Please note: This English version is provided for convenience only. Only the German version is legally binding. In the event of any discrepancy, the German version shall prevail.

General Terms and Conditions (GTC)


the one mip Consult GmbH for services over sofortdatenschutz.de
Status: October 2026
Part A – General provisions
Section 1 Scope of application
(1) These General Terms and Conditions (AGB) apply to all contracts that mip Consult GmbH the (hereinafter referred to as the „Provider“) enters into with its customers (hereinafter referred to as the „Customer“) via the website sofortdatenschutz.de or in connection with the services offered there. The applicable version is the one in effect at the time of the conclusion of the contract.
(2) Part A applies to all services. In addition, the special provisions in Part B apply to the service booked in question. In the event of any discrepancies, the provisions in Part B take precedence over those in Part A.
(3) The offer is exclusively directed at entrepreneurs within the meaning of § 14 BGB, legal persons under public law and special public-law funds. The customer confirms when placing the order that they are acting as an entrepreneur. Contracts with consumers within the meaning of § 13 BGB are not concluded.
(4) Any deviating, contradictory or supplementary terms and conditions of the customer shall not form part of the contract unless the provider has expressly agreed to their validity in writing. These terms and conditions shall also apply even if the provider provides services without reservation in the knowledge of deviating terms and conditions of the customer.
(5) Individual agreements, in particular individual offers from the provider, take precedence over these terms and conditions.
§ 2 Services and contract type
(1) Through sofortdatenschutz.de, the following services can be booked in particular: External Data Protection Officer including data protection advice and IS-analysis (Part B, Section 1), External Information Security Officer including information security advice (Section 2), External AI Officer including AI advice (Section 3), GDPR Website Check (Section 4), Data Protection Training as e-learning (Section 5), and mip WebScan™ (Section 6).
(2) The scope of services is determined by the description of services on the website at the time of ordering, the order confirmation pursuant to § 3, paragraph 4, and the provisions in Part B.
(3) Unless expressly agreed otherwise, the contracts are service contracts within the meaning of §§ 611 et seq. of the German Civil Code. The provider is solely responsible for performing the work professionally, not for a specific level of success, in particular not for a specific level of data protection or security, the absence of complaints from supervisory authorities, or the complete elimination of risks. Reports, analyses, and documents are documentation results of the service contractually required activity and not independently created works within the meaning of § 631 of the German Civil Code; a certificate of acceptance is not required.
(4) Responsibility for compliance with legal obligations, in particular those under the GDPR, the BDSG, the NIS2 Implementation Act and the AI Act, remains with the customer. The provider provides advice, support and supervision within the scope of the contracted service; the customer is responsible for deciding on the implementation of measures.
(5) The services provided by the provider do not constitute legal services within the meaning of the Legal Services Act. Legal advice is provided exclusively by licensed attorneys based on a separate mandate. [Lawyer to check]
Section 3 Order and conclusion of the contract
(1) The presentation of the services on the website does not constitute a binding offer from the provider, but an invitation to place an order.
(2) The customer selects the desired service and package, provides the requested booking information (e.g. number of employees, locations, desired contract start date, domains to be checked), and adds the service to the shopping cart. In the ordering process, they enter their billing and contact information and select a payment method. Before submitting the order, the customer can review and correct all details. By clicking the „Order subject to payment“ button, the customer submits a binding offer to conclude the contract.
(3) The provider confirms the receipt of the order immediately by email (receipt confirmation). The receipt confirmation does not constitute acceptance of the offer.
(4) The contract will only be concluded with the receipt of a separate order confirmation (acceptance declaration) from the provider in text form, but no later than at the start of the performance of the services. The provider may cancel the offer within [5] Accepts workdays.
(5) If a price is marked with „ab“, the final price depends on the actual scope, in particular the number of employees, locations, sub-sites or technologies used. If the review of the booking details reveals a higher scope, the provider will submit a customized offer in text form to the customer before the conclusion of the contract. A contract at the higher price will only come into effect if the customer accepts this offer; if they reject it, no contract will come into effect and any payments already made will be refunded.
(6) If the customer chooses an individual package or a service without a fixed price, no contract is concluded via the shop; the customer receives an individual offer.
(7) The provider stores the contract text. The order details and these terms and conditions are sent to the customer in text form with the order confirmation. The current terms and conditions are available at any time at sofortdatenschutz.de and can be saved or printed out.
(8) The contract language is German.
§ 4 Prices and payment
(1) The prices stated on the website at the time of ordering apply. All prices are net, plus the statutory value-added tax.
