Terms of Service

1. General Clauses and Scope of the Terms of Service

1.1 These Terms of Service (" Terms ") govern your access and use of our products and services ("Services") on our website research.iot-inspector.com. The Services are hosted and provided by IoT Inspector GmbH, Germany.

1.2 Any reference to a) " you" or " your" means you as user of the Services, any reference to "we”, "us", "our" or "IoT Inspector" is to IoT Inspector GmbH; b) "Website" means the website research.iot-inspector.com; c) "Software" means any Software, Application Computer Program (including any information, text, graphics, URLs, files, audio, video, photos, or other materials) uploaded for inspection to the Services; d) "inspect" means any testing, review, analysis, measurement, description, review, reporting, or other procedure performed in connection with the Services; e) "IoT Inspector report" means a written document created by the Services in which we may address certain security issues and/or recommendations.

1.3 These Terms of Service shall apply exclusively in its latest version as published on our website. You accept the Terms by accepting them during the registration process and using and/or accessing our Services. By using and/or accessing our Services you agree that you have read, understood and consent to be bound by these Terms.

1.4 Any deviating Terms and Conditions of the customer are hereby expressly rejected.

2. Use of the Services

2.1 IoT Inspector conducts comprehensive security research in the area of IoT to discover vulnerabilities and vulnerability patterns within IoT devices to further enhance automated identification and allow for scalable detection within IoT Inspector, a cloud-based platform for automated security analysis and compliance checks of IoT firmware. Purpose of securing the Internet of Things is for vendors to fix existing vulnerabilities, but also for users of affected de-vices to become aware of security issues and apply latest security patches. IoT Inspector offers you the possibility to upload firmware of IoT devices in order to detect vulnerabilities within the firmware. After analysis of the Software an IoT Inspector report is provided, which can be accessed online or may be downloaded in various formats.

2.2 In order to use the Services, you must be at least eighteen (18) years old and able to enter contracts. To use the Services, you must complete the registration process including agreeing to these Terms and you must provide and maintain true, complete and up to date contact in-formation for as long as you use the Services. Further, in order to use the services, you must use or enable the use of the latest browser technologies. If older technologies are used, you may not be able to use the services to their full extent. The firmware-analysis works best with Linux-based IoT systems.

2.3 Unless otherwise specified, these Services are free of charge, but you are responsible for all Internet fees, and other fees and taxes associated with your use of the Services.

2.4 Any use of the Services as a whole or in parts for any commercial purposes (e.g., using the Service to re-offer it to third parties) such as re-offering the Services or results of the Services to third parties is prohibited. You will use the Services for your own personal use, you will not sell, resell, lease, license, recreate, modify, or reverse engineer in any manner whatsoever the Services or attempt to do so.

2.5 To use the Services, you must register. When you register for the Services, we will create an account for you. Your account is personal to you and must not be used by, assigned, or transferred to anyone else. Your account may not be sold, leased, licensed, or assigned.

2.6 By registering as user, you confirm that you are only using the Service in personal capacities.

2.7 For the registration, your contact details are required, such as your name, address and email address. Additional information may be required to use certain functionalities of the Service.

2.8 A license key is only issued after successful registration. The license key is required to create a user account. To create a user account an activation email is sent to the registered email address. After confirmation of the activation email, the account is active, and you may use the Services.

2.9 Any access or use of the Website or the Services in any automated form (e.g., spiders, bots/robots, scrapers) is prohibited. Any use of any information collected in such way constitutes a violation of this Terms.

2.10 You must follow all policies made available to you within the Services. You also agree to use the Services only for lawful purposes, in a manner that is not expressly prohibited by these Terms, and in a manner that does not infringe the rights or interests of IoT Inspector or third parties; to abstain from any activity that could damage, overload, harm or impede the normal functioning of the Services.

2.11 We may, from time to time, at our sole discretion, add or remove parts or products to / from the Services. We may refuse service, close accounts and change requirements for use at any time. We may suspend or terminate the Services at any time, with or without cause, in our discretion.

2.12 Browsing the Website or using the Services may contravene local laws. The usage of the Internet or certain services may be restricted in your territory. In any case, you should take into account the legal situation applying to your circumstances when using the Service. It is your responsibility to use the Services and Website in compliance with any local laws, which may apply to your location. We are not promoting and are not responsible for your non-compliance or compliance with such laws, and any consequences of your compliance or non-compliance with such laws including death, injury and property damage.

