General Terms and Conditions of hsp GmbH
Terms and Conditions of Delivery, Service, Payment and Licence for the Supply of Software Programmes
1.1 The subject matter of the following terms and conditions is the provision of software programmes for a fee or the opportunity to use software via the Internet, as well as the granting of rights of use to the software in accordance with the service/product description, as well as the provision of services by hsp in connection with the supply of the software – such as installation, implementation and training – which must be commissioned separately in each case. The customer is aware of the functional features and system requirements of the software. The customer has verified that these specifications comply with their wishes and requirements. Any deviations from these terms and conditions shall only be valid if hsp confirms them in writing.
1.2 These terms and conditions are solely binding, notwithstanding any terms and conditions of the customer that conflict with or deviate from them; hsp does not recognise such terms and conditions. These terms and conditions shall apply even if hsp performs the contract without reservation whilst being aware of terms and conditions of the customer that conflict with or deviate from them.
1.3 These terms and conditions shall also apply to all future transactions of a similar nature between hsp and the customer arising from the ongoing business relationship.
1.4 These terms and conditions apply only to businesses. We do not enter into contracts with consumers.
1.5 „Consumer“, for the purposes of these terms and conditions, means any natural person who enters into a legal transaction for purposes which are predominantly neither commercial nor related to their self-employed professional activity.
„Entrepreneur“ means a natural or legal person, or a partnership with legal capacity, which, when entering into a legal transaction, acts in the course of its commercial or self-employed professional activities, whereby a partnership with legal capacity is a partnership that has the capacity to acquire rights and incur liabilities.
2.1 Offers made by hsp are always subject to change, unless hsp has expressly stated otherwise in writing. A contract is only concluded if hsp confirms an order in writing or carries out the order. hsp shall supply the licensed software in a ready-to-use, executable form (object code) on electronic data carriers. Installation, implementation or training by hsp shall only take place if a separate agreement has been made.
2.2 The following rules apply to orders placed via one of our online shops:
The customer makes a binding offer to enter into a contract by successfully completing the ordering process set out on the website. The order is placed in the following steps:
a) Select the desired product by clicking on the „Add to basket“ button.
b) Entering the required details (e.g. billing details, payment method) after clicking the „Proceed to checkout“ button.
c) By clicking on the „Buy now“ button, you are submitting a binding offer to purchase the products and services in your shopping basket.
d) You can view and amend the details at any time before submitting your order. The application can only be submitted and sent once you have accepted these Terms and Conditions by ticking the checkbox and thereby included them in your application.
e) Once the order has been completed, we will send you an automatic confirmation of receipt by email, which sets out your order once again and which you can print using the „Print“ function. The automatic confirmation of receipt merely confirms that we have received your order and does not constitute acceptance of your order.
f) The contract is only concluded once we have issued a declaration of acceptance, which will be sent in a separate email (order confirmation). In this email or in a separate email, but no later than when you start using the products or services, the text of the contract (consisting of the order, the General Terms and Conditions and the order confirmation) on a durable medium (email or paper printout) (contract confirmation).
g) The order will be processed and any statements and documents relating to the conclusion of the contract (e.g. the invoice) will be sent by email. You must therefore ensure that the email address you have provided to us is correct, that receipt of emails is technically guaranteed and, in particular, that it is not blocked by spam filters.
h) We do not store the text of the contract once it has been concluded. However, you have the option of creating a customer account and using it to access your order history. You can access your order history for as long as you hold an account with us. When you delete your account, your order history will also be deleted.
(i) German is the sole language in which the contract may be drawn up.
2.3 hsp supplies the licensed software in a ready-to-use, executable form (object code) as a download or on electronic data carriers. Installation, implementation or training by hsp shall only take place if a separate agreement has been made. Where software is used via the Internet by means of other software or a browser, the software is not physically supplied; instead, access details are provided to enable the customer to use the software.
2.4 hsp shall provide the customer with the following documentation as part of the grant of rights of use in respect of the licensed software:
– User manuals available for download or on electronic media
– Installation documentation
The rights of use in respect of the documentation are determined by the rights of use for the licensed product.
2.5 There is no entitlement to the disclosure of the source code.
2.6 Any subsequent changes to the agreed scope of services require a written agreement. Notwithstanding this, hsp is entitled to make subsequent changes which it deems necessary or appropriate, even without prior agreement with the customer, provided that the change has only a minor impact on the customer’s operations and does not entail an increase in the contractual remuneration. hsp shall inform the customer of any such changes.
3.1 Depending on the terms of the agreement entered into, hsp grants the customer a non-exclusive and non-transferable right to use the licensed software via the internet, either using software or via a web browser, or on the devices specified in the contractual documents, for the purposes set out in the contract. hsp grants the customer a non-exclusive and non-transferable right to use the licensed software on the devices specified in the contractual documents for the purposes set out in the contract.
3.2 The licensed software may only be used on a device other than that specified if that device is equivalent to the one described in terms of its suitability for running the licensed software and hsp has expressly given its consent.
3.3 The customer is prohibited from decompiling, reverse engineering or otherwise modifying or altering the licensed software or any part thereof.
3.4 The customer shall use and store the licensed software and programme documentation in such a way as to safeguard them against any use or disclosure not in accordance with the contract. Copies of the licensed software may only be made to the extent necessary to ensure the future use of the software, for the customer’s own use, specifically for backup and archiving purposes only.
3.5 Where hsp supplies the customer with software which hsp has obtained from third parties, the relevant licence terms of the third party, which hsp shall provide to the customer, shall apply in this regard, unless the parties have agreed otherwise in a specific case.
3.6 The granting of rights of use is subject to a condition precedent and shall only take effect upon full payment of the remuneration due for the contractual supply and/or service. hsp may provisionally permit the customer to use the licensed software prior to this point in time; however, this does not constitute a transfer of the rights of use.
4.1 The delivery of licensed software shall be at the customer’s risk and expense. hsp is entitled to make partial deliveries, provided that there is no discernible legitimate interest on the part of the customer that would preclude such deliveries. The risk in respect of the licensed software shall, as a general rule, pass to the customer when the software leaves hsp’s premises, but at the latest upon delivery.
