General Terms and Conditions (GTC) of yappyBuy GmbH for SaaS Services
Effective: May 2025
These General Terms and Conditions (GTC) govern the contractual relationship between yappyBuy GmbH, Kaiselsbergstraße 41, 63808 Haibach, Germany ("yappyBuy") and its customers regarding the use of the Software-as-a-Service (SaaS) products "Buddy" and "Eazy Checkout" as well as future modules.
Part A – Introduction and Definitions
1. Scope
1.1 These General Terms and Conditions (GTC) govern the provision and use of SaaS products and associated services by yappyBuy GmbH. They apply to all contracts concluded between yappyBuy and entrepreneurs (§ 14 German Civil Code – BGB), legal entities under public law, or special funds under public law.
1.2 Deviating, conflicting, or supplementary terms and conditions of the customer shall not become part of the contract unless yappyBuy has expressly agreed to their validity in writing.
2. Subject Matter of the Contract
2.1 yappyBuy operates a modular SaaS platform for online merchants and digital business models, consisting of:
• "Buddy Assistant": an AI-based virtual assistant for customer support on websites and online shops;
• "Buddy Reporter": an analytics and reporting module for internal evaluation of usage data;
• "Eazy Checkout": a one-click checkout solution to optimize the payment process;
• and additional modules (e.g. Convert+, Buddy Pilot, Buddy Wizard) that can be booked optionally.
2.2 The individual modules can be booked and used independently. The respective scope of services is defined in the service descriptions at https://yappybuy.com.
3. Definitions
3.1 "SaaS" refers to software that is centrally hosted by yappyBuy and made available to the customer via the internet, without requiring a local installation.
3.2 "Customer" refers to any natural or legal person who enters into a contract with yappyBuy for the use of the modules.
3.3 "User" refers to persons accessing the platform on behalf of the customer, including employees or technical systems of the customer.
3.4 "Modules" are independent functional components of the SaaS platform that can be booked separately and serve specific purposes (e.g. analytics, checkout, interaction).
3.5 "Ticket Portal" means the support system operated by yappyBuy at https://docs.yappybuy.de, through which technical and content-related inquiries are handled.
3.6 "DPA" means the Data Processing Agreement pursuant to Art. 28 GDPR, which the customer accepts upon conclusion of the contract and which governs the processing of personal data.
3.7 "Availability" refers to the technical accessibility of the modules via the internet, measured by the reachability of the server.
3.8 "Contract Term" means the duration of use of a module selected by the customer (monthly or yearly), starting from the date of paid activation.
Part B – General Provisions
1. Conclusion of the Contract
1.1 The contract is concluded either by:
• selecting and booking a module via the online order form on yappyBuy's website, or
• acceptance of a custom offer by the customer.
1.2 By concluding the contract, the customer accepts the GTC and the applicable service descriptions.
1.3 yappyBuy may accept the customer's contract offer within 7 business days. Until acceptance, the customer remains bound by the offer.
2. Scope of Services and Modifications
2.1 The scope of services is determined by the product profile valid at the time of conclusion and supplementary module descriptions on the website.
2.2 yappyBuy may modify or further develop platform functions as long as it remains reasonable for the customer.
2.3 If a core module is significantly changed or discontinued, yappyBuy will notify the customer at least 4 weeks in advance. The customer then has a special right of termination.
3. Rights of Use and Intellectual Property
3.1 All rights to the provided software, platform components, and content remain with yappyBuy.
3.2 The customer receives a non-exclusive, non-transferable right to use the booked modules for the duration of the contract.
3.3 Use is permitted solely for the customer's internal business purposes. Transfer to or use by third parties requires written consent.
4. Customer Obligations
4.1 The customer shall support yappyBuy appropriately in providing the services. In particular, the customer agrees:
• to provide accurate technical information,
• to configure its systems according to documentation,
• to independently integrate the solution into its website or shop,
• to fulfill data protection information obligations to its own end users.
5. Availability, Maintenance and Incidents
5.1 yappyBuy aims to provide 98.5% annual availability (“best-effort”).
