As of: October 2026
(1) These T&C apply to all contracts between Taglauer und Künnecke GbR, ©r2studio, Werkstrasse 10, 85614 Kirchseeon, Germany (hereinafter "Provider") and its customers for the use of the ReachOS software platform (hereinafter "ReachOS" or "Platform"). ReachOS is a product of ©r2studio.
(2) The offer is directed exclusively at businesses within the meaning of Section 14 BGB (German Civil Code), legal entities under public law and special funds under public law. Consumers are excluded from use.
(3) Deviating or supplementary terms and conditions of the customer do not become part of the contract, even if the Provider does not expressly object to them.
(1) ReachOS is a web-based platform for analyzing and optimizing the visibility of brands, websites and content in AI-powered answer systems and search engines (Answer Engine Optimization, Generative Engine Optimization). The exact scope of functions results from the respective offer or service description at [website / offer].
(2) The Provider makes ReachOS available as software as a service over the internet. The software is not provided for installation on the customer's systems.
(3) The Provider may further develop and adapt its services, provided the contractually agreed core benefit for the customer is not materially impaired.
(4) Consulting, concept and implementation services by ©r2studio (e.g. branding, Webflow, Shopify) are not subject matter of these T&C and are agreed separately.
(1) The presentation of the Platform on the website is not a binding offer. The contract is concluded when the Provider accepts the customer's offer in text form or activates access.
(2) A user account is required for use. The customer is obliged to provide complete and correct information during registration and to keep it up to date.
(3) Access credentials must be kept secret and protected from access by third parties. The customer is liable for all actions carried out under their account, unless they are not responsible for the misuse. The Provider must be informed immediately of any suspected misuse.
(1) For the duration of the contract, the Provider grants the customer a non-exclusive, non-transferable, non-sublicensable right to use ReachOS to the agreed extent for its own business purposes.
(2) The customer is not permitted to copy, decompile or reverse engineer the Platform or to make it available to third parties, whether for a fee or free of charge, unless mandatorily permitted by law. Automated mass queries outside the agreed interfaces and circumvention of technical protection measures and usage limits are likewise prohibited.
(3) All rights to ReachOS, the brand, the source code, methods, scoring models and evaluation formats remain with the Provider.
(4) Content and data entered by the customer (e.g. domains, brand names, texts, search terms) remain with the customer. The customer grants the Provider the non-exclusive right to process this content to the extent necessary to provide the services.
(1) The customer ensures that it is entitled to use the domains, brands and content it enters and that their processing does not infringe the rights of third parties.
(2) The customer uses ReachOS only within the framework of applicable law. In particular, use for the dissemination of unlawful content, for the infringement of third-party rights or for impairing the Platform or the third-party systems used is prohibited.
(3) The customer is itself responsible for backing up its data, unless the Provider expressly owes data backup.
(1) Fees are determined by the agreed plan or offer. All prices are net plus statutory value added tax. [Add pricing model, billing period and currency]
(2) Invoices are issued electronically and are due for payment without deduction within [14] days. In the event of late payment, statutory default interest applies. In the event of late payment, the Provider may block access after prior notice in text form.
(3) The Provider may adjust prices with at least [six weeks'] notice in text form, effective at the start of the next billing period. In this case the customer may terminate extraordinarily as of the date the change takes effect.
(1) The contract term and notice periods result from the offer. Unless otherwise agreed, the contract runs for an indefinite period and may be terminated with [one month's] notice to the end of the respective billing period. [Add term model]
(2) The right to extraordinary termination for good cause remains unaffected.
(3) Termination requires text form.
(4) After the end of the contract, the customer may export its data for [30] days. Thereafter the Provider deletes the data, unless statutory retention obligations prevent this.
(1) The Provider owes an average availability of the Platform of [99%] on an annual average. Excluded are times for maintenance, disruptions outside the Provider's sphere of influence (e.g. outages of infrastructure or AI providers, force majeure) and times in which third parties unlawfully impair the Platform.
(2) Planned maintenance work will, where possible, be announced in advance and carried out outside normal business hours.
(1) ReachOS evaluates answers and sources of external AI systems and search engines. These systems are operated by third parties, change continuously and deliver non-reproducible results. The Provider has no influence on the content, behavior and availability of these systems.
(2) Analyses, scores, recommendations and generated content are snapshots. The Provider does not guarantee that recommendations will lead to a particular mention, placement, visibility or increase in revenue.
(3) Content generated by the Platform may be incorrect or incomplete. The customer reviews it on its own responsibility before publication or use.
(1) For defects in the Platform, the statutory provisions of German tenancy law apply, unless otherwise provided below. Strict liability for defects existing at the time of conclusion of the contract under Section 536a (1) BGB is excluded.
(2) The customer reports defects without delay and as comprehensibly as possible in text form to hallo@r2studio.de.
(1) The Provider is liable without limitation in cases of intent and gross negligence, for injury to life, body or health, under the German Product Liability Act and to the extent of an expressly assumed guarantee.
(2) In the event of slightly negligent breach of essential contractual obligations (obligations whose fulfilment is a prerequisite for the proper performance of the contract and on whose observance the customer may regularly rely), liability is limited to the foreseeable damage typical for this type of contract. This liability is capped in amount at [the fees paid in the last twelve months].
(3) Otherwise, liability for slight negligence is excluded.
(4) Liability for loss of data is limited to the typical restoration effort that would have arisen had the customer made regular backups appropriate to the risk.
