General Terms and Conditions
Agreement on the provision of a SaaS service for sending newsletters
between
4OfficeAutomation GmbH, Schlägelweg 46a, 31275 Lehrte, hereinafter referred to as “4OA”.
hereinafter referred to as the “Customer”.
§ 1 Subject matter of the contract
The following provisions govern the framework for providing access to the functions of 4OA’s “mailfino” Software-as-a-Service (SaaS) solution described in more detail below. This solution is ordered by means of individual orders (also possible by email) in accordance with this framework agreement.
§ 2 Rights and obligations
Rights and obligations of 4OA
4OA provides the “mailfino” service platform. This is a technical, internet-based platform for sending emails, operated on one or more servers provided by 4OA in Germany. It also includes functions for creating emails, managing users and generating statistics. This service is also referred to below as the “Service”.
4OA acts solely as a transmitter of emails and is not responsible for the content of emails sent through the Service. 4OA makes multiple delivery attempts for all emails to be sent. However, as 4OA has no influence over the behaviour of recipients and recipient servers, successful delivery cannot be guaranteed.
4OA will maintain “mailfino” throughout the term of the contract. There is no entitlement to specific extensions or additions to the software. The usability of the software is ensured in accordance with the service description (through software maintenance and support and the provision of new software versions), with an availability of 98 %.
Rights and obligations of the Customer
In return for payment, 4OA grants the Customer a non-exclusive right, limited to the term of this contract, to access the current version of “mailfino” via the internet and to use its associated functions to carry out email marketing activities in accordance with this contract. Providing the Customer with internet access is expressly excluded from the Service.
The Customer must have agreed to the Rules of Participation (Appendix A), which form part of this contract, in order to use the Service. 4OA is entitled to refuse or discontinue the provision of the Service immediately and without prior notice to customers who breach or have breached the Rules of Participation.
The Customer shall keep the usage and access authorisations and identification and authentication safeguards assigned to the Customer or its users confidential and ensure that no unauthorised person becomes aware of them or can use them. As soon as the Customer becomes aware that this has occurred, the Customer shall notify 4OA without undue delay in text form.
The Customer shall ensure that all industrial property rights and copyrights are respected (for example, when transferring third-party text and data to the server).
The Customer shall not misuse “mailfino” or allow it to be misused, and in particular shall not transmit information containing unlawful content or content contrary to accepted standards of morality.
§ 3 Fees
The fees payable by the Customer correspond to the current version of the price list available at www.mailfino, which forms part of this contract.
If the maximum permitted number of emails changes during the term, the resulting revised fees become payable from the date of the change.
The contractually agreed fees must be paid in advance for the following year. The fees for the first year are payable upon receipt of the respective order. Unless otherwise agreed, 4OA will collect the amount from the Customer’s account by direct debit.
The applicable value added tax is added to the fees charged.
If the Customer is in arrears with a payment of a not insignificant amount, 4OA is entitled to block access to “mailfino”. The Customer shall bear the costs of returned direct debits.
§ 4 Contract term and termination
The minimum term of this framework agreement is 1 year from conclusion of the contract (date of signature). Thereafter, the Customer or 4OA may terminate the contract by giving 90 days’ notice to the end of the period.
The right to extraordinary termination for good cause remains unaffected. Good cause exists in particular if a party fails to comply with one or more material provisions and, following a written request to remedy the breach, fails to do so within 14 days and has not sufficiently demonstrated that it was not at fault. 4OA also has grounds for extraordinary termination if payment is overdue by more than 1 month.
If the usage fees under the price list increase, the Customer has a special right of termination within 14 days of receiving the invoice.
Any notice of termination must be given in text form.
Individual orders have the fixed term specified by the Customer in the respective order. An individual order can only be placed for full calendar months. The minimum term for an individual order is 1 calendar month. An individual order may only be placed while this framework agreement is in force.
§ 5 Data protection
When the Service is used, 4OA stores the following data, usually for one year:
The content of the email.
The Customer’s IP address at the time a mailing is sent.
The list of recipients, including all personalisation data.
The sending results
Statistics, including in particular statistics on clicks, opens and unsubscribes.
All data generated when completing and submitting forms provided by 4OA, for example as part of a double opt-in, is stored permanently
Data relating to people who use mechanisms provided by 4OA to unsubscribe from future mailings is stored permanently
The Customer acknowledges that the confidentiality of its data can only be ensured if it keeps the access credentials supplied to it confidential, does not disclose them to third parties and does not grant third parties access to its system. If the credentials are lost or the Customer becomes aware that unauthorised persons may have obtained knowledge of them, the Customer must notify 4OA without undue delay so that 4OA can prevent unauthorised use.
