General Terms and Conditions ONE WARE – ONE AI
ONE WARE has developed the software solution ONE AI (hereinafter the "Software"), which aims to increase the efficiency and performance of Artificial Intelligence (AI). The goal is to train specific AI models for various subject areas at the customer's request. For this purpose, customers can upload and edit content, in particular images, and use it to train an AI model. ONE WARE uses this data to optimise the models specifically according to the customer's wishes and to adapt them to the respective requirements and topics. This creates a tailor-made AI solution that meets the specific needs of the customer.
Having said this, the parties agree as follows:
This English version is a translation for convenience. In the event of discrepancies, the German version prevails.
1 Additional applicable provisions and order of precedence
1.1 In addition to the provisions of this User Agreement, the provisions of the annexes to the User Agreement shall apply (User Agreement and annexes together the "Contract").
1.2 In the event of contradictions between the annexes and the User Agreement, the respective provisions shall apply in the order specified below:
a) Annex 2 to the User Agreement (DPA)
b) Annex 1 to the User Agreement (Service description – specification)
c) Annex 3 to the User Agreement (Pricing Annex)
d) User Agreement
2 Subject matter and conclusion of the contract; Customer's General Terms and Conditions
2.1 The contract for the use of the Software is concluded by the customer registering on the ONE WARE Studio website via the ONE AI extension. To do so, the customer downloads the ONE AI extension and selects the "Sign up" option there.
2.2 As part of the conclusion of the contract, the customer may cancel the registration process at any time up until clicking the "Register" button, or delete, add to or correct the information entered in the various fields. After completing the registration, the customer can access and change all data provided during registration at any time in the "Account Settings".
2.3 By completing the registration process, the customer submits a legally binding offer to ONE WARE to conclude a contract. ONE WARE will send the customer a confirmation of receipt of the offer immediately after receipt of the offer to the e-mail address provided by the customer during registration. However, this confirmation does not yet constitute acceptance of the customer's offer.
2.4 A contract between ONE WARE and the customer is only concluded once ONE WARE has accepted the offer. The customer receives the declaration of acceptance either by e-mail or by being granted access to the Software ("Conclusion of contract").
2.5 ONE WARE does not store the contract text after conclusion of the contract. However, the customer may access the contract text at any time throughout the entire online conclusion of the contract at https://one-ware.com/docs/legal/terms.
2.6 The contract may be concluded in German or English. In the event of discrepancies between the German and the English version, the German version shall prevail; the English version is provided for convenience only.
2.7 The customer's general terms and conditions shall only become part of the contract if ONE WARE expressly agrees to this in writing.
2.8 The Software is aimed exclusively at entrepreneurs within the meaning of section 14 of the German Civil Code (BGB). ONE WARE reserves the right to request appropriate information and evidence demonstrating that the customer is not a consumer pursuant to section 13 BGB. There is no entitlement to the conclusion of a contract.
3 Services provided by ONE WARE
3.1 ONE WARE provides the customer with access to the Software via the ONE AI extension for a limited period for the term of the contract. A customer is entitled to register several users in accordance with the service description. Each user is assigned a separate account.
3.2 In a first step ("training preparation"), the customer may use the Software to store images locally as training material. The customer can edit and organise this training data set in order to prepare the training of the AI model in the best possible way. In particular, the customer can classify the images, mark relevant areas and apply pre-filters (e.g. colour enhancement, focus, cropping). In addition, the customer can already make default settings for the desired AI model and, if applicable, select and define the hardware resources on which the model is to run later.
3.3 Once the customer has prepared the training data accordingly and made all necessary model and hardware settings, the customer may start the training and have it carried out by ONE WARE against payment of the remuneration described in clause 5 and in the Pricing Annex contained in Annex 3 ("Credits"). For this purpose, the customer uploads the training data to the ONE AI Cloud. The customer can individually determine the start, time and scope of the training.
3.4 After completion of the training, the customer has the option of testing the AI model ("Testing"). For this purpose, the customer can view in the ONE AI extension how the AI model classifies data. The customer can also upload new data sets in order to evaluate whether the AI model works for the desired application. The customer also has the option of obtaining a test licence for the AI model in order to test whether the AI model works on the respective hardware ("hardware test"). The customer can select this option by clicking the "Export" button. Details of the testing and in particular the hardware test are set out in clause 8.
3.5 If the customer is satisfied with the result of the testing, the customer may acquire a licence from ONE WARE in order to be able to use and export the trained AI model in productive operation. For this purpose, the customer contacts ONE WARE after completion of the testing and requests such a licence. The parties agree individually on the commercial terms of this licence. Upon conclusion of the licence agreement, it becomes part of this contract as Annex 4.
3.6 The details of the functions of the Software for training preparation, training, testing, export and use of the AI model are set out in the service description and the specification in Annex 1. Beyond the agreed services, the customer has no claim to any particular design or functionality of the Software.
3.7 Operation and maintenance of the Software are the responsibility of ONE WARE. The place of handover of the service is the router output of ONE WARE's data centre. The customer is responsible for the availability of internet access and any hardware required at the customer's premises for access to the Software (e.g. router, smart device) as well as for downloading the ONE AI extension. The customer has no claim to access to the source code of the Software.
3.8 Unless otherwise agreed, the average availability of the Software is 98% on an annual average. This excludes necessary scheduled maintenance work as well as disruptions beyond ONE WARE's control (in particular force majeure or failures due to incorrect operation by the customer). Where possible, ONE WARE will inform the customer of planned maintenance work in good time in text form. However, ONE WARE reserves the right to carry out unannounced maintenance work if necessary, in particular if this is required for data and operational security.
3.9 During training preparation, the customer is responsible for storing the training data itself. ONE WARE has no access to the customer's training data during this phase. When the customer uploads the training data to the ONE AI Cloud, ONE WARE stores this data on a server operated by ONE WARE. ONE WARE deletes the customer's training data uploaded to the ONE AI Cloud after 90 days, unless the customer carries out training or the parties have agreed on a longer storage period.
