Transparency matters. Here you find all legal, privacy, and licensing information about NIS2Have.
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany
E-Mail: info@nis2have.eu
Contact via ✉️ Contact Form
We respond to all enquiries submitted via the contact form within 2 business days.
VAT: In accordance with § 19 UStG (German small business regulation), no VAT is charged or shown.
David Steng
Address as above.
As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to § 7(1) DDG. However, pursuant to §§ 8–10 DDG, we are not obligated to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
Obligations to remove or block the use of information under general law remain unaffected. Liability in this regard is only possible from the point in time at which we become aware of a specific infringement.
Our website contains links to external third-party websites over whose content we have no influence. We cannot accept any liability for this external content. The respective provider or operator of the linked pages is always responsible for the content of the linked pages.
We do not participate in dispute resolution proceedings before any consumer dispute resolution body (VSBG) or alternative dispute resolution (ADR) entity. Our services are offered exclusively to business customers (B2B). Note: The European Commission's former online dispute resolution (ODR) platform has been permanently discontinued since 20 July 2025 (Regulation (EU) 2024/3228).
German law applies exclusively. Place of jurisdiction is Winnenden, Germany, where legally permissible. The application of the UN Convention on Contracts for the International Sale of Goods (CISG) is excluded.
Data Controller pursuant to Art. 4(7) GDPR:
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany.
Contact via
✉️ Contact Form
This website is hosted and protected using services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA). Cloudflare acts as a reverse proxy and CDN; all HTTP(S) requests pass through their network. Cloudflare may process IP addresses and request metadata for security and performance purposes.
Backend services and databases are provided by Supabase, Inc. (hosted in the EU). Supabase stores transactional data related to template purchases and report deliveries. For customers of the web application it also stores the user accounts and the compliance data those customers enter themselves. Processing on their behalf is governed by the data processing agreement, which is available — together with the technical and organisational measures — under “Vertrag & Sicherheit” once signed in.
Communication with users is handled via Brevo (Sendinblue) (Paris, France) for transactional emails and optional marketing communications. Brevo processes email addresses and contact attributes for email delivery.
Payments are processed by Stripe Payments Europe, Ltd. (Dublin, Ireland).
The applicability check runs as an automated workflow at n8n GmbH (Novalisstr. 10, 10115 Berlin, Germany). It processes your email address, the domain being checked and the size figures you provide. A data processing agreement under Art. 28 GDPR is in place.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in operating a secure, performant service). Data processing agreements are in place to the extent the recipient acts as a processor on our behalf; Stripe acts as an independent controller with respect to payment data.
When you access our website or use our services, we (and our infrastructure providers) may process technical log data, including IP address, timestamps, requested URLs, user-agent, and error logs.
Purpose: ensuring the security and availability of the service, preventing abuse (e.g., rate limiting, fraud prevention, and attack detection), and troubleshooting.
We use Cloudflare Turnstile on certain forms to verify that submissions are made by humans rather than automated bots. Turnstile may process device and browser characteristics. See Cloudflare's Privacy Policy.
On devices without up-to-date Apple software, Turnstile collects personal data such as
the IP address and transmits it to Cloudflare in the USA. As part of the bot check, the
cookie cf_clearance is set, which proves that the check was passed and
avoids repeated queries. We rely on § 25(2) No. 2 TDDDG, as bot protection is strictly
necessary to provide the form you requested.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure service);
§ 25(2) No. 2 TDDDG for the cf_clearance cookie.
Retention: logs are stored only as long as required for the stated purposes and are regularly deleted or anonymized. Security incident data may be retained longer for investigation and defense.
We use Cloudflare Web Analytics (Cloudflare, Inc.) for aggregated reach measurement. The service operates without cookies and without cross-device recognition; it processes technical data such as the page visited, referrer, approximate region, and browser type.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring reach and technical troubleshooting).
