Transparency matters. Here you find all legal, privacy, and licensing information about NIS2Have.
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany
Contact via ✉️ Contact Form
We respond to all enquiries submitted via the contact form within 2 business days.
David Steng
Address as above.
NIS2Have does not provide legal, regulatory, or certification advice. All reports, assessments, templates, and guides are informational aids designed to support your compliance efforts. They do not constitute a legal opinion and do not replace qualified professional advice from lawyers, auditors, or certified information security consultants.
We make no guarantee that use of our products will result in full NIS2 compliance or regulatory approval. Compliance is the sole responsibility of the operator of the essential or important entity as defined by the NIS2 Directive and its national transpositions.
Our reports are generated with the assistance of AI models (Anthropic Claude, xAI Grok) and are based on publicly available information (OSINT). While we employ extensive validation layers to ensure accuracy, AI-generated outputs may contain errors or incomplete information. Users must independently verify all findings before relying on them for business decisions.
All services and digital products are provided "as is" without warranty of any kind, either express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement.
NIS2Have assessments are based on publicly available information (OSINT) collected from DNS records, SSL certificates, HTTP headers, and other non-intrusive sources. No active vulnerability scanning or penetration testing is performed.
Reports are generated using a multi-agent AI workflow combining attack path analysis with structured report generation. All findings undergo automated validation to minimize false positives. Users should treat findings as indicative rather than definitive and validate them with their own security teams.
As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to § 7(1) DDG. However, pursuant to §§ 8–10 DDG, we are not obligated to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
Obligations to remove or block the use of information under general law remain unaffected. Liability in this regard is only possible from the point in time at which we become aware of a specific infringement.
Our website contains links to external third-party websites over whose content we have no influence. We cannot accept any liability for this external content. The respective provider or operator of the linked pages is always responsible for the content of the linked pages.
We do not participate in dispute resolution proceedings before any consumer dispute resolution body (VSBG) or alternative dispute resolution (ADR) entity. Our services are offered exclusively to business customers (B2B). Note: The European Commission's former online dispute resolution (ODR) platform has been permanently discontinued since 20 July 2025 (Regulation (EU) 2024/3228).
German law applies exclusively. Place of jurisdiction is Winnenden, Germany, where legally permissible. The application of the UN Convention on Contracts for the International Sale of Goods (CISG) is excluded.
Data Controller pursuant to Art. 4(7) GDPR:
David Steng
Silberpappelstraße 11
71364 Winnenden
Germany.
Contact via
✉️ Contact Form
This website is hosted and protected using services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA). Cloudflare acts as a reverse proxy and CDN; all HTTP(S) requests pass through their network. Cloudflare may process IP addresses and request metadata for security and performance purposes.
Backend services and databases are provided by Supabase, Inc. (hosted in EU region, Frankfurt). Supabase stores transactional data related to template purchases and report deliveries.
Communication with users is handled via Brevo (Sendinblue) (Paris, France) for transactional emails and optional marketing communications. Brevo processes email addresses and contact attributes for email delivery.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in operating a secure, performant service). Data processing agreements (DPAs) are in place with all sub-processors.
When you access our website or use our services, we (and our infrastructure providers) may process technical log data, including IP address, timestamps, requested URLs, user-agent, and error logs.
Purpose: ensuring the security and availability of the service, preventing abuse (e.g., rate limiting, fraud prevention, and attack detection), and troubleshooting.
We use Cloudflare Turnstile on certain forms to verify that submissions are made by humans rather than automated bots. Turnstile may process device and browser characteristics. No cookies are set. See Cloudflare's Privacy Policy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure service).
Retention: logs are stored only as long as required for the stated purposes and are regularly deleted or anonymized. Security incident data may be retained longer for investigation and defense.
For certain analysis and report-generation steps, we use third-party AI model providers, including Anthropic (Claude) and xAI (Grok).
By using our services, users acknowledge that inputs provided to the platform may be processed by these providers in accordance with their respective privacy policies. We use API-based access where provider terms state that inputs are not used for model training.
Users are responsible for ensuring that no personal data or confidential information beyond what is necessary for the assessment is submitted. Our assessments are based on publicly available data (domain names, company names) and do not require the submission of sensitive personal data.
Legal basis: Art. 6(1)(b) GDPR (contract performance – generating the requested report).