5.2 Maintenance is scheduled outside core usage hours whenever possible. Where feasible, yappyBuy will notify customers via email at least 48 hours in advance.
5.3 The customer must report issues immediately via the ticket portal. yappyBuy will resolve issues as quickly as operationally possible.
6. Prices, Payment Terms, Default
6.1 The applicable prices are those published on the website at the time of contract conclusion.
6.2 Billing is handled via Stripe on a monthly or yearly basis, as selected by the customer.
6.3 Payments are due immediately. If the customer defaults on a payment, yappyBuy may temporarily block access to the services.
6.4 Other rights in the event of default (e.g. termination, damages) remain unaffected.
7. Term and Termination
7.1 Contracts may be concluded with a monthly or yearly term.
7.2 The contract is automatically renewed for the selected term unless terminated with 7 days' notice before the end of the period.
7.3 The right to terminate for good cause remains unaffected.
8. Liability
8.1 yappyBuy is liable without limitation for intent and gross negligence.
8.2 In cases of slight negligence, liability is limited to foreseeable damages typical for the contract if a material contractual obligation was breached.
8.3 Liability for lost profits, missed savings, indirect damages, and consequential damages is excluded.
8.4 For data loss, yappyBuy is only liable if the customer has performed regular backups in line with the state of the art.
8.5 Liability under the Product Liability Act remains unaffected.
9. Confidentiality
9.1 Both parties agree to maintain confidentiality of all business secrets disclosed during the course of collaboration.
9.2 This obligation continues for three (3) years after the end of the contract.
Part C – Module-Specific Terms
1. Buddy Assistant
1.1 Buddy Assistant is a module for assisting end users on the customer’s websites or online shops. It answers inquiries, provides recommendations, and can be linked with other modules (e.g., Eazy Checkout).
1.2 Integration is client-side by embedding a code snippet into the customer’s website. The customer is responsible for GDPR-compliant implementation (e.g., cookie consent, privacy notice).
1.3 Use is public and accessible to website visitors. The customer must ensure that presentation and communication comply with applicable competition law.
1.4 No unlawful, discriminatory, or third-party infringing content may be shared via Buddy Assistant. yappyBuy reserves the right to deactivate content in case of violations.
2. Buddy Reporter
2.1 Buddy Reporter is an internal analytics and reporting module. It processes usage data (e.g., interactions, clicks, dwell time) to evaluate customer behavior within the customer’s systems.
2.2 Collected data is made available exclusively to the customer. yappyBuy does not use such data for its own purposes.
2.3 The customer is responsible for ensuring proper information to data subjects and, if required, obtaining any necessary consents under data protection law.
2.4 Results produced by Buddy Reporter may not be publicly disclosed or marketed without yappyBuy’s prior written consent.
3. Eazy Checkout
3.1 Eazy Checkout is an extension module designed to simplify the checkout process using streamlined steps (e.g., one-click purchase).
3.2 Integration is done via plugin or API into existing shop systems. Compatibility is documented on the website.
3.3 The customer must use only legally compliant payment providers (e.g., Stripe, PayPal) when processing payments through Eazy Checkout.
3.4 If Eazy Checkout is used in conjunction with Buddy Assistant, the terms of Buddy Assistant apply accordingly.
4. Convert+ and Future Modules
4.1 yappyBuy may introduce additional modules at any time (e.g., Convert+, Buddy Pilot, Buddy Wizard). Their use requires separate subscription.
4.2 Unless otherwise specified in the product description, the provisions of these GTC apply accordingly to new modules.
Customers are expressly advised to include a notice regarding the use of yappyBuy services in their website/shop terms and privacy policies. In particular, visitors must be informed that yappyBuy acts as a commissioned processor in the context of Eazy Checkout.
Part D – Data Processing Agreement (DPA) under Art. 28 GDPR
1. Subject and Duration of Processing
1.1 This Data Processing Agreement (DPA) governs the processing of personal data on behalf of the customer by yappyBuy in accordance with Art. 28 GDPR.
1.2 Processing is carried out solely for the purposes contractually agreed. The duration of processing corresponds to the term of the respective module.
2. Nature and Purpose of Processing
2.1 Data processed include those collected during use of the SaaS modules, such as customer data, usage data, and support data.
