Skip to content
Back to home

General Terms and Conditions (GTC) of Entalys GmbH for the Service "paless"

Effective: 2026-07-03Version: 

Authoritative version

This English version is provided for convenience only. The legally authoritative version is the German version available at https://paless.eu/de/agb. In the event of inconsistency between language versions, the German version prevails, subject to mandatory consumer protection provisions of the law of the consumer's habitual residence (Article 6 Rome I Regulation).

Preamble

(1) These General Terms and Conditions (hereinafter "GTC") govern the contractual relationships between Entalys GmbH, Carmenstr. 18, 40668 Meerbusch, registered in the commercial register of the Local Court of Neuss under HRB 25084, VAT ID DE460863235, represented by the managing director Christoph Kleinhans (hereinafter "Provider"), and natural or legal persons using the document management service offered under the name "paless" (hereinafter "Customer").

(2) The subject matter of the contract is the provision of the software-based document management service "paless" as a browser-based application (Software-as-a-Service) in accordance with the service description applicable from time to time (Annex 1) and in accordance with the service package selected by the Customer from the price list applicable from time to time (Annex 5).

(3) Conflicting, deviating or supplementary terms and conditions of the Customer shall not become part of the contract unless the Provider expressly consents to their application in text form.

(4) Support contributions made via crowdfunding platforms (e.g. Kickstarter) are governed by the terms and conditions of the respective platform. The subsequent provision and use of the Service in the course of redeeming a support contribution is governed by these GTC in conjunction with the conditions confirmed upon redemption (cf. Annex 5 no. 9).

PART A — EU Baseline (applies to all Customers in the EU)

The following clauses are based on directly applicable Union law or on minimum-harmonisation directives.

Section 1 — Scope; Definitions

(1) These GTC apply to all contracts between the Provider and the Customer concerning the use of "paless". (2) For the purposes of these GTC, the following terms mean:

  • "Service": the document management service provided by the Provider under the name "paless", including the associated interfaces, functionalities and content in accordance with the service description (Annex 1);
  • "Customer Content": all data, documents, files, metadata and other information that the Customer introduces into the system in the course of using the Service or generates through use of the Service;
  • "Consumer": a natural person within the meaning of Article 2(1) of Directive 2011/83/EU (in Germany: § 13 BGB);
  • "Trader": a natural or legal person, or a partnership with legal capacity, within the meaning of Article 2(2) of Directive 2011/83/EU (in Germany: § 14 BGB);
  • "AI system": an automated system within the meaning of Article 3(1) of Regulation (EU) 2024/1689 (AI Act);
  • "Text form": a readable statement on a durable medium (within the meaning of Article 2(10) of Directive 2011/83/EU and, respectively, § 126b BGB), in particular by email.
  • In case of doubt, the Customer shall be deemed a Trader within the meaning of these GTC unless the Customer expressly confirms in the order process that it will use the Service predominantly for private purposes.

Section 2 — Conclusion of the Contract

(1) The presentation of the Service and the tariffs in the online shop and on the Provider's website does not constitute a binding offer, but a non-binding invitation to the Customer to submit an offer.

(2) The Customer submits a binding offer by completing the order process and clicking the button "zahlungspflichtig bestellen" (order with obligation to pay). Before submitting the offer, the Customer is shown, in a clearly arranged order summary, all essential elements of the contract (service, term, total price including all price components and, where applicable, follow-on prices) in a clear and comprehensible manner.

(3) The contract is concluded upon receipt by the Customer of the Provider's confirmation of acceptance in text form (email). The Provider is entitled to accept or decline the Customer's offer within 14 days.

(4) The Provider stores the contract text after conclusion of the contract and makes it accessible to the Customer. The Customer may retrieve and save the GTC applicable from time to time at any time at https://paless.eu/de/agb.

(5) The contract language is German. Further language versions are made available for ease of understanding; in the event of inconsistencies, the German version prevails, save where mandatory consumer protection provisions of the Customer's state of habitual residence preclude this.

Section 3 — Subject Matter of the Contract and Scope of Services

(1) The Provider makes the Service available to the Customer via the public internet for use through a standard browser. The specific functional scope results from the chosen service package and from the service description applicable from time to time (Annex 1).

(2) The Provider reserves the right, within the bounds of what is technically and economically feasible, to further develop, adapt, expand or restrict the Service, in particular in order to improve security, to remedy defects, to adapt to changes in the law or to introduce new functions. Material restrictions of functionality shall be communicated to the Customer in text form with appropriate advance notice. Section 19 (Amendments) remains unaffected.

(3) Insofar as the Service uses artificial intelligence (AI) for semantic tagging, for classification and for a dialogue-based search ("Pal"), Section 12 (AI notice) applies.

(4) The Provider is entitled to designate individual functionalities as beta, preview or test functions. Such functions are additional, voluntary services and are not part of the contractually owed performance or of the agreed characteristics; they may be modified or discontinued at any time and do not give rise to any claims regarding availability or defects. Vis-à-vis Consumers, §§ 327 ff. BGB remain unaffected with respect to the performance owed for remuneration.

(5) The following, in particular, are not part of the contractual performance: • a) the processing of files protected by password or other cryptographic means without provision of the required key material by the Customer; • b) the processing of files that cannot, or cannot reliably, be read by machine according to prevailing standards (in particular severely damaged or blurred documents or documents degraded by lossy compression); • c) the processing of files in technically unsupported formats or above the size, volume or processing limits set out in the service description (Annex 1); • d) the processing of content in languages or writing systems that are not supported, or are supported only to a limited extent, by the OCR and AI components used; • e) the provision of functions whose prerequisites lie outside the Provider's sphere of responsibility or which require external systems or services controlled by the Customer (e.g. mail intake via a mail server operated by the Customer, connection of a cloud storage service of the Customer). Section 8 (Liability for Defects) does not apply to requirements falling under points a) to e).

Section 4 — Acceptable Use; Customer Obligations

(1) The Customer undertakes to use the Service only within the framework of applicable laws and these GTC. In particular, the following are prohibited: • a) the uploading, storage or distribution of content that infringes applicable law (in particular copyright, criminal law, data protection law), the rights of third parties or public morals; • b) the uploading or distribution of malware or of content liable to impair the security, integrity or availability of the Service or of the infrastructure of third parties; • c) the unauthorised circumvention or overcoming of access, volume or security restrictions; • d) the automated scraping, mirroring or mass replication of the Service or its content beyond the technical means required for the contractual use; • e) the use of the Service for purposes that conflict with the contractually intended purpose of document management, in particular use as mere bulk storage without any management or analysis nexus.

(2) The Customer is obliged to keep its access credentials confidential and to protect them against access by third parties. The Customer is responsible for all activities carried out under its account, to the extent that it is at fault.

(3) The Customer shall ensure that it is entitled to introduce the content it uploads into the Service and to have it processed by the Provider, in particular from a data protection, copyright and employment law perspective. Where the Customer processes personal data of third parties, the Customer is the controller within the meaning of the GDPR; the Provider is in that respect a processor in accordance with the DPA (Annex 2).

(4) In the event of a reasonable suspicion of a material breach of paragraph (1) or upon an order by a competent authority, the Provider is entitled to temporarily block access to individual content or to the entire account, or to remove content, to the extent this is necessary and proportionate to avert damage, to comply with statutory obligations or to protect third parties. The Provider shall inform the Customer of the measure and its reasoning in text form without undue delay (cf. Section 13 on DSA compliance).

(5) The Provider is entitled to enforce moderate technical usage limits (in particular storage volume, number of documents per period, number of OCR pages, number of queries to "Pal", maximum file size, API call frequency) in accordance with the chosen service package. The specific limits are set out in the service description (Annex 1).

(6) The Customer shall indemnify the Provider, upon first written demand, against all claims asserted by third parties against the Provider on account of an infringement of their rights by content introduced into the Service by the Customer or by a use of the Service for which the Customer is responsible (in particular copyright, personality rights, data protection positions, industrial property rights or provisions of unfair competition law). The indemnification includes the reasonable costs necessary for the legal defence. It does not apply to the extent that the claim is based on fault attributable to the Provider. The Provider shall inform the Customer without undue delay of any claim asserted, shall allow the Customer to conduct the defence and shall not conclude any settlement without the Customer's consent. Vis-à-vis Consumers, this indemnification clause does not apply; the general rules on damages (§§ 280 ff. BGB) apply exclusively.

(7) User accounts for minors may only be created by the Customer as their legal representative or with the latter's consent. In any event, the Customer remains the contracting party; the Customer is responsible for the use of the Service via the user accounts created by it in accordance with paragraph (2).

