Section A: General Terms of Service

§ 1 Scope and Target Audience

These General Terms of Service ("Terms") govern the contractual relationship between ReguLib (Caspar Vogel & Mathieu Ribeiro GbR) ("Provider", "we") and corporate clients ("Customer", "you") regarding access to and use of our SaaS platform for claim verification and evidence management.

The Service is intended exclusively for commercial enterprises and business clients within the meaning of § 14 of the German Civil Code (BGB). Consumers within the meaning of § 13 BGB are expressly excluded from registering and using the platform.

Any conflicting or deviating terms of the Customer shall not apply unless explicitly agreed to by the Provider in writing.

§ 2 Formation of Contract

The presentation of the SaaS platform on our website does not constitute a legally binding offer.

A binding contract is concluded when the Customer completes the online registration, creates an account, and accepts these Terms.

§ 3 Service Scope, Availability & Customer Content Responsibility

Service Scope: ReguLib provides a cloud-based software environment enabling Customer legal/compliance teams to upload, manage, and verify marketing claims with supporting evidence, while allowing marketing teams restricted access to review and utilize approved claims.

Platform Availability (SLA Target): The Provider endeavors and targets an annual average platform availability of 99.5%, excluding scheduled maintenance windows announced at least 24 hours in advance and events beyond the Provider's reasonable control (e.g., host infrastructure outages, upstream internet failures). The target availability does not constitute a strict guarantee or liquidated damages commitment.

Intellectual Property & Licensing: The Customer retains all intellectual property rights and title to all uploaded documents, evidence files, and claims ("Customer Content"). The Customer grants the Provider a non-exclusive, worldwide, royalty-free license solely to host, transmit, store, and display Customer Content as necessary to operate the Service.

Customer Responsibility & Content Monitoring: The Customer carries sole legal responsibility for the legality, accuracy, non-infringement, and appropriateness of all Customer Content uploaded to the platform. The Provider does not actively monitor, audit, screen, or review Customer Content for legal compliance, accuracy, or copyright infringement. The Customer warrants that Customer Content does not violate applicable laws, third-party rights, or contain special categories of personal data pursuant to Art. 9 GDPR (e.g., medical or health records). The Provider reserves the right to suspend or remove access to specific content if notified of an explicit legal violation.

§ 4 Billing, Taxes & Terms

Subscription fees are billed in advance on a recurring basis (monthly or annually) according to the selected plan.

Subscription fees are due immediately upon invoicing at the start of each billing period.

All listed prices are net prices exclusive of statutory Value Added Tax (VAT).

For EU-based business customers outside Germany holding a valid EU VAT ID, VAT will be processed under the intra-Community Reverse Charge mechanism.

In the event of failed payments, failed SEPA direct debits, or credit card chargebacks caused by the Customer, the Customer shall reimburse the Provider for any actual third-party processing bank fees incurred.

§ 5 Term and Cancellation

Monthly subscriptions may be canceled at any time prior to the end of the current monthly billing cycle, taking effect at the end of that period.

Annual subscriptions may be canceled up to 30 days prior to the expiration of the annual billing term.

Cancellation Mechanism: Cancellation may be executed directly by the Customer in self-serve text form within the platform's billing dashboard, or by sending a written notice in text form (e.g., email to contact@regulib.com).

The right of both parties to extraordinary termination for cause remains unaffected.

§ 6 Suspension of Service

The Provider reserves the right to suspend platform access if payment is overdue by more than 14 days following a formal reminder, or in cases of material security breaches caused by the Customer. Suspension does not relieve the Customer of its ongoing payment obligations.

§ 7 Integration of Data Processing Agreement (DPA)

To the extent that Customer Content contains personal data (such as names, job titles, email addresses, or signatures in uploaded compliance records), the parties hereby conclude the Data Processing Agreement set forth in Section B, which forms an integral, legally binding part of this contract pursuant to Art. 28 GDPR.

§ 8 Disclaimer of Legal Advice

ReguLib provides document management, role access controls, and administrative SaaS tools. ReguLib does not provide legal advice, legal claim verification, or legal representation. The Customer remains solely responsible for verifying the regulatory compliance, legal accuracy, and truthfulness of its marketing claims under applicable advertising laws (e.g., UWG, EU Green Claims Directive).

