KORTHEXkorthex.io

Service Level Agreement for Korthex

This Service Level Agreement (SLA) describes the tier-based support, availability, and security services for Korthex (Free, Community, Business, Enterprise). It supplements the general terms of Flowence Infrastructure (https://flowencehq.com/terms) and the product-specific terms for Korthex (https://korthex.io/terms) and constitutes the deviating agreement foreseen in § 8(1) of the general terms. For the Business and Enterprise tiers it is concluded as an individual agreement and takes precedence over the aforementioned terms within its scope (§ 305b BGB).

1. Preamble and Contracting Parties

This Service Level Agreement (hereinafter "SLA") is concluded between the Provider and the Customer (together the "Parties").

The subject matter of this SLA is the tier-based support, availability, and security services for the operation and maintenance of the "Korthex" software. Korthex is a platform for cryptographic security analysis, inventory, and migration planning and a product of Flowence Infrastructure.

This SLA supplements (a) the general terms and conditions of Flowence Infrastructure, available at https://flowencehq.com/terms (hereinafter "General Terms"), and (b) the product-specific terms of service for Korthex, available at https://korthex.io/terms (hereinafter "Korthex Terms"). It constitutes the deviating agreement expressly foreseen in § 8(1) of the General Terms.

The service levels of this SLA apply in a tiered manner to the Free, Community, Business, and Enterprise plans. For the Free plan, services are provided on a best-effort basis only, without committed times or availability. Binding response, resolution, and availability commitments and service credits apply only to the paid plans in accordance with the following sections. For the Business and Enterprise plans, this SLA is concluded as an individual agreement.

Unless this SLA provides otherwise, the Korthex Terms and, supplementarily, the General Terms continue to apply.

In the event of conflict, the order of precedence of the contractual documents agreed in Section 1 of the Korthex Terms applies. Under that order, this SLA prevails over the Korthex Terms and the General Terms within its scope; individual agreements between the parties and the order confirmation prevail over this SLA. The precedence of this SLA derives from that agreed order and not from classifying this document as an individually negotiated agreement.

In its pre-formulated version, this SLA constitutes standard business terms within the meaning of Section 305(1) of the German Civil Code (BGB) and is subject to review under Sections 305 et seq. BGB. An individually negotiated agreement within the meaning of Section 305b BGB exists only in so far as an individual provision has actually been negotiated between the parties. Where that is the case, the negotiated provision prevails over all pre-formulated provisions, without any need for it to be specially marked as such.

The Provider offers Customers on the Business and Enterprise plans the opportunity to negotiate the provisions of this SLA upon request. Where a provision is amended on that basis, the parties will record the amended version in text form; it is then deemed individually negotiated within the meaning of the preceding paragraph.

References in this SLA to individual provisions of the Korthex Terms or the General Terms refer to the version of the respective document applicable at the time the contract was concluded. If the numbering there changes, the reference applies to the provision governing the same subject matter. Where a reference does not resolve, the provision that most closely corresponds to the designated subject matter applies; the validity of the remaining provisions remains unaffected.

The Provider is currently operated as a sole proprietorship. Should the Provider intend to transfer the business operations relating to Korthex to a company, in particular to a GmbH yet to be incorporated, it will inform the Customer in text form at least thirty (30) days before the intended transfer. The notice will identify the acquiring company, the date of the transfer, and the fact that this SLA continues to apply unchanged in substance.

The Customer may object to the transfer of the contract in text form within thirty (30) days of receiving the notice. If the Customer does not object, consent to the assumption of this contract by the named company is deemed granted; the Provider will expressly point out this legal consequence and the objection period in the notice. If the Customer objects, the existing contracting party remains the contracting party; in that case either party may terminate the contract upon three (3) months’ notice to the end of the current contract year. Until the transfer takes effect, the existing contracting party remains responsible for all obligations under this SLA.

2. Definitions

For the purposes of this SLA, the following definitions apply. The definitions of the Korthex Terms and the General Terms apply supplementarily.

List of abbreviations:

3. Service Description

3.1 Scope of services. Under this SLA and depending on the selected plan, the Provider performs the following services: (a) tiered technical support pursuant to Sections 4 and 5; (b) operation of the Portal with the availability committed in Section 4.1 (Business and Enterprise); (c) security-related maintenance of the software pursuant to Section 4.4; (d) escalation and incident management pursuant to Section 6; (e) regular reporting pursuant to Section 10 (Business and Enterprise).

