Terms and Conditions
Terms and Conditions for the provision of the sugarLENS Software as a Service
These are the Terms and Conditions (the “Contract”) applicable between Justaddsugar GmbH, Winterhuder Weg 62, 22085 Hamburg (“Justaddsugar”) and our customers (“Customer”) for the provision of the “sugarLENS” software for creative-performance intelligence by way of Software as a Service (the “Software”). Our offering is directed exclusively at entrepreneurs within the meaning of Sec. 14 BGB, i.e. a natural or legal person or a partnership with legal capacity acting, when concluding a legal transaction, in the exercise of its commercial or independent professional activity. The Customer’s general terms and conditions do not become part of the contract.
Contents
- Subject Matter of the Contract
- Services of Justaddsugar
- Scope of Use and Rights
- Service Level Agreement (SLA)
- Remuneration and Payment Terms
- Customer’s Obligations
- Data Protection and Confidentiality
- Term and Termination
- Warranty
- Liability
- Defects of Title, Indemnification
- Final Provisions
Annex 1: Data Processing Agreement (DPA) pursuant to Art. 28, 29 GDPR · Appendix 1 to the DPA: Subprocessors
Subject Matter of the Contract
- The subject matter of the contract is the granting of use of the Software by the Customer for consideration and limited in time to the term of the contract.
- Justaddsugar may involve subcontractors in rendering its own services. The use of subcontractors does not release Justaddsugar from its sole obligation towards the Customer to fully perform the contract.
Services of Justaddsugar
- The Software serves as a creative-performance-intelligence tool and, among other things, ingests advertising-performance data from connected advertising platforms, evaluates creatives, or performs an AI-supported analysis of selected assets. The functional scope of the Software results from the respective offer (e.g. on the Justaddsugar website).
- Justaddsugar grants the Customer the use of the respective current version of the Software for the agreed number of authorised users and requests over the internet via access through a browser. The Software is designed for browsers with the Chromium engine (Edge, Chrome) and, for security reasons, optimised for the respective current version. Use with other browsers or outdated versions of a browser may lead to a different user experience.
- Justaddsugar warrants, in accordance with Sec. 4, a functionality and availability of the Software outside announced maintenance windows (cf. Sec. 2.6) of 99 % per month, and will maintain it in a condition suitable for contractual use.
- After conclusion of the contract, Justaddsugar will provide the Customer without undue delay, in electronic form, with access data for use of the Software. Justaddsugar will activate the contractually agreed number of users (“seats”) after notification of the individual users by the Customer. Changes to the user group must be communicated to Justaddsugar in text form.
- Justaddsugar may, without being obliged to do so, update or further develop the Software at any time and, in particular, adapt it due to a changed legal situation, technical developments, or to improve IT security. In doing so, Justaddsugar will appropriately take into account the legitimate interests of the Customer and inform the Customer in good time about significant updates and upgrades. In the event of a material impairment of the Customer’s legitimate interests, the Customer is entitled to a special right of termination. Justaddsugar does not, in principle, owe any adaptation to the individual needs or the IT environment of the Customer.
- Justaddsugar will maintain the Software regularly. Maintenance that restricts usability will, in principle, be carried out outside the usual business hours (Mon–Fri 09:00–18:00, excluding public holidays at Justaddsugar’s registered office), unless maintenance must be carried out at another time for compelling reasons. Customers will be informed in good time about any restrictions.
- Insofar as booked by the Customer within the functional scope, Justaddsugar provides the Customer with storage space on its servers for storing data and for purposes of using the Software, to an extent customary for the contractual purpose.
- During the term of the contract, Justaddsugar will take measures to protect the data corresponding to the state of the art.
- The analysis system contained in the platform is operated using artificial intelligence, which, despite all care measures taken by Justaddsugar, may be erroneous. The AI-supported analyses and evaluations are to be understood solely as a supporting decision aid and constitute non-binding suggestions. They do not replace the Customer’s own responsible entrepreneurial review and decision. Justaddsugar recommends subjecting reports as well as other outputs generated in the system to a manual review.