(2) The fee is due immediately after the conclusion of the contract, unless a different payment deadline has been agreed. One-time services (e.g. IST analysis, GDPR website check, data protection training, WebScan Basic and Premium) are due upon conclusion of the contract; monthly packages (External Data Protection, Information Security and AI Officer) are due monthly in advance, for the first time at the agreed contract start date; the - WebScan Excellence- package annually in advance.
(3) Payment is made through the payment service provider Mollie B.V. using the payment methods offered in the ordering process (e.g., credit card, PayPal, or bank transfer as advance payment); the terms and conditions thereof apply in addition. For ongoing services, the subsequent payment can be withdrawn using the mandate issued for the first payment. [mip confirm]
(4) The customer agrees to the transmission of invoices in electronic form.
(5) The provider is entitled to begin providing the service only after payment has been received.
(6) If the customer is in default with payment, the statutory regulations apply, in particular default interest at the rate of 9 percentage points above the base interest rate and the default penalty fee pursuant to § 288, paragraph 5 of the German Civil Code. The assertion of further default damages remains reserved.
(7) For monthly packages, the provider is entitled to change the prices with a notice period of [three months] to be adjusted appropriately at the beginning of a new contract year. In this case, the customer may terminate the contract exceptionally at the time the price adjustment takes effect; this is mentioned in the announcement. [mip decide whether it is desired]
§ 5 Term of validity and termination of month-long packages
(1) Monthly packages (External Data Protection Officer, External Information Security Officer, External AI Officer) begin at the agreed contract start date and have a minimum term of [12] Months.
(2) The contract is extended for an indefinite period after the end of the minimum term and can then be terminated by either party with a notice period of [three months] to [End of month] to be terminated. [mip decision: extension by 12 months each time or indefinitely]
(3) One WebScan-time services end with their completion; no regular termination is provided for. Part B, Section 6 applies to the Excellence package.
(4) The right to terminate the contract for good cause remains unaffected. A good cause exists for the provider, in particular, when the customer is in default with the payment of more than two monthly salaries or fails to fulfill their duty to cooperate despite a reminder with a reasonable deadline.
(5) Notices of termination must be in writing (§ 126b BGB).
(6) Upon termination of the contract, the provider shall, upon request, provide the customer with the documentation and documents prepared for them in a common electronic format, unless they already exist.
§ 6 Obligations of the customer to cooperate
(1) The customer ensures that their details when ordering, in particular regarding employee numbers, locations, domains and websites, are correct and complete, and immediately notifies any changes.
(2) The customer appoints a responsible contact person and a deputy who can be reached promptly.
(3) The customer shall provide the provider with all information, documents and access necessary for the provision of the service in a timely and free of charge manner and shall promptly involve the provider in relevant processes.
(4) Delays or additional costs arising from a breach of obligations to cooperate shall not be borne by the provider. The provider may charge additional costs separately in accordance with the hourly rates in force at any given time, after informing the customer accordingly.
Section 7: Provision of services, deadlines and additional services
(1) The provider provides its services in accordance with the state of the art and with the diligence of a responsible businessman through technically qualified personnel. The services are usually provided remotely; on-site appointments are arranged by arrangement. [mip adds: travel costs]
(2) The desired start date of the contract is non-binding until the provider confirms it in the order confirmation.
(3) Services that go beyond the agreed scope of services are provided by the provider upon separate commission at the hourly rates in effect at the time or as an extra-hour consulting package.
(4) The provider is entitled to employ qualified subcontractors and assistants. In the case of order processing, Article 28(2) and (4) of the GDPR also applies.
Section 8 Data protection and confidentiality
(1) To the extent that the provider processes personal data on behalf of the customer, the parties conclude a contract for the processing of orders pursuant to Article 28 GDPR. The role of the appointed data protection officer is carried out within the scope of the tasks under Article 39 GDPR. [Lawyer to check: Role distribution by service]
(2) The processing of personal data by the provider takes place within the European Union. The provider implements appropriate technical and organizational measures in accordance with Article 32 of the GDPR.
(3) Both parties undertake to keep all confidential information acquired in connection with the contract secret and to use it only for the purposes of the contract. Confidential information includes, in particular, technical information, business secrets, analysis results, reports, and information about data breaches and vulnerabilities.
(4) The duty of confidentiality does not apply to information that is publicly known or becomes known without violating this obligation, that the receiving party already knew, that has been legitimately made accessible by third parties, or that must be disclosed due to legal regulations or official orders. In the latter case, the disclosing party informs the other party as soon as possible.
