Terms & Conditions
This page will contain the general terms and conditions of SecurBit.
of Oday Almustafa, trading under the business name “SecurBit”
Proprietor: Oday Almustafa
Address: Ringstraße 141, 04209 Leipzig, Germany
Email: info@securbit.de
Telephone: +49 1590 6303827
– hereinafter referred to as “SecurBit” or the “Provider” –
§ 1 Scope of Application
(1) These General Terms and Conditions apply to all contracts, offers, services and other business relationships between SecurBit and its customers.
(2) SecurBit’s services are directed exclusively at entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law. Contracts are not concluded with consumers within the meaning of Section 13 BGB.
(3) These General Terms and Conditions apply in particular to services, project-related services and ongoing service, support and technical assistance packages.
(4) These General Terms and Conditions become part of the contract if SecurBit informs the customer of their applicability before or upon conclusion of the contract and gives the customer a reasonable opportunity to review their contents. This may take place in particular by transmission by email, reference in an offer or provision on the website.
(5) Any conflicting, deviating or supplementary general terms and conditions of the customer shall not apply unless SecurBit has expressly agreed to their application in text form.
(6) Individual agreements, in particular those contained in offers, order confirmations, service descriptions or Service Level Agreements (SLAs), shall take precedence over these General Terms and Conditions.
§ 2 Subject Matter of the Contract and Types of Services
(1) SecurBit provides IT services and IT support services, in particular in the following areas:
- a) Network and security architecture
- b) Firewall implementation, migration and troubleshooting
- c) Vendor solutions, in particular Cisco ASA, Cisco FTD/FMC, Fortinet, Sophos, Check Point, Palo Alto Networks, Aruba, Dell, Microsoft and comparable solutions
- d) VPN solutions (IPsec, SSL VPN, site-to-site, remote access)
- e) Routing and switching (including BGP, OSPF, EIGRP, VLAN, STP and Layer 2/Layer 3)
- f) Cisco ISE / NAC
- g) MFA, secure-access and zero-trust solutions
- h) Cisco Meraki, Cisco Umbrella, Cisco Duo, ZTNA and comparable technologies
- i) IDS/IPS, segmentation and security hardening
- j) LAN/WAN and WLAN infrastructure
- k) Infrastructure migration and modernisation
- l) High availability and resilient network designs
- m) Windows Server, Active Directory, DNS, DHCP and RADIUS
- n) Linux administration and troubleshooting
- o) Cloud and platform technologies, in particular Microsoft Azure and Microsoft 365
- p) Network documentation and diagrams
- q) Support, maintenance, analysis, monitoring and technical assistance as agreed
- r) AI security, governance and consulting services, in particular AI inventorying, risk and protection-needs analyses, access and identity concepts, data and DLP controls, assessment of AI applications, AI models and AI agents, implementation of technical guardrails, assessment of interfaces and AI supply chains, and documentation and evidence support
The service portfolio also includes comparable AI, network, security, cloud and infrastructure technologies.
(2) The above list is not exhaustive. The specific scope of services is determined by the relevant individual agreement.
(3) Unless expressly agreed otherwise in text form, SecurBit provides its services under a service contract (Dienstvertrag). A specific result under a contract for work (Werkvertrag) shall only be owed if expressly agreed in text form.
(4) SecurBit does not owe any specific economic, technical, regulatory or other outcome unless expressly agreed in the individual case. A specific project result, a specific technical effect, certification, successful completion of an audit or recognition by authorities, certification bodies or other third parties shall likewise only be owed if expressly agreed in text form.
(5) Technical results depend in particular on the agreed services, the existing IT and AI infrastructure, the customer’s cooperation and the applicable technical, organisational and regulatory framework conditions.
(6) SecurBit points out that IT and AI security cannot guarantee absolute protection against attacks, security incidents, data loss, incorrect or undesirable AI output or system failures. SecurBit owes only the professional performance of the agreed services, not the complete or permanent elimination of security and operational risks.
(7) Where services are provided with reference to regulatory requirements, standards or recognised frameworks, in particular the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, OWASP recommendations or NIS2 requirements, these serve as professional guidance for the agreed technical and organisational services.
(8) Unless expressly agreed in text form, SecurBit does not provide legal advice and does not owe the customer’s complete legal or regulatory compliance, the granting of certification, successful completion of an audit or recognition by authorities, certification bodies or other third parties.
(9) Information relating to response times, support hours, availability, time quotas or escalation levels shall apply only if expressly agreed in text form, in particular in a separate SLA.
§ 3 Offers and Conclusion of Contract
(1) Offers made by SecurBit are subject to change and non-binding unless expressly designated as binding.
(2) A contract is concluded in particular by:
- a) the customer’s acceptance of an offer
- b) SecurBit’s order confirmation
- c) commencement of the services with the customer’s consent
(3) Text form, in particular by email, is sufficient for the conclusion of contracts, order confirmations, amendments and declarations, unless a stricter form is required by law.