2.13 Our Services are not intended for distribution to or use in any country or territory where such distribution or use would violate local law or would subject us to any regulations in another country or territory. We reserve the right to limit our Services in any country or territory.

2.14 You will comply with all applicable export control and trade sanctions laws (“Export Laws”). You will not, directly or indirectly, export, re-export, provide, or otherwise transfer our Services (i) to any individual, entity, territory, or country prohibited by Export Laws, (ii) to anyone on government restricted parties lists or (iii) for any purpose prohibited by Export Laws, including nuclear, chemical, or biological weapons, or missile technologies applications without the re-quired government authorizations. You will not use our Services if you are located in a restrict-ed country or territory, if you are currently listed on a restricted parties list, or for any purpose prohibited by Export Laws, and you will not disguise your location through IP proxying or other methods.

3. Responsibility for the Software

3.1 You hereby grant IoT Inspector the necessary permission to inspect the Software and grant IoT Inspector the right to upload, copy and run the Software into the Services for this purpose.

3.2 The rights are granted worldwide and in terms of time and content in accordance with the purpose of the Services and within the scope of the statutory requirements.

3.3 You confirm that you are the original owner of Software or that you have the necessary rights, title and permissions to authorize us to upload, copy and run the Software for the purpose of the Services provided by IoT Inspector. You warrant and guarantee that you are entitled to use and upload the Software to the Services.

3.4 You agree to give us evidence of all such rights and permissions if so requested by us. Therefore, you are obliged to provide all details and information correctly and completely with regard to legal obligations concerning upload of the Software (e.g., Copyright Act, Company Code, Trade Regulation Act, Unfair Competition Act, Trademark Protection Act, etc.).

3.5 You shall indemnify and hold IoT Inspector harmless from and against any and all breaches of law and third-party claims caused by the violation of their rights and titles by making use of the Software through IoT Inspector in accordance with this terms and conditions in order to provide the Services and you shall reimburse IoT Inspector for all costs of reasonable legal defense, including, without limitation, lawyers' fees, court fees, and costs of experts.

3.6 IoT Inspector is not obliged to verify your rights for uploading the Software. IoT Inspector also does not examine the accuracy and completeness of the information you give.

3.7 If you do not want the Software provided by you to the Services to be disclosed in the manner set out in these Terms or in the Privacy Policy, do not send it/share it with us.

3.8 IoT Inspector reserves the right to refuse, remove, or delete the Software at any time without prior notice and at our sole discretion.

3.9 Providing the Services under these Terms by IoT Inspector does not release you from your own auditing obligations or your own contractual and any legal obligations.

4. Contract duration and Termination / Right to cancel

4.1 The term of the contractual relationship between you and IoT Inspector shall start with successful registration / confirmation of the activation mail according to Section 2.8 of an account on the Website for an unlimited duration of time.

4.2 You may terminate your contractual relationship with IoT Inspector anytime for any reason by deleting your account. We may modify, suspend, or terminate your access to or use of our Services anytime for any reason such as (but not limited to) if you violate these Terms of Ser-vice, if you create harm, risk or possible legal exposure for us, our users or others. We may also disable or delete your account if it does not become active after account registration or if it remains inactive for an extended period of time. The following provisions will survive any termination of your relationship with IoT Inspector: “Confidentiality”, “Proprietary Rights”, “Exclusion of Warranty”, “Limitation of Liability”, “Jurisdiction and Governing Law; Place of Performance” and “Final Clauses”.

4.3 Right to cancel: Notwithstanding Section 4.2, if you are a consumer (acting for purposes with are mainly outside your trade, business, craft or profession), you have the right to cancel the contractual relationship for the Services within 14 days without giving any reason. The cancellation period will expire after 14 days from the day of the conclusion of the contract. To exercise the right to cancel, you must inform:

IoT Inspector GmbH, Tannenwaldallee 2, 61348 Bad Homburg, Germany, or by e-mail sup-port@iot-inspector.com of your decision to cancel the contract by a clear statement (e.g., a letter sent by post or email). You may use the below model cancellation form, but it is not obligatory. To meet the cancellation deadline, it is sufficient for you to send your communication concerning your exercise of the right to cancel before the cancellation period has expired.

