Terms and Conditions AI Trust Audit
These Terms and Conditions govern the use of the online tool "AI Trust Audit" ("Tool"), which is provided by Trusted Shops SE, Subbelrather Str. 15c, 50823 Cologne, Germany ("Trusted Shops" or "Provider"). "User" refers to the entrepreneur within the meaning of section 14 of the German Civil Code who uses the tool. Consumers are excluded from the use of the tool.
By using the tool, the User agrees to the applicability of these Terms and Conditions.
Table of Contents
1. Subject matter of the contract
1.1. The Tool performs automated analyses of publicly available data (e.g., publicly visible reviews, domain content, and structured data), based on this, it generates reports on the trustworthiness and visibility of domains as well as concrete recommendations for action. The results are for informational purposes only and do not constitute any guarantee of ranking or revenue. 1.2. Access to non-public areas does not occur.
2. Scope, Description of Service and Prerequisites for Use
2.1. The provider makes the tool available as a SaaS service. For the basic evaluation, entering a domain is sufficient. To receive a complete report, registration is required; the registering person confirms with the registration that they are authorized to enter data. 2.2. The tool is provided as a beta version. Trusted Shops assumes no warranty for the availability, freedom from errors, completeness, or economic usability of the provided data. The service is currently provided free of charge. However, Trusted Shops reserves the right to offer the tool in whole or in part for a fee in the future or to discontinue it. 2.3. It is not permitted to use the tool for the manipulation of reviews, for the circumvention of technical or organizational protective measures, for unlawful data extraction, or for other abusive purposes. 2.4. In addition to the one-time registration for retrieving a report, users can create a voluntary, permanent user account. The user account enables recurring access to previously conducted reports of the same email address. 2.5. Login is passwordless via a so-called magic link: Upon request, Trusted Shops sends a login link to the email address provided by the user. The link is valid only for a limited period and is intended exclusively for the respective user. The user is obligated to treat the link confidentially and not to pass it on to third parties. 2.6. The reports that the user starts after logging in or in the respective session are assigned to the user account and displayed there collectively. 2.7. The provision of the user account is free of charge. There is no claim to permanent or uninterrupted availability. Trusted Shops is entitled to adapt, restrict, or discontinue the account feature at any time. 2.8. The user can terminate their user account and request its deletion at any time. With the deletion of the account, the account-related data will be treated in accordance with the provisions of the data protection notices.
3. Rights and Obligations of the User
3.1. The User is responsible for complying with all legal requirements applicable when using the tool, in particular those relating to data protection, competition law, and any professional or industry-specific regulations. 3.2. If the User violates applicable law, they shall indemnify Trusted Shops upon first request against all claims asserted by third parties in connection with the User's unlawful use of the tool. Trusted Shops is entitled to take appropriate measures to defend against such claims or to enforce its own rights. The indemnification also includes reimbursement of the costs of legal prosecution and defense. 3.3. Trusted Shops grants the User a simple, non-transferable and non-sublicensable right of use to the results generated specifically for their domain. 3.4. The User grants Trusted Shops and the companies affiliated with Trusted Shops pursuant to section 15 of the German Stock Corporation Act a non-exclusive, royalty-free, perpetual, and irrevocable right to use the results generated by the tool as well as the usage data collected for their own business purposes.
4. Controls and Restrictions by Trusted Shops
4.1. Trusted Shops is entitled to verify whether the use of the tool complies with these terms and may, at its sole discretion, restrict or block its use if violations or indications of abusive behavior are present. 4.2. The User is not permitted to copy, modify, create derivative works from, reverse-engineer, disassemble, translate, or otherwise alter the source code of the tool or any part thereof – except to the extent expressly permitted under sections 69d and 69e of the German Copyright Act.
5. Data Protection
The processing of personal data is carried out in accordance with Art. 6 para. 1 p. 1 lit. f GDPR and 6 para. 1 lit. a GDPR. Details can be found in the applicable data protection notices and the attached data processing agreement.
6. Notice on the Use of AI Technology
The tool uses algorithmic and AI-assisted methods for analysis. Analyses may be inaccurate, incomplete or erroneous. The provider complies with the legal requirements applicable to it, including the relevant provisions of the EU AI Act, to the extent they apply.
7. Final Provisions
7.1. This agreement and all disputes arising out of or in connection with it shall be governed exclusively by German law. 7.2. The contract language is English. 7.3. For all disputes arising out of or in connection with this agreement, the court of Cologne shall have jurisdiction to the extent permitted by law. The same applies, if the User has no general place of jurisdiction in Germany or if the User's residence or usual place of abode is unknown at the time the action is filed. 7.4. Trusted Shops may amend these Terms and Conditions at any time. The User agrees, that the version of the Terms in effect at the time of use shall apply, which is published at all times on https://business.trustedshops.de/vorteile/ai-trust-audit. 7.5. If any provision of this agreement is or becomes invalid, the validity of the remaining provisions shall not be affected. In place of the invalid provision, the statutory provision shall apply.
