Skip to main content

General Terms and Conditions (AGB)
#

Last updated: 2026-06-16


1. Scope of Application
#

These General Terms and Conditions (hereinafter “GTC”) apply to all services provided by XenoElectronics (hereinafter “we” or “us”), in particular:

  • IT support, consulting, and training
  • On-site and remote services
  • IT monitoring & security checks
  • Maintenance and monitoring contracts for IT systems
  • Sales of goods via our online shop (shop.xenoelectronics.com)

The GTC apply to both private consumers (B2C) and business clients (B2B). By utilizing our services (whether in writing, verbally, or through actual use), the customer explicitly acknowledges the validity of these GTC.

Deviating agreements require text form. Insofar as separate contractual agreements (e.g., a maintenance & monitoring contract) have been made with the customer, those regulations take precedence over these GTC.


2. Service Description & Demarcation
#

We provide IT services according to the respectively agreed scope of services.

Typical Services
#

  • IT support, error analysis, and system assistance
  • Management of Windows and Linux systems
  • IT monitoring & security checks
  • Setup, optimization, training, and consulting

Basic Demarcation (Contract for Services / Dienstvertrag)
#

Unless explicitly agreed upon in writing as a contract for work (Werkvertrag), we owe no specific guaranteed outcome, but a professional service according to the current state of technology.

Recommendations, tips, or assessments do not constitute a guarantee for a specific result, complete problem resolution, or permanent functionality. The obligation to pay exists independently of whether a malfunction or problem could be fully resolved. The decisive factor is the actual use of the service (time expended) as well as the professional execution.

Not Included (unless separately agreed)
#

  • 24/7 availability or guaranteed response times
  • Emergency or immediate deployments
  • Manufacturer or vendor support
  • Data recovery without a prior functioning backup
  • Hardware repairs or spare parts procurement

3. IT Monitoring & Security Checks
#

Monitoring services exclusively serve the purpose of:

  • Observation
  • Control
  • Early detection of problems

No automatic troubleshooting takes place unless this was separately commissioned. The monitoring does not replace virus protection and no complete security surveillance. It offers no absolute protection against security incidents (e.g., malware, ransomware, phishing, zero-day attacks).

Recommended measures are only implemented after explicit commissioning (“Go”). If the customer decides against recommended measures, liability for resulting damages is excluded.


4. Conclusion of Contract & Proof of Identity (Bot Protection)
#

A contract is concluded through written, electronic, or verbal commissioning. Contracts are concluded exclusively with fully legally competent, adult natural persons or legal entities.

Commissioning also specifically includes:

  • the telephone request for support or service,
  • the request for assistance via e-mail, direct social media messages, or messenger services (especially WhatsApp Business and Telegram),
  • the approval of a remote access connection,
  • or the implied commissioning through the actual utilization of the service.

A separate written confirmation is not required for this.

Protection against automated bot traffic in the AI era: Due to the heavily increasing abuse by automated bot networks, AI-generated fake accounts, and identity theft, we reserve the right to demand the presentation of an official proof of identity (e.g., a scan of the ID card) during the digital intake of new customers (onboarding). In these cases, a legally binding contract is only concluded after successful manual verification of identity by us.


5. Prices, Payment Terms & Surcharges
#

5.1 Basic Conditions, Working Hours & Tariff Splitting (B2B / B2C)
#

Remuneration is based on time spent. All quoted prices are final prices. In accordance with § 19 UStG (small business status), no VAT is charged or shown.

We structurally differentiate between conditions for commercial clients (B2B) and private end consumers (B2C):

  • Consumer Tariff (B2C): To relieve private individuals in economically difficult times, lower hourly rates can be granted. Claiming the B2C tariff requires the customer to proactively prove and demonstrate that they do not operate a company/trade and that the IT service serves exclusively private purposes (e.g., by presenting an ID and a written self-declaration). If this proof cannot be provided, the B2B conditions apply automatically.
  • System Integration & 1st Level (Support, Client Setup, Hardware): €89.00 / hour
  • System Administration & 2nd Level (Linux/Windows Server, Nextcloud, Backups): €159.00 / hour
  • IT Architecture, DevOps & Security (Cluster Design, Automation, Forensics): €319.00 / hour
  • Billing interval: Per 15 minutes or part thereof.
  • Minimum purchase: A minimum of 30 minutes will be charged per order (on-site or remote).
  • Scope of working hours: In addition to the purely technical service, the calculated time expenditure also includes strictly necessary administrative closing activities (e.g., case documentation, ticket closure, invoice creation, as well as transport-safe packaging for hardware returns).
  • Remote maintenance flat rate: For remote assignments (e.g., via RustDesk), a one-time provisioning fee of €29.00 per session will be charged in addition to the time spent.

