Terms & Conditions
Sophera Consulting
Max Fey
Elsdorfer Straße 29
50126 Bergheim
Germany
Email: fey@sopheraconsulting.de
– hereinafter referred to as the “Provider” –
Last updated: 1 June 2026
§ 1 Scope of application
(1) These General Terms and Conditions (hereinafter “GTC”) apply to all contractual relationships between Sophera Consulting, Max Fey (hereinafter “Provider”), and the respective client (hereinafter “Client”) in the fields of AI automation, digitalisation consulting, software development, process optimisation, training, workshops and technical implementation.
(2) These GTC apply exclusively. Deviating, conflicting or supplementary general terms and conditions of the Client shall only become part of the contract if and to the extent that the Provider has expressly consented to their application in writing. This requirement of consent applies in every case, even if the Provider renders the services without reservation while aware of the Client’s terms and conditions.
(3) These GTC also apply to all future business between the parties, provided that these are legal transactions of a related nature.
(4) When the Provider’s online services are used — in particular the automation check, the appointment booking and the payment pages — these GTC are incorporated by way of an active confirmation (checkbox) before any data is transmitted. The Provider’s privacy policy informs about the processing of personal data (Art. 13 GDPR); it is not part of the contract and does not require consent.
(4a) The Provider’s offering is directed exclusively at entrepreneurs within the meaning of § 14 BGB (German Civil Code), at legal persons under public law and at special funds under public law. Contracts with consumers within the meaning of § 13 BGB are not concluded. By entering into the contract, the Client confirms that it is acting in the exercise of its commercial or independent professional activity. This status is asked for separately during appointment booking and in the automation check.
(4b) As the offering is not directed at consumers, there is no statutory right of withdrawal under §§ 312g, 355 BGB. Should a contract nevertheless be concluded with a consumer in an individual case, the statutory consumer protection provisions take precedence over these GTC; in that case the Provider will instruct the consumer separately about their right of withdrawal, and the provisions of these GTC concerning warranty periods, limitations of liability and place of jurisdiction shall not apply.
(5) Individual agreements made in a particular case (including ancillary agreements, supplements and amendments) always take precedence over these GTC (§ 305b BGB). They should be recorded in text form; their validity does not depend on this.
(6) Where these GTC require written form or a written declaration, text form (§ 126b BGB), in particular email, is sufficient unless the statutory written form (§ 126 BGB) is expressly referred to.
§ 2 Subject matter of the contract and scope of services
(1) The subject matter and scope of the contractual services follow from the respective offer, the service description or the individual agreement. The Provider renders its services in accordance with the recognised state of the art.
(2) Depending on the type of service, different types of contract apply:
- Services under a contract for work (e.g. the creation of automations, software development, integrations): The Provider owes the production of an agreed work result.
- Services under a service contract (e.g. consulting, strategy development, training, workshops, ongoing support): The Provider owes the diligent performance of the agreed activities, but not a particular result.
(3) Under no circumstances does the Provider owe a guaranteed economic success. This applies in particular to:
- Increases in revenue or profit
- Cost savings of a particular amount
- Efficiency gains going beyond the technical functionality
- Specific ROI figures or amortisation periods
(4) Projected savings or efficiency gains that are mentioned in the course of consulting, the AI automation check or comparable analyses constitute non-binding estimates and do not establish any legal claim.
§ 3 Offer and conclusion of contract
(1) Offers of the Provider are subject to change and non-binding unless they are expressly designated as binding.
(2) The contract comes into existence through the written placement of an order by the Client and the written acceptance of the order or the commencement of performance by the Provider.
(3) The Provider confirms verbal commitments, ancillary agreements and amendments in text form. The confirmation serves as evidence; § 1 (5) remains unaffected.
(4) Change requests: if the Client requests a change to or an extension of the scope of services after conclusion of the contract, the Provider assesses the effects on effort, remuneration and deadlines and submits an offer in text form. Until agreement is reached, the originally agreed scope of services remains decisive.
§ 4 Provision of services and methodology
(1) The Provider renders its services at its own professional discretion. It is free in its choice of methods, tools and technologies unless agreed otherwise by contract.
(2) The Provider is entitled to engage qualified subcontractors and vicarious agents in order to fulfil its contractual obligations. Responsibility towards the Client remains with the Provider.
(3) Implementation may – where this is sensible given the nature of the service – take place iteratively and in partial steps (agile methodology). The Client will be informed about material interim steps.
(4) Schedules and delivery dates are binding only if they are expressly designated as binding in the offer or in text form. Otherwise they constitute non-binding guide values. A transaction for delivery by a fixed date (§ 323 (2) no. 2 BGB) exists only if expressly agreed as such.
(5) For damage arising from a delay in performance, the Provider is liable in accordance with § 10.
§ 5 Duties of the Client to cooperate
(1) The Client is obliged to cooperate comprehensively. The success of the project presupposes active collaboration.
(2) The Client shall in particular ensure:
- Complete, correct and timely provision of all required information, data and materials
- Timely provision of system access, API keys and technical infrastructure
- Designation of competent contact persons with decision-making authority
- Prompt feedback and approvals (within 5 working days unless agreed otherwise)
- Internal coordination and organisational prerequisites
(3) Delays, additional effort or additional costs arising from late, incomplete or faulty cooperation on the part of the Client shall be borne exclusively by the Client. The Provider is entitled to demand appropriate additional remuneration for this.
