The Customer cooperates appropriately in the provision of the services and reports disruptions with a comprehensible description.
(7) For serious breaches of paragraphs 1, 3 or 4, or a specific and well-founded suspicion of misuse, the Provider may temporarily suspend only the access or functions necessary to avert the danger. Unless immediate action is required, it first gives a warning and an opportunity to remedy the situation. It explains the measure, informs the Customer without undue delay, takes account of access to GxP records and enables secure return or read-only access where possible without perpetuating the danger. The suspension is reviewed regularly and lifted without undue delay once its grounds cease to apply. Further statutory rights remain unaffected.
§ 7 Rights of use and Customer Data
(1) For the term of the contract, the Provider grants the Customer the simple (non-exclusive), non-transferable and non-sublicensable right to use GxP-Desk to the agreed extent for its own business purposes through its Users. Use for affiliated companies (Section 15 of the German Stock Corporation Act, AktG) requires an agreement in the Order Form. All other rights in GxP-Desk remain with the Provider or its licensors.
(2) The Customer may use and adapt supplied templates and Validation Library content for its own business purposes. It may continue to use documents created with them after the contract ends and disclose them to authorised recipients for validation, supplier assessment and evidence to authorities. Standalone distribution or publication of the unmodified templates as such is not permitted.
(3) Customer Data remains with the Customer. The Customer grants the Provider only the rights required to perform the contract, including the handling under § 10. The Provider processes personal data only in accordance with the DPA.
(4) These Terms do not grant the Provider any right to use personal Customer Data for its own product analytics or other purposes of its own. Any anonymisation on behalf of the Customer requires lawful documented instructions; the DPA continues to govern. Analysis of the Provider's own personal operational and security data is governed by the Privacy Policy.
§ 8 Remuneration and payment
(1) The remuneration is set out in the Order Form; all prices are net plus statutory value added tax.
(2) Recurring remuneration is payable in advance for the agreed billing period (monthly or annually). Invoices are payable without deduction by bank transfer within 14 days of receipt. In the event of default, the statutory provisions apply.
(3) If the Customer is in default with at least one month's fees for more than 30 days, the Provider may restrict access proportionately after a specific payment demand and notice in text form allowing at least 14 days to pay. Valid rights to reduce fees, set off or withhold performance are taken into account. Read-only access, data retrieval and statutory switching rights are preserved unless separate security grounds prevent this; if necessary, the Provider supplies the data by another secure means. It lifts the restriction without undue delay once the arrears are paid. Fees and statutory countervailing rights continue to be governed by the contract and the law.
(4) Unilateral price increases during the current term are excluded. For a renewal, the Provider may propose new fees in text form at least three months before the current term ends; they apply only if expressly agreed. Without agreement, the existing fees continue to apply upon renewal. Ordinary termination rights remain unaffected; silence does not constitute acceptance.
§ 9 Term and termination
(1) Term and notice periods are governed by the Order Form. Absent such a provision, the term is twelve months from the start of the services and renews for a further twelve months each time unless terminated with two months' notice to the end of the term.
(2) Either party may end the trial access at any time without notice; § 2(3) applies accordingly.
(3) The right to terminate for good cause under the statutory requirements remains unaffected. Payment default or serious security breaches may constitute good cause; any required warning or opportunity to remedy must be provided. Section 12(5) governs termination for defects.
(4) Notices of termination require text form. The rights under § 10 remain unaffected.
§ 10 Switching and data portability
(1) Chapter VI of Regulation (EU) 2023/2854 (Data Act) and the following provisions also apply to the free trial. The Provider removes unlawful contractual, technical and organisational obstacles to switching. An Enterprise plan does not by itself qualify for an exception under Art. 31 Data Act; any genuinely applicable exception requires pre-contractual information and leaves the other obligations unaffected.
(2) The Customer may request initiation of switching at any time in text form to info@gxpdesk.app. The maximum notice period is two months from receipt, regardless of a fixed contract term; any shorter agreed period prevails. No later than expiry, the Customer may decide to switch to another service of the same service type, transfer data to its own IT infrastructure or have its exportable data and digital assets deleted, including compatible combinations of these measures. Details of the destination provider need only be supplied when required for the particular switch.
