Terms of Service for Korthex
These product-specific Terms of Service supplement the General Terms and Conditions of Flowence Infrastructure, available at https://flowencehq.com/terms. In the event of any conflict between these product-specific Terms of Service and the General Terms and Conditions, these product-specific Terms of Service shall prevail to the extent that they concern the scope of Korthex services.
1. Scope and Subject Matter of the Agreement
These Terms of Use (hereinafter referred to as the “Korthex Terms”) govern the use of the software “Korthex”, including the associated desktop application, command-line interface, web interfaces, APIs, documentation, updates, beta features, and other product-related services (hereinafter collectively referred to as “Korthex” or the “Software”). Korthex is a platform for cryptographic security analysis, inventory management, policy evaluation, and migration planning.
Korthex is developed, provided, and distributed by Flowence Infrastructure, proprietor Hendrik Schneider (hereinafter referred to as the “Provider”, “we”, or “us”). The contractual partner of the User is Flowence Infrastructure, unless expressly agreed otherwise in an individual case.
Korthex is an independent product of Flowence Infrastructure and is subject to these product-specific Terms of Use. Other products and services offered by Flowence Infrastructure, including Sentinal and Voxar, are subject to their own product-specific terms and are not covered by this Agreement unless expressly agreed otherwise.
These Korthex Terms supplement the general terms and conditions of Flowence Infrastructure, available at https://flowencehq.com/terms (hereinafter referred to as the “General Terms”). Unless these Korthex Terms contain a differing provision, the General Terms apply in addition.
The following order of precedence governs the relationship between the contractual documents. In the event of a conflict, the higher-ranking document prevails: (1) individual agreements between the parties in text form, in particular Enterprise agreements, data processing agreements, and individually negotiated supplementary agreements (Section 305b of the German Civil Code (BGB)); (2) the order confirmation and the service description of the selected plan; (3) the applicable Service Level Agreement for Korthex, available at https://korthex.io/sla, within its scope; (4) these Korthex Terms; (5) the General Terms.
The General Terms provide for a corresponding precedence rule in favour of product-specific terms. Should such a mirroring provision not be, or no longer be, contained in the General Terms, these Korthex Terms shall nevertheless prevail as the more specific agreement concluded for the Korthex product, to the extent that the conflict concerns the scope, provision, or use of Korthex. A conflict between the two documents does not render the affected provision invalid; it is resolved exclusively in accordance with the order of precedence set out above.
Where a conflict between the contractual documents cannot be resolved even after applying the order of precedence set out above, the provision more favourable to the consumer applies in relation to consumers, and the more specific provision applies in relation to entrepreneurs. Section 305c(2) of the German Civil Code (BGB) remains unaffected.
Korthex is intended in particular for companies, developers, security professionals, and technical teams that wish to examine software projects, dependencies, configurations, or binary files for the use of weak, outdated, or no longer recommended cryptographic methods and plan a migration to current cryptographic standards.
The specific scope of services depends on the selected plan, the features available at the time of use, the product documentation, and, where applicable, separate service descriptions or individual agreements. Features may be restricted, unavailable, or available only as part of a Beta or Early Access programme depending on the selected plan, permissions, platform, region, technical environment, or release status.
Korthex supports the identification, assessment, and prioritisation of potential cryptographic risks. However, its results, assessments, recommendations, migration guidance, and automatically generated configurations do not constitute a binding security assurance, legal advice, compliance certification, guarantee of complete accuracy, or assurance that a project is free from security vulnerabilities. The User remains responsible for reviewing, assessing, and implementing results in their own environment.
References by the Provider to third-party standards, frameworks, publications, or requirements, in particular to NIST publications including FIPS 140-3 and FIPS 203/204/205, BSI TR-02102, BSI IT-Grundschutz, PCI-DSS, ISO/IEC 27001, or Regulation (EU) 2024/2847 (Cyber Resilience Act), describe exclusively that Korthex compares detected cryptographic characteristics against the requirements of those standards and derives findings, assessments, and reports from that comparison. Such references mean neither that Korthex itself is certified, assessed, or accredited under those standards, nor that using Korthex establishes, demonstrates, or replaces compliance with them. Certification, accreditation, auditing, or regulatory approval of the User or the User’s systems is not the subject matter of this Agreement.
References to post-quantum cryptography, post-quantum migration, or comparable terms describe support for the inventory, assessment, and planning of corresponding migration steps. They do not constitute an assurance that a system is post-quantum secure after using Korthex. Section 3 applies in addition.
Public statements made by the Provider, in particular statements in advertising, on the website, and in the product documentation, remain decisive for the agreed quality of Korthex, unless mandatory statutory provisions provide otherwise. The preceding paragraphs specify the content of such statements; they are not intended to limit or exclude them. Where a public statement goes beyond the scope of services described in these Korthex Terms in an individual case, the public statement prevails, unless the statutory conditions for disregarding it are met (cf. Section 327e(3) and Section 434(3) of the German Civil Code (BGB)). These Korthex Terms are not intended to effect a surprising exclusion of advertised characteristics within the meaning of Section 305c(1) of the German Civil Code (BGB).
Unless expressly agreed in text form, the following are not the subject matter of the Agreement: an individual security assessment, a manual code review, a penetration test, the complete detection of all vulnerabilities, continuous monitoring of the User’s systems, and the creation or issuance of compliance evidence. This list describes the scope of the services owed. It constitutes neither an exclusion nor a limitation of statutory rights in the event of defects; those rights are governed by Section 9.
The following applies in addition in relation to consumers: The quality of Korthex is determined by the subjective and objective requirements set out in Sections 327d and 327e of the German Civil Code (BGB). A deviation from the objective requirements is effective only if the consumer was specifically informed of it before submitting their contractual declaration and the deviation was expressly and separately agreed in the contract (Section 327h of the German Civil Code (BGB)). No such separate agreement is made by these Korthex Terms. No blanket exclusion of the suitability of Korthex for ordinary use or for the purpose presupposed under the contract is made in relation to consumers.
The following applies in relation to entrepreneurs: The Provider owes suitability for a specific purpose of the User going beyond the purpose presupposed under the contract only where that purpose has been agreed in text form. Suitability for ordinary use and for the purpose presupposed under the contract remains unaffected.
By completing the registration, ordering, or activation process and subsequently using Korthex, the User agrees to these Korthex Terms. Where required by law, acceptance of these Korthex Terms is obtained as part of the respective contract formation process.
Any differing, conflicting, or supplementary general terms and conditions of the User, in particular purchasing, supplier, or framework terms, shall not become part of the Agreement. The Provider hereby expressly objects to their applicability as a precautionary measure.
This objection also applies where the Provider renders performance without reservation while aware of differing terms of the User, in particular by providing a license key, enabling access, executing an order, or accepting a payment. Neither silence on the part of the Provider nor the execution of an order, the acceptance of a payment, or the failure to reject a commercial letter of confirmation constitutes consent to differing terms.
Terms of the User become part of the Agreement only where the Provider has expressly consented to their applicability in the individual case, in text form, identifying the specific document including its version, through a person authorised to represent the Provider. Such consent does not extend to later versions or to further orders.
The paid Community, Business, and Enterprise plans are intended exclusively for entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law, or special funds under public law. The free Free plan may also be used by consumers within the meaning of Section 13 of the German Civil Code (BGB).
Where consumers use the Free plan, mandatory consumer-protection provisions of applicable law take precedence. Provisions of these Korthex Terms or the General Terms that deviate from such provisions to the detriment of a consumer shall not apply to that extent and are replaced by the statutory provisions. Statutory rights, including any rights of withdrawal, warranty rights, rights in the event of defects, and rights regarding updates and modifications under Sections 327 et seq. of the German Civil Code (BGB), remain unaffected.
Where Users use Korthex on behalf of a company, organisation, or other third party, they represent that they are authorised to represent that legal entity and enter into this Agreement. In that case, the represented legal entity shall be deemed to be the User and contractual partner.
2. Contract Formation, Registration, and License Activation
The presentation of Korthex, plans, prices, and features on the website, within the Software, or through other distribution channels does not constitute a binding offer to enter into an agreement, unless expressly stated otherwise. It constitutes an invitation for the User to submit an offer to enter into a contract.
For paid plans, the User submits an offer to enter into a subscription agreement by completing the ordering process, selecting a plan, and confirming the order. The Agreement is concluded when the Provider expressly confirms the order, provides a license key, enables access, or activates Korthex for use. An automatically generated confirmation of receipt merely confirms that the order has been received and does not constitute acceptance.
The Provider will accept or reject an offer submitted by the User within ten (10) business days of its receipt. If the Provider does not accept the offer within that period, the offer is deemed rejected and the User is no longer bound by it. Any payments already made will be refunded in full without undue delay in such a case. Section 147(2) of the German Civil Code (BGB) remains unaffected.
The price, scope of services, and plan features applicable to an order are those displayed in the ordering process at the time the offer is submitted. Changes to prices or conditions that take effect after receipt of the order and before its acceptance do not apply to that order.
Where a price or service specification displayed in the ordering process is based on an obvious error, in particular a typographical, calculation, transmission, or display error, the Provider is entitled to refuse acceptance of the offer. The Provider will inform the User accordingly in text form without undue delay and at the latest within the acceptance period set out above, and will communicate the correct price; the User may then submit a new offer. Any payments already made will be refunded in full without undue delay. There is no entitlement to conclude a contract at the erroneous price. Statutory rights of avoidance and mandatory rights of the User remain unaffected.
For the free Free plan, the agreement for use is concluded when the User completes registration, accepts these Korthex Terms, and the Provider enables access to the Software or the associated services. Where registration is not required for individual features, the agreement for use is concluded at the latest when those features are first used.
License keys and access credentials are provided to the User after contract formation through the website korthex.io, the associated user account, email, or authorised distribution partners. The User is not entitled to receive a license key before the contract has been concluded or before full payment has been made, where payment is due for the selected plan.
Each license key is generally tied to the number of devices and Users specified in the relevant plan, order, or individual agreement. Where a device fingerprint is used to enforce this device binding, it is generated during activation or use and matched against the license key or user account.
Korthex verifies the validity of the license at recurring intervals. Under the paid plans, Korthex remains fully usable for a period of seven (7) days without a successful license check (offline grace period). The Provider will notify the User within the Software of the pending license check before that period expires. After the period expires, paid features may be restricted until a license check succeeds; analysis results, inventories, reports, and migration plans already created remain locally accessible and exportable. Where the absence of a successful license check is due to an outage of the Provider’s online services for which the Provider is responsible, Section 8 applies. Separately agreed terms apply to air-gapped use.
The device fingerprint is used exclusively for license management, abuse prevention, detection of unauthorised multiple activations, and the technical security of the activation system. Details regarding the data processed, processing purposes, legal bases, retention periods, and data subject rights are set out in the Korthex Privacy Policy at https://korthex.io/privacy.
