Transparency matters. Here you find all legal, privacy, and licensing information about NIS2Have.
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany
E-Mail: info@nis2have.eu
Contact via ✉️ Contact Form
We respond to all enquiries submitted via the contact form within 2 business days.
VAT: In accordance with § 19 UStG (German small business regulation), no VAT is charged or shown.
David Steng
Address as above.
NIS2Have does not provide legal, regulatory, or certification advice. All reports, assessments, templates, and guides are informational aids designed to support your compliance efforts. They do not constitute a legal opinion and do not replace qualified professional advice from lawyers, auditors, or certified information security consultants.
We make no guarantee that use of our products will result in full NIS2 compliance or regulatory approval. Compliance is the sole responsibility of the operator of the essential or important entity as defined by the NIS2 Directive and its national transpositions.
Our reports are generated with the assistance of AI models (Anthropic Claude, xAI Grok) and are based on publicly available information (OSINT). While we employ extensive validation layers to ensure accuracy, AI-generated outputs may contain errors or incomplete information. Users must independently verify all findings before relying on them for business decisions.
Our liability is governed by § 5 of the License Terms below.
NIS2Have assessments are based on publicly available information (OSINT) collected from DNS records, SSL certificates, HTTP headers, and other non-intrusive sources. No active vulnerability scanning or penetration testing is performed.
Reports are generated using a multi-agent AI workflow combining attack path analysis with structured report generation. All findings undergo automated validation to minimize false positives. Users should treat findings as indicative rather than definitive and validate them with their own security teams.
As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to § 7(1) DDG. However, pursuant to §§ 8–10 DDG, we are not obligated to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
Obligations to remove or block the use of information under general law remain unaffected. Liability in this regard is only possible from the point in time at which we become aware of a specific infringement.
Our website contains links to external third-party websites over whose content we have no influence. We cannot accept any liability for this external content. The respective provider or operator of the linked pages is always responsible for the content of the linked pages.
We do not participate in dispute resolution proceedings before any consumer dispute resolution body (VSBG) or alternative dispute resolution (ADR) entity. Our services are offered exclusively to business customers (B2B). Note: The European Commission's former online dispute resolution (ODR) platform has been permanently discontinued since 20 July 2025 (Regulation (EU) 2024/3228).
German law applies exclusively. Place of jurisdiction is Winnenden, Germany, where legally permissible. The application of the UN Convention on Contracts for the International Sale of Goods (CISG) is excluded.
Data Controller pursuant to Art. 4(7) GDPR:
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany.
Contact via
✉️ Contact Form
This website is hosted and protected using services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA). Cloudflare acts as a reverse proxy and CDN; all HTTP(S) requests pass through their network. Cloudflare may process IP addresses and request metadata for security and performance purposes.
Backend services and databases are provided by Supabase, Inc. (hosted in EU region, Frankfurt). Supabase stores transactional data related to template purchases and report deliveries.
Communication with users is handled via Brevo (Sendinblue) (Paris, France) for transactional emails and optional marketing communications. Brevo processes email addresses and contact attributes for email delivery.
Payments are processed by Stripe Payments Europe, Ltd. (Dublin, Ireland).
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in operating a secure, performant service). Data processing agreements are in place to the extent the recipient acts as a processor on our behalf; Stripe acts as an independent controller with respect to payment data.
When you access our website or use our services, we (and our infrastructure providers) may process technical log data, including IP address, timestamps, requested URLs, user-agent, and error logs.
Purpose: ensuring the security and availability of the service, preventing abuse (e.g., rate limiting, fraud prevention, and attack detection), and troubleshooting.
We use Cloudflare Turnstile on certain forms to verify that submissions are made by humans rather than automated bots. Turnstile may process device and browser characteristics. See Cloudflare's Privacy Policy.
On devices without up-to-date Apple software, Turnstile collects personal data such as
the IP address and transmits it to Cloudflare in the USA. As part of the bot check, the
cookie cf_clearance is set, which proves that the check was passed and
avoids repeated queries. We rely on § 25(2) No. 2 TDDDG, as bot protection is strictly
necessary to provide the form you requested.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure service);
§ 25(2) No. 2 TDDDG for the cf_clearance cookie.
Retention: logs are stored only as long as required for the stated purposes and are regularly deleted or anonymized. Security incident data may be retained longer for investigation and defense.
We use Cloudflare Web Analytics (Cloudflare, Inc.) for aggregated reach measurement. The service operates without cookies and without cross-device recognition; it processes technical data such as the page visited, referrer, approximate region, and browser type.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring reach and technical troubleshooting).