(3) The Provider then carries out the switch without undue delay and at the latest within a transitional period of 30 calendar days. During this period, the contract continues to apply and the Provider
- provides reasonable assistance to the Customer and third parties authorised by it in the switching process;
- acts with due care to maintain business continuity and continues to provide the contractual services;
- provides clear information on known risks to the continuity of the services;
- ensures a high level of security, in particular during the data transfer and the data retrieval period.
(4) If the transitional period is technically unfeasible, the Provider gives specifically substantiated notice within 14 working days of receiving the switching request and states an alternative transitional period of no more than seven months; where applicable it ensures service continuity throughout. Independently, the Customer may extend the transitional period once by a period appropriate for its purposes. Commercial reasons alone do not permit an extension by the Provider.
(5) The parties and authorised third parties cooperate in good faith. The Provider supports the exit strategy with all relevant information. They coordinate data scope, destination, permissions and secure transfer; the Customer checks delivered data and reports apparent omissions. Cooperation and coordination must not unreasonably extend statutory periods or create additional switching charges.
(6) Exportable data includes all input and output data, including metadata, directly or indirectly generated or co-generated through use, and transferable digital assets that the Customer has a right to use independently of the existing contractual relationship. Within the agreed functionality, this exhaustively includes the following categories:
- all data entered, uploaded or generated through use by the Customer and its Users, such as system inventory, lifecycle and phase-gate records, change control records, risk and supplier assessments, and periodic reviews;
- documents including all versions, and file attachments;
- audit trail entries;
- electronic signature records;
- training records;
- logs of the AI Functions;
- configuration data, in particular user accounts with roles and permissions, templates and account and tenant settings;
- customer-related communication data, bug reports and other uploaded content;
- metadata relating to such data, such as timestamps, authors, status and links.
The application offers exports in DOCX, PDF and JSON; format and scope depend on the export function. The Provider must supply all exportable data in a structured, commonly used and machine-readable format unless an applicable interoperability specification takes precedence. Absence of coverage by existing functions is not grounds for exclusion. PDF and DOCX alone do not replace a required structured data export; exportable attachments are supplied in their uploaded format.
(7) Exempt, exhaustively, are data relating to the internal functioning of GxP-Desk whose disclosure would jeopardise the Provider's trade secrets or the security of the platform: source code, security and operational logs of the platform (without prejudice to the Customer's audit trail entries), cryptographic keys and authentication secrets such as password hashes, and aggregated operational metrics. These exemptions do not impede or delay the switching process. The exception applies only to genuinely internal or protected data and does not exclude customer-related audit, signature, AI or other exportable data across the board. Necessary non-secret information and suitable alternatives must still be supplied.
(8) After the agreed transitional period ends, the Customer receives a retrieval period of at least 30 calendar days. Where the contract ends without a switching procedure, Customer Data remains available for retrieval for 30 calendar days from termination. Longer agreed or mandatory periods and the choice of deletion under the DPA remain unaffected.
(9) After the retrieval period expires or an agreed later date, and only after successful completion in the case of a switch, the Provider deletes all exportable data and digital assets directly generated by or directly relating to the Customer within five working days (Monday to Friday, excluding public holidays at the Provider's registered office). For remaining backup copies, the parties agree a later deletion date no more than 90 days after deletion from active systems; until then they are restricted to recovery purposes, and deletion is reapplied after restoration. A valid earlier deletion instruction and mandatory erasure obligations remain controlling. Where deletion is chosen under paragraph 2, the five-working-day period starts after the notice period expires; personal Customer Data may be deleted earlier under the DPA. Only the Provider's statutory retention obligations permit exceptions. On request it confirms deletion and any outstanding backup deletion in text form.
(10) In the case of a switch, the contract ends upon successful completion; where deletion is chosen, it ends upon expiry of the maximum notice period. The Provider confirms this to the Customer in text form. Retrieval, security, return and deletion obligations continue thereafter. Prepayments for the period after termination are refunded pro rata.
