Skip to main content

Terms & Conditions

Sophera Consulting
Max Fey
Elsdorfer Straße 29
50126 Bergheim
Germany

Email: fey@sopheraconsulting.de

– hereinafter referred to as the “Provider” –

Last updated: 14 April 2026

§ 1 Scope of application

(1) These General Terms and Conditions (hereinafter “GTC”) apply to all contractual relationships between Sophera Consulting, Max Fey (hereinafter “Provider”), and the respective client (hereinafter “Client”) in the fields of AI automation, digitalisation consulting, software development, process optimisation, training, workshops and technical implementation.

(2) These GTC apply exclusively. Deviating, conflicting or supplementary general terms and conditions of the Client shall only become part of the contract if and to the extent that the Provider has expressly consented to their application in writing. This requirement of consent applies in every case, even if the Provider renders the services without reservation while aware of the Client’s terms and conditions.

(3) These GTC also apply to all future business between the parties, provided that these are legal transactions of a related nature.

(4) By using our online services — in particular the automation check, the appointment booking and the payment pages — the user declares their agreement with these GTC and the privacy policy. Consent is obtained before every transmission of data by way of an active confirmation (checkbox).

(4a) The Provider’s offering is directed exclusively at entrepreneurs within the meaning of § 14 BGB (German Civil Code), at legal persons under public law and at special funds under public law. Contracts with consumers within the meaning of § 13 BGB are not concluded. By entering into the contract, the Client confirms that it is acting in the exercise of its commercial or independent professional activity. This status is asked for separately during appointment booking and in the automation check.

(4b) As the offering is not directed at consumers, there is no statutory right of withdrawal under §§ 312g, 355 BGB. Should a contract nevertheless be concluded with a consumer in an individual case, the statutory consumer protection provisions take precedence over these GTC; in that case the Provider will instruct the consumer separately about their right of withdrawal, and the provisions of these GTC concerning warranty periods, limitations of liability and place of jurisdiction shall not apply.

(5) Individual agreements made in a particular case (including ancillary agreements, supplements and amendments) always take precedence over these GTC. A written contract or the written confirmation of the Provider is decisive for the content of such agreements.

§ 2 Subject matter of the contract and scope of services

(1) The subject matter and scope of the contractual services follow from the respective offer, the service description or the individual agreement. The Provider renders its services in accordance with the recognised state of the art.

(2) Depending on the type of service, different types of contract apply:

  • Services under a contract for work (e.g. the creation of automations, software development, integrations): The Provider owes the production of an agreed work result.
  • Services under a service contract (e.g. consulting, strategy development, training, workshops, ongoing support): The Provider owes the diligent performance of the agreed activities, but not a particular result.

(3) Under no circumstances does the Provider owe a guaranteed economic success. This applies in particular to:

  • Increases in revenue or profit
  • Cost savings of a particular amount
  • Efficiency gains going beyond the technical functionality
  • Specific ROI figures or amortisation periods

(4) Projected savings or efficiency gains that are mentioned in the course of consulting, the AI automation check or comparable analyses constitute non-binding estimates and do not establish any legal claim.

§ 3 Offer and conclusion of contract

(1) Offers of the Provider are subject to change and non-binding unless they are expressly designated as binding.

(2) The contract comes into existence through the written placement of an order by the Client and the written acceptance of the order or the commencement of performance by the Provider.

(3) Verbal commitments, ancillary agreements and amendments require written confirmation by the Provider in order to be effective.

§ 4 Provision of services and methodology

(1) The Provider renders its services at its own professional discretion. It is free in its choice of methods, tools and technologies unless agreed otherwise by contract.

(2) The Provider is entitled to engage qualified subcontractors and vicarious agents in order to fulfil its contractual obligations. Responsibility towards the Client remains with the Provider.

(3) Implementation may – where this is sensible given the nature of the service – take place iteratively and in partial steps (agile methodology). The Client will be informed about material interim steps.

(4) Schedules and delivery dates are binding only if they have been expressly agreed in writing as fixed dates. Otherwise they constitute non-binding guide values.

(5) If the Provider is in default, it is liable only in accordance with the general statutory provisions, provided that the default is based on intent or gross negligence.

§ 5 Duties of the Client to cooperate

(1) The Client is obliged to cooperate comprehensively. The success of the project presupposes active collaboration.