4.2 Unless otherwise expressly agreed, the delivery times quoted are always non-binding.
4.3 If, following a delay, the customer sets hsp a reasonable period of time, the customer shall be entitled to withdraw from the contract once this period has expired without result. Claims for damages arising from failure to meet delivery deadlines or dates, or from non-performance, are excluded, unless the delay is due to wilful misconduct, gross negligence or a negligent breach of a material obligation. In such cases, liability shall be limited to damages directly caused by the delay. Furthermore, liability in such cases shall be limited to foreseeable damages typical for this type of contract, unless hsp can be accused of wilful misconduct.
4.4 Events of force majeure and delays in delivery due to other unforeseen circumstances for which hsp is not responsible shall not constitute a default. Agreed delivery periods shall be automatically extended by the duration of the hindrance and a reasonable start-up period. If the hindrance lasts for more than three months, both parties shall be entitled, following the expiry of a reasonable grace period, to withdraw from the contract in respect of the part not yet fulfilled. Claims for damages are excluded in such cases.
4.5 If the customer is in default of acceptance or breaches their contractual obligations to cooperate, hsp may claim compensation for any resulting losses, including any additional costs incurred. In such cases, the risk of accidental loss or accidental deterioration of the licensed software, or parts thereof, shall also pass to the customer at the time they fall into default of acceptance.
5.1 hsp possesses specialist expertise relating to its own software products and shares this through training courses. hsp offers both open-enrolment training courses in Hamburg and on-site training at the customer’s premises.
5.2 hsp shall appoint trainers who are suitably qualified in terms of both subject matter and teaching methodology for the relevant training course. A change of trainer or a postponement of the training programme shall not entitle the customer to withdraw from the contract or to a reduction in the fee due, provided that the change or postponement does not materially affect the content of the training.
5.3 hsp does not guarantee the success of the training. This depends, in particular, on the participants’ prior knowledge and their individual commitment. Training services are governed by the law on contracts for services in accordance with Sections 611 et seq. of the German Civil Code (BGB), unless otherwise specified in these General Terms and Conditions.
6.1 Open training courses
Training courses at hsp take place at the venue specified by hsp in its training programme. hsp reserves the right to change the training venue at short notice, provided that this is reasonable for the participants.
6.2 On-site training courses
Subject to a specific agreement with the customer, training courses may be held on the customer’s premises. The customer shall provide suitable premises for this purpose free of charge.
7.1 Open training courses
The training fees set out in hsp’s current price list apply. The training fees are per participant, plus VAT at the statutory rate. The training fees include training materials, refreshments during coffee breaks and a certificate of attendance. Any other costs incurred by participants in connection with a training course (in particular travel expenses, other catering costs and accommodation costs) are to be borne by the participants themselves.
7.2 On-site training courses
On-site training courses are conducted exclusively for the relevant customer at their premises. Course fees are agreed on a case-by-case basis. In the absence of a specific agreement, the current price list for training courses applies.
7.3 Travel, accommodation and subsistence expenses incurred by the speaker(s) shall be settled separately on the basis of actual costs, subject to the provision of relevant supporting documents.
7.4 No reduction for partial attendance: Partial attendance at an open training course or an on-site training course does not entitle the participant to a reduction in the course fee.
7.5 Seminar fees and any pro-rata charges for rebooking or cancellation in accordance with clauses 4.2 and 4.3 are payable in full, without deduction, within 7 days of the invoice date. In the event of a rebooking or cancellation, any fees paid in excess will be refunded immediately.
8.1 If the training takes place at hsp, the necessary hardware, software and other equipment will be provided.
8.2 If the training takes place at the customer’s premises, the customer shall provide the necessary software and hardware, as well as any other required equipment, free of charge. The training shall cover the latest software versions for which the customer holds a licence. The customer shall ensure that all participants have this software version installed on their computers for the duration of the training. If necessary, hsp shall provide the participants with a suitable licence for the duration of the training.
8.3 Should any technical problems arise during the training session with regard to hardware or software components of the customer’s IT system, the customer shall provide technical assistance at their own expense. During the training, the customer shall ensure the availability of at least one member of staff who is familiar with the company’s IT system and who can provide expert advice on request.
8.4 Where prior knowledge is required for an open-enrolment course or on-site training, this will be indicated in the course description. Each participant or client shall ensure that they or their staff possess the necessary prior knowledge.
9.1 Open training courses
The contract is concluded on the basis of the training offer upon the customer’s valid registration and confirmation of this registration by hsp. These General Terms and Conditions, together with the training terms and conditions, form an integral part of the training offer. Registrations are processed in the order in which they are received. The registration deadline is one week before the start of the training course.
9.2 On-site training
The contract is concluded upon the customer’s acceptance of hsp’s training offer. These General Terms and Conditions and the training guidelines form an integral part of the offer.
10.1 Open training courses
Rescheduling to an alternative date is free of charge, provided it is done at least 10 working days before the seminar begins. Once the course fee has been paid, the participant will receive a voucher entitling them to attend the course on an alternative date. The alternative date must be taken within 12 months of the originally booked training course.
If a rebooking is made less than 10 working days before the seminar begins, 50 per cent of the seminar fees will be charged. This amount will not be credited towards a training course held at a later date.
10.2 On-site training courses
An on-site training course may be rescheduled at any time. However, the customer shall bear any verifiable costs incurred by hsp as a result of the rescheduling (in particular, cancellation fees for travel and accommodation).
11.1 Open training courses
If a participant is unable to attend, they may provide a substitute to take part in the training at no extra cost. This does not affect the participants’ contractual obligations.
11.2 In the event of cancellation – without the provision of a replacement participant – up to 10 working days before the seminar begins, hsp will charge a cancellation fee of 50 % of the seminar fees. If the cancellation is made – without a replacement being provided – less than 10 working days before the seminar begins, the full seminar fee will be charged.
11.3 On-site training courses
An in-person training course may be cancelled at any time. However, the customer shall bear any demonstrable costs incurred by hsp as a result of the cancellation (in particular cancellation fees for travel and accommodation).