(11) The Provider charges no switching fees or separate data extraction, assistance or exit fees for switching. This already applies before the statutory ban on switching charges from 12 January 2027. Regular agreed fees for services actually provided until termination remain payable; no additional compensation or penalty is charged under these Terms solely because of an early Data Act switch.
(12) The known transfer methods are the DOCX, PDF and JSON export functions and the REST API described in the API documentation. The Provider supplies, free of charge, the open interfaces and sufficient information required for switching under Art. 30(2) Data Act. Exported data is not an executable replacement for the application; workflows and application-internal integrity checks do not automatically continue in the destination system. The Provider explains further known technical restrictions before conclusion and during the particular switch. It must ensure the compatibility required by Art. 30 with applicable common specifications or harmonised standards after the statutory implementation period expires. Complete functional equivalence of another SaaS application is not promised; Art. 30(6) remains unaffected.
(13) The Provider undertakes to supply the Customer with an up-to-date publicly accessible online register under Art. 26(b) Data Act before conclusion and throughout use, and to communicate its specific link. For every category in paragraph 6 it must contain actual data structures, fields, relationships, formats, relevant standards and open interoperability specifications, and transfer methods and restrictions. General documentation or the API documentation replaces this register only if that information is actually complete and current there.
(14) Information on international processing is available in these publicly accessible Terms, the DPA, in particular § 11 and Annex 2, and the Privacy Policy, in particular sections 14 and 15. The application, including backups, is hosted by Hetzner in Germany. The third-country cases described there apply to GitHub summaries and AI recipients selected by the Customer. The Provider undertakes to keep current public documentation of the jurisdictions applicable to the particular infrastructure and safeguards against international government access contrary to EU law under Art. 28 and 32 Data Act. For access requests, it assesses jurisdiction and the legal basis, uses available legal remedies, limits disclosure to what is legally required and informs the Customer where legally permitted. Transport encryption, access restrictions, tenant separation and encrypted backups do not replace this legal assessment.
§ 11 Data protection and confidentiality
(1) The DPA governs processing of personal data on behalf of the Customer, provided it is incorporated when the contract, including the trial agreement, is concluded. In matters of processing on behalf of the Customer, it takes precedence over other standard contractual terms; individually agreed provisions and mandatory statutory rights remain controlling. The Privacy Policy covers processing whose purposes and means the Provider determines itself; classification depends on the purpose of the particular processing.
(2) The parties treat confidential information of the other party confidentially, use it only to perform the contract and disclose it only to employees, advisers and subcontractors who need it for this purpose and are bound to confidentiality. Confidential information includes Customer Data and information marked as confidential or recognisably confidential, in particular trade secrets.
(3) Exempt is information that is publicly known without breach of contract, was already known, was lawfully obtained from third parties or was independently developed, as well as disclosures required by law or by authorities. The Customer may disclose information from its supplier qualification of the Provider to supervisory authorities to the extent required during inspections.
(4) The confidentiality obligation continues for other confidential information until three years after the contract ends, for Customer Data for as long as it is processed, and for trade secrets for as long as they are legally protected as such. Statutory confidentiality and data protection obligations remain unaffected.
§ 12 Rights in case of defects
(1) The provisions of German tenancy law (Sections 535 et seq. BGB) apply accordingly to defects in the SaaS services unless otherwise provided below.
(2) Only strict liability for damages arising from defects present when the contract is concluded under Section 536a(1), first alternative, BGB is excluded, to the extent permitted by law. The cases of unlimited liability under § 13(1), in particular injury to life, body or health, fraudulent concealment and guarantees, remain unaffected, as do rectification of defects, fee reduction and other statutory claims.
(3) The Customer notifies defects without undue delay in text form with a comprehensible description. The Provider remedies them within a reasonable period and may provide a reasonable workaround in the meantime.
(4) The right to reduce the remuneration (Minderung, Section 536 BGB) remains unaffected.
(5) Termination for defects is governed by statutory requirements, in particular Section 543 BGB. A reasonable period to remedy must first be allowed where required; statutory exceptions, for example definitive refusal or unreasonableness, remain unaffected.