Cookies in the "Statistics" and "Marketing" categories are only set after you have given your consent.
| Name / Provider | Purpose | Category | Duration | Legal Basis |
|---|---|---|---|---|
| Consent cookie | Stores your consent decision | Necessary | 6 months | § 25(2) No. 2 TDDDG |
cf_clearance (Cloudflare) |
Proof of passed bot check, prevents repeated challenges | Necessary | 30 minutes | § 25(2) No. 2 TDDDG |
_ga, _ga_07E6TS6P6R |
Distinguishing users and sessions | Statistics | 2 years (browsers may shorten) | Consent |
_gcl_au, _gcl_aw, _gcl_dc, _gac_* (Google Ads) |
Conversion measurement | Marketing | 90 days | Consent |
| Stripe (Checkout) | Payment processing, fraud prevention | Necessary | Session / Stripe default | Art. 6(1)(b) GDPR |
For certain analysis and report-generation steps, we use third-party AI model providers, currently Anthropic (Claude).
By using our services, users acknowledge that inputs provided to the platform may be processed by these providers in accordance with their respective privacy policies. We use API-based access where provider terms state that inputs are not used for model training.
Users are responsible for ensuring that no personal data or confidential information beyond what is necessary for the assessment is submitted. Our assessments are based on publicly available data (domain names, company names) and do not require the submission of sensitive personal data.
Legal basis: Art. 6(1)(b) GDPR (contract performance – generating the requested report).
EU AI Act (Regulation (EU) 2024/1689), Art. 50: We disclose that our platform deploys AI systems (Anthropic Claude) for report generation and analysis. NIS2Have acts as an operator of AI systems that are built on third-party general-purpose AI models. All AI-generated outputs are presented as automated results and require independent verification before reliance. No high-risk AI systems as classified in Annex III of the EU AI Act are deployed.
To produce an applicability assessment, we analyze publicly available information about the domain and organization you provide — in particular DNS and WHOIS records, SSL/TLS certificates, HTTP headers, and publicly available company information. In individual cases this may include personal data, such as the name or business contact details of a technical or administrative contact person.
Categories of data: business contact details, technical metadata about externally reachable infrastructure.
Source: publicly accessible registers and the organization's own publicly reachable internet services.
Purpose and legal basis: Art. 6(1)(f) GDPR — our legitimate interest and that of our customer in assessing their own regulatory scope. The data is not otherwise used or disclosed to third parties other than the requesting customer.
Because the data relates to the organization examined at its own request, and we do not hold direct contact details of the individuals named in such registers, individual notification would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR. This notice takes its place.
Retention: see retention periods above.
Payments are processed by Stripe, Inc. (South San Francisco, CA, USA). When you make a purchase, you are redirected to Stripe's checkout page where Stripe collects and processes your payment information directly.
NIS2Have does not store or process credit card numbers or payment credentials. We receive from Stripe only: confirmation of payment, email address, purchased product, and transaction ID.
Legal basis: Art. 6(1)(b) GDPR (contract performance). Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
When you purchase a template kit, we store your email address and company name in our CRM system (Brevo) to deliver the product, grant the license, and inform you about updates during the update period. We may also inform you by email about our own similar products. You may object to this use at any time, free of charge — via the unsubscribe link in every email or by contacting us; you were already informed of this right when your email address was collected.
Legal basis: Art. 6(1)(b) GDPR (delivery), Art. 6(1)(f) GDPR in conjunction with § 7(3) UWG.
If you download a free guide or subscribe to updates without making a purchase, we only send you information if you have expressly consented. Consent is obtained and logged using the double opt-in procedure. You may withdraw it at any time with effect for the future via the unsubscribe link in every email (Art. 7(3) GDPR).
Legal basis: Art. 6(1)(a) GDPR, § 7(2) No. 2 UWG.
We use Google Analytics (Google Ireland Limited, Dublin, Ireland) to obtain aggregated statistics on website usage and to improve performance and security.
No Google Signals are active and we do not build individual advertising profiles ourselves. However, our Google Analytics property is linked to our Google Ads account for conversion measurement (see below).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG. Analytics and advertising tags are only loaded after you have given consent via our consent banner. You may withdraw your consent at any time with effect for the future via the "Cookie Settings" link in the footer (Art. 7(3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.
