Terms and Conditions for Managed/Hosted Applications

including a data processing agreement pursuant to Article 28 of the GDPR

As of July 21, 2026

For business owners only: These terms and conditions do not apply to consumers.

Part A – General Terms and Conditions

1. Provider, Scope, and Definitions

The provider is Tim Schnarr, operating under the business name LimesGroup® and its brand LimesTec®, Gotenstraße 26, 61352 Bad Homburg v. d. Höhe, email: , phone: +49 (0)6172 671708 (hereinafter “LimesTec” or “Provider”).

These General Terms and Conditions apply to the provision and support of web-based applications that LimesTec operates for a customer on its own or leased hosting infrastructure (hereinafter “Managed/Hosted Application”). The specific scope of services is set forth in the order, the service description, and the invoice or order confirmation.

These terms and conditions apply exclusively to business entities as defined in Section 14 of the German Civil Code (BGB), legal entities under public law, and special funds under public law. Contracts with consumers are not concluded on this basis.

Any terms and conditions of the customer that differ from these shall apply only if LimesTec has expressly agreed to them in writing. Individual agreements and the details of the accepted order take precedence over these terms and conditions.

2. Order and Conclusion of the Contract

The presentation of services on a website does not constitute a binding offer by LimesTec. By submitting the order form, the customer makes a binding offer to enter into a contract for the services they have selected.

The contract is concluded as soon as LimesTec confirms the order in writing, begins the custom setup of the ordered application, makes the application available to the customer, or issues an invoice for the ordered services—whichever occurs first.

The Terms and Conditions accepted by the customer upon submission of the order, including the agreement on order processing contained therein, shall become an integral part of the contract and shall continue to govern the contractual relationship.

An invoice issued by LimesTec also serves as confirmation of acceptance of the order, unless the contract has already been concluded.

3. Subject Matter of the Contract and Scope of Services

LimesTec makes the ordered managed/hosted application available to the customer for use during the term of the contract and provides the agreed-upon technical setup and support. If agreed upon, the application is operated under a customer-specific domain or subdomain and with a technically separate database or instance.

The Company is obligated solely to provide the functions and services specified in the order or service description. The Company is not obligated to provide any custom development, data migration, training, content maintenance, legal reviews, process consulting, or integrations with third-party systems that have not been expressly agreed upon.

LimesTec does not guarantee any specific economic, legal, or practical success for the customer. The customer is solely responsible for determining whether the application is suitable for its purposes and legal requirements.

LimesTec may use appropriate hosting, infrastructure, email, backup, maintenance, and support service providers to deliver its services. Subcontracting relationships under data protection law are governed by Part B of these Terms and Conditions.

4. Right of Use and Technical Requirements

For the term of the agreement, the customer is granted a simple, non-exclusive, non-transferable, and non-sublicensable right to use the provided application to the agreed extent for its own business purposes.

There is no entitlement to receive the source code, an installable copy of the program, or the underlying development, server, or administration environment.

The customer may not circumvent technical protection measures, perform security checks without prior consent, reverse-engineer the application, or make it available to third parties outside the agreed-upon user group, unless permitted by mandatory law.

Domains, subdomains, certificates, interfaces, and third-party services are provided only to the extent agreed upon. The rights and technical specifications of the respective third-party providers remain unaffected.

5. Scope of Responsibility and Obligations of the Customer

The customer is solely responsible for the content and data entered, stored, published, sent, or otherwise processed by the customer or its users, as well as for the accuracy, completeness, and legality of such content and data.

In particular, the customer shall ensure that its use complies with data protection, copyright, trademark, competition, consumer, tax, record-keeping, and other regulations applicable to it. LimesTec does not provide legal advice and does not review customer content without a separate request.

The customer is solely responsible for managing its users, roles, and permissions; protecting login credentials from unauthorized access; and promptly notifying LimesTec of any suspected security incidents or unauthorized use.

The customer may not use the application to host any content or processes that are illegal, offensive, discriminatory, misleading, contain malicious code, or pose a security risk.