(5) The duty of confidentiality applies beyond the end of the contract for three years. Legal duty of confidentiality, in particular in accordance with Article 38(5) GDPR in conjunction with § 6(5) BDSG, remains unaffected and applies indefinitely.
(6) The provider requires its employees and agents to maintain confidentiality.
Section 9 Liability
(1) The parties are fully liable for intent and gross negligence, for injury to life, body or health, for the breach of a guarantee, and under the Product Liability Act.
(2) In the event of slight negligence in the breach of essential contractual obligations, the parties shall be liable for only the foreseeable, typical damage that was foreseeable at the time of entering into the contract. Essential contractual obligations are those whose fulfillment first and foremost enables the proper performance of the contract and the other party may regularly rely on their compliance. The liability of the provider under this paragraph is limited in amount to three times the annual net remuneration agreed for the respective contract, but in any event to a maximum of EUR 50,000 per claim and EUR 100,000 for all claims within a contractual year. [Check MIP: Coverage of professional liability]
(3) Furthermore, liability is excluded in the event of slight negligence.
(4) The provider is not liable for fines, damages, or losses that arise from the customer not implementing the provider’s recommendations or implementing them not in a timely manner, violating their duty of cooperation, or providing incorrect or incomplete information.
(5) The limitations of liability also apply to the employees, representatives and vicarious agents of the Provider.
(6) The customer’s claims shall expire within twelve months from the statutory limitation period. This does not apply in the cases of paragraph 1.
§ 10 Final provisions
(1) Amendments and additions to the contract must be in writing (§ 126b BGB). This also applies to the waiver of this formal requirement.
(2) The provider is entitled to amend these terms and conditions for ongoing monthly packages with a period of at least six weeks before their entry into force, unless the change affects the ratio of performance and consideration. The customer will be informed by email. If the customer does not object within four weeks of receiving the notification in text form, the change will be deemed approved. The customer will be specifically informed about the deadline and the consequences of silence in the notification.
(3) Events of force majeure that prevent a party from fulfilling its obligations in a proper manner shall exempt it from the performance obligation for the duration and to the extent of their effect. Higher force majeure shall in particular include natural disasters, war, terrorist attacks, pandemics, government orders, strikes, serious cyberattacks on the infrastructure of the provider, and the failure of telecommunications and energy infrastructure, insofar as these are not attributable to the affected party.
(4) The customer may only transfer rights and obligations under the contract to third parties with the prior consent of the provider; § 354a HGB remains unaffected.
(5) The customer may only offset undisputed or legally established claims. A right of retention exists only insofar as the counterclaim is based on the same contractual relationship.
(6) The provider may mention the customer by name and logo as a reference, unless the customer objects in writing. The mention is made without mentioning content, results or weaknesses.
(7) The law of the Federal Republic of Germany applies, excluding the UN Sales Convention (CISG).
(8) The exclusive place of jurisdiction is the registered office of the provider, provided that the customer is a merchant, a legal person under public law, or a special public-law entity.
(9) Should any provision be invalid or unenforceable, the validity of the remaining provisions shall remain unaffected. The statutory provision shall replace the invalid provision.
Part B – Special provisions for individual services
Section 1: External Data Protection Officer and IST analysis
(1) The provider provides the customer with a qualified person as an external data protection officer within the meaning of Article 37 GDPR and § 38 BDSG. The tasks result from Article 39 GDPR and the description of the contracted package (Light or Pro). The data protection advice is included within the contracted package. [mip add: included consulting quota per package]
(2) The customer appoints the data protection officer in writing and provides the contact details of the relevant supervisory authority (Article 37(7) GDPR). The provider assists him in this.
(3) The customer shall involve the data protection officer properly and in a timely manner in all matters concerning the protection of personal data, provide the necessary resources and information, and ensure his/her freedom of instruction (Art. 38 GDPR).
(4) The package includes a one-time booking of an IS audit (Light or Pro, depending on the chosen package). The IS audit includes a structured inventory of the data protection level, the review of the existing documentation, and a prioritized action plan. The fee for the IS audit is due once the contract is signed.
(5) The packages are based on the number of employees and locations specified when booking. If these change significantly, the parties are entitled to request an adjustment of the package and the remuneration.
(6) The reporting of data protection violations to the supervisory authority (Article 33 GDPR) and the notification of affected parties (Article 34 GDPR) are the responsibility of the customer as the responsible party. The provider supports the customer within the scope of the booked package; support beyond that is provided as emergency assistance in the event of data breaches upon separate assignment.