Retention: user- and event-level data is automatically deleted after 14 months. The maximum lifetime of the Google Analytics cookies is two years; browsers may shorten this significantly.
Users may object by adjusting browser settings or using the Google Analytics Opt-out Add-on.
We use Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to measure which advertisements lead to a purchase or an enquiry. Our Google Analytics property is linked to our Google Ads account, so that conversion events are passed to Google Ads. Google Signals is disabled; no cross-device profiles are built. The cookies used are stored for up to 90 days.
Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent).
When contacting us via the ✉️ Contact Form, we process the submitted data (e.g. email address, message content) solely for handling the request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual communication) or Art. 6(1)(f) GDPR (legitimate interest).
Data is deleted after final processing unless statutory retention obligations apply.
Some sub-processors are based in the United States (Cloudflare, Stripe, Google, Anthropic).
Insofar as the recipient is certified under the EU-US Data Privacy Framework, the transfer is based on the adequacy decision of 10 July 2023; otherwise on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with a documented transfer impact assessment.
Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21).
Where processing is based on consent, you may withdraw that consent at any time with effect for the future (Art. 7(3) GDPR), for example via the "Cookie Settings" link in the footer or the unsubscribe link in our emails.
You may object to the processing of your data for direct marketing purposes at any time, free of charge and without giving reasons (Art. 21(2) GDPR).
No automated decision-making with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place. Our assessments are automatically generated working aids; you make any decisions based on them yourself.
To exercise these rights, contact us via the contact form. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, www.baden-wuerttemberg.datenschutz.de.
We may update this privacy notice to reflect changes in our services or legal requirements. The current version is always available at this URL. Last updated: August 22, 2026.
These terms apply to everything NIS2Have provides: the document kits, the web application at nis2have.eu/app, and free offerings such as the applicability check.
They are the general framework. Whatever applies in addition to or differently from them in an individual case — in particular the data processing agreement, the technical and organisational measures, and your order — is available once you are signed in, under Vertrag & Sicherheit in your organisation. Those documents take precedence over these terms (§ 1(4)).
(1) These terms govern all contracts between David Steng, Silberpappelstraße 11, 71364 Winnenden, Germany (“NIS2Have”) and the customer concerning (a) the supply of document kits in Word, Excel and PDF format (“kits”), (b) the provision of the web application for use over the internet (“the application”), and (c) free services such as the applicability check and free guides.
(2) Business customers only. Contracts are concluded exclusively with entrepreneurs within the meaning of § 14 BGB, legal persons under public law and special funds under public law. The customer warrants that, in concluding the contract, it acts in the exercise of its commercial or independent professional activity. No contract is concluded with consumers.
(3) Deviating or supplementary terms of the customer do not become part of the contract, even if NIS2Have does not expressly object to them.
(4) Contract documents and order of precedence. The following apply in this order: (i) the individual order or quotation, (ii) the documents provided under Vertrag & Sicherheit in the application, in particular the data processing agreement and the technical and organisational measures, (iii) these terms.
(5) The version in force at the time the contract is concluded applies. The current version is available at this address and can be saved and printed.
(6) Language versions. These terms are provided in German, English and French. The German version prevails; the others are non-binding translations. Where a translation is followed by a German legal term in parentheses, the German legal term shall prevail.
(1) The presentation of services on the website is not a binding offer. By ordering, the customer makes an offer; the contract is concluded when NIS2Have confirms it or provides the service.
(2) All prices are net. In accordance with § 19 UStG (German small business regulation), no VAT is shown.
(3) Payment is processed by Stripe. Subscriptions are payable in advance for the respective billing period. Kits are made available for download or by email without delay after receipt of payment, at the latest within 24 hours.
(4) Price adjustment for subscriptions. NIS2Have may adjust fees at most once per contract year, giving six weeks' notice with effect from the start of the next billing period. The customer may then terminate for cause with effect from that date; the notice will say so.
(5) No right of withdrawal. There is no right of withdrawal, as contracts are concluded exclusively with entrepreneurs.
(1) Kits. NIS2Have supplies personalised templates and guides for download. The customer receives an unlimited right to use the version delivered, in accordance with § 4; updates are governed by § 8.
