Version 1.1 · 2026-07-24
Terms of Service — SecurApp
§ 1 Scope and Parties
(1) These Terms of Service ("Terms") govern the use of the web application SecurApp ("Service"), operated by:
[Provider — full company name or individual's name]
[Address]
[Postcode] [City], Germany
E-mail: [e-mail]
("Provider")
(2) Users ("User", used in a gender-neutral sense for all genders) are exclusively natural persons using the Service for private purposes within the meaning of § 13 of the German Civil Code (BGB). Use by companies, law firms or other legal entities is subject to separate agreements.
(3) Conflicting terms and conditions of the User shall not apply unless the Provider has expressly agreed to their applicability in writing.
§ 2 Formation of Contract and Registration
(1) The usage contract is formed when the User completes the registration form, expressly accepts the version of these Terms identified there, and the Provider accepts the registration by sending a confirmation e-mail. The Privacy Notice is provided as information; it is not consent and is not “accepted" as a contractual term.
(2) Registration requires: a valid e-mail address and a password (minimum 12 characters). Providing a real name is not mandatory; the use of a pseudonym is permitted.
(3) The User is obliged to keep their login credentials confidential and not to share them with third parties. In the event of suspected misuse, the Provider must be notified immediately.
(4) By registering, the User confirms they are at least 16 years of age. Use by minors under 16 is not permitted. [Legal review required: age threshold and whether age verification is actually required.]
§ 3 Description of Services
(1) SecurApp is a technical tool (not a legal services provider) that assists private individuals in exercising their rights under the General Data Protection Regulation (GDPR). Services provided in the MVP scope include:
- Provision and management of a user account with secure login (e-mail/password, optional two-factor authentication).
- Management of a "Digital Twin" for the structured storage of the User's personal data, used exclusively to pre-fill GDPR request letters.
- Generation of standardised GDPR request letters for Art. 15 (access), Art. 17 (erasure), Art. 21 (objection) GDPR.
- Sending generated requests by e-mail to the company selected by the User.
- Routing of company replies via a reply alias system.
- Deadline management and reminders as non-binding guidance: Art. 12(3) GDPR generally requires a response without undue delay and within one month; an extension by up to two further months may be available under the conditions stated there.
- Integrity-protected document archive for sent requests and received replies.
- Access to a curated company directory with data protection contacts.
(2) Further features (AI assistant, privacy score, law firm referral, partner API) are not part of the MVP and will be provided in later phases.
(3) The Provider makes the Service available as Software-as-a-Service via the internet. No guaranteed availability level or service level agreement applies in the context of the free MVP unless otherwise agreed. [Legal review required: SLA formulation for future paid tiers.]
(4) The User initiates each dispatch and first checks the content, their own information and the recipient. SecurApp technically transmits the request from a SecurApp sender address with a request-specific reply alias. SecurApp does not act as the User's lawyer, authorised agent or representative, does not verify the User's identity and makes no statement to the recipient that identity verification has been completed. The recipient company may request additional proportionate information to verify identity.
(5) Replies and attachments from the recipient company may arrive through the reply alias, be assigned to the request, undergo security checks and be made available in the archive. Malware scanning reduces risk but does not guarantee that a file is harmless. Replies uploaded manually originate from the User; SecurApp does not confirm their origin or evidential value.
§ 4 No Substitute for Legal Advice — No Legal Services
(1) SecurApp is a technical aid and not a legal services provider within the meaning of the German Legal Services Act (RDG). The Provider does not provide legal advice, legal information or any other legal service within the meaning of § 2 RDG.
(2) The letters and templates generated by the app are based on legally reviewed standard texts. They are, however, general in nature and do not take into account the individual circumstances of a specific case. It is expressly recommended to seek legal advice in legally complex situations, when a request is refused by a company, or before initiating legal proceedings.
(3) Information and explanations provided by the Service are for general informational purposes only and do not constitute binding legal advice.
§ 5 Disclaimer for Templates and Request Outcomes
(1) The Provider maintains the GDPR request templates with reasonable care and updates them when relevant statutory or regulatory changes occur. No guarantee is given that:
- a generated request will be recognised by the addressed company as complete or legally sufficient;
- the addressed company will respond within the statutory deadline or at all;
- the exercise of a GDPR right will lead to the desired outcome (e.g. erasure, access, acknowledgement of an objection).
(2) The Provider is not liable for damages arising from a company ignoring, refusing or responding adversely to a generated request.
(3) The Service facilitates the exercise of rights but does not guarantee their enforcement.
§ 6 Limitation of Liability
(1) The Provider is fully liable under statutory law for damages arising from injury to life, body or health, and for damages based on intentional or grossly negligent conduct by the Provider or its vicarious agents.