3.2 Plan dependency. The Free plan includes no committed service levels; support is provided exclusively via documentation and publicly available community resources (best effort). The paid Community plan includes support during service hours with committed response times but no availability commitment and no service credits. The Business plan additionally includes a portal availability commitment and service credits. The Enterprise plan includes the highest service level, including 24x7 handling of critical incidents.

3.3 Excluded services. The following are, in particular, not the subject of this SLA: (a) an availability commitment for the locally operated Client (cf. § 8(1) of the General Terms); (b) the processing, storage, or backup of the Customer's source code or analysis results, as these do not leave the Customer's system (offline-first architecture); (c) ensuring the Customer's compliance with regulatory requirements (cf. § 10(8) of the General Terms); (d) customizations, training, or integration services unless separately agreed.

3.4 Service locations and operating environment. The Client is operated on the Customer's systems. The Portal's API infrastructure is operated at Vercel with a processing region in the European Union. The database and storage infrastructure is operated in the United Kingdom (Supabase, London). Support is provided remotely.

3.4.1 No commitment to exclusive EU processing. Individual technically necessary network, delivery, and operational components of the providers used may also be located outside the European Economic Area or administered from there. The Provider therefore does not commit to processing exclusively within the European Union. For transfers to third countries, the safeguards described in Section 11 and in the Korthex Privacy Policy apply, in particular adequacy decisions or standard contractual clauses. Where the Customer requires processing restricted to particular regions, this requires a separate agreement.

3.5 Technical prerequisites and dependencies. The committed service levels apply only if the Customer operates the software in an environment supported by the Provider, installs required updates within the agreed periods, and provides the network connectivity required for license activation and optional relay/update services. A complete list of supported configurations is set out in Annex D.

4. Service Levels and KPIs

4.1 Availability. The following availability commitments relate exclusively to the Portal and are measured per calendar month. The locally operated Client is not subject to an availability commitment. When the Air-Gapped License is used, ongoing Client operation remains largely unaffected by Portal outages.

Recovery targets for the Portal: Business RTO 8 hours / RPO 24 hours; Enterprise RTO 4 hours / RPO 12 hours. The technical and organisational measures underlying these targets, in particular encrypted backups and the restoration procedures, are described in Section 11 of this SLA and in Section 11 of the Korthex Privacy Policy.

4.2 Response and resolution times by priority. Incidents are classified according to the priorities P1 to P4 defined in Section 6.1. The response and resolution targets applicable per plan are set out in the plan details (Section 5). All times are measured from receipt of a correctly classified incident via an approved channel.

4.3 Performance metrics. The Client's analysis performance (throughput, scan duration) depends significantly on the Customer's hardware and codebase; the Provider therefore does not commit to specific throughput or latency values. For interactive Portal endpoints, a target median response time of under 1 second applies.

4.4 Security SLA. The Provider assesses security-relevant vulnerabilities in the software using CVSS and provides a patch or documented mitigation within the following target times. The period begins with the Provider's verification of the vulnerability. The target times below apply to the Business and Enterprise plans; in the Free and Community plans, security fixes are provided as part of the next regular release.

Security updates are provided to consumers using the Free plan as a digital product, irrespective of the plan tiers above, pursuant to § 327f BGB.

4.5 Measurement points, methodology, and reporting period. Portal availability is measured based on the Provider's server-side monitoring. The reporting period is the calendar month. Announced maintenance windows (Section 5.4) and excluded events (Section 13.4) are excluded from the availability calculation. Results are reported pursuant to Section 10.

4.6 Reporting obligations under the Cyber Resilience Act. The target times under Section 4.4 concern the provision of fixes to the Customer. These are to be distinguished from the Provider's own reporting obligations as the manufacturer of a product with digital elements under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act). Those obligations apply from 11 September 2026, exist irrespective of the Customer's plan, and apply irrespective of whether a patch is already available.

Where the Provider becomes aware of an actively exploited vulnerability in Korthex or of a severe security incident affecting the security of Korthex, it will submit (a) an early warning to the CSIRT designated as coordinator and to ENISA within 24 hours of becoming aware, (b) a notification within 72 hours setting out the nature and impact and, where available, corrective or mitigating measures, and (c) a final report, for vulnerabilities within 14 days of a corrective or mitigating measure becoming available and, for severe incidents, within one month of the notification under point (b).

