Legal
Terms and Conditions
1. Scope and business customers
1.1 These Terms and Conditions (“Terms”) apply to all contracts for use of the ByeBot CAPTCHA and bot-detection service (“Service”) between Luvion Labs UG (haftungsbeschränkt), Rheydter Straße 67, 41352 Korschenbroich, registered with Amtsgericht Neuss under HRB 25514 (“Provider”), and the customer (“Customer”). Further provider details appear in the Legal notice.
1.2 The Service is offered exclusively to entrepreneurs within § 14 BGB: natural or legal persons or partnerships with legal capacity acting in the course of their commercial or independent professional activity. The Provider does not contract with consumers under § 13 BGB. Registration confirms that the Customer acts as an entrepreneur. If a Customer proves to be a consumer, either party may terminate immediately; prepaid fees will be refunded pro rata.
1.3 Deviating, conflicting, or supplementary terms of the Customer do not become part of the contract even if the Provider does not expressly object. 1.4 The contractual language is German.
2. Formation of contract
2.1 The Customer opens an account by providing an email address and confirming the sign-in link sent by email. Confirmation creates an account-use agreement under these Terms. An account without a subscription provides dashboard access but not use of the Service on Customer websites.
2.2 The Customer purchases a subscription through the payment provider’s checkout in the dashboard. Completing checkout is a binding offer. The subscription contract begins when the Provider confirms the booking by email or enables the Service, whichever occurs first.
2.3 The selected volume, billing period, and price are shown during checkout and remain available in the dashboard. The Provider does not separately store the contract text; the controlling version is the version of these Terms in force when booked, which the Customer can save and print.
3. Service description
3.1 The Service includes the challenge widget for Customer websites and applications, the server-side verification API, the configuration and statistics dashboard, and documentation. Scope follows these Terms and the checkout details under § 2.3.
3.2 The Service uses technical methods to assess whether a request comes from a person or a program and to impede automated abuse. No bot protection can exclude all automation, and individual human visitors may be rejected incorrectly. The Provider owes the described functionality, not a particular detection result.
3.3 Every subscription includes all functions. Subscriptions differ by monthly check volume (§ 5.2), numbers of websites and domains, and dashboard-statistics retention. Current values appear in the pricing section.
3.4 The Provider may modify functions for good cause, especially detection effectiveness, technical development, security, or legal change, provided the core agreed service remains. Material adverse changes will be announced in text form at least six weeks in advance; the Customer may terminate when the change takes effect and will be informed of that right.
3.5 Delivery occurs at the egress of the data centres running the Service. Internet connectivity for the Customer and its visitors is outside the contract. 3.6 No particular accessibility conformity of the widget is owed.
4. Trial
4.1 New Customers may test the Service once for seven days at no charge. A payment method is required. The trial volume is 10,000 checks per month regardless of the selected subscription.
4.2 At the end of the trial, the account moves to the paid subscription selected during booking and the displayed price is first charged. Cancellation in the dashboard during the trial ends the contract when the trial expires without charge.
4.3 During the free trial the Provider is liable only for intent and gross negligence; § 14.4 remains unaffected.
5. Prices, counting, and payment
5.1 The prices shown in the pricing section and checkout at booking apply. All prices are net plus statutory VAT, which is shown separately during checkout and on invoices.
5.2 Price depends on the booked monthly check volume. A check counts when a request reaches verification, whether it passes or fails. Earlier rejections, including Customer block lists, country filters, rate limits, or Provider server-side preliminary checks, do not count. Each billing month begins on the contract-start day; its volume renews and its counter resets monthly even with annual payment. The payment period is one month or one year as selected.
5.3 The Customer may change volume in the dashboard. The change applies immediately and the payment provider prorates the difference as a charge or credit. Volume cannot be changed during the trial.
5.4 Fees are due at the start of each payment period and collected from the stored payment method. The provider named in § 18.3 processes payment. Invoices are electronic.
5.5 In payment default the Customer owes interest at nine percentage points above the base rate (§ 288(2) BGB) and the statutory €40 lump sum (§ 288(5) BGB), credited against recoverable enforcement costs. Further damages remain reserved. After notice, the Provider may suspend the Service (§ 10).
6. Exceeding the volume
6.1 Current monthly usage is always available in the dashboard; the Customer monitors it.
6.2 Once the volume is reached, all websites in the account switch to demo mode for the rest of the billing month. The widget remains visible and reports success without checking, and the verification API continues to accept the issued tokens. A server-verified form remains usable but is not protected against automated access during this period. The Customer acknowledges this consequence.
