Terms of Service
Effective: July 2026 — These Terms of Service ("Terms") apply between Cyber-Sec.IT GbR ("Provider") and the respective customer ("Customer") for the use of the Security Awareness Platform ("Platform"). Deviating terms of the Customer are not accepted.
Note: The legally binding version of these Terms is the German version above. This English translation is provided for convenience only.
1. Subject Matter and Service Description
1.1 The Provider grants the Customer access to a web-based platform for security awareness training and phishing simulations. The scope of functions is defined by the service description valid at the time of contract conclusion as displayed on the website.
1.2 The Customer selects a usage package with a defined maximum number of users at contract conclusion. Exceeding this limit entitles the Provider to require the Customer to upgrade to a higher package or to restrict access.
1.3 The Provider delivers the service according to the state of the art. No specific availability or freedom from errors is owed unless expressly agreed in writing. The Provider endeavors to resolve disruptions as quickly as possible.
1.4 The Provider is entitled to further develop, adapt, or modify platform features at any time, provided the contractually agreed core functionality is maintained.
1.5 Exclusive B2B Service Offer. The service offer is directed exclusively at business entities within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law, or special funds under public law. Entering into a contract with consumers within the meaning of Section 13 BGB is excluded.
2. Contract Conclusion
2.1 The offers displayed on the website constitute a non-binding invitation to the Customer to submit an offer for contract conclusion.
2.2 The contract is concluded when the Customer completes the payment process via the payment service provider Stripe and subsequently fills out and submits the onboarding form on the Platform. The Customer receives confirmation by email.
2.3 The Customer warrants that all information provided during contract conclusion is true and complete. Providing a valid business email address and the correct Microsoft 365 tenant ID is mandatory.
3. Customer Obligations — Permitted and Prohibited Use
3.1 The Customer undertakes to use the Platform exclusively for the agreed purpose — security awareness training and phishing simulations within its own organization.
3.2 Expressly prohibited is any use of the Platform capable of harming, deceiving, or harassing third parties, in particular:
- Sending phishing simulations to persons outside the Customer's own organization;
- Using the Platform for actual phishing attacks, fraud, social engineering, or other unlawful activities;
- Use under a false identity or by misrepresenting a non-existent company affiliation;
- Spying, scraping, or automated extraction of the Platform;
- Reverse engineering, decompilation, or manipulation of the Platform software;
- Sharing access credentials with unauthorized third parties;
- Any use that violates applicable law, including criminal law, data protection law, or unfair competition law.
3.3 The Customer is solely responsible for obtaining necessary consents from its employees to carry out phishing simulations and to process personal data within the scope of Platform use. The Customer indemnifies the Provider against all third-party claims arising from a breach of this obligation.
3.4 The Customer is obliged to keep its access credentials and those of its users confidential and to protect them from unauthorized access. The Customer is liable for all activities occurring under its account.
3.5 In the event of a breach of the above obligations, the Provider is entitled to block the Customer's access to the Platform with immediate effect and to terminate the contract without notice. Fees already paid will not be refunded in this case. The Provider's claims for damages remain unaffected.
3.6 The Customer is obliged to inform the Provider immediately upon becoming aware of any misuse of its account or a security breach.
3.7 Technical Preparation of the Microsoft 365 Environment. Phishing simulation emails are delivered via the Microsoft Graph API within the Customer's own Microsoft 365 tenant. The Customer is responsible for technically preparing its tenant, in particular:
- Creating and configuring a dedicated sender mailbox account;
- Setting up whitelisting or allow-list rules to ensure deliverability of simulations and to prevent false positives from third-party filters;
- Ensuring that simulation emails are not redirected, blocked, deleted, or duplicated by transport rules, connector rules, or other automated processes in the tenant;
- Verifying that third-party security solutions (e.g. Proofpoint, Mimecast, Cisco Email Security) are compatible with the simulations and do not process them in an unintended manner.
The Provider assumes no liability for damages resulting from inadequate technical preparation of the tenant.
4. Fees and Payment Terms
4.1 Use of the Platform is subject to a fee. The amount of the fee depends on the package selected by the Customer and is stated on the website. All prices are exclusive of applicable statutory VAT.
4.2 Billing is conducted as a recurring subscription (Abo) in advance (monthly or annually depending on the selected plan). The Customer pays the fee for the first billing cycle immediately upon contract conclusion via the payment service provider Stripe. For subsequent cycles, the fee is automatically charged at the beginning of each new billing period via the payment method registered with Stripe.