Model cancellation form:

To IoT Inspector GmbH Tannenwaldallee 2 61348 Bad Homburg, Germany

or by e-mail: office@iot-inspector.com

I hereby give notice to cancel my contract of the supply of the following Services:

IoT Inspector (free of charge version)

Name of Consumer: Registered E-Mail Address of Consumer: Address:

Signature:

If you cancel the contract, your account will be deleted, and you will no longer be able to use the Services.

The sending of the activation mail according to Section 2.8 in order for you to confirm the account shall be deemed as execution of the performance (Services). With the active registration (Section 2.8) you declare your explicit request for early performance prior to the expiry of the withdrawal period.

You hereby acknowledge and expressly agree that with the initial registration (confirmation of the activation email), the performance of our Services takes place before the expiry of the withdrawal period. Thus, this shall not be deemed as a loss of the right of withdrawal.

5. Passwords and Personal Keys / Credentials

You are responsible for safeguarding any password/keys/credentials used to access the Services and for any activities or actions under these credentials. We recommend the use of "strong" passwords (passwords that use a combination of upper and lower-case letters, numbers, and symbols). IoT Inspector cannot and will not be liable for any loss or damage arising from your failure to comply with this guidance.

You are responsible for your use of the Website and the Services and any activity under your account, whether or not you authorized it. If you become aware of any unauthorized use of your account, you will immediately notify us. We are not responsible for any claims, losses or other proceedings relating to shared, stolen or hacked passwords or accounts.

6. Privacy

Our Privacy Policy can be accessed under www.iot-inspector.com/privacy-policy and explains how we meet the requirements of the GDPR and BDSG and treat your personal data and protect your privacy when you use our Services as may be amended by us from time to time. The information to be provided according to Art. 13 GDPR are accessible on our Website and will be displayed during the registration process.

7. Legal Use / Confidentiality / Responsible Disclosure

7.1 You must access and use the Services only for legal, authorized and acceptable purposes. You will not use (or assist others in using) the Services in ways that (i) violate, misappropriate or infringe the rights of IoT Inspector, our users, or others (e.g., Vendors of the Software), including privacy, publicity, intellectual property or other proprietary rights; (ii) are illegal, defamatory, threatening, intimidating, harassing or ethnically offensive, or instigate or encourage con-duct that would be illegal or otherwise inappropriate or (iii) involve any non-personal use of our Services.

7.2 You must not (or assist others to) directly, indirectly, through automated or other means, access, use, copy, adapt, modify, prepare derivative works based upon, distribute, license, sublicense, transfer or otherwise exploit the Services in impermissible or unauthorized manners, or in ways that burden, impair or harm IoT Inspector, the Services, our users, or others (e.g. Vendors of the Software or users of the Software), including that you must not directly or through automated means: (i) reverse engineer, alter, modify, create derivative works from, decompile, or extract code from the Services, (ii) send, store or transmit viruses or other harmful computer code through or onto the Services, (iii) gain or attempt to gain unauthorized access to the Services or the Software, (iv) interfere with or disrupt the safety, security, confidentiality, availability or performance of our Services, (v) sell, resell, rent or charge for our Services or data obtained from us or the Services in an unauthorized manner, (vi) create software that function substantially the same as the Services and offer them for use by third parties in an unauthorized manner.

7.3 The content of the IoT Inspector report and any other results of the inspections are strictly confidential. It is not allowed for you to disclose the IoT Inspector report and/or its results to any third parties in whatsoever kind except with the Vendor of the Software in order to responsibly disclose relevant information to the Vendor of the affected Software/IoT device or to publish the IoT Inspector report or these results or to otherwise make them accessible to the public – except with the prior written consent of IoT Inspector. In any case of permitted disclosure of the IoT Inspector reports or any of its results or any other results of the inspections according to this Section 7.3 (e.g., as part of an academic research or as part of providing relevant information to the Vendor of the affected Software) you must in any case make reference to IoT Inspector (e.g. “Research conducted with support of IoT Inspector”).

7.4 IoT Inspector is allowed to use the data from the IoT Inspector report and any other results of the inspections (e.g., identified vulnerabilities of the Software) especially in order to collect in-formation for evaluating and analyzing IoT firmware for its own research activities, to perform statistical evaluations and to improve its services. IoT Inspector will respect the confidentiality of analyses conducted via the Services and will not publicly release any vulnerabilities identified via the Services. Nonetheless we are entitled to disclose the results of the inspections (e.g., vulnerabilities of the Software) identified by the analysis via the Services to the Vendor of the Software in order to responsibly disclose relevant information to the Vendor of the affected Software/IoT device. We herewith take reference to our Responsible Disclosure Policy (https://www.iot-inspector.com/responsible-disclosure-policy/).