(2) The Client shall in particular ensure:

  • Complete, correct and timely provision of all required information, data and materials
  • Timely provision of system access, API keys and technical infrastructure
  • Designation of competent contact persons with decision-making authority
  • Prompt feedback and approvals (within 5 working days unless agreed otherwise)
  • Internal coordination and organisational prerequisites

(3) Delays, additional effort or additional costs arising from late, incomplete or faulty cooperation on the part of the Client shall be borne exclusively by the Client. The Provider is entitled to demand appropriate additional remuneration for this.

(4) If the Client fails to comply with its duties to cooperate despite a written reminder and the setting of a reasonable deadline, the Provider is entitled to terminate the contract extraordinarily. The claim to remuneration for services already rendered remains unaffected by this.

§ 6 Technological dependencies and third-party providers

(1) The services of the Provider are regularly based on technologies, platforms, APIs and services of third parties (e.g. AI models, cloud services, SaaS platforms, open-source software).

(2) The Provider assumes no warranty and no liability for:

  • Changes to, restrictions of or discontinuation of third-party services or APIs
  • System failures, maintenance windows or performance restrictions at third-party providers
  • Price changes for third-party licences or services
  • Security vulnerabilities in third-party software
  • Changes in AI models that lead to deviating results

(3) If adjustments to the services rendered become necessary as a result of external changes, these shall be remunerated separately at the hourly rate applicable at that time or on the basis of an individual offer.

(4) The Provider expressly points out that, in the course of the provision of services, data of the Client may be transmitted to third-party providers of AI, cloud and communication services. This includes in particular:

  • AI services: Anthropic (Claude), OpenAI (GPT, ChatGPT), Google AI (Gemini, Vertex AI), Microsoft Azure OpenAI, Amazon Bedrock
  • Google Workspace: Gmail, Google Drive, Google Calendar, Google Meet (incl. AI-assisted meeting notes via Gemini), Google Forms, Google Docs, Google Sheets
  • Google Cloud Platform (GCP): Cloud Storage, Compute Engine, Cloud Run, Cloud Functions, BigQuery, Cloud SQL, Firestore, Pub/Sub, Vertex AI, Cloud Logging & Monitoring
  • Amazon Web Services (AWS): S3, EC2, Lambda, RDS, DynamoDB, SQS/SNS/EventBridge, CloudFront, CloudWatch, Bedrock, IAM, KMS, Secrets Manager
  • Microsoft 365: Outlook, Teams, OneDrive, SharePoint, Azure
  • Telephony: Placetel GmbH, Köln (cloud telephone system, server location Germany)
  • Further providers: Meta, Zoom, Stripe, Supabase, Vercel as well as comparable services required in the respective project context

The Provider has no influence on how these third-party providers process or store the transmitted data or use it for their own purposes (including model training). When selecting providers, Sophera Consulting will always choose the option that is most suitable from a data protection perspective (e.g. EU regions, API variants with model training disabled, DPF-certified providers).

(5) The Provider assumes no liability for the data processing carried out by third-party AI providers. This includes in particular:

  • The use of entered data for the training of AI models by the third-party provider
  • The storage, transfer or disclosure of data by the third-party provider
  • Breaches of data protection regulations (GDPR, BDSG) by the third-party provider
  • The unintentional reproduction of Client data in AI-generated outputs for third parties

(6) Before the start of the project, the Client will be informed which AI services are used. It is the responsibility of the Client not to provide any data whose transmission to third-party AI providers is inadmissible for legal, regulatory or contractual reasons (e.g. professional secrets, special categories of personal data pursuant to Art. 9 GDPR).

(7) Insofar as the Client wishes to exclude the use of certain AI services, this must be communicated in writing before conclusion of the contract. Additional costs arising from the use of alternative technologies shall be borne by the Client.

§ 6a Funding advisory service (partner service)

(1) Within the scope of the partner service “funding advisory service”, the Provider refers the Client to external, certified funding advisors (hereinafter “funding partner”). In this respect the Provider acts as an intermediary and not as the provider of the funding advisory service.

(2) The initial consultation (15 minutes) is free of charge and non-binding. Only if the Client decides in favour of further cooperation with the funding partner does a separate contract come into existence between the Client and the funding partner. The Provider is not a party to this contract.

(3) In order to carry out the referral, it is necessary for the Provider to pass on certain personal data of the Client (name, contact details, project description) to the funding partner. This takes place exclusively with the express consent of the Client (cf. privacy policy, section 7.5).