§ 4 Performance of Services
(1) SecurBit shall perform the agreed services professionally and in accordance with recognised technical standards.
(2) Unless otherwise agreed, the services shall be performed remotely.
(3) The specific scope of services is determined by the relevant offer, ticket, call-off, service order or SLA. Ongoing coordination with the customer serves to specify the scope of services already agreed. Any chargeable extension of the scope of services requires corresponding commissioning or approval by the customer in text form.
(4) SecurBit is entitled to interrupt or postpone performance where this is necessary for technical, organisational or security-related reasons and is reasonable for the customer.
(5) SecurBit is entitled to engage qualified subcontractors, freelancers or other vicarious agents for the performance of the services. SecurBit remains responsible to the customer for the proper performance of the contractually owed services.
(6) Where the use of subcontractors or other vicarious agents is relevant under data-protection law, such use shall be governed by the applicable legal requirements and, where applicable, a concluded data processing agreement.
§ 5 Project Services and Changes
(1) Project services include in particular consulting, migration, implementation, optimisation and documentation services.
(2) Formal acceptance and a specific result under a contract for work (Werkvertrag) shall only be owed if expressly agreed in text form.
(3) If the customer requests changes or extensions to the agreed scope of services after conclusion of the contract, these shall be treated as a change request. SecurBit shall inform the customer of the resulting additional effort. Implementation shall take place only after agreement on the additional remuneration and any changes to deadlines.
(4) SecurBit is entitled to interrupt work already commenced until a decision has been made on the change request where continuation without prior clarification would not be technically, organisationally or economically reasonable.
(5) Changes or extensions to the scope of services may result in adjustments to scheduling, remuneration and technical framework conditions.
§ 6 Service and Support Services
(1) Ongoing services are provided on the basis of individual agreements or SLAs.
(2) If a monthly time quota has been agreed, it applies exclusively to the respective billing period. Unused hours expire at the end of that period and are neither refundable nor transferable to subsequent periods unless expressly agreed otherwise or unless SecurBit is responsible for the customer’s inability to use them.
(3) Services outside the agreed scope shall be remunerated separately on a time-and-material basis if commissioned by the customer or approved by the customer before performance.
(4) This applies in particular to emergency deployments, work outside agreed service hours, vendor cases, licensing matters or analyses of third-party systems.
(5) If the customer cannot be reached in time and measures are objectively necessary to avert an imminent and substantial loss, SecurBit may take the necessary measures to an appropriate extent, provided that, in the circumstances, SecurBit may reasonably assume that the measures are in the customer’s interests and correspond to the customer’s presumed wishes. The services shall be charged on a time-and-material basis. SecurBit shall inform the customer without undue delay.
§ 7 Customer Cooperation and Data Backup
(1) The customer shall provide SecurBit in due time with all information, documents, contact persons, approvals, credentials, remote-access facilities and other prerequisites required for performance of the services.
(2) The customer shall appoint at least one suitably qualified contact person who is able to make or arrange decisions promptly.
(3) The customer is responsible for properly backing up its data, systems and configurations unless data backup has expressly been agreed as a service to be provided by SecurBit.
(4) Before technical changes, migrations, updates or configuration changes begin, the customer is required to create a current and functional backup unless data backup has expressly been agreed as a service to be provided by SecurBit.
(5) Before commencing such work, SecurBit is entitled to verify the existence of a current and functional backup or suitable recovery option. SecurBit may postpone the work until corresponding confirmation or implementation has been provided.
(6) The customer shall report complaints, disruptions and error messages without undue delay in a comprehensible form and shall provide reasonable assistance to SecurBit in analysing and isolating them.
(7) Demonstrable additional effort resulting from missing, delayed or incomplete cooperation by the customer and not attributable to SecurBit may be charged on a time-and-material basis after prior notice to the customer. If prior notice is not possible due to particular urgency, SecurBit shall inform the customer without undue delay afterwards.
(8) In the case of services relating to AI systems, the customer shall provide SecurBit in due time and in full with all information required for the assessment and protection of such systems. This includes in particular the intended purpose, models and services used, types of data, interfaces, user groups, permissions and existing technical and organisational measures.
(9) Unless expressly agreed otherwise, the customer remains responsible for the lawful use of its AI systems, the professional review and approval of AI output, the required human oversight and the operational or business decisions derived from such output.
§ 8 Access to Customer Systems and Third-Party Systems
(1) SecurBit is entitled, to the extent necessary for performance, to access customer systems and third-party systems or services designated by the customer.
(2) The customer shall ensure that access to the customer systems and the provision of the required credentials and permissions are lawful.
