Terms of Service: BitHive Reporting Desk
BitHive UG (haftungsbeschränkt), Heisenbergstraße 3, 10587 Berlin, Germany, registered with the commercial register of the Amtsgericht Charlottenburg under HRB 255394, represented by its managing director Alireza Khalili ("BitHive", "we").
Version 1.1 · September 2026 · Replaces version 1.0 (changes: Section 9.2 place of processing, Section 12.6 language versions)
1. Scope
1.1 These Terms apply to all contracts under which BitHive provides the BitHive Reporting Desk and related services (the "Service") to a customer (the "Customer").
1.2 The Service is offered exclusively to entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law. It is not offered to consumers. By ordering, the Customer confirms that it acts in the course of its trade, business or profession.
1.3 General terms of the Customer do not apply, even if BitHive does not expressly object to them or performs without reservation. They apply only if BitHive expressly agrees to them in text form.
1.4 Individual agreements (in particular order forms and offers) take precedence over these Terms.
2. Conclusion of the contract
2.1 Descriptions and prices on the website are an invitation to submit an order, not a binding offer.
2.2 The contract is concluded when BitHive accepts the Customer's order in text form, when BitHive activates the Customer's account for a paid plan, or when the Customer accepts a written offer from BitHive, whichever occurs first.
2.3 If BitHive offers a free trial, the trial ends automatically at the end of the trial period unless the Customer orders a paid plan. During a trial, Sections 10.2 and 10.3 apply with the proviso that BitHive is liable only for intent and gross negligence.
3. The Service
3.1 The Service is a software application provided over the internet ("software as a service"). Its functions are described in the service description on the website and in the documentation current at the time of the order. In summary, the Service enables the Customer to:
- upload software bills of materials ("SBOMs") for its products via the web interface or the API;
- have the components listed in the SBOMs automatically compared with vulnerability information from the sources named in the documentation, including information on active exploitation;
- receive notifications when a match is found;
- track the deadlines of reporting obligations and prepare report texts in guided forms;
- document actions and decisions in an audit log.
3.2 Nature of the Service. The Service is a technical tool. It does not provide legal advice. In particular, BitHive does not assess whether the Customer's products are subject to the Cyber Resilience Act (Regulation (EU) 2024/2847) or other legislation, whether a vulnerability is actively exploited within the meaning of that legislation, or whether, when and with what content a report must be made. These decisions, and the submission of reports to the competent authorities (including via ENISA's Single Reporting Platform), remain the sole responsibility of the Customer.
3.3 Data sources. The results of the Service depend on the completeness and accuracy of the SBOMs provided by the Customer and on the information published by the third-party sources named in the documentation. BitHive processes this information carefully and without undue delay after its publication, but has no influence on its content, completeness or timing.
3.4 BitHive may further develop the Service, in particular adapt it to technical progress, new data sources and legal requirements, provided that the functions agreed in the contract are not materially restricted and the change is reasonable for the Customer. BitHive will announce changes that materially affect the use of the Service at least four weeks in advance in text form.
3.5 BitHive may use subcontractors. It remains responsible for the Service vis-à-vis the Customer.
4. Availability and support
4.1 BitHive provides the Service with the availability and support described in the Service Level Agreement, which forms part of the contract.
4.2 BitHive's performance obligations end at the interface of the data centre to the public internet. BitHive is not responsible for the Customer's internet connection or for disruptions of the public internet.
5. Obligations of the Customer
5.1 The Customer shall:
- keep access credentials and API tokens confidential, protect them against misuse and inform BitHive without undue delay if it suspects misuse;
- upload SBOMs that reflect its products and supported versions and keep them up to date;
- maintain at least two reachable recipients for notifications and keep their contact details up to date;
- review notifications from the Service without undue delay;
- keep its own copies of the SBOMs it uploads;
- use the Service only in accordance with the contract and applicable law, and in particular not upload malicious code, attempt to circumvent security measures or place excessive load on the Service beyond the fair-use limits set out in the documentation.
5.2 The Customer is responsible for all activities carried out with its accounts and API tokens unless it proves that it is not responsible for them.
6. Rights of use and Customer Data
6.1 For the term of the contract, BitHive grants the Customer the non-exclusive, non-transferable right, which cannot be sublicensed, to use the Service for its own business purposes within the scope of the booked plan. The Customer may allow its employees and agents acting on its behalf to use the Service within the booked number of users.
6.2 All data that the Customer uploads to or creates in the Service ("Customer Data") remains the property of the Customer. The Customer grants BitHive the rights necessary to store and process Customer Data solely for the purpose of providing the Service. BitHive does not use Customer Data for any other purpose, in particular not for training AI models, and does not disclose it to third parties except to subcontractors bound under Section 9.
6.3 The Customer can export its Customer Data at any time during the term in a common machine-readable format.
7. Fees and payment
7.1 The fees result from the order or, if none is agreed there, from the price list published on the website at the time of the order. All prices are net amounts plus statutory value added tax.