For the purposes of technical analysis and troubleshooting, 4OA has the right to inspect the Customer’s data, including without notifying the Customer.
4OA undertakes to ensure data protection within the meaning of the German Federal Data Protection Act and not to disclose the Customer’s data to third parties or use it for purposes not defined in this contract.
4OA and the Customer have entered into a data processing agreement (Appendix B), which forms part of this contract.
§ 6 Transfer
4OA may transfer the contract to another legal entity that assumes the rights and obligations towards the Customer arising from the contract.
§ 7 Severability
If any provision of this contract is or becomes wholly or partly invalid, the validity of the remaining provisions shall remain unaffected. The parties undertake to replace an invalid provision with a provision that comes as close as possible to it.
§ 8 Miscellaneous
The place of jurisdiction is the city of Hanover in the Federal Republic of Germany.
This contract is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods.
Amendments must be made in writing.
Appendices
Rules of Participation
Data processing on behalf of a controller
Technical and organisational measures
A: Rules of Participation of 4OfficeAutomation GmbH (4OA) for “mailfino”
Responsibility
Sole responsibility for the content of emails lies with their creator and sender, hereinafter referred to as the “User”.
The User is responsible for ensuring that emails are sent lawfully and, in particular, that the content of the emails sent does not violate legal prohibitions or requirements.
The User must acknowledge that sending emails may be subject to the laws of the respective countries in which the recipient is established or resides and undertakes to comply with the laws and regulations applicable in those countries, i.e. the User must not send emails that violate such legal rights or regulations.
Consent
The User undertakes to send emails only to recipients who have given their consent (see Art. 7 GDPR). The recipient’s consent must be documented and supplied to 4OA on request. In particular, this consent must meet the following requirements:
Consent must be given actively and separately. The recipient must either click/tick a box or make a similarly unambiguous declaration of consent. This declaration must relate solely to advertising and must not form part of other declarations (for example, agreement to general terms and conditions or general privacy provisions).
Consent must have been given for the specific case and on an informed basis. The beneficiary of the consent must be specifically named. The industries and areas to be advertised must also be stated clearly and comprehensibly.
Consent given by minors is only valid if they have reached the age of 16 or their legal guardians have consented.
When consent is obtained, it must be clearly and explicitly stated that consent may be withdrawn at any time with effect for the future. This notice must include information on how and to whom withdrawal can be declared. Withdrawing consent must not be more complicated than giving it. A withdrawal must be implemented within five working days at the latest.
As an exception, emails may also be sent to customers without an explicit opt-in (see 2.1.) under the following conditions:
an existing customer relationship (an exchange contract for consideration exists),
direct advertising for the sender’s own similar products or services,
notice of the right to object at any time (when the email address is collected and whenever it is used), without incurring any costs other than transmission costs at the basic rates, and
no objection has been made.
When using email addresses that the User or its customers have acquired from third parties, the following applies:
Before undertaking advertising activities, the User or its customer must ensure that consent exists (see clause 2.2). This consent must also explicitly cover the User or its customer.
When the data was collected, the recipient must have been able to view the list of beneficiary companies easily and unambiguously.
The number of companies or persons for whom the address data was collected must have been limited to a level that prevents user data from being passed on to a disproportionately large group of third parties. The number must allow the user to easily understand the implications and scope of their consent and to easily monitor the lawful handling of their data
For clarity, companies for which address data is generated may not pass this address data on to third parties without obtaining separate additional consent from the user.
At 4OA’s request, the User must explain how recipients’ email addresses were collected.
Sending spam emails is prohibited.
The User acknowledges that, due to legal obligations, email addresses to which emails permanently cannot be delivered because of a so-called hard bounce are added to a suppression list by 4OA and excluded from future delivery attempts. The same applies to the email addresses of recipients who have submitted complaints.
Email requirements
Every business email sent must include a readily identifiable legal notice in full text. The legal notice must contain the following information:
the name and address at which the client is established and, for legal entities, additionally the legal form, the commercial register, register of associations, partnership register or cooperative register in which they are entered, and the corresponding registration number,
contact information, including at least a valid telephone number or an electronic contact form, as well as an email address and a legal notice stating the User’s name and company name and full contact information (see §5 paragraph 1 TMG),
a VAT identification number or a business identification number, if available.
