General Terms of Use

Last updated: 4 October 2025

General Terms of Use for the AI-based bookkeeping service (AIaaS)


1. Scope

These terms apply to all orders for and use of the AI-based bookkeeping service (the "Service") provided by IconicC Digital GmbH (the "Provider") exclusively to entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB). By ordering or using the Service, the customer agrees to these terms. Deviating terms of the customer do not apply unless they have been expressly accepted in writing.

2. Subject matter of the Service

The Provider makes an AI-based platform ("AIaaS") available for bookkeeping services. The scope of services results from the website and, where applicable, the detailed services stated in the order. The Service supports the customer in GoBD-compliant bookkeeping but does not replace tax advice.

3. Customer obligations

  • Provide complete and accurate documents in the agreed formats and interfaces.
  • Remain responsible for the legal propriety of the bookkeeping.
  • Cooperate in a timely manner when questions arise.
  • Do not disclose access credentials or use the Service outside the agreed scope.
  • Ensure that the customer meets its own tax-advice obligations.

4. Data rights and AI outputs

  • Input, such as documents and business transactions, remains the property of the customer.
  • Output, such as booking proposals and reports, is made available to the customer on a non-exclusive basis for its own business purposes.
  • The Provider may use anonymised data for training purposes unless the customer expressly objects (opt-out).
  • System-generated outputs may not be unique.

5. Data protection

A separate data-processing agreement under Article 28 GDPR applies. Transfers to third countries take place only in accordance with Articles 44 et seq. GDPR. Special categories of personal data under Article 9 GDPR are processed only by express agreement.

6. Remuneration

Prices are stated in the order and are based on the published price list, plus statutory VAT. Billing takes place monthly in arrears. The Provider may adjust prices annually by up to plus or minus 10 percent, or in the event of proven exceptional cost increases. Service credits are credited against subsequent invoices.

7. Service level and defects

The Provider aims for 98 percent availability per quarter, excluding maintenance and force majeure. In the event of material deviations, the Provider will remedy the issue; a reduction or extraordinary termination may apply where significant restrictions remain. The agreement is a service contract, not a contract for work and services.

8. Liability

Liability is unlimited in cases of intent, gross negligence, injury to life, body, or health, and under the German Product Liability Act. In cases of simple negligence, liability applies only to the breach of essential contractual obligations and is limited to foreseeable, typical damage. To the extent legally permitted, the Provider is not liable for lost profits or AI-related erroneous decisions. The provisions of the German Civil Code and Regulation (EU) 2024/1689 (AI Act) apply.

9. Term and termination

The agreement begins with the order and runs for an indefinite period. Either party may terminate with four weeks' notice to the end of a month. After termination, data, including general ledgers and documents, will be returned in a common format and deleted after 30 days unless retention obligations apply.

10. Confidentiality

Both parties must keep business and trade secrets confidential. The confidentiality obligation continues for three years after termination.

11. Force majeure

Neither party is liable for events of force majeure, including natural disasters, war, strikes, or pandemics. Section 313 BGB remains unaffected.

12. Final provisions

  • German law applies. The place of jurisdiction is Munich.
  • Changes and additions require written form.
  • If any provision is invalid, the remaining provisions remain valid.
  • There are no third-party beneficiaries.
  • Export controls under the EU Dual-Use Regulation and BAFA requirements apply.
  • The Provider may use the customer's brand as a reference only where the customer has not expressly opted out.
  • Sections concerning data protection, data rights, service level, liability, termination, and confidentiality continue to apply after the agreement ends.

For questions about these terms, contact info@iconicc.com.


Appendix: Data Processing Agreement

Preamble

The Provider processes personal data on behalf of the customer in connection with the AI-based bookkeeping service. This agreement specifies the parties' rights and obligations under the GDPR and the German Federal Data Protection Act.

1. Scope

This agreement applies to processing of personal data, such as documents, business transactions, and contact details, arising in connection with the Service. The categories of data include master data, financial data, and, where applicable, contact details of employees or business partners. Special categories of personal data under Article 9 GDPR are processed only by express agreement. The duration corresponds to the term of the Service agreement.

2. Provider obligations

The Provider processes data only on the documented instructions of the customer unless legally required to do otherwise. All authorised persons are bound to confidentiality. The Provider supports the customer with data-subject requests under Articles 15 to 22 GDPR, data-protection impact assessments under Article 35 GDPR, and notification obligations under Articles 33 and 34 GDPR. Processing takes place only in the EU/EEA or with appropriate safeguards under Articles 44 et seq. GDPR.

3. Technical and organisational measures

The Provider implements measures under Article 32 GDPR to protect confidentiality, integrity, and availability, including encryption, access controls, and backups. The Provider informs the customer about incidents and documents changes to its measures.

4. Sub-processors

The Provider may appoint sub-processors. Agreements with sub-processors provide at least the same level of protection, and the Provider remains responsible for their compliance.

5. Audit and evidence rights

The Provider makes information about compliance available and permits audits, for example through reports or on-site inspections. The Provider maintains a record of processing activities under Article 30 (2) GDPR.

6. End of processing and return of data

After the agreement ends, the Provider returns or deletes all data in a common format. A deletion record is available on request. Data is retained only where legally required.

7. Liability and other provisions

Liability is governed by Article 82 GDPR and, additionally, Section 8 of these Terms. Changes require written form. The governing law and venue are as stated in Section 12 of these Terms.