§ 9 Limitation of Liability

The Provider is liable without limitation under statutory German law for intent, gross negligence, injury to life, body, or health, or under statutory product liability acts.

In cases of slight negligence, the Provider is strictly liable only for breaches of essential contractual obligations—the fulfillment of which enables proper performance of the contract—and liability shall be capped at typical, foreseeable contractual damages.

To the extent permitted by law, liability for simple negligence shall be limited to direct, foreseeable damages typical for this type of contract, explicitly excluding loss of profit, loss of revenue, indirect damages, or consequential commercial loss.

§ 10 Confidentiality

Each party agrees to maintain strict confidentiality regarding all non-public business, technical, and financial information received from the other party in connection with this contract. This obligation survives termination of the contract for a period of three years.

§ 11 Amendments to Terms

The Provider reserves the right to amend these Terms at any time. The Provider shall notify the Customer of intended amendments in text form (e.g., via email or platform notification) at least 30 days prior to their planned effective date. If the Customer does not object to the amendments within 30 days of receiving notification, the amended Terms shall be deemed accepted. The Provider shall explicitly inform the Customer of this consequence in the notification.

§ 12 Governing Law, Jurisdiction & Language

These Terms shall be governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).

The exclusive place of jurisdiction for all disputes arising from or in connection with this contract is Düsseldorf, Germany.

In the event of any conflict or discrepancy between this English version of the Terms and the German language version (AGB), the German language version shall prevail.

§ 13 Severability & Contact

Should any provision of these Terms be held invalid or unenforceable, the validity of the remaining provisions shall remain unaffected.

Contractual notices, support inquiries, and legal communications should be directed to contact@regulib.com.

Section B: Data Processing Agreement (Art. 28 GDPR)

§ 14 Roles, Subject Matter & Instruction-Bound Processing (Art. 28(3)(a) GDPR)

Roles: Customer acts as Data Controller; ReguLib acts as Data Processor.

Subject Matter: Hosting, storage, role-based access management, and infrastructure management for claim evidence documents uploaded by the Customer.

Duration: Concurrent with the active SaaS subscription under Section A.

Instruction-Bound Processing: The Processor shall process personal data solely on documented instructions from the Controller, including with regard to transfers of personal data outside the EU/EEA, unless required to do so by applicable EU or Member State law.

§ 15 Processing Scope, Data Categories & Staff Confidentiality (Art. 28(3)(b) GDPR)

Data Categories: Names, email addresses, platform user roles (e.g., Legal/Compliance, Marketing) contained in account logs, and job titles, electronic signatures, and professional credentials that may be embedded within uploaded evidence files.

Data Subjects: Customer employees, external auditors, legal counsel, compliance officers, and third-party signers appearing within uploaded evidence files.

Staff Confidentiality: The Processor ensures that personnel authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

§ 16 Technical and Organizational Security Measures (Art. 28(3)(c) GDPR)

The Processor maintains strict technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk (Art. 32 GDPR), including:

§ 17 Sub-processor Authorizations (Art. 28(2) & (4) GDPR)

The Controller hereby grants general authorization to engage the following sub-processors:

The Processor shall inform the Controller at least 14 days in advance of any intended addition or replacement of sub-processors. The Controller may object to such changes on reasonable data protection grounds.

§ 18 Assistance with Data Subject Rights & Incident Notification (Art. 28(3)(e) & (f) GDPR)

Assistance with Rights: Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising data subject rights under Chapter III GDPR.

Breach Notification: The Processor shall notify the Controller without undue delay, and at the latest within 48 hours, upon confirming a personal data breach affecting Customer Content.

§ 19 Audit Rights & Data Deletion (Art. 28(3)(h) & (g) GDPR)

Audit Rights: The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable advance notice and non-disclosure obligations.

Data Return and Deletion: Upon termination of the subscription, the Processor shall, at the choice of the Controller, delete or return all personal data within 30 days, unless statutory law mandates continued retention.