(6) The free trial is for evaluation and includes no assurance of suitability for production GxP records. Claims relating to defects are governed by the applicable statutory rules for use provided free of charge; liability under § 13 and data protection, return and deletion obligations remain unaffected.
§ 13 Liability
(1) The Provider is liable without limitation for intent and gross negligence, for injury to life, body or health, to the extent of a guarantee given, for fraudulent conduct (Arglist), under the German Product Liability Act (Produkthaftungsgesetz) and where otherwise mandatory by law.
(2) Otherwise, in the event of slight negligence, the Provider is only liable for breaches of material contractual obligations (Kardinalpflichten), i.e. obligations whose fulfilment makes the proper performance of the contract possible in the first place and on whose observance the Customer may regularly rely, such as the provision of GxP-Desk and the protection of Customer Data. Liability is then limited to the damage foreseeable at the time the contract was concluded and typical for this type of contract.
(3) Liability for data loss is governed by paragraphs 1 and 2. A culpable failure by the Customer to take reasonable, agreed backup measures may be considered contributory negligence under Section 254 BGB. The Provider's own backup, protection and recovery obligations remain unaffected; the absence of a Customer export does not automatically limit damages to hypothetical recovery costs.
(4) Paragraphs 1 to 3 also apply to the free trial; its purpose as an evaluation provided free of charge is taken into account when determining foreseeable loss typical of the contract. Mandatory claims under the GDPR remain unaffected.
(5) Paragraphs 1 to 4 also apply to the Provider's liability for its corporate bodies and vicarious agents (Erfüllungsgehilfen) and to their personal liability.
(6) These provisions do not change the burden of proof to the Customer's detriment.
§ 14 Force majeure
(1) Neither party is liable for impediments caused by exceptional external events that it could not prevent or overcome even with the care required by the contract and law. These may include natural disasters, war or widespread public network outages. Cyberattacks or a service provider's failure do not constitute force majeure merely by that designation; preventability and compliance with the party's own precautionary obligations are decisive.
(2) The affected party informs the other party without undue delay and limits the effects as far as possible. The affected performance obligations are suspended for the duration of the impediment plus a reasonable start-up period; the Customer owes no remuneration for services not provided.
(3) If the impediment lasts longer than three months, either party may terminate the contract in text form.
§ 15 Amendments to these Terms
(1) Changes to these Terms for existing contracts require agreement between the parties. The Provider may propose necessary adjustments for a changed legal situation or other objective reasons in text form and explains their content and grounds. Changes in the law apply to the extent of their mandatory effect independently of an amendment to the contract.
(2) A proposed amendment includes the proposed text and intended effective date. It is accepted only by the Customer's express consent; silence and merely continuing to use the service do not constitute acceptance. The provisions on permissible service changes (§ 3), fees (§ 8) and amendments to the DPA remain unaffected.
(3) Without agreement, the contract continues on the existing terms. Rejection of a proposed amendment does not create any additional right for the Provider to terminate or suspend services. Existing ordinary termination rights and the statutory right to terminate for good cause remain in force.
§ 16 Final provisions
(1) The laws of the Federal Republic of Germany apply, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
(2) To the extent permitted by Section 38 ZPO and the applicable EU jurisdiction rules, the parties agree that the courts at the Provider's registered office have exclusive jurisdiction for merchants (Kaufleute), legal entities under public law and special funds under public law. Statutory jurisdiction rules apply to other business customers. Mandatory exclusive jurisdiction and overriding international rules remain unaffected.
(3) Declarations relating to the contract require text form unless a stricter form is required by law; the precedence of individual agreements (Section 305b BGB) remains unaffected.
(4) The Customer may only set off claims that are undisputed or have been finally established by a court and may only exercise a right of retention on the basis of such claims; counterclaims arising from the same contractual relationship and mandatory statutory countervailing rights are exempt from this restriction.
(5) The Customer may only transfer rights under the contract with the Provider's consent in text form; the Provider does not unreasonably withhold its consent. Section 354a of the German Commercial Code (HGB) remains unaffected.
(6) Should individual provisions be invalid, the remainder of the contract remains valid; the invalid provisions are replaced by the statutory provisions (Section 306 BGB).