8. Proprietary Rights

8.1 ALL CONTENT OF THE SERVICES IS PROTECTED BY COPYRIGHT. The Website and the Services, including service names, and all content and elements of the Website and the Ser-vices, including any and all graphics, logos, content, images, files, text, layout and designs are the registered and unregistered property of IoT Inspector, our licensors or other applicable third parties. EXCEPT AS SPECIFICALLY PERMITTED HEREIN, NO INFORMATION INCLUDED IN THE SERVICES MAY BE REPRODUCED IN ANY FORM, OR BY ANY MEANS NEITHER IN WHOLE NOR IN PARTS, COMMERCIALLY EXPLOITED WITHOUT PRIOR WRITTEN PERMISSION FROM IOT INSPECTOR.

8.2 All rights, title, and interest in and to the Services (excluding third party brand names) are and will remain the exclusive property of IoT Inspector and its licensors. Nothing in these Terms should be construed as conferring by implication or otherwise any license or right under any copyright, patent, trademark, database right, sui generis right or other intellectual property or proprietary interest of IoT Inspector, its licensors or any third party. Neither these Terms nor use of the Services or the Website grants you ownership or any other interests in the Services or the Website or its contents. You will not use, interfere with, or attempt to gain access to the Website and the Services in any manner whatsoever other than as provided for in the Terms, including using methods or tools to data mine or scrape information from the Website and/or the Services.

8.3 Additionally, nothing in the Terms gives you a right to use IoT Inspector trademarks, logos, domain names, and other distinctive brand features.

9. Exclusion of Warranty

9.1 Your access to and use of the Services is at your own risk. You understand and agree that the Services are provided to you on an "AS IS" and "AS AVAILABLE" basis.

9.2 Without limiting the foregoing, IOT INSPECTOR AND ITS AFFILIATES, AGENTS, PARTNERS, AND SUBSIDIARIES DISCLAIM ANY WARRANTIES, EXPRESSED OR IMPLIED, OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE.

9.3 YOU EXPRESSLY AGREE THAT USE OF THE SERVICES IS AT YOUR SOLE RISK. NEITHER IOT INSPECTOR, ITS SUBSIDIARIES, ITS AFFILIATES, NOR ANY OF THEIR EMPLOYEES, AGENTS, OR LICENSORS WARRANT ACCORING THE SERVICES.

9.4 NOR DO THEY MAKE ANY WARRANTY AS TO THE RESULTS THAT MAY BE OBTAINED FROM USE OF THE SERVICE, OR AS TO THE ACCURACY, RELIABILITY, OR CONTENT OF ANY INFORMATION, PRODUCT, OR SERVICE PROVIDED THROUGH THE SERVICES.

9.5 The inspections are at general state of the art at the time they are carried out. However, IoT Inspector does not guarantee the faultless result of the inspections nor does a vulnerability imply a general security risk.

9.6 According to the current state of technology, it is not possible to program Software or an Internet platform that is 100 percent error-free and to guarantee that the Service addresses all Software issues.

9.7 Also, it is not possible to guarantee that our website iot-inspector.com can be operated without interruption or error at any time (e.g. for maintenance and the installation of updates, other interruptions of access).

9.8 Furthermore, it is not possible to guarantee that the Services are compatible to inspect all kinds of Software and that all Services are completely accessible and error-free at all times.

9.9 You also agree that IoT Inspector has no responsibility or liability for the deletion of, or the failure to store or to transmit, any Software or other content and other communications maintained by the Services.

10. Limitation of Liability

10.1 Unless otherwise stipulated, IOT INSPECTOR AND ITS DIRECTORS, SUBSIDIARIES, AFFILIATES, OFFICERS, EMPLOYEES, AGENTS, PARTNERS, AND LICENSORS AND LICENSEES WILL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING WITHOUT LIMITATION, LOSS OF PROFITS, DATA, USE, GOODWILL, OR OTHER LOSSES, RESULTING FROM a) YOUR ACCESS TO OR USE OF OR INABILITY TO ACCESS OR USE THE SERVICES; b) ANY CONDUCT OR CONTENT OF ANY THIRD PARTY, INCLUDING WITHOUT LIMITATION, ANY DEFAMATORY, OFFENSIVE, OR ILLEGAL CONDUCT OF OTHER USERS OR THIRD PARTIES; AND c) ANY UNAUTHORISED ACCESS, USE, OR ALTERATION OF YOUR TRANSMISSIONS OR CONTENT WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), OR ANY OTHER LEGAL THEORY, WHETHER OR NOT WE HAVE BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE.