The customer shall indemnify LimesTec against any claims by third parties, including reasonable legal defense costs, to the extent that such claims arise from unlawful use for which the customer is responsible, from customer content, or from a breach of the customer’s obligations. This shall not apply if LimesTec is itself responsible for the claim.

6. Operation, Maintenance, and Availability

LimesTec provides the application to the extent permitted by technical and operational capabilities. A specific level of uninterrupted availability, response time, or recovery time is only guaranteed if it has been expressly agreed upon.

In particular, the following shall not be considered downtime for which LimesTec is responsible: announced or necessary maintenance, security, and update work; disruptions within the customer’s area of responsibility; Internet outages or outages caused by third-party providers; force majeure; cyberattacks despite appropriate protective measures, and restrictions implemented to mitigate specific security risks.

LimesTec may update the application and its technical environment, adjust security measures, and make technically necessary changes, provided that the agreed-upon core functions are not materially impaired. Significant foreseeable restrictions will be announced, to the extent reasonably possible.

To the extent that data backups are agreed upon or technically implemented, they are intended for business recovery purposes. They do not replace audit-compliant archiving and do not relieve the customer of its own legal obligations regarding data retention and backup.

7. Support and Participation

The type, scope, and method of communication for support are specified in the service description or order. Unless a response time has been agreed upon, LimesTec processes inquiries during normal business hours based on urgency and availability.

The customer shall describe malfunctions in a clear and understandable manner and provide all information necessary for analysis. If the customer fails to provide the necessary cooperation, service and response times will be extended accordingly.

Any additional work beyond the agreed scope of services may be billed separately, provided prior notice is given.

8. Compensation, Invoices, and Late Payments

Fees, billing intervals, and any setup or additional costs are specified in the order, service description, or invoice. All prices are exclusive of applicable sales tax, if any.

Invoices are due for payment without deduction within 14 calendar days of the invoice date, unless otherwise agreed.

In the event of late payment, the statutory provisions shall apply. LimesTec may temporarily suspend access—following a prior reminder and the setting of a reasonable deadline—if the customer is in arrears for a significant amount. The obligation to pay remains in effect to the extent that the suspension was justified.

9. Data Protection and Incorporation of the AVV

Each party is responsible for fulfilling its own data protection obligations.

To the extent that LimesTec processes personal data on behalf of the customer as part of the services ordered, Part B of these Terms and Conditions shall serve as a data processing agreement pursuant to Article 28 of the GDPR. By accepting these Terms and Conditions, the parties simultaneously enter into the data processing agreement contained therein. A separate signature is not required.

In the event of any conflict, Part B shall take precedence over the other provisions of these Terms and Conditions with respect to issues related to data processing on behalf of the client.

10. Defects

The customer shall report reproducible defects immediately, providing a clear description of the defect. LimesTec shall be given the opportunity to inspect the defect and remedy it within a reasonable period of time.

A defect does not exist if a limitation is due to unauthorized use, unsuitable customer systems, modifications made by the customer or third parties, unsupported interfaces, or circumstances beyond LimesTec’s control.

The customer’s statutory rights remain unaffected in all other respects.

11. Liability

LimesTec bears unlimited liability in cases of willful misconduct and gross negligence, for damages resulting from injury to life, limb, or health, for fraudulent concealment of a defect, for the assumption of a warranty expressly designated as such, and in accordance with mandatory statutory provisions.

In the event of a breach of a material contractual obligation due to simple negligence, LimesTec shall be liable only for damages typical of the contract and foreseeable at the time the contract was concluded. Material contractual obligations are obligations whose fulfillment is essential for the proper performance of the contract and on whose compliance the customer may reasonably rely.

In all other respects, liability for ordinary negligence is excluded. To the extent that liability applies pursuant to the preceding paragraph, liability for each claim is limited to the net compensation paid by the customer during the twelve months preceding the occurrence of the loss. If the contract term is shorter, the net compensation paid up to the date of the loss-causing event shall be decisive.

To the extent permitted by law, LimesTec shall not be liable for indirect or consequential damages, lost profits, lost savings, or data loss if and to the extent that the customer could have prevented the damage by taking reasonable backup, export, or recovery measures of its own.