11.4 Cancellation by hsp
hsp reserves the right to cancel a training course if, due to circumstances beyond hsp’s control, it cannot be held as agreed, in particular if one or more speakers are unable to attend through no fault of their own. The same applies if the minimum number of participants has not been reached by the registration deadline. The client or the participants will be informed of this without delay. Any seminar fees paid will be refunded. hsp shall not bear any costs incurred by participants as a result of the cancellation (e.g. cancellation fees for travel and accommodation), provided that hsp is not responsible for the cancellation.
12.2 If material defects arise during the warranty period of one year from the date on which the licensed software is made available to the customer, the customer must notify hsp of such defects in writing and without delay, provided that the customer wishes to make a warranty claim. Notwithstanding the above provision, the statutory warranty periods shall apply if these are set by law at a duration of more than two years. The limitation periods set out in this clause 12.2 shall also apply to consequential damage resulting from defects, insofar as such damage is to be compensated in accordance with the provisions set out below.
12.3 A material defect exists if, when used in accordance with the contract, the licensed software fails to deliver the services set out in the specification or product sheet, and this has more than a negligible effect on the suitability of the licensed software for use in accordance with the contract.
12.4 Claims for defects by commercial customers are subject to the condition that they inspect the licensed software immediately upon receipt by installing it and testing its functionality. Any defects discovered in the course of this must be reported to hsp in writing without delay, specifying the nature of the defect (Section 377 of the German Commercial Code (HGB)). Non-commercial customers must also install and test the licensed software immediately upon receipt, and must notify hsp in writing of any obvious defects within two weeks of their discovery, specifying the nature of the defect. If installation by hsp has been agreed, the Customer’s obligations set out above shall commence upon completion of the installation.
12.5 Where a material defect already exists at the time of the passing of risk, hsp shall remedy it at its own expense or supply replacement software. Instead of remedying the defect or supplying a replacement, hsp may offer the use of a newer version of the programme. The customer is obliged to accept the newer version of the programme if this is necessary to prevent other programmes from failing or serves to prevent and remedy defects, and provided that this does not incur any additional costs for the customer. The costs necessary for subsequent performance, in particular any transport and postage costs, shall be borne by hsp.
12.6 Before the customer may assert any further rights, such as withdrawal, a reduction in price, or compensation for damages or expenses, hsp must first be given the opportunity to carry out the subsequent performance described above. If two repeated attempts by hsp to remedy the defect are unsuccessful and hsp is unable to provide replacement software, the customer may withdraw from the contract or demand a reduction in the licence fee, provided that the nature of the software or the defect, or the circumstances, do not necessitate further attempts at rectification.
In the event of withdrawal, any benefits granted by either party must be returned, with the exception of services already provided by hsp.
12.7 Where hsp provides the customer with software or other IT components on a temporary basis, liability without fault for defects that were already present at the time the contract was concluded is excluded.
12.8 The warranty shall not apply if hsp’s operating or maintenance instructions are not followed, if the licensed software has been modified or supplemented, or if the defect was caused by improper use of the licensed software, unless the defect relates to the unmodified licence programme and it can be proven that it would have occurred even without any action on the part of the customer. If the analysis of the defect is made significantly more difficult by the circumstances mentioned, the customer shall reimburse hsp for any additional costs incurred as a result.
12.9 Any further claims, in particular claims for compensation for damage to the licensed programme or for damage not arising from the subject-matter of the contract itself – in particular for the loss of, or incorrect processing of, data, turnover or profit – are excluded, unless hsp is liable on the grounds of wilful misconduct or gross negligence. hsp shall also be liable for direct damage resulting from a defect in the event of a negligent breach of essential contractual obligations; however, this shall not apply to consequential damage resulting from such defects.
In cases of simple negligence, liability is limited to foreseeable damage typical of the contract.
The above limitations of liability shall not apply in the event of damage resulting from loss of life, bodily injury or damage to health, nor to claims under Sections 1 and 4 of the Product Liability Act.
12.10 Furthermore, hsp shall only be liable for wilful misconduct and gross negligence, as well as for the negligent breach of material contractual obligations. In the event of simple negligence, hsp’s liability shall always be limited, in terms of total amount, to the foreseeable damage typical for the contract. The above limitations of liability do not apply to damage resulting from injury to life, limb or health, nor to claims arising under Sections 1 and 4 of the Product Liability Act.
The limitation period for claims for damages against hsp is subject to the time limits set out in clause 12.2, unless the claims arise under the Product Liability Act.
12.11 hsp shall not be liable for the loss of data and/or programmes to the extent that the damage is attributable to the customer’s failure to carry out data backups and thereby ensure that lost data can be restored at a reasonable cost. hsp’s liability for data loss is limited to the cost of restoration that would have been incurred had such proper data backups been carried out.
12.12 The provisions of this clause 12 shall also apply for the benefit of hsp’s legal representatives, employees and vicarious agents.
13.2 Should a third party assert copyright or other neighbouring rights in respect of the licensed software, the customer shall notify hsp thereof without delay. In the event of an infringement of third-party intellectual property rights for which hsp is responsible, hsp may, at its discretion, either obtain from the third party a licence sufficient for the contractual use and grant this to the customer, or amend the service in question so that third-party intellectual property rights are not infringed, or replace the service, provided that this does not materially impair the Customer’s contractual use. If this is not possible or not reasonable for hsp, the Customer may assert their statutory rights. Clauses 12.2 (Limitation period) and 12.9 (Liability for defects) shall apply mutatis mutandis to legal defects. Clause 12.10 shall also apply to claims for damages arising from infringements of intellectual property rights.
14.1 The term of the contract is as set out in the relevant agreement. Where a contract has a minimum term (e.g. one year, two years), it shall be extended for a further year in each instance unless it is terminated by either party, subject to three months’ notice, at the end of the relevant contract term.