Further information obligations under national laws remain unaffected.
Every email must state that the recipient can unsubscribe from further emails (opt-out). As a rule, recipients must be able to unsubscribe from emails without knowing any access credentials (such as a login and password).
Neither the sender nor the commercial nature of the message may be obscured or concealed in the email’s header and subject line. Obscuring or concealing occurs when the header and subject line are deliberately designed so that, before viewing the content of the communication, the recipient receives no information or misleading information about the sender’s actual identity or the commercial nature of the message.
Emails containing any of the following content must not be sent:
Offers or links to offers that are prohibited by law in the European Union or the recipient’s country, such as illegal software, cracks, pirated copies, MP3s, DVDs or illegal narcotics.
Extremist, fraudulent, racist, offensive, pornographic, defamatory content, content glorifying violence or content otherwise contrary to accepted standards of morality.
Demonstrably disreputable offers, in particular those that violate the German Act Against Unfair Competition.
Content that violates the provisions of the German Protection of Young Persons Act.
Deliberately misleading content, such as a misleading sender or subject line intended to conceal the content or origin of an email.
Viruses, scripts or similarly potentially dangerous content.
The User can upload files to 4OA’s servers to provide images and attachments, create emails and import addresses. The User assumes full responsibility and liability for all data uploaded to the server and undertakes not to upload any data to a 4OA server that
contains viruses
infringes copyright
contains other illegal content, content contrary to accepted standards of morality or content that endangers the Service.
4OA reserves the right to carry out spot checks on the content of emails that have been sent or are to be sent through the software.
Breaches
Users who breach one or more of the Rules of Participation may be excluded from using the Service temporarily or permanently, immediately and without prior notice.
If complaints are received, 4OA is entitled to prevent the User from sending further emails without prior notice and to suspend the user account at its own discretion, subject to a charge where applicable.
If a User is excluded from using the Service for breaching the Rules of Participation, there is no entitlement to a refund of fees already paid.
If sending a mailing by the User demonstrably causes one or more of 4OA’s IP addresses or domains to be blocked or added to so-called blacklists, 4OA is entitled to charge its current hourly rate to remedy the situation and, where applicable, claim damages.
Data storage
4OA has the right to store the User’s IP addresses each time an email is sent, usually for a period of one year.
When the Service is used, 4OA stores the following data, usually for one year:
The content of the email.
The User’s IP address at the time a mailing is sent.
The list of recipients, including all personalisation data.
The sending results
Statistics, including in particular statistics on clicks, opens and unsubscribes
Data relating to unsubscribes and complaints (recipient’s email address, date, IP, user ID) is usually stored permanently to comply with the legal requirements of the GDPR (in particular Art. 7 3).
The User acknowledges that the confidentiality of its data can only be ensured if it keeps the access credentials supplied to it confidential, does not disclose them to third parties and does not grant third parties access to its system. If the credentials are lost or the User becomes aware that unauthorised persons may have obtained knowledge of them, the User must notify 4OA without undue delay so that 4OA can prevent unauthorised use.
For the purposes of technical analysis and troubleshooting, 4OA has the right to inspect the User’s data, including without notifying the User.
4OA undertakes to ensure data protection within the meaning of the German Federal Data Protection Act and not to disclose the User’s data to third parties or use it for purposes not defined in this contract.
Last updated: 24.05.2022
B: Data processing pursuant to
Art. 28(3) GDPR
Between the Customer (address) (Controller) and 4OfficeAutomation GmbH, Schlägelweg 46a, 31275 Lehrte, HRB 203395, Hildesheim Local Court (Processor)
1. Subject matter and duration of the processing
The subject matter of the data handling assignment comprises the creation of email newsletters and their transmission to specified recipient addresses, in each case to the extent determined by the Controller. The duration of this assignment (term) corresponds to the term of the service agreement.
2. Nature and purpose of the intended processing of personal data
The data to be processed includes, in particular, lists of email newsletter recipients and associated personalisation data to an extent determined at the Controller’s discretion, as well as log data generated in the course of carrying out the assignment.
The contractually agreed data processing takes place exclusively in a member state of the European Union or another contracting state to the Agreement on the European Economic Area. Any transfer to a third country requires the Controller’s prior consent and may take place only if the special requirements of Arts. 44 et seq. GDPR are met.