- The platform relies on application programming interfaces and third-party services, including the advertising platforms (Meta, Google/YouTube, TikTok) and providers of artificial intelligence. The availability, scope, accuracy, and continued existence of these third-party services lie outside Justaddsugar’s sphere of influence. Justaddsugar is not responsible for interruptions, changes, discontinuations, blocks, or inaccuracies of such third-party services or for data supplied by them.
- To ensure a consistently high service quality for all customers, fair-use limits apply. These relate to an above-average number of requests per user/account/period, the use of computing or storage resources, file size and upload volumes, API usage, the number of concurrent sessions, and automated processes. In the case of unusually high, abusive, or system-burdening use that is grossly disproportionate to the remuneration, Justaddsugar is entitled to take appropriate measures. Such a disproportion is presumed if the costs incurred by Justaddsugar due to the Customer’s use exceed the remuneration payable by the Customer by 30 % or more. Before taking measures, Justaddsugar informs the Customer by email. Possible measures are: temporary throttling, restriction of individual functions, or temporary suspension of access. A permanent suspension only occurs in the case of serious or repeated violations after prior written warning.
- Justaddsugar is entitled to provide functions that are marked as beta, preview, or experimental functions. Such functions are provided “as is”, may be changed or discontinued at any time, and are excluded from any warranty and from any availability commitments. The Customer uses such functions at its own discretion.
Scope of Use and Rights
- The Customer receives, in the respective current version of the Software and for the contractually defined number of users, simple — i.e. non-sublicensable and non-transferable — rights, limited in time to the term of the contract, to use the Software via access through a browser in accordance with the contractual provisions.
- The Customer may use the Software only within the scope of its own business activity, through its vicarious agents or third parties associated with the Customer. Any further use of the Software by the Customer is not permitted.
- The Software may also serve the processing of personal data. In this respect, the Data Processing Agreement in Annex 1, which forms part of this contract, applies.
- As between the parties, all rights to the Customer data remain with the Customer. The Customer grants Justaddsugar the non-exclusive right to host, process, reproduce, and display Customer data insofar as this is necessary to provide, secure, maintain, and improve the service, including the creation of aggregated and anonymised analyses, benchmarks, and insights that identify neither the Customer nor any individual.
Service Level Agreement (SLA)
- The overall availability of the services granted by Justaddsugar pursuant to Sec. 2.2 relates to the handover point. The handover point is the router output of the data centre used by Justaddsugar.
- Availability means the Customer’s ability to use the offered main functions of the Software. Announced maintenance times as well as periods of disruption complying with the remediation time count as periods of availability of the Software. Periods of insignificant disruptions are disregarded in calculating availability. The measuring instruments in Justaddsugar’s data centre are authoritative for proving availability.
- The Customer must report disruptions to Justaddsugar without undue delay.
- The elimination of insignificant disruptions is at Justaddsugar’s discretion.
- Support is provided during the usual business hours (Mon–Fri 09:00–18:00, excluding public holidays at Justaddsugar’s registered office) via a ticket system at sugarlens@justaddsugar.de. If the platform is unreachable, the response time is 2 h from receipt of the error report within the usual business hours. If essential functions of the platform are unavailable or only very limitedly available, the response time is 1 day from receipt of the error report within the usual business hours.
- For free-of-charge services (“free trial”), Justaddsugar does not warrant any service pursuant to this Sec. 4.
Remuneration and Payment Terms
- The Customer must pay Justaddsugar the remuneration resulting from the respective offer. Payment is, in principle, due in advance.
- All payments must be settled within two weeks of receipt of the invoice at the latest. In the event of default of payment or in the case of an agreed deferral, the Customer must pay default interest of at least 8 percentage points above the respective base interest rate, unless Justaddsugar has incurred a higher interest damage. Further default claims remain unaffected.
Customer’s Obligations
- The Customer must protect and keep the access data transmitted to it against third-party access in accordance with the state of the art. The Customer will ensure that use only takes place within the contractually agreed scope. Unauthorised access must be reported to Justaddsugar without undue delay.