5.2 Travel Expenses & Travel Time
#

Since we provide our services mobile, travel costs apply. These are composed as follows: Vehicle flat rate: 0.39 € per kilometer driven (outward and return journey from our business seat in Suderburg). Travel time: The time for the outward and return journey counts as working time and is billed at the regular hourly rate.

5.3 Hardship Allowance, Third-Party Costs & Subcontractor Clause
#

We reserve the right to charge special surcharges for assignments under difficult conditions. The customer will be informed of this before work begins:

  • Hygiene & Environment (+ 50%): Work on heavily soiled devices (e.g., smokers’ equipment, construction dust) or in a health-hazardous environment.
  • Legacy Systems (+ 50%): Work on hardware or software older than 10 years or no longer supported by the manufacturer (“End-of-Life”).
  • Missing Documentation (+ 50%): Additional effort (reverse engineering) due to missing access data or documentation on the part of the customer.
  • B2B / Support for External IT Providers (+ 300%): If we are brought in by other IT system houses or service providers as subcontractors for troubleshooting at their end customers, we charge a flat 300% surcharge on the respective hourly rate.
  • Third-Party Margin: Should third-party licenses (e.g., Microsoft, VMware), proprietary hardware, or external specialists be strictly required at the customer’s express request, these costs will be passed on to the customer 1:1 plus an industry-standard handling margin of 30%.

5.4 Infrastructure Flat Rates & Service Level Agreements (SLA)
#

Our Managed IT prices always consist of two modules: the base infrastructure and the chosen SLA level (Service Level Agreement).

Module 1: Base Infrastructure (monthly)

  • Endpoints: €39.00 / PC or €29.00 / Mobile Device
  • Server (Bare-Metal): €99.00 / Server
  • Server (VM): €49.00 / VM
  • Container/Stacks: from €39.00 / Stack (user-based)
  • Network devices (NAS, Firewall, Router): €30.00 / Device

Module 2: SLA Surcharge (monthly) The chosen SLA regulates the guaranteed response times. It always applies to the entire IT environment and is added to the base infrastructure per managed device/container:

  • Standard SLA: + €0.00 per device (Response time usually next business day / Best-Effort).
  • Business SLA: + €39.00 per endpoint / + €99.00 per server/infrastructure (Guaranteed response time max. 4 hours during business hours, prioritized routing).
  • Enterprise SLA: Calculated individually upon request (Response time under 1 hour, highest priority, extended IT liability coverage).

5.5 Due Date & Default in Payment
#

Invoices are due immediately upon receipt without deduction. For continuing obligations (maintenance), billing occurs monthly in advance. If the customer defaults on payments for ongoing services (hosting/monitoring) for more than 2 months, we are entitled to temporarily suspend the service (blocking of access). This suspension will be announced to the customer in text form at least 7 working days in advance. The obligation to pay continues during the suspension. If the customer (business client / B2B) is in default of payment, we are entitled to claim default interest at the statutory rate as well as the statutory default flat rate of 40.00 € (Section 288 (5) of the German Civil Code / BGB).

5.6 Emergency Service, Off-Hours & Holiday Surcharges
#

Deployments outside regular business hours take place only by arrangement and availability. For assignments during off-hours (weekdays before 09:00 and after 17:00 as well as Fridays after 13:00) and on Saturdays, we charge a surcharge of 100% on the hourly rate. For manual deployments and support services rendered on Sundays or statutory public holidays (decisive are nationwide public holidays as well as the statutory holiday regulations of the Federal State of Lower Saxony), a holiday surcharge of 150% is calculated on the basic hourly rate.


6. Customer’s Obligations to Cooperate
#

The customer ensures:

  • required access rights, passwords, and information
  • functioning hardware and internet connection

Missing cooperation or waiting times due to unavailable systems or contact persons count as working time and will be billed.

6.1 Sensitive Data & Professional Confidentiality
#

The following applies to all customers: Please never send us unencrypted access data (passwords, server keys) via unsecured messenger services (such as WhatsApp or Telegram). Please only use our encrypted channels (e.g., PGP email or our secure password exchange) for this purpose.

If the customer is a professional who is bound by professional secrecy (e.g., doctors, lawyers, tax advisors), they are also solely responsible for not sending us any sensitive client or patient data in plain text when requesting support.