14.2 This shall not affect the right of either party to terminate the contract for good cause. Good cause entitling hsp to terminate the contract with immediate effect shall exist, in particular, if:
(a) the client becomes insolvent,
(b) the client fails to remedy, within the specified time limit, a breach of any material obligations under this contract – in particular, but not limited to, the obligation to pay the care fee – despite a written warning from hsp setting a reasonable time limit,
(c) where there are significant changes in the client’s ownership or management structure, unless there is no reason to fear that this will adversely affect hsp’s interests; in any event, the client must inform hsp of such changes without delay.
14.3 Any notice of termination must be in writing to be valid.
15.1 The remuneration for the licensed software and the services to be provided by hsp shall be determined in accordance with the contractual agreement. The sole determining factor is the price stated on the order confirmation, plus postage and handling charges and the statutory value-added tax applicable at the time of delivery. With regard to deliveries and services provided under a contract designed for long-term supply or service provision – for example, under a distribution agreement – hsp is entitled to amend prices at its reasonable discretion and shall notify the customer of any such price changes in good time before they take effect.
15.2 Unless otherwise agreed, all invoices are due for payment within 10 days of the invoice date. Upon expiry of the payment period, the customer shall be in default without the need for a reminder. From the date on which the customer is in default, hsp shall be entitled to charge interest on arrears at a rate of 9 percentage points per annum above the applicable base rate. In the event of default, hsp expressly reserves the right to claim further damages.
15.3 The Customer may only set off claims against us if their counter-claims are undisputed, have been established by a final and binding judgement, or have been acknowledged by hsp. The exercise of rights of retention is only permitted if the above conditions are met and the counter-claim arises from the same contractual relationship.
16.1 hsp reserves title to the licensed software and the documentation provided until the licence fee has been paid in full. In the event of the Customer’s breach of contract, in particular in the event of late payment following the setting of a reasonable deadline, hsp shall be entitled to reclaim the licensed software supplied or parts thereof; unless such reclaim is not permitted due to the application for or commencement of insolvency proceedings in respect of the Customer’s assets. Following the repossession of the software, hsp shall be entitled to realise its value; the proceeds of such realisation shall be set off against the customer’s outstanding liabilities, less reasonable costs of realisation. hsp reserves the right to claim damages. The provisions of the Insolvency Code remain unaffected.
16.2 The customer is obliged to treat the delivered items, including the licensed software, with due care and to insure them at their own expense against damage caused by fire, water and theft, at replacement value. Should maintenance work be required, the customer shall carry this out in good time at their own expense.
16.3 In the event of attachment or other interventions by third parties, the customer must inform hsp immediately in writing. The customer shall be liable to hsp for the judicial and extrajudicial costs of any necessary legal action pursuant to Section 771 of the German Code of Civil Procedure (ZPO) (third-party objection proceedings).
If the customer is an end user of the licensed software, they are not permitted to resell the software subject to retention of title, or any part thereof.
16.4 If the customer is a distribution partner of hsp, they are entitled to resell the licensed software or parts thereof in the ordinary course of business. However, the customer hereby assigns to hsp all claims amounting to the final invoice amount which it receives from the resale of the licensed software to third parties. This applies regardless of whether or not the customer bundles the licensed software with their own products under an OEM licence. hsp accepts the assignment. The customer remains entitled to collect their claims against third parties. However, hsp is itself entitled to collect these claims if the customer no longer meets its payment obligations from the proceeds received, falls into arrears, suspends payments, or an application for insolvency is filed in respect of the customer’s assets. In such cases, hsp may require the customer to identify the assigned claims and their debtors to hsp, to provide all information necessary for the collection of the claims and to hand over the relevant documents, and to inform the third parties of the assignment. hsp shall not be precluded from collecting the claims only if this is prohibited by the Insolvency Code.
17.1 The place of performance is hsp’s registered office.
17.2 These terms and conditions, as well as the contract between the parties, are governed exclusively by German law. The application of the UN Convention on Contracts for the International Sale of Goods is expressly excluded. The exclusive place of jurisdiction for all legal disputes arising from the contractual relationship, including claims relating to cheques and bills of exchange, shall be Hamburg, provided that the customer is a trader, a legal person under public law or a special fund under public law.
17.3 There are no verbal side agreements relating to the contract. Any amendments and/or additions to the contract must be made in writing to be valid. This also applies to the waiver of the requirement for the written form.
17.4 Should any provision of the contract or these terms and conditions be or become invalid, this shall not affect the validity of the remaining provisions.
The parties agree that, in such a case, the invalid provisions shall be replaced by valid provisions which most closely reflect the economic purpose of the invalid provisions.
The General Terms and Conditions of hsp Handels-Software-Partner GmbH:
Data Processing Agreement pursuant to Article 28 of the GDPR
between the hsp Handels-Software-Partner GmbH, Notkestraße 9, 22607 Hamburg, hereinafter referred to as the Contractor, and the Customers, who has entered into a contract with the Contractor regarding the online shop (see clause 2.2. f of the General Terms and Conditions), hereinafter referred to as the Client.
The subject matter of this contract is set out in the contract concluded between the parties via the online shop concerning the use of the licensed software (hereinafter referred to as the ‘Software’), to which reference is made here (hereinafter the ‘Service Agreement’).
1.2. Duration
The duration of this contract (term) corresponds to the term of the service agreement.
1.3. Without prejudice to the preceding paragraph, the contract shall remain in force for as long as the contractor processes the client’s personal data
processed (including backups).
1.4. Where other agreements between the Client and the Contractor contain different provisions regarding the protection of personal data, this contract for data processing shall take precedence, unless the parties expressly agree otherwise.
2.1. The nature and purpose of the processing of personal data by the Contractor on behalf of the Client are set out in detail in the Service Agreement. In principle, the Contractor has no access to the data which it processes on its IT system using the software. The data is stored in an SQL database on the Client’s server. However, if the Client transmits data via the software’s interface (e.g. by inviting a client), the data is transmitted in encrypted form, so that, in principle, neither the Contractor nor any third party is able to access it. However, if, for example, the Client submits a support request to the Contractor, the Contractor may become aware of certain data whilst handling the support request (e.g. first name, surname, email addresses of customers and employees, usage data, etc.).