Data Processing Agreement between Trusted Shops SE and the user
Insofar as the user processes personal data on the website to be audited when carrying out the AI Trust Audit by means of the tool provided by Trusted Shops SE, Trusted Shops SE acts as a data processor. The following regulations on data processing shall apply. Standard Contractual Clauses Section 1 Clause 1 – Purpose and scope a) These Standard Contractual Clauses (hereinafter ‘Clauses’) are intended to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). b) The controllers and processors listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article 29(3) and (4) of Regulation (EU) 2018/1725. c) These Clauses apply to the processing of personal data as specified in Annex II. d) Annexes I to IV are an integral part of the Clauses. e) These Clauses are without prejudice to the obligations to which the controller is subject by virtue of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. f) These Clauses do not in themselves ensure compliance with the obligations related to international transfers in accordance with Chapter V of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. Clause 2 – Invariability of the Clauses a) The Parties undertake not to modify the Clauses, except for adding or updating information in the Annexes. b) This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, the Clauses or prejudice the fundamental rights or freedoms of data subjects. Clause 3 – Interpretation a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively, those terms shall have the same meaning as in the relevant Regulation. b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively. c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 or prejudices the fundamental rights or freedoms of data subjects. Clause 4 – Hierarchy In the event of a contradiction between these Clauses and the provisions of related agreements existing at the time the Clauses are agreed or entered into thereafter, these Clauses shall prevail. Clause 5 – Docking clause a) An entity that is not a Party to these Clauses may, with the agreement of all the Parties, accede to these Clauses at any time as a controller or as a processor by completing the Annexes and signing Annex I. b) Once it has completed and signed the Annexes as referred to in (a), the acceding entity shall be treated as a Party to these Clauses and have the rights and obligations of a controller or a processor, in accordance with its designation in Annex I. c) The acceding entity shall have no rights or obligations resulting from these Clauses from the period prior to its accession. Section 2 – Obligations of the Parties Clause 6 – Description of processing The details of the processing operations, in particular the categories of personal data and the purposes for which the personal data are processed on behalf of the controller, are specified in Annex II. Clause 7 – Obligations of the Parties 7.1 Instructions a) The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. In such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The controller may issue further instructions throughout the duration of the processing of personal data. These instructions shall always be documented. b) The processor shall immediately inform the controller if, in its opinion, instructions given by the controller infringe Regulation (EU) 2016/679, Regulation (EU) 2018/1725 or applicable Union or Member State data protection provisions. 7.2 Purpose limitation The processor shall process the personal data only for the specific purpose(s) of the processing, as set out in Annex II, unless it receives further instructions from the controller. 7.3 Duration of the processing of personal data The processor shall process the data only for the duration specified in Annex II. 7.4 Security of processing a) The processor shall implement at least the technical and organisational measures specified in Annex III to ensure the security of the personal data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (hereinafter ‘personal data breach’). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects. b) The processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The processor shall ensure that persons authorised to process the personal data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. 7.5 Sensitive data If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions and offences (hereinafter 'sensitive data'), the processor shall apply specific restrictions and/or additional safeguards. 7.6 Documentation and compliance a) The Parties must be able to demonstrate compliance with these Clauses. b) The processor shall deal promptly and properly with inquiries from the controller about the processing of data in accordance with these Clauses. c) The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations set out in these Clauses and stemming directly from Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the controller’s request, the processor shall also permit and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or audit, the controller may take into account relevant certifications held by the processor. d) The controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the processor and shall, where appropriate, be carried out with reasonable notice. e) The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request. 7.7 Use of sub-processors a) The processor has the controller's general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform the controller in writing of any intended changes to that list through the addition or replacement of sub-processors at least 1 month in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The processor shall provide the controller with the information necessary to enable the controller to exercise its right to object. b) Where the processor engages a sub-processor for carrying out specific processing activities (on behalf of the controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the processor in accordance with these Clauses. The processor shall ensure that the sub-processor complies with the obligations to which the processor is subject pursuant to these Clauses and to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. c) The processor shall provide, at the controller’s request, a copy of such a sub-processing agreement and any subsequent amendments. To the extent necessary to protect business secrets or other confidential information, including personal data, the processor may redact the text of the agreement before sharing a copy. d) The processor shall remain fully responsible to the controller for the performance of the sub-processor’s obligations in accordance with its contract with the processor. The processor shall notify the controller of any failure by the sub-processor to fulfil its contractual obligations. e) The processor shall agree a third-party beneficiary clause with the sub-processor whereby – in the event the processor has factually disappeared, ceased to exist in law or has become insolvent – the controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data. 7.8 International transfers a) Any transfer of data by the processor to a third country or an international organisation shall be done only on the basis of documented instructions