6.2 Unsolicited Submission & Packaging of Hardware
#

If the customer sends hardware to us without prior arrangement or approval, or drops it off unsolicited at our premises (e.g. leaving a parcel at the doorstep without personal handover), this automatically counts as the placement of a binding order for a chargeable system diagnosis and registration. For this, at least the regular minimum purchase (30 minutes) will be charged as a diagnostic flat rate. This applies even if a repair proves to be uneconomical or technically impossible. The customer bears the sole risk for damages or theft (e.g. when dropping items off at the door). To ensure safe return shipping, we are entitled to equip inadequately packaged devices with new, transport-safe packaging material (outer cartons/pack sets) at the customer’s expense and to pass on these costs.

6.3 Duty to Update Contact Details & Invoice Delivery
#

The customer is obliged to report any change in their personal or business contact details (in particular name/company, postal address, telephone number, mobile number, and e-mail address) immediately and without being asked.

This notification of change must strictly be made via the secure contact form provided on our website (n8n workflow). The customer is obliged to provide exclusively correct and truthful information.

If the customer fails to comply with this contractual obligation to update, and notifications or invoices cannot be delivered as a result, invoices and declarations shall nevertheless be deemed legally effective and validly delivered if they were sent to the e-mail address or postal address last provided to us by the customer.


7. Acceptance / Service Confirmation
#

After completion of an order, a performance or activity confirmation may take place. The signature serves exclusively for documentation purposes and has no influence on the obligation to pay.


8. Backup & Data Responsibility
#

(1) The customer is solely responsible for functioning data backups unless an explicit “Managed Backup Service” has been contractually agreed upon. We are not liable for data loss that could have been avoided by a simple restore from a recent backup.

(2) Central Storage (Hosting): If a Managed Backup Service is agreed upon, the customer expressly consents to the encrypted backup copies of their systems and user data being stored on the service provider’s central servers (or its certified European data centers). These data are protected against unauthorized access according to the latest state of the art and will be destroyed in compliance with data protection regulations after the termination of the contract.

(3) Data Sovereignty & Handover: The customer’s pure user data always remains their property. The customer can request the handover or deletion of their user data at any time. Any manual technical effort required for this (e.g., creation of database dumps) will be billed at the regular hourly rate. Infrastructure code and scripts belonging to the service provider are excluded from this.


9. Liability & Disclaimer
#

We shall be liable without limitation in cases of intent and gross negligence, as well as in cases of injury to life, limb, or health, or under the Product Liability Act.

In cases of slight negligence, we shall only be liable for breaches of essential contractual obligations (cardinal obligations) whose fulfillment is essential for the proper execution of the contract. In this case, liability shall be limited to the foreseeable damage typical for this type of contract.

Special exclusions of liability (IT security & updates):

  1. Updates: We are not liable for system failures, incompatibilities, data loss, or malfunctions caused by automatic updates from software manufacturers (“third-party risk”).
  2. Cyber security: Liability for damage caused by hacker attacks, ransomware, zero-day exploits, or similar cybercrime is excluded, provided that we have professionally implemented the commissioned protective measures in accordance with the current state of the art.

10. Remote maintenance, SSH & administrative access
#

(1) Definition of remote maintenance & access: Remote maintenance includes not only the graphical remote control of desktops, but also any administrative access to the customer’s IT systems or network infrastructure. This includes, in particular, SSH, web consoles, PowerShell Remote, and network interventions.

(2) Billing: Any active technical intervention in the systems is considered a chargeable service. Billing is based on time spent plus the remote maintenance flat rate in accordance with the valid price list.

(3) Technologies: We only use encrypted connection technologies (e.g., RustDesk via our own servers). The selection of suitable tools is the responsibility of the service provider.


11. Access Data, Administrator Rights & Exclusivity
#

11.1 Responsibility
#

The customer is responsible for the security of their own access data. We assume no liability for misuse, loss, or unauthorized sharing.

11.2 Administrative Sovereignty & Exclusivity
#

During the term of maintenance and monitoring contracts, the administrative sovereignty for the managed systems lies exclusively with us. The customer commits not to grant administrative access to competing IT service providers.

Co-Managed IT & Internal Administrators
#

If the customer has their own IT staff, they may be granted restricted administrative access (e.g., to graphical web interfaces such as TrueNAS or Nextcloud) by mutual agreement. Access to deeper infrastructure levels (e.g., SSH, root privileges, virtualization hosts, container management) remains strictly prohibited and reserved for the service provider to protect the GitOps architecture. The service provider assumes no liability and voids any SLA guarantees for system failures or data loss proven to be caused by incorrect interventions by the customer’s internal staff. In such cases, system restoration will be billed based on the actual time spent.