3.10 ONE WARE is entitled to engage subcontractors as vicarious agents for the provision of services at its own discretion.
3.11 Extensions, further developments, changes
ONE WARE may make changes to the Software in the following cases:
3.11.1 Extensions and further development
ONE WARE is entitled to add additional information to the services at any time. Functions introduced by ONE WARE after conclusion of the contract shall – unless otherwise agreed – be deemed additional services provided free of charge. ONE WARE is entitled to discontinue these, taking into account the interests of both parties. ONE WARE also reserves the right to offer optional extensions and further developments only against payment of additional remuneration and subject to the conclusion of an additional usage agreement.
3.11.2 Reasonable and non-material changes
ONE WARE is entitled to change, restrict or discontinue the scope of functions of the services to the extent reasonable for the customer. Such a change is reasonable in particular if it only affects non-essential components of the services to be provided by ONE WARE (such as mere design or display changes that do not impair the functionality of the service or only do so insignificantly) or becomes necessary for good cause. Good cause exists in particular if
a) there are disruptions in the provision of services by ONE WARE's subcontractors,
b) the change is required for security reasons,
c) it is required due to changes in legislation or case law, or
d) there are similarly important reasons which, after weighing them against the interests of the customer, make the change in question reasonable for the customer.
Subject to clause 3.11.3, in the event of any change to the scope of functions, the performance features defined in the respective order and in Annex 1 shall be substantially retained and ONE WARE's main contractual obligations shall be retained in full.
3.11.3 Other changes
ONE WARE is entitled to make changes to the scope of functions of the services in cases other than those specified in clauses 3.11.1 and 3.11.2 as well, taking into account the interests of both parties. In this case, ONE WARE will inform the customer of the planned changes two months before the changes are introduced. During this period, the customer has the right to declare whether or not it accepts the planned changes. If the customer does not respond within this period, the changes shall be deemed approved. If the customer objects to the changes within the period, ONE WARE has the right, at its discretion, either to continue providing the affected service without the planned changes or to terminate the contract with a notice period of one month from receipt of the customer's objection.
4 Rights of use
4.1 Upon commencement of the contract, ONE WARE grants the customer the non-exclusive, non-transferable right, limited to the term of the contract, to use the Software in accordance with the contract. The right of use may only be sublicensed to the extent that this is strictly necessary for the customer's intended use of the Software. More extensive statutory rights of the customer remain unaffected.
4.2 Excluded from the granting of rights are components of the Software which are recognisably subject to third-party rights for the customer, in particular open source licences. Components which are disclosed by ONE WARE within the Software or in accompanying text files as third-party content are deemed recognisable in particular.
4.3 The contractual rights of use with regard to AI models trained by ONE WARE on behalf of the customer under this contract result, for the testing phase, from the provisions in clause 8 and otherwise from the licence agreement to be concluded between the parties, which will be attached to this contract as Annex 4 upon its conclusion.
5 Fees
5.1 The customer pays ONE WARE the remuneration agreed in the Pricing Annex in Annex 3 for the training and the storage of training data and trained AI models.
5.2 The remuneration for the use and export of trained models results from the licence agreement to be concluded between the parties, which will be attached to this contract as Annex 4 upon its conclusion.
5.3 Unless expressly agreed otherwise, the fees are net amounts plus applicable VAT.
5.4 Unless expressly agreed otherwise, all amounts are due upon invoicing.
5.5 If the customer grants ONE WARE a SEPA direct debit mandate, ONE WARE will not debit the invoice amount from the agreed account before the seventh day after the invoice date and the SEPA pre-notification.
6 Obligations of the customer
6.1 The customer must keep the access data to the Software secure and may only make it available to duly authorised employees. The customer undertakes to ensure that the access data is treated confidentially and to inform ONE WARE immediately if there is a suspicion that the access data may have become known to unauthorised persons. Furthermore, the customer undertakes to comply with all security precautions and functional and other restrictions of the Software. In particular, the customer may not remove, overcome, deactivate or otherwise circumvent protection or authentication mechanisms.
6.1.1 The customer is prohibited from making the Software available to third parties unless expressly agreed otherwise.
6.1.2 The customer is obliged to keep the information provided during registration up to date and to notify ONE WARE of any changes without undue delay. This includes in particular data relating to the customer's contact and business information.
6.2 The customer must regularly back up its data and content stored, processed and otherwise transmitted to ONE WARE within the scope of the Software (within the meaning of clause 6.5.1) in a manner appropriate to the risk, insofar as this is technically possible for the customer.
6.3 The customer names ONE WARE a contact person within its company who is authorised to receive and issue declarations of intent in connection with the contract with ONE WARE.
6.4 It is incumbent on the customer to ensure that it uploads the training data required for the training to the ONE AI Cloud in accordance with the technical requirements set out in the specification in Annex 1 and thus makes it available to ONE WARE for the training of the AI model.
6.4.1 The customer undertakes to refrain from any measures that endanger or disrupt the functioning of the Software, and not to access or process data which it is not authorised to access.
6.5 Content; use of the Software
6.5.1 All rights to information, images, texts and other content transmitted by the customer to ONE WARE in the course of using the Software, in particular as training data ("Content"), remain with the customer. However, the customer grants ONE WARE a non-exclusive right of use to this Content to use the Content to the extent necessary to fulfil the contract with the customer. ONE WARE is entitled to grant sublicences to its vicarious agents insofar as this is necessary for the performance of the contract. In all other respects, the right of use is non-transferable. ONE WARE is entitled to retain the customer's Content beyond the term of the contract insofar as this is technically or legally required.
6.5.2 For the avoidance of doubt: ONE WARE does not use the customer's Content to train AI models other than those which the customer has trained itself via the Software.
6.5.3 The customer will not upload or process any Content as training data via the Software which
a) infringes third-party rights (for example personality rights, rights to one's own image, copyrights, trademark rights, etc.) or otherwise violates applicable law;
b) contains illegal or immoral material and/or content, in particular information that incites hatred, provides instructions for criminal offences or glorifies or trivialises violence, is pornographic or sexually offensive or is likely to seriously endanger the morals of children or adolescents, or contains pornographic or obscene material; or
c) contains personal data
("Prohibited Content").