Section 4a — Protection against Misuse and Disproportionate Access

(1) The Provider is entitled to block access to individual endpoints, to individual interface credentials (e.g. API keys) or to the entire account immediately and without prior warning if, on the basis of objective indications, there is misuse or a disproportionate utilisation of the Provider's systems. The following, in particular, are deemed to constitute misuse or disproportionate utilisation: • a) flooding or unusually loading individual endpoints (e.g. with the appearance of a denial-of-service attack); • b) the use of scripts, bots or other automation, unless effected via the interfaces expressly provided by the Provider for that purpose or where the limits documented there are exceeded; • c) the scraping, mirroring or mass replication of the Service or its content; • d) the circumvention or attempted circumvention of volume, frequency or security restrictions, including rate limits; • e) anomalous access patterns, in particular brute-force login attempts, unusually high frequencies of OCR, AI or Pal queries, and other patterns indicating automated or abusive use.

(2) The Provider shall inform the Customer of the measure taken without undue delay in text form, stating the material facts and the legal or contractual basis (Section 13 of these GTC; Article 17 DSA remains unaffected).

(3) The block shall be lifted as soon as the Customer demonstrates that the underlying cause has been remedied and that a recurrence is not to be feared. The Provider may make the lifting of the block conditional upon the agreement of appropriate technical or organisational measures.

(4) In the event of repeated or particularly serious violations, the Provider is entitled to extraordinary termination of the contract for cause (Section 6(4) of these GTC, § 314 BGB). Claims of the Provider for damages remain unaffected.

(5) Vis-à-vis Consumers, § 314 Abs. 2 BGB remains unaffected. A block vis-à-vis Consumers without prior warning shall occur only where the circumstances set out in paragraph (1) points a) to e) render a warning manifestly dispensable, in particular in the event of an acute risk to the availability or security of the Service or in the event of criminal conduct.

Section 4b — Requests by Authorities; Sanctions; Limits of Use; Services Provided Free of Charge; Log Data

(1) The Provider shall disclose Customer Content to authorities or other third parties only to the extent that it is legally obliged to do so under the law of the European Union or of a Member State. The Provider shall, to the extent reasonable, review requests as to their legal basis, shall inform the Customer prior to any disclosure to the extent legally permissible, and shall limit the disclosure to the legally required scope.

(2) The Provider is not obliged to provide the Service to the extent that sanctions or embargo provisions of the European Union or its Member States preclude this. If the Customer is listed on a relevant sanctions list, the Provider is entitled to suspend performance and to terminate the contract for cause to the extent legally required; the Customer will be informed thereof to the extent legally permissible.

(3) The Service is a tool for document management. The Customer must not use the Service or the outputs of the AI functions as part of practices within the meaning of Article 5 of Regulation (EU) 2024/1689 (prohibited practices) or as a component of a high-risk AI system within the meaning of Article 6 in conjunction with Annex III of that Regulation. If the Customer uses the Service contrary to sentence 2 or makes a substantial modification within the meaning of Article 25 of Regulation (EU) 2024/1689, the obligations resulting therefrom shall be incumbent solely on the Customer; Section 4(6) (indemnification) applies mutatis mutandis.

(4) For services that the Provider provides free of charge (in particular test and preview phases as well as additional, non-remunerated functions), the Provider is liable only for intent and gross negligence and for damages arising from injury to life, body or health. Mandatory rights of the Consumer under §§ 327 ff. BGB with respect to the performance owed for remuneration remain unaffected.

(5) Vis-à-vis Traders, the substantive accuracy of the system and access logs generated by the Service is rebuttably presumed; the Trader remains free to prove that the logs are inaccurate.

Section 5 — Prices, Value Added Tax, Payment

(1) The prices displayed in the order process and set out in the price list applicable from time to time (Annex 5) shall apply.

(2) Vis-à-vis Consumers, prices are stated as gross prices and include the statutory value added tax of the EU Member State in which the Consumer has his or her habitual residence. Vis-à-vis Traders, prices are stated as net prices plus the applicable statutory value added tax.

(3) For cross-border supplies to Traders holding a valid VAT identification number of another EU Member State, invoicing shall be carried out under the reverse-charge procedure in accordance with the provisions of Union law; in such cases, the tax liability is transferred to the recipient of the supply.

(4) The Customer is obliged to provide complete and accurate address and tax data and to notify any changes without undue delay. The Provider is entitled to verify the plausibility of the data provided within the scope of the statutory requirements.

(5) Payment is made in advance by one of the means of payment offered in the order process. In the case of monthly billing, the fee is due at the beginning of each billing period; in the case of annual billing, it is due once at the beginning of the contractual term.

(6) If the actual use exceeds the storage volume included in the service package, additionally required storage shall be invoiced at the rates set out in the price list, per gigabyte commenced. The Provider shall inform the Customer in text form before the additional charging commences.

(7) In the event of default of payment, the Provider is entitled to claim statutory default interest and to suspend further provision of the Service after a prior reminder in text form and the setting of a reasonable grace period. The right to extraordinary termination for cause remains unaffected. A suspension on account of default of payment does not extend to read access to content already stored or to the data export under Section 11; both remain available for at least 30 days from the beginning of the suspension. In all other respects, the Provider is entitled to suspend, in a targeted manner, intake and processing functions (in particular upload, OCR and AI functions).

(8) The Customer may only set off against claims of the Provider with counterclaims that are undisputed or have been established by a final court decision. The Customer is entitled to a right of retention only insofar as its counterclaims are based on the same contractual relationship. Vis-à-vis Consumers, the statutory provisions apply.

(9) The Provider is entitled to adjust the prices of existing contracts no more than once per calendar year, to the extent that the overall costs relevant to the provision of the Service (in particular costs of data centre and network infrastructure, energy, software licences and personnel, as well as costs caused by changes in the law) have demonstrably changed since the prices were last set. The adjustment shall be made at the Provider's reasonable discretion (§ 315 BGB) and at most to the extent of the change in costs; cost reductions shall be taken into account so as to reduce prices in accordance with the same standards. Price adjustments shall be notified to the Customer in text form at least six weeks before they take effect. If the Provider increases the prices, the Customer may terminate the contract in text form with effect from the date on which the increase takes effect; the Customer shall be separately advised of this in the notification. No deemed-approval mechanism applies to price changes. Permanent discounts promised to the Customer (in particular founder terms from supporter campaigns, cf. Annex 5 no. 9) remain unaffected by an adjustment of the list price.

Section 6 — Contractual Term; Ordinary Termination (general baseline)

(1) The contractual term depends on the service package selected by the Customer (monthly or annual; cf. price list, Annex 5).

(2) Contracts with monthly billing may be ordinarily terminated by the Customer with one month's notice to the end of the current billing period.

(3) Contracts with an initial annual term shall be extended for an indefinite period upon expiry of the initial term and may thereafter be ordinarily terminated by the Customer with one month's notice to the end of any calendar month. For contracts with Consumers, Section 22 applies in addition.

(4) The right of either party to terminate for cause remains unaffected. For the Provider, cause shall be deemed to exist in particular in the event of a material breach by the Customer of Section 4 of these GTC that continues despite a warning, or in the event of default of payment for more than 30 days despite a reminder.

(5) Notices of termination require at least text form.

Section 7 — Availability; Maintenance

(1) The Provider endeavours to ensure the highest possible availability of the Service. No specific availability quota and no specific service level is warranted, and neither forms part of these GTC; an express service level agreement may be agreed separately. Vis-à-vis Traders, the actual availability does not constitute an agreement on characteristics within the meaning of § 434 BGB. Vis-à-vis Consumers, the update and defect provisions of §§ 327 ff. BGB remain unaffected; to that extent, the Service is provided in such a way that it meets the objective requirements for a service of this type.

(2) The Provider is entitled to carry out plannable maintenance work during low-usage periods (in particular during night-time hours, Central European Time) and to temporarily restrict or interrupt the Service for that purpose. Planned maintenance windows shall be announced to the Customer with appropriate advance notice, as a rule at least 72 hours in advance; for urgent security-related maintenance, this period may be shortened.

(3) Impairments of availability resulting from force majeure, interventions by third parties, disruptions of upstream or downstream telecommunications services, disruptions of subcontractors or sub-processors outside the Provider's sphere of responsibility, as well as resulting from announced maintenance, do not constitute a defect of the Service.

(4) The Provider is entitled to engage suitable subcontractors for the provision of the Service. The current list of sub-processors used is set out in Annex 3.

Section 8 — Liability for Defects; Duty to Update (digital service)

(1) The Provider warrants that, during the period of provision, the Service complies with the service description (Annex 1) and otherwise with the objective requirements for a service of this type, unless mandatory legal provisions of the Customer's state of residence provide for a stricter standard.

(2) The Provider shall, during the contractual term, provide the updates necessary to maintain conformity of the Service, in particular security-related updates. The Customer shall be informed of updates in an appropriate manner (e.g. by in-app notice, email or status message), insofar as this is necessary for use.

(3) Defects shall be notified to the Provider in text form without undue delay. In the event of defects, the Customer's statutory rights shall apply. For Consumers in the Federal Republic of Germany, Part B Section 24 applies in addition.