(4) If the Client fails to comply with its duties to cooperate despite a written reminder and the setting of a reasonable deadline, the Provider is entitled to terminate the contract extraordinarily. The claim to remuneration for services already rendered remains unaffected by this.
§ 6 Technological dependencies and third-party providers
(1) The services of the Provider are regularly based on technologies, platforms, APIs and services of third parties (e.g. AI models, cloud services, SaaS platforms, open-source software).
(2) The Provider assumes no warranty and no liability for:
- Changes to, restrictions of or discontinuation of third-party services or APIs
- System failures, maintenance windows or performance restrictions at third-party providers
- Price changes for third-party licences or services
- Security vulnerabilities in third-party software
- Changes in AI models that lead to deviating results
The Provider remains responsible for the careful selection, integration and monitoring of the services used; § 10 (1) to (3) remain unaffected.
(3) If adjustments to the services rendered become necessary as a result of external changes, these shall be remunerated separately at the hourly rate applicable at that time or on the basis of an individual offer.
(4) The Provider expressly points out that, in the course of the provision of services, data of the Client may be transmitted to third-party providers of AI, cloud and communication services. This includes in particular:
- AI services: Anthropic (Claude), OpenAI (GPT), Google AI (Gemini, Vertex AI), Microsoft Azure OpenAI, Amazon Bedrock, Mistral AI, Cohere and further providers named in the privacy policy
- Google Workspace: Gmail, Google Drive, Google Calendar, Google Meet (incl. AI-assisted meeting notes via Gemini), Google Forms, Google Docs, Google Sheets
- Google Cloud Platform (GCP): Cloud Storage, Compute Engine, Cloud Run, Cloud Functions, BigQuery, Cloud SQL, Firestore, Pub/Sub, Vertex AI, Cloud Logging & Monitoring
- Amazon Web Services (AWS): S3, EC2, Lambda, RDS, DynamoDB, SQS/SNS/EventBridge, CloudFront, CloudWatch, Bedrock, IAM, KMS, Secrets Manager
- Microsoft 365: Outlook, Teams, OneDrive, SharePoint, Azure
- Telephony: Placetel GmbH, Köln (cloud telephone system, server location Germany)
- Workflow automation: n8n (also self-hosted), Make, Zapier, Microsoft Power Automate
- Further cloud providers: Microsoft Azure, Oracle Cloud Infrastructure, IBM Cloud, STACKIT, T Cloud Public, IONOS Cloud, OVHcloud, Hetzner
- Self-operated AI models: open-weight models (e.g. Llama, Mistral, Gemma, gpt-oss, Qwen, DeepSeek), operated locally, at the Client or in an EU cloud; according to the Provider’s state of knowledge and the information of the respective developers, no data is transferred to the model developers (see paragraph 8)
- Further providers: Zoom, Stripe, Supabase, Vercel as well as comparable services required in the respective project context
The Provider has no influence on how these third-party providers process or store the transmitted data or use it for their own purposes (including model training). When selecting services, the Provider chooses the option that, in its assessment, is suitable from a data protection perspective (e.g. EU regions, API variants with model training disabled, DPF-certified providers). The current overview of the services used is set out in the Provider’s privacy policy; which services are used in an individual project follows from the offer or the data processing agreement.
(5) Where the Provider engages third-party providers as sub-processors for personal data of the Client, it is liable to the Client in this respect in accordance with Art. 28 (4) and Art. 82 GDPR. Otherwise, the Provider is not liable for conduct of third-party providers that it could neither recognise nor prevent despite careful selection, contract design and monitoring, in particular:
- a use of entered data for the training of AI models by the third-party provider in breach of contract
- a storage, transfer or disclosure of data by the third-party provider in breach of contract
- breaches of data protection regulations by the third-party provider that lie outside the Provider’s sphere of influence
§ 10 (1) to (3) remain unaffected.
(6) Before the start of the project, the Client will be informed which AI services are used. It is the responsibility of the Client not to provide any data whose transmission to third-party AI providers is inadmissible for legal, regulatory or contractual reasons (e.g. professional secrets, special categories of personal data pursuant to Art. 9 GDPR).
(7) Insofar as the Client wishes to exclude the use of certain AI services, this must be communicated in writing before conclusion of the contract. Additional costs arising from the use of alternative technologies shall be borne by the Client.
(8) Third-party information. Statements by the Provider on data flows, places of processing, retention periods, the non-transfer of data to developers and the non-use of data for training AI models are based on the information, documentation and contractual commitments of the respective developers and third-party providers and on the Provider’s state of knowledge at the time of the statement. They constitute neither an agreement on quality nor a guarantee. The Provider gives no warranty for the accuracy and completeness of such information and is not liable for damage resulting from information of a developer or third-party provider being inaccurate or incomplete or from its deviation from such information, unless the Provider knew of the inaccuracy or would have recognised it but for gross negligence. § 10 (1) and (2) remain unaffected.
§ 6a Funding advisory service (partner service)
(1) Within the scope of the partner service “funding advisory service”, the Provider refers the Client to external, certified funding advisors (hereinafter “funding partner”). In this respect the Provider acts as an intermediary and not as the provider of the funding advisory service.