2.2. Type of data
The processing of personal data therefore concerns the following types/categories of data
• Personal master data
• Contact details (e.g. telephone, email)
• All personal data entered into the software by the client
2.3. Categories of data subjects
The categories of data subjects affected by the processing include:
• Clients
• Employees of the client
3.2. Should the client’s review or audit reveal a need for adjustment, this shall be implemented by mutual agreement.
3.3. The agreed technical and organisational measures are subject to technical progress and further development. In this respect, the Contractor shall be permitted in future to implement alternative, equivalent measures. In doing so, the level of security provided by the specified measures must not be compromised. The Client must be notified immediately of any significant changes, which must be documented by the Contractor.
4.1. The Contractor shall assist the Client, within its area of responsibility and as far as possible by means of appropriate technical and organisational measures, in responding to and implementing requests from data subjects regarding their data protection rights. The Contractor must not, on its own initiative, disclose, transfer, rectify, erase or restrict the processing of the data processed on behalf of the Client, but may only do so in accordance with documented instructions from the Client. Where a data subject contacts the Contractor directly in this regard, the Contractor shall forward this request to the Client without delay.
4.2. Insofar as this is covered by the scope of services, the Contractor shall ensure, in accordance with the Client’s documented instructions, that the rights to access, rectification, restriction of processing, erasure and data portability are upheld directly by the Contractor.
5.1. In addition to complying with the provisions of this contract, the Contractor has its own legal obligations under the GDPR; in this regard, it shall, in particular, ensure compliance with the following requirements:
• Written appointment of a data protection officer in accordance with statutory requirements. The Contractor’s data protection officer is Mr Hendrik Sievers, beck rechtsanwälte, Ericusspitze 4, 20457 Hamburg, telephone: 040 / 3010070, email: datenschutz@hsp-software.de. The Client must be notified immediately of any change in the Data Protection Officer.
• Maintaining confidentiality in accordance with Articles 28(3), second sentence, point (b), 29 and 32(4) of the GDPR. In carrying out the work, the Contractor shall only employ staff who are bound by a duty of confidentiality and who have previously been made aware of the data protection provisions relevant to them. The Contractor and any person under the Contractor’s authority who has legitimate access to personal data may process such data exclusively in accordance with the Client’s instructions, including the powers granted in this contract, unless they are legally obliged to process it.
• The client and the contractor shall, upon request, cooperate with the supervisory authority in the performance of its duties.
• The immediate notification of the client regarding any inspections and measures taken by the supervisory authority, insofar as these relate to this contract. This also applies where a competent authority is conducting an investigation in relation to the processing of personal data by the data processor in the context of administrative or criminal proceedings.
• Insofar as the client is, for its part, subject to an inspection by the supervisory authority, administrative or criminal proceedings, a claim for damages by a data subject or a third party, any other claim or a request for information in connection with the processing of personal data by the data processor, the data processor shall assist the client to the best of its ability.
• The contractor shall regularly review its internal processes and the technical and organisational measures in place to ensure that processing within its area of responsibility is carried out in accordance with the requirements of applicable data protection law and that the rights of data subjects are safeguarded.
• The ability to demonstrate to the client the technical and organisational measures taken, within the scope of the client’s powers of inspection under Clause 8 of this contract.
• The Contractor shall report any breaches of personal data protection to the Client without delay, in such a way that the Client can fulfil its legal obligations, in particular those under Articles 33 and 34 of the GDPR. The Contractor shall draw up documentation covering the entire process, which it shall make available to the Client for further action.
• The contractor shall assist the client within its area of responsibility and, as far as possible, in fulfilling existing obligations to provide information to supervisory authorities and data subjects, and shall make all relevant information available to the client without delay in this regard.
• Where the client is obliged to carry out a data protection impact assessment, the contractor shall assist the client, taking into account the nature of the processing and the information available to the contractor. The same applies to any obligation to consult the competent data protection supervisory authority.
• This contract does not exempt the contractor from complying with other provisions of the GDPR.
6.1. For the purposes of this provision, ‘subcontracting arrangements’ are to be understood as those services which relate directly to the provision of the main service. This does not include ancillary services utilised by the Contractor, e.g. telecommunications services, postal/transport services, cleaning services or security services. Maintenance and testing services constitute a subcontracting relationship if they are provided for IT systems that are used in connection with a service provided by the Contractor under this contract. However, the Contractor is obliged to enter into appropriate and legally compliant contractual agreements and to implement control measures to ensure the data protection and data security of the Client’s data, even in the case of outsourced ancillary services.
6.2. The Contractor may only engage subcontractors (further data processors) with the prior, express written or documented consent of the Client.
Outsourcing to subcontractors or a change in accordance with Appendix 2 Subcontracts with an existing subcontractor are permitted provided that:
• the contractor gives the client advance notice of such outsourcing to a subcontractor, in writing or in text form, within a reasonable period of time, which must not be less than 14 days, and
• the client does not raise any objection to the planned outsourcing in writing or in text form to the contractor by the time the data is handed over, and
• is based on a contractual agreement in accordance with Article 28(2)–(4) of the GDPR.
6.3. The disclosure of the client’s personal data to the sub-contractor and the sub-contractor’s commencement of work shall only be permitted once all the conditions for sub-contracting have been met. Compliance with and implementation of the technical and organisational measures by the sub-contractor shall be monitored by the contractor, taking into account the risk posed by the sub-contractor, prior to the processing of personal data and subsequently on a regular basis. The contractor shall make the results of these checks available to the client on request. The Contractor shall also ensure that the Client can exercise its rights under this Agreement (in particular its rights of supervision) directly against the sub-contractors.
6.4. Any further subcontracting by the subcontractor requires the express consent of the main contractor (at least in writing). All contractual provisions in the chain of contracts must also be imposed on any further subcontractors.
7.1. Any transfer of personal data to a third country or to an international organisation requires a documented instruction from the client and must comply with the requirements for the transfer of personal data to third countries set out in Chapter V of the GDPR.