A license key is transferred to another device through the deactivation and reactivation process provided by the Provider. The specific number of devices that may be activated simultaneously depends on the selected plan or a differing individual agreement.
The User may release an existing device activation at any time via their user account or, where no corresponding self-service function is available, through the Provider’s support channels (deactivation). Upon effective deactivation, the affected device slot becomes available again and may be used for another device.
A device change is possible up to six (6) times per User seat within any twelve (12) month period without stating reasons. Where that number is exceeded, the Provider may request a plausible explanation from the User. The Provider may refuse reactivation only where there are concrete indications of unauthorised use within the meaning of the following paragraphs; any refusal must be substantiated to the User in text form.
Where a device is defective, lost, stolen, or otherwise inaccessible and the activation therefore cannot be released from the device itself, the Provider will release the activation at the User’s request. The Provider will process such a request within two (2) business days of receipt, and within ten (10) business days for Users of the Free plan. No proof of defect, loss, or theft is required; the Provider may, however, request confirmation from the User in text form that the affected device will no longer be used to run Korthex.
The Provider does not charge a separate fee for deactivation or reactivation.
Device fingerprints associated with a deactivated or expired activation are deleted as soon as they are no longer required for license management, and at the latest thirty (30) days after effective deactivation or expiry of the license. Longer retention takes place only to the extent and for as long as this is necessary to prevent specific misuse, to comply with statutory retention obligations, or to establish, exercise, or defend legal claims. Upon termination of the contractual relationship, sentence 1 applies accordingly to all device fingerprints stored in connection with that contract. Details are set out in the Korthex Privacy Policy.
The User is prohibited from circumventing, manipulating, disabling, or assisting others in circumventing the device binding, license verification, activation process, technical usage restrictions, or other protective measures. It is also prohibited to use a license key beyond the contractually agreed number of devices, Users, or instances. Use of the deactivation and reactivation process governed by the preceding paragraphs does not constitute circumvention.
Where there are concrete indications of unauthorised use, including circumvention of license verification, abusive multiple activations, sharing of license keys, or use outside the agreed license scope, the Provider is entitled to temporarily suspend the affected license key or access. Any suspension must be limited to what is necessary and to the affected license keys, access credentials, or features.
Before imposing a suspension, the Provider will, where possible and reasonable in the circumstances, notify the User of the suspicion in text form and grant the User a period of at least five (5) business days to comment or to remedy the situation. No prior hearing is required where immediate suspension is necessary to avert substantial damage, security risks, infringements of rights, or a continuing material exceedance of the license scope.
Where a suspension is imposed without a prior hearing, the Provider will inform the User in text form without undue delay, and at the latest within two (2) business days after the suspension takes effect, of the suspension, its essential grounds, and the opportunity to comment, to the extent this is legally permissible and no overriding security or investigative interests conflict with such notice.
The User may object to the suspension in text form within fourteen (14) days of receiving the notice and present facts that rebut the suspicion. The Provider will review the objection without undue delay and decide within five (5) business days of its receipt. The Provider will communicate the outcome of the review to the User in text form.
The suspension ends as soon as the suspicion has been dispelled or the breach has been remedied. If the Provider has not decided within thirty (30) days of the start of the suspension whether to restore access or to terminate the Agreement for cause, the suspension must be lifted. This does not apply where the delay is due to a lack of cooperation by the User or where administrative or court proceedings prevent a decision.
Where the suspicion proves to be unfounded or the suspension was otherwise unjustified, the Provider will lift the suspension without undue delay. For paid plans, the Provider will credit the User on a pro rata basis for the remuneration attributable to the duration of the unjustified suspension; the credit will be offset against the next invoice or, at the User’s request, refunded. Claims under the applicable Service Level Agreement and further statutory claims of the User remain unaffected.
The procedural provisions of the preceding paragraphs apply accordingly to suspensions for abusive use under Section 4. Suspensions for late payment are governed exclusively by Section 6. Further rights of the Provider, in particular the right to terminate for cause under Section 12, remain unaffected.
The User is required to provide complete, accurate, and current information during registration, ordering, and account management. Changes to contact, billing, or company information must be updated in the user account without undue delay or communicated to the Provider in text form.
The User is responsible for keeping their access credentials, recovery codes, API keys, and license keys confidential. Access credentials and license keys must not be shared with unauthorised third parties. If there is a suspected loss, disclosure, unauthorised access, or misuse, the User must inform the Provider without undue delay and, where appropriate, change the access credentials or arrange for the license key to be deactivated.
The User is liable in accordance with applicable law for actions performed through their user account, access credentials, or license key where the User is responsible for the unauthorised use. Statutory rights and obligations, in particular those applying to consumers, remain unaffected.
The general statutory rules on the burden of proof apply to the question of whether the User is responsible for an unauthorised use. The Provider bears the burden of presentation and proof for the circumstances establishing that the User is responsible. These Korthex Terms do not create any reversal of the burden of proof to the detriment of the User; in particular, there is no presumption that every action carried out using the User’s access credentials was initiated by the User or is attributable to the User. In relation to entrepreneurs, a secondary burden of presentation regarding circumstances within the User’s sphere, in particular the organisation of access management, remains unaffected.
The User’s liability for the acts of third parties ends upon receipt by the Provider of a notification from the User regarding the loss, disclosure, or misuse of the access credentials or the license key. This does not apply where the User acted intentionally or with gross negligence.
Where a person uses Korthex for a company, organisation, or other third party, that person represents that they are authorised to do so. In this case, the represented legal entity becomes the contractual partner.
3. Description of Services
Korthex is a desktop application based on an offline-first architecture. Its core analysis functions are executed locally within the User’s environment. Korthex supports the examination of source code, binary files, dependencies, and project-related configurations for cryptographic methods, their use, and potential modernisation requirements.
The available functionality may include static code analysis, detection of cryptographic patterns and libraries, identification of outdated or no longer recommended algorithms, assessment of key lengths and configurations, creation of cryptographic inventories, and migration and remediation recommendations. The specific scope of available functionality depends on the selected plan, the installed version, the operating system, supported programming languages and file formats, and the release status of the relevant feature.
Source code analysis is generally performed on the User’s device or within an execution environment controlled by the User. Korthex does not transmit source code, analysed binary files, or complete analysis results to the Provider’s servers unless the User expressly activates or uses a feature that requires such transmission. This does not affect technically necessary data transfers for license activation, update checks, account and permission management, or telemetry, error-reporting, support, or integration features expressly activated by the User.
The User is responsible for verifying, before activating optional online, telemetry, support, export, or integration features, whether the transmission of the relevant data complies with the User’s internal security requirements, contractual obligations, and applicable legal requirements.
Korthex may create and store analysis results, inventories, reports, and migration plans locally. The quality and completeness of results depend, among other factors, on the analysed artefacts, supported programming languages, used frameworks, available dependency information, configurations, and the version of Korthex in use. Analysis results do not replace an individual security assessment or professional review by qualified personnel.
Where available and activated by the User, Korthex may provide a Mesh Networking feature. This feature enables the encrypted exchange of released files, analysis results, or other data between multiple authorised Korthex instances.
The Mesh Networking feature is disabled in its delivered state. Its use requires express activation by the User, a separate selection of the content to be released, and successful network authentication. Before the first activation, Korthex informs the User of the nature and extent of the possible data transmission and displays which content will be released. Content that the User has not selected through a deliberate act of release is not transmitted.
The User’s responsibility for content transmitted through the Mesh Network extends only to content the User has selected through a deliberate act of release. Where a malfunction, an incorrect default setting, or a misleading presentation in the user interface causes content to be transmitted contrary to the configuration made by the User, this constitutes a defect of the Software. The User’s rights under Section 9 and mandatory statutory rights in the event of defects remain unaffected; no transfer of that responsibility to the User takes place in such cases.
The User is the controller under data protection law for the content transmitted through the Mesh Network. The Provider remains responsible for the security of the transmission and authentication mechanism it provides. Section 7 of these Korthex Terms and the Korthex Privacy Policy at https://korthex.io/privacy apply in addition.
Korthex may use local models or rule-based analysis components to support the detection, classification, and prioritisation of cryptographic findings. Where model, rule, or signature updates are obtained through an online feature, at least technical version, compatibility, and update information is processed for this purpose. Source code and complete analysis results are not transmitted as part of a standard update check.
Korthex’s post-quantum cryptography features support the inventory and planning of potential migration steps. They do not constitute an assurance that a system is post-quantum secure, fully compliant, or free from cryptographic vulnerabilities. The User remains responsible for selecting, implementing, testing, and approving cryptographic methods within their environment. Section 1 on the meaning of references to third-party standards applies in addition.
For the duration of the provision period, the Provider supplies those updates that are necessary to maintain the conformity of Korthex. These include, in particular, security updates as well as rule, signature, and model updates to the detection logic, to the extent they are necessary for Korthex to continue to meet the contractually agreed requirements and the requirements customary for cryptographic analysis software. The Provider informs the User of the availability of such updates.
These updates are also provided to Users of the Free plan for as long as the Free plan is offered and the agreement for use of the Free plan is in effect. This does not create any entitlement to new features, to features of other plans, or to further developments going beyond the maintenance of conformity.
Updates within the meaning of the preceding paragraphs are provided at least for the current major version of Korthex and for the immediately preceding major version until twelve (12) months after the release of the subsequent major version. In relation to consumers, this applies only where the statutory provision period under Section 327f of the German Civil Code (BGB) is not longer; in that case the statutory period is decisive.
Details regarding the provision of updates, support, and the consequences of a failure to install an update are governed by Section 8 of these Korthex Terms. The statutory update obligation towards consumers under Section 327f(1) of the German Civil Code (BGB) and the exemption from liability provided for in Section 327f(2) of the German Civil Code (BGB) where a supplied update is not installed remain unaffected.
The Provider continuously develops Korthex and may add, modify, replace, or discontinue features where a valid reason exists. Only the following constitute a valid reason: (a) adaptation to a changed technical environment, in particular to changed operating systems, runtime environments, interfaces, or hardware requirements; (b) adaptation to a changed number of Users or to changed capacity requirements; (c) the remedying or prevention of security vulnerabilities and the maintenance of IT security; (d) adaptation to changed statutory or regulatory requirements, to supreme court case law, or to changed requirements of third parties whose services are necessary for the operation of Korthex; (e) the discontinued availability of third-party components, in particular libraries, signature sources, or data sources; (f) the remedying of defects and improvements to stability, compatibility, or performance; (g) the continuation of an individual feature no longer being economically reasonable, provided the Provider makes a functionally equivalent alternative available or the change does not materially impair the purpose of the contract. This list is exhaustive.
Changes under the preceding paragraph do not entail any additional costs for the User. When making changes, the Provider will reasonably consider the User’s legitimate interests and will limit changes that impair usability to what is necessary.