(2) The application. NIS2Have provides the application for use over the internet for the term of the contract, to the extent of the modules and seats booked. The contract for the application is a lease within the meaning of §§ 535 et seq. BGB. The point of delivery is where data passes from the data centre into the internet; NIS2Have is not responsible for the connection from there to the customer.
(3) Free services may be changed or discontinued at any time. No availability is warranted for them.
(4) The following is expressly not part of the contract:
Content, templates, checklists and assessments are general information and working aids. Legal assessment, adaptation to the individual case and implementation are the customer's responsibility; where necessary, the customer must have them examined by a qualified third party.
(5) Automated assessments and AI. Parts of the service — in particular the applicability check and individual assessments — are generated automatically using third-party AI systems. They may be incomplete or incorrect and must be verified by the customer before any use. No automated decision producing legal effects within the meaning of Art. 22 GDPR takes place. Their use is disclosed pursuant to Art. 50 of Regulation (EU) 2024/1689.
(6) No contract for work, no result owed. The subject matter of the contract is the supply of templates and the provision of the application, not the production of a work (Werk). No particular result is owed — in particular not complete, audit-proof or officially recognised documentation — and no acceptance (Abnahme, § 640 BGB) takes place.
(7) Preview and test features — those marked “beta”, “pilot” or “in preparation” — are provided without warranty and without any availability commitment, and may be changed or discontinued at any time.
(1) Kits. The customer receives a simple, non-exclusive, non-transferable and non-sublicensable right to use the templates for internal purposes within the named company, unlimited in time. Permitted in particular: editing and completing them, submitting them to the BSI or other authorities, making internal copies for employees, and adapting them to the customer's own circumstances.
(2) The application. The customer receives a simple, non-transferable right of use, limited to the term of the contract and the seats booked. A seat is assigned to one natural person and must not be shared; it may be reassigned to another person when the first leaves.
(3) Prohibited: distribution, sale, rental or transfer to third parties; publication on the internet or in third-party intranets; use by other companies including affiliated companies and group subsidiaries (each requires its own licence); removing or altering licence IDs, watermarks or copyright notices; use as the basis for the customer's own commercial template or software products; reverse engineering beyond § 69e UrhG; automated bulk retrieval; and security testing without prior written consent.
(4) Personalisation. Kits carry a unique licence ID and the customer's company name in the document properties, headers and footers, and metadata. In the event of a breach of paragraph 3, NIS2Have reserves the right to revoke the licence and claim damages; unauthorised distribution is traceable via the licence ID.
(1) NIS2Have targets availability of the application of 95% on a monthly average, measured at the point of delivery under § 3(2).
(2) The following do not count as downtime: announced maintenance windows (as a rule outside 08:00–18:00 on business days, announced at least 24 hours in advance), urgent security measures, force majeure under § 12, disruptions within the customer's sphere or that of its access provider, and disruptions at third parties whose services are required for operation, provided NIS2Have selected and monitored them properly.
(3) Current operating status and past incidents are published without login at nis2have.eu/status.
(4) Support is provided on business days by email and through the contact form. No response or restoration time is warranted unless individually agreed.
(5) The customer does not execute a rent reduction under § 536 BGB unilaterally, but asserts it by giving notice to NIS2Have. § 14(3) remains unaffected.
(1) The customer keeps access credentials confidential, does not pass them on, and reports any suspected misuse without delay. The customer is responsible for actions taken through the seats assigned to it.
(2) The customer submits only lawful content, infringes no third-party rights, and introduces no malicious software.
(3) Personal data of third parties — for example emergency contacts, training participants or supplier contacts — may be entered only where the customer is entitled to do so. In that respect the customer is the controller within the meaning of Art. 4(7) GDPR.
(4) Backups. The customer exports the data it has entered at reasonable intervals and before the contract ends, and keeps it outside the application. Where the application provides no export function for a given set of data, NIS2Have supplies it on request in a common, machine-readable format.
(5) The customer ensures the system requirements: a current browser and suitable internet access.
(6) The customer reports defects without delay and in a comprehensible manner. § 377 HGB remains unaffected.