The Provider will inform affected Customers without undue delay after becoming aware of the vulnerability or incident and, where necessary, about mitigating measures and about steps the Customer can take. Such information is provided to the email address stored in the user account and, where one exists, to the designated technical contact. This information is provided irrespective of the target times under Section 4.4 and is not deferred until a patch becomes available.

Reporting obligations under other provisions, in particular Articles 33 and 34 GDPR in the event of a personal data breach, remain unaffected and apply in addition to the obligations under this Section. The Provider maintains documented processes, reporting channels, and responsibilities for both categories.

5. Support Hours and Plan Services

5.1 Regular service hours. Support is generally provided within the service hours (Section 2).

5.2 24x7 on-call. For P1 incidents, on-call coverage outside service hours (24x7) is maintained in the Enterprise plan. In the other plans, there is no on-call coverage outside service hours.

5.3 Contact channels. The approved channels for reporting incidents are the ticket system provided in the user account and the support email address; for P1 incidents in the Enterprise plan, an additional escalation phone number. Reports via other channels do not trigger service-level deadlines.

The specific contact details, including the escalation telephone number, are set out in Annex E. The Provider will send Annex E to the Customer in text form no later than when access is enabled and, for Enterprise agreements, no later than five (5) business days after conclusion of the contract, and will keep it up to date. For as long as the Customer has not been provided with an escalation telephone number, a ticket raised in the user account with priority P1, together with a parallel message to the support email address, counts as a permitted reporting channel for P1 incidents; in that case the periods under Section 5.2 run from receipt of that report. A missing or outdated Annex E is not to the Customer's detriment.

5.4 Maintenance windows. Planned maintenance is announced in advance and scheduled to minimize impact. Emergency maintenance may be carried out without observing the notice period where necessary to avert security or stability risks.

6. Incident and Problem Management

6.1 Incident classification and priorities. Incidents are classified by their impact, irrespective of the Customer's plan. The Provider assigns the initial priority; reclassification is made by mutual agreement.

Providing a workaround does not automatically result in a downgrade of the priority. A downgrade requires that the workaround actually removes the impairment for the use presupposed under the contract and meets the conditions that Section 9 of the Korthex Terms sets out for a workaround to be reasonable, in particular that it functions in automated environments without manual intervention. If the Customer does not agree to a downgrade, the existing priority remains decisive until final resolution; the Provider may have the classification clarified in accordance with Section 16.

The obligation to provide a final resolution continues to apply after a downgrade. Section 9 of the Korthex Terms governs the period for replacing a workaround with a permanent fix; for security-relevant vulnerabilities, the target times under Section 4.4 apply in addition.

6.2 Status updates. While an incident is being handled, the Provider informs the Customer of the processing status at recurring intervals (update interval). The update interval applicable to each plan and priority is set out in the plan details in Section 5. Where no update interval is stated there for a priority, the Provider will inform the Customer at least weekly for P3 incidents and upon handling the matter for P4 incidents. An update interval is deemed missed if the Provider has not reported the processing status within the applicable period; time outside service hours is disregarded unless 24x7 handling has been agreed.

6.3 Escalation levels and processes. If the handling of an incident does not progress within the committed times, the Customer may escalate as follows in the paid plans:

6.4 Problem management and root cause analysis (RCA). For recurring incidents and for every P1 incident, the Provider conducts a root cause analysis and documents suitable measures to prevent recurrence.

6.5 Postmortem for critical incidents. After a P1 incident is closed, the Provider provides the Customer (Business and Enterprise), upon request, within 5 business days a written postmortem report describing the sequence of events, cause, measures taken, and preventive measures.

7. Change Management

7.1 Change types. Changes to the Portal and the software are distinguished into standard changes (low risk, pre-approved), normal changes (planned, with notice), and emergency changes (to avert acute security or stability risks).

7.2 Approval. As the Service is provided centrally by the Provider, the Provider decides on the approval of changes. There is no formal customer change advisory board. A change may be approved only where a valid reason within the meaning of Section 3 of the Korthex Terms exists; the catalogue exhaustively set out there applies accordingly. The Provider limits a change to what is necessary to achieve that reason.