(2) The initial consultation (15 minutes) is free of charge and non-binding. Only if the Client decides in favour of further cooperation with the funding partner does a separate contract come into existence between the Client and the funding partner. The Provider is not a party to this contract.
(3) In order to carry out the referral, it is necessary for the Provider to pass on certain personal data of the Client (name, contact details, project description) to the funding partner. This takes place exclusively with the express consent of the Client (cf. privacy policy, section 7.5).
(4) The Provider assumes no liability for the services of the funding partner, in particular not for:
- the successful approval of funding
- the correctness of the funding advice
- compliance with application deadlines by the partner
- the data processing carried out by the funding partner
(5) The funding partners are selected to the best of the Provider’s knowledge and belief. The Provider verifies the qualification and certification of the partners. No guarantee is assumed for the quality of the partner services. For the careful selection of the partners the Provider is liable in accordance with § 10; § 10 (1) and (2) remain unaffected.
§ 6b Connected systems of the Provider
(1) For the handling of business, the Provider uses interconnected systems (payment processing, accounting, customer relationship management, database). Which systems these are, which data is exchanged between them and how long it is stored is described in the Provider’s privacy policy (sections 8.11–8.14).
(2) The processing takes place for the performance of the contract and for compliance with statutory obligations (Art. 6 (1) (b) and (c) GDPR); no consent of the Client is required for this. All data transfers are encrypted.
§ 6c AI-assisted meeting notes (Gemini in Google Meet)
(1) In video conferences via Google Meet, the Provider may use the “AI-assisted meeting notes” function (Google Gemini, Workspace feature “Take notes with Gemini” or “Attend for me”) in order to create a written transcript and a summary of the conversation automatically. The transcripts are stored in Google Drive and may be made accessible to the Client via the Sophera client portal.
(2) Activation takes place exclusively with the express consent of all participants. Before the start of each recording, all persons involved are actively informed and asked for their consent. This corresponds to the requirements of § 201 StGB (German Criminal Code, confidentiality of the spoken word) as well as of the GDPR (Art. 6 (1) (a)). During active transcription, Google Meet displays a visual notice for all participants.
(3) If a participant refuses consent, the recording will not be started or will be ended without undue delay. Refusal of consent entails no disadvantages whatsoever for the conduct of the conversation.
(4) The generated transcripts and summaries are used exclusively for documentation purposes within the scope of the respective consultation. They are not passed on to third parties without renewed consent. At the Client’s request, recordings will be deleted at any time.
(5) The processing of the audio and video data by Gemini takes place in the EU regions of Google, insofar as this is technically possible. In accordance with the Workspace contract terms, Google does not use the transmitted data for the training of generative AI models.
(6) Since 2 August 2026, the transparency obligations of Art. 50 EU AI Act apply to AI-generated content. AI transcripts and summaries are labelled accordingly (“AI-generated”).
(7) Details on the data processing can be found in the privacy policy, sections 8.1 (Google Workspace incl. Meet) and 8.2 (Google AI / Gemini).
(8) AI-assisted meeting notes are not used where sensitive data may be discussed in the meeting – in particular special categories of personal data (Art. 9 GDPR, e.g. health and patient data), personnel data of individual employees or professional secrets (Section 203 German Criminal Code). For clients in the healthcare sector, recording is generally not carried out unless otherwise agreed in writing in the individual case.
§ 7 Acceptance
(1) In the case of services under a contract for work, the Client is obliged to declare acceptance as soon as the Provider notifies completion and the service has been rendered substantially in conformity with the contract.
(2) Acceptance takes place expressly by written declaration or through conclusive conduct (in particular productive use of the service).
(3) If the Client does not respond within 10 working days of receipt of the notice of completion and does not specify any concrete, material defects, the service shall be deemed accepted (deemed acceptance). The Provider informs the Client of this legal consequence in the notice of completion.
(4) Minor deviations that do not materially impair the functionality do not entitle the Client to refuse acceptance.
(5) If the Client refuses acceptance, it must specify the defects in writing and in concrete terms. The Provider shall be granted a reasonable period for rectification.
§ 8 Remuneration and terms of payment
(1) The remuneration is governed by the respective offer or the individual agreement. All prices stated are in euros plus statutory value added tax unless indicated otherwise.
(2) Invoices are due for payment without deduction within 7 days of receipt unless agreed otherwise.
(3) In the case of larger projects, the Provider is entitled to demand reasonable instalment payments or an advance payment of up to 50 % of the total remuneration.
(4) If the Client is in default of payment, the Provider is entitled to demand default interest of 9 percentage points above the respective base rate of interest (§ 288 (2) BGB) if the Client is an entrepreneur.
(5) In the event of default of payment of more than 14 days, the Provider is entitled to suspend its services until payment has been made in full, without any claims for damages of the Client arising from this.
(6) Set-off against claims of the Provider is permissible only with undisputed counterclaims, counterclaims ready for decision or counterclaims established by a final judgment. This does not apply to counterclaims of the Client arising from the same contractual relationship, in particular on account of defects in the service.