(7) Indemnity. If the customer breaches paragraphs 2 or 3, it shall, at its own cost, defend, indemnify and hold NIS2Have harmless from and against all third-party claims arising from that breach, including reasonable costs of legal defence.
(1) The data the customer enters remains the customer's data. NIS2Have processes it solely to perform the contract.
(2) Where NIS2Have processes personal data on the customer's behalf, the data processing agreement applies. It is available, together with the technical and organisational measures and the list of sub-processors, under Vertrag & Sicherheit in the application. Details of the processing are set out in the privacy notice.
(3) No AI model training. NIS2Have does not use customer data to train its own or third-party AI models. Any evaluation for statistical purposes is carried out only in anonymised or aggregated form.
(4) After the contract ends, the customer's data remains available for 30 days; NIS2Have supplies it on request in a common, machine-readable format. It is then deleted within a further 30 days, unless statutory retention obligations apply; § 147 AO and § 257 HGB apply to invoicing and licence data.
(5) Confidentiality. Each party keeps confidential any information of the other that is marked confidential or recognisably so, uses it only to perform the contract, and discloses it only to those who need it for that purpose and are themselves bound accordingly. This does not apply to information that was already known to the receiving party, that it lawfully obtained afterwards from a third party under no duty of confidence, that is or becomes public without breach of this clause, or that it developed independently without recourse to the confidential information. Statutory or official disclosure obligations remain unaffected; the affected party informs the other where that is permitted. The obligation applies for the term of the contract and for three years afterwards, and for trade secrets within the meaning of the GeschGehG for as long as they remain trade secrets.
(1) Kits. The customer receives free updates for 12 months from the date of purchase where the requirements under BSIG/NIS2UmsuCG or BSI guidance change. Updates are delivered by email. After that period there is no claim to further free updates; a paid extension may be offered separately.
(2) The application. The application is developed continuously. NIS2Have may change, extend or replace features provided the contractual benefit is not materially impaired. NIS2Have will announce material reductions in functionality at least six weeks in advance in text form; the customer may then terminate for cause with effect from that date.
(1) The purchase of a kit does not create a continuing obligation; the right of use under § 4(1) is unlimited in time.
(2) The term for the application follows the order. It renews for the same period unless terminated with 14 days' notice (monthly term) or one month's notice (annual term) to the end of the term.
(3) The right to terminate for cause remains unaffected. For NIS2Have, good cause exists in particular where there is a material breach of § 4 or § 6, or payment default exceeding two monthly amounts.
(4) Termination and payment collection are two different things. Notice must be given in text form; an email is sufficient and effective. On its own, however, it does not stop collection by our payment provider. The customer therefore also cancels the running subscription in the subscription management linked under Vertrag & Sicherheit. Where the customer has only given notice in text form, we arrange for the subscription to end without undue delay; any amount collected regardless is refunded.
(5) Suspension. In the event of a material breach, NIS2Have may temporarily suspend access after prior notice. The claim to remuneration remains for that period. Read access to data already entered, and its export, remain possible where reasonable and where the ground for suspension does not preclude it.
(1) Kits. The statutory warranty for digital products in business-to- business dealings applies. Subsequent performance is rendered by supplying a corrected version.
(2) The application. §§ 535 et seq. BGB apply. Strict liability irrespective of fault for defects already present at the conclusion of the contract (§ 536a(1) alt. 1 BGB) is excluded.
(3) Immaterial deviations, and impairments caused by use contrary to the contract, by changes made by the customer, or by disruptions within the customer's sphere, are not defects.
(4) No acceptance takes place (§ 3(6)). Using the application, downloading templates and paying fees are not an acceptance and not an acknowledgement that performance conformed to the contract.
(1) NIS2Have is liable without limitation (a) for intent and gross negligence, (b) for damage arising from injury to life, body or health, (c) under the German Product Liability Act, and (d) to the extent of a guarantee given and in the event of fraudulent concealment of a defect.