7.2.1 Notice. Standard changes are not announced separately. Normal changes affecting the Customer are announced pursuant to Section 5.4. Where a normal change is likely to impair the Customer's use of the Portal or the software more than insignificantly, the Provider will announce it in text form at least thirty (30) days before the planned effective date, stating its content, timing, the applicable valid reason, and the expected effects.

7.2.2 Objection. The Customer may object to a change under Section 7.2.1 in text form within ten (10) business days of receiving the notice, setting out the specific impairment. The Provider will review the objection and inform the Customer before the effective date whether it will adjust, postpone, or implement the change unchanged; in the latter case it will give reasons. An objection does not suspend implementation where the change is necessary to avert security or stability risks or to comply with a legal obligation.

7.2.3 Consequences of a material impairment. Where an implemented change permanently impairs contractual use more than insignificantly, the Customer may terminate the contract upon thirty (30) days' notice; Section 15 applies accordingly to the settlement. Where the Provider does not make a functionally equivalent alternative available, it will credit the remuneration attributable to the affected scope of services and period on a pro rata basis. In relation to consumers, the rights under Section 3 of the Korthex Terms and under Section 327r of the German Civil Code (BGB) remain unaffected.

7.2.4 Emergency changes. Emergency changes may be implemented without prior notice and without an opportunity to object. The Provider will inform the Customer without undue delay after implementation of the cause, content, and effects, and will include the change in the reporting under Section 10.

7.3 Release and deployment management. Software releases are provided according to a documented release process. The Customer is obligated to install security-relevant releases within the periods stated in Annex D.

7.3.1 Conditions for relief. Where the Customer fails to install a security-relevant release, the Provider may rely on that failure only if it has previously informed the Customer of the availability of the release, of the consequences of failing to install it, and of proper installation, and the installation instructions were not defective. These conditions apply equally in relation to entrepreneurs and consumers; in relation to consumers, Section 327f(2) of the German Civil Code (BGB) applies in addition.

7.3.2 Scope of relief. Where the conditions of Section 7.3.1 are met, the service-level commitments are suspended only to the extent that the impairment is actually caused by the absence of the release not installed, and only for the duration of that state. Service-level claims do not lapse for the entire reporting period or for matters not affected by it. The availability commitments for the Portal remain unaffected unless the impairment of the Portal is itself caused by the missing release. In all other respects, the principle of Section 8.4 applies accordingly: delays extend the affected periods without the claim lapsing in principle.

7.3.3 Subsequent installation. Once the Customer installs the release, the service-level commitments apply again without restriction from the time of successful installation.

8. Customer's Duties to Cooperate

8.1 The Customer provides the Provider with the information, access, and diagnostic data required for the performance of services in a reasonable scope and in a timely manner.

8.2 The Customer designates one or more responsible contacts and their deputies and notifies changes without undue delay (Annex E).

8.3 The Customer complies with the minimum technical requirements set out in Annex D, operates the software in a supported environment, and installs required updates on time.

8.4 The Customer reports incidents via the approved channels, providing the information required for diagnosis. Delays attributable to insufficient cooperation extend the service-level deadlines accordingly.

9. Responsibilities and Roles

9.1 Responsibility matrix (RACI). The following matrix allocates responsibility for key activities. R = Responsible, A = Accountable, C = Consulted, I = Informed.

The matrix serves to allocate roles and as an aid to interpretation. It does not create obligations going beyond the contractual provisions and does not create independent claims. Where the matrix and the obligations set out in Sections 3, 7, and 8 of this SLA or in the Korthex Terms diverge, those provisions prevail.

9.1.1 Migration recommendations. The assessment, approval, and implementation of migration recommendations rest with the Customer; Section 10 of the Korthex Terms remains unaffected. The Customer may raise questions about a recommendation through the approved support channels; the Provider will respond in accordance with the response times applicable to the Customer's plan. Where the Customer reports a recommendation it considers incorrect or incomplete, the Provider will review the report as an incident under Section 6 and will treat a confirmed misjudgement of the detection or recommendation logic as a defect under Section 9 of the Korthex Terms.