The following applies in addition where the User is a consumer and Korthex is provided on a continuous basis: Where a change does not merely insignificantly impair access to or usability of Korthex, the Provider will inform the consumer on a durable medium at least thirty (30) days before the date of the change. The information sets out the characteristics and the date of the change and expressly refers to the right of termination under the following paragraph.
In that case, the consumer may terminate the contract free of charge within thirty (30) days. The period begins upon receipt of the information or, where the change occurs at a later date, at the time of the change. Where the consumer does not receive the information, does not receive it in due time, or does not receive it in full, the period begins only upon receipt of proper information. The right of termination does not exist where the impairment is only insignificant or where the consumer continues to have access to Korthex in its unchanged state at no additional cost and its conformity is maintained (Section 327r(4) of the German Civil Code (BGB)).
Changes to these Korthex Terms themselves are governed by Section 17. Changes to plan features and usage limits are governed by Section 4, and price adjustments by Section 6.
Beta, Preview, Early Access, and similarly labelled features may still be under development. They may be incomplete, contain defects, change, become temporarily unavailable, or not be included in a stable release. A feature is labelled as Beta, Preview, or Early Access within the Software, in the product documentation, or in the release notes.
The respective published Beta or Early Access terms apply to such features with priority. Where no separate terms are published for a labelled feature, the following provisions of this paragraph apply exclusively; there is no regulatory gap in this respect.
(a) Beta features are provided free of charge and in addition to the agreed scope of services. They do not form part of the agreed quality of the selected plan; their unavailability, modification, or discontinuation does not constitute a defect of the Software and does not give rise to any claim for a reduction or refund of the remuneration for the selected plan. (b) No Service Level Agreement applies to Beta features; no availability, response, or restoration times are owed. (c) The Provider may modify, restrict, or discontinue Beta features at any time and will inform the User in advance with reasonable notice where possible and reasonable. (d) The User will separately review results produced by Beta features before using them in production environments or for security-critical decisions. (e) The Provider’s liability for Beta features is likewise governed by Section 10.
In relation to consumers, mandatory statutory rights remain unaffected for Beta features as well. In particular, Section 327(3) and Sections 327d et seq. of the German Civil Code (BGB) remain unaffected to the extent that the Beta feature qualifies as a supplied digital product under those provisions. The provisions of the preceding paragraph apply in relation to consumers only to the extent that they are compatible with those mandatory provisions.
4. Plans and Usage Restrictions
Korthex is offered under the plans described below. The functionality applicable to the User, the relevant usage limits, the number of permitted Users and devices, and the available support services are determined by the plan selected at the time of contract formation, the order confirmation, and, where applicable, an individual agreement.
- [object Object]
- [object Object]
- [object Object]
- [object Object]
These Korthex Terms are decisive for the designation of the plans. The second paid plan was referred to as “Extended” in earlier versions of the Service Level Agreement, in older ordering documents, and in earlier product descriptions; it is the same plan as the one referred to here as “Community”. Where a contractual document uses a different designation for the same plan, this does not affect the scope of services and creates neither an additional nor a reduced entitlement. In case of doubt, the allocation is to be made on the basis of the usage limits stated in the order confirmation.
A scan is an analysis process initiated by the User or started through a permitted integration.
An analysed file is any file that Korthex actually reads and subjects to substantive analysis during a scan. The following are not counted as analysed files: files that (a) were excluded from analysis by exclusion rules, filters, or the User’s configuration, (b) could not be opened due to missing read permissions, (c) are in a format not supported by the installed Korthex version, or (d) could not be analysed, or could not be analysed in full, for technical reasons. The cause of the technical impairment under point (d) is irrelevant; in particular, it does not matter whether it is attributable to the sphere of the User or that of the Provider.
Only the definition set out above is decisive for counting against a usage allowance. Where the technical count deviates from that definition to the detriment of the User, the deviation is not counted against the allowance.
Korthex displays the number of files counted in a scan in the respective scan result and the consumption for the current calendar month in the user account. The User may object in text form to the counting of individual scans or files within sixty (60) days of the relevant scan. The Provider will review the objection without undue delay and credit any scans or files counted in error back to the User’s allowance. The User’s statutory rights remain unaffected.
The applicable monthly usage limits refer to the calendar month and reset at the beginning of each new calendar month. Unused scans, file allowances, or CI/CD runs are not carried over into the following month unless expressly agreed otherwise.
Once a plan-specific usage limit has been reached, Korthex may reject or technically restrict additional scans, additional CI/CD runs, or use of the affected feature until the allowance is reset, the User changes plans, or additional capacity is purchased. Scans already in progress are not aborted.
Where technically possible, the Provider will notify the User upon reaching eighty (80) per cent and one hundred (100) per cent of a usage limit.
Even where a usage limit has been reached, access to analysis results, inventories, reports, and migration plans already created, and the export thereof, remain fully available. Reaching a usage limit does not result in suspension of the user account.
Users of the Community, Business, and Enterprise plans may purchase additional allowances at any time for a fee. The Provider will enable purchased additional allowances without undue delay.
The following emergency provision applies in addition to Users of the Business and Enterprise plans: Where the User requires additional capacity at short notice because of an acute security incident in their environment, the Provider will, upon request in text form, make available free of charge once per contract year an additional allowance amounting to twenty-five (25) per cent of the monthly scan and CI/CD limits applicable to the User’s plan. For service components included in the plan without a limit, no emergency reserve applies for want of a limit. The Provider will enable the emergency allowance within one (1) business day of receiving the request. No proof of the security incident is required; the Provider may request an informal confirmation from the User.
The Software consists of open-source scanner components and proprietary closed-source engine modules.
The classification of a component of Korthex as an open-source component is determined exclusively by its listing in the overview of open-source components provided within the Software under “Licenses”. The overview identifies the applicable license and the source for each component. Upon request, the Provider will additionally make the overview available in text form. Components of Korthex not listed there, in particular the proprietary engine modules, local models, rule sets, and signatures, are not open-source components.
The open-source components listed in the overview may be used independently of a Korthex plan in accordance with the respective license. The joint distribution, bundling, or technical combination of open-source components with proprietary components does not create any right to use, extract, reproduce, or distribute proprietary components in isolation, without a valid plan, or outside the agreed license scope. Sections 5 and 15 apply in addition.
The User may use Korthex only within the selected plan, the contractually agreed User, device, and usage limits, and for lawful purposes. In particular, it is prohibited to use Korthex to analyse source code, binary files, systems, or projects where the User does not have the required authorisation to conduct such analysis.
It is also prohibited to use Korthex to circumvent third-party security measures, prepare or carry out unlawful activities, unlawfully disclose analysis results, or circumvent technical, plan-based, or license-related usage restrictions.
Where there are concrete indications of abusive use, circumvention of usage limits, unauthorised use of license keys, or any other breach of these Terms of Use, the Provider is entitled to temporarily suspend the affected feature, access, or license key to the extent necessary.
The procedural provisions of Section 2 apply accordingly to prior notice, prior hearing, notification of the User, the right to object, the maximum duration of the suspension, and the consequences of an unjustified suspension. In particular, a suspension must be lifted where the Provider has not decided within thirty (30) days of its start, and the User receives a pro rata credit for the remuneration attributable to the suspension period in the event of an unjustified suspension. Further rights of the Provider, in particular the right to terminate for cause under Section 12, remain unaffected.
For agreements already concluded for paid plans, the plan features, usage limits, and service components agreed at the time of contract formation remain unchanged for the duration of the current contract term. No reduction of usage limits, removal of service components, or other diminution of the agreed scope of services takes place during a current contract term.
The Provider may change plan features, usage limits, and service components with effect from the beginning of a renewal period where a valid reason exists. Only the reasons exhaustively listed in Section 3 constitute a valid reason; those reasons apply accordingly to changes under this paragraph.
The Provider will inform the User of a change under the preceding paragraph in text form at least ninety (90) days before it takes effect. The notification will state the previous and future scope of services, the effective date, and the applicable valid reason.
Where a change has an adverse effect on the User, the User may terminate the affected plan with effect from the end of the current billing period until the change takes effect. The Provider will inform the User of this right of termination in the change notification. Price adjustments are governed exclusively by Section 6.
By way of derogation from the preceding paragraphs, the Provider may change plan features and usage limits during a current contract term where this is necessary to avert a specific security threat or to comply with a mandatory statutory or regulatory obligation. The Provider will limit any such change to what is necessary and to the necessary duration, inform the User in text form without undue delay, and, where possible and reasonable, make a functionally equivalent alternative available. Where this is not possible and usability is impaired more than insignificantly, the Provider will refund on a pro rata basis the remuneration attributable to the affected period and scope of services. The User’s right to terminate for cause under Section 12 remains unaffected.
For the free Free plan, the Provider may change plan features and usage limits upon thirty (30) days’ notice where a valid reason within the meaning of Section 3 exists. The provisions in favour of consumers under Section 3, in particular the information obligation and the right of termination under Section 327r of the German Civil Code (BGB), remain unaffected.
For future contract formations, the Provider may change plan features, usage limits, service components, and prices at any time. Agreements already concluded and mandatory statutory rights, in particular those of consumers, remain unaffected.
5. License and Intellectual Property
Subject to full payment of all fees due and compliance with these Terms of Use, the Provider grants the User, for the duration of the relevant agreement for use, a non-exclusive, non-transferable, non-sublicensable right, limited to the contractually permitted territory of use, to use Korthex within the scope of the selected plan and exclusively for the User’s own internal purposes.
Use for the User’s own internal purposes means the analysis of source code, binary files, dependencies, configurations, artefacts, and systems that are owned by the User, operated by the User, or for which the User is responsible. Undertakings affiliated with the User within the meaning of Sections 15 et seq. of the German Stock Corporation Act (AktG) are treated as part of the User’s own organisation, provided their use remains within the contractually agreed number of Users and devices.
Use for the User’s own internal purposes also includes the analysis of third-party software, components, or systems that the User uses or intends to use as part of the User’s own development, procurement, supplier, or security process, in particular the assessment of supplier, library, or third-party components before deploying them in the User’s own environment. Passing on an analysis result produced in this way to the affected third party for the purpose of remediation remains permitted.
The license does not cover the use of Korthex to provide analysis, assessment, audit, consulting, penetration testing, or managed service offerings to third parties, whether for a fee or free of charge (service use). Service use exists in particular where the User uses Korthex to analyse software, systems, or artefacts of a third party and provides that third party with the analysis result, a report derived from it, or a recommendation based on it as a service. The fact that the analysis process is technically executed within the User’s environment is irrelevant in this respect.
Service use is permitted only on the basis of a separate partner, service provider, or Enterprise agreement in text form. The Provider will offer such an agreement upon request on the terms applicable at the time; there is no entitlement to conclude one. Until such an agreement is concluded, use for the User’s own internal purposes under the preceding paragraphs remains unaffected.
