Terms and Conditions
This English translation is provided for convenience. In the event of discrepancies, the German version is authoritative.
Terms and Conditions
1. Scope and contractual basis
(1) These General Terms and Conditions apply to contracts between Thomas Siegbert (hereinafter “service provider”) and clients for services in the areas of IT security, technical consulting and security-related knowledge transfer.
(2) The offer is aimed exclusively at entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law. Contracts with consumers will not be concluded on the basis of these General Terms and Conditions.
(3) The General Terms and Conditions become part of the contract if the service provider refers to them before or upon conclusion of the contract and the client agrees to their validity. Differing terms and conditions of the client only apply if the service provider has expressly agreed to them.
(4) Individual agreements have priority. In addition, the accepted offer, the service description and - in the case of security tests - the agreed test and release rules apply. Changes and additions should be recorded in text form for reasons of proof; the priority of individual agreements remains unaffected.
2. Conclusion of contract, scope of services and changes
(1) Offers are subject to change unless they are expressly designated as binding. A contract is concluded through acceptance of a binding offer, through an order confirmation from the service provider or through another clear declaration of acceptance.
(2) The content and scope of the service, service period, work results and remuneration result from the respective agreement. Services not expressly agreed are not owed.
(3) The legal classification of the service depends on the agreed obligations. If professional activity is owed without a specific result, the provisions governing service contracts apply. If a specific deliverable subject to acceptance is owed, the provisions governing contracts for work and services apply, unless the parties agree otherwise. Reports, documentation or presentations that document a consulting or testing service do not, for that reason alone, constitute an obligation to achieve any further specific result.
(4) The service provider performs the agreed services professionally and with reasonable professional care, based on the information available at the time of performance. Security assessments reflect the agreed testing period and scope. Complete or permanent freedom from defects and attacks is not guaranteed.
(5) Change requests from the client will be checked for their impact on effort, remuneration and deadlines. The service provider only implements it once the parties have agreed on the change and its consequences.
(6) The service provider is responsible for carrying out its services. Project-related coordination as well as security, access and compliance requirements of the client remain binding as long as they were communicated in a timely manner and affect the provision of the service.
(7) The service provider may use qualified subcontractors and remains responsible for their contractual performance. Any consent required by law or contract remains a prerequisite. Subcontractors receive access to personal data only where the requirements of Article 28 GDPR are met. For projects involving classified information or similarly sensitive security requirements, their use is subject to prior project-specific agreement.
3. Security testing and security-sensitive projects
(1) Penetration tests and comparable security tests are only carried out within a predetermined scope and on the basis of an express approval from the client in text form (“Permission to Test”). Scope, test period, permitted methods, excluded systems, contact persons and termination criteria are determined on a project-by-project basis.
(2) Red team measures require separate rules of engagement in text form. Social engineering, phishing, physical access attempts and personal testing are only permitted if they have been approved individually. Target groups, excluded people and actions, limits of permissible deception, data protection, communication and escalation are determined in advance.
(3) The client guarantees that he is authorized to carry out the commissioned tests. He obtains all necessary approvals for systems, applications, cloud environments and third-party infrastructures in a timely manner and ensures the necessary internal approvals. Unless a covert test scenario has been agreed, he informs the affected internal departments. The service provider may request suitable evidence.
(4) The client maintains current data backups and functional recovery procedures before the start of the test. He names a contact person for safety and operational questions who can be reached during the agreed test times.
(5) Despite careful planning, security tests can affect the availability, performance or function of the systems tested. If a party recognizes a significant, unforeseen threat to systems, data or business operations, it will inform the other party immediately. The service provider may interrupt the affected measures until they have been clarified together.
(6) Any weak points identified will be documented and communicated in accordance with the agreed procedure. The client decides on risk treatment and implementation of the recommendations if no implementation service has been agreed. A later retest or ongoing monitoring is only required if this has been expressly ordered.
(7) If an order requires special security or confidentiality requirements, the parties agree on the necessary evidence, approvals, access rights and protective measures on a project-specific basis. These General Terms and Conditions do not constitute a right of access or an authority to handle classified information.
4. Advice and training
(1) For consulting, review and support services, prioritization, implementation, release and operation of the systems remain with the client, unless further services are expressly agreed. Recommendations are based on the reported status and do not replace an examination outside the agreed scope.
(2) For training courses and workshops, the agreed content and formats are owed, but not a specific learning, examination or implementation success. Practical security exercises only take place in approved or isolated environments.
(3) Recordings of workshops or training courses as well as the reproduction of the materials provided for them are only permitted to the agreed extent.
5. Participation of the client
(1) The client provides the information, documents, access, test data, technical requirements and expert contact persons required for the service in a timely manner. It points out special operational risks, protection needs and regulatory requirements.
(2) The client checks the interim results and queries provided within a reasonable period of time. He communicates changes to systems, scope or framework conditions as far as they are relevant to the performance.
(3) If the service is delayed due to a lack of or improper cooperation, the affected dates will be postponed appropriately. After prior notice, the service provider may invoice the proven additional effort caused by this at the agreed rates.
6. Deadlines and obstacles to performance
(1) Dates and deadlines are binding if they have been expressly agreed as binding. Otherwise, this is planning information.
(2) If the service is prevented or made significantly more difficult by an event for which the party concerned is not responsible, it will inform the other party immediately. These include, in particular, force majeure, official measures, significant failures of necessary infrastructure and unforeseeable security-related disruptions. Dates and deadlines are extended by the duration of the disability plus an appropriate restart time.