(3) In particular, the customer shall ensure that all required consents, permissions, licences and other legal prerequisites for access to third-party systems, services or infrastructure are in place.
(4) SecurBit shall use such access exclusively within the scope of the contractually agreed services.
(5) The customer is required to transmit credentials securely and, where necessary, to change or deactivate them after completion of the services. SecurBit is not required to retain credentials provided by the customer on a permanent basis.
(6) Processing of personal data on behalf of the customer shall take place only on the basis of a separate data processing agreement pursuant to Article 28 GDPR.
§ 9 Remuneration and Billing Units
(1) Remuneration is determined by the relevant individual agreement.
(2) Unless otherwise agreed, billing shall take place:
- a) on a time-and-material basis
- b) as project-based remuneration
- c) as a flat fee or time quota
(3) Unless otherwise agreed, time-based services are billed in units of 15 minutes for each continuous work assignment. Any started unit shall be rounded up to the next full 15-minute unit. Time worked shall be documented in a comprehensible manner.
(4) All prices are net prices plus statutory VAT, where applicable.
(5) Travel time, travel costs, expenses, third-party services and other disbursements shall be remunerated separately unless otherwise agreed.
§ 10 Invoicing and Payment
(1) Invoices may be issued based on time spent, project progress, monthly or following completion of individual services.
(2) SecurBit is entitled to transmit invoices electronically, in particular in a legally permissible structured electronic-invoice format, to the most recently notified electronic receiving address of the customer. The customer is required to keep this receiving address up to date and ensure proper receipt.
(3) The statutory provisions shall apply to the receipt of electronic invoices.
(4) Invoices are due for payment without deduction within 14 calendar days of receipt unless otherwise agreed.
(5) In the event of default, SecurBit is entitled to claim statutory default interest.
(6) If the customer is in default with due payments, SecurBit is entitled, following a prior reminder and expiry of a reasonable grace period, to suspend further services until the outstanding amounts have been paid. This shall not apply where suspension would be disproportionate to the outstanding amount in the individual case or where immediately required measures to avert substantial risks are concerned.
(7) The customer may set off claims only if they are undisputed or have been finally adjudicated. This restriction shall not apply to counterclaims arising from the same contractual relationship.
§ 11 Term and Termination
(1) Ongoing contracts, in particular service or support agreements, shall run for the individually agreed term.
(2) If no specific term or notice period has been agreed for an ongoing service or support agreement, it may be terminated by giving three months’ notice to the end of a calendar month.
(3) For project-related services, the term and termination provisions agreed in the relevant offer or contract shall take precedence.
(4) Services already performed or commenced up to the effective date of termination shall be invoiced on a time-and-material basis or in accordance with the agreed remuneration arrangement. Non-cancellable third-party services and expenses shall be reimbursed by the customer where they were incurred in accordance with the contract.
(5) The right to terminate for good cause remains unaffected.
(6) Notices of termination must be given at least in text form.
§ 12 Deadlines, Disruptions and Force Majeure
(1) Deadlines are binding only if expressly agreed as binding in text form.
(2) Delays caused by force majeure, official measures, the customer’s failure to cooperate or other external factors shall extend agreed deadlines by a reasonable period, provided that SecurBit is not responsible for those circumstances.
(3) Such events include in particular natural events, power or internet outages, cyberattacks or ransomware incidents that could not be avoided despite appropriate protective measures, global supply shortages, cloud-service outages and disruptions affecting manufacturers, providers or other third parties, provided that such events are outside SecurBit’s reasonable sphere of influence.
(4) Additional effort caused by circumstances attributable to the customer, failure to cooperate, incorrect information or changes initiated by the customer may be charged separately after prior notice to the customer.
(5) Additional effort resulting from disruptions affecting manufacturers, providers or other third parties shall be charged only where the customer has commissioned or approved the corresponding analysis, recovery or adaptation services.
§ 13 Third-Party Products and Vendors
(1) Where SecurBit’s services concern third-party products, software, hardware, cloud services or support services, those vendor, licence and third-party terms shall additionally apply that either apply directly between the customer and the relevant third party or were made available to the customer before conclusion of the contract and validly incorporated into the contractual relationship.
(2) SecurBit shall not be liable for disruptions, restrictions or failures arising exclusively within the sphere of responsibility of the relevant manufacturer, licensor, provider or other third party, provided that SecurBit is not itself responsible for those circumstances.
(3) SecurBit does not owe permanent compatibility with future updates, releases, licensing models, product changes, interface changes or other changes made by manufacturers or third parties unless expressly agreed otherwise.
(4) The customer is responsible for providing the required licences, rights of use, maintenance agreements and vendor access unless these are expressly included in SecurBit’s services.
(5) Where the services concern third-party AI models, AI platforms, cloud services, interfaces or other services, SecurBit does not warrant their permanent availability, freedom from defects, output accuracy, model behaviour, data processing or future compatibility, provided that SecurBit is not responsible for those circumstances.