- The Customer is responsible for the selection of its authorised users, for their scope of access, and for ensuring that they comply with the terms of this contract.
- The Customer and the users selected by it are not permitted to:
- circumvent or attempt to circumvent access controls, the account restriction, or data-separation mechanisms, or access the data of other customers or tenants;
- reverse-engineer, decompile, or disassemble the service or attempt to derive its source code, unless such a restriction is impermissible under mandatory law;
- automatically read out or extract data beyond the intended functionality, or unreasonably burden the infrastructure;
- resell, rent, sublicense, or make the service available to third parties, or use it to build a competing product;
- upload or transmit unlawful, infringing, defamatory, or harmful (malware-containing) content; or
- use the service in violation of applicable law, official orders, third-party rights, or agreements with third parties.
- The Customer must maintain the permissions required for data ingestion at the advertising platforms it uses (Meta, Google/YouTube, TikTok or similar) and comply with the respectively applicable terms of those platforms.
Data Protection and Confidentiality
- The parties undertake to maintain secrecy about all confidential information (including trade secrets) that the parties learn in connection with this contract and its performance, and not to disclose, pass on, or otherwise use it towards third parties. Confidential information is such information as is marked as confidential or whose confidentiality results from the circumstances, regardless of whether it has been communicated in written, electronic, embodied, or oral form. The confidentiality obligation does not apply insofar as the respective party is obliged by law or by a final or legally binding decision of an authority or court to disclose the confidential information. The parties undertake to agree a provision identical in content to the preceding paragraph with all employees and subcontractors. The provisions of the Data Processing Agreement pursuant to Annex 1 remain unaffected.
Term and Termination
- The term of the contract results from the offer. After expiry of the contract term, the contract is automatically extended by the original contract term.
- The contract may be terminated by both parties with a notice period of one month to the end of the agreed contract term.
- The right to extraordinary termination for good cause remains unaffected.
- Termination requires at least text form.
- Upon termination of the contract, the return or deletion of the Customer’s personal data is governed by the provisions of the Data Processing Agreement pursuant to Annex 1.
Warranty
- The statutory warranty for defects applies.
- The Customer must notify Justaddsugar of any defects without undue delay.
- The warranty for only insignificant reductions in the suitability of the service is excluded. The strict (no-fault) liability pursuant to Sec. 536a(1) BGB for defects that already existed at the time of conclusion of the contract is excluded.
Liability
- The parties are liable without limitation in the case of intent, gross negligence, and culpable injury to life, body, or health.
- Notwithstanding the cases of unlimited liability pursuant to Sec. 10.1, Justaddsugar is liable in the case of slightly negligent breach of duty only for the breach of material contractual obligations — i.e. obligations whose fulfilment makes the proper performance of the contract possible in the first place and on whose compliance the other party may regularly rely — but limited to the foreseeable, contract-typical damage at the time of conclusion of the contract, and at most 100 % of the remuneration paid by the Customer in the last 12 months.
- The foregoing limitations of liability do not apply to liability under the Product Liability Act (Produkthaftungsgesetz) or within the scope of guarantees assumed in writing by a party.
- Sec. 10.1 to 10.3 also apply in favour of the employees, representatives, and bodies of the parties.
Defects of Title, Indemnification
- The Customer will inform Justaddsugar without undue delay of claims by third parties asserted against it on the basis of the contractual use of the platform, and grant it all necessary powers of attorney and authorisations to defend against the claims.
- The Customer warrants that the content and data stored on Justaddsugar’s servers, as well as their use and provision by Justaddsugar, do not violate applicable law, official orders, third-party rights, or agreements with third parties. The Customer will indemnify Justaddsugar on first demand against claims asserted by third parties on the basis of a violation of this Sec. 11.2.
Final Provisions
- There are no oral or written side agreements to this contract. Amendments to this contract and its annexes require written form. This also applies to this written-form clause.
- In the event of a conflict, the agreements from the DPA (Annex 1) take precedence, then the provisions from the respective offer, and subsequently the provisions from this contract.
- German law applies, excluding the conflict-of-laws provisions and the United Nations Convention on Contracts for the International Sale of Goods of 11 April 1980 (CISG).