(7) Usage-based third-party costs. a) Usage-based third-party costs within the meaning of this provision are all fees charged by third-party providers according to actual use, in particular fees for the processing of tokens by AI models and for the use of application programming interfaces (APIs), computing power and storage in cloud services.
b) Which party bears the usage-based third-party costs incurred until acceptance (§ 7) is determined by the offer. The offer may provide that
- aa) the Provider bears these costs. In this case they are covered by the agreed remuneration. The assumption of costs is limited to costs incurred through use as intended for creating and testing the service described in the offer. Costs resulting from an extension of the scope of services initiated by the Client or from use not as intended are borne by the Client. Where the third-party provider invoices these costs directly to the Client, the Provider reimburses the Client for the costs incurred until acceptance in the amount evidenced by the third-party provider’s invoice or cost report, including VAT to the extent the Client is not entitled to deduct input tax. Unless the offer provides otherwise, reimbursement is made, at the Provider’s option, by set-off against the final invoice by way of a reduction of the remuneration or by a commercial credit note paid out within 14 days of acceptance;
- bb) the Client bears these costs. In this case the third-party provider invoices the Client directly. Where this is not possible, the Provider invoices the Client for the costs in the amount evidenced.
c) If the offer contains no provision, the Client bears the costs in accordance with letter b) bb).
d) The usage-based third-party costs incurred in ongoing operation from acceptance onwards are borne by the Client unless otherwise agreed in writing.
e) Information provided by the Provider on the expected amount of usage-based third-party costs is based on the third-party providers’ prices applicable at the time the offer is prepared and on the assumptions on the scope of use set out in the offer. It constitutes a non-binding estimate and establishes neither a quality guarantee nor a cost guarantee. Price changes by third-party providers are borne by the party that bears the costs under letters b) to d).
(8) Assignment: the Client may assign claims arising from the contract only with the Provider’s consent in text form; § 354a HGB remains unaffected.
§ 9 Warranty and remedy of defects
(1) In the case of services under a contract for work, the Provider is liable for defects in accordance with the statutory provisions, subject to the following provisos:
(2) The Client must notify defects in writing without undue delay after discovery, describing the fault in concrete terms. Blanket complaints are not sufficient.
(3) The Provider has the right to rectify the defect. As a rule, the Provider must be granted two attempts at rectification within a reasonable period before the Client may assert further rights.
(4) The limitation period for claims based on defects is 12 months from acceptance. This does not apply to damage arising from injury to life, body or health, to damage based on intent or gross negligence, in the case of fraudulent concealment of a defect or in the cases of § 10 (1) and (2); in these cases the statutory periods apply.
(5) There is no defect if:
- The fault is attributable to changes to the Client’s system environment for which the Provider is not responsible
- Third-party systems have been changed or discontinued
- The Client or third parties have made changes to the service without the consent of the Provider
- Use takes place contrary to the documentation or instructions
§ 10 Liability
(1) The Provider is liable without limitation for damage arising from injury to life, body or health that is based on an intentional or negligent breach of duty by the Provider, as well as for damage covered by liability under the Product Liability Act.
(2) The Provider is furthermore liable without limitation for damage caused intentionally or by gross negligence.
(3) In the case of slight negligence, the Provider is liable only in the event of a breach of material contractual obligations (cardinal obligations). In this case liability is limited to the damage typical for the contract and foreseeable, but at most to the net remuneration agreed for the respective order. A different maximum amount may be agreed in the offer.
(4) In the case of slight negligence, the Provider is not liable for indirect damage, consequential damage, lost profit and savings not realised, unless, in the event of a breach of a cardinal obligation, such damage forms part of the damage typical for the contract and foreseeable within the meaning of paragraph 3.
(5) Without prejudice to paragraphs 1 to 3, the Provider is not liable for:
- Economic decisions of the Client that are taken on the basis of consulting or analyses of the Provider
- Individual incorrect outputs of AI systems within the tolerance agreed under § 15a (1)
- Loss of data, insofar as the Client has not carried out an appropriate data backup
- Failures or malfunctions of external systems and third-party services
- Damage arising from late or absent cooperation of the Client
(6) The Client is obliged to take appropriate measures to prevent and mitigate damage, in particular to ensure regular data backups and access control.
(7) The Provider provides information on its insurance cover (business and professional indemnity insurance) on request.
§ 11 Support, maintenance and further development
(1) Ongoing support, maintenance, updates and further development are not part of the project services and require a separate contractual agreement (e.g. a service level agreement).
(2) Without a separate agreement, responsibility for the operation, security, updating and functionality of the delivered solutions lies with the Client. The warranty under § 9 remains unaffected.
(3) The Provider expressly points out that software and AI systems require regular maintenance and updating in order to maintain functionality and security.
(4) Notwithstanding paragraphs 1 and 2: where a maintenance agent is expressly described in the offer as part of the services, it forms part of the work to be delivered. The maintenance agent runs continuously in the Client’s environment, checks the delivered workflows, performs ongoing maintenance and automatic updates and thereby supports autonomous operation; in the event of serious errors it shuts down the affected workflow and informs the contact person named by the Client without undue delay. This does not include an on-call service, guaranteed response times or an availability commitment (service level agreement). The operating costs of the maintenance agent, in particular token costs, are borne by the Client.
§ 12 Intellectual property and rights of use
(1) All copyrights, intellectual property rights and industrial property rights in the services created by the Provider (concepts, documentation, software, code, workflows, training materials) remain with the Provider.