The license covers only the use of those features, modules, User seats, devices, instances, and usage volumes to which the User is entitled under the selected plan, order confirmation, or individual agreement. The grant of usage rights does not transfer ownership, copyrights, trademark rights, source code, or any other rights in or to Korthex.
The license is generally tied to the registered User or, where Korthex is used on behalf of a company, to the contracting legal entity. The User may not sell, assign, transfer, sublicense, rent, lease, lend, or make available to unauthorised third parties any license keys, access credentials, user accounts, or usage rights unless the Provider has expressly agreed in text form in advance.
Where individual Korthex features or components contain or are based on open-source software, the respective open-source license terms apply exclusively to those components. These Korthex Terms do not restrict any rights to which the User is entitled under an applicable open-source license.
The Provider ensures that the proprietary engine modules do not incorporate, and are not combined with, open-source components under a copyleft license, in particular the GNU General Public License (GPL), the GNU Affero General Public License (AGPL), or the GNU Lesser General Public License (LGPL), in a manner that would give rise to an obligation to disclose the source code of the proprietary engine modules. Where copyleft-licensed components are used, they are used exclusively as independent, unmodified programs invoked through defined interfaces.
Should it emerge that an open-source component has been incorporated contrary to the preceding paragraph, the Provider will remedy this without undue delay, in particular by replacing or removing the affected component or by obtaining a suitable license. Rights to which the User is mandatorily entitled under the respective applicable open-source license remain unaffected and are neither restricted nor excluded by these Korthex Terms.
The intellectual property associated with Korthex is divided into the following categories:
- [object Object]
- [object Object]
- [object Object]
Unless expressly permitted by these Terms of Use, the selected plan, an open-source license, or mandatory law, the User is prohibited from copying, reproducing, distributing, making publicly available, selling, renting, leasing, lending, editing, translating, modifying, or creating derivative works from Korthex or proprietary components, in whole or in part.
The User is also prohibited from circumventing, manipulating, disabling, or assisting third parties in circumventing technical protection measures, license checks, activation mechanisms, usage restrictions, or other protective measures.
Decompiling, disassembling, reverse engineering, or otherwise attempting to derive the source code of proprietary components is prohibited unless expressly permitted by mandatory law. This does not affect the statutory entitlements under Sections 69d and 69e of the German Copyright Act (UrhG), namely acts that are necessary for intended use, error correction, the creation of a required backup copy, or the achievement of interoperability with an independently created computer program.
Where the User intends to establish interoperability between an independently created program and Korthex, the User may request the necessary interface information from the Provider. The Provider will make the necessary information available free of charge and to the extent required for that purpose within twenty (20) business days of receiving the request. The Provider may require the conclusion of a reasonable confidentiality agreement; such agreement must not restrict the use of the information for interoperability purposes.
The procedure set out in the preceding paragraph is a voluntary additional offer by the Provider. It does not restrict the User’s statutory entitlements under Section 69e of the German Copyright Act (UrhG). In particular, the User is not obliged to submit such a request or to await a response before exercising their statutory rights.
All rights in Korthex that are not expressly granted remain with the Provider or the respective rights holders. The name “Korthex”, the Korthex logo, product names, domains, graphic elements, and other Korthex identifiers are protected company, trademark, or other intellectual property rights of the Provider or its licensors.
The User may use Korthex trademarks, logos, and other identifiers only with the Provider’s prior express consent in text form. This does not apply to purely descriptive and accurate references to Korthex where required to describe a permitted compatibility, integration, or use, provided that no inaccurate business relationship with the Provider is implied.
The license ends automatically upon termination of the relevant agreement for use. After the license ends, the User must stop using the proprietary components and delete or uninstall any existing copies, unless their retention is permitted or required by mandatory law, legitimate archival interests, technically unavoidable backup copies, or applicable open-source licenses.
Where the User is an entrepreneur, a legal entity under public law, or a special fund under public law, the User must confirm the deletion or uninstallation to the Provider in text form within thirty (30) days of the Provider’s request. The confirmation shall identify any retained copies and the reason for their retention. The Provider may request such confirmation no more than once per terminated agreement. No confirmation obligation applies in relation to consumers.
Further obligations to return or delete confidential information are governed by Section 11. The User’s rights in their own data and locally created analysis results under point (c) and under Section 12 remain unaffected.
6. Fees and Payment Terms
Use of the Free plan is free of charge. The prices displayed on korthex.io, during the ordering process, in the order confirmation, or in an individual offer at the time of contract formation apply to the paid Community, Business, and Enterprise plans.
All prices are stated in euros and exclude applicable statutory value-added tax, where and to the extent such tax applies. Where legally required, prices displayed to consumers include applicable statutory value-added tax.
Unless otherwise specified during the ordering process, in the order confirmation, or in an individual agreement, billing is performed annually in advance. Invoices are due for payment in full, without deduction, within fourteen (14) days of the invoice date.
The User is responsible for ensuring timely and complete payment. Timeliness is determined by receipt of the full invoice amount by the Provider. The User shall bear the costs of any chargeback, reversed direct debit, payment reversal, or failed payment for which the User is responsible, provided that such costs are actually incurred and reasonable.
In relation to entrepreneurs, legal entities under public law, and special funds under public law, the User may set off only against undisputed claims or claims established by a final and binding court decision. The User may assert a right of retention only in respect of counterclaims arising from the same contractual relationship. In relation to consumers, only the statutory provisions apply; the foregoing restrictions do not apply to consumers.
Where the User is in default with a due payment, statutory default interest applies. For entrepreneurs, the default interest rate for payment claims is nine (9) percentage points above the applicable base interest rate pursuant to Section 288(2) of the German Civil Code (BGB). For consumers, statutory default interest applies pursuant to Section 288(1) of the German Civil Code (BGB). The Provider reserves the right to claim further demonstrable damages caused by default.
In relation to entrepreneurs, the Provider may also claim the statutory default compensation pursuant to Section 288(5) of the German Civil Code (BGB). This compensation shall be credited against any damages claim to the extent that such claim is based on costs of legal enforcement.
The Provider may adjust the prices for recurring paid plans at the beginning of a new renewal period where and to the extent necessary due to changes in the costs of operation, infrastructure, support, licenses, security measures, statutory charges, or comparable cost-related circumstances. Cost increases and cost reductions shall be reasonably taken into account when making such adjustments. Where the relevant costs decrease, the Provider is obliged to reduce the price accordingly; a price reduction does not require a separate request from the User.
A price increase under the preceding paragraph may not exceed ten (10) per cent of the price last applicable to the affected plan per renewal period. Any increase beyond that takes effect only with the User’s express consent.
The Provider will inform the User of a price adjustment in text form at least ninety (90) days before it takes effect. The notification will state the effective date, the previous and new price, and the principal reasons for the adjustment.
At the User’s request, the Provider will set out, in a comprehensible manner, the cost categories relevant to the adjustment and their development over the relevant period. The Provider is not obliged to disclose trade secrets, individual purchasing terms, or agreements with third parties; the presentation must, however, enable the User to carry out a plausibility check of the adjustment. The Provider documents the cost development relevant to an adjustment and retains that documentation for three (3) years from the date the adjustment takes effect.
If the price increases, the User may terminate the affected paid plan with effect from the end of the current billing period until the price adjustment takes effect. The Provider will inform the User of this right of termination in the price-adjustment notification. Statutory rights, in particular those of consumers, remain unaffected.
Where the User is in default with a due payment for more than thirty (30) days, the Provider may temporarily suspend access to paid features until all due amounts have been paid in full. Such suspension requires that the Provider has previously issued a payment reminder and given notice of the suspension in text form at least ten (10) days before it takes effect. The Free plan and the User’s statutory rights remain unaffected, unless suspension is permitted for other reasons.
The Provider will lift a suspension for late payment without undue delay, and at the latest within one (1) business day of receiving payment in full. Even during such a suspension, access to analysis results, inventories, reports, and migration plans already created, and the export thereof, remain available.
Where a suspension for late payment was unjustified, in particular because payment had already been received, the claim did not exist, or the User was not responsible for the default, the credit provision of Section 2 applies accordingly.
A suspension does not affect the User’s payment obligation for the agreed billing period where the User is responsible for the payment default. Further rights of the Provider, in particular the right to terminate for cause under Section 12, remain unaffected.
Where a billing period paid in advance ends prematurely, the following applies to the refund of the remuneration attributable to the period that can no longer be used: (a) Where the Provider terminates for cause on grounds for which the User is responsible, there is no entitlement to a refund; the Provider’s claims for damages and the crediting of saved expenses remain unaffected. (b) Where the Provider terminates, whether ordinarily or for cause, on grounds for which the User is not responsible, in particular where the plan or the product is discontinued, the Provider will refund on a pro rata basis the remuneration attributable to the period that can no longer be used. (c) Where the User terminates for cause on grounds for which the Provider is responsible, Section 12 applies. (d) In all other cases, in particular ordinary termination by the User, Section 12 applies.
A refund under point (b) is calculated on a calendar-day basis from the date the termination takes effect and is paid out within fourteen (14) days of that date via the payment method used for the original payment, unless the parties agree otherwise. Mandatory statutory rights, in particular those of consumers, and claims under the applicable Service Level Agreement remain unaffected.
7. Privacy and Data Processing
The Provider processes personal data in connection with the provision and use of Korthex solely in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection requirements.
Details regarding the processing of personal data in connection with Korthex, including categories of processed data, processing purposes, legal bases, recipients, retention periods, possible international data transfers, and data subject rights, are set out in the Korthex Privacy Policy at https://korthex.io/privacy. The general Flowence Infrastructure Privacy Policy at https://flowencehq.com/privacy also applies.
Korthex follows an offline-first architecture. Source code, binary files, local project files, and complete analysis results are generally processed locally on the User’s device or within an execution environment controlled by the User. Such data is not transferred to the Provider’s servers as part of standard local analysis.
This does not affect data transfers that are technically required to provide individual features or that have been expressly activated by the User. Such transfers may include data for registration, license activation, account management, permission checks, update checks, error reports, telemetry, support requests, external integrations, optional model, rule, or signature updates, and Mesh Networking features.
Where optional online features are activated, the Provider processes only the data required for the relevant feature. The specific data categories, transmission methods, and settings depend on the feature used, the User’s technical configuration, and the Korthex Privacy Policy.
The Mesh Networking feature is disabled by default and is used only after explicit activation by the User. Through their configuration and permissions, the User determines which Korthex instances are connected and which files, analysis results, or other data may be transferred within the Mesh Network.
The Provider designs the default settings of the Mesh Networking feature and of other optional online features so that no personal data is transmitted without an express act of the User (Article 25(2) GDPR). The User’s responsibility for transmitted content extends only to content the User has selected through a deliberate act of release. Where a transmission results from a malfunction, an incorrect default setting, or a misleading presentation in the user interface, the Provider bears the corresponding responsibility; Section 3 applies accordingly.