(4) The OCR, the AI-assisted classification and semantic tagging, and the dialogue-based search assistant "Pal" are statistical methods whose results depend on the input material, language, image quality, model quality and further factors. The contractually agreed characteristic is the provision of these functions with suggested results, not the achievement of a particular recognition, classification or response quality. Classification suggestions and responses from "Pal" are supportive indications and do not replace a substantive review by the Customer. Vis-à-vis Consumers, the statutory rights in respect of defects (§§ 327 ff. BGB) remain unaffected; they relate to the characteristics as thus defined.

Section 9 — Liability (general baseline, subject to national tightening)

(1) The Provider is liable without limitation for intent and gross negligence as well as in accordance with product liability law.

(2) In the event of slightly negligent breach of material contractual duties (duties the performance of which is essential for the proper performance of the contract in the first place and the observance of which the Customer regularly relies on and is entitled to rely on — so-called cardinal duties), the Provider's liability is limited to the damage that is typical for the contract and foreseeable.

(3) Any further liability of the Provider for slight negligence is excluded.

(4) The above limitations of liability do not apply to damages arising from injury to life, body or health, do not apply to liability under the Product Liability Act and do not apply to damages based on fraudulent deception or on the assumption of a guarantee by the Provider.

(5) Vis-à-vis Traders, the following additionally applies: Liability for lost profits, missed savings and indirect consequential damages is excluded in the case of slight negligence. To the extent permitted, the Provider's liability vis-à-vis Traders for all claims resulting from a single instance of damage is limited in amount to the sum that the Customer has paid to the Provider during the twelve months preceding the event giving rise to the damage, but no less than EUR 1,000; for all instances of damage within one contract year, liability is limited in aggregate to 200 % of that amount. In the case of data loss, liability is additionally limited to the expense that would have been required to restore the data if the Customer had additionally carried out an at least weekly full backup and daily incremental backups of the content provided by the Customer; this applies irrespective of whether the Provider maintains its own backup copies as part of its backup routines.

(6) The Customer is obliged to regularly make its own backup copies of its content, insofar as recovery is possible with reasonable effort. The Provider draws attention to the export and backup options described in the service description.

(7) Contributory fault of the Customer, in particular a breach of the obligations under Section 4(2) and Section 9(6), shall be taken into account so as to reduce claims in accordance with § 254 BGB.

Section 10 — Data Protection; Processing on Behalf

(1) The Provider processes the Customer's personal data exclusively within the framework of the applicable data protection provisions, in particular Regulation (EU) 2016/679 (GDPR) and the applicable national provisions. Details on the processing of the personal data of the Customer itself (master, contract, billing and support data) are set out in the privacy policy, available at https://paless.eu/privacy.

(2) Insofar as the Provider, in the course of providing the Service, processes personal data for which the Customer is responsible within the meaning of Article 4(7) GDPR (in particular personal data contained in the documents or metadata uploaded by the Customer), the Provider acts as processor within the meaning of Article 4(8) GDPR. In that respect, the Data Processing Agreement (DPA) pursuant to Annex 2 applies. In the event of conflict between these GTC and the DPA, the DPA prevails.

(3) The Provider undertakes not to use personal Customer Content for the training of its own or third-party AI models and not to disclose it to external providers for the purpose of content analysis, unless otherwise required by a mandatory legal obligation or determined by the Customer's express, separate consent.

(4) The Service is provided within the European Union. The list of sub-processors used is set out in Annex 3. The Customer shall be informed of changes of sub-processors in text form with appropriate advance notice; the Customer has a right of objection in that respect in accordance with the DPA.

Section 11 — Data Export; Switching Providers (Data Act)

(1) The Customer may at any time during the contractual term, and for a reasonable period after the end of the contract, request an export of its content stored in the Service in a structured, commonly used and machine-readable format. The Provider shall provide appropriate technical means for this purpose, as a rule by way of download of a data archive comprising the original documents, structured metadata and a technical manifest. Details of the format are set out in the service description (Annex 1).

(2) Upon termination of the contract, the Provider shall support the Customer in switching to another provider or to the Customer's own infrastructure in accordance with Regulation (EU) 2023/2854 (Data Act). The transition period for such a switch is up to 30 days from the effective date of termination. At the Customer's request, this period may be extended by up to six months; a reasonable expense-based fee in accordance with the price list (Annex 5 no. 8) is payable for the extension, to the extent that Articles 25 and 29 of Regulation (EU) 2023/2854 permit this.

(3) The Provider does not charge any separate fees for the export of the Customer's content or for the switching process as such during the transition period pursuant to paragraph (2) sentence 2 (30 days). An extension of the period pursuant to paragraph (2) sentence 3 is subject to remuneration in accordance with these GTC and the price list. From 12 January 2027, Article 29 of Regulation (EU) 2023/2854 applies to the switching process.

(4) After expiry of the transition period or — where no switch is desired — after expiry of the retention period referred to in paragraph (5), the Customer's content shall be definitively deleted from the production system and shall no longer be available for restoration. The Provider shall advise the Customer of the upcoming deletion in text form when the termination takes effect and again a reasonable time before the definitive deletion. No claims to restoration exist in respect of content deleted in accordance with this Section 11; claims based on intent or gross negligence as well as Section 9(4) remain unaffected.

(5) After the termination takes effect, the Customer's content shall remain retrievable for the duration of the transition period under paragraph (2), but for at least 30 days, for the purpose of data portability. Thereafter, it shall be deleted from the production system; it shall be removed from regular backup copies in accordance with the respective rotation cycles documented in Annex 3. Section 14 (statutory retention obligations) remains unaffected.

Section 12 — Artificial Intelligence; Transparency

(1) The Service contains AI systems within the meaning of Article 3(1) of Regulation (EU) 2024/1689 (AI Act), in particular • a) the dialogue-based search assistant "Pal" (retrieval-augmented generation on the basis of self-hosted language models) and • b) the AI-assisted classification and semantic tagging of documents.

(2) The Provider shall, before the Customer's first interaction with the dialogue-based search assistant "Pal", indicate in the user interface that an AI system is involved (Article 50(1) AI Act).

(3) Content generated automatically by an AI system (in particular responses from "Pal", tagging and classification suggestions) shall, to the extent technically possible, be marked as AI-generated by technical or visual means (Article 50(2) AI Act).

(4) The Provider uses AI models that it operates itself on its own infrastructure within the European Union. Transmission of the Customer's content to external AI providers for inference or training does not take place in the standard configuration of the Service. Should the Customer optionally enable functions that integrate external services, the Customer shall be separately notified of this prior to activation.

(5) The Customer acknowledges that AI-assisted responses may be erroneous, incomplete or fabricated ("hallucinated"). Responses of the search assistant "Pal" and classification suggestions are to be understood as supportive aids and do not replace the Customer's own review; in particular, they do not constitute legal, tax or accounting advice.

(6) Insofar as the Service provides functions by which, on the basis of AI outputs, actions with effect vis-à-vis third parties can be prepared (in particular the drafting and sending of emails including attachments, the filling-in of forms, the applying of electronic signatures and the releasing of content via sharing functions), such actions are executed exclusively after express confirmation by the Customer. The Customer is obliged to review the content, attachments and recipients before release; responsibility for the release lies with the Customer. Electronic signatures in the Service are, unless expressly agreed otherwise, not qualified electronic signatures within the meaning of Regulation (EU) No 910/2014 (eIDAS); the Provider does not warrant that they satisfy formal requirements that presuppose a specific form of signature.

Section 13 — Content Responsibility; Notices of Illegal Content (DSA)

(1) The Provider is a hosting service provider within the meaning of Article 6 of Regulation (EU) 2022/2065 (Digital Services Act, DSA). Notices regarding allegedly illegal content may be submitted to the Provider electronically at dsa@paless.eu. The Provider shall examine notices received and shall take such measures as may be required in the circumstances.

(2) The Provider designates dsa@paless.eu as the single point of contact within the meaning of Articles 11 and 12 DSA. Working languages are German and English.

(3) Where the Provider restricts or removes the Customer's content, or restricts the Customer's account, the Customer shall receive a reasoned statement in text form setting out the material facts and the legal or contractual basis (Article 17 DSA). This does not apply to the extent that statutory obligations of confidentiality or orders by competent authorities preclude such a statement.

(4) The Provider, as a pure hosting service provider without any functionality of public dissemination, is not an online platform within the meaning of Article 3, point (i) DSA; the obligations under Chapter III Section 3 DSA (Articles 20 et seq.) are to that extent not applicable.

Section 14 — Retention; Statutory Retention Obligations

(1) The Provider is obliged to retain billing- and contract-relevant data in accordance with the statutory retention obligations (in particular under commercial and tax law). To that extent, no deletion or only restricted deletion takes place; the data shall no longer be used for other purposes.