The foregoing liability provisions apply mutatis mutandis to the legal representatives, employees, and agents of LimesTec.

12. Blocking

LimesTec may temporarily restrict or suspend access if this is necessary to avert a specific threat to security or stability, due to legal or regulatory requirements, in the event of significant unlawful use, or in the event of a serious breach of contract.

LimesTec takes the customer’s legitimate interests into account and, to the extent legally and practically possible, informs the customer in advance or immediately after the action is taken.

13. Term, Termination, and Data After the Contract Ends

The term and notice period are specified in the order or service description. If no fixed term or notice period is specified therein, the contract is for an indefinite term and may be terminated by either party with four weeks’ notice to the end of the month.

The right to terminate the contract for cause remains unaffected. For LimesTec, cause includes, in particular, serious unlawful use, a significant threat to the application, or repeated significant delays in payment.

The customer is required to back up the data they need before the end of the contract using the export options provided. To the extent technically feasible and provided there are no legal or security-related reasons preventing it, LimesTec will make the customer’s data available for retrieval for up to 30 days after the end of the contract. Additional migrations or custom exports may be billed separately.

After the retention period expires, data will be deleted or anonymized in accordance with Part B and statutory retention requirements.

14. Confidentiality

The parties shall treat as confidential all information of the other party that comes to their knowledge in connection with the contract, whether designated as confidential or confidential by its nature, and shall use such information solely for the purpose of performing the contract.

This obligation does not apply to information that is publicly known without any breach of contract, has been lawfully obtained from third parties, or must be disclosed due to a statutory, regulatory, or judicial obligation.

15. Final Provisions

Any amendments or additions to individual agreements must be made in writing at a minimum. Individual agreements take precedence over these General Terms and Conditions.

German law applies, excluding the UN Convention on Contracts for the International Sale of Goods.

To the extent permitted by law, the exclusive place of jurisdiction is Bad Homburg v. d. Höhe if the customer is a merchant, a legal entity under public law, or a special fund under public law.

If any provision is or becomes invalid in whole or in part, the remaining provisions shall remain valid. The invalid provision shall be replaced by the applicable statutory provision.

Part B – Data Processing Agreement

Agreement Pursuant to Article 28 of the General Data Protection Regulation (GDPR)

The customer is the data controller. LimesTec is the data processor. The order and Part A of these terms and conditions constitute the main contract.

1. Purpose, Scope, and Duration

The subject matter of this agreement is the processing of personal data on behalf of the Client in connection with the managed/hosted applications provided under the Main Agreement, as well as the associated hosting, server, database, email, storage, backup, maintenance, administration, and support services. The specific scope of services is set forth in the order and the main contract.

This agreement applies exclusively to the extent that LimesTec processes personal data on behalf of the customer and in accordance with the customer’s instructions. In this regard, the customer is the data controller and LimesTec is the data processor. It also applies to persons acting under the responsibility of LimesTec, as well as to authorized subprocessors.

Processing operations for which LimesTec itself determines the purposes and essential means are not covered by this AVV. This applies in particular to LimesTec’s own contract and customer management, billing, receivables processing, compliance with statutory retention obligations, as well as domain registration and abuse handling procedures, to the extent that LimesTec itself is the data controller under data protection law.

The term of this Data Processing Agreement corresponds to the term of the main agreement and ends as soon as LimesTec no longer processes personal data on behalf of the client. Obligations regarding confidentiality, documentation, return, and deletion remain in effect until they are fully fulfilled.

2. Details of the Processing

The purpose of the processing is to provide the technical infrastructure, ensure secure operation, and provide contractual support for the subscribed application and related services. The data is not processed for our own advertising, profiling, or other purposes unrelated to the contract.

Processing may include, in particular, collection, recording, organization, storage, retrieval, consultation, use, disclosure, provision, restriction, protection, restoration, correction, erasure, and destruction.