Where the User uses Korthex within an organisation or company, the User remains responsible for ensuring the lawfulness of personal data processing, selecting appropriate security measures, managing user authorisations, and ensuring the permissibility of integrations and data transfers within the User’s environment. That responsibility does not extend to processing carried out by the Provider for its own purposes.
Where the Provider itself determines the purposes and means of a processing activity, the Provider is the controller within the meaning of Article 4(7) GDPR in that respect. This applies in particular to processing for the purposes of product improvement, improvement of the detection logic, reach and usage analysis, abuse and fraud prevention, license enforcement, and compliance with the Provider’s own statutory obligations. Responsibility for such processing is not allocated to the User and cannot be allocated to the User by these Korthex Terms.
Where the Provider and the User jointly determine the purposes and means of a processing activity, the parties shall conclude an arrangement on joint controllership pursuant to Article 26 GDPR before the relevant processing begins. The Provider will make a template available upon request for that purpose.
Where the Provider processes personal data solely on behalf of the User and the User acts as the data controller, the parties shall enter into a data processing agreement pursuant to Article 28 GDPR before the relevant processing begins. Whether processing on behalf of the User exists depends exclusively on the specific processing activity and not on the selected plan.
The entitlement to conclude a data processing agreement applies irrespective of the plan. Where processing on behalf of the User exists, the Provider will make a template available to the User free of charge upon request and will conclude the data processing agreement, regardless of whether the User uses the Free, Community, Business, or Enterprise plan. The Provider will make the template available within fifteen (15) business days of receiving the request, via the user account or the support channels. This entitlement is not subject to any plan-based restriction.
Irrespective of the foregoing, the Provider offers Users of the Business and Enterprise plans the conclusion of a data processing agreement without a separate request. The User remains responsible for fulfilling any applicable information, documentation, record-keeping and, where applicable, consultation obligations.
The Provider implements appropriate technical and organisational measures to protect personal data in accordance with the risk associated with the respective processing activity. The specific security measures and their scope depend on the nature, scope, circumstances, and purposes of processing, as well as the state of the art.
8. Availability, Updates, and Support
Korthex is primarily a locally installed desktop application. The Provider therefore does not guarantee a specific availability level for the local Software in the sense of server uptime. The usability of local features depends in particular on the User’s hardware, operating system, security and network configurations, available permissions, and other system environment conditions.
For online services provided in connection with Korthex, in particular license activation, account management, permission checks, update and signature delivery, model updates, documentation, the website, and the support portal, the Provider owes availability in accordance with the following paragraphs.
The availability level owed depends on the selected plan and is set out in the applicable Korthex Service Level Agreement, available at https://korthex.io/sla (there, Section 4.1 – Portal availability). For the paid plans, the availability values stated there and, where provided for, service credits apply. For the free Free plan, no specific availability is owed; provision is made on a reasonable-efforts basis. Continuous or error-free availability is not owed under any plan.
An outage of the Provider’s online services does not render an already activated Korthex installation unusable; the local analysis functions remain usable within the applicable license validation intervals. Where the User is nevertheless unable to use Korthex as intended for more than twenty-four (24) hours due to an outage of the online services for which the Provider is responsible, the Provider will, for paid plans, credit the User on a pro rata basis for the remuneration attributable to the outage period. Scans that fail as a result of such an outage are not counted against the allowance under Section 4. Claims under the Service Level Agreement and further statutory claims remain unaffected.
Temporary restrictions or interruptions may arise in particular from necessary maintenance work, security measures, updates, technical faults, attacks on IT systems, disruptions affecting telecommunications or hosting providers, force majeure events, or other circumstances outside the Provider’s control. Planned maintenance work will be announced in advance where technically possible and reasonable.
Technical support is provided according to the selected plan and is governed in detail by the applicable Korthex Service Level Agreement and, where applicable, an individual agreement.
Users of the Free plan are not entitled to individual technical support. They may use the available product documentation, public notices, and, where available, community resources. Support services provided outside a contractually agreed support scope are voluntary and do not create an entitlement to a response time, resolution, or availability.
Users of the Community plan receive support by email or ticket system within the service hours and response times described in the Service Level Agreement. Users of the Business plan receive priority support and the portal availability services agreed for their plan. Enterprise Users are subject to individually agreed support, response time, availability, and, where applicable, service credit arrangements.
Within the scope of the relevant plan and ongoing technical development, the Provider provides updates, bug fixes, rule and signature updates, or other improvements for Korthex. The User is responsible for installing provided updates within a reasonable period unless an automatic update feature has been enabled.
By way of derogation from the preceding paragraph, security updates remedying vulnerabilities in Korthex itself are provided to all Users irrespective of the selected plan, including Users of the Free plan. The provision of security-related fixes is not made conditional on a paid plan, a change of plan, or additional remuneration.
Only the target times for providing a security-related fix are tiered by plan; those target times are set out in the Service Level Agreement (there, Section 4.4 – Security SLA). Under the Free and Community plans, provision takes place as part of the next regular release. This does not affect the Provider’s obligation to remedy a vulnerability without undue delay for all affected Users, or to provide a documented mitigation, where the risk is substantial.
Where the User is a consumer and uses Korthex as a digital product within the meaning of Sections 327 et seq. of the German Civil Code (BGB), the Provider will provide the updates required to maintain contractual conformity during the legally relevant period, including required security updates. The Provider will inform the consumer about the availability of such updates. The statutory update obligation under Section 327f(1) of the German Civil Code (BGB) applies irrespective of the plan and is not restricted by the tiering of target times under the preceding paragraph.
Where a consumer fails to install a provided update within a reasonable period, the Provider is not liable for a defect that results solely from the absence of that update, provided that the Provider has informed the consumer about the availability of the update, the consequences of failing to install it, and the proper installation procedure, and provided that the failure to install the update is not caused by defective installation instructions.
In relation to consumers, the exclusion of a defect on the ground that an update was not installed under Section 9 always requires that the conditions set out in the preceding paragraph are met.
9. Defect Rights and Functional Limitations
The Provider provides Korthex within the scope of the agreed plan and in accordance with the service description available at the time of contract formation. The selected plan, the order confirmation, any applicable individual agreement, and the version of the product documentation in force at the time of contract formation determine the contractually agreed characteristics of the Software. Section 1 on the relevance of public statements applies in addition.
Korthex supports the identification, classification, and prioritisation of potential cryptographic risks. Analysis results are based, among other factors, on available files, supported programming languages, detected dependencies, configurations, rule sets, signatures, and heuristic methods. Results may be incomplete, contain false classifications, or differ from a professional assessment.
In particular, the Provider does not guarantee that Korthex will identify all cryptographic implementations, dependencies, configurations, or vulnerabilities within a project. Nor is it guaranteed that every risk assessment reflects the latest scientific, regulatory, or industry-specific knowledge, or that proposed migration measures can be implemented without the User’s own technical, legal, and organisational review.
Korthex results do not constitute legal advice, compliance certification, a binding security approval, or an assurance of complete security. The User remains responsible for professionally assessing analysis results, conducting appropriate tests, and reviewing changes to source code, configurations, cryptographic methods, policies, or CI/CD pipelines before deploying them in production environments.
A defect does not exist to the extent that an impairment is caused by circumstances for which the User is responsible. This applies in particular to unsupported or incompatible system environments, insufficient permissions, incorrect installation, modifications to the Software or its components by the User or third parties, use outside the product documentation or plan limits, and disruptions caused by force majeure.
Where an impairment results solely from the User’s failure to install a provided update, a defect is absent only if the conditions set out in Section 8 are met. The Provider must therefore have informed the User about the availability of the update, the consequences of failing to install it, and the proper installation procedure, and the failure to install must not be caused by defective installation instructions. These conditions apply equally in relation to consumers and entrepreneurs; in relation to consumers, Section 327f(2) of the German Civil Code (BGB) applies in addition.
Where the User is a merchant within the meaning of the German Commercial Code (HGB), the User must give notice in text form of obvious defects within ten (10) business days of the provision of the affected version, and of non-obvious defects without undue delay after their discovery and at the latest within ten (10) business days of discovery. Where no such notice is given, the performance is deemed approved in that respect. This does not apply where the Provider fraudulently concealed the defect or assumed a guarantee as to quality. Section 377 of the German Commercial Code (HGB) otherwise remains unaffected.
The notification period set out in the preceding paragraph applies exclusively in relation to merchants. No contractual notification period applies in relation to consumers or to entrepreneurs who are not merchants; only the statutory provisions apply to them.
The User reports defects through the designated support channels with as much detail as possible, including the affected features, the Korthex version in use, the operating system, relevant error messages, and reproducible steps. An incomplete report preserves the notification period provided that the defect is identified in a manner that allows the Provider to allocate it; the Provider will request any missing information without undue delay.
Where the User is an entrepreneur, the Provider will first provide cure in the event of a justified defect claim. The Provider will propose the type of cure to the User and may provide it through a bug fix, provision of an update, provision of a workaround, or renewed provision of the affected feature. The User may object to the proposed type of cure in text form within five (5) business days, stating reasons; in that case the parties will agree on a suitable type of cure. Where no agreement is reached, the Provider decides, giving reasonable consideration to the User’s interests.
Cure by way of a workaround is reasonable for the User only where the workaround (a) fully compensates for the defect in respect of the use presupposed under the contract, (b) does not require permanent additional manual effort and functions in automated environments, in particular in CI/CD processes, without manual intervention, (c) does not reduce the security level of Korthex, and (d) does not cause additional costs for the User. A workaround is always an interim solution; the Provider will remedy the defect definitively within ninety (90) days of providing the workaround.
Cure is deemed to have failed where (a) two attempts at cure by the Provider in respect of the same defect have been unsuccessful, (b) the Provider has not remedied the defect within a reasonable period set by the User, (c) a workaround has not, contrary to the preceding paragraph, been replaced by a definitive remedy within ninety (90) days, or (d) the Provider refuses cure. In relation to consumers, only the statutory provisions apply; the foregoing criteria do not restrict their rights and apply in their favour as a minimum standard.
Where cure fails, is refused by the Provider, or is unreasonable for the User, the User shall have the statutory rights available to them. For entrepreneurs, the liability provisions set out in Section 10 of these Korthex Terms apply in addition.
In relation to consumers, the statutory provisions governing the provision of digital products and remedies for defects apply without restriction. In particular, statutory rights to cure, price reduction, termination of the contract, damages, and reimbursement of futile expenses remain unaffected.
No reduction of statutory limitation periods applies to consumers. For entrepreneurs, statutory limitation periods apply unless a different provision has been validly agreed in an individual agreement.
10. Liability
The Provider is liable without limitation for damages arising from injury to life, body, or health that are based on an intentional or negligent breach of duty by the Provider, its legal representatives, or its vicarious agents.
The Provider is further liable without limitation for damages caused by intentional or grossly negligent conduct of the Provider, its legal representatives, or its vicarious agents.