(2) The Customer acknowledges that, from regular backup copies, individual data items will only be fully removed upon expiry of the respective rotation cycles. The Provider takes appropriate technical and organisational measures to ensure that data from backup copies is not used for purposes other than recovery in case of emergency.

Section 15 — Geo-blocking; Equal Treatment in the Internal Market

The Provider grants all Customers established in an EU Member State equal access to the website and to the order process. No discrimination on the grounds of nationality, place of residence or place of establishment takes place. Differences in the gross price display for Consumers are based exclusively on the respective national value added tax rates and do not constitute prohibited discrimination within the meaning of Regulation (EU) 2018/302 (Geo-blocking Regulation).

Section 16 — Force Majeure

No contracting party shall be liable for the non-performance or delayed performance of its obligations to the extent that this is due to events of force majeure which are beyond its reasonable sphere of influence and were neither foreseeable nor avoidable by reasonable means. These include in particular • a) natural disasters, war, terrorism, sabotage and comparable events; • b) measures by public authorities, in particular regulatory orders against the Provider or against a sub-processor; • c) strikes and industrial action, unless they exclusively concern the Provider's own operations; • d) general failures of the internet, electricity or telecommunications; • e) serious cyber attacks that cannot be averted notwithstanding compliance with the state of the art, including critical zero-day vulnerabilities in third-party software used; • f) pandemic situations and comparable health-related events that entail measures by public authorities or extensive staff absences; • g) supply chain failures at sub-processors, to the extent that equivalent substitute services cannot be procured within a reasonable period. The affected party shall inform the other party without undue delay and shall use its best efforts to mitigate the effects.

Section 17 — Rights in the Service; Customer Content

(1) All rights in the Service, in particular copyrights, trade marks and other intellectual property rights, vest in the Provider or its licensors. For the term of the contract, the Customer is granted the non-exclusive, non-transferable, non-sublicensable right, limited to the contractual use, to use the Service.

(2) The Provider does not acquire in the Customer Content any rights beyond the use required for the performance of the contract. The Customer grants the Provider the non-exclusive right, limited geographically to the EU, limited in time to the contractual term and to the retention and deletion operations required for the provision of the Service, to store, reproduce, index and technically transform the content (e.g. format conversion, OCR, generation of vector representations) and to make it accessible to the Customer within the framework of the functions of the Service.

(3) The Provider is entitled to process anonymised usage, telemetry and error data aggregated in non-personal form for the purposes of operation, security, troubleshooting, capacity planning and product improvement. Processing of Customer Content for the training of the Provider's own or third-party AI models does not take place pursuant to Section 10(3); that clause remains unaffected by sentence 1.

(4) In business dealings with Traders (§ 14 BGB), the Customer is prohibited from reverse engineering, decompiling or disassembling the Service, its components or the underlying software, from conducting comparative competitive analyses or from systematically extracting the Service or its content for competitive purposes, unless and to the extent that § 69d Abs. 1 and § 69e UrhG confer statutory rights to the contrary. Vis-à-vis Consumers, the statutory limitations remain unaffected.

Section 17a — Naming as Reference; Marketing

(1) The Provider is entitled to name the company name and the company logo of the Trader Customer in a customer reference list on its website, in press releases and in sales materials in order to factually document the business relationship. Substantive statements about the customer's use (in particular case studies, testimonials, quotations) require a separate written approval by the Customer.

(2) The Trader Customer may object to the naming at any time in text form. The Provider shall then remove the naming within 30 days.

(3) This clause does not apply vis-à-vis Consumers.

Section 18 — Confidentiality

The contracting parties shall treat all confidential information of the other party that becomes known to them in the context of the business relationship as confidential and shall use it solely for the purposes of performing the contract. This obligation shall continue for a period of three years after termination of the contract. It does not apply to information that is publicly known, that becomes publicly known without fault, that is lawfully acquired by the receiving party from third parties or that is to be disclosed by virtue of law or an order of a competent authority.

Section 19 — Amendments to the GTC

(1) The Provider reserves the right to amend these GTC and the Annexes where this is necessary due to • a) mandatory statutory, regulatory or supreme-court requirements, • b) technical or security-related requirements whose implementation does not reduce the core performance of the Service, or • c) the introduction of new or additional functions without reduction of the existing core performance. A reduction of the contractual core performance or a material deterioration of the Provider's principal obligations by way of unilateral amendment is excluded; such an amendment requires the Customer's consent or entitles the Customer to extraordinary termination with effect from the planned entry-into-force date. Changes to prices are governed exclusively by Section 5(9).

(2) Planned amendments shall be notified to the Customer in text form at least six weeks before entry into force. The notice shall contain the amended clauses, a summary of the reasoning as well as a reference to the Customer's right of objection, the objection period and the consequences of failing to object.

(3) If the Customer does not object in text form within the objection period of six weeks following receipt of the amendment notice, the amendments shall be deemed approved. The Customer shall be separately advised of this in the notice.

(4) If the Customer objects in due time, the contract shall continue on the previous terms. In that case, the Provider is entitled to ordinarily terminate the contract with effect from the planned entry-into-force date of the amendment.

(5) Amendments that have an exclusively beneficial effect or that merely implement an adaptation to mandatory law may become effective without observance of the aforementioned period.

Section 20 — Choice of Law; Jurisdiction

(1) All legal relationships arising out of or in connection with this contract shall be governed by the law of the Federal Republic of Germany to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG).

(2) Where the Customer is a Consumer, the choice of law under paragraph (1) shall apply only to the extent that the Consumer is not deprived of the protection afforded by the mandatory provisions of the law of his or her state of habitual residence (Article 6(2) of Regulation (EC) No 593/2008 [Rome I Regulation]).

(3) Where the Customer is a Trader, a legal person under public law or a special fund under public law, the exclusive place of jurisdiction for all disputes arising out of or in connection with the contract shall be Düsseldorf. The Provider is also entitled to bring proceedings against the Trader Customer at the latter's general place of jurisdiction.

(4) For Consumers, the statutory places of jurisdiction under Articles 17 et seq. of Regulation (EU) No 1215/2012 (Brussels Ia Regulation) and, respectively, under the applicable national provisions shall apply.

(5) Vis-à-vis Traders, contractual claims against the Provider become time-barred twelve months after the statutory commencement of the limitation period (§ 199 BGB). Excluded from this are claims • a) arising from intent or fraudulent deception on the part of the Provider, • b) for injury to life, body or health, • c) under the Product Liability Act, • d) under a guarantee assumed by the Provider, • e) as well as other claims to the extent that mandatory law provides for a longer limitation period (in particular Article 82 GDPR). Vis-à-vis Consumers, the statutory limitation periods apply unchanged.

Section 21 — Final Provisions

(1) Should individual provisions of these GTC be or become invalid or unenforceable, or become invalid or unenforceable after conclusion of the contract, the validity of the remaining GTC shall remain unaffected. The respective statutory provision shall replace the invalid or unenforceable provision. Vis-à-vis Consumers, no validity-preserving reduction (geltungserhaltende Reduktion) shall take place where this would lead to an unreasonable disadvantage.

(2) There are no oral side agreements. Amendments and additions to this contract require text form. This also applies to the waiver of this text form requirement.

(3) Set-off with claims that have been assigned to the Customer by third parties is permissible vis-à-vis the Provider only if the assigned claim is undisputed, has been established by a final court decision or is ready for adjudication. Section 5(8) remains unaffected.

(4) The Provider is entitled to transfer the rights and obligations under this contract, in whole or in part, to a legal successor, in particular by way of demerger, merger, an asset deal or a transfer to a company affiliated with the Provider within the meaning of §§ 15 ff. AktG. A planned transfer shall be notified to the Customer in text form with appropriate advance notice. The Customer is entitled to terminate the contract extraordinarily with effect from the planned transfer date if the transfer is not reasonably acceptable to the Customer.

(5) The Provider may ordinarily terminate the contractual relationship with a Customer who has not logged in to the Service for a continuous period of twelve months, with 30 days' notice in text form. During the notice period, the data export under Section 11 remains available to the Customer. Statutory retention obligations (Section 14) remain unaffected.

PART B — German-specific Provisions (DE Layer)

The following clauses apply, in addition to the EU baseline (Part A), to contracts governed by German law and, irrespective of the choice of law, to Consumers with habitual residence in the Federal Republic of Germany (Article 6 Rome I Regulation). In the event of conflict with Part A, Part B prevails.

Section 22 — Contractual Term; Termination vis-à-vis Consumers (§ 309 Nr. 9 BGB)

(1) If a contract with a Consumer is concluded with an initial term of more than one month, the initial term shall not exceed 24 months. Upon expiry of the initial term, the contract shall be extended for an indefinite period unless one party terminates no later than one month before expiry of the initial term.

(2) After the transition to the indefinite period, the Consumer may terminate the contract at any time with one month's notice to the end of a calendar month.