9.2 Contacts of both parties. The named technical and commercial contacts and their availability are set out in Annex E.

9.3 Third parties and subcontractors. The Provider is entitled to use subcontractors (e.g. hosting, payment, and email service providers) to perform the services. Insofar as personal data is processed on behalf in this context, the data processing agreement pursuant to Annex C applies. The Provider remains responsible to the Customer for the services of its subcontractors.

10. Reporting and Review

10.1 Regular service reports. The Provider provides the Customer with the following reports in the Business and Enterprise plans:

10.2 SLA review cycles. The Parties review the appropriateness of the agreed service levels at least annually and adjust them by mutual agreement where necessary.

10.3 Escalation reports. For P1 incidents and where the availability commitment is not met, the Provider prepares an executive summary for the Customer's management level.

An executive summary is also prepared where, within a reporting period, the Provider has failed to meet a committed first-response time or an update interval under Section 6.2 in three (3) or more cases involving incidents below priority P1. The report identifies the matters concerned, the causes, and the measures taken to remedy them. The Customer may also request such a summary where fewer breaches have occurred, if it demonstrates a legitimate interest.

11. Data Protection and Data Security

11.1 GDPR compliance. The processing of personal data is governed by the GDPR, the BDSG, and the TDDDG, as well as by the Provider's privacy policy (https://korthex.io/privacy and, supplementarily, https://flowencehq.com/privacy). Due to the offline-first architecture, the Provider processes neither the Customer's source code nor analysis results.

11.2 Processing on behalf. Insofar as the Provider processes personal data on behalf of the Customer (in particular account and license data via the Portal), the Parties conclude a data processing agreement pursuant to Art. 28 GDPR, attached to this SLA as Annex C.

11.3 Confidentiality. The confidentiality provision of § 11 of the Korthex Terms or the General Terms applies. In addition, any non-disclosure agreement (NDA) concluded between the Parties applies insofar as the Customer is granted access to source code or non-public technical information.

11.4 Data localization and third-country transfer. The Portal API is operated with a processing region in the European Union; processing exclusively within the European Union is not committed to, since individual technically necessary network, delivery, and operational components of the providers used may also be located outside the European Economic Area or administered from there (Section 3.4.1); the database and storage infrastructure is operated in the United Kingdom (Supabase, London), for which an adequacy decision of the EU Commission exists. Transfers to the USA (in particular to Stripe and Google) are based on the EU-US Data Privacy Framework where the recipient is certified, and additionally on EU standard contractual clauses. Access is role-based according to the principle of least privilege. Details are set out in the privacy policy and Annex C.

11.5 Breach notification. If the Provider becomes aware of a personal data breach that has occurred within the Provider's area of responsibility, it informs the Customer without undue delay and at the latest within twenty-four (24) hours of becoming aware. Insofar as the Provider acts as a processor in that respect, this obligation follows from Article 33(2) GDPR; no separate 72-hour period applies to the processor.

The notification is made even where not all details are yet available. The Provider first transmits the information available and supplements it without undue delay as further findings emerge. The notification contains, to the extent known, the nature of the breach, the categories of data and data subjects concerned, the likely consequences, and the measures taken and proposed.

The Provider supports the Customer in fulfilling the Customer's notification obligations under Articles 33 and 34 GDPR (Article 28(3)(f) GDPR) and provides the information required for that purpose in good time so that the Customer can meet its own 72-hour period vis-à-vis the supervisory authority. The controller's statutory period remains unaffected.

The Provider's reporting obligations under the Cyber Resilience Act apply in addition and are governed by Section 4.6.

11.6 Handling of cryptographic material. The software's local encryption keys are generated on the Customer's system and protected by the operating system (e.g. DPAPI on Windows); the Provider has no access to them (no key escrow). License and activation keys are used exclusively for license management. Upon termination of the contract, the exit-management provisions apply (Section 15.4).

11.7 Product security and coordinated disclosure. The Provider handles security-relevant vulnerabilities pursuant to Section 4.4. The Provider is the manufacturer of a product with digital elements within the meaning of Regulation (EU) 2024/2847 (Cyber Resilience Act) and is therefore a direct addressee of the obligations set out therein. Those obligations relate to the Korthex product itself and apply irrespective of whether the Customer operates the software air-gapped or connected to the Portal, and irrespective of the Provider's infrastructure. The reporting and information obligations under Article 14 of the Regulation are governed by Section 4.6. The Customer is entitled to test the Korthex installation it operates within its own area of responsibility at its own expense. Tests against the Portal infrastructure operated by the Provider require prior written coordination regarding time window, scope, and methodology. Identified vulnerabilities are to be reported to the Provider by way of coordinated disclosure.