The data processed may include, in particular:

  • Master Data, Contact Information, and Communication Data
  • Contract, customer, prospect, order, billing, and payment data, to the extent that such data is contained in the application
  • User, account, login, authorization, and authentication data
  • IP addresses, device, connection, access, error, security, and other log data
  • Application, website, database, file, form, message, and email content, including attachments
  • Backup, archival, recovery, temporary, and technically necessary copies
  • Special categories of personal data under Article 9 of the GDPR and data under Article 10 of the GDPR, to the extent that the customer lawfully processes such data

Data subjects may include, in particular, customers, prospective customers, website visitors, users, subscribers, members, employees, job applicants, suppliers, service providers, contacts, and other individuals whose data the customer processes through the application.

Within the scope of services, the customer determines the specific data, data subjects, purposes, and retention periods. The customer informs LimesTec in advance of any specific risks not apparent from the contract or any additional protective measures that may be required.

3. Instructions from the Data Controller

LimesTec processes personal data exclusively in accordance with documented instructions from the customer, unless there is a legal obligation to process such data. These instructions may also pertain to transfers to third countries or international organizations.

Documented instructions include, in particular, the Master Agreement, these General Terms and Conditions (AVV), the configuration and usage selected by the Customer, as well as instructions provided in writing, via a customer portal, or through an agreed-upon support system. The Customer shall immediately confirm any verbal instructions in writing.

If LimesTec is legally required to process data, the customer will be informed of the legal requirement prior to processing, unless such notification is prohibited by law.

If LimesTec considers an instruction to be in violation of data protection laws, the customer will be notified immediately. Execution of the instruction may be suspended until the instruction is confirmed, amended, or withdrawn.

4. Confidentiality and Authorized Persons

LimesTec ensures that all persons authorized to process data have been bound by a confidentiality obligation or are subject to an appropriate statutory duty of confidentiality. This obligation continues even after their employment has ended.

Access to personal data is restricted to individuals who need it to perform their duties. These individuals are informed of their obligation to follow instructions and of data protection and security requirements.

5. Security and Technical and Organizational Measures

LimesTec implements appropriate technical and organizational measures in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context, and purposes of the processing, and the varying likelihood and severity of the risks.

LimesTec maintains the technical and organizational measures (“TOM”) in up-to-date, versioned documentation. The version in effect at the time the contract is concluded specifies the obligations under the General Terms and Conditions of Contract (AVV). Upon a legitimate written request, it will be made available to the customer confidentially and within a reasonable period of time.

LimesTec may adapt these measures to technical and organizational developments, provided that the agreed-upon level of protection is not compromised. Significant changes will be documented and communicated to the customer upon request.

6. Support for the Data Controller

LimesTec assists customers, to the extent possible and taking into account the nature of the processing, by taking appropriate measures to fulfill requests from data subjects under Chapter III of the GDPR.

If a data subject submits a request directly to LimesTec, it will be forwarded to the customer immediately and will not be answered by LimesTec itself, unless otherwise instructed or required by law.

LimesTec assists customers, taking into account the available information, in fulfilling their obligations under Articles 32 through 36 of the GDPR, particularly with regard to security incidents, reports, notifications, data protection impact assessments, and prior consultations.

Standard support required by law and available information are covered by the fee. Significant additional work outside the scope of services that is not caused by LimesTec may be billed at a reasonable rate upon prior notice. This shall not delay the fulfillment of mandatory obligations or the implementation of urgent measures.

7. Violations of Personal Data Protection

LimesTec will notify the customer immediately after becoming aware of a breach involving the protection of personal order data. Notifications will be sent to the contact address provided by the customer.

The notification shall include, to the extent available, a description of the nature of the breach, the categories of data and individuals affected, approximate numbers of affected individuals and data records, likely consequences, remedial measures taken or proposed, and a point of contact. Any missing information will be provided without undue delay.

LimesTec documents the incident and provides the customer with the necessary support. The report does not constitute an admission of any breach of duty or liability.

8. Subcontracted Processors

The customer grants LimesTec general written authorization to engage subprocessors to the extent necessary to provide the agreed-upon services. To this end, LimesTec maintains an up-to-date, versioned list containing the identity, function, location of processing, and, where applicable, third-country status of the subprocessors relevant under data protection law.