(3) Notice of termination may be given in text form (by email to kuendigung@paless.eu) or via the cancellation button within the meaning of § 312k BGB.

Section 23 — Cancellation Button (§ 312k BGB)

(1) For the termination of contracts concluded online concerning continuing obligations for consideration, the Provider makes an easily accessible cancellation button available to Consumers on the website. This button is directly reachable — without prior login — at the URL https://paless.eu/de/kuendigen and is unambiguously labelled "Verträge hier kündigen" (cancel contracts here).

(2) After activating the cancellation button, the Consumer is taken to a confirmation page on which the Consumer can provide the information required for the unambiguous identification of the contractual relationship, for the designation of the type of termination, for the indication of the notice period and for the communication of an electronic confirmation of receipt. The confirmation page contains a button labelled "Jetzt kündigen" (cancel now), the activation of which effectively submits the notice of termination.

(3) The Provider shall confirm to the Consumer the receipt of the notice of termination and its content without undue delay, by electronic means, in text form.

Section 24 — Rights in Respect of Defects; Duty to Update for Digital Products (§§ 327 ff. BGB)

(1) If the Customer is a Consumer and the Provider provides the Service to the Consumer against payment of a price, §§ 327 ff. BGB on contracts concerning digital products apply in addition. In particular, the Provider shall, pursuant to § 327f BGB, provide the Consumer throughout the entire provision period with the updates that are necessary for the Service to remain in conformity with the contractually agreed characteristics and the objective requirements; this includes in particular security-related updates.

(2) The Consumer shall be informed in an appropriate manner of the availability of an update and of the consequences of failing to install an update. If a defect becomes apparent within one year of provision, it shall be presumed that the defect already existed at the time of provision (§ 327k Abs. 1 BGB).

(3) If the Service is defective, the Consumer is entitled to the statutory rights in respect of defects (subsequent performance pursuant to § 327l BGB, termination of the contract pursuant to § 327m BGB, price reduction pursuant to § 327n BGB, damages pursuant to §§ 327i, 280 ff. BGB). These rights shall not be curtailed to the detriment of the Consumer.

Section 25 — Limitation of Liability vis-à-vis Consumers (§ 309 Nr. 7 BGB)

Section 9 (Liability) applies vis-à-vis Consumers with the proviso that no limitation of the Provider's liability applies to damages arising from injury to life, body or health; this also applies where the breach of duty is based on simple negligence. The maximum liability amount provided for in Section 9 does not apply vis-à-vis Consumers.

Section 26 — Right of Withdrawal for Consumers

(1) For contracts concluded online with the Provider, Consumers have a right of withdrawal in accordance with §§ 312g, 355 BGB. The details and the instructions required in each case are contained in the instructions on withdrawal pursuant to Annex 4, which form part of the contract.

(2) Where the Consumer expressly requests that the Provider begin performing the contractually owed digital service before expiry of the withdrawal period, and confirms his or her knowledge of the expiry of the right of withdrawal, the right of withdrawal expires upon complete performance of the service pursuant to § 356 Abs. 4 BGB. For the partial services provided up to the withdrawal, the Consumer owes compensation for value to the extent that such compensation is owed in accordance with § 357 BGB.

Section 27 — Prices; Price Indication Ordinance (PAngV)

Prices vis-à-vis Consumers are indicated as total prices including the statutory value added tax and all other price components (§ 3 PAngV). For contracts with automatic renewal, the Consumer is informed clearly and comprehensibly, in the order summary and in these GTC, of the amount of the follow-on costs after expiry of the initial term. The Provider expressly indicates in the order process the amount of the fee payable after expiry of the initial term.

Section 28 — Consumer Dispute Resolution (§ 36 VSBG)

(1) Notice concerning the European Commission's online dispute resolution platform: The online dispute resolution platform previously available at ec.europa.eu/consumers/odr was discontinued on 20 July 2025. A reference to this platform is therefore omitted.

(2) The Provider is neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board.

(3) The general consumer arbitration board competent pursuant to § 36 Absatz 1 Nummer 2 VSBG is the Universalschlichtungsstelle des Zentrums für Schlichtung e. V. (Universal Arbitration Board of the Zentrum für Schlichtung e. V.), Straßburger Straße 8, 77694 Kehl am Rhein (https://www.universalschlichtungsstelle.de). Consumers will be referred to this board in the event of a dispute.

Section 29 — Provider Identification; Reference to Legal Notice and Privacy Policy

(1) The provider information required under § 5 of the German Digital Services Act (Gesetz über digitale Dienste, DDG) and under § 18 of the German State Media Treaty (Medienstaatsvertrag, MStV) is set out in the legal notice (Impressum), available at https://paless.eu/de/impressum.

(2) The information on the processing of personal data and in particular on the use of cookies and comparable technologies pursuant to § 25 TDDDG is set out in the privacy policy, available at https://paless.eu/privacy.

Section 30 — Notice on Advertising with Functionalities and Standards

(1) The Provider advertises the Service inter alia as supporting the requirements of the German principles for the proper keeping and retention of books, records and documents in electronic form and for data access (GoBD, circular of the German Federal Ministry of Finance (BMF) of 28 November 2019). The Provider expressly points out that compliance with the GoBD in a specific bookkeeping or document filing arrangement is not ensured by the use of software alone, but additionally requires procedural documentation (Verfahrensdokumentation) to be prepared by the Customer, a suitable internal control system and further organisational measures. The Provider does not warrant GoBD conformity of the Customer's bookkeeping as a whole and assumes no guarantee in that respect.

(2) The Provider advertises the Service inter alia with hosting in data centres within the European Union and with the absence of hyperscaler providers established outside the EU. This statement applies to the production operation of the Service; the sub-processors used from time to time are set out in Annex 3.

(3) Insofar as the Provider advertises the multiply redundant storage of the Customer's content, this statement constitutes a description of the technical architecture used. It does not entail a guarantee within the meaning of § 443 BGB that the content cannot be lost or destroyed. The Customer is required to make its own regular backup copies within the scope of its capabilities (Section 9(6)).

(4) The Provider reserves the right to commit bindingly to individual functions, individual conformity commitments or individual audit results only after defined internal maturity criteria have been reached. Vis-à-vis Traders, statements in marketing, website or other sales materials do not constitute an agreement on characteristics prior to their express inclusion in the service description (Annex 1) or in a separate agreement. Vis-à-vis Consumers, the relevance of public statements of the Provider is governed by §§ 327e Abs. 3, 327h BGB; public statements that were corrected before conclusion of the contract in the same or an equivalent manner accordingly do not form part of the objective requirements.

Section 31 — Severability Clause (supplementary for Germany)

Should individual clauses of these GTC be invalid vis-à-vis Consumers due to a violation of mandatory provisions of German consumer protection law, they shall be replaced by the respective statutory provision. No validity-preserving reduction (geltungserhaltende Reduktion) shall take place in that respect. The validity of the remaining clauses remains unaffected.

Annex 1 — Service Description "paless"

The service description forms part of the Provider's GTC. It may be versioned independently of the GTC and updated in accordance with Section 19 of the GTC (Amendments). Specific quantity figures per tariff are set out in the price list (Annex 5). This service description describes the functions envisaged at the time these GTC enter into force. Functions not made available in production are not part of the performance owed. Statements in marketing or sales materials do not constitute an agreement on characteristics, in accordance with Section 30(4) of the GTC. Functions marked as "beta", "preview" or "in preparation" are subject to Section 3(4) of the GTC and are not part of the performance owed.

Annex 1 · 1. Description of the Service

The Service "paless" is a browser-based application for the management of digital documents. It is operated as Software-as-a-Service and provided via the public internet. The user interface is available in a large number of languages.

Annex 1 · 2. Scope of Functions

The scope of functions comprises — depending on the chosen tariff — the following functional areas:

2.1 Capture of documents: • Uploading of documents via the web interface; • ingestion of documents from an email mailbox of the Customer ("mail ingest"); • uploading via an optimised mobile web interface; • ingestion of scanned documents from a network share provided by the Customer. • Ingestion of documents from a cloud storage connected by the Customer, including automatic ingestion of newly incoming files and the mapping of folder names to tags (deployment status pursuant to no. 7); • splitting of scanned batches into individual documents using QR separator sheets (deployment status pursuant to no. 7).

2.2 Preparation of documents: • Optical character recognition (OCR) for the following input formats: PDF, PNG, JPEG, TIFF, GIF, WebP. Pure text formats are ingested without OCR. Further formats may be supported in an optional configuration. • Automated classification and suggestions for tags and correspondents on the basis of self-hosted models. These AI-assisted tagging functions are included in all tariffs. • Generation of a preview and a thumbnail. • The OCR extracts text; depending on the source document, tabular structures, chart values and formulas may additionally be recognised. The scope and quality of the structure recognition are not a warranted characteristic (cf. no. 6).