12. Remuneration and Payment Terms

12.1 The remuneration and payment terms of § 6 of the Korthex Terms or the General Terms apply (prices net plus VAT, payment in advance per billing period, due within 14 days, default interest, price adjustment with 90 days' notice). This SLA establishes no deviating payment terms unless otherwise provided below.

12.2 The service levels provided under this SLA are included in the remuneration for the selected plan, unless a separate SLA fee is shown (Annex B).

12.3 One-time setup fees (e.g. onboarding) and additional services outside the agreed scope are billed on a time-and-materials basis at the rates stated in Annex B.

12.4 Invoicing and payment terms are governed by § 6 of the General Terms.

13. Service Credits

13.1 Service credit model. If the actual Portal availability in a calendar month falls below the availability committed in Section 4.1, the Customer receives, in the Business and Enterprise plans and upon request, a service credit calculated as a percentage of the monthly pro-rata annual remuneration. No service credits exist in the Free and Community plans.

13.2 Claiming. Service credits must be claimed in text form within 30 days after the affected month. They are offset against the next invoice and not paid out.

13.3 Legal nature and relationship to liability. Service credits are a lump-sum compensation for non-compliance with the availability commitment. The Customer reserves the right to prove that no or substantially less damage has occurred (§ 309 No. 5 lit. b BGB). Service credits are the primary remedy for non-compliance with the availability commitment and are offset against any further claim for damages arising from the same availability shortfall. The Provider's statutory liability - in particular for damages arising from injury to life, body, or health, for intent and gross negligence, for the breach of material contractual obligations, and under the Product Liability Act - as well as the rights of consumers remain unaffected. The liability cap set out in § 10 of the General Terms remains unaffected and is not increased by this SLA.

13.4 Exceptions. No service credits exist for outages attributable to: announced maintenance; force majeure within the meaning of § 14 of the General Terms and Section 14 of the Korthex Terms, including the conditions set out there for cyberattacks (protective measures in line with the state of the art); circumstances attributable to the Customer; failures of the customer network, hardware, or third-party software; use in unsupported environments; and incidents reported via non-approved channels.

14. Liability and Warranty

14.1 Warranty and liability are governed unchanged by §§ 9 and 10 of the Korthex Terms or the General Terms. This SLA does not extend the Provider's liability.

Irrespective of the content of the documents referred to, the following applies: The Provider's liability for damages arising from injury to life, body, or health and for intent and gross negligence is neither excluded nor limited. This also applies to the personal liability of the Provider's employees, staff, representatives, corporate bodies, and vicarious agents. No exemption going beyond the extent permitted by Section 309 no. 7 of the German Civil Code (BGB) is agreed by this SLA or by the documents referred to; any diverging provision in a referenced document does not apply in that respect.

14.2 In particular, § 9(4) of the General Terms applies: analysis results are probabilistic; there is no guarantee of completeness or accuracy, and the absence of a finding does not constitute a security guarantee. Compliance with the service levels of this SLA does not change this.

14.3 For non-compliance with availability service levels, the service credits under Section 13 are the primary remedy; any further damages are governed by the limits of § 10 of the General Terms. The statutory provisions apply vis-à-vis consumers.

14.4 Responsibility for the implementation of technical changes and migration recommendations remains with the Customer pursuant to § 10(7) of the General Terms.

15. Term and Termination

15.1 Commencement and term. This SLA takes effect on the date stated in the header and is linked to the term of the associated usage contract. The term and renewal provisions of § 12 of the General Terms or the Korthex Terms apply.

15.1.1 Change of plan. Where the Customer changes plan during the running contract term, this SLA remains in force unchanged; no new SLA document is required. The service levels of the new plan apply from the date on which the change of plan takes effect. For the reporting period in which the change falls, availability and service credits are calculated on a pro rata basis according to the commitments applicable in each case.

The Provider will update the annexes affected by the change of plan, in particular Annexes D and E, without undue delay and send them to the Customer in text form. Where the Customer moves to a plan without an availability commitment or without service credits, those entitlements cease only with effect for the period after the change; entitlements already accrued remain unaffected.