Cookies in the "Statistics" and "Marketing" categories are only set after you have given your consent.
| Name / Provider | Purpose | Category | Duration | Legal Basis |
|---|---|---|---|---|
| Consent cookie | Stores your consent decision | Necessary | 6 months | § 25(2) No. 2 TDDDG |
cf_clearance (Cloudflare) |
Proof of passed bot check, prevents repeated challenges | Necessary | 30 minutes | § 25(2) No. 2 TDDDG |
_ga, _ga_07E6TS6P6R |
Distinguishing users and sessions | Statistics | 2 years (browsers may shorten) | Consent |
_gcl_au, _gcl_aw, _gcl_dc, _gac_* (Google Ads) |
Conversion measurement | Marketing | 90 days | Consent |
| Stripe (Checkout) | Payment processing, fraud prevention | Necessary | Session / Stripe default | Art. 6(1)(b) GDPR |
For certain analysis and report-generation steps, we use third-party AI model providers, including Anthropic (Claude) and xAI (Grok).
By using our services, users acknowledge that inputs provided to the platform may be processed by these providers in accordance with their respective privacy policies. We use API-based access where provider terms state that inputs are not used for model training.
Users are responsible for ensuring that no personal data or confidential information beyond what is necessary for the assessment is submitted. Our assessments are based on publicly available data (domain names, company names) and do not require the submission of sensitive personal data.
Legal basis: Art. 6(1)(b) GDPR (contract performance – generating the requested report).
EU AI Act (Regulation (EU) 2024/1689), Art. 50: We disclose that our platform deploys AI systems (Anthropic Claude, xAI Grok) for report generation and analysis. NIS2Have acts as an operator of AI systems that are built on third-party general-purpose AI models. All AI-generated outputs are presented as automated results and require independent verification before reliance. No high-risk AI systems as classified in Annex III of the EU AI Act are deployed.
To produce an applicability assessment, we analyze publicly available information about the domain and organization you provide — in particular DNS and WHOIS records, SSL/TLS certificates, HTTP headers, and publicly available company information. In individual cases this may include personal data, such as the name or business contact details of a technical or administrative contact person.
Categories of data: business contact details, technical metadata about externally reachable infrastructure.
Source: publicly accessible registers and the organization's own publicly reachable internet services.
Purpose and legal basis: Art. 6(1)(f) GDPR — our legitimate interest and that of our customer in assessing their own regulatory scope. The data is not otherwise used or disclosed to third parties other than the requesting customer.
Because the data relates to the organization examined at its own request, and we do not hold direct contact details of the individuals named in such registers, individual notification would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR. This notice takes its place.
Retention: see retention periods above.
Payments are processed by Stripe, Inc. (South San Francisco, CA, USA). When you make a purchase, you are redirected to Stripe's checkout page where Stripe collects and processes your payment information directly.
NIS2Have does not store or process credit card numbers or payment credentials. We receive from Stripe only: confirmation of payment, email address, purchased product, and transaction ID.
Legal basis: Art. 6(1)(b) GDPR (contract performance). Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
When you purchase a template kit, we store your email address and company name in our CRM system (Brevo) to deliver the product, grant the license, and inform you about updates during the update period. We may also inform you by email about our own similar products. You may object to this use at any time, free of charge — via the unsubscribe link in every email or by contacting us; you were already informed of this right when your email address was collected.
Legal basis: Art. 6(1)(b) GDPR (delivery), Art. 6(1)(f) GDPR in conjunction with § 7(3) UWG.
If you download a free guide or subscribe to updates without making a purchase, we only send you information if you have expressly consented. Consent is obtained and logged using the double opt-in procedure. You may withdraw it at any time with effect for the future via the unsubscribe link in every email (Art. 7(3) GDPR).
Legal basis: Art. 6(1)(a) GDPR, § 7(2) No. 2 UWG.
We use Google Analytics (Google Ireland Limited, Dublin, Ireland) to obtain aggregated statistics on website usage and to improve performance and security.
No Google Signals are active and we do not build individual advertising profiles ourselves. However, our Google Analytics property is linked to our Google Ads account for conversion measurement (see below).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG. Analytics and advertising tags are only loaded after you have given consent via our consent banner. You may withdraw your consent at any time with effect for the future via the "Cookie Settings" link in the footer (Art. 7(3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.