2.3 Research and search: • Full-text search across the OCR results; • semantic search on the basis of self-generated vector representations; • dialogue-based search assistant "Pal" on the basis of a self-hosted language model.

2.4 Organisation: • Assignment of tags, correspondents, document types and storage paths; • versioning of documents; • tenant and role management. • Time-limitable share links as well as granular sharing of individual documents or areas with further users (deployment status pursuant to no. 7).

2.5 Export and data portability (Article 25 of Regulation (EU) 2023/2854): Upon request, the Provider shall make available to the Customer, at any time during the contractual term and for the transition period after the end of the contract described in Section 11 of the GTC, a complete export of the data provided by the Customer and generated through the use of the Service, in a structured, commonly used and machine-readable format.

The export is delivered as a ZIP archive and as a rule contains: • all original documents in the file format originally uploaded; • the PDF/A archive files generated by OCR with embedded full text; • a file "manifest.json" containing the structured metadata (in particular correspondents, tags, document types, storage paths, custom fields, notes, workflows as well as the model objects for users and permissions) in JSON format in accordance with the Django serialisation convention; • a file "metadata.json" containing a version stamp of the software used at the time of the export.

The export is generated by the underlying open-source software paperless-ngx (cf. docs.paperless-ngx.com) and can be re-imported into the Customer's own or a third-party paperless-ngx instance using the associated import tool "document_importer". The exact schema of the manifest file is tied to the paperless-ngx major version used from time to time; in the event of conflict between the schema description and the export behaviour, the format actually generated by the tool at the time of the export prevails. The precise trigger mechanism for an export (e.g. via the user interface or an interface) is set out in the current online documentation of the Service. The Provider warrants that the export schema is compatible with the import tool "document_importer" of the paperless-ngx major version used in production at the time of the export. After a change to a new major version, the previous schema version remains import-compatible for a period of twelve months; thereafter, compatibility is tied to the current major version.

2.6 Identity and access management: • Login via a central identity provider based on OpenID Connect; • passwordless login methods using passkeys and hardware security keys (FIDO2) as well as optional multi-factor authentication; an authenticator app is also permitted.

2.7 Tariff-specific functions: The following functions may be assigned to individual tariffs and are then available only in those tariffs: • GoBD-oriented retention functions (versioning, audit logging, audit-proof storage) that support the Customer in complying with tax retention obligations and thereby support the GoBD requirements, without warranting GoBD conformity of the Customer's bookkeeping as a whole (see Section 30(1) of the GTC); • "Verfahrensdokumentation" (procedural documentation) function as a drafting aid for the user (initially available for the German legal situation only); • knowledge base with an integrated editor for creating own documentation alongside the managed documents; • priority support. Priority support comprises preferential handling with a targeted initial response time of, as a rule, eight working hours (Monday to Friday); it does not entail a guarantee within the meaning of § 443 BGB or a commitment to resolve problems within specific periods.

2.8 Assistance and editing functions (deployment status pursuant to no. 7): • Drafting of emails by the search assistant "Pal" including suggested attachments; sending takes place only after express confirmation by the Customer (Section 12(6) of the GTC); • filling-in of forms on the basis of existing documents with subsequent review and release by the Customer; • editing of PDF files (in particular rotating, splitting, merging, versioning); • applying of electronic signatures; these are not qualified electronic signatures within the meaning of Regulation (EU) No 910/2014 (eIDAS), unless expressly agreed otherwise. The respective maturity level of these functions (production, beta, in preparation) is set out in the online documentation.

Annex 1 · 3. Volume and Usage Limits

The Provider applies moderate usage limits within the meaning of Section 4(5) of the GTC. The values applicable per tariff are set out in the price list (Annex 5) and may concern in particular the following dimensions: All quantity figures are to be understood as "up to" maximum values.

  • maximum included storage space;
  • maximum number of pages processed with OCR per billing period;
  • maximum number of documents per billing period;
  • maximum query volume for the dialogue-based search assistant "Pal", measured in tokens;
  • maximum size of an individual file;
  • maximum number of user accounts.

For the number of documents per billing period, a migration amnesty applies during the first 30 days after activation of the tariff in accordance with Annex 5 no. 7.

Annex 1 · 4. Updates

During the provision period, the Provider shall provide the updates necessary for conformity of the Service, in particular security-related updates. Information about updates is provided in an appropriate manner. Functional enhancements are not part of the contractually owed duty to update.

Annex 1 · 5. Operating Environment and Data Residency

The Service is operated in data centres within the European Union. A list of the sub-processors used can be found in Annex 3. Availability quotas are not warranted in the standard tariff structure; Section 7 of the GTC remains unaffected. Planned maintenance windows are predominantly scheduled during night-time hours and announced with the advance notice described in Section 7(2) of the GTC.

Annex 1 · 6. Characteristics Not Warranted

The following characteristics of the Service depend on the purpose of use, on the input quality and on the configured tariff and are not part of the contractually owed characteristics within the meaning of Section 3(5) and Section 8(4) of the GTC:

  • a specific recognition accuracy of the OCR or a specific scope of the structure recognition (tables, chart values, formulas);
  • a specific hit rate and accuracy of the AI-assisted classification and tagging;
  • a specific substantive accuracy of the responses of the search assistant "Pal" (responses may be erroneous, incomplete or fabricated);
  • deliverability of externally received emails (mail ingest depends on the external mail system);
  • processing of files protected by password or other cryptographic means without provision of the key material, as well as the other constellations set out in Section 3(5) of the GTC.

Annex 1 · 7. Deployment Status

The Service is transferred into production operation in stages. The Provider is entitled to make individual functions available in production only after defined internal maturity criteria have been reached. The functions available at any given time are set out in this service description in conjunction with the online documentation. Functions marked in this service description or in the online documentation as "beta", "preview" or "in preparation" are subject to Section 3(4) of the GTC.

Annex 2 — Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

This agreement forms part of the Provider's GTC and applies in addition where the Customer is a controller within the meaning of Article 4(7) GDPR with respect to the personal data processed via the Service. In the event of conflict with the GTC, this DPA prevails.

Annex 2 · Contracting Parties

Entalys GmbH

Carmenstr. 18, 40668 Meerbusch, Germany

Registered in the commercial register of the Local Court of Neuss under HRB 25084

VAT ID: DE460863235

Represented by the managing director Christoph Kleinhans

Data protection contact: datenschutz@paless.eu

Controller (hereinafter "Customer"): the natural or legal person named as the contracting party in the online order process.

Processor (hereinafter "Provider"): Entalys GmbH (address and contact details see above).

Annex 2 · Section 1 — Subject Matter and Duration

(1) The subject matter of this agreement is the processing of personal data in the course of providing the Service "paless" on the basis of the main contract concluded between the parties (the Provider's GTC including the service description).

(2) The duration of this agreement corresponds to the term of the main contract. Obligations which by their nature continue to have effect beyond the end of the contract (in particular confidentiality, return/deletion of data, obligations to furnish evidence) shall survive the end of the contract.

Annex 2 · Section 2 — Nature and Purpose of the Processing, Categories of Data, Categories of Data Subjects

(1) Nature and purpose of the processing: provision of a software-based document management service including capture (upload, mail intake, mobile upload), storage, indexing, automated text recognition (OCR), AI-assisted classification and semantic tagging, full-text and semantic search, dialogue-based search ("Pal"), export, as well as authentication and access control.

(2) Nature of the personal data: all categories of data contained in the content introduced into the Service by the Customer. These include in particular: • Identification and contact data (names, addresses, telephone numbers, email addresses); • contract, billing and correspondence data; • financial data (e.g. bank/account details in invoices); • where contained in the Customer's content, also special categories of personal data within the meaning of Article 9 GDPR (e.g. health data in medical invoices, religious affiliations in certificates, data on ethnic origin in personnel records) as well as data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Customer is obliged to verify, before uploading special categories of personal data, whether it is entitled to do so.

(3) Categories of data subjects: • Employees and former employees of the Customer; • customers and business partners of the Customer; • family members and other related persons of the Customer (in the case of private use); • other third parties appearing in the Customer's content.

Annex 2 · Section 3 — Obligations of the Provider

(1) The Provider processes personal data exclusively on documented instructions from the Customer. Processing beyond the performance of the contract takes place only where the Provider is required to do so by Union or Member State law; in such a case, the Provider shall inform the Customer of those legal requirements before processing, unless the law in question prohibits such information.

(2) Instructions include in particular the configurations made by the Customer in the Service, the functions used by the Customer, and supplementary individual instructions in text form. The Provider shall inform the Customer without undue delay if it is of the opinion that an instruction infringes applicable data protection law.

(3) The Provider ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of secrecy.

(4) The Provider shall implement the technical and organisational measures within the meaning of Article 32 GDPR specified in Appendix A to this DPA. The measures shall evolve in line with the state of the art; a deterioration of the level of protection is not permitted.