In the event of a slightly negligent breach of material contractual obligations, the Provider’s liability is limited in amount to the damage typical for this type of contract and foreseeable at the time of contract formation. Material contractual obligations are obligations whose fulfilment makes the proper performance of the contract possible in the first place and on whose fulfilment the User may regularly rely.
In all other respects, the Provider’s liability for damages caused by slight negligence is excluded.
Where Korthex produces analysis results, risk assessments, migration guidance, policies, configurations, CI/CD templates, or other recommendations, the User is responsible for independently reviewing them from a technical, professional, legal, and organisational perspective. The Provider is not liable for damages arising from the User implementing results or recommendations in a production environment without appropriate review, validation, testing, or approval, unless the damage is based on a breach of material contractual obligations for which the Provider is responsible, on intent, or on gross negligence.
The foregoing limitations of liability do not apply where an express guarantee has been assumed, where a defect has been fraudulently concealed, to claims under the German Product Liability Act, or in any other case of mandatory statutory liability.
Where the Provider’s liability is excluded or limited under the preceding paragraphs, this also applies to the personal liability of its employees, staff, representatives, corporate bodies, and vicarious agents. This expressly does not apply to liability for intent or gross negligence, nor to liability for damages arising from injury to life, body, or health; in those respects, the aforementioned persons are liable without limitation in accordance with the statutory provisions. This provision is not intended to, and does not, exempt those persons beyond the extent permitted by Section 309 no. 7 of the German Civil Code (BGB).
The liability provisions of this Section apply to claims of any legal nature, in particular to contractual and non-contractual claims and to claims arising from fault at the time of contract formation. The foregoing provisions do not alter the statutory burden of proof to the detriment of the User.
11. Confidentiality and Non-Disclosure
The parties undertake to treat as confidential all confidential information of the other party that becomes known to them in connection with the initiation, performance, or termination of the contractual relationship. Confidential information may be used exclusively for the purposes of performing this contractual relationship.
Confidential information means all information, documents, data, and knowledge that is marked as confidential or whose confidential nature follows from the circumstances, its content, or its nature. This includes in particular trade secrets, source code, binary files, technical documentation, security architectures, analysis results, inventories, reports, migration plans, access credentials, customer and user data, pricing and contractual terms, product plans, and strategic, commercial, and technical information.
The receiving party may make confidential information available only to those employees, affiliated undertakings, advisers, service providers, or other vicarious agents who require that information to perform the contract and who are bound to at least an equivalent level of confidentiality.
At the request of the disclosing party, the receiving party shall demonstrate in text form within twenty (20) business days that the persons and undertakings engaged pursuant to the preceding paragraph are effectively bound to confidentiality. Such evidence shall be provided by identifying the engaged recipients and submitting the relevant confidentiality provisions; the receiving party may redact prices, remuneration, and other elements unrelated to confidentiality. Such a request is limited to once per calendar year, unless there are concrete indications of a breach of the confidentiality obligation.
The receiving party is liable for compliance with the confidentiality obligation by the persons and undertakings it engages as it is for its own conduct.
The confidentiality obligation does not apply to information that the receiving party demonstrably already lawfully knew, that was publicly known at the time of disclosure or subsequently becomes publicly known without a breach of this agreement, that was lawfully obtained from a third party entitled to disclose it and without an obligation of confidentiality, or that was developed independently by the receiving party without recourse to confidential information of the other party.
Where the receiving party is required to disclose confidential information by statutory provisions, an administrative order, or a court decision, it may disclose the necessary information. It will, to the extent legally permissible and actually possible, inform the other party in text form in advance of the intended disclosure and limit the scope of disclosure to what is legally required.
The Provider ensures that its employees, subcontractors, and other service providers who may gain access to confidential information in the course of performing the services are bound to confidentiality to an appropriate extent.
At the request of the disclosing party, and at the latest upon termination of the contractual relationship, the receiving party must delete or return confidential information and any copies made of it, unless a statutory retention obligation, a legitimate interest in legal defence, or a technically unavoidable backup copy prevents this. Legally required retention and secured archive copies remain subject to this confidentiality obligation.
The receiving party shall confirm the deletion or return to the disclosing party in text form within thirty (30) days of the latter’s request. The confirmation shall identify the categories of information deleted or returned as well as any retained copies and the reason for their retention. Where the User is a consumer, no confirmation obligation applies; the deletion and return obligation itself remains unaffected. Section 5 applies in addition to the deletion of proprietary components.
Where the User culpably breaches the confidentiality obligation, the User promises the Provider a contractual penalty for each case of culpable infringement, the amount of which is determined by the Provider at its reasonable discretion and which may, in the event of a dispute, be reviewed by the competent court as to its appropriateness. The contractual penalty shall not exceed EUR 50,000 per individual case and EUR 250,000 in total per contract year. In the case of a continuing infringement, all acts of infringement based on the same course of conduct count as one case.
This contractual penalty provision applies exclusively to Users who are entrepreneurs, legal entities under public law, or special funds under public law. No contractual penalty is agreed in relation to consumers.
A forfeited contractual penalty shall be credited against any claim for damages of the Provider arising from the same infringement; a claim for damages shall be credited against a forfeited contractual penalty. The assertion of further damages and claims under the German Trade Secrets Act remain unaffected. The User reserves the right to prove that no damage or substantially less damage has occurred.
The confidentiality obligation applies during the term of the contract and continues for three (3) years after its termination. For information constituting a trade secret within the meaning of the German Trade Secrets Act, the obligation continues beyond that period for as long as such information is protected as a trade secret.
12. Term and Termination
Unless otherwise specified during the ordering process, in the order confirmation, or in an individual agreement, agreements for the paid Community, Business, and Enterprise plans are concluded for a minimum term of one (1) year.
After expiry of the minimum term, an agreement for a paid plan is extended by a further twelve (12) months in each case unless terminated by either party in text form with three (3) months’ notice to the end of the respective contract term. This provision applies exclusively in relation to entrepreneurs, legal entities under public law, and special funds under public law.
The Provider will remind the User in text form, at the latest thirty (30) days before the notice period expires, of the upcoming automatic renewal, the date on which the period expires, and the option to terminate. Where such a reminder is not given, the User may still give notice of termination within thirty (30) days of receiving a subsequent reminder or, if none is given, after the start of the renewal period, with effect from the start of the renewal period. In that case, any remuneration already paid for the renewal period will be refunded in full.
Where a paid plan is exceptionally provided to a consumer, only the mandatory statutory provisions apply to the minimum term, automatic renewal, and notice periods. In particular, after expiry of an agreed minimum term, a consumer contract is extended only for an indefinite period and may be terminated by the consumer at any time with a notice period of no more than one (1) month.
Use of the Free plan may be ended by either party at any time in text form or, where available, through the account management function. The Provider may discontinue the Free plan or end access upon reasonable notice where there is an objective reason to do so, in particular where the plan is discontinued or for technical, security-related, or legal reasons. Mandatory statutory rights of the User remain unaffected.
The right of both parties to terminate for cause remains unaffected. Cause exists where, taking into account all circumstances of the individual case and weighing the interests of both parties, the terminating party cannot reasonably be expected to continue the contractual relationship until the agreed term or notice period expires.
Cause for the Provider may exist in particular where the User breaches material obligations under these Korthex Terms, in particular where the User materially breaches the license provisions under Section 5, the usage restrictions under Section 4, or the confidentiality obligations under Section 11, circumvents technical protection measures or license checks, discloses access credentials or license keys without authorisation, or fails to pay due remuneration despite a reminder and the setting of a reasonable period.
Where the cause consists in the breach of a contractual obligation, termination for cause is permissible only after a reasonable period set for remedy has expired without success or after an unsuccessful formal warning (Section 314(2) of the German Civil Code (BGB)).
A formal warning within the meaning of the preceding paragraph requires text form and must (a) identify the alleged breach of duty by time, place, and content specifically enough for the warned party to allocate and remedy it, (b) identify the contractual obligation breached, (c) request remedy within a specified, reasonable period, and (d) expressly state that termination of the contractual relationship is intended should the remedy be unsuccessful. A communication that does not meet these requirements does not qualify as a formal warning within the meaning of this Section.
Setting a period or issuing a formal warning is dispensable where the other party seriously and definitively refuses performance, where special circumstances exist which, weighing the interests of both parties, justify immediate termination (Section 314(2) sentence 3 in conjunction with Section 323(2) of the German Civil Code (BGB)), or where a remedy is evidently not to be expected.
Termination for cause may only be declared within a reasonable period from becoming aware of the grounds for termination (Section 314(3) of the German Civil Code (BGB)).
The opening of insolvency proceedings over the assets of a party, the rejection of such proceedings for lack of assets, or the filing of a corresponding application does not in itself give rise to a right of termination for cause, to the extent that mandatory insolvency law provides otherwise. Statutory rights remain unaffected.
Notices of termination require text form; termination by email is sufficient. Where the Provider provides a termination function in the user account, termination may also be effected through that function.
Upon the termination taking effect, the right to use the proprietary components of Korthex ends. The User must cease use and uninstall or delete the proprietary components, unless their continued retention is required by statutory obligations, legitimate archival interests, or technical backup copies. Open-source components remain subject to their respective open-source license terms.
Analysis results, inventories, reports, exports, and migration plans created by the User or stored locally remain with the User. The User is responsible for exporting or backing up any required data in good time.
After the termination takes effect, the Provider grants the User export-only access for a period of thirty (30) days to the analysis results, inventories, compliance reports, and migration plans stored in the user account or portal (export window). The export window applies irrespective of which party terminated and on what grounds. The User’s obligation to cease using the proprietary components under the preceding paragraph remains unaffected; access during the export window does not entitle the User to continue using Korthex productively.
The Provider may exceptionally shorten or not grant the export window where this is necessary to avert a specific security threat, to prevent continued abusive use, or to comply with a mandatory statutory or regulatory obligation. In that case, the Provider will make the affected data available to the User upon request within ten (10) business days in a common, machine-readable format. After the export window expires, the Provider deletes the data stored in the portal in accordance with the Korthex Privacy Policy.
The following applies to the refund of remuneration paid in advance: In the event of ordinary termination by the User, remuneration already paid for the current billing period is not refunded. Where the User terminates for cause on grounds for which the Provider is responsible, or where the Provider terminates ordinarily or on grounds for which the User is not responsible, remuneration paid in advance is refunded on a pro rata basis for the period that can no longer be used after the termination takes effect.
Where the Provider terminates for cause on grounds for which the User is responsible, the Provider refunds the remuneration paid in advance for the period that can no longer be used after the termination takes effect, less any damages incurred and still to be incurred by the Provider and less services already rendered that cannot be reversed. The Provider will set out the deducted items in a comprehensible manner at the User’s request. The remuneration paid in advance is not forfeited in full.
