AssetObserve
Sign in Start free
Legal

AGB

Last updated: 8 July 2026

Agreement

These Terms and Conditions govern access to and use of AssetObserve, including the public website, SaaS platform, agents, scanners, integrations, APIs, reports, support, and related services. "AssetObserve", "we", "us", or "our" means AssetObserve. "Customer" or "you" means the organization or person that creates an account, orders a plan, or uses the service.

Business use

AssetObserve is primarily intended for organizations, IT teams, managed service providers, consultants, and professional users. If a consumer-protection law applies despite this business purpose, mandatory consumer rights remain unaffected.

Account authority

By creating an account or using AssetObserve for an organization, you confirm that you have authority to bind that organization, provide accurate information, keep account details current, and ensure that all users under your workspace comply with these Terms.

Service scope

AssetObserve helps customers document authorized internal infrastructure, scanner coverage, assets, software, cloud resources, risk findings, reports, and related evidence. The service provides decision-support information. It does not guarantee complete discovery, complete security, legal compliance, vulnerability absence, exploitability, business continuity, insurance eligibility, or regulatory certification.

Authorized use only

You may use AssetObserve only for assets, networks, cloud accounts, identities, systems, and data sources that you own, administer, or are expressly authorized to assess. You must not use AssetObserve to attack, disrupt, overload, scan without permission, exploit, exfiltrate, evade monitoring, spread malware, harvest credentials, violate privacy rights, or break any law or third-party contract.

Scanning, agents, and integrations

You are responsible for scoping scans safely, obtaining permissions, setting appropriate rate limits, scheduling scans to avoid disruption, excluding sensitive systems where needed, and validating results before action. You are responsible for deploying agents lawfully, informing affected personnel where required, and removing agents when no longer authorized. You are responsible for all integrations and credentials that you configure.

Credentials and secrets

You must use least-privilege credentials where possible, protect secrets, rotate credentials regularly, remove stale credentials, and immediately revoke credentials if compromise is suspected. AssetObserve is not responsible for customer-side credential misuse, excessive permissions, or unauthorized configuration by your administrators.

Customer data

Customer data remains the customer's data. You grant AssetObserve the rights needed to host, process, transmit, display, secure, back up, and support the service. You are responsible for the lawfulness, accuracy, quality, and permissions for customer data. You must not upload unlawful data, special-category data, secrets, or third-party personal data unless you have a lawful basis and the service is appropriate for that use.

Data processing agreement

Where AssetObserve processes personal data on behalf of a customer, the parties will apply the applicable data processing agreement or equivalent data protection terms. If no separate data processing agreement has been signed and one is legally required, you must contact us before using AssetObserve with personal data.

Availability and support

We aim to operate AssetObserve with reasonable skill and care. Unless a written service level agreement states otherwise, we do not promise uninterrupted or error-free availability. Maintenance, updates, security actions, customer configuration, third-party providers, internet outages, force majeure, and emergency mitigations may affect availability.

Plans, trials, fees, and taxes

Plans, limits, prices, currencies, billing periods, included features, and trial rules are shown in the product, order form, or invoice. You are responsible for fees, taxes, valid billing information, and payment-provider requirements. Trial access may be limited, changed, or terminated to prevent abuse.

Renewal, cancellation, and refunds

Unless an order form states otherwise, paid subscriptions renew for the selected billing period until cancelled. Cancellation stops future renewal but does not automatically refund past fees. Refunds, credits, chargebacks, cancellation rights, and withdrawal rights apply only where stated in the order form or required by mandatory law.

Third-party services

AssetObserve may integrate with identity providers, cloud providers, payment processors, email providers, vulnerability feeds, warranty data sources, and other third-party services. Third-party services are governed by their own terms and privacy notices. We are not responsible for third-party outages, data, terms, changes, or misuse outside our control.

Intellectual property

AssetObserve and its software, user interface, workflows, reports, documentation, trademarks, and content are owned by us or our licensors. Subject to these Terms and payment of applicable fees, you receive a limited, non-exclusive, non-transferable right to use the service for your internal business purposes. No source code, ownership, or intellectual property rights are transferred to you.

Feedback

If you provide ideas, suggestions, or feedback, we may use them without restriction or compensation, provided we do not disclose your confidential information in doing so.