(2) Upon full payment of the agreed remuneration, the Client receives a simple, non-transferable, non-sublicensable right of use of the contractually agreed services for the agreed purpose. The right of use includes use by companies affiliated with the Client (§ 15 AktG) and by the Client’s institutions and sites named in the offer.
(3) Until full payment has been made, the right of use is limited to testing and acceptance. In the event of default of payment, the Provider may block access to delivered solutions if it has first sent the Client a reminder, set a reasonable grace period and announced the block in text form at least 14 days in advance. For systems under § 20 (healthcare), a block is excluded.
(4) Any transfer, publication, sublicensing or other exploitation beyond the agreed purpose requires the express written consent of the Provider.
(5) The Provider is entitled to use the services rendered in anonymised form as a reference in its portfolio unless the Client expressly objects.
(6) The solutions created by the Provider may contain open-source components (e.g. under MIT, Apache 2.0, GPL or comparable licences). On request, the Provider will inform the Client about the open-source components used and their licence terms.
(7) The Client is itself responsible for complying with the respective open-source licence terms, in particular in the case of redistribution, publication or commercial exploitation of the software. The Provider is not liable for breaches of open-source licences by the Client.
(8) Insofar as content is generated by AI systems in the course of the provision of services (texts, code, images, concepts etc.), the Provider points out that the eligibility of such content for copyright protection is unresolved under applicable German law. The Provider gives no warranty that AI-generated content enjoys copyright protection or is free from third-party rights.
(9) For work created individually for the Client (software, workflows, prompt templates, configurations), the Client receives the sources in editable form upon full payment and may modify and further develop them for its own operation. For errors resulting from such modifications, § 9 (5) applies. There is no claim to the release of the sources of the Provider’s standard components and blueprints (paragraph 10); a source code escrow arrangement requires a separate agreement.
(10) Blueprints: the Provider is entitled to derive blueprints from all AI systems, automations and workflows it has created, to store and further develop them and to use them for its own purposes and for services to other clients. Blueprints are abstracted, reusable components, in particular architectures, process and data models, templates for prompts and rule sets, code modules, configurations and validation routines. They contain no personal data, no data or content from the Client’s systems and no confidential information of the Client within the meaning of Section 13; client-specific names, metric values and trade secrets are removed before adoption. Personal data that the Provider processes on behalf of the Client are processed exclusively on the Client’s instructions and are not used for blueprints. The Provider may freely use the general expertise acquired in the course of the cooperation. The rights to the blueprints remain with the Provider (para. 1); the Client’s right of use under para. 2 remains unaffected.
§ 13 Confidentiality and data protection
(1) Both parties undertake to treat all confidential information of the respective other party obtained in the course of the cooperation as strictly confidential and neither to make it accessible to third parties nor to exploit it in any other way.
(2) This confidentiality obligation continues beyond the end of the contract for a period of 3 years. For trade secrets within the meaning of the German Trade Secrets Act (GeschGehG) and for information subject to professional secrecy under § 203 StGB, it applies without time limit.
(3) Excluded from the confidentiality obligation is information which:
- is or becomes publicly known without the receiving party being responsible for this
- was already known to the receiving party before disclosure
- must be disclosed on the basis of a statutory obligation
- was demonstrably developed independently by the receiving party
(4) Personal data are processed exclusively in accordance with the GDPR and the BDSG (German Federal Data Protection Act). Where the Provider processes personal data on behalf of the Client, the parties conclude a data processing agreement pursuant to Art. 28 GDPR before processing begins; the Provider provides a template for this purpose.
§ 14 Contract term and termination
(1) The contract term follows from the respective individual agreement.
(2) Continuing obligations (e.g. ongoing consulting, support, maintenance) may be terminated ordinarily by either party with a notice period of 30 days to the end of the month unless agreed otherwise.
(3) The right to extraordinary termination for good cause remains unaffected. Good cause exists in particular if:
- A party breaches material contractual obligations despite a written reminder and the setting of a reasonable deadline
- Insolvency proceedings are opened over the assets of a party or the opening is refused for lack of assets
- The Client falls into default of payment of more than 30 days
(4) In the event of termination, services already rendered and expenses incurred must be remunerated without undue delay.
(5) Terminations must be made in text form (§ 126b BGB; email is sufficient).
§ 15 EU AI Act (Regulation (EU) 2024/1689) and regulatory requirements
(1) The Provider renders its services taking into account the regulatory requirements applicable at the time the services are rendered, in particular Regulation (EU) 2024/1689 (“EU AI Act”).
(2) Responsibility for compliance with regulatory obligations that are incumbent on the deployer of an AI system lies exclusively with the Client. This includes in particular:
- The risk classification of the AI system used (prohibited, high-risk, limited, minimal)
- Compliance with transparency obligations towards the persons concerned (e.g. labelling of AI-generated content)
- Carrying out a fundamental rights impact assessment for high-risk AI systems
- Human oversight of AI-assisted decision-making processes
- The registration of high-risk AI systems in the EU database
(3) The Provider supports the Client on request in assessing regulatory requirements. This does not constitute the provision of legal advice. The Provider recommends that the Client consult a specialist lawyer for the legal assessment.
(4) Changes to regulatory requirements that come into force after the services have been rendered do not establish any claim to rectification. Any necessary adjustments must be remunerated separately.