Refunds under the preceding paragraphs are calculated on a calendar-day basis and paid out within fourteen (14) days of the termination taking effect via the payment method used for the original payment, unless the parties agree otherwise. Section 6 applies in addition. Mandatory statutory rights, in particular those of consumers, remain unaffected.
13. Indemnification
This indemnification provision applies exclusively to Users who are entrepreneurs, legal entities under public law, or special funds under public law. No indemnification obligation is agreed in relation to consumers; only the statutory provisions apply to them.
The User shall indemnify the Provider against justified third-party claims to the extent that such claims are based on the User having used Korthex unlawfully, in breach of contract, or in violation of third-party rights, and the User is responsible for the underlying breach of duty.
The indemnification obligation requires that the third-party claim has been established by a final and binding decision, acknowledged by the User, is undisputed between the parties, or that the User has consented to the Provider satisfying the claim. No obligation of the User to pay before the merits of the claim have been clarified is created. In particular, this does not constitute an obligation to pay on first demand.
Pending clarification of the merits of a claim, the Provider may require the User to provide reasonable security in the amount claimed, provided that the claim has been substantiated conclusively and brought before a court. The User may provide the security, at its option, by way of a guarantee, a deposit, or equivalent security. The security must be released without undue delay to the extent that the claim is dismissed, withdrawn, or otherwise resolved.
An indemnification obligation may arise in particular where the User uses Korthex to analyse source code, binary files, systems, or data without the required authorisation, infringes third-party rights, discloses access credentials or license keys without authorisation, violates statutory export control or sanctions provisions, or breaches material usage, license, or confidentiality obligations under these Korthex Terms.
The indemnification obligation covers the justified third-party claim itself, including any damages owed by the Provider, as well as the reasonable and necessary costs of legal defence, including statutory court costs and legal fees. Further statutory claims for damages of the Provider against the User remain unaffected.
No indemnification obligation exists to the extent that a third-party claim is based on conduct for which the Provider is responsible, on a defective performance by the Provider, or on a breach of the Provider’s own obligations. Where both parties are at fault, the indemnification is limited to the User’s share of responsibility.
The Provider will inform the User without undue delay of asserted third-party claims, to the extent legally permissible and reasonable for the purposes of legal defence. The User will provide the Provider with the information and documents required for review and defence to a reasonable extent. Where the Provider fails to inform the User without undue delay and the User’s legal defence is thereby impeded, the indemnification obligation ceases to apply to the extent of the resulting disadvantage.
The Provider remains entitled to conduct or coordinate the defence against third-party claims at its own discretion. A settlement, acknowledgement, or other agreement that imposes obligations on the User going beyond the statutory or contractual indemnification obligation may not be concluded without the User’s prior consent.
The User may refuse consent to a settlement only on one of the following grounds: (a) the settlement obliges the User to render a performance going beyond its indemnification obligation; (b) the settlement contains an admission of fault or a finding of fact to the User’s detriment; (c) the settlement obliges the User to do or refrain from doing something that impairs its business operations more than insignificantly; (d) the settlement amount substantially exceeds the amount that would reasonably be expected if the proceedings were continued; or (e) the settlement does not contain a provision releasing the User from further claims of the same third party arising from the same set of facts.
The User shall communicate its decision on consent in text form within ten (10) business days of receiving the settlement request; where a court has set a shorter period, that period applies. Where the User refuses consent, it must substantiate the refusal by stating one of the grounds set out above. Where the User does not respond within the period, consent is deemed granted; the Provider will point out this legal consequence in the settlement request.
14. Force Majeure
Neither party is liable for the non-performance or delayed performance of its contractual obligations to the extent and for as long as this is due to an event of force majeure. Force majeure means an external event that is unforeseeable and cannot be averted even with reasonable care, and that lies outside the control of the affected party.
Events of force majeure include in particular natural disasters, epidemics, pandemics, war, terrorism, civil unrest, embargoes, sanctions, official measures, fire, floods, accidents, general labour disputes, significant disruptions of telecommunications networks, energy supply networks, data centres, or hosting infrastructure, and serious cyberattacks, to the extent that the affected party is not responsible for them.
A cyberattack constitutes an event of force majeure only where, at the time of the attack, the affected party maintained technical and organisational protective measures in line with the state of the art and the attack could not have been averted even by complying with those measures. Where an attack is based on a vulnerability that could have been avoided by complying with the state of the art, in particular through available security updates, appropriate access controls, network segmentation, logging, and contingency planning, force majeure does not apply.
With respect to the security of the infrastructure it operates, the Provider is subject to the standard of care applicable to providers of security software. The burden of presentation and proof that the conditions of the preceding paragraph are met lies with the party invoking force majeure.
The party affected by force majeure will inform the other party in text form without undue delay of the occurrence, the expected duration, and the material effects of the event, to the extent this is possible and reasonable for it. It will take appropriate measures to limit the effects of the event and to resume performance of its obligations as soon as possible.
For the duration and to the extent of the impairment, the performance obligations affected by the event are suspended. Payment obligations already incurred or falling due irrespective of the event remain unaffected, unless payment itself is rendered impossible or unreasonably impaired by force majeure.
Where the User is unable to make a due payment on time due to an event of force majeure, in particular an outage of payment, banking, or payment service provider systems, no consequences of default arise for the duration of the impairment. Default interest, flat-rate default compensation, and suspension under Section 6 are excluded in that respect. The User will make the payment without undue delay after the impairment ceases and will inform the Provider of the impairment.
Where the Provider is unable to render a service owed due to an event of force majeure, scans and other usage operations that fail as a result are not counted against the allowances under Section 4.
Where an event of force majeure continues for more than ninety (90) consecutive days and resumption of the affected performance obligations within a reasonable period is not foreseeable, either party is entitled to terminate the contract affected by the impairment in text form upon thirty (30) days’ notice. Further statutory rights remain unaffected.
Where a contract is terminated under the preceding paragraph, the Provider refunds to the User, on a pro rata basis, remuneration paid in advance for the period that can no longer be used after the termination takes effect. In addition, the Provider refunds the remuneration attributable to the period during which the service could not be rendered, or could not be rendered to the agreed extent, due to the force majeure event. Section 12 applies accordingly to the calculation, period, and method of payment. No claims for damages arise in respect of the non-performance caused by force majeure.
15. Open-Source Components
Korthex may contain, use, or interact with open-source software components. Where required, a complete and current overview of the open-source components contained in Korthex, together with the relevant copyright notices, license texts, and, where applicable, source references, is provided in the “Licenses” section of the Software. Upon request, the Provider will additionally make the overview available in text form.
Individual open-source components are subject to the open-source licenses applicable to them. These may include in particular the MIT License, the Apache License 2.0, and other licenses identified in the license notices. The use, reproduction, modification, distribution, and licensing of an open-source component are governed exclusively by the license applicable to that component.
These Korthex Terms do not restrict any rights to which the User is entitled under an applicable open-source license. Where the provisions of an open-source license deviate from these Korthex Terms in respect of a particular open-source component, the provisions of that open-source license prevail for that component.
Where scanner components or source code repositories provided separately by the Provider are published under an open-source license, those components may be used, modified, and distributed independently of a Korthex plan in accordance with the respective license. There is no entitlement to the publication of particular components, to the provision of source code of proprietary modules, or to the free use of proprietary features.
Proprietary components of Korthex, in particular closed-source engine modules, advanced analysis algorithms, local models, rule sets, signatures, user interfaces, integrations, and Mesh Networking implementations, are not open source. They are subject exclusively to the license provisions set out in Section 5 of these Korthex Terms and, where applicable, to supplementary individual agreements.
Whether and to what extent an open-source license with copyleft effect extends to proprietary components is determined exclusively by the respective license and the technical form of the combination. These Korthex Terms can neither bring about nor exclude such a legal consequence. The following paragraphs therefore describe the actual arrangement on which the license structure of Korthex is based.
The Provider does not incorporate open-source components under a copyleft license, in particular under the GNU General Public License (GPL) or the GNU Affero General Public License (AGPL), into the proprietary engine modules, and does not link them statically or dynamically with those modules. Where such components are used, they are used exclusively as independent, unmodified programs executed in a separate process and invoked through defined interfaces such as command-line calls or inter-process communication. Components under the GNU Lesser General Public License (LGPL) are linked dynamically only and without modification.
Before each release of a version, the Provider reviews the licenses of all incorporated components and the technical form of their combination, and documents the outcome. Where such a review or a third-party notice reveals that a component has been incorporated contrary to the preceding paragraph, the Provider will remedy this without undue delay, in particular by replacing, removing, or separating the affected component or by obtaining a suitable license, and will inform affected Users.
The Provider warrants that it holds the rights required to grant the usage rights under Section 5 and that, to its knowledge, the contractual use of Korthex does not infringe any third-party rights.
Where a claim is asserted against the User on the ground that the contractual use of Korthex infringes copyright, patent, trademark, or other intellectual property rights of third parties, or breaches the terms of an open-source license, the Provider shall indemnify the User against that claim. Section 13 applies accordingly in favour of the User to the conditions, procedure, cooperation, conclusion of settlements, and scope of the indemnification. Section 10 applies as to the amount.
The indemnification under the preceding paragraph does not apply to the extent that the claim is based on the User having modified Korthex, used it outside the product documentation or the agreed license scope, combined it with software not provided by the Provider, or passed it on to third parties contrary to Section 5.
Where a defect of title exists, the Provider may, at its option, obtain the necessary rights, replace the affected component with a functionally equivalent one, or modify Korthex so that the infringement ceases, provided that this is reasonable for the User. The User’s rights under Section 9, in particular the criteria for reasonableness and for the failure of cure, apply accordingly. Where none of these measures is possible or reasonable, either party may terminate the affected contract for cause; Section 12 applies accordingly to the settlement.
Where the User intends to integrate Korthex or components thereof into its own products or to redistribute them, this requires a separate agreement under Section 5. Without such an agreement, the indemnification under this Section does not extend to claims arising from an integration or redistribution by the User.
16. Export Controls and Sanctions
Depending on its technical configuration, the cryptographic functions used, the country of destination, the end user, and the end use, Korthex may be subject to export control or sanctions restrictions. The User is obliged to comply with all export control, foreign trade, and sanctions provisions applicable to its use of Korthex.
The Provider’s own export control and sanctions obligations as an exporter remain unaffected by the provisions of this Section. The User’s obligations under this Section do not relieve the Provider of its own review and authorisation obligations.
The Provider carries out an export control classification for Korthex under Regulation (EU) 2021/821, keeps it up to date, and communicates it to the User in text form upon request. The User may use that classification for its own assessment; it does not replace the User’s own assessment for its specific export, transfer, or end use.
Where the provision of Korthex is based on a Union General Export Authorisation, in particular the Union General Export Authorisation EU007 for intra-group transfers of software and technology or the Union General Export Authorisation EU008 for encryption items, the Provider will inform the User upon request which authorisation it relies on. Reliance on a general authorisation requires compliance with the conditions, reporting and record-keeping obligations, and use restrictions set out therein; the User will comply with the conditions applicable to it and provide the Provider with the information required for that purpose.