10.2 The IoT Inspector report is not all-encompassing and 100% comprehensive. It is therefore possible that there may be software issues and problems that are not addressed in the report.

10.3 In no event will we be responsible for the information contained in the IoT Inspector report and the addressed issues, their practices, or for your use of the IoT Inspector report or the Software.

10.4 We recommend that you review the information provided by the IoT Inspector report (such as, but not limited to, the Software issues and recommendations). We do not review, approve, monitor, endorse, warrant, or make any representations with respect to the functionality or security of the Software.

10.5 You expressly relieve us from any and all liability arising from your use of the IoT Inspector report and the Software. We encourage you to be aware when you read the IoT Inspector re-port and decide whether you continue use the Software or if you decide for a replacement.

10.6 IoT Inspector shall be liable without limitation only in the event of intent or gross negligence for damage caused by IoT Inspector or their legal representatives or vicarious agents.

10.7 In case of slight negligence, IoT Inspector shall be liable without limitation in case of injury to life, body, or health.

10.8 Apart from this, IoT Inspector shall only be liable to the extent that it has breached a material contractual obligation (cardinal obligation). In these cases, liability shall be limited to compensation for foreseeable, typically occurring damage but not more than five times the fee for the service.

10.9 Liability under the Product Liability Act shall remain unaffected.

10.10 IoT Inspector shall not be liable for any damages caused by force majeure.

10.11 The liability and obligations of IoT Inspector in the case of termination of the platform for whatever reason shall be limited to the reimbursement of access fees pro rata temporis.

11. Waiver

The failure of IoT Inspector to exercise or enforce any right or provision of this Terms shall not constitute a waiver of such right or provision.

12. Jurisdiction and Governing Law; Place of Performance

12.1 Any contractual relationship and all disputes between you and IoT Inspector shall be subject to German law.

12.2 The place of jurisdiction is agreed the court having subject matter jurisdiction for Frankfurt am Main, Germany; if you are not seated within the European Union (EU) or not within a state that is member of the Lugano Convention (Convention on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters), all disputes shall be finally settled in accordance with the Rules of Arbitration of the International Chamber of Commerce (ICC) by one or more arbitrators appointed in accordance with the said Rules; the place of arbitration shall be Berlin, Germany.

12.3 IoT Inspector shall also be entitled to pursue any claim before the courts of law competent for the defendant's domicile or general residence.

12.4 The place of performance of any duties and obligations for both your and IoT Inspector sides shall be Frankfurt am Main, Germany.

12.5 According to applicable law we are obliged to inform you as follows: The European Commission provides a platform for online dispute settlement between entrepreneurs and consumers; the platform can be found at: https://ec.europa.eu/consumers/odr. This information shall not be deemed as an obligation or acceptance to take part in any kind of dispute settlement.

You may also send complaints directly to us under: support@iot-inspector.com].

13. Final Clauses

13.1 Amendments. Please note that we may update and amend these Terms from time to time, particularly if the service provided is extended or changes in legislation so require. Any changes will be posted on the website. The current version of the General Terms and Conditions is available under research.iot-inspector.com/tos. By continuing to access the Services after any changes become effective, you agree to be bound by the revised Terms of Service. If you do not want to agree to any changes made to the Terms of Service, you should stop using the Website and/or Service.

13.2 Changes. Changes and/or additions to the contractual relationship between you and IoT Inspector must be made in writing (confirmed e-mail correspondence is sufficient). This also applies if depart from the written form requirement.

13.3 Severability. Should any clause of these Terms be legally void or ineffective, this shall not affect the validity of the remaining regulations. If necessary, void, or ineffective regulations are to be replaced by such valid regulations which come closest to the intended economic purpose.

13.4 Communication per email and Website notification. Communication will be by email or by notification on the Website. It is agreed that all notices, disclosures, and other communications provided electronically will be sufficient, unless law requires a more specific form.

Terms of Service - IoT Inspector

Version Date: June 15, 2021

IoT Inspector GmbH, Tannenwaldallee 2, 61348 Bad Homburg, Germany

©2021 IoT Inspector, a IoT Inspector GmbH product