7.2. The contractually agreed data processing shall take place exclusively in the Federal Republic of Germany.
7.3. Where the client instructs the transfer of data to third parties in a third country, the client is responsible for compliance with Chapter V of the GDPR.
8.1. The Client shall be entitled, in consultation with the Contractor, to carry out inspections or to have them carried out by inspectors to be appointed on a case-by-case basis. The Client shall be entitled to verify, by means of spot checks – which shall generally be given reasonable notice – that the Contractor is complying with this agreement in the course of its business operations during normal business hours.
8.2. The Contractor shall ensure that the Client is satisfied that the Contractor is complying with its obligations under Article 28 of the GDPR
can demonstrate. The contractor undertakes to provide the client with the necessary information upon request and, in particular, to provide evidence of the implementation of the technical and organisational measures.
8.3. Evidence of the technical and organisational measures taken to comply with the specific data protection requirements in general, as well as those relating to the contract, may be provided in the form of up-to-date certificates, reports or extracts from reports issued by independent bodies (e.g. data protection officers).
9.1. The Contractor shall process personal data only on the basis of documented instructions from the Client, unless the Contractor is obliged to do so under the law of a Member State or under Union law. The Client shall confirm any verbal instructions without delay (at least in writing). The Client’s initial instructions are set out in this contract.
9.2. The Contractor must inform the Client without delay if it considers that an instruction contravenes data protection regulations. The Contractor is entitled to suspend the implementation of the instruction in question until it has been confirmed or amended by the Client.
10.1. No copies or duplicates of the data shall be made without the client’s knowledge. This does not apply to backup copies,
insofar as they are necessary to ensure that data is processed correctly, as well as data required to comply with statutory retention obligations.
10.2. Upon completion of the contractually agreed work, or earlier upon request by the Client – and at the latest upon termination of the service agreement – the Contractor shall hand over to the Client all documents that have come into its possession, all processed and utilised results produced, and all data sets relating to the contractual relationship, or, subject to prior consent, destroy them in accordance with data protection regulations. The same applies to test and scrap material. A record of the destruction must be provided on request.
Appendix 1 – technical and organisational measures implemented by hsp Handels-Software-Partner GmbH
- Access control:
Security key with key management;
Reception;
Visitors may only remain on the premises in the presence of staff;
CCTV at the entrances;
Burglar-proof windows (5th floor);
Server room locked; access restricted to IT staff and management (security key);
Outside business hours: surveillance of the stairwell by an external security service (which does not have access to the business premises);
Careful selection of cleaning staff - Access control:
Identification and authentication via username/password;
Password policy:- Password history: the last 24 saved passwords
- Maximum password validity: 90 days
- Minimum password length: 8 characters
- Minimum password age: 1 day
- Complexity: „3 out of 4“ (upper-case letters, lower-case letters, numbers, special characters)
Limiting the number of failed attempts;
System administrator permissions/logging;
Instructions for locking the screen;
Firewall (WatchGuard) and antivirus software - • Access control:
Authorisation model with roles and different authorisation levels;
VPN profiles defined according to user activities for external access to IT systems; administrator rights reduced to the „absolute minimum“;
In-house data carrier destruction with a record of the process;
Paper destruction by a specialist company: careful selection, written contract - Principle of separation:
Several separate virtual test systems for processing data;
Logical client separation (software-based);
Different databases;
Defining database rights;
Separation of production and test systems
- Disclosure control:
Inventory and stock control of data storage media by the person responsible for data processing and the Data Protection Officer;
No data storage media will be passed on to third parties - Input validation:
Monitoring of the SQL database, which logs all changes and access attempts;
Data remains unchanged until it is actively deleted manually
- Availability check:
Risk and vulnerability analysis as part of the annual audit carried out by the Data Protection Officer;
Backup on a redundant system (SAN);
A backup every 24 hours to a self-contained facility (Norderstedt data centre, TÜV-certified);
Training of staff on safety requirements by the DSB;
The server room must not be located beneath sanitary facilities;
Uninterruptible Power Supply (UPS);
Air conditioning in the server room;
External attack: Firewall (WatchGuard) - Rapid recovery:
secured through virtualisation (SAN, backups every 24 hours in the self-contained area)
- Data Protection Management:
Data protection documentation is in place, complete and up to date;
Certificates of competence for the Data Protection Officer (DPO) have been provided;
Compliance with data confidentiality; all staff are bound by data confidentiality;
Regular data protection information sheets for staff;
Data protection training delivered by the Data Protection Officer;
Guidelines on the use of email;
Annual audits by the Data Protection Officer - Incident Response Management:
Any incidents must be reported to the DPO immediately;
Handling of any incidents by the DPO - Order monitoring:
Written contracts relating to data processing are in place and are audited annually by the Data Protection Officer;
Monitoring the contractor’s compliance and/or carrying out checks
Certificate(s) issued by DSB, logging
Appendix 2 – technical and organisational measures implemented by hsp Handels-Software-Partner GmbH
| Company Subcontractor | Address/Country | Performance | Information on appropriate safeguards for data transfers to a third country |
|---|---|---|---|
| InterNetX GmbH | 55 Johanna-Dachs-Str., 93055 Regensburg | Hosting of the Opti.Tax Cloud in a certified data centre. Certificates available here: https://www.internetx.com/data-center/ A separate database is created for each customer. The data is processed in encrypted form, meaning that, in principle, the subcontractor is not intended to have access to it. |
No data is transferred to a third country. |
| WIADOK GmbH & Co. KG | Am Speicher 2, 49090 Osnabrück | With the WIADOK extension, the process of approaching clients and recording orders in hsp Opti.Tax Property Tax can be automated. The add-on is integrated into the firm’s existing website. | No transfer of data to a third country |
The General Terms and Conditions of hsp Handels-Software-Partner GmbH:
Agreement on Compliance with Statutory Confidentiality Obligations
between the hsp Handels-Software-Partner GmbH, Notkestraße 9, 22607 Hamburg, hereinafter referred to as the ‘Contracting Party’, and the Customers, who has entered into a contract with the contracting party regarding the online shop (see clause 2.2. f of the General Terms and Conditions), hereinafter referred to as the ‘customer’.