6.5.4 AI agent inputs (prompts)
Inputs made by the customer to the AI assistant ("prompts") also constitute "Content" within the meaning of this clause 6.5. The customer is prohibited from entering personal data or unlawful content into the AI agent. The customer bears full responsibility for the content of its prompts.
7 Temporary blocking
7.1 ONE WARE is entitled to block the customer's access to the Software if
a) there are indications that the customer's access data has been or is being misused, or that the access data has been or is being made available to an unauthorised third party, or that access data is being used by more than one natural person;
b) there are indications that unauthorised third parties have otherwise gained access to the IT infrastructure provided to the customer;
c) the blocking is necessary for technical reasons;
d) ONE WARE is obliged to block access under applicable law or by court or official order;
e) the customer uploads Prohibited Content to the Software;
f) the customer is in default of payment of the agreed fees pursuant to clause 5 of the contract for more than two (2) weeks; or
g) the customer has provided incorrect or invalid contact details and communication between ONE WARE and the customer is no longer possible.
7.2 ONE WARE shall announce the blocking to the customer in text or written form no later than one working day before the blocking takes effect, insofar as such announcement is reasonable taking into account the interests of both parties and compatible with the purpose of the blocking.
8 Testing; hardware test
8.1 The customer is entitled to test the AI model free of charge in the ONE AI extension after completion of the training. The test is limited exclusively to evaluating the function of the model and may not be used for productive operation.
8.2 The customer is entitled to upload new Content in order to test the model, provided this serves exclusively to evaluate the function of the model.
8.3 Hardware test
8.3.1 For a hardware test, the customer must submit a separate request to ONE WARE via the "Start Export" button. After approval, the customer receives a code in order to be able to export the AI model to its own hardware for testing.
8.3.2 Upon approval of the hardware test, ONE WARE grants the customer the non-exclusive, non-transferable right, limited to 30 days, to use the AI model exclusively for test purposes.
8.3.3 The hardware test is limited to test operation and may not be used for productive purposes. After expiry of the test period, the customer is obliged to cease test operation and to delete all copies of the AI model unless it concludes a licence agreement with ONE WARE regarding this AI model.
8.4 The customer bears sole responsibility for the security of the test environment, in particular the hardware used.
8.5 Without prejudice to mandatory statutory provisions, the customer is not entitled to carry out any form of reverse engineering of the AI model or to make any other attempts to discover the source code or the underlying components of the model.
9 Warranty
9.1 For services provided free of charge, ONE WARE provides warranty in accordance with the statutory provisions.
9.2 In all other respects, ONE WARE provides warranty for defects in the provision of the Software exclusively in accordance with the following provisions.
9.3 If the services to be provided by ONE WARE under this contract are defective, ONE WARE will, at its discretion, rectify the services or provide them again within a reasonable period and after receipt of a written notice of defects from the customer (e-mail is sufficient). The provision of instructions for use with which the customer can reasonably circumvent defects that have occurred in order to use the Software in accordance with the contract shall also be deemed rectification.
9.4 If the defect-free provision of the services fails for reasons for which ONE WARE is responsible, even within a reasonable period set by the customer in writing, the customer may reduce the agreed remuneration by a reasonable amount. The right to reduction is limited to the amount of the monthly fixed price relating to the defective part of the service.
9.5 If the reduction pursuant to clause 9.4 reaches the maximum amount specified in clause 9.4 in two consecutive months or in two months of a quarter, the customer may terminate the contract without notice.
9.6 The customer will notify ONE WARE of any defects that occur without undue delay in written form (e-mail is sufficient). Furthermore, the customer will support ONE WARE free of charge and in a reasonable manner in remedying defects and will in particular provide ONE WARE with all information and documents that ONE WARE requires for the analysis and elimination of defects.
9.7 In addition to reduction and termination, the customer may claim damages in accordance with the statutory provisions and the limitation of liability in clause 10.
9.8 Further warranty claims are excluded.
9.9 The limitation period for warranty claims is one year, unless they are based on intent or gross negligence or relate to damage resulting from injury to life, body or health.
10 Damages and liability
10.1 For services provided free of charge, ONE WARE is liable in accordance with the statutory provisions.
10.2 In all other respects, ONE WARE is liable without limitation for intent and gross negligence as well as for damage resulting from injury to life, body or health.
10.3 In cases of simple negligence, ONE WARE is liable for the breach of a material contractual obligation. A material contractual obligation within the meaning of this clause is an obligation whose fulfilment is a prerequisite for the proper performance of the contract and on whose fulfilment the customer may therefore regularly rely.
10.4 ONE WARE is not liable for lack of economic success, loss of profit or indirect damages.
10.5 Liability is limited to the typical, foreseeable damage at the time of conclusion of the contract.
10.5.1 Liability for AI outputs
The outputs generated by the AI agent (e.g. configuration files, code snippets, technical answers) are automated and non-binding. ONE WARE assumes no warranty for the accuracy, completeness or suitability of these outputs for any particular purpose. The use of AI-generated results, in particular the productive use of configuration files, is at the customer's own risk. With regard to AI-based advice, ONE WARE does not owe any particular result.
10.6 Liability for damage due to data loss is limited to the amount of the restoration of the data that would also have been incurred if the customer had backed up the data regularly and in a manner appropriate to the risk.
10.7 The limitations of liability apply accordingly for the benefit of ONE WARE's employees, agents and vicarious agents.
10.8 Any liability of ONE WARE for guarantees given (which must be expressly designated as such) and for claims under the German Product Liability Act remains unaffected.
10.9 Any further liability of ONE WARE is excluded. In particular, the strict liability for initial defects pursuant to section 536a (1) 1st alternative BGB is excluded.