(3) Agreed dates for workshops, training or on-site services can be postponed or canceled according to the conditions specified in the offer. If there is no such regulation, the statutory provisions apply. The client is responsible for travel or third-party costs that have already been approved and can no longer be canceled; Saved expenses will be taken into account.
7. Compensation and payment terms
(1) Remuneration, billing model and, if applicable, agreed advance payments result from the offer. All prices are net plus statutory sales tax, if applicable.
(2) Services outside the agreed scope will only be reimbursed after the corresponding order has been placed. If there is no price agreement for an additional service ordered, the usual remuneration applies.
(3) Travel, accommodation and other additional costs will only be charged if this has been agreed or approved in advance by the client.
(4) Invoices for services are due without deductions within 14 calendar days of receipt, unless the invoice or individual agreement specifies another payment term. For work services, the due date depends on the agreed payment plan or, if there is no such plan, on acceptance and receipt of the invoice. The statutory regulations apply to late payments.
8. Work results and rights of use
(1) The client’s rights to his data, documents, systems and other content provided remain unaffected. The same applies to factual information and findings about the client’s systems.
(2) After full payment, the client receives a simple right to use individually created reports, documentation, concepts, presentations, training documents and comparable work results for the contractually stipulated purpose. This includes the necessary internal reproduction, processing and integration into checking and remediation processes. Further use can be agreed in the offer.
(3) The client may make work results available to affiliated companies and associated employees, consultants, lawyers, auditors, insurers, service providers and authorities to the extent necessary if they need them for the purpose of the contract and are appropriately obliged to maintain confidentiality or are legally obliged to maintain secrecy. Publication or commercial use requires the prior consent of the service provider.
(4) The service provider’s pre-existing methods, tools, templates, libraries and general specialist knowledge remain with the service provider. To the extent that such components are included in a work result and are necessary for its contractual use, the right of use also includes their use to this extent.
(5) The service provider may continue to use general methods, skills and experiences, provided that no confidential information, personal data or conclusions about the client are disclosed.
9. Confidentiality and data protection
(1) Both parties treat the other party’s confidential information confidentially and use it exclusively to execute the contract. In particular, non-public technical, organizational, economic and security-related information, access data, reports and vulnerabilities are considered confidential.
(2) The obligation of confidentiality does not apply to information that was demonstrably already lawfully known to the receiving party, is publicly known without a breach of contract, was lawfully obtained by a third party or was developed independently.
(3) Confidential information may be made accessible to employees, subcontractors and professional consultants to the extent that they need it to carry out the contract and are appropriately obliged to maintain confidentiality or are legally obliged to maintain confidentiality.
(4) If disclosure is required by law, court or authority, the affected party may disclose the required information. To the extent legally permissible, it will inform the other party in advance and limit disclosure to the extent necessary.
(5) The confidentiality obligations apply for five years after the end of the contract. Trade secrets within the meaning of the Trade Secrets Act must also be treated confidentially for as long as the legal protection requirements exist. Access data, unresolved vulnerabilities and security-critical architectural information remain protected regardless, as long as they are confidential and security-relevant.
(6) Both parties observe the data protection regulations that apply to them. If the service requires order processing within the meaning of Article 28 GDPR, the parties will conclude a separate agreement before the relevant processing begins. Other data protection roles and responsibilities are determined on a project-by-project basis.
10. Liability
(1) The service provider is liable without limitation in the event of intent and gross negligence, in the event of culpable injury to life, body or health, in the event of an express warranty, in the case of fraudulent concealment of a defect, as well as in accordance with the Product Liability Act and other mandatory legal regulations.
(2) In the case of simple negligence, the service provider is only liable if an essential contractual obligation is breached. Essential contractual obligations are obligations whose fulfillment enables the proper execution of the contract and on whose compliance the client can regularly rely. In this case, liability is limited to the contract-typical damage foreseeable at the time the contract was concluded.
(3) Otherwise, liability for simple negligence is excluded. The above restrictions also apply to the legal representatives, employees and vicarious agents of the service provider.
(4) In the case of data loss caused by simple negligence, liability according to paragraph 2 is limited to the effort that would have been incurred to restore the data if the data had been properly backed up and appropriate to the risk.
(5) If damage is based on incorrect information, a lack of authorization, non-approved changes or any other breach of duty by the client, the service provider is only liable to the extent that it contributed to the damage and is responsible for it.
11. Term and Termination
(1) Term and regular termination depend on the individual agreement and the legal regulations. The right of both parties to terminate for good cause remains unaffected.
(2) Services provided in accordance with the contract until the termination takes effect must be remunerated. Otherwise, compensation and compensation claims are based on the individual agreement and the legal regulations.
(3) After the end of the contract, the parties return or delete access and documents that are no longer required. The instructions of the client, the agreement on order processing and Art. 28 GDPR apply to data from order processing. Otherwise, only data that is required due to legal obligations or to assert, exercise or defend legal claims may be retained. Access should be limited to this purpose; the data must be deleted after the purpose no longer applies. Legally permitted backup copies remain protected until they are routinely deleted.
(4) Regulations on confidentiality, data protection, rights of use and liability apply beyond the end of the contract to the extent their purpose requires this.
12. Applicable Law and Place of Jurisdiction
(1) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
(2) The statutory provisions apply to the place of jurisdiction. A jurisdiction agreement that deviates from this remains permissible as long as the legal requirements are met in the individual case.
13. Final provisions
(1) If individual provisions of these General Terms and Conditions are or become ineffective in whole or in part, the remainder of the contract remains effective.
(2) The statutory provisions take the place of any provision that is not included or is ineffective.
As of July 15, 2026