Before a license key is provided for the first time, and on an ad hoc basis where warranted, the Provider screens the contract and user data against the applicable sanctions lists. For that purpose, the User provides complete and accurate information on the contracting party, users, countries of establishment, and, where known, the end use, and communicates any changes without undue delay. Where the screening produces a match or the User refuses to provide the required information, the Provider is entitled to decline to conclude the contract or to suspend provision.
The User may not export, re-export, transfer, provide, or make accessible Korthex, the associated documentation, updates, license keys, technical information, or services derived from them, whether directly or indirectly, where doing so would violate applicable export control or sanctions provisions.
In particular, the User may not make Korthex available to persons, organisations, entities, or end users subject to an applicable sanctions or embargo measure where such provision is prohibited or subject to authorisation. The same applies to countries, regions, territories, or end uses subject to applicable restrictions, prohibitions, or authorisation requirements.
Before any cross-border provision or provision to foreign users, the User undertakes to assess on its own responsibility whether authorisation, notification, review, or other obligations apply. This applies in particular to provision to end users outside the European Union, access from sanctioned territories, military or security-related end uses, and the transfer of cryptographic functions or technical information.
To the extent applicable to the use of Korthex, the User shall in particular observe Regulation (EU) 2021/821 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, the German Foreign Trade and Payments Act, the German Foreign Trade and Payments Ordinance, and applicable restrictive measures of the European Union and the Federal Republic of Germany.
Any required authorisations must be obtained before the relevant export, transfer, provision, or other controlled activity. The User is responsible for correctly classifying its own data, projects, end uses, and recipients, and for obtaining the authorisations required for its use.
The Provider is entitled to refuse, restrict, or suspend the provision of Korthex, individual features, updates, support services, or license keys where this is necessary to comply with applicable export control or sanctions provisions, or where there are concrete indications of a corresponding violation. Section 2 applies accordingly to the procedure for such a suspension, unless legal requirements preclude informing or hearing the User.
Where a suspension under the preceding paragraph is not based on conduct of the User, in particular where it results from a subsequent change in the legal situation, either party may terminate the affected contract for cause if the suspension continues for more than sixty (60) days. Section 12 applies accordingly to the settlement.
The Provider accepts no liability for violations of export control or sanctions provisions by the User, unless the violation is based on a breach of material contractual obligations for which the Provider is responsible, on intent, or on gross negligence.
17. Changes to These Korthex Terms
The Provider may change these Korthex Terms at any time for future contract formations. For existing contractual relationships, changes apply only in accordance with the following provisions.
The Provider may propose changes to these Korthex Terms where there is an objective reason to do so. Such a reason exists in particular in the case of changes in the legal situation, binding regulatory requirements, supreme court case law, security requirements, technical framework conditions, or the range of services offered for Korthex.
Changes affecting the core of the contract, in particular the nature, scope, or price of the principal service owed, the contract term, material liability provisions, usage rights, or data protection obligations, require an express agreement with the User. They cannot take effect solely through a notification by the Provider or through the User’s silence.
The Provider will transmit proposed changes to existing contractual relationships to the User in text form at least six (6) weeks before the intended effective date, or make them available for acceptance in the user account. The notification contains the full text of the changes, a comprehensible description of the material changes, the intended effective date, the period within which the User may respond, and a statement that the changes take effect only with the User’s express consent and that the User’s silence does not constitute consent.
Where the User does not respond within the period stated in the notification, the existing Korthex Terms continue to apply unchanged to the existing contractual relationship. The User’s silence constitutes neither consent nor rejection; it does not bring about any change to the contractual relationship and does not create a state of suspense. The User may expressly consent to a proposed change at any time, including after the period has expired.
Where the User does not consent to the proposed changes or does not respond, the existing Korthex Terms continue to apply to the existing contractual relationship.
Where the Provider cannot reasonably be expected to continue the contractual relationship on the existing terms for an objective reason, the Provider may terminate the contract ordinarily, observing the agreed or statutory notice period, at the earliest possible date. The Provider must state the relevant reason in the notice of termination. Until the termination takes effect, the contract continues on the existing terms. Section 12 applies to the refund of remuneration paid in advance; such a termination is deemed a termination on grounds for which the User is not responsible. The right to terminate for cause remains unaffected.
Purely editorial changes, clarifications, and updates to contact details, references, URLs, or formatting that have no adverse effect on the User’s rights or obligations may be made by the Provider without express consent. The Provider will identify such changes in an appropriate manner.
The Provider keeps the version of these Korthex Terms applicable to a contractual relationship available for the duration of that relationship and makes it available to the User in text form upon request.
Price changes, changes to the scope of services, and changes to digital products are additionally governed by the provisions set out for that purpose in these Korthex Terms, in particular Sections 3, 4, and 6, and by mandatory statutory provisions.
18. Governing Law and Jurisdiction
These Korthex Terms and all legal relationships between the Provider and the User are governed by the law of the Federal Republic of Germany, excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).
In relation to consumers, this choice of law applies only to the extent that it does not deprive them of the protection of mandatory provisions of the law of the state in which they have their habitual residence. Mandatory consumer-protection provisions remain unaffected.
Where the User is a merchant within the meaning of the German Commercial Code, a legal entity under public law, or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from or in connection with this contract is the Provider’s registered office.
Where the User has no general place of jurisdiction in Germany, relocates its registered office or habitual residence abroad after contract formation, or where its registered office or habitual residence is unknown at the time the action is brought, the Provider’s registered office is likewise the exclusive place of jurisdiction (Section 38(2) and (3) of the German Code of Civil Procedure (ZPO)).
Within its scope of application, the jurisdiction agreement under the preceding paragraphs constitutes an exclusive choice of court agreement within the meaning of the Hague Convention on Choice of Court Agreements of 30 June 2005.
The jurisdiction agreement is concluded in text form. At the request of either party, the parties will conclude a separate jurisdiction agreement with the same content signed by both parties, in particular where this is necessary for formal validity in relation to a User established outside the European Union. Where the jurisdiction agreement is ineffective in an individual case, the statutory provisions on international and local jurisdiction apply; the validity of the remaining provisions remains unaffected.
The Provider remains entitled to bring an action at the User’s general place of jurisdiction, to the extent legally permissible.
In relation to consumers, only the statutory provisions on the international and local jurisdiction of the courts apply.
The Provider is neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration body within the meaning of the German Act on Alternative Dispute Resolution in Consumer Matters. The User’s right to bring proceedings before the competent courts remains unaffected.
19. Severability
Should individual provisions of these Korthex Terms be or become invalid, void, unenforceable, or fail to become part of the contract, in whole or in part, the validity of the remaining provisions and of the contract in all other respects remains unaffected.
To the extent that a provision is invalid, void, unenforceable, or has not become part of the contract, the statutory provisions apply in its place (Section 306(2) of the German Civil Code (BGB)).
Where these Korthex Terms contain an unintended gap, the statutory provisions likewise apply. Supplementary contractual interpretation remains unaffected to the extent permitted under the applicable statutory provisions.
Invalid provisions are not reduced so as to preserve their validity. An invalid provision is not cut back to the legally permissible extent but is replaced by the statutory provisions.
An invalid provision is not automatically replaced by a provision that comes as close as possible to its economic purpose. In relation to entrepreneurs, the parties remain free to replace an invalid provision by a separate individual agreement; such an agreement is concluded only by corresponding declarations of both parties in text form.
20. Right of Withdrawal for Consumers
This Section applies exclusively to consumers within the meaning of Section 13 of the German Civil Code (BGB) who conclude a contract for Korthex by means of distance communication or off business premises. Entrepreneurs, legal entities under public law, and special funds under public law have no right of withdrawal.
Where Korthex is provided to a consumer free of charge and without the provision of personal data as counter-performance, no statutory right of withdrawal exists pursuant to Section 312(1) and (1a) of the German Civil Code (BGB). The Provider nevertheless grants consumers on the Free plan the right to end the usage relationship at any time without stating reasons and without observing a notice period; Section 12 remains unaffected.
Withdrawal instruction. You have the right to withdraw from this contract within fourteen (14) days without giving any reason. The withdrawal period is fourteen days from the day of the conclusion of the contract.
To exercise your right of withdrawal, you must inform us (Flowence Infrastructure, proprietor Hendrik Schneider, Berghäuserstr. 105, 45663 Recklinghausen, Germany, email: contact@flowencehq.com) of your decision to withdraw from this contract by an unequivocal statement, for example a letter or email. You may use the model withdrawal form set out below, but it is not obligatory. To meet the withdrawal deadline, it is sufficient for you to send your communication concerning the exercise of the right of withdrawal before the withdrawal period has expired.
Effects of withdrawal. If you withdraw from this contract, we shall reimburse to you all payments received from you, including the costs of delivery (with the exception of the supplementary costs resulting from your choice of a type of delivery other than the least expensive type of standard delivery offered by us), without undue delay and in any event not later than fourteen days from the day on which we are informed about your decision to withdraw from this contract. We will carry out such reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.
For digital products you owe no compensation for value pursuant to Section 357a(3) of the German Civil Code (BGB). Following an effective withdrawal you may no longer use Korthex; the provisions of Section 5 on the end of the license apply accordingly.
Early expiry of the right of withdrawal. In the case of a contract for the supply of digital content not supplied on a tangible medium, your right of withdrawal expires pursuant to Section 356(5) of the German Civil Code (BGB) where we have begun performance of the contract after you have (a) expressly consented to us beginning performance before the end of the withdrawal period, (b) confirmed your awareness that you lose your right of withdrawal by giving that consent once performance begins, and (c) we have provided you with a confirmation of the contract pursuant to Section 312f of the German Civil Code (BGB) on a durable medium.
The Provider obtains this consent and confirmation separately during the ordering process. If any of the above conditions is not met, your right of withdrawal continues until the withdrawal period expires. Without your consent under point (a), we will not begin provision until the withdrawal period has expired.
Model withdrawal form. If you wish to withdraw from the contract, please complete and return this form: To Flowence Infrastructure, proprietor Hendrik Schneider, Berghäuserstr. 105, 45663 Recklinghausen, Germany, email: contact@flowencehq.com. - I/We (*) hereby give notice that I/We (*) withdraw from my/our (*) contract of sale of the following goods (*) / for the provision of the following service (*): __________ - Ordered on (*) / received on (*): __________ - Name of consumer(s): __________ - Address of consumer(s): __________ - Signature of consumer(s) (only if this form is notified on paper): __________ - Date: __________ - (*) Delete as appropriate.
End of the withdrawal instruction. This instruction is additionally made available to you before you submit your contractual declaration during the ordering process and, together with the contract confirmation pursuant to Section 312f of the German Civil Code (BGB), on a durable medium.