11 Confidentiality and secrecy
11.1 The parties undertake to treat confidential information and documents ("confidential information") of the respective other party which have been designated or marked as confidential by the disclosing party as business and/or trade secrets, to use them exclusively for the purposes of this contract and not to make them accessible to third parties. The receiving party will take appropriate technical and organisational measures to prevent unauthorised access to / disclosure of confidential information. Affiliated companies of the respective receiving party in which the receiving party does not hold a majority of capital and voting rights shall also be deemed third parties within the meaning of this agreement. The employees of the receiving party and other third parties engaged by it (including subcontractors and freelancers) shall be obliged accordingly.
11.2 On the part of ONE WARE, confidential information includes in particular the Software as well as all technologies of ONE WARE and this contract including the annexes and the agreed terms.
11.3 The receiving party is entitled to pass on the information and documents made available to it to third parties if and to the extent that this is indispensable for the performance of this contract or the exercise of contractual rights, or if this is mandatorily required for legal or regulatory reasons. In the event of requests from third parties, courts or administrative authorities regarding the disclosure of confidential information, the receiving party must inform the disclosing party thereof without undue delay in writing or in text form. The receiving party must furthermore support the disclosing party in its efforts to prevent the disclosure of the confidential information.
11.4 The confidentiality obligation does not apply insofar as the confidential information was already known to the receiving party before disclosure, is generally known or becomes known without fault of the receiving party, was developed by the receiving party itself without access to the disclosing party's confidential information, or is brought to its attention by a bona fide third party entitled to do so, or which does not allow any conclusions to be drawn about natural persons or the disclosing party. Mandatory statutory disclosure obligations remain reserved. If the receiving party invokes one or more of the aforementioned grounds, it must substantiate them by providing suitable evidence.
11.5 The confidentiality obligation begins upon becoming aware of the confidential information and exists for the entire term of this contract. In addition, the confidentiality obligation exists for a period of three years from termination or the end of the contract term, unless statutory provisions provide for a longer confidentiality obligation. In particular, any trade secrets must be treated confidentially for as long as they constitute trade secrets.
11.6 Insofar as agreed in the service description, ONE WARE is entitled to name the customer as a reference customer in marketing materials (including websites), stating the full company name and using the company logo.
11.7 With the exception of clause 11.6, the above provisions do not establish any intellectual property rights of use. All rights of use granted under this contract remain unaffected by the above provisions.
12 Data protection
12.1 With regard to the personal data that ONE WARE processes on behalf of the customer within the scope of this contract, the parties conclude the data processing agreement in Annex 2 ("DPA"). In the event of contradictions between this contract and the DPA, the provisions of the DPA shall prevail.
13 Term and termination
13.1 The contract begins upon conclusion of the contract and runs for an indefinite period.
13.2 The parties' right to terminate for good cause remains unaffected. For ONE WARE, good cause exists in particular if:
a) the customer repeatedly and despite prior warning by ONE WARE uploads Prohibited Content to the Software;
b) the customer is in default of payment of the agreed fees pursuant to clause 5 for more than six weeks and ONE WARE has threatened the customer with termination in text or written form with a notice period of two weeks until the termination takes effect.
14 Final provisions
14.1 Amendments and ancillary agreements to this contract must be made in writing. This also applies to this written form clause.
14.2 In the event of contradictions between the annexes and the contract, the provisions of the annexes shall prevail.
14.3 The customer may only offset against claims of ONE WARE or assert a right of retention if the counterclaim is undisputed or has been legally established or is in a synallagmatic relationship with the respective claim concerned.
14.4 The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
14.5 The exclusive place of jurisdiction for all disputes arising from or in connection with this contract is the registered office of ONE WARE, provided that the contracting parties are merchants or the customer has no general place of jurisdiction in Germany or in another EU member state or has relocated its permanent residence abroad after these General Terms and Conditions have taken effect, or the residence or habitual abode is not known at the time the action is brought.
14.6 References to German law are binding; translations serve for orientation only.
Annex 1 – Service description (specification)
(1) Subject matter of the service
With "ONE AI", the provider makes available a software solution for the automated creation and optimisation of tailor-made AI models. The platform enables users to generate and train individual AI models on the basis of their data and to export them in various formats.
(2) Scope of services
The functions provided include in particular:
- Analysis and pre-processing of image data (PNG, JPG) and associated label files (TXT)
- Support of image analysis for use cases such as image classification and object detection
- AI model prediction and automated training on ONE AI servers or locally
- Export of the trained models in formats such as ONNX and TensorFlow Lite, export as a project in the languages C++ for processor-based systems or VHDL for FPGA-based systems, or as an executable program for systems running the Linux operating system
(3) Technical restrictions
- Maximum data volume per project: 50 GB upload limit
- Supported file formats: PNG and JPG images as well as TXT label files
- Maximum image resolution: Prediction by AI models is only supported for images up to 8000x6000 pixels
(3.1) AI assistant / AI agent
Interactive support within the platform for answering technical questions and generating technical suggestions (e.g. configuration files).
- Storage: Questions and answers are stored in order to enable history and context.
- Disclaimer: The AI agent generates answers on the basis of probabilities. There is no entitlement to completeness, freedom from errors or suitability for a particular purpose. The customer is responsible for technically validating the results before use.
(4) Services not owed
- The provider does not provide any personal or individual consulting. Support is limited to technical enquiries, error reports and assistance with the use of the platform.
- Feature adaptations, hardware consulting or commissioned AI development are provided exclusively on the basis of a separate written agreement.
(5) Customer's obligations to cooperate
- The customer is responsible for the accuracy, formatting and suitability of the uploaded data.
- Before use, the customer must ensure that the system requirements are met and that all project content complies with data protection regulations.
Annex 2: Data Processing Agreement (DPA)
This data processing agreement ("DPA") specifies the data protection obligations and rights of the parties in connection with the processing of personal data processed by ONE WARE GmbH (hereinafter the "Processor") for the customer (hereinafter the "Controller") under the ONE AI User Agreement concluded between the parties (hereinafter the "Main Agreement").