(2) For slightly negligent breaches of material contractual obligations (cardinal obligations), liability is limited to the foreseeable damage typical for this type of contract. Material contractual obligations are those whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the User may rely.
(3) Any further liability for slightly negligent breaches of duty is excluded.
(4) The above limitations do not apply to claims under the German Product Liability Act (ProdHaftG) or where a defect was fraudulently concealed.
[Legal review required: Liability clause vis-à-vis consumers; review under §§ 307 et seq. BGB.]
§ 7 User Obligations
(1) The User is obliged to use the Service exclusively for lawful purposes. In particular, the following are prohibited:
- using the Service for abusive, mass or harassing GDPR requests;
- entering third parties as the sender of GDPR requests without their consent;
- using the Service to attack, compromise or overload the Provider's or third parties' systems;
- conducting automated access without the Provider's express permission.
(2) The User is solely responsible for the content of data entered in the Digital Twin. The User ensures that the data entered relates to their own person and contains no unlawful content.
(3) The User must notify the Provider immediately of any change to their e-mail address.
§ 8 Termination, Data Export and Erasure
(1) The User may delete their account at any time without notice via the account settings. Deletion terminates the usage contract.
(2) Before account deletion, the User is advised that all archived documents will be permanently deleted and is recommended to download a ZIP export of all archive data (Art. 20 GDPR — data portability). The ZIP export includes all sent PDFs, received EML files and a machine-readable index (JSON).
(3) Following account deletion, personal data are removed from active primary systems in accordance with the erasure cascade described in the Privacy Notice. A transition period of up to 30 days is currently planned for archive objects. Encrypted backup generations may persist until their rolling 35-day lifecycle expires; they are used only for disaster recovery and erasure operations must be re-applied after a restore. [Legal review required and to be finalised under LEGAL-03.] Data treated separately or excepted include:
- Minimised audit factual records (actor ID, IP hash and user agent are removed and the target ID is generalised; period and legal basis require approval under
LEGAL-03— see Privacy Notice Section 4.7 and § 9 of these Terms). - Data whose retention is required by law.
(4) The Provider may terminate the usage contract for good cause without notice, in particular if the User breaches the obligations set out in § 7. Upon termination by the Provider, the User's data are handled pursuant to the Privacy Policy.
§ 9 Data Protection
The processing of the User's personal data by the Provider is explained in the Privacy Notice available at /legal/datenschutz. It is privacy information, not a consent declaration. It explains in particular:
- Categories of data processed, purposes and legal bases;
- Processors (Resend for e-mail, Hetzner for hosting, storage and key management);
- Retention periods, the erasure cascade and time-limited backup exceptions;
- User rights as a data subject (Art. 15–21 GDPR, Art. 7(3) GDPR, Art. 77 GDPR).
§ 10 Availability and Technical Changes
(1) The Provider is entitled to change, expand or discontinue the Service at any time. In the event of material reductions to the scope of services, registered users will be notified at least 30 days in advance, to the extent technically and legally possible. [Legal review required: Applicability to consumers under free service arrangements.]
(2) The User is responsible for ensuring the technical prerequisites for using the Service (internet connection, browser, operating system).
§ 11 Dispute Resolution
The Provider is [neither obligated nor willing / or: willing — please select and specify the relevant body if applicable — legal review required] to participate in dispute resolution proceedings before a consumer arbitration board. The former EU online dispute resolution platform was discontinued on 20 July 2025 and is therefore not linked.
§ 12 Governing Law and Jurisdiction
(1) These Terms are governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). Mandatory consumer protection provisions of the User's country of residence remain unaffected.
(2) The place of jurisdiction for all disputes arising from this contract is — to the extent permitted by law — [provider's location]. [Legal review required: Jurisdiction clause is generally unenforceable against consumers under German law; consumers may bring claims before their local court.]
§ 13 Final Provisions
(1) Should any provision of these Terms be or become wholly or partially invalid, the validity of the remaining provisions shall not be affected. The invalid provision shall be replaced by the legally permissible provision that most closely reflects the economic purpose of the invalid provision.
(2) The Provider reserves the right to amend these Terms with at least 30 days' notice. Amendments will be communicated to registered users by e-mail. If the User does not object within 30 days of receiving the notification, the amended Terms shall be deemed accepted. The notification will expressly advise of this consequence. If the User objects, the Provider is entitled to terminate the contractual relationship as of the date the changes take effect. [Legal review required: Amendment clause vis-à-vis consumers, § 309 No. 1 BGB.]
(3) No verbal collateral agreements exist.
*Version 1.1 | 2026-07-24 | Product/privacy-counsel approval pending*