6.3 Increasing volume in the dashboard avoids or ends the switch. The prior widget modes are restored automatically after an increase or at the next billing month. Sites deliberately placed in demo mode are unaffected. There is no retrospective overage charge.
7. Price changes
7.1 The agreed booking price applies for the current subscription term. 7.2 To change it, the Provider terminates under § 8.2 at term end and offers continuation at the new price.
8. Term, termination, and contract end
8.1 The account-use agreement runs indefinitely. Either party may terminate it without notice; the Customer does so by deleting the account in the dashboard.
8.2 A subscription runs for one month or one year and renews for the same term unless terminated by its last day. Either party may terminate for term end; the Customer may use the dashboard or text form sent to § 20.7, and the Provider uses text form. Service continues in full until then and there is no pro-rata refund, except where early termination under § 3.4, § 19.3, § 20.4, or § 5.3 of the DPA requires refund of the unused prepaid period. § 545 BGB does not apply.
8.3 Termination for good cause remains available. For the Provider, good cause includes a continued § 9 breach after warning or default on two consecutive payment periods.
8.4 At contract end the licence expires and checks stop. The Customer removes the integration. On request in text form within 30 days, the Provider supplies website configuration and aggregate statistics in a common machine-readable format without a fee for supply, switching assistance, or termination. After 30 days account data is deleted under the DPA unless statutory retention duties apply.
8.5 Provisions intended to survive, especially § 8.4, §§ 14, 15, 17, 18, and 20 and § 9 of the DPA, remain effective.
9. Customer obligations
9.1 The Customer must:
- keep credentials, sign-in links, and API keys confidential and report unauthorised account use immediately;
- integrate the widget and server verification according to the documentation and test them after website changes;
- use the Service only on websites and applications for which it is responsible and only for lawful purposes;
- inform visitors about the Service in its privacy policy and take responsibility for the legal basis, using the DPA’s processing description;
- keep email and billing data current and back up its own configuration at reasonable intervals.
9.2 The Customer must not:
- circumvent, disrupt, or analyse Service security, including reverse engineering widgets or scripts, except where §§ 69d and 69e UrhG permit; testing the Customer’s own integration remains permitted;
- resell, sublicense, or offer the Service as its own without prior Provider consent in text form;
- use the Service for malware, to block legitimate third-party access, or contrary to data-protection law; or
- manipulate verification tokens or direct load attacks at the Service.
10. Suspension
10.1 The Provider may suspend access wholly or partly for a § 9 breach, payment default (§ 5.5), or a threat to Service security or availability originating from the Customer’s account or websites.
10.2 Where reasonably possible, especially without immediate danger, the Provider gives prior notice in text form and a reasonable cure period. Suspension ends when its cause ends. Fees remain payable during a suspension attributable to the Customer.
11. Availability and maintenance
11.1 The Provider makes the Service available at the delivery point and maintains it in a condition suitable for contractual use during the term.
11.2 Where possible, disruptive maintenance is announced in the dashboard or in text form. Urgent security maintenance needs no advance notice. Announced maintenance windows totalling up to four hours per calendar month are not a defect.
11.3 Continuous operation is not owed. The Provider is not responsible for effects outside its control, especially internet disruption, third-party attacks that reasonable safeguards could not prevent, or incorrect Customer integration; these and § 11.2 maintenance are not defects.
11.4 The Customer reports faults immediately to § 20.7 with enough detail for reproduction.
12. Rights of use and feedback
12.1 For the contract term, the Provider grants a non-exclusive, non-transferable right to use the widget and scripts on Customer websites and applications and call the API according to the documentation. All other rights in the Service, software, marks, and documentation remain with the Provider.
12.2 The Provider may use suggestions, bug reports, and other feedback without payment or attribution to improve the Service, excluding § 17 confidential information. The Customer must not submit third-party confidential information as feedback.
13. Defects
13.1 The Customer reports a defect immediately (§ 11.4). The Provider remedies defects within a reasonable period and may provide a workaround that substantially restores use while a final remedy follows within reasonable time.
13.2 Statutory defect rights, including fee reduction for a Provider-attributable defect, remain unaffected. Damages follow § 14.
13.3 Failure to detect automation or rejection of a human in individual cases (§ 3.2), a § 11.3 circumstance, or integration contrary to documentation is not a defect.