1 Scope of application
When providing the services under the Main Agreement, the Processor processes personal data made available by the Controller for the provision of the services and in respect of which the Controller acts as controller within the meaning of data protection law or as processor for other processors or controllers ("Controller Data"). In the event of contradictions between this DPA and provisions of other agreements, in particular the Main Agreement, the provisions of this DPA shall prevail.
2 Subject matter and scope of the engagement / Controller's right to issue instructions
2.1 The Processor will process the Controller Data exclusively on behalf of and in accordance with the instructions of the Controller, unless the Processor is legally obliged to process the data under the law of the European Union or of a member state. In such a case, the Processor shall inform the Controller of these legal requirements prior to the processing, unless the relevant law prohibits such notification on important grounds of public interest.
2.2 The processing of Controller Data by the Processor takes place exclusively in the manner, to the extent and for the purpose specified in Appendix 1 to this DPA; the processing relates exclusively to the types of personal data and categories of data subjects designated therein.
2.3 The duration of the processing corresponds to the term of the Main Agreement.
2.4 The Processor is permitted to process Controller Data outside the European Economic Area ("EEA") or to have it processed by further processors pursuant to clause 5 if the requirements of Art. 44 to 48 GDPR are met or an exception pursuant to Art. 49 GDPR applies.
2.5 The instructions result from the Main Agreement. The Controller is only entitled to issue further instructions regarding the nature, scope, purposes and means of the processing of Controller Data if such instructions are required under the law of the European Union or of a member state or on the basis of a court or official order.
2.6 Instructions should be issued in written or text form. The Controller will confirm verbal instructions in writing or by e-mail.
2.7 If the Processor is of the opinion that an instruction of the Controller violates this DPA, the GDPR or other data protection provisions of the Union or of the member states, it will inform the Controller thereof without undue delay in written or text form. The Processor is entitled to suspend the execution of such an instruction until the Controller confirms it in written or text form. If the Controller insists on the execution of an instruction despite the concerns raised by the Processor, the Controller shall indemnify the Processor against all damages and costs incurred by the Processor as a result of executing the Controller's instruction. The Processor will inform the Controller of damages asserted against it and costs incurred by it, will not acknowledge third-party claims without the Controller's consent and will, at the Processor's option, conduct the defence in coordination with the Controller or leave it to the Controller.
3 Personnel requirements
3.1 The Processor must oblige all persons who process Controller Data to maintain confidentiality, unless they are subject to an appropriate statutory duty of confidentiality.
3.2 The Processor ensures that persons under its authority who have access to Controller Data process it only in accordance with this DPA and the Controller's instructions, unless they are required to process it under the law of the European Union or of the member states.
4 Security of processing
4.1 The Processor takes all appropriate technical and organisational measures which, taking into account the state of the art, the costs of implementation and – insofar as known to the Processor – the nature, scope, circumstances and purposes of the processing of the Controller Data as well as the varying likelihood and severity of the risk to the rights and freedoms of data subjects, are necessary to ensure a level of protection for the Controller Data appropriate to the risk.
4.2 Before the start of the processing of the Controller Data, the Processor must in particular implement the technical and organisational measures specified in Appendix 2 to this DPA, maintain them for the term of the Main Agreement and ensure that the processing of Controller Data is carried out in accordance with these measures.
4.3 It is incumbent on the Controller to review the technical and organisational measures taken by the Processor, in particular whether they are also sufficient with regard to circumstances of the data processing that are not known to the Processor.
4.4 Since the technical and organisational measures are subject to technical progress, the Processor is entitled and obliged to implement alternative, adequate measures in order not to fall below the security level of the measures set out in Appendix 2. If the Processor makes material changes to the measures set out in Appendix 2, it will inform the Controller thereof in advance.
5 Engagement of further processors
5.1 When processing the Controller Data, the Processor engages the further processors listed in Appendix 3. These are deemed approved upon conclusion of the DPA.
5.2 The Processor may engage further processors for the processing of Controller Data subject to the following conditions: the Processor informs the Controller at least 30 days before engaging the further processor in text or written form to an address designated by the Controller for these purposes. Unless the Controller objects within 14 days, the engagement is deemed approved.
5.3 If the Controller objects, the Processor is entitled, at its discretion, either to provide its services under the Main Agreement without the use of the rejected further processor or to terminate the Main Agreement and this DPA.
5.4 The Processor must impose on each further processor substantially the same data protection obligations that apply to the Processor under this DPA.
5.5 The Processor is obliged to select and engage only such further processors that provide sufficient guarantees that the appropriate technical and organisational measures are implemented in such a way that the processing of the Controller Data is carried out in accordance with the requirements of the GDPR and this DPA.
6 Rights of data subjects
6.1 The Processor will take all reasonable technical and organisational measures to support the Controller in fulfilling its obligation to respond to requests from data subjects exercising their rights.
6.2 In particular, the Processor will:
a) inform the Controller without undue delay if a data subject contacts the Processor directly with a request to exercise its rights in relation to Controller Data;
b) provide the Controller upon request with all information available to it about the processing of Controller Data that the Controller requires in order to respond to a data subject's request and which the Controller does not have itself;
c) rectify, delete or restrict the processing of Controller Data without undue delay upon instruction of the Controller, insofar as the Controller cannot do so itself and this is technically possible for the Processor;
d) support the Controller, insofar as necessary, in receiving the Controller Data processed within the Processor's area of responsibility – insofar as this is technically possible for the Processor – in a structured, commonly used and machine-readable format, insofar as a data subject asserts a right to data portability with regard to the Controller Data vis-à-vis the Controller.
7 Other support obligations of the Processor
7.1 The Processor shall notify the Controller without undue delay after becoming aware of any breach of the protection of Controller Data, in particular incidents that lead to the destruction, loss, alteration, or unauthorised disclosure of, or unauthorised access to, Controller Data. Where possible, the notification shall contain a description of:
a) the nature of the breach of the protection of the Controller Data, where possible stating the categories and approximate number of data subjects concerned;
b) the likely consequences of the breach of the protection of the Controller Data;
c) the measures taken or proposed by the Processor to remedy the breach of the protection of the Controller Data and, where applicable, measures to mitigate its possible adverse effects.