(5) Taking into account the nature of the processing and the information available to it, the Provider shall assist the Customer in complying with the Customer's obligations under Articles 32 to 36 GDPR (in particular data security, notification of personal data breaches, data protection impact assessment, prior consultation).

(6) The Provider shall assist the Customer by appropriate technical and organisational measures in fulfilling the rights of data subjects (Articles 12–22 GDPR), insofar as this is reasonable for the Provider and the Customer cannot itself exercise the required functions in the Service.

(7) The Provider shall notify the Customer without undue delay, as a rule within 48 hours of becoming aware of it, of a personal data breach within the meaning of Article 4(12) GDPR that has occurred within the Provider's sphere of responsibility. The notification shall contain the information required under Article 33(3) GDPR, to the extent known to the Provider, and shall be supplemented on an ongoing basis.

(8) Upon request, the Provider shall make available to the Customer in text form the information necessary to demonstrate compliance with this DPA. For this purpose, the Provider may refer, with priority, to current audit reports of recognised auditors, comparable certificates or meaningful self-assessments. An on-site inspection by the Customer or by an auditor commissioned by the Customer, bound by professional secrecy and not a competitor of the Provider, is permitted at most once per contract year, after prior scheduling with a notice period of at least 30 days, during normal business hours; in the event of concrete indications of a personal data breach, also more frequently and at shorter notice. The inspection shall be limited to the scope necessary in each case and shall be conducted in such a way that ongoing operations are impaired as little as possible; the Provider's business and trade secrets as well as data of other customers shall be protected. The costs of an on-site inspection shall be borne by the Customer, unless the inspection reveals a material breach of this DPA by the Provider.

(9) The Provider shall provide assistance under paragraphs (5), (6) and (8) against reasonable expense-based remuneration, unless the assistance results from a breach of duty by the Provider. The Provider may make instructions that go beyond the contractually agreed scope of services conditional upon the agreement of a reasonable fee, unless they are necessary for compliance with mandatory data protection law. If a data subject contacts the Provider directly, the Provider shall forward the request to the Customer without undue delay and shall not respond to it without an instruction from the Customer.

Annex 2 · Section 4 — Sub-processors

(1) The Customer hereby grants the Provider general written authorisation to engage further processors (sub-processors) within the meaning of Article 28(2) sentence 2 GDPR. The current list of the sub-processors used is set out in Annex 3 of the GTC ("List of Sub-processors").

(2) If the Provider intends to engage a new sub-processor or to replace an existing sub-processor, it shall inform the Customer thereof in good time, but at least four weeks before the planned change, in text form.

(3) The Customer may object to the intended change in text form within two weeks of receipt of the notification, for an important data protection reason. If the objection is justified and the parties cannot agree on an amicable solution within a reasonable period, each party has an extraordinary right of termination with respect to the services affected by the change.

(4) The Provider shall contractually bind its sub-processors to data protection obligations essentially equivalent to those of this DPA; in particular, it shall ensure that the sub-processors also implement appropriate technical and organisational measures.

Annex 2 · Section 5 — Data Transfers to Third Countries

(1) As a matter of principle, no transfer of personal data to countries outside the European Economic Area (third countries) or to international organisations takes place in the course of providing the Service.

(2) Should a transfer to a third country become necessary in an individual case, it shall take place exclusively on a legal basis under Chapter V GDPR (in particular an adequacy decision or standard contractual clauses pursuant to Article 46(2)(c) GDPR with supplementary measures where required) and after prior information of the Customer in text form.

Annex 2 · Section 6 — Cooperation Obligations of the Customer

(1) In relation to the data subjects, the Customer is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects (Article 24 GDPR).

(2) The Customer shall ensure that it issues instructions in text form and that the persons authorised to issue instructions are named to the Provider.

(3) The Customer warrants that it will not upload special categories of personal data to the Service without a sufficient legal basis.

Annex 2 · Section 7 — Termination; Return and Deletion

(1) After the end of the main contract, the Customer's content shall, at the Customer's choice, be returned or deleted. Details regarding the period, the format of the return and the handling of backup copies are set out in Section 11 of the GTC and in Annex 3.

(2) Where statutory retention obligations exist, the data concerned shall remain with the Provider until expiry of the respective retention period; such data shall be stored separately and blocked against further use, and shall subsequently be deleted.

Annex 2 · Section 8 — Liability; Contractual Penalties

For claims of the parties against each other, including recourse between controller and processor pursuant to Article 82(5) GDPR, the liability provisions of the GTC (Sections 9 and 25) apply mutatis mutandis, to the extent legally permissible. Liability vis-à-vis data subjects pursuant to Article 82 GDPR remains unaffected. No contractual penalties are agreed under this DPA.

Annex 2 · Section 9 — Applicable Law; Jurisdiction

The law of the Federal Republic of Germany applies. The exclusive place of jurisdiction for disputes arising out of or in connection with this DPA is Düsseldorf, provided that the Customer is a Trader. In relation to Consumers, the statutory places of jurisdiction apply.

Annex 2 · Section 10 — Final Provisions

Should individual provisions of this DPA be invalid, the validity of the remainder of the DPA shall remain unaffected. Amendments and additions require text form. In the event of conflicts between the main contract and this DPA, the provisions of this DPA prevail insofar as data protection matters are concerned.

Annex 2 · Appendix A — Technical and Organisational Measures (Article 32 GDPR)

The following measures describe the intended target state at the time of the envisaged productive launch of the Service. The Provider is entitled to further develop the measures in order to adapt them to the state of the art, provided that this does not reduce the level of protection. The Provider shall, on its own initiative, inform the Customer in text form of deviations from the target state that affect the level of protection more than insignificantly.

Annex 2 · Appendix A · A. Confidentiality (Article 32(1)(b) GDPR)

Measures to ensure confidentiality:

  • Physical access control (data centre): Processing takes place in data centres within the European Union with independent physical access controls (mantrap entry, multi-factor authentication, video surveillance, visitor registration) at the level of the respective infrastructure sub-processor (see Annex 3).
  • System access control (logical): Multi-level authentication via a central identity provider based on OpenID Connect; mandatory multi-factor authentication for administrative accounts (hardware security keys and authenticator apps equally permitted).
  • Data access control: Role- and permission-based access management; tenant separation at application and database level; permissions are granted according to the principle of least privilege and reviewed regularly.
  • Pseudonymisation and separation control: Data of different customers are processed separately on a per-tenant basis. Identifiers are pseudonymised or logged in truncated form, where operationally possible.
  • Encryption in transit: TLS 1.3 or higher for all communication between end device and Service as well as for internal communication between production components, where technically possible.
  • Encryption at rest: Encryption of the underlying storage media in accordance with the state of the art (e.g. AES-256), combined with separately managed key material.

Annex 2 · Appendix A · B. Integrity (Article 32(1)(b) GDPR)

Measures to ensure integrity:

  • Input control: Logging of administrative and security-relevant events with timestamp (UTC) and user reference; audit-proof retention of the logs in accordance with the configuration of the Service.
  • Transfer control: Transfers outside the data centre take place exclusively in encrypted form; contractually secured commitment of the sub-processors used to corresponding obligations.

Annex 2 · Appendix A · C. Availability and Resilience (Article 32(1)(b) and (c) GDPR)

Measures to ensure availability and resilience:

  • Redundancy: Multiply redundant storage of the original documents within several data centres of the infrastructure sub-processor.
  • Backup copies: Regular data backups with documented rotation and retention cycles; backup copies are stored in encrypted form and at a separate storage location.
  • Contingency planning: Documented recovery plans for the essential components; regular exercising of the recovery procedures.

Annex 2 · Appendix A · D. Procedures for Regular Review, Assessment and Evaluation (Article 32(1)(d) GDPR)

Measures for regular review and assessment:

  • Security updates and patch management: Security-relevant updates are treated with priority in accordance with a documented patch policy.
  • External audits: An external penetration test has been commissioned and is envisaged before the productive launch of the Service; regular repetition at a minimum frequency of once per year is targeted.
  • Internal controls: Semi-annual internal review of the technical and organisational measures (TOM review); data protection impact assessment for particularly high-risk processing situations.

Annex 2 · Appendix A · E. Control of Commissioned Processing (Art. 28 GDPR)

Written contracts with all sub-processors; confidentiality undertakings by all persons involved in the processing; training of staff on data protection and information security.

Annex 3 — List of Sub-processors

This list is maintained in versioned form; changes are notified to Customers in text form with appropriate advance notice (see Section 4(2) of the DPA). This list describes the planned production operation. As long as the Service is not yet offered in production, the entries are to be understood as the target state. The applicable state will be fixed as binding before the start of production operation.