(5) Intended purpose: the systems created by the Provider do not evaluate persons. They exclusively check the completeness of data and do not enter any data into the Client’s systems (review only, read-only access), unless expressly agreed otherwise in writing in the individual case.
(6) If the Client uses outputs of the systems in deviation from the intended purpose – in particular to evaluate the performance or behaviour of individual employees, which may trigger a classification as a high-risk AI system under Annex III No. 4 of Regulation (EU) 2024/1689 –, the classification, the resulting obligations and the responsibility therefor lie exclusively with the Client. The Provider shall not be liable for damage resulting from such use contrary to the intended purpose; Section 10 (1) and (2) remain unaffected.
§ 15a AI outputs, hallucinations and the Client’s duty to review
(1) AI systems may output content that is factually incorrect, incomplete, outdated or invented (so-called “hallucinations”). This is a characteristic inherent in generative AI models at the current state of the art. Individual incorrect outputs do not constitute a defect as long as the system meets the quality metric agreed in the offer (e.g. detection rate in the acceptance test). If the offer contains no metric, the value documented in the acceptance test under § 7 is deemed agreed.
(2) All AI-generated outputs (texts, code, analyses, proposed decisions, forecasts) are non-binding work results. The Client is obliged to review these in terms of content and subject matter through qualified personnel before productive or business-critical use (“human-in-the-loop” principle).
(3) Human control is mandatory in particular for the following applications:
- Decisions with legal effect towards third parties (e.g. conclusions of contracts, reminders, terminations)
- Medical, tax, legal or financial information provided to end customers
- Automated messages to customers, suppliers or authorities
- Publication of content (website, social media, advertising)
- Execution of security-relevant scripts or code deployments in production systems
(4) The Provider is not liable for damage arising from the unreviewed adoption of AI-generated outputs, unless there is statutory liability for intent or gross negligence.
(5) Labelling obligation: The Client is obliged to label AI-generated content that is published to end users accordingly, in accordance with the transparency obligations of the EU AI Act (Art. 50).
(6) Data quality: The Client ensures that the input data transmitted to AI systems have been collected lawfully and do not infringe any copyright, personality or confidentiality rights of third parties. The Client indemnifies the Provider against third-party claims arising from breaches of this obligation.
§ 16 Remote maintenance and remote access
(1) Insofar as remote access to systems of the Client is required for the provision of services, the Client shall provide the necessary access (VPN, SSH, API keys etc.).
(2) The Provider uses the access provided exclusively for the contractually agreed purposes and does not pass on access credentials to unauthorised third parties.
(3) The Client is responsible for the security of its own systems, in particular for:
- The establishment of appropriate access restrictions (principle of least privilege)
- The monitoring and logging of access
- The withdrawal of access credentials after the end of the contract
(4) The Provider is not liable for damage arising from inadequate security measures on the part of the Client.
§ 17 Data retention and deletion after the end of the contract
(1) After termination of the contract, the Provider retains project-related data and documents for a period of 90 days, unless statutory retention obligations (e.g. pursuant to § 257 HGB (German Commercial Code), § 147 AO (German Fiscal Code)) require longer retention.
(2) Within this period the Client has the right to demand the release of its data in a machine-readable format. After expiry of the period, the data will be irrevocably deleted unless a statutory retention obligation exists.
(3) Personal data are deleted in accordance with Art. 17 GDPR as soon as the purpose of the processing ceases to apply and no statutory retention obligations conflict with this.
(4) The Provider confirms the deletion in writing at the request of the Client.
§ 18 Force majeure
(1) Neither party is liable for non-performance or delayed performance of its contractual obligations to the extent that this is attributable to circumstances of force majeure.
(2) Force majeure is deemed to include in particular: natural disasters, pandemics, strikes, official orders and large-scale power outages. Cyberattacks and failures of essential cloud infrastructure are deemed force majeure only if they were unavoidable despite appropriate security and precautionary measures of the affected party.
(3) If a case of force majeure lasts longer than 60 days, either party may terminate the contract in text form with regard to the services not yet rendered.
§ 19 Client portal
(1) Purpose and range of functions. The Sophera client portal (hereinafter “Portal”) enables registered Clients to access project-related functions, in particular: overview and management of ongoing projects, appointment booking and meeting minutes, download of catalogues and project documents, release approval of project documents, team management (invitation of further users), payment processing (credit card, SEPA via Stripe), access to roadmaps and project status.
(2) Access requirements. Use of the Portal presupposes an existing business relationship. Portal access is activated by the Provider and takes place via password-protected accounts. The Client is obliged to keep access credentials secret and not to pass them on to third parties. If misuse is suspected, the Provider must be informed without undue delay.
(3) Consent before first use. Before using the Portal for the first time, every user (owner, administrator or member) must expressly accept the Portal GTC as well as the privacy policy in their respective current version. Consent is logged in an audit-proof manner with time stamp, version, IP address and user agent.
(4) User roles and liability of the owner. Within the client portal, the Provider distinguishes three Client-internal roles:
- Owner: primary contact person at the Client (e.g. management), full rights within the Client account
- Administrator: further person at the Client with invitation and approval rights
- Member: Client-internal employees with read rights and document download
The Provider (Sophera Consulting) is not part of this Client-internal role structure, but administers the Portal via a separate administrative interface (admin dashboard). The Client is responsible for the actions of the users invited by its owner or its administrators as for its own actions (§ 278 BGB).