(4) The Provider assumes no liability for the services of the funding partner, in particular not for:

  • the successful approval of funding
  • the correctness of the funding advice
  • compliance with application deadlines by the partner
  • the data processing carried out by the funding partner

(5) The funding partners are selected to the best of the Provider’s knowledge and belief. The Provider verifies the qualification and certification of the partners. No guarantee is assumed for the quality of the partner services.

§ 6b Data processing in connected systems

(1) For the provision of services and the handling of business, the Provider uses various interconnected software systems, in particular:

  • Stripe (Stripe Technology Europe Ltd., Dublin, Ireland) — for the secure handling of online payments by credit card, SEPA direct debit, Apple Pay and Google Pay
  • Lexoffice (Haufe-Lexware GmbH & Co. KG, Freiburg, Germany) — for accounting, invoicing and customer administration
  • Pipedrive (Pipedrive OÜ, Tallinn, Estonia) — for customer relationship management (CRM) and sales management
  • Supabase (EU servers) — as the central database for contact, booking and payment data

(2) These systems communicate with one another automatically. Within the scope of the business relationship, the following data are transmitted between the systems:

  • Contact data (name, email, telephone) — to all systems
  • Customer number — generated by Lexoffice, referenced in all systems
  • Invoice data (amount, project designation, invoice number) — to Stripe and Lexoffice
  • Payment status and payment method — from Stripe to Lexoffice and Pipedrive
  • Project information and deal status — to Pipedrive

(3) All data transfers are encrypted (TLS/HTTPS). The Provider has concluded data processing agreements pursuant to Art. 28 GDPR with all service providers, insofar as this is required. Details on the data processing can be found in the privacy policy (sections 8.11–8.14).

(4) By using the services of the Provider, the Client agrees that its data will be processed in the systems named above, insofar as this is necessary for the performance of the contract or for compliance with statutory obligations.

§ 6c AI-assisted meeting notes (Gemini in Google Meet)

(1) In video conferences via Google Meet, the Provider may use the “AI-assisted meeting notes” function (Google Gemini, Workspace feature “Take notes with Gemini” or “Attend for me”) in order to create a written transcript and a summary of the conversation automatically. The transcripts are stored in Google Drive and may be made accessible to the Client via the Sophera client portal.

(2) Activation takes place exclusively with the express consent of all participants. Before the start of each recording, all persons involved are actively informed and asked for their consent. This corresponds to the requirements of § 201 StGB (German Criminal Code, confidentiality of the spoken word) as well as of the GDPR (Art. 6 (1) (a)). During active transcription, Google Meet displays a visual notice for all participants.

(3) If a participant refuses consent, the recording will not be started or will be ended without undue delay. Refusal of consent entails no disadvantages whatsoever for the conduct of the conversation.

(4) The generated transcripts and summaries are used exclusively for documentation purposes within the scope of the respective consultation. They are not passed on to third parties without renewed consent. At the Client’s request, recordings will be deleted at any time.

(5) The processing of the audio and video data by Gemini takes place in the EU regions of Google, insofar as this is technically possible. In accordance with the Workspace contract terms, Google does not use the transmitted data for the training of generative AI models.

(6) From 2 August 2026, extended transparency obligations under the EU AI Act apply to AI-generated content. From that point in time, AI transcripts and summaries will be labelled accordingly (“AI-generated” pursuant to Art. 50 EU AI Act).

(7) Details on the data processing can be found in the privacy policy, sections 8.1 (Google Workspace incl. Meet) and 8.2 (Google AI / Gemini).

§ 7 Acceptance

(1) In the case of services under a contract for work, the Client is obliged to declare acceptance as soon as the Provider notifies completion and the service has been rendered substantially in conformity with the contract.

(2) Acceptance takes place expressly by written declaration or through conclusive conduct (in particular productive use of the service).

(3) If the Client does not respond within 10 working days of receipt of the notice of completion and does not specify any concrete, material defects, the service shall be deemed accepted (deemed acceptance). The Provider informs the Client of this legal consequence in the notice of completion.

(4) Minor deviations that do not materially impair the functionality do not entitle the Client to refuse acceptance.

(5) If the Client refuses acceptance, it must specify the defects in writing and in concrete terms. The Provider shall be granted a reasonable period for rectification.