11.3 Disclaimer for Third-Party Access
#

If the customer nevertheless grants administrative intervention rights (‘Root Access’) to third parties or themselves, we assume no liability or warranty for system malfunctions, errors, or security vulnerabilities that can be proven to result from this third-party access. The rectification of such malfunctions will be billed separately on a time and material basis.

11.4 Handover of Admin Data
#

The handover of administrative access data created by us for the provision of services generally only takes place after termination of the contractual relationship and complete settlement of all outstanding claims.

11.5 Intellectual Property & Prohibition of Reverse Engineering (Contractual Penalty)
#

The customer expressly acknowledges that the automation scripts, playbooks, docker-compose files, and the architecture of the GitOps infrastructure used by the service provider constitute a substantial and protected trade secret of the service provider. The customer and any third parties commissioned by them (especially other IT service providers) are strictly prohibited from copying, reproducing, using for their own purposes outside this contract, extracting, or recreating these configurations and codes through reverse engineering.

For every case of culpable violation of this prohibition, the customer undertakes to pay a contractual penalty to the service provider. The amount of the contractual penalty will be determined by the service provider at their reasonable discretion and, in the event of a dispute, can be reviewed for its appropriateness by the competent court (so-called “Hamburger Brauch” / Hamburg Custom). The assertion of further claims for damages remains unaffected by this. This expressly also applies to “Custom Code” (individual programming) developed at the special request of the customer for an hourly wage, unless a different transfer of rights has been agreed upon in writing. The customer receives a simple right of use for these individual scripts and setups, which is tied to the contract.

11.6 Temporary Right of Use, Mandatory De-Boarding & Penalty for Refusal
#

The logical security architecture (overlay network, management agents, provided Docker containers, and scripts) is provided to the customer exclusively as an “As-a-Service” model for the duration of the contract. A transfer of ownership of these configurations does not take place. Upon termination of the contract, the right of use expires. The service provider is entitled and obligated to disconnect all connections and uninstall these specific software components on the customer’s systems (System Rollback/De-Boarding). The customer commits to tolerate this software rollback and to make it technically possible.

Contractual Penalty & Usage Fee: If the customer refuses the rollback or blocks it technically (e.g., by revoking administrative rights before the de-boarding is completed), they shall be liable for damages. For every case of culpable violation, a contractual penalty according to the Hamburg Custom (“Hamburger Brauch”) becomes due. Additionally, for each started month of unauthorized continued use of the infrastructure configurations, a flat-rate compensation equal to the previous total monthly invoice amount (infrastructure flat rate plus SLA) will be charged.


12. Subcontractors & Data Processing
#

We use qualified subcontractors to provide our services. The customer expressly agrees to the use of the following infrastructure partners:

  • Hetzner Online GmbH (Renting of external B2B customer hosting resources/VPS at the customer’s request)
  • AWS (E-Mail Delivery for automated system messages)
  • Cloudflare (DNS, DDoS Protection, Security for web interfaces)
  • Netlify & GitHub (Web Hosting of the static main presence, Code Management)
  • Proton AG (Secure E-Mail Communication)
  • Google Ireland Ltd. (Gemini AI for anonymized error analysis)
  • Plausible Analytics (Privacy-friendly Web Analytics)
  • Stripe (Payment processing for Online Shop)

Note: Our proprietary core systems (Online Shop, Nextcloud for file sharing, and the n8n automation framework) are operated entirely as self-hosted instances on our own local hardware.

The exact details on the processing of personal data by these service providers are regulated in our Privacy Policy.


13. Confidentiality
#

Both parties commit to not disclosing confidential information to unauthorized third parties.


14. Right of Withdrawal (Consumers Only)
#

Private consumers have a statutory right of withdrawal of 14 days. The right of withdrawal expires prematurely if we have fully performed the service at the explicit request of the customer before the expiry of the withdrawal period.


15. Contract Duration & Termination
#

  1. General Services: Cancellable at any time; remuneration is due up to the point of termination.
  2. Maintenance & Monitoring Contracts (Business Customers / B2B): To ensure maximum flexibility, these contracts are concluded for an indefinite period. Unless otherwise specified in the individual contract, they can be terminated by either party with a notice period of 30 days to the end of the respective calendar month in text form.
  3. Maintenance & Monitoring Contracts (Private Consumers / B2C): Statutory regulations apply. After the expiry of an agreed minimum term, the contract is extended for an indefinite period and can be canceled at any time with a notice period of one month.