- The exclusive place of jurisdiction for all disputes arising out of or in connection with this contract is the registered office of Justaddsugar.
Annex 1: Data Processing Agreement (DPA)
Data Processing Agreement pursuant to Art. 28, 29 GDPR — between Justaddsugar GmbH (“Processor”) and the Customer (“Controller”)
Preamble. The Processor processes personal data on behalf of the Controller within the meaning of Art. 4 No. 8 and Art. 28 of Regulation (EU) 2016/679 – General Data Protection Regulation (“GDPR”). This Data Processing Agreement (the “Agreement”) specifies the data-protection obligations of the contracting parties resulting from the commissioned data processing described in the main contract. This Agreement applies to all activities connected with the main contract and in which employees of the Processor or third parties commissioned by the Processor may come into contact with personal data provided by the Controller.
Definitions
- Personal data means any information provided by the Controller relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person (Art. 4 No. 1 GDPR).
- Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction (Art. 4 No. 2 GDPR).
- Instructions are all directions that the Controller gives to the Processor and by which the Processor is required to process personal data. The instructions are initially set out in the main contract and may thereafter be changed, supplemented, or replaced by the Controller through individual instructions (“individual instructions”).
Subject Matter of the Agreement, Responsibility
- The Processor processes the personal data on behalf of the Controller. The Controller is solely responsible for compliance with the statutory provisions of the data-protection laws, in particular for the lawfulness of the transfer of the personal data to the Processor as well as the lawfulness of the processing thereof (“Controller” within the meaning of Art. 4 No. 7 GDPR).
Duration
- The duration of this Agreement corresponds to the term of the main contract. The right to extraordinary termination remains unaffected.
Scope, Nature, and Purpose of the Intended Processing of Personal Data
- The scope, nature, and purpose of the processing of personal data by the Processor on behalf of the Controller are specifically described in the main contract.
Nature of the Data
The following types/categories of data are the subject of the processing of personal data:
- Username and login data
- Creator name and asset metadata
- Communication data (sugarChat chat content)
- Advertising-performance data from the connected advertising platforms (Meta, Google/YouTube, TikTok or similar), insofar as these contain personal data
- Usage metadata (timestamps, session data, requests)
Categories of Data Subjects
The group of data subjects whose personal data is processed comprises:
- Users of the customers (employees who use the Software)
- Creators/influencers
Rectification, Erasure, Blocking, and Surrender of Data
- The Controller may, at any time during and after termination of this Agreement or the main contract, within the scope of a lawful individual instruction, demand the rectification, erasure, blocking, and surrender of personal data.
- The Controller determines the measures for the surrender of the transferred data media and/or deletion of the stored personal data after termination of the contract, contractually or by individual instruction.
Technical and Organisational Measures
- The Processor will take technical and organisational measures to adequately secure the personal data against misuse and loss that meet the requirements of Art. 24, 32 GDPR. This includes in particular, where appropriate:
- denying unauthorised persons access to data-processing facilities with which the personal data is processed and used (physical access control);
- preventing data-processing systems from being used by unauthorised persons (system access control);
- ensuring that persons authorised to use a data-processing system can access exclusively the data subject to their access authorisation, and that personal data cannot be read, copied, altered, or removed without authorisation during and after processing (data access control);
- ensuring that personal data cannot be read, copied, altered, or removed without authorisation during electronic transmission or during its transport or storage on data media, and that it can be verified and established to which bodies a transfer of personal data by data-transmission facilities is intended (transfer control);
- ensuring that it can subsequently be verified and established whether and by whom personal data has been entered into, altered, or removed from data-processing systems (input control);
- ensuring that personal data can be processed only in accordance with the Controller’s instructions (job control);
- ensuring that personal data is protected against accidental destruction or loss (availability control);
- ensuring that data collected for different purposes can be processed separately (separation control);
- the pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services related to processing;
- the ability to restore the availability of and access to personal data quickly in the event of a physical or technical incident;
- a procedure for regularly reviewing, assessing, and evaluating the effectiveness of the technical and organisational measures for ensuring the security of processing.