3. Technical and organisational measures
Before processing begins, the Processor must document the implementation of the required technical and organisational measures presented before the assignment was awarded, in particular with regard to the specific performance of the assignment, and submit this documentation to the Controller for review. If accepted by the Controller, the documented measures become the basis of the assignment. If the Controller’s review/audit identifies a need for adjustments, these must be implemented by mutual agreement.
The Processor must ensure security in accordance with Arts. 28(3)(c), 32 GDPR, in particular in conjunction with Art. 5(1), (2) GDPR. Taken as a whole, the measures to be implemented are data security measures intended to ensure a level of protection appropriate to the risk with regard to the confidentiality, integrity, availability and resilience of systems. The state of the art, implementation costs and the nature, scope and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons within the meaning of Art. 32(1) GDPR, must be taken into account.
Technical and organisational measures are subject to technological progress and further development. The Processor is therefore permitted to implement appropriate alternative measures. These must not fall below the level of security provided by the specified measures. Material changes must be documented.
4. Rectification, restriction and erasure of data
The Processor may not rectify or erase data processed on behalf of the Controller or restrict its processing on its own initiative, but only on the Controller’s documented instructions. If a data subject contacts the Processor directly in this regard, the Processor shall forward the request to the Controller without undue delay.
Where included in the scope of services, the Processor must directly ensure the implementation of the erasure policy, the right to be forgotten, rectification, data portability and access in accordance with the Controller’s documented instructions. Any costs incurred in this respect shall be borne by the Controller.
5. Quality assurance and other obligations of the Processor
In addition to complying with the provisions of this assignment, the Processor has statutory obligations under Arts. 28 to 33 GDPR; in this respect, it guarantees compliance in particular with the following requirements:
Data protection officer The Processor is not required to appoint a data protection officer. The designated contact at the Processor is Mr Johannes Vorwerk, Managing Director, 05132/946 7012 jvorwerk@mailfino.
Confidentiality Maintaining confidentiality in accordance with Art. 28(3), second sentence, point (b), Art. 29 and Art. 32(4) GDPR. The Processor shall only assign employees to the work who are bound by confidentiality obligations and have previously been familiarised with the data protection provisions relevant to them. The Processor and any person acting under its authority who has access to personal data may process that data only in accordance with the Controller’s instructions, including the powers granted under this contract, unless they are legally required to process it.
Implementation of and compliance with all technical and organisational measures required for this assignment pursuant to Art. 28(3), second sentence, point (c), and Art. 32 GDPR [details in Annex 1]
The Controller and the Processor shall cooperate with the supervisory authority, on request, in the performance of its tasks.
Informing the Controller without undue delay about inspections and measures by the supervisory authority insofar as they relate to this assignment. This also applies where a competent authority investigates the Processor in the context of administrative offence or criminal proceedings relating to the processing of personal data on behalf of the Controller.
If the Controller is itself subject to an inspection by the supervisory authority, administrative offence or criminal proceedings, a liability claim by a data subject or a third party, or another claim in connection with processing by the Processor on its behalf, the Processor shall provide the Controller with the best possible assistance. Any costs incurred in this respect shall be borne by the Controller.
The Processor shall regularly review its internal processes and technical and organisational measures to ensure that processing within its area of responsibility complies with the requirements of applicable data protection law and that the rights of data subjects are protected.
6. Subprocessing arrangements
For the purposes of this provision, subprocessing arrangements mean services that directly relate to the provision of the main service. They do not include ancillary services used by the Processor, such as telecommunications or hosting services, postal/transport services, maintenance and user support, the disposal of data media or other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems. However, to ensure the protection and security of the Controller’s data, the Processor is also required to put in place appropriate, legally compliant contractual arrangements and monitoring measures for outsourced ancillary services.
The Processor may engage subprocessors (further processors) only with the Controller’s prior express written or documented consent.
The transfer of the Controller’s personal data to a subprocessor and the commencement of the subprocessor’s activities are permitted only once all requirements for subcontracting have been met.
If the subprocessor provides the agreed service outside the EU/EEA, the Processor shall take appropriate measures to ensure that this is permissible under data protection law. The same applies if service providers within the meaning of paragraph 1, sentence 2, are to be used.
Further outsourcing by the subprocessor is not permitted.
7. Controller’s audit rights
The Controller has the right, in consultation with the Processor, to carry out audits or have them carried out by auditors appointed on a case-by-case basis. The Controller has the right to verify the Processor’s compliance with this agreement through spot checks at the Processor’s business premises, which must generally be announced with adequate notice.