(5) Team invitations. The owner or an administrator may add further team members by email invitation. The invited person must consent to the use of the Portal and to the data processing independently. The owner ensures that invited persons are authorised to process company-related data.
(6) Payment processing via the Portal. Payments are processed via the payment service provider Stripe (Stripe Technology Europe Limited, Dublin, Ireland). The Client may store payment methods in the Portal; tokenisation takes place directly at Stripe — the Provider does not receive complete card or account details. Billing takes place in accordance with the respective contract; invoices are additionally sent by email. § 8 (remuneration and terms of payment) remains unaffected.
(7) Document release (release feature). Project documents that the Provider releases for final download may be accepted by the Client in the Portal via the button expressly labelled “Declare acceptance”. By this confirmation, the Client declares acceptance of the relevant part of the work pursuant to § 640 BGB; § 7 otherwise remains unaffected.
(8) Availability. The Provider endeavours to achieve Portal availability of 99 % on an annual average, however without contractual assurance. Maintenance windows will be announced in advance where possible. Short outages do not give rise to any claim to rescission of the contract or to damages, unless the Provider acts intentionally or with gross negligence.
(9) Portal deactivation by the Provider. The Provider may deactivate the Portal account of a Client upon the end of the business relationship (90 days grace period), in the event of default of payment of more than 30 days or in the event of misuse of the Portal (e.g. passing on of access credentials). Upon deactivation, data will be deleted or archived in accordance with § 17 and the privacy policy.
(10) Termination of Portal access by the Client. The Client may terminate Portal access in writing at any time by email to fey@sopheraconsulting.de. This leads to deactivation of the account; the underlying business relationship remains unaffected by this.
(11) Roadmaps. The Provider makes project roadmaps available in the Portal that visualise the planned course of the project, milestones and delivery dates. Roadmap entries constitute a non-binding planning aid and have no binding character with regard to specific delivery dates, unless these have been expressly designated as binding in text form (cf. § 4 (4)). Changes to roadmaps are presented transparently to the Client in the Portal; there is no claim to the retention of a previously displayed plan.
(12) Data protection. Details on the data processing in the Portal are governed by section 7.6 of the privacy policy.
(13) Exclusion of liability for use of the Portal. § 10 (liability) applies accordingly to the use of the Portal. Within the scope of § 10 (3) to (5), the Provider is not liable for the following Portal-specific risks:
- Incorrect operation by users: Loss of data or malfunctions arising from incorrect operation of the Portal by the Client or its team members (e.g. accidental deletion of documents, misconfigurations, faulty document releases).
- Passing on of access credentials: Damage arising from the unauthorised passing on of Portal passwords, email access or session cookies by the Client or its team members.
- Content uploaded by the Client: Damage and third-party claims arising from content that the Client or its team uploads to the Portal, including infringements of copyright, personality, data protection or confidentiality rights. In this respect the Client indemnifies the Provider against third-party claims.
- Payment processing via Stripe: Damage arising from the payment processing itself (debiting errors, chargebacks, cases of fraud, disruptions of the Stripe service), unless they are based on fault of the Provider in selection or monitoring. Under data protection law, Stripe is an independent controller.
- Third-party provider failures: Disruptions, outages, loss of data or security incidents at the infrastructure service providers used by the Provider (Supabase, Vercel, Google, AWS, Stripe and others), unless these are based on intentional or grossly negligent conduct of the Provider in their selection or monitoring.
- Interruptions of availability: The availability of 99 % on an annual average referred to in paragraph (8) constitutes a non-binding target figure. Short outages, maintenance windows or delayed performance do not give rise to claims for damages.
- Consequential damage from roadmap planning: Roadmaps are non-binding planning aids (cf. paragraph 11). Economic dispositions of the Client on the basis of Portal roadmaps are made at the Client’s own risk.
- AI-generated content in the Portal: Transcripts, summaries and analyses created by AI systems (e.g. Gemini meeting notes) are non-binding work results. § 15a of these GTC (AI outputs, hallucinations and the duty of the Client to review) applies.
- Data portability after Portal deactivation: After expiry of the 90-day grace period (paragraph 9), the Provider is no longer liable for the availability of data that has not been exported. The Client is obliged to request its data export in good time.
(14) Maximum liability limit for use of the Portal. Insofar as the Provider is liable for slight negligence, liability for all damage in connection with the use of the Portal is limited per calendar year to the damage typical for the contract and foreseeable, but at most to the amount that the Client actually paid for Portal-related services of the Provider in the relevant calendar year, but at least to EUR 10,000. Unlimited liability in the case of intent, gross negligence, injury to life, body or health and under the Product Liability Act remains unaffected; in this respect § 10 (1) and (2) of these GTC apply.
§ 20 Special terms for healthcare clients
(1) Scope and order of precedence: the following provisions apply to clients operating hospitals, care facilities, medical care centres, medical practices or other healthcare institutions, including church and public bodies. They take precedence over the other provisions of these GTC. For the processing of personal data, the data processing agreement takes precedence over all other provisions. Otherwise, the offer or individual contract takes precedence over this § 20, and this § 20 takes precedence over the other provisions of these GTC.