Confidentiality

Each party may receive non-public information from the other. The receiving party must protect confidential information with reasonable care, use it only for the relationship, and disclose it only to personnel, advisers, providers, or authorities who have a legitimate need or legal basis.

Privacy and cookies

Our processing of personal data is described in the Privacy Policy and Cookie Policy. Customers remain responsible for their own privacy notices, employee notices, customer notices, and lawful-basis assessments for data they submit to AssetObserve.

Acceptable content and DSA-style notices

AssetObserve is not designed as a public content-sharing platform or marketplace. If hosted content is alleged to be unlawful or rights-infringing, notices may be sent to contact@assetobserve.com. We may remove, restrict, preserve, or disclose content where required by law, contract, security needs, or platform integrity. Where legally required, we will provide reasons and appeal information.

Compliance, export, and sanctions

You must comply with applicable laws, including cybersecurity, privacy, telecommunications, employment, procurement, tax, export-control, sanctions, anti-corruption, and sector-specific rules. You must not use AssetObserve where prohibited by sanctions or export-control laws, or for military, surveillance, or high-risk uses that are unlawful or require permissions you do not have.

Suspension

We may suspend access immediately if we reasonably believe that use of AssetObserve threatens security, violates law, infringes rights, risks service integrity, causes operational harm, creates payment risk, or breaches these Terms. We will use reasonable efforts to limit suspension to the affected account, workspace, feature, or activity where practical.

Termination

Either party may terminate according to the order form or product cancellation flow. We may terminate for material breach if not cured within a reasonable period after notice, or immediately for serious misuse, unlawful activity, non-payment, sanctions issues, or security risk. After termination, access may end and customer data may be deleted according to the retention rules, backup cycle, and applicable law.

Disclaimers

To the maximum extent permitted by law, AssetObserve is provided "as is" and "as available". We disclaim implied warranties of merchantability, fitness for a particular purpose, non-infringement, uninterrupted operation, error-free results, and complete detection. Security findings can be incomplete, inaccurate, duplicated, stale, or false positive. You must independently verify findings before remediation, disclosure, disciplinary action, purchasing decisions, insurance submissions, or regulatory filings.

Liability limits

Nothing in these Terms limits liability that cannot legally be limited, including liability for intent, gross negligence, death or personal injury caused by negligence, fraud, or mandatory statutory rights. Otherwise, to the maximum extent permitted by law, we are not liable for indirect, incidental, special, consequential, punitive, or exemplary damages, lost profits, lost revenue, lost data, business interruption, reputational harm, procurement costs, or security incidents caused by customer configuration or third parties. Our aggregate liability is limited to the fees paid or payable for the affected service during the 12 months before the event giving rise to liability, unless a different mandatory limit applies.

Indemnity

You will defend and indemnify us against claims, losses, fines, damages, costs, and expenses arising from your unauthorized scanning, unlawful content, customer data, misuse of credentials, breach of these Terms, violation of law, or infringement of third-party rights, except to the extent caused by our breach or mandatory law provides otherwise.

Changes

We may update these Terms for legal, security, operational, product, or business reasons. The updated version will be posted with a new date. Material changes may be communicated through the product, email, or another appropriate channel. Continued use after the effective date means acceptance of the updated Terms, unless mandatory law requires a different process.

Governing law and venue

Unless mandatory law requires otherwise, these Terms are governed by the laws of Germany, excluding conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. If you are a merchant, public-law entity, or special public-law fund, the courts at our registered seat have jurisdiction, unless mandatory law requires another venue.

Contact

Questions about these Terms, legal notices, security notices, and contract requests may be sent to contact@assetobserve.com.

Placeholder notice

Before launch, replace bracketed company details and review the plan model, payment flow, data processing agreement, service levels, refund rules, consumer exposure, liability cap, governing law, and international enforceability with qualified counsel.

Contact: contact@assetobserve.com

AssetObserve

AssetObserve helps IT teams and service providers document authorized internal infrastructure, scanner coverage, risk findings and reports from one SaaS workspace.

Platform Platform Capabilities Plans
Compliance NIS2 readiness BSI IT-Grundschutz
Company Help FAQ Contact Support
Legal Impressum Datenschutz AGB Cookie Richtlinie
© AssetObserve
contact@assetobserve.com