§ 8 Remuneration and terms of payment

(1) The remuneration is governed by the respective offer or the individual agreement. All prices stated are in euros plus statutory value added tax unless indicated otherwise.

(2) Invoices are due for payment without deduction within 7 days of receipt unless agreed otherwise.

(3) In the case of larger projects, the Provider is entitled to demand reasonable instalment payments or an advance payment of up to 50 % of the total remuneration.

(4) If the Client is in default of payment, the Provider is entitled to demand default interest of 9 percentage points above the respective base rate of interest (§ 288 (2) BGB) if the Client is an entrepreneur.

(5) In the event of default of payment of more than 14 days, the Provider is entitled to suspend its services until payment has been made in full, without any claims for damages of the Client arising from this.

(6) Set-off against claims of the Provider is permissible only with undisputed or legally established counterclaims.

§ 9 Warranty and remedy of defects

(1) In the case of services under a contract for work, the Provider is liable for defects in accordance with the statutory provisions, subject to the following provisos:

(2) The Client must notify defects in writing without undue delay after discovery, describing the fault in concrete terms. Blanket complaints are not sufficient.

(3) The Provider has the right to rectify the defect. The Provider must be granted at least two attempts at rectification before the Client may assert further rights.

(4) The warranty period is 12 months from acceptance, unless a longer period is mandatorily prescribed by law.

(5) There is no defect if:

  • The fault is attributable to changes to the Client’s system environment for which the Provider is not responsible
  • Third-party systems have been changed or discontinued
  • The Client or third parties have made changes to the service without the consent of the Provider
  • Use takes place contrary to the documentation or instructions

§ 10 Liability

(1) The Provider is liable without limitation for damage arising from injury to life, body or health that is based on an intentional or negligent breach of duty by the Provider, as well as for damage covered by liability under the Product Liability Act.

(2) The Provider is furthermore liable without limitation for damage caused intentionally or by gross negligence.

(3) In the case of slight negligence, the Provider is liable only in the event of a breach of material contractual obligations (cardinal obligations). In this case liability is limited to the damage typical for the contract and foreseeable, but at most to the net remuneration agreed for the respective order.

(4) Liability for indirect damage, consequential damage, lost profit, savings not realised and damage arising from third-party claims is – to the extent legally permissible – excluded.

(5) The Provider is in particular not liable for:

  • Economic decisions of the Client that are taken on the basis of consulting or analyses of the Provider
  • Results or actions of AI systems whose outputs are not deterministic
  • Loss of data, insofar as the Client has not carried out an appropriate data backup
  • Failures or malfunctions of external systems and third-party services
  • Damage arising from late or absent cooperation of the Client

(6) The Client is obliged to take appropriate measures to prevent and mitigate damage, in particular to ensure regular data backups and access control.

§ 11 Support, maintenance and further development

(1) Ongoing support, maintenance, updates and further development are not part of the project services and require a separate contractual agreement (e.g. a service level agreement).

(2) Without a separate agreement, responsibility for the operation, security, updating and functionality of the delivered solutions lies entirely with the Client.

(3) The Provider expressly points out that software and AI systems require regular maintenance and updating in order to maintain functionality and security.

§ 12 Intellectual property and rights of use

(1) All copyrights, intellectual property rights and industrial property rights in the services created by the Provider (concepts, documentation, software, code, workflows, training materials) remain with the Provider.

(2) Upon full payment of the agreed remuneration, the Client receives a simple, non-transferable, non-sublicensable right of use of the contractually agreed services for the agreed purpose.

(3) Until full payment has been made, the Client has no right of use whatsoever. The Provider reserves the right to block access to delivered solutions in the event of default of payment.

(4) Any transfer, publication, sublicensing or other exploitation beyond the agreed purpose requires the express written consent of the Provider.

(5) The Provider is entitled to use the services rendered in anonymised form as a reference in its portfolio unless the Client expressly objects.

(6) The solutions created by the Provider may contain open-source components (e.g. under MIT, Apache 2.0, GPL or comparable licences). On request, the Provider will inform the Client about the open-source components used and their licence terms.

(7) The Client is itself responsible for complying with the respective open-source licence terms, in particular in the case of redistribution, publication or commercial exploitation of the software. The Provider is not liable for breaches of open-source licences by the Client.