7.2 Fees are payable in advance for the respective billing period (monthly or annually). Invoices are due within 14 days of receipt without deduction. BitHive may issue invoices electronically.
7.3 If the Customer is in default of payment for more than 14 days, BitHive may, after prior notice in text form with a deadline of at least seven days, suspend access to the Service until payment is made. Notifications about actively exploited vulnerabilities continue to be sent during a suspension for up to 30 days. Further rights remain unaffected.
7.4 BitHive may adjust the fees for the next renewal period with effect for the future by giving at least eight weeks' notice in text form. If the fees increase, the Customer may terminate the contract with effect from the date on which the increase takes effect. BitHive will point out this right in the notice.
7.5 The Customer may only set off claims that are undisputed or have been finally established by a court. This does not apply to counterclaims arising from the same contractual relationship.
8. Term and termination
8.1 Monthly plans run for one month and renew automatically by one month unless terminated by either party with effect from the end of the current month.
8.2 Annual plans run for twelve months and renew automatically by twelve months unless terminated by either party with one month's notice to the end of the current term.
8.3 The right of both parties to terminate for good cause remains unaffected. Good cause for BitHive exists in particular if the Customer is in default of payment for more than two months or seriously breaches Section 5.1 despite a warning.
8.4 Terminations must be made in text form (for example by e-mail to contact@bithive-it.com) or via the account settings.
8.5 After the end of the contract, the Customer can export its Customer Data for 30 days. BitHive then deletes the Customer Data, unless it is obliged by law to retain it. Backups are overwritten in the regular backup cycle, at the latest within a further 35 days.
9. Data protection and confidentiality
9.1 Insofar as BitHive processes personal data on behalf of the Customer, the parties conclude the Data Processing Agreement provided by BitHive, which forms part of the contract.
9.2 Customer Data is stored and processed exclusively in data centres in Germany. E-mails sent by the Service are delivered by an e-mail service provider in the European Union; details, including any processing by its sub-processors in third countries and the applicable safeguards, are set out in the Data Processing Agreement. BitHive will inform the Customer at least four weeks in advance of any change to the storage location.
9.3 Each party shall keep confidential all non-public information of the other party that it obtains in connection with the contract, in particular Customer Data and information about vulnerabilities in the Customer's products, and shall use it only for the purposes of the contract. This obligation continues for three years after the end of the contract and indefinitely for information about vulnerabilities that have not been publicly disclosed. It does not apply to information that is or becomes publicly known without breach of this obligation, that was already known to the receiving party, or that must be disclosed by law or by order of a court or authority.
10. Warranty and liability
10.1 Defects. BitHive warrants that the Service essentially has the agreed functions during the term. The Customer shall report defects without undue delay in text form with a description that allows them to be reproduced. BitHive will remedy defects within a reasonable period. Strict liability for defects that already existed at the time the contract was concluded (Section 536a (1), first alternative BGB) is excluded.
10.2 Liability. BitHive is liable without limitation for damage caused intentionally or through gross negligence, for injury to life, body or health, under the German Product Liability Act and within the scope of any guarantee it has expressly given.
10.3 In cases of slight negligence, BitHive is liable only for the breach of an essential contractual obligation, that is, an obligation whose fulfilment makes the proper performance of the contract possible in the first place and on whose fulfilment the Customer regularly relies (cardinal obligation). In this case, liability is limited to the damage that is foreseeable and typical for this type of contract at the time the contract was concluded.
10.4 For the loss of data, BitHive is liable under Sections 10.2 and 10.3 only for the effort that would have been necessary to restore the data if the Customer had kept its own copies in accordance with Section 5.1.
10.5 The above limitations also apply in favour of BitHive's employees, representatives and subcontractors.
11. Changes to these Terms
11.1 BitHive may amend these Terms with effect for the future if there is a valid reason, in particular changes in the law or case law, or new functions of the Service. BitHive will send the amended Terms to the Customer in text form at least six weeks before they take effect.
11.2 The amendments are deemed accepted if the Customer does not object in text form before they take effect. BitHive will point out this consequence in the notice. If the Customer objects, either party may terminate the contract with effect from the date on which the amendments would have taken effect.
11.3 Changes to the scope of services or the fees are governed exclusively by Sections 3.4 and 7.4.
12. Final provisions
12.1 The Customer may only assign rights under this contract to third parties with BitHive's consent. Section 354a of the German Commercial Code (HGB) remains unaffected.
12.2 BitHive may name the Customer as a reference only with the Customer's prior consent in text form.
12.3 The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
12.4 If the Customer is a merchant, a legal entity under public law or a special fund under public law, or has no general place of jurisdiction in Germany, the exclusive place of jurisdiction for all disputes arising from this contract is Berlin. BitHive may also sue the Customer at its general place of jurisdiction.
12.5 Should individual provisions of these Terms be or become invalid, the validity of the remaining provisions remains unaffected. The statutory provisions apply in place of the invalid provision.
12.6 These Terms exist in a German and an English version. In the event of discrepancies, the German version prevails.