The contracting party is aware that – insofar as the client is a person bound by professional secrecy under German law, i.e. a tax adviser, auditor or solicitor – special confidentiality obligations apply. Those bound by professional secrecy must comply with mandatory legal requirements when engaging service providers who assist in their professional activities.
Insofar as the contractual partner grants or may grant the customer access to data relating to the customer’s clients and falling within the scope of Section 203 of the German Criminal Code (hereinafter referred to as „client data“), the following shall apply:
1. The contracting party undertakes to treat all client data as confidential for an indefinite period and to protect it from access by third parties.
2. The contracting party undertakes to access client data only to the extent necessary for the purposes of the services to be provided in accordance with the contract.
3. The client draws the contracting party’s attention to the fact that persons who assist a person bound by professional secrecy in the performance of their professional duties may be liable to prosecution under the applicable statutory provisions (e.g. under Section 203(4), first sentence, of the German Criminal Code (StGB)) if they disclose without authorisation a third party’s secret – including client data – which has come to their knowledge in the course of or in connection with their work. Depending on the circumstances of the breach of confidentiality, the criminal consequences may include a custodial sentence or a fine.
4. Where the contracting party engages other persons (e.g. its own employees or subcontractors) who, in accordance with their duties, have access to or are able to gain access to client data in order to fulfil the services owed, it shall oblige them in writing to maintain the confidentiality of such data. Should the contracting party fail to impose such an obligation on the other persons involved, the contracting party shall be liable to prosecution under Section 203(4), second sentence, No. 2 of the German Criminal Code (StGB) (imprisonment or a fine), if the other persons involved disclose, without authorisation, a secret belonging to another party which has come to their knowledge in the course of or in connection with their work.
To make use of
• subcontractors for the purpose of performing the services owed, or
• Services provided outside the Member States of the European Union,
the contracting party requires the customer’s consent in writing.
5. The Customer’s right to terminate the underlying contract for cause remains unaffected. In particular, it shall constitute good cause if, as a result of a security incident or other circumstances, there is more than a trivial doubt as to the reliability of the contracting party, its employees or other agents with regard to compliance with confidentiality obligations (see points 1 to 4 above) as a result of a security incident or other circumstances.
The contracting party undertakes, at any time during the term of the underlying contract, at the customer’s request, to
(a) to provide information by way of a self-assessment and to furnish further information or to name persons capable of providing such information, enabling the client, at its own discretion, to verify the contracting party’s compliance with its contractual obligations and its reliability with regard to the provision of the services owed, in particular compliance with points 1, 2 and 4, and
(b) in the event of any irregularities or doubts, to allow for the technical and organisational measures to be audited, either by the contracting party itself or by engaging an independent third party bound by a duty of confidentiality. Irrespective of this, the contracting party is obliged, in the event of a breach of the obligations set out herein or where there are indications of such a breach, to inform the customer without delay and to cooperate in minimising any loss.
6. The contracting party has been informed that it has a comprehensive right to refuse to give evidence before public authorities pursuant to
§ 53a of the Code of Criminal Procedure (StPO) in relation to client data, and that he is obliged to exercise this right to refuse to give evidence as long as and to the extent that the client does not release him from this obligation.
7. The Contractual Partner has been informed that the client data in the Contractual Partner’s custody is protected from seizure under Section 97(2) of the Code of Criminal Procedure (StPO). The contracting party undertakes not to disclose this client data to third parties without the client’s express consent and, in the event of such data being seized, to object to the seizure and, insofar as permitted by law, to inform the client without delay.
8. The provisions set out herein („Agreement“) shall apply in addition to the contractual arrangements governing the provision of services by the contracting party. This Agreement applies both to the provisions in force at the time of conclusion of a main contract and to any future agreements supplementing those provisions, whether such agreements are made expressly or by way of a dynamic reference. In the event of a conflict between a provision in this Agreement and a provision in the main contract, this Agreement shall take precedence.
The General Terms and Conditions of hsp Handels-Software-Partner GmbH:
Cloud Services Agreement
between the hsp Handels-Software-Partner GmbH, Notkestraße 9, 22607 Hamburg, hereinafter referred to as the ‘provider’, and the Customers, who has entered into a contract with the contracting party in relation to the online shop (see clause 2.2. f of the General Terms and Conditions), hereinafter referred to as the Customer (the Provider and the Customer are each referred to individually as a ‘Party’ and collectively as the ‘Parties’).
2.1. The Provider grants the Customer the right to use the latest version of the software for the agreed number of authorised users via the internet, accessed via a web browser.
2.2. The Provider guarantees that the software will function properly and remain available for the duration of the contractual relationship, and shall maintain it in a condition suitable for use in accordance with the contract. The scope of the software’s functions and the conditions of use are set out in Clause 2 of the General Terms and Conditions.
2.3. Whilst the Customer is using the software, the Provider shall make information and guidance on the use of the software available to the Customer in a suitable electronic format. This may be provided within the software itself, in particular through guided introductions, explanations of individual functions, training or explanatory videos, or similar support services. In addition, the Provider may make supplementary support and e-learning content available via the hsp Community as a platform for exchange and learning, in particular courses, training or explanatory videos, learning videos or similar learning resources.
2.4. The Provider may, without being obliged to do so, update or further develop the software at any time and, in particular, adapt it in response to changes in the legal situation, technical developments or to improve IT security. In doing so, the Provider shall take the Customer’s legitimate interests into account appropriately and inform the Customer in good time of any necessary updates. In the event of a material impairment of the Customer’s legitimate interests, the Customer shall be entitled to a special right of termination.
2.5. The provider is under no obligation to adapt the service to the customer’s individual needs or IT environment.
2.6. The Provider shall carry out regular maintenance on the software and inform the Customer in good time of any restrictions associated with this. Maintenance shall normally be carried out outside the Customer’s usual business hours, unless compelling reasons necessitate that it be carried out at a different time.