(8) Insofar as content is generated by AI systems in the course of the provision of services (texts, code, images, concepts etc.), the Provider points out that the eligibility of such content for copyright protection is unresolved under applicable German law. The Provider gives no warranty that AI-generated content enjoys copyright protection or is free from third-party rights.

(9) A claim to the release of source code exists only if this has been expressly agreed in writing. Without a separate agreement, the Client receives exclusively the compiled or executable versions of the solutions created. A source code escrow arrangement requires a separate agreement.

§ 13 Confidentiality and data protection

(1) Both parties undertake to treat all confidential information of the respective other party obtained in the course of the cooperation as strictly confidential and neither to make it accessible to third parties nor to exploit it in any other way.

(2) This confidentiality obligation continues beyond the end of the contract for a period of 3 years.

(3) Excluded from the confidentiality obligation is information which:

  • is or becomes publicly known without the receiving party being responsible for this
  • was already known to the receiving party before disclosure
  • must be disclosed on the basis of a statutory obligation

(4) Personal data are processed exclusively in accordance with the GDPR and the BDSG (German Federal Data Protection Act). Where necessary, the parties will conclude a data processing agreement (DPA) pursuant to Art. 28 GDPR.

§ 14 Contract term and termination

(1) The contract term follows from the respective individual agreement.

(2) Continuing obligations (e.g. ongoing consulting, support, maintenance) may be terminated ordinarily by either party with a notice period of 30 days to the end of the month unless agreed otherwise.

(3) The right to extraordinary termination for good cause remains unaffected. Good cause exists in particular if:

  • A party breaches material contractual obligations despite a written reminder and the setting of a reasonable deadline
  • Insolvency proceedings are opened over the assets of a party or the opening is refused for lack of assets
  • The Client falls into default of payment of more than 30 days

(4) In the event of termination, services already rendered and expenses incurred must be remunerated without undue delay.

(5) Terminations must be made in writing (email is sufficient).

§ 15 EU AI Act (Regulation (EU) 2024/1689) and regulatory requirements

(1) The Provider renders its services taking into account the regulatory requirements applicable at the time the services are rendered, in particular Regulation (EU) 2024/1689 (“EU AI Act”).

(2) Responsibility for compliance with regulatory obligations that are incumbent on the deployer of an AI system lies exclusively with the Client. This includes in particular:

  • The risk classification of the AI system used (prohibited, high-risk, limited, minimal)
  • Compliance with transparency obligations towards the persons concerned (e.g. labelling of AI-generated content)
  • Carrying out a fundamental rights impact assessment for high-risk AI systems
  • Human oversight of AI-assisted decision-making processes
  • The registration of high-risk AI systems in the EU database

(3) The Provider supports the Client on request in assessing regulatory requirements. This does not constitute the provision of legal advice. The Provider recommends that the Client consult a specialist lawyer for the legal assessment.

(4) Changes to regulatory requirements that come into force after the services have been rendered do not establish any claim to rectification. Any necessary adjustments must be remunerated separately.

§ 15a AI outputs, hallucinations and the Client’s duty to review

(1) AI systems may output content that is factually incorrect, incomplete, outdated or invented (so-called “hallucinations”). This is a characteristic inherent in generative AI models at the current state of the art and does not constitute a defect in the services of the Provider.

(2) All AI-generated outputs (texts, code, analyses, proposed decisions, forecasts) are non-binding work results. The Client is obliged to review these in terms of content and subject matter through qualified personnel before productive or business-critical use (“human-in-the-loop” principle).

(3) Human control is mandatory in particular for the following applications:

  • Decisions with legal effect towards third parties (e.g. conclusions of contracts, reminders, terminations)
  • Medical, tax, legal or financial information provided to end customers
  • Automated messages to customers, suppliers or authorities
  • Publication of content (website, social media, advertising)
  • Execution of security-relevant scripts or code deployments in production systems

(4) The Provider is not liable for damage arising from the unreviewed adoption of AI-generated outputs, unless there is statutory liability for intent or gross negligence.

(5) Labelling obligation: The Client is obliged to label AI-generated content that is published to end users accordingly, in accordance with the transparency obligations of the EU AI Act (Art. 50).

(6) Data quality: The Client ensures that the input data transmitted to AI systems have been collected lawfully and do not infringe any copyright, personality or confidentiality rights of third parties. The Client indemnifies the Provider against third-party claims arising from breaches of this obligation.