Retention: user- and event-level data is automatically deleted after 14 months. The maximum lifetime of the Google Analytics cookies is two years; browsers may shorten this significantly.
Users may object by adjusting browser settings or using the Google Analytics Opt-out Add-on.
We use Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to measure which advertisements lead to a purchase or an enquiry. Our Google Analytics property is linked to our Google Ads account, so that conversion events are passed to Google Ads. Google Signals is disabled; no cross-device profiles are built. The cookies used are stored for up to 90 days.
Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent).
When contacting us via the ✉️ Contact Form, we process the submitted data (e.g. email address, message content) solely for handling the request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual communication) or Art. 6(1)(f) GDPR (legitimate interest).
Data is deleted after final processing unless statutory retention obligations apply.
Some sub-processors are based in the United States (Cloudflare, Stripe, Google, Anthropic, xAI).
Insofar as the recipient is certified under the EU-US Data Privacy Framework, the transfer is based on the adequacy decision of 10 July 2023; otherwise on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with a documented transfer impact assessment.
Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21).
Where processing is based on consent, you may withdraw that consent at any time with effect for the future (Art. 7(3) GDPR), for example via the "Cookie Settings" link in the footer or the unsubscribe link in our emails.
You may object to the processing of your data for direct marketing purposes at any time, free of charge and without giving reasons (Art. 21(2) GDPR).
No automated decision-making with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place. Our assessments are automatically generated working aids; you make any decisions based on them yourself.
To exercise these rights, contact us via the contact form. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, www.baden-wuerttemberg.datenschutz.de.
We may update this privacy notice to reflect changes in our services or legal requirements. The current version is always available at this URL. Last updated: August 2, 2026.
The following terms apply to all NIS2Have template kits (Word, Excel) and associated guides (PDF) purchased or downloaded from nis2have.eu. By purchasing or downloading, you accept these terms.
Upon purchase, the licensee receives a simple, non-transferable, and non-sublicensable right to use the templates for internal purposes within the named company.
Permitted: Use, customize, and complete templates for internal company use; submit completed templates to the BSI or other authorities as required by law; create internal copies for employees; adapt templates to company-specific requirements.
Prohibited: Distribution, sale, rental, or transfer to third parties; publication on the internet or in third-party intranets; use by other companies, including affiliated companies or group subsidiaries (each requires a separate license); removal or alteration of license IDs, watermarks, or copyright notices; use as a basis for own commercial template products.
All documents are personalized and contain a unique license ID and the licensee's company name in document properties, headers/footers, and metadata. This serves attribution and protection against unauthorized distribution.
In the event of a breach, NIS2Have reserves the right to revoke the license and pursue claims for damages. Unauthorized distribution is traceable via the license ID.
The license includes free updates for 12 months from the purchase date if legal requirements under the BSIG / NIS2UmsuCG (German Act Implementing the NIS 2 Directive, promulgated 5 December 2025, in force since 6 December 2025) or BSI guidelines change. Updates are delivered by email.
(1) For intent and gross negligence, for damages arising from injury to life, body, or health, and for claims under the Product Liability Act, the statutory provisions apply.
(2) In the case of slightly negligent breach of a material contractual obligation, liability is limited to the damage typically foreseeable at the time of contract conclusion. Material contractual obligations are those whose fulfillment makes proper performance of the contract possible in the first place and on whose observance the licensee may regularly rely.
(3) Liability under paragraph 2 is limited in amount to the net amount paid for the affected license.
(4) Liability for indirect damages, consequential damages, and lost profits is excluded within the scope of paragraph 2.
(5) Liability is otherwise excluded.
(6) Claims by the licensee against NIS2Have become time-barred within one year from the statutory commencement of the limitation period. This does not apply to claims under paragraph 1; the statutory limitation periods continue to apply to those (§ 202(1) BGB).
The subject matter of the contract is the provision of personalized document templates to support the licensee's own compliance documentation. Not included are: review or evaluation of the documents completed by the licensee, creation of a compliance concept tailored to the individual case, the provision of legal, audit, or information-security consulting, the achievement of a specific compliance status, or official recognition of the documents. The templates reflect the legal situation at the time of their creation. Reviewing the content, adapting it to the licensee's own circumstances, and implementing the statutory requirements are the licensee's responsibility.
German law applies. Place of jurisdiction is Winnenden, Germany, where legally permissible. Should individual provisions be invalid, the remaining provisions remain unaffected.
The version applicable to your purchase is the version in effect at the time of purchase. The current version is always available at this URL. Last updated: August 2, 2026.