(5) The above provisions also apply for the benefit of the Provider's employees, partners and vicarious agents.
(1) Both parties comply with applicable data protection regulations, in particular the GDPR. Information on the processing of personal data on the website is contained in the privacy policy.
(2) If the Provider processes personal data on behalf of the customer within the Platform, the customer is the controller and the Provider is the processor within the meaning of Art. 28 GDPR. In this case the data processing agreement in Annex 1 applies, which forms part of these T&C.
(3) The customer is responsible for ensuring that a legal basis exists for the processing it initiates and that data subjects are properly informed.
(1) The parties treat all non-public information of the other party that becomes known to them in the course of performing the contract as confidential and use it only to perform the contract.
(2) The obligation does not apply to information that is publicly known, was already lawfully known to the receiving party, was independently developed or lawfully obtained from third parties, or must be disclosed due to a legal or official order.
(3) The obligation continues after the end of the contract.
The Provider may amend these T&C with effect for the future if this is necessary for a compelling reason (e.g. changes in law, changes to the services) and the customer is not unreasonably disadvantaged. Amendments will be communicated in text form at least [six weeks] before they take effect. They are deemed approved if the customer does not object in text form within this period. This consequence will be pointed out separately in the notice. In the event of an objection, both parties have the right to terminate as of the date the amendment takes effect.
(1) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
(2) The exclusive place of jurisdiction for all disputes arising from or in connection with this contract is [Munich / registered office of the Provider], insofar as legally permissible.
(3) Should individual provisions be or become invalid, the validity of the remaining provisions remains unaffected.
(4) Amendments and additions require text form. This also applies to the amendment of this clause.
This agreement applies insofar as the Provider (processor) processes personal data on behalf of the customer (controller).
(1) The subject matter is the processing of personal data in the course of providing ReachOS in accordance with the main contract and T&C.
(2) The duration corresponds to the term of the main contract.
(1) Nature and purpose: hosting, storage, evaluation and provision of the domains, content and analysis results stored by customers, as well as user and account management. [adapt to actual functions]
(2) Data categories: master data (name, company, email), usage and log data (IP address, timestamps, device information), content entered by the customer insofar as it relates to individuals. [add]
(3) Categories of data subjects: employees and users of the customer, contact persons of the customer and, where applicable, persons named in the content entered by the customer. [add]
(1) The Provider processes personal data only on documented instructions from the customer, unless required to do otherwise by Union or Member State law. The main contract, this agreement and the customer's use of the Platform constitute instructions.
(2) If the Provider considers an instruction to be unlawful, it informs the customer without delay. It may suspend execution until the instruction is confirmed or amended.
(1) The Provider obliges all persons authorized to process data to maintain confidentiality.
(2) The Provider implements the technical and organizational measures described in Annex 2 pursuant to Art. 32 GDPR.
(3) The Provider reasonably supports the customer in responding to data subject requests, in complying with the obligations under Art. 32 to 36 GDPR and in data protection impact assessments.
(4) The Provider reports personal data breaches to the customer without undue delay, as a rule within [48] hours of becoming aware.
(1) The customer grants general authorization for the use of sub-processors. At the time of conclusion of the contract, the sub-processors listed in Annex 3 are authorized, including Webflow, Inc. (hosting) and Cloudflare, Inc. (CDN, DNS, security).
(2) The Provider informs the customer in text form at least [14] days in advance of intended changes. The customer may object in text form within this period for an important data protection reason. If no agreement is reached, both parties have a special right of termination.
(3) The Provider concludes a contract with each sub-processor that imposes essentially the same data protection obligations on it as this agreement. The Provider is liable for their fulfilment of obligations in accordance with Art. 28(4) GDPR.
Some sub-processors, in particular Cloudflare, Inc. and Webflow, Inc., are based in the USA. The transfer takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework, insofar as the provider is certified, and additionally on the basis of standard contractual clauses pursuant to Art. 46 GDPR. The Provider reviews these bases regularly.
Upon request, the Provider provides the customer with the information necessary to demonstrate compliance with this agreement. The customer may carry out or have carried out audits, including on site, with reasonable advance notice and during normal business hours. The Provider may demand reasonable remuneration for this, insofar as the effort is not insignificant.
After the end of the contract, the Provider deletes all personal data of the customer or returns it on request, unless a statutory retention obligation exists. Deletion takes place within [30] days after the end of the contract, backups at the latest after [90] days.
Art. 82 GDPR applies to liability. As between the parties, § 11 of the T&C applies, insofar as legally permissible.
[To be completed by the Provider, e.g.: physical access, system access and data access control, encryption (TLS, encryption of data at rest), pseudonymization, separation control, logging, backup and recovery concept, incident response process, regular review, employee commitment.]
Webflow, Inc.
398 11th Street, 2nd Floor, San Francisco, CA 94103, USA
Service: hosting of the website and, where applicable, CMS and forms
Data categories: IP address, usage and form data
Third country: USA (DPF / standard contractual clauses)
Cloudflare, Inc.
101 Townsend St., San Francisco, CA 94107, USA
Service: CDN, DNS, protection against attacks and bots (WAF), where applicable Workers, database and object storage [add Cloudflare products used]
Data categories: IP address, request data, security features, where applicable stored application data
Third country: USA (DPF / standard contractual clauses)
Find out in 30 seconds whether AI assistants can see you at all.