16. Force Majeure
#

No liability for events beyond our control (e.g., power outages, internet disruptions, natural disasters).


17. Jurisdiction & Applicable Law
#

German law applies. Place of jurisdiction for merchants, legal entities under public law, or special funds under public law is the competent court for our business seat (District Court Uelzen / Regional Court Lüneburg), as far as legally permissible.


18. Changes to the GTC, Service Descriptions & Prices
#

We reserve the right to adapt these GTC, the Service & Support Conditions, our Privacy Policy, and our pricing structures at any time to reflect legal, technical, or economic developments.

The amended conditions will be sent to the customer via e-mail (text form) at least four weeks before they are scheduled to take effect. If the customer does not object to the validity of the new conditions within 30 days of receiving the e-mail, the amended conditions shall be deemed legally accepted (fictitious consent). We will explicitly inform the customer in the notification of change about the significance of this period and the legal consequences of remaining silent.

Consequence of Objection (Automatic De-Boarding): If the customer objects in due time, a continuation of the managed IT infrastructure under outdated framework conditions is excluded for security and administration reasons. In this case, the objection automatically counts as an extraordinary termination of the contract at the time the changes are scheduled to take effect. In this event, the mandatory rollback and de-boarding obligations according to § 11.6 of these GTC shall apply immediately.


19. Software Licenses & Third Parties
#

Software licenses, subscriptions, or paid trial versions from third-party providers (e.g., Microsoft, cloud services) are not part of our services. Procurement, payment, and lawful use are the sole responsibility of the customer.


20. Hardware Sales & System Delivery (Purchase Contract)
#

20.1 General
#

If the service provider sells hardware, this constitutes a purchase contract (Sections 433 ff. of the German Civil Code / BGB). We owe the handover in functional condition.

20.2 Warranty & Guarantee
#

  • Consumers (B2C): 24 months warranty.
  • Business Clients (B2B): 12 months warranty. We only mediate manufacturer guarantees. Claims arising from these must be asserted directly against the manufacturer.

20.3 Returns & Retention of Title
#

There is no general right of return for business clients. The goods remain our property until full payment has been made. The installation of the hardware is billed separately as a service.


21. Special Conditions for the Online Shop (shop.xenoelectronics.com)
#

For orders of hardware, software, and digital goods via our WooCommerce shop at shop.xenoelectronics.com, the following conditions apply additionally:

21.1 Conclusion of Contract in the Shop
#

  1. The presentation of goods in the shop does not constitute a legally binding offer but a non-binding online catalog.
  2. By clicking the button “Order with obligation to pay” (or “Buy”), you place a binding order for the goods contained in the shopping cart.
  3. A purchase contract is only concluded when we accept your order by sending a separate order confirmation via e-mail or by delivering the goods to you.

21.2 Prices, Shipping & Delivery
#

  1. The prices displayed in the shop at the time of the order apply.
  2. Shipping costs are clearly displayed during the ordering process.
  3. Delivery Area: Delivery takes place exclusively to countries of the European Union (EU).

21.3 Payment via Stripe
#

We use the payment service provider Stripe (Credit Card, Apple Pay, Google Pay, SEPA, etc.). By selecting the payment method, you authorize Stripe to collect the due amount.


22. Hosting & Cloud Services
#

If we provide Managed Hosting:

  1. Availability: We guarantee the availability guaranteed to us by the respective upstream provider (e.g., Hetzner).
  2. Contents: The customer is solely liable for their uploaded content.
  3. Domains: We only act as an intermediary for registration. No guarantee for the allocation.

23. Final Provisions (Severability Clause)
#

If individual provisions of this contract are invalid, the validity of the remaining provisions of the contract shall remain unaffected.


24. Use of Artificial Intelligence (AI)
#

The service provider is entitled to use AI-supported systems (e.g., Google Gemini, GitHub Copilot) to optimize workflows or for error analysis. It is ensured that no confidential business secrets or sensitive personal data of the customer are fed into public AI models for training, unless otherwise agreed.


25. Contact
#

E-Mail: info@xenoelectronics.com

Legal Notice / Impressum Privacy Policy Service & Support


Disclaimer regarding the English translation: This English translation of our Terms and Conditions / Privacy Policy / Service Agreements is provided solely for your convenience and informational purposes. In the event of any discrepancies, conflicts, or contradictions between this translated version and the original German document, the original German version shall be exclusively legally binding and shall prevail in all cases.