§ 16 Remote maintenance and remote access

(1) Insofar as remote access to systems of the Client is required for the provision of services, the Client shall provide the necessary access (VPN, SSH, API keys etc.).

(2) The Provider uses the access provided exclusively for the contractually agreed purposes and does not pass on access credentials to unauthorised third parties.

(3) The Client is responsible for the security of its own systems, in particular for:

  • The establishment of appropriate access restrictions (principle of least privilege)
  • The monitoring and logging of access
  • The withdrawal of access credentials after the end of the contract

(4) The Provider is not liable for damage arising from inadequate security measures on the part of the Client.

§ 17 Data retention and deletion after the end of the contract

(1) After termination of the contract, the Provider retains project-related data and documents for a period of 90 days, unless statutory retention obligations (e.g. pursuant to § 257 HGB (German Commercial Code), § 147 AO (German Fiscal Code)) require longer retention.

(2) Within this period the Client has the right to demand the release of its data in a machine-readable format. After expiry of the period, the data will be irrevocably deleted unless a statutory retention obligation exists.

(3) Personal data are deleted in accordance with Art. 17 GDPR as soon as the purpose of the processing ceases to apply and no statutory retention obligations conflict with this.

(4) The Provider confirms the deletion in writing at the request of the Client.

§ 18 Force majeure

(1) Neither party is liable for non-performance or delayed performance of its contractual obligations to the extent that this is attributable to circumstances of force majeure.

(2) Force majeure is deemed to include in particular: natural disasters, pandemics, strikes, official orders, cyberattacks, large-scale power outages or failures of essential cloud infrastructure.

§ 22 Client portal

(1) Purpose and range of functions. The Sophera client portal (hereinafter “Portal”) enables registered Clients to access project-related functions, in particular: overview and management of ongoing projects, appointment booking and meeting minutes, download of catalogues and project documents, release approval of project documents, team management (invitation of further users), payment processing (credit card, SEPA via Stripe), access to roadmaps and project status.

(2) Access requirements. Use of the Portal presupposes an existing business relationship. Portal access is activated by the Provider and takes place via password-protected accounts. The Client is obliged to keep access credentials secret and not to pass them on to third parties. If misuse is suspected, the Provider must be informed without undue delay.

(3) Consent before first use. Before using the Portal for the first time, every user (owner, administrator or member) must expressly accept the Portal GTC as well as the privacy policy in their respective current version. Consent is logged in an audit-proof manner with time stamp, version, IP address and user agent.

(4) User roles and liability of the owner. Within the client portal, the Provider distinguishes three Client-internal roles:

  • Owner: primary contact person at the Client (e.g. management), full rights within the Client account
  • Administrator: further person at the Client with invitation and approval rights
  • Member: Client-internal employees with read rights and document download

The Provider (Sophera Consulting) is not part of this Client-internal role structure, but administers the Portal via a separate administrative interface (admin dashboard). The owner (on the Client’s side) is liable for all actions of the team members invited by the owner or by the owner’s administrators pursuant to § 278 BGB (vicarious agents).

(5) Team invitations. The owner or an administrator may add further team members by email invitation. The invited person must consent to the use of the Portal and to the data processing independently. The owner ensures that invited persons are authorised to process company-related data.

(6) Payment processing via the Portal. Payments are processed via the payment service provider Stripe (Stripe Technology Europe Limited, Dublin, Ireland). The Client may store payment methods in the Portal; tokenisation takes place directly at Stripe — the Provider does not receive complete card or account details. Billing takes place in accordance with the respective contract; invoices are additionally sent by email. § 8 (remuneration and terms of payment) remains unaffected.

(7) Document release (release feature). Project documents that the Provider releases for final download must be actively confirmed by the Client. By confirming, the Client declares acceptance of the relevant part of the work pursuant to § 640 BGB.

(8) Availability. The Provider endeavours to achieve Portal availability of 99 % on an annual average, however without contractual assurance. Maintenance windows will be announced in advance where possible. Short outages do not give rise to any claim to rescission of the contract or to damages, unless the Provider acts intentionally or with gross negligence.

(9) Portal deactivation by the Provider. The Provider may deactivate the Portal account of a Client upon the end of the business relationship (90 days grace period), in the event of default of payment of more than 30 days or in the event of misuse of the Portal (e.g. passing on of access credentials). Upon deactivation, data will be deleted or archived in accordance with § 17 and the privacy policy.