15.2 Ordinary termination. Ordinary termination is governed by § 12 of the General Terms (renewal for one year at a time, three months' notice to the end of the term).

15.3 Extraordinary termination. The right to extraordinary termination for good cause under § 12 of the General Terms remains unaffected.

15.4 Transition and exit management. Upon termination, the Provider supports the Customer to a reasonable extent in the orderly termination of use. Upon the end of the contract, the usage rights expire; the Customer uninstalls the software pursuant to § 12 of the Korthex Terms. Locally generated analysis results and reports remain with the Customer. License and activation keys are deactivated by the Provider; there is no key escrow of local cryptographic keys (Section 11.6).

16. Dispute Resolution and Jurisdiction

16.1 In the event of disagreements about compliance with the service levels, the Parties first seek an amicable solution at the level of the named contacts and then at management level. This escalation should be concluded within fifteen (15) business days of the first written complaint. It is not a condition of admissibility for bringing proceedings before the courts; the right of each party to seek judicial relief at any time, in particular by way of interim relief, remains unaffected.

16.2 Otherwise, the applicable law and place of jurisdiction of § 16 of the General Terms or § 18 of the Korthex Terms apply (exclusively German law, excluding the UN Convention on Contracts for the International Sale of Goods; place of jurisdiction at the Provider's registered office where the Customer is a merchant, a legal entity under public law, or a public-law special fund). For consumers, the statutory provisions on jurisdiction apply.

16.3 No arbitration clause is agreed.

17. Miscellaneous

17.1 Text form. Amendments and supplements to this SLA should be made in text form. Individual contractual agreements always take precedence over the provisions of this SLA pursuant to Section 305b of the German Civil Code (BGB); they are effective even where they were made orally or by conclusive conduct and do not comply with the text form. This form requirement serves evidentiary purposes and neither excludes later individual agreements nor renders them invalid.

17.2 Severability. Should a provision of this SLA be or become invalid, void, unenforceable, or fail to become part of the contract, in whole or in part, the validity of the remaining provisions remains unaffected. The statutory provisions apply in its place (Section 306(2) of the German Civil Code (BGB)). No reduction preserving validity takes place; an invalid provision is not cut back to the legally permissible extent. It is not automatically replaced by a provision that comes as close as possible to its economic purpose; the parties remain free to replace an invalid provision by a separate individual agreement in text form. Section 19 of the Korthex Terms applies accordingly.

17.3 Entire agreement. This SLA, the Korthex Terms, the General Terms, and the annexes constitute the entire agreement of the Parties on the subject matter of this SLA. The order of precedence under Section 1 applies.

17.4 Prohibition of assignment. The Customer may transfer rights and obligations under this SLA to third parties only with the Provider's prior consent in text form. Section 354a of the German Commercial Code (HGB) remains unaffected: where the assignment of a monetary claim is a commercial transaction for both parties, the assignment remains effective despite the foregoing prohibition. In that case the Provider may render performance with discharging effect to the Customer as the previous creditor until the assignment has been notified to the Provider in text form. Consent to a transfer must not be unreasonably withheld. Section 1 applies to a transfer on the Provider's side.

18. Annexes

The following annexes form part of this SLA and are completed per contract:

The Provider sends the Customer the annexes relevant to its plan in text form, at the latest when access is enabled and, for Enterprise agreements, no later than five (5) business days after conclusion of the contract. The Provider keeps them up to date and sends changes without undue delay.

For as long as an annex has not been provided to the Customer, the following applies: For Annexes A and B, the details in the order confirmation and the plan description under Section 4 of the Korthex Terms are decisive. For Annex D, the supported environments stated in the product documentation and the release notes apply; in that case the period for installing security-relevant releases is thirty (30) days from provision and notification pursuant to Section 7.3.1. For Annex E, the substitute reporting channel under Section 5.3 applies.

The absence or incompleteness of an annex is not to the Customer's detriment. The Provider may rely on a duty of the Customer set out in an annex only to the extent that the annex concerned had been provided to the Customer. Annex C must be concluded before any processing of personal data on behalf begins; Section 11.2 of this SLA and Section 7 of the Korthex Terms remain unaffected.