The Processor shall ensure that the Controller can verify the Processor’s compliance with its obligations under Art. 28 GDPR. The Processor undertakes to provide the Controller with the necessary information on request and, in particular, to demonstrate the implementation of technical and organisational measures.
Evidence of measures that do not relate solely to the specific assignment may be provided through
– compliance with approved codes of conduct pursuant to Art. 40 GDPR;
– certification under an approved certification procedure pursuant to Art. 42 GDPR; current attestations, reports or report extracts from independent bodies (e.g. public auditors, internal audit, data protection officers, IT security departments, data protection auditors, quality auditors);
– appropriate certification through an IT security or data protection audit (e.g. under BSI IT-Grundschutz).
The Processor may claim remuneration for enabling audits by the Controller.
8. Notification of breaches by the Processor
The Processor shall assist the Controller in complying with the obligations set out in Articles 32 to 36 GDPR concerning the security of personal data, notification of data breaches, data protection impact assessments and prior consultations. This includes, among other things,
ensuring an appropriate level of protection through technical and organisational measures that take account of the circumstances and purposes of processing and the anticipated likelihood and severity of a possible infringement of rights through security vulnerabilities, and that enable relevant breaches to be detected immediately.
the obligation to report personal data breaches to the Controller without undue delay
the obligation to assist the Controller in meeting its obligation to inform the data subject and to provide the Controller with all relevant information in this context without undue delay
assisting the Controller with its data protection impact assessment
assisting the Controller with prior consultations with the supervisory authority
The Processor may claim remuneration for assistance services that are not included in the service description or are attributable to misconduct by the Processor.
9. Controller’s authority to issue instructions
The Controller shall confirm oral instructions without undue delay (at least in text form).
The Processor must inform the Controller without undue delay if it believes that an instruction violates data protection provisions. The Processor is entitled to suspend implementation of the relevant instruction until it is confirmed or amended by the Controller.
10. Erasure and return of personal data
No copies or duplicates of the data shall be made without the Controller’s knowledge. Exceptions are backup copies where required to ensure proper data processing, and data required to comply with statutory retention obligations.
After completion of the contractually agreed work, or earlier at the Controller’s request, and no later than upon termination of the service agreement, the Processor must hand over to the Controller all documents received, processing and usage results created, and data holdings relating to the assignment, or destroy them in compliance with data protection requirements with prior consent. The same applies to test and scrap material. The erasure record must be provided on request.
The Processor must retain documentation that serves as evidence of proper data processing in accordance with the assignment beyond the end of the contract for the applicable retention periods. The Processor may hand this documentation over to the Controller at the end of the contract to discharge this obligation.
C: Description of the technical and organisational data security measures pursuant to Art. 32 GDPR for the “mailfino” service of 4OfficeAutomation GmbH
To ensure the protection of customer data, 4OfficeAutomation GmbH (hereinafter referred to as the “Provider”) takes the following technical and organisational measures:
Encryption of personal data
HTTPS encryption in web communications (Data-at-Transport)
Ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services associated with processing
Access to systems only with individual usernames and passwords
Authorised persons can only access data for which they have authorisation
Stored personal data can only be read, copied, modified or removed within the authorisation framework
Use of continuously updated antivirus software
Protection of email traffic against viruses and spam
Firewall systems
Use of tested software
Separation of the production environment from the testing and development environment
Employees bound by data confidentiality obligations
Air conditioning in server rooms
Strong password security
No unauthorised access to the data centre’s data processing systems
Access to business premises monitored by employees during business hours
Visitors to data centres are accompanied
Lists of persons authorised to access sensitive areas of the data centres
Defined group of persons with access authorisation
Secure erasure of data media
Use of personal data media prohibited
Reception staffed during business hours
Fire protection equipment
Ability to restore the availability of and access to personal data promptly in the event of a physical or technical incident
Duplicate or multiple provision of all data processing components (e.g. data backups and mirroring of hardware components)
Data backup and recovery policy
Personal data is continuously available and protected against accidental destruction or loss through regular backups
Backup copies
Uninterruptible power supply
Redundant power feeds
Monitoring and notification systems
Procedures for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures to ensure processing
Regular review of whether and to what extent access rights are still required
Incident response management
Monitoring of processing carried out on behalf of a controller
Implementation of necessary adjustments