(10) Termination of Portal access by the Client. The Client may terminate Portal access in writing at any time by email to fey@sopheraconsulting.de. This leads to deactivation of the account; the underlying business relationship remains unaffected by this.

(11) Roadmaps. The Provider makes project roadmaps available in the Portal that visualise the planned course of the project, milestones and delivery dates. Roadmap entries constitute a non-binding planning aid and have no binding character with regard to specific delivery dates, unless these have been separately agreed in writing as fixed dates (cf. § 4 (4)). Changes to roadmaps are presented transparently to the Client in the Portal; there is no claim to the retention of a previously displayed plan.

(12) Data protection. Details on the data processing in the Portal are governed by section 8.15 of the privacy policy.

(13) Exclusion of liability for use of the Portal. § 10 (liability) applies accordingly to the use of the Portal. To the extent legally permissible, the Provider additionally excludes any liability for the following Portal-specific risks:

  • Incorrect operation by users: Loss of data or malfunctions arising from incorrect operation of the Portal by the Client or its team members (e.g. accidental deletion of documents, misconfigurations, faulty document releases).
  • Passing on of access credentials: Damage arising from the unauthorised passing on of Portal passwords, email access or session cookies by the Client or its team members.
  • Content uploaded by the Client: Damage and third-party claims arising from content that the Client or its team uploads to the Portal, including infringements of copyright, personality, data protection or confidentiality rights. In this respect the Client indemnifies the Provider against third-party claims.
  • Payment processing via Stripe: Damage arising from the payment processing itself (debiting errors, chargebacks, cases of fraud, disruptions of the Stripe service). In this respect Stripe is an independent controller; liability is governed by the terms of use of Stripe.
  • Third-party provider failures: Disruptions, outages, loss of data or security incidents at the infrastructure service providers used by the Provider (Supabase, Vercel, Google, AWS, Stripe and others), unless these are based on intentional or grossly negligent conduct of the Provider in their selection or monitoring.
  • Interruptions of availability: The availability of 99 % on an annual average referred to in paragraph (8) constitutes a non-binding target figure. Short outages, maintenance windows or delayed performance do not give rise to claims for damages.
  • Consequential damage from roadmap planning: Roadmaps are non-binding planning aids (cf. paragraph 11). Economic dispositions of the Client on the basis of Portal roadmaps are made at the Client’s own risk.
  • AI-generated content in the Portal: Transcripts, summaries and analyses created by AI systems (e.g. Gemini meeting notes) are non-binding work results. § 15a of these GTC (AI outputs, hallucinations and the duty of the Client to review) applies.
  • Data portability after Portal deactivation: After expiry of the 90-day grace period (paragraph 9), the Provider is no longer liable for the availability of data that has not been exported. The Client is obliged to request its data export in good time.

(14) Maximum liability limit for use of the Portal. Insofar as the Provider is liable for slight negligence, liability for all damage in connection with the use of the Portal is limited per calendar year to the damage typical for the contract and foreseeable, but at most to the amount that the Client actually paid for Portal-related services of the Provider in the relevant calendar year. If the Portal is provided free of charge (free additional feature), the Provider is not liable in the case of slight negligence (§ 521 BGB by analogy). Unlimited liability in the case of intent, gross negligence, injury to life, body or health and under the Product Liability Act remains unaffected; in this respect § 10 (1) and (2) of these GTC apply.

§ 19 Applicable law

(1) The law of the Federal Republic of Germany applies exclusively, to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG) and to the exclusion of private international law.

(2) This also applies to Clients domiciled abroad.

§ 20 Place of jurisdiction

(1) The exclusive place of jurisdiction for all disputes arising from or in connection with the contractual relationship is – to the extent legally permissible – 50126 Bergheim (Rhein-Erft-Kreis), Germany.

(2) This agreement on the place of jurisdiction also applies to Clients domiciled abroad, to the extent legally permissible.

§ 21 Severability clause

(1) Should individual provisions of these GTC be or become invalid in whole or in part, the validity of the remaining provisions shall remain unaffected by this.

(2) In place of the invalid provision, that valid arrangement shall apply which comes closest to the economic purpose of the invalid provision. The same applies to any gaps in the contract.

(3) Amendments and supplements to these GTC must be made in writing. This also applies to the amendment of this written form clause.