7.2 The Processor is obliged, in the event of any breach of the protection of Controller Data, to take without undue delay all necessary and reasonable measures to remedy the breach of the protection of the Controller Data and, where applicable, to mitigate its possible adverse effects.
7.3 If the Controller is obliged vis-à-vis a public authority or a person to provide information about the processing of Controller Data or to otherwise cooperate with such bodies, the Processor is obliged to support the Controller in providing such information or fulfilling other cooperation obligations to the extent possible.
7.4 The Processor will support the Controller in complying with the obligations set out in Art. 32 GDPR, insofar as this is possible for it taking into account the information available to it about the specific use of the Controller's services.
7.5 In the event that the Controller is obliged to inform the supervisory authorities and/or data subjects pursuant to Art. 33, 34 GDPR, the Processor will support the Controller upon request, to the extent possible, in complying with these obligations. In particular, the Processor is obliged to document all breaches of the protection of Controller Data, including all related facts, in a manner that enables the Controller to demonstrate compliance with any applicable statutory notification obligations.
7.6 The Processor will support the Controller, with the information available to it and to the extent reasonable, in any data protection impact assessments to be carried out by the Controller and in any subsequent consultations with the supervisory authorities pursuant to Art. 35, 36 GDPR.
8 Deletion and return of data
8.1 Upon termination of the Main Agreement, the Processor will completely delete all Controller Data, unless the Processor is obliged under the law of the European Union or of a member state to continue storing the Controller Data.
8.2 However, the Processor is entitled to retain backup copies of the Controller Data for a period of 30 days, insofar as deletion of the Controller Data from these backup copies is not required for technical reasons or with regard to Art. 32 GDPR. For this period, the rights and obligations of the parties under this DPA continue to apply to the backup copies, notwithstanding clause 2.3.
8.3 Documentation serving as evidence of the processing of the Controller Data in accordance with the engagement and with applicable law must be retained by the Processor beyond the end of this DPA in accordance with the statutory retention periods.
9 Evidence and audits
9.1 The Processor must ensure and regularly verify that the processing of the Controller Data complies with this DPA, the Main Agreement and the Controller's instructions.
9.2 The Processor will document the implementation of the obligations under this DPA in an appropriate manner and, upon request, provide the Controller with all necessary evidence of compliance with the Processor's obligations under the GDPR and this DPA.
9.3 The Controller is entitled to audit the Processor with regard to compliance with the provisions of this DPA, in particular the implementation of the technical and organisational measures pursuant to Appendix 2, itself or through a qualified auditor bound to secrecy; including by means of inspections. The Processor enables such audits and contributes to them through all appropriate and reasonable measures, including by granting the necessary rights of access and providing all necessary information.
9.4 The audits and inspections should, as far as possible, not impede the Processor's normal business operations and not place an unreasonable burden on it. In particular, inspections at the Processor without specific cause should take place no more than once per calendar year and only during the Processor's normal business hours. The Controller must announce inspections to the Processor in advance in written or text form in good time.
9.5 In accordance with the provisions of the GDPR, the Controller and the Processor are subject to public supervision by the competent supervisory authority. At the Controller's request, the Processor will provide the requested information to the supervisory authority and grant it the opportunity to carry out an audit; this includes inspections at the Processor by the supervisory authority or the persons designated by it. In this context, the Processor grants the competent supervisory authority the necessary rights of access, information and inspection.
10 Miscellaneous
10.1 Amendments and ancillary agreements to this DPA must be made in writing. This also applies to this written form clause.
10.2 Choice of law and jurisdiction agreements from the Main Agreement apply accordingly to this DPA.
Appendix 1 – Purpose, nature and scope of the data processing, type of data and categories of data subjects
| Purpose of the data processing | The stored data is used for the following purposes: – Provision of the Software – Ensuring the availability and security of the systems – User login and user profile data for the provision of user accounts |
| Nature and scope of the data processing | – Storage and provision of logins to the Software – Storage of names and address data of customers – Insofar as agreed, carrying out onboarding measures for the Controller |
| Type of data | The subject of the collection, processing and/or use of personal data under this data processing agreement are the following types/categories of data: – Login data (name, e-mail address, etc.) and other personal data provided during registration |
| Categories of data subjects | Users of the Software |
Appendix 2: Technical and organisational measures
1 Pseudonymisation and encryption (Art. 32 (1) (a) GDPR)
Basic measures
- Encryption of data carriers in laptops / notebooks
- Encryption of data during further online transmissions
2 Confidentiality (Art. 32 (1) (b) GDPR)
2.1 Technical and organisational measures
- Definition of access authorisations for employees and third parties, including the respective documentation
- Special security areas with their own access control ("closed shops")
- Policy for the organisation of files
- Internal data processing policies and procedures, instructions for action, work instructions, process descriptions and rules for the programming, testing and release of data
- Personal data is processed only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation
- Existence of a data security concept
- Binding policies and procedures for the processor's employees in connection with data processing
- Upon request, the processor can provide the controller with all information necessary to demonstrate compliance with the data processing agreement, including at short notice (within a maximum of 48 hours)
- Upon request, the processor grants the controller access so that the controller can monitor compliance with this agreement by means of audits and inspections
- Existence of a contingency plan (backup contingency plan)
- Separation of tasks/functions between the IT department and other departments
- Instructions for employees on the processing of personal data
- Clear delimitation between the areas of responsibility of the controller and the processor
2.2 Physical access control for persons
- Physical access to the premises where data is processed is logged
- Documentation of key allocation
- Collection and accompaniment of external persons by employees
- Chip card / transponder locking system
- Regulation of keys/codes (key issuance, etc.)