The list will be provided to the customer confidentially and within a reasonable time upon a valid written request. It may be used solely to fulfill data protection-related audit and compliance obligations.

LimesTec shall notify the customer in writing at least 14 calendar days prior to any intended engagement or replacement of a subcontractor. The customer may object within this period on the basis of a documented, objective data protection reason. If no reasonable solution is possible and the service cannot be provided without the subcontractor, either party may terminate the affected portion of the service on an extraordinary basis. In justified urgent cases, the notification may be provided immediately after the change; the urgency must be justified.

LimesTec requires each subcontractor to comply with at least the same data protection obligations and remains responsible to the customer for the subcontractor’s compliance with these obligations.

Ancillary services that do not involve access to personal order data—in particular, services limited to transportation, telecommunications, postal services, cleaning, or security—are not considered subcontracted processing.

9. Processing in Third Countries

Processing outside the European Union or the European Economic Area will only take place in compliance with the requirements of Articles 44 through 49 of the GDPR and, where necessary, in accordance with documented instructions from the customer.

To the extent necessary, appropriate transfer mechanisms—in particular, applicable Standard Contractual Clauses issued by the European Commission—will be agreed upon, and supplementary safeguards will be implemented.

10. Documentation and Inspections

LimesTec provides customers with the information necessary to demonstrate compliance with the obligations under Article 28 of the GDPR. This may include, in particular, TOM documentation, test reports, certificates, or comparable evidence.

The customer may conduct checks, including inspections, either on its own or through a qualified inspector bound by a duty of confidentiality. Routine inspections must generally be announced at least ten business days in advance, conducted during normal business hours, and organized in such a way that they do not unduly interfere with operational processes, safety, or the rights of other customers.

The restrictions on routine audits do not apply in cases of a specific suspicion of a significant data breach, following a relevant security incident, or in response to an official order.

Existing information and supporting documentation will be provided without additional compensation. Reasonable, previously notified costs for any additional on-site inspection may be charged if such an inspection was not caused by a violation on the part of LimesTec and does not reveal any significant deficiencies. Statutory inspection rights must not be obstructed.

11. Return and Deletion

Upon completion of the processing services, LimesTec will, at the customer’s discretion, either delete all personal data related to the order or return it and delete any existing copies, provided there is no legal obligation to retain such data.

The customer must notify LimesTec of its choice no later than the end of the contract term and must use the provided export or retrieval options in a timely manner. If no instructions are provided, LimesTec will delete the order data upon expiration of the contractual retention or restoration period.

To the extent that individual data items cannot be specifically deleted during backups, they will be blocked and will not be further processed until they are routinely deleted in accordance with the backup and deletion policy, unless restoration is necessary for compelling technical reasons.

Data subject to statutory retention requirements is stored exclusively for this purpose, its processing is limited, and it is deleted upon expiration of the retention period. Upon request, LimesTec will confirm that the data has been deleted in accordance with the contract.

12. Obligations of the Data Controller

The customer is responsible for ensuring the lawfulness of the processing, protecting the rights of data subjects, the accuracy of its instructions, and the data protection-compliant use and configuration of the application.

The customer shall promptly notify LimesTec of any errors, irregularities, or special risks that it identifies while reviewing the services or handling personal data.

The customer shall designate accessible points of contact for data protection and security reports and keep this information up to date.

13. Final Provisions of the AVV

In the event of any conflict between these General Terms and Conditions and any other agreements, the provisions of these General Terms and Conditions shall take precedence with respect to matters relating to data processing. In all other respects, the provisions of the main contract and Part A remain unaffected.

Any amendments or additions to these General Terms and Conditions must be made in writing or in text form, unless mandatory law requires a more stringent form.

These General Terms and Conditions (AVV) become part of the main contract upon acceptance of the General Terms and Conditions during the electronic ordering process. A separate signature is not required.

If any provision is or becomes invalid, the remaining provisions shall remain in effect. The invalid provision shall be replaced by the applicable statutory provision.

Scroll to Top