- The technical and organisational measures are subject to technical progress and further development. In this respect, the Processor is permitted to implement alternative adequate measures. In doing so, the security level of the defined measures must not be undercut. Significant changes that may impair the integrity, confidentiality, or availability of the personal data must be documented.
Instructions
- The Controller has the right to issue individual instructions to the Processor at any time regarding the nature, scope, and procedure of the processing of personal data. Individual instructions must be made in writing.
- The Processor may process personal data only within the scope of the main contract, this Agreement, and individual instructions, unless the Processor is obliged to process the personal data under Union law or the law of the member states.
- Provisions on any remuneration for additional expenses incurred by the Processor as a result of the Controller’s individual instructions remain unaffected.
- The Processor must inform the Controller of exceptions to the duty to follow instructions due to law applicable to it, unless that very law prohibits such notification for reasons of an important public interest.
Other Rights and Obligations of the Processor
- The Processor appoints — where required by law — a data protection officer who can perform his/her activity in accordance with Art. 37, 38, 39 GDPR. Their contact details are communicated to the Controller on request for the purpose of direct contact.
- The Processor ensures that the employees involved in the processing of personal data are obliged to maintain data secrecy (Art. 28(3)(b) GDPR) and have been instructed in the protective provisions of the GDPR. Data secrecy continues to exist after termination of the activity.
- The Processor informs the Controller in the event of serious disruptions to the operational process, in the case of suspected data-protection breaches, or other irregularities in the processing of the personal data. This also applies to any control actions and measures of the supervisory authority pursuant to Art. 51–59 GDPR or investigations pursuant to Art. 83, 84 GDPR.
- It is known that the Processor may be subject to information obligations under Art. 33 GDPR in the event of unlawful transmission or acquisition of knowledge of certain personal data. Therefore, such incidents must be reported to the Controller without undue delay, irrespective of who caused them. The Processor’s notification to the Controller must in particular contain the following information:
- a description of the nature of the personal-data breach, where possible with details of the categories and approximate number of data subjects concerned, the categories concerned, and the approximate number of personal-data records concerned;
- a description of the measures taken or proposed by the Processor to remedy the personal-data breach and, where appropriate, measures to mitigate its possible adverse effects.
- The Processor must take appropriate measures to secure the data and to mitigate possible adverse consequences for data subjects.
- The Processor is obliged to provide the Controller with information at any time insofar as its data and documents are affected by a personal-data breach. The Processor undertakes the data-protection-compliant destruction of material on the basis of an individual order by the Controller and at the Controller’s expense. In special cases to be determined in writing by the Controller, storage or handover takes place.
- The processing of data in private homes (telework or home office of the Processor’s employees) is permitted by the Controller. Insofar as the data is processed in a private home, the Processor warrants that the measures pursuant to Art. 32 GDPR are also ensured for telework and home office.
- Insofar as the Processor renders services under this Agreement that are not remunerated by the main contract, the Processor may demand appropriate remuneration.
- The Processor informs the Controller without undue delay if it is of the opinion that instructions given by the Controller violate the GDPR or applicable data-protection provisions of the Union or the member states.
- The Processor will support the Controller, taking into account the nature of the processing and the information available to it, in complying with the obligations set out in Articles 32 to 36 GDPR.
Rights and Obligations of the Controller
- The Controller is solely responsible for assessing the permissibility of the processing of personal data and for safeguarding the rights of data subjects.
- The Controller must inform the Processor without undue delay and completely in writing if it discovers errors or irregularities regarding data-protection provisions when reviewing the order results.
- The information obligations arising from Art. 33 GDPR are incumbent on the Controller.
Requests from Data Subjects
- If the Controller is obliged, under applicable data-protection laws, to provide an individual with information on the processing of their personal data, the Processor will support the Controller, insofar as necessary, in providing this information, provided that the Controller has requested the Processor to do so in writing.
- The Processor will inform the Controller if data subjects assert their data-subject rights against the Processor.