(6) Changes to models, interfaces, security mechanisms, licence terms, terms of use or data-processing practices of the relevant providers are outside SecurBit’s sphere of influence. Any adaptation services required as a result shall be remunerated separately unless they are expressly included in the agreed scope of services and have been commissioned or approved by the customer.
§ 14 Confidentiality
(1) Both parties undertake to treat as confidential all confidential information that becomes known to them in connection with the contractual relationship. This applies in particular to credentials, security concepts, configurations, documentation, trade secrets and technical and organisational information.
(2) The confidentiality obligation does not apply to information that is publicly known, was already lawfully known to the receiving party, was lawfully obtained from an authorised third party, was independently developed or must be disclosed pursuant to a legal, regulatory or court order.
(3) The parties may disclose confidential information to their employees, freelancers, advisers, subcontractors and other vicarious agents to the extent necessary for performance of the contract. The relevant persons must be appropriately bound to confidentiality.
(4) The confidentiality obligation shall continue after termination of the contractual relationship.
§ 15 Rights of Use in Work Results
(1) Where SecurBit provides the customer with documentation, concepts, configurations, scripts, diagrams or other work results as part of the services, the customer shall, upon full payment of the remuneration attributable to the relevant work result, receive a non-exclusive right of use for its own business purposes.
(2) The customer may also make the work results available to affiliated companies, its own employees or IT service providers engaged by it where this is necessary for the operation, maintenance, review or further development of its systems and the persons or companies concerned are bound to confidentiality.
(3) Until full payment of the remuneration attributable to the relevant work result, the rights of use in that work result shall remain with SecurBit. If use is permitted before full payment, such permission shall be provisional. Revocation shall be permissible only if the customer is in default with the relevant payment and a reasonable payment deadline previously set has expired without payment.
(4) Any further disclosure to third parties or use outside the contractually intended purpose requires SecurBit’s prior consent unless mandatory law provides otherwise.
(5) Pre-existing know-how, methods, templates, tools, scripts, practical experience and general concepts shall remain with SecurBit.
(6) Rights in third-party software, open-source components or vendor documentation are governed exclusively by the applicable licence and terms of use of the respective rights holders.
§ 16 Liability
(1) SecurBit shall be liable without limitation in cases of intent and gross negligence, for damage arising from injury to life, body or health and in cases of mandatory statutory liability.
(2) In the event of a slightly negligent breach of a material contractual obligation, SecurBit’s liability shall be limited to the foreseeable damage typical for the contract at the time the contract was concluded. Material contractual obligations are obligations whose fulfilment is essential for proper performance of the contract and on whose compliance the customer may regularly rely.
(3) In all other respects, SecurBit’s liability for slight negligence is excluded.
(4) Liability for data loss shall be limited to the typical restoration costs that would have arisen if the customer had carried out regular, proper and risk-appropriate data backups, unless data backup was expressly agreed as a service to be provided by SecurBit.
(5) The above limitations of liability shall apply accordingly in favour of SecurBit’s legal representatives, employees, freelancers, subcontractors and vicarious agents.
(6) The above provisions do not alter the statutory burden of proof to the customer’s detriment.
§ 17 Data Protection
(1) SecurBit processes personal data of the customer, its contact persons and other persons involved in accordance with the applicable data-protection laws, in particular where processing is necessary for the initiation, performance and administration of the contractual relationship.
(2) Where SecurBit processes personal data on behalf of the customer, such processing shall take place exclusively on the basis of a separate data processing agreement pursuant to Article 28 GDPR.
(3) The customer remains responsible for the lawfulness of the processing of personal data in its systems and for compliance with its own data-protection obligations unless SecurBit expressly assumes a different service obligation.
(4) Further information on the processing of personal data is set out in the privacy policy currently available on SecurBit’s website.
§ 18 Final Provisions
(1) German law shall apply, excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).
(2) If the customer is a merchant, a legal entity under public law or a special fund under public law, the place of performance for all services under the contractual relationship shall be SecurBit’s place of business.
(3) If the customer is a merchant, a legal entity under public law or a special fund under public law, SecurBit’s place of business shall be the exclusive place of jurisdiction for all disputes arising out of or in connection with the contractual relationship.
(4) Amendments and supplements to the contract must be made at least in text form. Statutory form requirements and the precedence of individual agreements remain unaffected.
(5) This English version is provided solely for information and better understanding. In the event of any discrepancy, ambiguity or inconsistency between the German and English versions, the German version shall exclusively prevail.
(6) If any provision of these General Terms and Conditions is or becomes invalid, the validity of the remaining provisions shall remain unaffected. The invalid provision shall be replaced by the applicable statutory provision.
Effective from: 1 June 2026