(2) Data protection law and processing on behalf: depending on the body, the Church Data Protection Act (KDG), the Data Protection Act of the EKD (DSG-EKD) or state law, in particular state hospital acts, apply in addition to or instead of the GDPR. The Provider processes the Client’s personal data solely as a processor on the Client’s instructions and on the basis of a data processing agreement concluded before processing begins (Art. 28 GDPR, § 29 KDG or § 30 DSG-EKD). Without such an agreement the Provider is given no access to patient or employee data.
(3) Sub-processors and place of processing: notwithstanding § 6 (4), the Client’s data is transferred only to the sub-processors conclusively named in the offer or the data processing agreement. Processing takes place in the European Union; AI models are operated via EU regions (e.g. Amazon Bedrock with an EU profile) unless otherwise agreed in writing. The services used are selected and configured so that the Client’s data is not used to train AI models. The Provider notifies the Client in advance of changes to sub-processors; the Client may object in accordance with the data processing agreement.
(4) Health data: § 6 (6) does not apply insofar as the processing of health data and other special categories of personal data (Art. 9 GDPR) is the subject of the engagement and is governed by the data processing agreement. The Provider processes only the data required for the agreed purpose and pseudonymises it where the purpose allows.
(5) Liability for sub-processors: for the sub-processors engaged under paragraph 3, the Provider is liable exclusively under the data processing agreement and the statutory provisions; § 6 (5) sentence 2 does not apply (Art. 28 (4) and Art. 82 GDPR or the corresponding church law provisions). For damage arising from breaches of data protection law, a liability cap deviating from § 10 (3) may be agreed in the offer or the data processing agreement. The Provider provides information on its insurance cover on request.
(6) Professional secrecy under § 203 German Criminal Code (StGB): the Provider participates in the Client’s professional activity as an other contributing person within the meaning of § 203 (3) sentence 2 StGB and is bound to secrecy. It obliges all persons it engages to secrecy in text form before they start work, instructs them on the criminal consequences of a breach, and involves further persons or subcontractors only where this is necessary for the service and they are obliged in the same way (§ 203 (4) sentence 2 StGB). On request, the Provider signs the Client’s declaration of commitment provided for this purpose.
(7) Information security: the Provider supports the Client in meeting its information security obligations, in particular under § 391 SGB V (formerly § 75c SGB V), the industry-specific security standard for hospital healthcare (B3S) and, where applicable, the BSI Act. It provides a description of its technical and organisational measures and accesses systems only through the accounts set up by the Client, with the rights required for the service; the Client may revoke this access at any time. The Provider reports security incidents and personal data breaches to the Client without undue delay. Participation in inspections and audits beyond the scope agreed in the offer is charged by effort.
(8) Not a medical device: the systems serve organisation, checking of documentation and reporting. They do not make diagnoses, give no therapy recommendations and are not intended to detect, monitor or predict diseases; they are not medical devices within the meaning of Regulation (EU) 2017/745. Notices and alerts from the systems, for example about missing documentation, do not replace professional assessment by the Client’s staff. The intended purpose under § 15 (5) applies; § 15 (6) applies accordingly to use for medical purposes.
(9) Rule set and thresholds: notwithstanding § 9 (5) and § 12 (4), the Client may itself adjust the business rules, thresholds, recipients and times that are configurable according to the documentation. The warranty for the remaining parts of the service remains unaffected. The Provider is not liable for errors directly caused by such an adjustment.
(10) References: notwithstanding § 12 (5), the Provider names the Client or services rendered for it as a reference only with the Client’s prior express consent in text form. The right to blueprints under § 12 (10) remains unaffected; blueprints contain no information that allows conclusions about the Client.
(11) Return and deletion: notwithstanding § 17 (1) and (2), after the end of the contract or at the Client’s request, the Provider returns or deletes, at the Client’s choice and without undue delay, personal data from the Client’s systems, in particular patient and employee data, unless there is a statutory obligation to retain it. This also applies to intermediate results, logs and copies held by sub-processors. The Provider confirms deletion with a deletion log in text form. Data held in the Client’s own systems or accounts is managed by the Client.
(12) Co-determination: if the use of the systems is subject to co-determination, for example under the Catholic employee representation regulations (MAVO), the EKD Employee Representation Act, works constitution law or staff representation law, the Client obtains the required consent before productive operation. On request, the Provider provides a description of the systems for this purpose.
§ 21 Applicable law
(1) The law of the Federal Republic of Germany applies exclusively, to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG) and to the exclusion of private international law.
(2) This also applies to Clients domiciled abroad.
§ 22 Place of jurisdiction
(1) The exclusive place of jurisdiction for all disputes arising from or in connection with the contractual relationship is – to the extent legally permissible – 50126 Bergheim (Rhein-Erft-Kreis), Germany.
(2) This agreement on the place of jurisdiction also applies to Clients domiciled abroad, to the extent legally permissible.
§ 23 Severability clause
(1) Should individual provisions of these GTC be or become invalid in whole or in part, the validity of the remaining provisions shall remain unaffected by this.
(2) The statutory provisions take the place of an invalid provision (§ 306 (2) BGB).
(3) Amendments to these GTC for an existing contractual relationship must be made in text form. Individual agreements under § 1 (5) remain unaffected.