Cooperation with the Supervisory Authority
- The Controller and the Processor and, where applicable, their representatives cooperate on request with the supervisory authority in the performance of its tasks.
Control Obligations of the Controller
- The Controller satisfies itself, before the start of the data processing and thereafter regularly, of the technical and organisational measures of the Processor and documents the result. For this purpose, it may, for example, obtain self-disclosures from the Processor or have an audit carried out at its own expense. In the case of an audit, the Controller also bears the costs of the Processor’s employees who must participate in the audit.
Subprocessors
- The commissioning of subprocessors is possible within the scope of this Agreement and the activities specified in Sec. 3, 4, 5, 6, provided that the Processor ensures that the subprocessor assumes the obligations under this Agreement towards the Processor. In particular, the requirements for confidentiality, data protection, and data security set out in this Agreement apply.
- The Controller must be granted control and review rights corresponding to Sec. 14. By written request, the Controller is entitled to obtain from the Processor information about the essential content of the contract and the implementation of the data-protection-relevant obligations of the subprocessor, if necessary also by inspecting the relevant contract documents.
- The subprocessors commissioned by the Processor result from Appendix 1. The Processor is entitled to commission further subprocessors, provided that they meet the requirements pursuant to Sec. 15.1 and 15.2 and the Processor notifies the Controller thereof and the latter does not object in writing within seven days.
Confidentiality Obligation
- The Processor is obliged to maintain confidentiality when processing personal data. The Processor undertakes to observe the same secrecy-protection rules as are incumbent on the Controller. The Controller is obliged to notify the Processor of any special secrecy-protection rules in writing.
General Provisions, Information Obligations, Written-Form Clause, Choice of Law
- Should personal data at the Processor be endangered by seizure or confiscation, by insolvency or composition proceedings, or by other events or measures of third parties, the Processor must inform the Controller thereof without undue delay. The Processor will inform all parties responsible in this context without undue delay that sovereignty and ownership of the personal data lie exclusively with the Controller as the “Controller” within the meaning of the GDPR.
- The processing of personal data takes place exclusively within the territory of the Federal Republic of Germany, in a member state of the European Union, or in another contracting state of the Agreement on the European Economic Area. Any relocation to a third country requires the prior consent of the Controller and may only take place if the special requirements of Art. 44, 45, 46 GDPR are met. Insofar as the processing is carried out by a third party named in Appendix 1, the Controller hereby gives its consent.
- Amendments and supplements to this Agreement and all its components — including any assurances of the Processor — require a written agreement and the express reference that it is an amendment or supplement to this Agreement. This also applies to the waiver of this formal requirement.
- German law applies, with the exception of conflict-of-laws rules.
- The place of jurisdiction is the place of jurisdiction resulting from the main contract, provided that this lies in the Federal Republic of Germany. Otherwise, the exclusive place of jurisdiction is the registered office of the Processor.
Appendix 1 to the DPA: Subprocessors
| Subprocessor | Service | Location / data residency |
|---|---|---|
| Supabase (Supabase Inc., 548 Market St, San Francisco, CA 94104, USA) | Database, authentication, and file storage | EU (Frankfurt am Main region) |
| Railway (Railway Corp., 548 Market St, San Francisco, CA 94104, USA) | Application hosting and runtime environment (backend) | EU (EU-West region, Amsterdam, Netherlands) |
| Vercel (Vercel Inc., 440 N Barranca Ave Pmb 4133, Covina, CA 91723, USA) | Hosting of the web interface (frontend) | EU (Frankfurt am Main and Stockholm) |
| Google Vertex AI / Gemini (Google Ireland Ltd., Gordon House, Barrow Street, D04 Dublin E5W5, Ireland) | AI application: analysis of creatives, the integrated assistant “sugarChat”, generation of text embeddings for semantic search | EU (Europe-West4 region or EU multi-region). If the European configuration is unavailable, a similar provider — likewise hosted in the EU — may be used as a substitute. |
| Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) | Single sign-on (authentication) for Justaddsugar employees; processing within the scope of Google Workspace use on the basis of the Google Cloud Data Processing Addendum | EU |
— End of the Terms and Conditions —