14. Liability
14.1 The Provider has unlimited liability for damage caused intentionally or through gross negligence by it, its legal representatives, or agents.
14.2 For slight negligence, liability applies only to essential contractual duties whose fulfilment enables proper performance and on which the Customer may regularly rely, especially § 11.1 availability. Liability is then limited to typical, foreseeable damage at contract formation. The parties define that damage across all claims in a calendar year as no more than the higher of the net fees owed or paid for that year.
14.3 Otherwise liability for slight negligence is excluded, as is strict liability for defects already present at contract formation under § 536a(1), alternative 1 BGB.
14.4 These limits do not apply to injury to life, body, or health; Product Liability Act liability; a Provider guarantee; fraudulent concealment; or Art. 82 GDPR claims.
14.5 For data loss, liability under the preceding clauses is limited to restoration effort that proper regular Customer backups (§ 9.1) would have required. 14.6 These rules also apply personally to Provider officers, employees, and agents.
15. Indemnity
15.1 If a third party claims against the Provider because the Customer used the Service contrary to § 9, especially by failing to inform visitors or integrating it on a third-party website without consent, the Customer indemnifies the Provider against those claims and reasonable defence costs to the extent the Customer is responsible.
15.2 The Provider promptly informs the Customer, makes no admission without consent, and on request permits the Customer to conduct the defence where reasonable.
16. Force majeure
16.1 Neither party is responsible for delay or non-performance caused by force majeure outside its control and not avoidable with reasonable care, including natural events, epidemics, war, strikes, official orders, or widespread electricity or telecommunications outages. The affected party promptly informs the other. Duties are suspended and fees reduced pro rata for the event’s duration.
16.2 If the event lasts over three months, either party may terminate in text form.
17. Confidentiality
17.1 Each party keeps information marked confidential or recognisably confidential under the circumstances, especially API keys, configurations, statistics, individually agreed prices, and technical Service details, confidential and uses it only for the contract. This duty lasts three years after contract end and, for trade secrets under the German Trade Secrets Act, while secrecy persists.
17.2 It excludes information publicly known without breach, already known to the recipient, or lawfully obtained from third parties. Statutory disclosure duties remain; where permitted, the affected party is informed beforehand.
18. Data protection and DPA
18.1 When used on Customer websites, the Provider processes visitor personal data on the Customer’s behalf. The Data Processing Agreement under Art. 28 GDPR, including its annexes, becomes part of the contract. For data-protection conflicts, the DPA prevails.
18.2 The Provider acts as controller for Customer and employee personal data needed for accounts, billing, and communication. Details appear in the Privacy policy.
18.3 Stripe Payments Europe, Ltd., Dublin, Ireland processes payments. Customers enter payment data directly with Stripe; the Provider receives no complete payment-instrument data.
19. Changes to these Terms
19.1 The Provider may change these Terms for good cause, especially legal or case-law change, technical Service change, or closing a regulatory gap, provided the balance of performance and consideration does not shift against the Customer. Main-service and fee changes follow only §§ 3.4 and 7.
19.2 Changed Terms are communicated in text form at least six weeks before taking effect with changes highlighted. Unless the Customer objects in text form by that date, they apply from then. The notice explains that consequence and the objection right.
19.3 On objection, the prior Terms continue. The Provider may then ordinarily terminate at the current term’s end.
20. Final provisions
20.1 German law applies, excluding the UN Convention on Contracts for the International Sale of Goods.
20.2 If the Customer is a merchant, public-law legal entity, or public-law special fund, the Provider’s registered office is the exclusive venue for contract disputes. The Provider may also sue at the Customer’s general venue.
20.3 The Customer may set off only undisputed, ready-for-decision, or finally adjudicated claims and may retain only for a counterclaim from the same contractual relationship.
20.4 Assignment of rights or duties requires Provider consent in text form; § 354a HGB remains unaffected. The Provider may transfer the contract to an affiliate or successor after six weeks’ notice in text form, with a Customer right to terminate at transfer.
20.5 Contractual text-form declarations are effective by email to the Customer’s account address and the Provider’s § 20.7 address. 20.6 If a term is ineffective, the rest of the contract remains effective and statutory rules replace it.
20.7 Contract notices and enquiries go to the contact details in the Legal notice or info@byebot.de.
20.8 In conflicts, precedence is: an individual agreement in text form; for data protection, the DPA; these Terms; then the § 3.1 service description. The Customer can save and print the applicable Terms and DPA.
Version 2.0, effective 4 September 2026