Terms of Service (AGB)
for the use of the training platform ThreatRoom (threatroom.io) operated by Can Yildiz and Stefan Pilarczyk, Dietrich-Bonhoeffer-Str. 23, 61440 Oberursel (Taunus), Germany — hereinafter the “Provider”.
This English translation is provided for convenience only. The German version is the authoritative and legally binding version.
§ 1 Scope
(1) These terms apply to all contracts on the use of the browser-based training platform ThreatRoom between the Provider and its customers.
(2) The offering is directed exclusively at entrepreneurs within the meaning of § 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law (the “Customer”). Contracts with consumers are excluded.
(3) Conflicting or deviating terms and conditions of the Customer do not become part of the contract unless the Provider expressly agrees to their application in text form.
§ 2 Subject of the contract
(1) ThreatRoom is a browser-based platform for interactive cybersecurity crisis simulations (incident-response training). Sessions are created and moderated via a trainer console; the Customer’s participants join via a session code — depending on the session configuration chosen by the Customer, either pseudonymously with a freely chosen codename (default) or with their real name (first and last name plus e-mail address, e.g. for attestation purposes).
(2) Scenario content (texts, tasks, evaluations and, where applicable, images and voice output) is partially generated at runtime by generative AI models and therefore varies from session to session. There is no entitlement to specific individual content, scenario progressions or evaluation results.
(3) The specific scope of services (training modules, number of participants, term, number of sessions) results from the respective offer or order confirmation of the Provider.
§ 3 Conclusion of contract
The presentation of the platform does not constitute a binding offer. The contract is concluded through an individual offer by the Provider and its acceptance by the Customer, or through the Provider’s order confirmation in text form.
§ 4 Access and rights of use
(1) The Customer receives access credentials for the trainer console for the term of the contract. Participants do not need their own account; access is granted via session-specific codes.
(2) The Customer receives the simple, non-exclusive, non-transferable and non-sublicensable right to use the platform for its own internal training purposes for the duration of the contract.
(3) All rights to the platform, its design and its content remain with the Provider or the respective rights holders. Reproduction, distribution or making platform content publicly available outside the training sessions requires the Provider’s prior consent in text form.
§ 5 Availability and maintenance
(1) The Provider renders its services with the diligence of a prudent businessperson in accordance with the current state of the art. Uninterrupted availability of the platform cannot be guaranteed; in particular, maintenance work, further development and disruptions outside the Provider’s sphere of influence (e.g. at network, hosting or AI service providers) may lead to temporary restrictions.
(2) The Provider schedules planned maintenance outside booked training dates where possible. In the event of a disruption affecting a firmly agreed training date, the parties will coordinate a replacement date.
§ 6 Obligations of the Customer
(1) The Customer is obliged to
- keep console access credentials secret, protect them from access by unauthorised third parties and inform the Provider without undue delay if misuse is suspected;
- inform participants before the session about the nature of the data processing — in particular whether the session is run pseudonymously or with real names; in pseudonymous sessions, to point out that real names should not be used as codenames; in real-name sessions, to ensure that a sound data-protection legal basis exists for collecting participants’ names and e-mail addresses;
- not to enter any personal data of third parties, trade secrets or other confidential real data into free-text fields, codenames or company profiles unless required for the training;
- not to misuse the platform, in particular not to enter unlawful, offensive or harmful content and not to take any actions that impair the security or availability of the platform.
(2) In the event of serious or repeated violations, the Provider is entitled to temporarily block access; the right to extraordinary termination remains unaffected.
§ 7 Simulation character; no advice
(1) All training content — including AI-generated scenarios, fictitious companies, threat situations and evaluations — serves training and exercise purposes only. It does not constitute legal, security or other professional advice and does not replace individual consulting or a real incident-response concept.
(2) AI-generated content is produced automatically. The Provider gives no warranty as to its technical accuracy, completeness or fitness for any particular purpose outside the training context. Any resemblance of fictitious scenarios to real companies, persons or events is coincidental, unless the Customer has provided a company profile itself.
§ 8 Remuneration
(1) The remuneration agreed in the offer or order confirmation applies. All prices are net plus the applicable statutory value-added tax.
(2) Unless otherwise agreed, invoices are due for payment without deduction within 14 days of the invoice date.
§ 9 Liability
(1) The Provider is liable without limitation for intent and gross negligence, for damages arising from injury to life, body or health, under the provisions of the German Product Liability Act and to the extent of any guarantee assumed.
(2) In the event of slightly negligent breach of an essential contractual obligation (cardinal obligation) — i.e. an obligation whose fulfilment makes the proper performance of the contract possible in the first place and on whose observance the Customer may regularly rely — liability is limited to the foreseeable damage typical for this type of contract at the time of conclusion.
(3) In all other respects, liability for slight negligence is excluded. Strict liability under § 536a (1) alt. 1 BGB for defects existing at the time of conclusion of the contract is excluded.
(4) For loss of data, the Provider is liable only to the extent that the damage would also have occurred with proper, regular data backups by the Customer, insofar as data backup falls within the Customer’s area of responsibility.
§ 10 Data protection and confidentiality
(1) Information on the processing of personal data is contained in the privacy policy. Insofar as the Provider processes personal data on behalf of the Customer, the parties will conclude a data processing agreement pursuant to Art. 28 GDPR upon request.
(2) The parties treat confidential information of the other party that becomes known to them in the course of the contract as confidential and use it only for the performance of the contract.
§ 11 Term and termination
(1) Term and notice periods result from the respective offer or order confirmation. Individual bookings end upon completion of the booked training.
(2) The right of both parties to extraordinary termination for good cause remains unaffected. Terminations must be made in text form.
§ 12 Changes to these terms
The Provider may amend these terms with effect for the future insofar as this is necessary due to changes in the legal situation, case law or technical framework conditions and does not unreasonably disadvantage the Customer. Changes will be communicated to the Customer in text form and are deemed approved unless the Customer objects within six weeks of receipt; this consequence will be specifically pointed out in the notification.
§ 13 Final provisions
(1) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
(2) If the Customer is a merchant, a legal entity under public law or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from or in connection with this contract is the Provider’s registered office. The Provider is also entitled to sue the Customer at the Customer’s general place of jurisdiction.
(3) Should individual provisions of these terms be or become invalid, the validity of the remaining provisions remains unaffected.
Version: July 2026