- Reporting of access events
- Manual locking system, doors are always kept locked
- Only competent employees have access to the data processing systems
2.3 User control
- Definition of access authorisations for employees and third parties, including the respective documentation
- Regular review of the validity of authorisations
- Granting of access authorisations only to specific persons
- Departures, team changes and inactive users (e.g. parental leave, sabbatical) are handled in good time (user accounts removed/deactivated/adjusted)
- Securing of workstations during absence while the system is running
- Use of intrusion detection systems, antivirus programs, hardware and software firewalls as well as central smartphone administration software (e.g. for remote deletion of data)
- Shielding of internal networks against external access
- Access to devices is password-protected
- Login only possible after identification
- All IT systems are password-protected
- Password assignment in accordance with the recommendations of the German Federal Office for Information Security (BSI), see www.bsi.bund.de
- Use of professional password management
- Automatic screen locks in the event of inactivity
- 2-factor authentication for critical systems and data
- Processes for testing and releasing programs
- Provisions for third parties (e.g. IT service providers)
- Installation and maintenance of virus scanners on all devices used for processing
- User passwords for data and programs
- Coding procedures for files
- Protective measures for data entry into storage as well as for reading out, blocking and deleting stored data
- Special access rules for procedures, control cards, process control methods and authorisations for cataloguing programs
- User names and passwords on all devices
- Log file of events (monitoring of intrusion attempts)
- Separation of production and test environments for libraries and data files
- Special control over the use of utility programs where these are capable of circumventing security measures
- Deletion or destruction of all erasable data and electronic media (e.g. notebooks and laptops, hard disks, CDs, DVDs, USB sticks, tapes, data carriers, memory cards, etc.) after the (contractually agreed) end of processing
2.4 Access and data carrier control
- Creation of an authorisation concept
- Ongoing review and evaluation of access authorisations
- Administration of rights by the system administrator
- User management via an Active Directory
- Encryption of data carriers
- Monitoring of system administration activities
- Logging of access to applications (in particular entry, modification, deletion and destruction of data)
- Password assignment in accordance with the recommendations of the German Federal Office for Information Security (BSI), see www.bsi.bund.de
- Automatic return of the user ID after several incorrect passwords have been entered
- Physical deletion of data carriers before reuse
- Proper and data protection compliant destruction of data carriers through the use of shredders or service providers, and logging of the destruction
- Data protection compliant deletion on systems
- Documentation of access authorisations and administration by a closed group of persons
- Logging of access
- Differentiated access rules for different systems
- Issuance and protection of identification codes
- Employees are obliged to maintain confidentiality / data secrecy
- Protection of internal networks against unauthorised access (e.g. by firewalls)
- Automatic locking of accounts in the event of unauthorised access attempts
- Installation and maintenance of virus scanners on all devices used for processing
2.5 Separability
- Clear internal company specifications for data collection and processing
- Definition of database rights
- Separation of production and test environments
- Logical client separation (on the software side)
- Storage of data of different controllers on separate data carriers (physical separation)
- Marking of data records with purpose limitation / data fields
3 Integrity (Art. 32 (1) (b) GDPR)
3.1 Transmission and transport control
- Definition of transmission channels and data recipients
- Securing of the transmission or transport route
- Careful selection of transport services, personal collections and the execution of transport
- Monitoring of the completeness and accuracy of the data transmission (end-to-end control)
- Policy on transmission/dispatch
- Digital signature
- Deletion of data or disposal of data carriers by a certified service provider
- External storage media are always encrypted
- Use of shredders or service providers (where possible with a data protection seal of approval)
- Restriction of the use of external storage media (in particular USB sticks, external hard disks, SD cards, CD and DVD burners) by technical means (e.g. software for controlling interfaces or complete deactivation of interfaces)
- Control of the disposal of data carriers
- Secure storage and release of data carriers exclusively to authorised persons
- Regular checking of files and controlled and documented destruction of data carriers
- Blocking of confidential data carriers (e.g. USB interface)
- In the event that a data breach is identified, the processor will inform the controller without undue delay
- Storage/transmission of data in encrypted form
- Transfer of data in anonymised or pseudonymised form
- Documentation of recipients, the duration of use and the agreed deletion period
- Documentation of remote locations/destinations to which a transmission is to take place and of the transmission route (logical route)
- Formalised data processing including lists of access and transmission processes
3.2 Input and storage control
- Logging of the entry, modification and deletion of data; retention of the logs insofar and as long as necessary
- Traceability of entry, modification and deletion of data by means of individual user names (not user groups)
- Assignment of rights to enter, modify and delete data on the basis of an authorisation concept
- Maintenance of audit-proof access authorisations
- Creation of an overview of retrieval and transmission programs
- Creation of an overview showing which applications can be used to modify and delete data
- Storage of forms from which data was taken for automated processing
4 Availability and resilience (Art. 32 (1) (b) GDPR)
4.1 Availability & recoverability
- Fire and smoke detection systems
- Air conditioning in server rooms
- Protective power strips in server rooms
- Fire extinguishers in server rooms
- No unsupervised storage of potentially flammable material (e.g. paper, cardboard)
- Devices for monitoring temperature and humidity in the server rooms
- Server rooms and IT systems specially protected against environmental influences (e.g. server rooms are not located beneath sanitary facilities; fire protection; temperature control)
- Installation of the server in a separately secured room or data centre
- Creation of a backup & recovery concept
- Creation of a contingency plan (backup contingency plan, testing of data recovery)
- Backups (to be specified if applicable, e.g. daily incremental, weekly full backup)
- Policies for control during the creation of backups
- Regular verification of the recoverability of backups
- Access to the data in the backups is restricted to authorised personnel
- Software-based monitoring of the systems and error messages
- Updating of the software used (e.g. by updates, corrections, bug fixes, etc.)