4.3 Payment processing is carried out exclusively via Stripe Payments Europe, Ltd. Stripe's terms of use apply. The Provider does not store any payment data (credit card details, bank details) on its own servers.
4.4 The Customer is not entitled to set off its own claims against the Provider's fee claim unless the counterclaim is undisputed or has been finally adjudicated.
5. Term and Cancellation
5.1 The contract is concluded for an indefinite period and has a minimum term of one year from the date of contract conclusion (unless explicitly agreed otherwise for the selected plan).
5.2 The contract automatically renews for a further year unless terminated with one month's notice before the end of the respective contract year.
5.3 Cancellation may be submitted at any time in text form (email sufficient) or directly online via the Customer Self-Service Portal ("Cancellation Button" / Subscription Settings in the Dashboard). Early termination before expiry of the minimum term is excluded. Payments already made will not be refunded on a pro-rata basis upon termination — for whatever reason.
5.4 The right to extraordinary termination for good cause remains unaffected for both parties. Good cause for the Provider exists in particular in the event of a breach of Section 3.2 of these Terms by the Customer.
6. Liability
6.1 The Provider is fully liable for intent and gross negligence, for injury to life, body, and health, in accordance with the provisions of the Product Liability Act, and for the assumption of an express guarantee.
6.2 In the event of simple negligent breach of a material contractual obligation (cardinal obligation), the fulfillment of which is essential to the proper performance of the contract and on which the Customer may regularly rely, the Provider's liability is limited to the typically foreseeable damage, but at most to the fees paid by the Customer in the twelve months preceding the damaging event.
6.3 Any further liability of the Provider is excluded. In particular, the Provider is not liable for:
- Indirect damages, consequential damages, or lost profits;
- Damages arising from the unavailability of the Platform;
- Damages resulting from the execution of phishing simulations — including but not limited to business interruptions, reputational damage, or psychological stress of individual employees;
- Damages arising from the technical delivery of simulation emails via the Microsoft Graph API — in particular through interactions with customer-side email rules, transport rules, connector configurations, third-party filters, forwarding, automatic replies (auto-reply), or other automated processing mechanisms within the Customer's Microsoft 365 tenant;
- Damages caused by unauthorized third-party access to the Customer account, provided the Customer has breached its duty of care under Section 3.4;
- Data losses, unless caused by the Provider's intent or gross negligence.
6.4 The limitations of liability also apply in favor of the Provider's legal representatives, employees, and agents.
6.5 The Customer acknowledges that IT services can never be provided completely error-free or without interruption and that phishing simulations by their nature involve a certain degree of unpredictability. The Customer further acknowledges that simulation emails are delivered via the Microsoft Graph API within its own tenant and that the Provider has no influence over tenant-specific configurations, third-party integrations, or API limits imposed by Microsoft.
7. Data Protection
7.1 The Provider processes personal data of the Customer and its users exclusively within the framework of the Privacy Policy and applicable data protection laws, in particular the GDPR.
7.2 The Privacy Policy is available at this link and forms an integral part of these Terms.
8. Intellectual Property Rights
8.1 All rights to the Platform, the underlying software, templates, landing pages, graphics, texts, and other content remain with the Provider or its licensors.
8.2 The Customer receives a non-exclusive, non-transferable right to use the Platform, limited to the contract term.
9. Changes to the Terms
9.1 The Provider is entitled to amend these Terms with future effect where this is necessary for valid reasons, in particular due to changes in the law, technical changes to the Platform, new features, or to close regulatory gaps.
9.2 Amendments will be notified to the Customer in text form (email) at least six weeks before they take effect. The Customer may object within this period. If no objection is made, the amended Terms are deemed accepted. The notification will expressly inform the Customer of the right to object and the consequences of failing to object. If the Customer objects, the Provider has the right to terminate the contract as of the date the amendment takes effect.
10. Final Provisions
10.1 This contract is governed exclusively by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
10.2 If the Customer is a merchant, a legal entity under public law, or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from this contract is Wetzlar, Germany. However, the Provider is entitled to sue the Customer at its general place of jurisdiction.
10.3 Should any provision of these Terms be or become invalid, this shall not affect the validity of the remaining provisions. The invalid provision shall be replaced by a valid provision that comes as close as possible to the economic purpose of the invalid provision. The same applies to any regulatory gaps.
10.4 All declarations under this contract require text form unless otherwise specified. Email satisfies the text form requirement.
© 2026 Cyber-Sec.IT GbR. All rights reserved.