Annex 3 · Overview

Sub-processors used (provider — registered office/location — purpose of processing — categories of personal data — contractual basis):

  • OVHcloud SAS, sovereign cloud offering (France, EU) — hosting, compute, object storage, backup copies — all content and metadata stored in the Service — DPA of the provider, dedicated agreement in preparation.
  • Bunny.net (Slovenia, EU) — delivery of the marketing website, ACME DNS for TLS certificate issuance — domain and host metadata, where applicable IP addresses of website visitors — DPA of the provider.
  • Transactional email dispatch: not yet finally determined — the default is self-operation, optionally an EU service provider (EU) — transactional email dispatch (account confirmation, password reset, notifications) — email address, content of the respective notification — if an external EU service provider is used, a DPA will be concluded before commencement of operation and this list will be updated.
  • Sender (UAB Sender.lt), Lvivo g. 25, 09320 Vilnius (Lithuania, EU) — dispatch of the email newsletter of the marketing website, provision of the newsletter sign-up form — email address of the subscribers, time and IP address of the consent — DPA of the provider.

Identity management (Authentik): The identity management system (Authentik) is operated by the Provider on its own infrastructure within the European Union and does not constitute a separate sub-processor. Hugging Face Inc. / Hugging Face S.A.S. is contacted exclusively at build or setup time for the one-off download of the AI model artefact. No personal data of the Customer is transferred. Hugging Face is therefore not a sub-processor within the meaning of Art. 28 GDPR with respect to the production operation of the Service.

Annex 3 · Additional Notes on Processing

Data residency: All processing of personal data takes place within the European Union. No transfer to third countries takes place in the production operation of the Service.

Retention of backup copies: Incremental backup copies are retained for a period of 30 days, full backups for 90 days. The definitive removal of deleted content from all generations of backup copies takes place upon expiry of the applicable rotation cycle.

Model provision of the AI components: The inference of all AI components (language model for the search assistant "Pal", embedding model for the semantic search, classification models for tagging) takes place within the Provider's EU infrastructure; no transfer of Customer Content to external inference endpoints takes place in the standard configuration of the Service.

Annex 4 — Instructions on Withdrawal and Model Withdrawal Form

The following texts follow the statutory model pursuant to Anlage 1 zu Art. 246a § 1 Abs. 2 Satz 2 EGBGB as well as the model withdrawal form in Anlage 2 zu Art. 246a § 1 Abs. 2 Satz 1 Nr. 1 EGBGB, in each case in the version applicable from time to time.

Annex 4 · 1. Instructions on Withdrawal — Right of Withdrawal

You have the right to withdraw from this contract within 14 days without giving any reason.

The withdrawal period will expire after 14 days from the day of the conclusion of the contract.

To exercise the right of withdrawal, you must inform us of your decision to withdraw from this contract by an unequivocal statement (e.g. a letter sent by post or an email). You may use the attached model withdrawal form, but it is not obligatory. To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.

Annex 4 · Withdrawal to be addressed to

Entalys GmbH

Carmenstr. 18

40668 Meerbusch

Germany

Phone: +49 176 63057818

Email: widerruf@paless.eu

Annex 4 · Effects of Withdrawal

If you withdraw from this contract, we shall reimburse to you all payments received from you, including the costs of delivery (with the exception of the supplementary costs resulting from your choice of a type of delivery other than the least expensive type of standard delivery offered by us), without undue delay and in any event not later than 14 days from the day on which we are informed about your decision to withdraw from this contract. We will carry out such reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.

If you requested to begin the performance of services during the withdrawal period, you shall pay us an amount which is in proportion to what has been provided until you have communicated us your withdrawal from this contract, in comparison with the full coverage of the contract.

Annex 4 · Expiry of the Right of Withdrawal

In the case of a contract for the provision of a digital service — which includes the Service "paless" —, the right of withdrawal expires if

  • a) we have begun performing the service with your express consent before expiry of the withdrawal period, and
  • b) you have at the same time confirmed your knowledge that the right of withdrawal expires upon commencement of the performance of the contract, and
  • c) we have performed the service in full (§ 356 Abs. 4 BGB).

You give the aforementioned declarations in the order process by actively ticking the checkbox provided for this purpose, which is not pre-ticked. By ticking the checkbox, you expressly request that we begin providing the Service before expiry of the withdrawal period, you confirm your knowledge that your right of withdrawal expires upon complete performance of the service, and you are aware that, in the event of a withdrawal before complete performance, you owe proportionate compensation for the value of the performance provided up to the withdrawal. You will additionally receive a corresponding confirmation on a durable medium (email). In the case of a contract for the continuous provision of the Service, the right of withdrawal does not, as a rule, expire before the end of the withdrawal period; in the event of withdrawal, the compensation for value is calculated pro rata temporis on the basis of the agreed total price, in the case of annual billing on the basis of the annual price.

Annex 4 · 2. Model Withdrawal Form

Complete and return this form only if you wish to withdraw from the contract.

To: Entalys GmbH, Carmenstr. 18, 40668 Meerbusch, Germany, email: widerruf@paless.eu

I/We (*) hereby give notice that I/We (*) withdraw from my/our (*) contract of sale of the following goods (*) / for the provision of the following service (*): ________________________________________

Ordered on (*) / received on (*): ________________________________________

Name of consumer(s): ________________________________________

Address of consumer(s): ________________________________________

Signature of consumer(s) (only if this form is notified on paper): ________________________________________

Date: ________________________________________

(*) Delete as appropriate.

Annex 5 — Price List

The price list forms part of the Provider's GTC. It is versioned separately so that changes remain possible without amending the entire GTC. Prices of existing contracts are changed exclusively in accordance with Section 5(9) of the GTC (price adjustment); editorial and structural changes to this Annex are governed by Section 19 of the GTC (Amendments). Note: The specific amounts per tariff and the volume limits applicable per tariff are set out in the current tariff overview on the Provider's website at https://paless.eu or the country variant provided there. The values displayed in the respective order process prevail over any deviations in this Annex.

Annex 5 · 1. Tariff Overview and Volume Limits

The applicable tariff overview — including the gross price for Consumers (with the value added tax of the respective EU state of habitual residence), the net price for Traders, the billing period (monthly or annual), the included storage volume, the monthly ingestion quota (number of documents), the number of user accounts, OCR pages per month, the token quota for the dialogue-based search assistant "Pal" and the maximum size of an individual file — can be viewed at any time on the Provider's website at https://paless.eu.

Price changes for existing contracts are governed by Section 5(9) of the GTC (price adjustment).

Annex 5 · 2. Additional Storage

If the storage volume included in the tariff is exceeded, additional storage is invoiced per gigabyte commenced. The calculation is carried out on an ongoing basis; the gigabytes exceeded are invoiced with the next following invoice. The applicable price per gigabyte commenced forms part of the tariff overview referred to in no. 1.

Annex 5 · 3. Follow-on Prices after the Initial Term

For contracts with an initial annual term, the price of the chosen tariff in the chosen billing period agreed at the conclusion of the contract continues to apply unchanged after expiry of the initial term. The price payable after expiry of the initial term is expressly indicated to the Customer in the order process. Subsequent changes are governed exclusively by Section 5(9) of the GTC (price adjustment).

Annex 5 · 4. Value Added Tax

The following applies to value added tax:

  • Consumers pay gross prices including the statutory value added tax of the EU Member State of their habitual residence.
  • Traders pay net prices plus the applicable statutory value added tax. Where a valid VAT identification number of another EU Member State is provided, the invoice is issued under the reverse-charge procedure.

Annex 5 · 5. Means of Payment

Accepted means of payment in the order process are credit card, SEPA direct debit, PayPal, wero and purchase on invoice (Traders only).

Annex 5 · 6. AI-assisted Tagging

AI-assisted tagging and semantic tagging are included in all tariffs and are not offered as a paid add-on module.

Annex 5 · 7. Special Rules — Migration Amnesty

During the first 30 days after activation of the tariff, the documents uploaded in the course of the initial migration do not count against the monthly ingestion quota (number of documents per month). The storage volume included in the tariff remains unaffected by this; any excess is invoiced as described in Section 5(6) of the GTC. For operational reasons, the number of documents that can be processed under the migration amnesty is limited to up to 5,000 documents; volumes beyond this may be agreed separately upon request.

Annex 5 · 8. Extended Transition Period (Data Act)

For the extension of the transition period under Section 11(2) of the GTC beyond the free 30 days, an expense-based fee applies which covers the continued provision of storage, backup copies and access infrastructure. It corresponds to the monthly fee of the tariff most recently booked, pro rata for each month of the extension commenced, unless Regulation (EU) 2023/2854 prescribes a lower ceiling. The export of the content itself remains free of charge during the extension as well.

Annex 5 · 9. Founder Terms from Supporter Campaigns

Founder terms promised in the course of supporter campaigns (e.g. Kickstarter) are granted as a permanent percentage discount on the applicable list price of the chosen tariff and continue to apply for as long as the respective subscription continues without interruption. The amount of the discount results from the respective campaign description and the redemption confirmation. A price adjustment under Section 5(9) of the GTC affects only the list price; the promised percentage discount remains unaffected.

The German version is authoritative.