Skip to content

Terms and conditions

Draft. These terms have not yet been reviewed by a lawyer. They describe what I actually offer and what I do not — as a basis for that review and for the conversation with the first businesses.

This is also a translation for convenience. In case of doubt, the German version at /de/agb governs.

§ 1 Scope and parties

(1) These terms govern the provision of the software Rebounz by Timm Ditz, Kryspi – IT & Fitness (the "Provider") to businesses (the "Customer").

(2) The offer is directed exclusively at entrepreneurs within the meaning of § 14 German Civil Code (BGB), at legal persons under public law and at special funds under public law. It is not directed at consumers (§ 13 BGB). There is therefore no right of withdrawal.

(3) Deviating terms of the Customer apply only where the Provider has agreed to them in writing.

§ 2 Subject matter

(1) The Provider makes Rebounz available for use over the internet (software as a service). The Customer receives its own address in the form name.rebounz.de.

(2) Rebounz lets the Customer run digital loyalty cards: create cards, give stamps, redeem rewards and see the current state. The scope of functions follows from the application in its current version.

(3) The Provider owes no outcome in terms of any particular number of guests, stamps or repeat visits.

(4) The Provider gives no legal, tax or data protection advice. In particular the Customer is responsible for which rewards it promises and on what conditions.

§ 3 Pilot phase

(1) Rebounz is being built. For customers admitted during the pilot phase, use is free of charge.

(2) During the pilot phase:

  • The Provider promises no particular availability.
  • Functions may change, be added or removed.
  • Maintenance windows may occur without notice.

(3) The Provider will announce any later charge at least three months in advance in text form. Anyone who does not agree may terminate before it takes effect and may take their data with them under § 6.

§ 4 Customer's obligations

(1) The Customer is responsible for its staff's credentials and ensures that they do not reach unauthorised persons.

(2) The Customer ensures that it informs its guests about the processing of their data, and keeps its own mandatory pages (legal notice, privacy policy) up to date at its address.

(3) The Customer may not use Rebounz for unlawful purposes and may not store content that infringes third-party rights.

§ 5 Availability and maintenance

(1) Outside the pilot phase the Provider aims for 99 % availability on monthly average, measured at the application's entry point. Announced maintenance and disruptions outside the Provider's control (in particular at the data centre operator) do not count.

(2) The Provider may develop the application further. Where something the Customer uses day to day changes, the Provider announces it in good time.

§ 6 Customer data

(1) Data arising from use — in particular cards, stamps, rewards and guest details — remain attributed to the Customer.

(2) The Customer may export its data at any time in a common, machine-readable format.

(3) After the contract ends, the Provider deletes the Customer's data within 30 days, unless a statutory retention obligation stands in the way. On request an export is provided beforehand.

(4) Processing of guests' personal data takes place on the Customer's behalf. Annex 1 applies (processing agreement under Art. 28 GDPR).

§ 7 Liability

(1) The Provider is liable without limitation for intent and gross negligence, for injury to life, body or health, and under the Product Liability Act.

(2) For ordinary negligence the Provider is liable only for breach of a material contractual obligation — an obligation whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the Customer may rely. In that case liability is limited to the foreseeable damage typical of this type of contract.

(3) As long as use is free of charge (§ 3), the Provider is liable only for intent and gross negligence.

(4) For loss of data the Provider is liable only up to the expense that would have been incurred for restoration had the Customer kept proper and regular backups.

§ 8 Term and termination

(1) The contract runs for an indefinite period.

(2) Either party may terminate it with 30 days' notice to the end of a month in text form. During the pilot phase the Customer may terminate at any time without notice.

(3) The right to extraordinary termination for good cause remains unaffected.

§ 9 Changes to these terms

The Provider may change these terms and announces this at least six weeks in advance in text form. If the Customer does not object before the change takes effect, the amended terms apply; the Provider points this out in the announcement. If the Customer objects, the contract ends when the change takes effect.

§ 10 Final provisions

(1) German law applies, excluding the UN Convention on Contracts for the International Sale of Goods.

(2) If the Customer is a merchant, a legal person under public law or a special fund under public law, the place of jurisdiction is the Provider's registered office.

(3) Should any provision be invalid, the remainder of the contract stays effective.


Annex 1 — Data processing agreement (Art. 28 GDPR)

This annex forms part of the contract. The Customer is the controller, the Provider is the processor.

1. Subject matter, duration, nature and purpose

The subject matter is the operation of Rebounz for the Customer. Processing serves that purpose alone and lasts as long as the contract.

2. Types of data and categories of data subjects

Guest data: email address; a display name if the guest wishes; membership of cards, stamping events with timestamps, redeemed rewards and vouchers.

Staff data: login name or email address, role, times of sign-ins and of actions performed.

Data subjects: the Customer's guests and the Customer's employees.

3. Instructions

The Provider processes the data solely on the Customer's documented instructions. Operating the application counts as an instruction. The Provider informs the Customer if it considers an instruction unlawful.

4. Confidentiality

The Provider is the only person with access and is bound to confidentiality. Should employees be engaged, they are bound accordingly beforehand.

5. Technical and organisational measures (Art. 32 GDPR)

  • Transmission exclusively encrypted (TLS).
  • Passwords are stored only as hashes, never in clear text.
  • Access to a business's data only within its context — enforced at two levels: in the application and in the database itself (row level security).
  • Role and permission system; access only as far as required for the task.
  • Logging of security-relevant events.
  • Servers in Germany, physically secured by the data centre operator.
  • Container logs are limited in size and roll over.

Open point — availability and restorability (Art. 32(1)(c) GDPR). The data sit on a persistent volume, which protects against restart and rebuild. An automatic off-site backup and a tested restore do not yet exist. This is stated here because a list of measures that hides a missing one is worse than a gap that is named. It must be in place before the first business is admitted; this passage will then be replaced.

6. Sub-processors

The Customer consents to the following sub-processor:

Company Location Service
Hetzner Online GmbH Gunzenhausen, Germany Servers and data centre

The Provider announces further sub-processors at least four weeks in advance in text form. The Customer may object; in that case either party may terminate the contract as of the planned change.

No processing takes place outside the EU.

7. Support for the Customer

The Provider supports the Customer with access, rectification and erasure requests from data subjects and with data protection impact assessments. If a data subject approaches the Provider, the Provider refers them to the Customer and informs the Customer.

8. Reporting breaches

The Provider reports a personal data breach to the Customer without undue delay, at the latest within 24 hours of becoming aware of it, stating what is known and what it is doing.

9. Deletion and return

After the contract ends the Provider deletes the data in accordance with § 6(3) of the main part. On request an export is provided beforehand.

10. Evidence

The Provider demonstrates compliance with this annex on request. An on-site inspection is possible by prior arrangement.

Last updated: 29/08/2026