from the controller or in order to fulfil a specific requirement under Union or Member State law to which the processor is subject and shall take place in compliance with Chapter V of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725. b) The controller agrees that where the processor engages a sub-processor in accordance with Clause 7.7. for carrying out specific processing activities (on behalf of the controller) and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the processor and the sub-processor can ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission in accordance with Article 46(2) of Regulation (EU) 2016/679, provided the conditions for the use of those standard contractual clauses are met. Clause 8 – Assistance to the controller a) The processor shall promptly notify the controller of any request it has received from the data subject. It shall not respond to the request itself, unless it has been authorised to do so by the controller. b) Taking into account the nature of the processing, the processor shall assist the controller in fulfilling its obligations to respond to data subjects’ requests to exercise their rights. In fulfilling its obligations under (a) and (b), the processor shall follow the instructions from the controller. c) In addition to the processor's obligation to assist the controller pursuant to Clause 8(b), the processor shall furthermore assist the controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the processor: 1) the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (hereinafter ‘data protection impact assessment’) where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons; 2) the obligation to consult the competent supervisory authority/ies prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk; 3) the obligation to ensure that personal data is accurate and up to date, by informing the controller without delay if the processor becomes aware that the personal data it is processing is inaccurate or has become outdated; 4) the obligations under Article 32 of Regulation (EU) 2016/679. d) The Parties shall set out in Annex III the appropriate technical and organisational measures by which the processor is required to assist the controller in the application of this Clause as well as the scope and the extent of the assistance required. Clause 9 – Notification of a personal data breach In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679 or, where applicable, Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the processor. 9.1 Data breach concerning data processed by the controller In the event of a personal data breach concerning data processed by the controller, the processor shall assist the controller: a) in notifying the personal data breach to the competent supervisory authority/ies without undue delay after the controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); b) in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the controller's notification, and must at least include: 1) the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; 2) the likely consequences of the personal data breach; 3) the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay; c) in complying with the obligation under Article 34 of Regulation (EU) 2016/679 to communicate the personal data breach to the data subject without undue delay, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. 9.2 Data breach concerning data processed by the processor In the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor has become aware of the breach. Such notification shall contain, at least: a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); b) the contact details of a contact point where more information concerning the personal data breach can be obtained; c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679. Clause 10 – Non-compliance with the Clauses and termination a) Without prejudice to the provisions of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725, in the event that the processor is in breach of its obligations under these Clauses, the controller may instruct the processor to suspend the processing of personal data until the latter complies with these Clauses or the contract is terminated. The processor shall promptly inform the controller in case it is unable to comply with these Clauses, for whatever reason. b) The controller shall be entitled to terminate the contract, insofar as it concerns processing of personal data in accordance with these Clauses, if: 1) the controller has suspended the processing of personal data by the processor pursuant to point (a) and compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension; 2) the processor is in substantial or persistent breach of these Clauses or its obligations under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725; 3) the processor fails to comply with a binding decision of a competent court or the competent supervisory authority/ies which concerns its obligations under these Clauses or under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. c) The processor shall be entitled to terminate the contract, insofar as it concerns processing of personal data under these Clauses, where the controller insists on compliance with its instructions, after being informed by the processor that its instructions infringe applicable legal requirements pursuant to Clause 7.1(b). d) Following termination of the contract, the processor shall, at the choice of the controller, delete all personal data processed on behalf of the controller and certify to the controller that it has done so, or return all the personal data to the controller and delete existing copies unless Union or Member State law requires storage of the personal data. Until the data is deleted or returned, the processor shall continue to ensure compliance with these Clauses. Annex I – List of Parties A. Controller(s) The controller is the user of the service according to the terms of use. B. Processor(s) Name: Trusted Shops SE Address: Subbelrather Str. 15C, 50823 Cologne Email: privacy@trustedshops.com Annex II – Description of the processing A. Categories of data subjects Persons published on the website (managing directors, DPO, persons with editorial responsibility); employees of the controller. B. Categories of personal data processed Name; address; email address; telephone number. C. Nature of the processing When a website URL is provided for the AI Trust Audit, the processor automatically retrieves the publicly accessible pages of the audited domain and analyzes their content. In doing so, personal data that the website operator has published there itself may also be processed. D. Purpose(s) of the processing Creation and display of the audit result, performance of the commissioned website audit. E. Duration of processing Corresponds to the duration of use of the service. Annex III – Technical and organisational measures The technical and organizational measures of Trusted Shops SE apply. Trusted Shops always publishes the current TOMs at https://help.etrusted.com/hc/de/articles/360021040178. Annex IV – Sub-processors Lovable Labs Incorporate — SaaS provider as a technical platform for performing the scan — Processing duration: Corresponds to the duration of use of the service.