Section 2: External Information Security Officer
(1) The provider provides the customer with a knowledgeable person as an external information security officer (ISB). The information security officer coordinates information security, advises the management, assists in developing guidelines, and monitors the implementation of measures within the contracted package (Light or Pro). [mip add: contained quota per package]
(2) Responsibility for information security and compliance with regulatory obligations, in particular under the NIS2 Implementation Act, remains with the customer's management.
(3) Section 1, paragraph 5 applies accordingly.
Section 3: External AI Officer
(1) The provider provides the customer with a knowledgeable person as an external AI consultant. This person supports the management of AI use, the assessment of risks, the creation of AI policies, the approval processes, and the implementation of the requirements of the AI Act and the GDPR. The AI consulting is included within the scope of the booked service.
(2) The AI Regulation does not provide for a statutory function of an AI Officer. The obligations under the AI Regulation, in particular regarding AI literacy pursuant to Art. 4, remain with the customer.
(3) The price is based on the scope, in particular the number of employees and the AI systems used; § 3, paragraph 5 applies.
Section 4: GDPR Website Check
(1) The provider checks the website provided by the customer for data protection requirements, in particular privacy information, consent management (cookie banner) and web forms, within the scope of the booked package (Light or Pro), and provides a report with recommendations.
(2) The examination refers to the state of the website at the time of the examination. Any subsequent changes to the website are not subject to the examination.
(3) The price depends on the number of subpages and the technologies used; § 3, paragraph 5 applies.
(4) The implementation of the recommendations is not part of the service unless otherwise agreed upon separately.
Section 5: Data Protection Training (E-Learning)
(1) The customer receives access to the basic data protection training on the provider’s e-learning platform for the number of participants booked. The fee is calculated per participant. Online bookings are possible for up to 100 participants; beyond that, an individual offer will be provided.
(2) The access is person-specific and may not be passed on to third parties. The access is restricted to [12 months] Available from activation onwards. [Mip to add]
(3) Upon successful completion of the learning progress check, the participating person will receive a certificate of participation.
(4) The training content is copyrighted. The customer receives a simple, non-transferable right to use it for internal training during the access period.
Section 6: mip WebScan™
(1) The subject matter is an automated security analysis of the customer’s publicly accessible systems (in particular websites, mail servers, DNS entries, open ports, and certificates) from the perspective of an external attacker. No active interventions in internal systems are made, no load tests are performed, and no software is installed on the customer’s side. WebScan It does not replace manual penetration testing.
(2) Packages: Basic (up to 3 websites, one-time scan), Premium (up to 5 websites, one-time scan), and Excellence (six scans within 12 months for up to 5 websites each, with progress control). The Excellence package is concluded for a period of twelve (12) months from the contract conclusion. It automatically renews for another twelve (12) months, unless terminated in writing with a period of three (3) months before its expiration.
(3) The customer receives a report after each scan with a prioritized assessment (critical, important, informative), a risk assessment and recommendations for action, as well as a personal review of the results.
(4) With the booking, the customer explicitly grants the provider permission to perform a security check of the specified domains and the associated systems accessible via the Internet („Permission to Attack“). The prerequisite for the execution is the receipt of payment. The scan usually takes place within 3 to 5 working days after payment has been received.
(5) The customer warrants that they are the owner of the specified domains and systems or have the necessary authorization to commission them, and obtains the necessary consents from third parties (in particular from hosts and service providers). He/she grants his/her consent upon request.
(6) The customer shall release the provider from liability for claims by third parties and the costs of reasonable legal defense arising from a false or incomplete guarantee pursuant to paragraph 5. This does not apply in the event of intentional or grossly negligent conduct on the part of the provider.
(7) Within the scope of the permission granted, the customer waives any claims against the provider and its agents for actions necessary for the proper execution of the scan, in particular in accordance with §§ 202a, 202b, 202c, 303a and 303b of the StGB. This does not apply to intentional acts outside the agreed scope of services.
(8) The approval granted under paragraph 4 may be revoked at any time in writing. The revocation shall not affect previously performed scans or the payment obligation.
(9) The report reflects the state as it was recognizable at the time of the scan. No guarantee is given that all vulnerabilities will be fully detected; a residual risk always remains.
Provider
mip Consult GmbH · Wilhelm-Kabus-Straße 9 · 10829 Berlin
Phone: +49 30 20 88 999 0 · Email: · kontakt@mip-consult.de www.mip-consult.de
Authorized representatives of the Managing Director: Asmus Eggert, Uwe Leider, Vera Schmidt
Registry: Amtsgericht Berlin-Charlottenburg · HRB 121869 · VAT ID: DE249276018