2.7. The Provider shall make storage space available to the Customer on its servers for the storage of data and for the purposes of using the software, to an extent appropriate for use in accordance with the contract. The amount of storage space provided may depend on the selected service and billing configuration, as well as the nature and extent of the use of the software. The Provider is entitled to set reasonable limits on the use of the storage space. The Provider shall ensure that the data is accessible within the scope of the use of the software.
2.8. The provider shall take state-of-the-art measures to protect the data. However, the provider shall have no duty of safekeeping or care with regard to the data. The customer is responsible for ensuring that the data is adequately secured.
2.9. The customer remains the owner of the data stored on the provider’s servers and may request its return at any time.
3.1. The software is not physically supplied to the customer.
3.2. The Customer shall be granted, in respect of the latest version of the software and for the number of users specified in the contract, simple rights – i.e. rights that cannot be sub-licensed or transferred and are limited in duration to the term of the contract – to use the software via a browser in accordance with the contractual provisions.
3.3. The number of users specified in the contract refers to specific authorised users in each instance. If an authorised user is deactivated, deleted, anonymised or has their user rights revoked in any other way, that user shall continue to be counted towards the contractually agreed number of users for a period of seven (7) days from the date of revocation of their user rights. Within this period, the user in question may be reactivated. Use by another person in place of this user is only possible once this period has expired. The contractually agreed number of users remains unaffected by this and may only be reduced at the start of the next contract term.
3.4. The customer may only use the software within the scope of its own business activities and by its own staff. Any other use of the software by the customer is not permitted.
4.1. The fee payable by the Customer for the use of the software is determined by the service and billing configuration selected by the Customer at the time of ordering, in particular by the contractually agreed number of users and the selected billing period. Where the Customer activates or uses additional chargeable service components, additional fees shall apply in accordance with the terms and conditions notified separately in each case.
4.2. Price adjustment: The contracting parties agree to adjust the remuneration in line with the cost-of-living index (Consumer Price Index for Germany, monthly, hereinafter „CPI“) as follows. The respective net remuneration shall be adjusted, at the earliest, one year after the commencement of the contract or the last price adjustment, in the same percentage proportion as the change in the Consumer Price Index for Germany (base 2020 = 100) has changed in comparison with the level last published at the start of the contract or the level for the month whose value was used as the basis for the last price adjustment under this provision. The most recent published level of the Consumer Price Index at the time the price adjustment is declared shall be decisive in each case. Any change to the remuneration pursuant to this agreement must be notified in writing, which may be done by sending the relevant invoice.
6.1. The Provider guarantees an overall service availability of at least 99.5 % per month at the handover point. The handover point is the router output of the Provider’s data centre.
6.2. Availability is defined as the Customer’s ability to use all the main functions of the software. Maintenance periods and periods of disruption, provided that the resolution time is observed, are considered periods of software availability. Periods of minor disruptions are not taken into account when calculating availability. The provider’s measuring instruments in the data centre shall be decisive for verifying availability.
6.3. In the event of serious faults (where it is not possible to use the software at all or to use a key function of the software), the Provider shall rectify the fault even outside service hours, at the latest within 2 hours of receiving notification of the fault – provided that the notification is made during service hours (rectification time). If it becomes apparent that the fault cannot be rectified within this timeframe, the Provider shall inform the Customer of this without delay and specify the expected delay beyond the timeframe.
6.4. Other significant faults (where the main or secondary functions of the software are disrupted but can still be used; or other faults that are not merely minor) shall be rectified within 12 hours at the latest during service hours (rectification time).
6.5. The resolution of minor faults is at the provider’s discretion.
6.6. Any other statutory claims the customer may have against the provider remain unaffected.
7.1. The customer must protect and safeguard the login details provided to them from unauthorised access by third parties in accordance with current technical standards. The customer shall ensure that such details are used only to the extent agreed in the contract. The provider must be notified immediately of any unauthorised access.
7.2. The customer must not store any data on the storage space provided whose use would contravene applicable law, official orders, the rights of third parties or agreements with third parties.
7.3. The customer shall scan the data for viruses or other malicious components before storing or using it in the software, and shall use state-of-the-art measures (e.g. antivirus software) for this purpose.
7.4. The customer is responsible for carrying out appropriate data backups on a regular basis.
8.1. With regard to the granting of the right to use the software and the provision of storage space, the warranty provisions of tenancy law (Sections 535 et seq. of the German Civil Code (BGB)) shall apply.
8.2. The customer must notify the provider of any faults without delay.
8.3. The warranty is excluded in respect of only minor impairments to the suitability of the service. Strict liability under Section 536a(1) of the German Civil Code (BGB) for defects that already existed at the time the contract was concluded is excluded.
9.1. The parties shall be liable without limitation in cases of wilful misconduct, gross negligence and culpable injury to life, limb or health.
9.2. Without prejudice to the cases of unlimited liability set out in clause 9.1, the parties shall only be liable to one another for breaches of duty arising from slight negligence in the event of a breach of material contractual obligations, that is to say, obligations whose fulfilment is essential to the proper performance of the contract or whose breach jeopardises the achievement of the purpose of the contract and on whose observance the other party may reasonably rely; however, liability shall be limited to damage typical of the contract and foreseeable at the time of its conclusion.
9.3. The above limitations of liability shall not apply to liability under the Product Liability Act or in respect of any guarantees given in writing by either party.
9.4. Clause 9 shall also apply in favour of the parties’ employees, representatives and governing bodies.
10.1. The Provider warrants that the software does not infringe any third-party rights. The Provider shall, upon first request, indemnify the Customer against all claims by third parties arising from infringements of intellectual property rights for which the Provider is responsible in connection with the contractual use of the software, and shall reimburse the costs of reasonable legal proceedings. The Customer shall immediately inform the Provider of any claims by third parties asserted against the Provider on the basis of the contractual use of the software and shall grant the Provider all necessary powers of attorney and authorisations to defend against such claims.
10.2. The Customer warrants that the content and data stored on the Provider’s servers, as well as their use and provision by the Provider, do not contravene applicable law, official orders, the rights of third parties or agreements with third parties. The Customer shall, upon first request, indemnify the Provider against any claims asserted by third parties arising from a breach of this clause.