(2) In cases of slight negligence, NIS2Have is liable only for breach of a material contractual obligation, and then limited in amount to the damage foreseeable and typical for this type of contract at the time it was concluded. Material obligations are those whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the customer may regularly rely.
(3) Amount. The foreseeable, contract-typical damage under paragraph 2 is limited to the fees the customer paid for the affected service in the twelve months before the event causing the damage (the contract volume). No minimum amount is agreed. For services provided free of charge those fees are nil, and there is accordingly no liability under paragraph 2.
(4) Loss of data. Liability for loss of data is limited to the effort that would have been required to restore it had the customer backed up its data in accordance with § 6(4).
(5) Indirect damage, consequential loss, lost profit. Within the scope of paragraph 2, NIS2Have is not liable for lost profits, savings not realised, or indirect damage, unless such damage was at the same time typical for this type of contract and foreseeable at the time of conclusion. Where there is such liability, the limit in paragraph 3 applies; no amount beyond it is owed.
(6) There is no liability for the accuracy, completeness or legal conformity of the documentation produced by the customer, nor for fines, sanctions or other measures taken by authorities against the customer. The reason is § 3(4): legal assessment and implementation are the customer's responsibility.
(7) Paragraphs 2 to 6 do not apply in the cases covered by paragraph 1.
(8) The above limitations also apply in favour of NIS2Have's legal representatives, employees and vicarious agents.
(9) § 254 BGB (contributory negligence) remains unaffected, in particular where the customer has breached § 6(4) (backups) or the duty of examination under § 3(4).
(10) Limitation period. Claims of the customer against NIS2Have become time-barred one year after the statutory commencement of the limitation period. This does not apply to claims under paragraph 1, nor in the event of fraudulent concealment of a defect; the statutory periods continue to apply in those cases (§ 202(1) BGB).
Events beyond a party's control — in particular natural events, war, industrial action, measures by authorities, large-scale failures of power, telecommunications or cloud infrastructure, and attacks on information technology — release that party from its obligation to perform for their duration and to the extent of their effect. The affected party gives notice without delay. If the event lasts longer than six weeks, either party may terminate the affected contract.
(1) Each contract is governed by the version of these terms the customer accepted when the contract was concluded. Later versions do not apply to that contract.
(2) The accepted version is kept available permanently, with its version label and date, under Vertrag & Sicherheit in the application, and can be retrieved there at any time. The time of acceptance and the person accepting are recorded with it.
(3) NIS2Have may publish a new version for future contracts at any time. New customers then contract on that version; nothing about an existing contract changes.
(4) The version governing an existing contract can only be changed with the customer's consent. NIS2Have may seek that consent under Vertrag & Sicherheit; if the customer does not give it, the existing version continues to apply.
(5) On a renewal under § 9(2) the version previously accepted continues to apply.
(1) German law applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
(2) The exclusive place of jurisdiction for all disputes is Winnenden, Germany, where the customer is a merchant, a legal person under public law or a special fund under public law. NIS2Have is also entitled to sue at the customer's general place of jurisdiction.
(3) The customer may set off only against undisputed claims or claims established by a final court decision. The customer has a right of retention only in respect of claims under the same contractual relationship.
(4) The customer may transfer rights and obligations under the contract only with NIS2Have's consent. § 354a HGB remains unaffected.
(5) There are no oral ancillary agreements. Amendments and additions require text form; this also applies to any waiver of this form requirement. Individually agreed terms take precedence (§ 305b BGB).
(6) Should individual provisions be or become wholly or partly invalid or unenforceable, or should the contract contain a gap, the validity of the remaining provisions is unaffected. In place of the invalid, unenforceable or missing provision, such valid and enforceable provision shall be deemed agreed as the parties would have agreed, having regard to the commercial purpose of the contract, had they been aware of the invalidity, unenforceability or gap when the contract was concluded.
(7) NIS2Have does not participate in dispute resolution proceedings before a consumer arbitration board; the services are addressed exclusively to businesses.
Version of 22 August 2026. The version in force when your contract was concluded is the one that applies to it; the current version is always available at this address. Signed-in customers can see the version that applies to them, and when they accepted it, under Vertrag & Sicherheit in their organisation.