2.2 The purpose of processing is to provide and improve the contracted modules (e.g., Buddy Assistant, Buddy Reporter, Eazy Checkout).
3. Types of Data and Data Subjects
3.1 The following categories of data may be processed:
• Contact data (e.g., names, email addresses),
• Technical usage data (e.g., IP addresses, log files),
• User communication content (e.g., chats with Buddy Assistant).
3.2 Data subjects may include users of the customer's systems and their customers.
4. Customer Responsibilities
4.1 The customer is the controller under Art. 4(7) GDPR.
4.2 The customer shall fulfill their information obligations and obtain consent from data subjects where required.
5. Obligations of yappyBuy
5.1 yappyBuy will only process personal data based on documented instructions from the customer.
5.2 All yappyBuy personnel involved in data processing are bound to confidentiality.
5.3 yappyBuy ensures appropriate technical and organizational measures in line with Art. 32 GDPR.
5.4 yappyBuy supports the customer in responding to data subject requests and in fulfilling obligations under data protection law.
6. Sub-processors
6.1 yappyBuy uses sub-processors (e.g., hosting providers, IT service providers). A current list is available at https://www.yappybuy.com/de/auftragsverarbeitungsvertrag
6.2 The customer will be informed of material changes to this list and may object within 14 days. Without objection, the change is deemed accepted.
7. Deletion and Return of Data
7.1 Upon termination of processing, yappyBuy shall, at the customer’s choice, return or delete all personal data unless retention is required by EU or Member State law.
7.2 Deletion must be permanent and irreversible. Processes must be logged and confirmed within 72 hours of execution.
8. Audits and Documentation
8.1 yappyBuy will allow reasonable inspections (e.g., via documentation or audits with notice).
8.2 yappyBuy maintains a record of processing activities and documents technical and organizational safeguards.
9. Instructions and Support
9.1 yappyBuy shall follow the customer's instructions unless legally prevented. In such cases, yappyBuy shall inform the customer unless prohibited by law.
9.2 Instructions must be documented and retained for three years beyond the contract term.
9.3 yappyBuy shall notify the customer if any instruction appears to violate applicable law.
9.4 Both parties shall appoint contact persons for instructions and notify each other of changes.
9.5 yappyBuy will assist the customer in fulfilling obligations under Articles 12–22 and 32–36 GDPR.
9.6 yappyBuy will inform the customer without undue delay of any data subject requests or inquiries from supervisory authorities.
10. Data Protection Contact
Data protection officer of yappyBuy:
PROLIANCE GmbH
www.datenschutzexperte.de
Leopoldstr. 21
80802 Munich
Email: datenschutzbeauftragter@datenschutzexperte.de
11. Technical and Organizational Measures (TOMs)
11.1 yappyBuy implements TOMs in accordance with Art. 32 GDPR to ensure confidentiality, integrity, availability, and resilience of systems.
11.2 Adjustments to TOMs must maintain an equivalent security level. Material changes must be documented and agreed in writing.
12. Breach Notification and Communication
12.1 yappyBuy shall notify the customer without undue delay of any data breaches or suspected breaches.
12.2 yappyBuy assists in mitigation, resolution, and communication with supervisory authorities and data subjects.
12.3 In case of insolvency or third-party access to personal data, yappyBuy shall inform the customer immediately.
12.4 Findings from supervisory authority audits must be shared with the customer if related to the data processing.
13. Final Provisions of the DPA
13.1 The customer may not withhold data under § 273 BGB.
13.2 Appendices to this agreement are integral parts.
13.3 Amendments require written or electronic form, including to this clause.
13.4 If any provision is or becomes invalid, the remainder shall remain unaffected.
yappyBuy GmbH
Kaiselsbergstraße 41
63808 Haibach
Germany
https://www.yappybuy.com
Johannes P. Hattingh
CEO
If you have questions or need assistance, please contact us at support@yappybuy.com or call +49 6021 32 711 50. Our support hours are Monday to Wednesday 09:00–17:00 (CET) and Thursday–Friday 09:00–12:00 (CET).