EU AI Act (Regulation (EU) 2024/1689), Art. 50: We disclose that our platform deploys AI systems (Anthropic Claude, xAI Grok) for report generation and analysis. NIS2Have acts as a deployer of general-purpose AI models. All AI-generated outputs are presented as automated results and require independent verification before reliance. No high-risk AI systems as classified in Annex III of the EU AI Act are deployed.
Payments are processed by Stripe, Inc. (South San Francisco, CA, USA). When you make a purchase, you are redirected to Stripe's checkout page where Stripe collects and processes your payment information directly.
NIS2Have does not store or process credit card numbers or payment credentials. We receive from Stripe only: confirmation of payment, email address, purchased product, and transaction ID.
Legal basis: Art. 6(1)(b) GDPR (contract performance). Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
When downloading a free guide or purchasing a template kit, your email address and company name are stored in our CRM system (Brevo) for the purpose of delivering the product and providing update notifications.
You may occasionally receive NIS2-related updates and product announcements. You can unsubscribe at any time using the link in every email or by contacting us.
Legal basis: Art. 6(1)(b) GDPR (product delivery), Art. 6(1)(f) GDPR (legitimate interest in informing customers about relevant updates), and § 7(3) UWG (marketing to existing customers for similar products).
We use Google Analytics (Google Ireland Limited, Dublin, Ireland) to obtain aggregated statistics on website usage and to improve performance and security.
Google Analytics is configured with IP anonymization and without advertising features, user profiling, cross-device tracking, or user identification.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interests are: measuring aggregate website usage to improve content and performance, identifying technical errors, and evaluating the effectiveness of our content. No individual user profiles are created; advertising features and cross-site tracking are disabled.
Users may object by adjusting browser settings or using the Google Analytics Opt-out Add-on.
When contacting us via the ✉️ Contact Form, we process the submitted data (e.g. email address, message content) solely for handling the request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual communication) or Art. 6(1)(f) GDPR (legitimate interest).
Data is deleted after final processing unless statutory retention obligations apply.
Some sub-processors are based in the United States (Cloudflare, Stripe, Google, Anthropic, xAI). Data transfers to the US are conducted on the basis of the EU-US Data Privacy Framework (DPF, adequacy decision of 10 July 2023) and Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. SCCs serve as an independent transfer safeguard irrespective of the continued validity of the DPF.
Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21).
To exercise these rights, contact us via the contact form. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW).
We may update this privacy notice to reflect changes in our services or legal requirements. The current version is always available at this URL. Last updated: June 2026.
The following terms apply to all NIS2Have template kits (Word, Excel) and associated guides (PDF) purchased or downloaded from nis2have.eu. By purchasing or downloading, you accept these terms.
Upon purchase, the licensee receives a simple, non-transferable, and non-sublicensable right to use the templates for internal purposes within the named company.
Permitted: Use, customize, and complete templates for internal company use; submit completed templates to the BSI or other authorities as required by law; create internal copies for employees; adapt templates to company-specific requirements.
Prohibited: Distribution, sale, rental, or transfer to third parties; publication on the internet or in third-party intranets; use by other companies, including affiliated companies or group subsidiaries (each requires a separate license); removal or alteration of license IDs, watermarks, or copyright notices; use as a basis for own commercial template products.
All documents are personalized and contain a unique license ID and the licensee's company name in document properties, headers/footers, and metadata. This serves attribution and protection against unauthorized distribution.
In the event of a breach, NIS2Have reserves the right to revoke the license and pursue claims for damages. Unauthorized distribution is traceable via the license ID.
The license includes free updates for 12 months from the purchase date if legal requirements under the BSIG / NIS2UmsG (German Act Implementing the NIS 2 Directive, in force since December 2025) or BSI guidelines change. Updates are delivered by email.
Templates serve as working aids for documentation and do not replace individual legal or security consulting. NIS2Have assumes no liability for correctness, completeness, or suitability for any specific use case. Responsibility for correct implementation of legal requirements remains with the licensee.
German law applies. Place of jurisdiction is the registered office of NIS2Have, where legally permissible. Should individual provisions be invalid, the remaining provisions remain unaffected.
The version applicable to your purchase is the version in effect at the time of purchase. The current version is always available at this URL. Last updated: June 2026.