- Verification of sufficient computing capacity
- Resilience of the IT system, including under (very) high load
- Formal release procedures for hardware, software and IT procedures
- Central procurement of hardware and software
- Internal data processing policies and procedures, instructions for action, work instructions, process descriptions and rules for the programming, testing and release of data
- Data mirroring
4.2 Resilience of the systems
- Automated reporting of malfunctions
- Use of anti-virus software
- Use of a hardware firewall
- Regular maintenance of the systems
- Routine measures to secure the systems in the event of error messages
- Central and uniform procurement of hardware and software
- Continuous updating of the software used
5 Procedures for regular review, assessment and evaluation (Art. 32 (1) (d), 25 (1) GDPR)
5.1 Engagement control
Ensuring that personal data processed on behalf of the controller can only be processed in accordance with the controller's instructions (engagement control)
- Obligation of employees to maintain confidentiality
- SOPs for employees to ensure processing in accordance with the engagement
- Ensuring the destruction of data after completion of the engagement
- Clear delimitation of competences between controller and processor
Insofar as the processor is permitted to engage a sub-processor in accordance with the data processing agreement, engagement control is ensured by the following measures:
- Selection of sub-processors on the basis of due diligence considerations (in particular with regard to data security)
- Data processing agreement pursuant to Art. 28 GDPR
- Effective audit rights agreed vis-à-vis the processor
- The processor must – where required – appoint a data protection officer
- Prior review and documentation of the security measures taken at the processor
- Ongoing review of the processor and its activities
5.2 Data protection management
Basic measures of the processor:
- Appointment of a data protection officer
- Appointment of a security officer
- Internal data processing policies, guidelines, work instructions, procedural rules for handling personal data
- An IT and data security concept exists for the regular review, assessment and evaluation of the technical and organisational measures for data security
- Regular training of employees
- The hardware and software used is regularly checked for functionality
- Existence of a record of processing activities
Appendix 3: Further processors
| Name | Address | Type of data | Purpose | Place of processing / safeguards |
|---|---|---|---|---|
| HubSpot, Inc. | 25 First Street, Cambridge, MA 02141, USA | Customer master data, contact data, invoicing information | Creation, administration and dispatch of invoices | USA – Standard Contractual Clauses (SCC) pursuant to Art. 46 GDPR |
| Paddle.com Market Ltd. | Judd House, 18-29 Mora Street, London EC1V 8BT, United Kingdom | Payment data, invoicing information | Payment processing and billing | United Kingdom – adequacy decision of the EU Commission pursuant to Art. 45 GDPR |
Annex 3 – Pricing Annex
Part I – Remuneration for use of the Software, training and storage space
1 Purchase of credits, credit pricing model
1.1 The customer purchases credits from ONE WARE as remuneration for the services.
1.2 The customer purchases the credits from ONE WARE in packages of at least 1,000 credits each.
1.3 The price for 1,000 credits is EUR 20.00.
1.4 Credits cannot be transferred to other customer accounts.
1.5 The services are priced in accordance with the credit pricing model as set out in the table below.
| Service | Price (in credits) |
|---|---|
| Training of AI models | 50 credits / minute |
1.6 Time-based discounts for training / volume discounts
ONE WARE may, at its own discretion, offer time-controlled discounts or volume discounts for training (e.g. during off-peak hours). ONE WARE will inform the customer if such discounts apply. In all other respects, the customer has no claim to the granting of such discounts.
1.7 Welcome credit for new customers
Upon initial registration, each user receives a one-off welcome credit of 25,000 credits. The welcome credit is granted only once per user.
2 Billing modalities
2.1 The customer may purchase credits in advance and use these credits as desired to use the Software.
2.2 Credits purchased in advance may be redeemed throughout the entire term of the contract.
2.3 If the customer grants ONE WARE a SEPA direct debit mandate, the customer may use further credits in addition to any credits purchased in advance ("post-payment option"). ONE WARE will invoice the additionally consumed credits in aggregate on a monthly basis at the end of the month.
2.4 The customer has the option of specifying a monthly maximum amount under the post-payment option.
3 Central user management
If the customer uses central user management, credits are managed centrally via an admin account. Users (e.g. employee accounts) are granted access to the Software without user-specific invoicing.
In this case, billing and invoicing take place solely centrally via the customer. The customer is responsible for the consumption of all users assigned to the customer.
4 Price adjustment
At the earliest after two years have elapsed following conclusion of the contract, ONE WARE may adjust the prices at its reasonable discretion. Such a change may not exceed the remuneration for the relevant service of the preceding twelve-month period by more than 10%. The customer will be notified thereof three months in advance in text form.
Part II – Remuneration under the licence agreement
1 Scope of application
If the parties have concluded a licence agreement pursuant to Annex 4 to this contract regarding an AI model trained by the customer on ONE AI ("Licensed Item"), the licence fee and the billing modalities are governed by the following provisions.
2 Licence model per execution unit
2.1 ONE WARE grants the customer the right to commercially use a Licensed Item in connection with a specific product, machine or software instance in accordance with the provisions of the licence agreement against payment of an annual licence fee.
2.2 The amount of the licence fee results from the licence description in the licence agreement attached to the User Agreement as Annex 4. Unless otherwise agreed in the licence agreement, the licence fee applies per year and per defined unit.
2.3 A defined unit is a specific physical or digital product specified in the licence description as the "field of application" (product type, model series, software solution, etc.).
2.4 The Licensed Item may be updated, improved or retrained as desired within the licensing development environment (IDE).
2.5 If the customer wishes to use the Licensed Item in a different field of application, a new licence agreement must be concluded. There is no (pro rata) refund of the licence fee for the previous licence agreement. This also applies if the new licence agreement is concluded during the current licence year.
3 Included credits
3.1 ONE WARE is free to grant any number of credits free of charge, on a one-off or repeated basis, for the use of ONE AI (e.g. training, analysis, storage) ("Included Credits").
3.2 Included Credits are only valid in the respective calendar month and expire if not used. Carrying them over to subsequent months or converting them into other services is excluded.
4 Price adjustment
At the earliest after two years have elapsed following conclusion of the licence agreement, ONE WARE may adjust the prices at its reasonable discretion. Such a change may not exceed the licence fee of the preceding twelve-month period by more than 10%. The customer will be notified thereof three months in advance in text form.