General Terms and Conditions

As of: 7 September 2026

These terms govern business use of the "EU AI Act Compliance Scanner" service. The German version is authoritative; the English one is provided for convenience.

§ 1 Scope and provider

These terms apply to the use of the "EU AI Act Compliance Scanner" service, offered by Jan Kiefer, Eitelbrodstraße 22, 38108 Braunschweig, Germany (the "provider"; once registered: Luciphy UG (haftungsbeschränkt)). The service is directed exclusively at entrepreneurs within the meaning of § 14 BGB and at legal entities under public law. Contracts with consumers within the meaning of § 13 BGB are not concluded; business capacity is asked for and recorded at registration. Deviating or conflicting terms of the customer do not become part of the contract, even absent an express objection to them.

§ 2 Subject of the service

The provider supplies cloud-based software with which organisations can register their AI systems and classify them in the context of Regulation (EU) 2024/1689. This covers both the organisation's own code repositories, which are examined for AI components, and purchased AI systems without source code of their own, for which the evidence rests on the respective provider's statements and assurances. From both, the software produces supporting documentation. The results do not constitute legal advice and do not replace a case-by-case legal review. Classifications and generated documents are AI-assisted drafts for professional review; they are not a legal service within the meaning of the RDG and not a conformity assessment, certification or examination within the meaning of Regulation (EU) 2024/1689. The detailed scope follows from the service description of the plan chosen at conclusion of contract.

§ 3 Results, licence and responsibility

Classifications, evaluations and generated documents are produced wholly or partly with AI assistance and are drafts for professional review. They are neither a legal service within the meaning of the RDG nor a declaration of conformity, certification or assessment within the meaning of Regulation (EU) 2024/1689. Responsibility for the accuracy, completeness and use of the results - in particular towards authorities and third parties - remains with the customer, as do the customer's own obligations as provider or deployer of an AI system. The provider grants the customer a non-exclusive licence to the generated documents, unlimited in time and territory, for the customer's own purposes including passing them to conformity-assessment bodies, auditors and authorities.

§ 4 Registration and accounts

Use requires an account. Customers name an account holder and assign the available roles to further members; rights follow from the assigned role. Credentials, API keys and stored access tokens for code hosts must be kept secret and must not be made available to third parties. Sharing one account between several people is not permitted; each person gets their own. Customers keep the details in the account current and inform the provider without undue delay where there is reason to believe that unauthorised persons have learned of credentials. Actions taken through an account are attributable to the customer insofar as they are responsible for the misuse.

§ 5 Prices, scope of services and payment

The plans and usage quotas chosen at conclusion of contract apply. All prices are net and subject to statutory VAT. The unit of billing is the monitored system per billing month: a system counts for the month in which it is created or monitoring of it continues; its scans, classifications and generated documents are included. Billing is handled by the payment service provider Stripe; fees fall due on invoicing. In the event of default the provider may suspend access after prior notice; statutory claims remain unaffected.

§ 6 Customer obligations

Customers warrant that they are authorised to connect and analyse the respective repositories and to enter the details of purchased systems, and that they will not submit unlawful content. They hold the necessary rights of use in the content transmitted. Interference with the software and its security mechanisms, automated extraction beyond the interfaces provided, and attempts to influence processing through instructions embedded in submitted content (prompt injection) are prohibited. Customers cooperate as required, in particular by giving accurate information in the system profile - the meaningfulness of the results depends directly on it.

§ 7 Availability and support

The provider aims for 99 % availability of the application on an annual average, measured by reachability of the production instance. Excluded are periods of announced maintenance, which takes place outside usual business hours where possible, and outages the provider is not responsible for, in particular faults at upstream suppliers. No availability beyond this is warranted; no service level agreement with contractual penalties is associated with it. Support is provided asynchronously through the application's ticket system, in German and English.

§ 8 Data protection and processing

The privacy policy and the data-processing agreement (DPA) apply. The subprocessors used are listed in the corresponding register.

§ 9 Communication and advertising

Messages required to perform the contract - scan results, quota and security notices and the monthly compliance digest - are sent by the provider to the addresses held in the account; recurring messages can be turned off per person in the settings. Advertising messages, in particular the regulatory newsletter, are sent by the provider only with prior express consent (§ 7(2) UWG); that consent may be withdrawn at any time without giving reasons.

§ 10 Liability

The provider is liable without limitation for intent and gross negligence, for injury to life, body or health, under the Product Liability Act, and to the extent of any guarantee given. For slightly negligent breach of a material contractual duty - a duty whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the customer may regularly rely - liability is limited to the foreseeable damage typical of this kind of contract, and at most to the fees paid in the twelve months before the damaging event. Liability is otherwise excluded. Excluded in particular is liability for fines and sanctions imposed on the customer for their own breaches under Regulation (EU) 2024/1689 or the GDPR; meeting those obligations is the customer's task, and the software's results are drafts for professional review (§ 3). The rules on the burden of proof remain unaffected.

§ 11 Term and termination

Depending on the plan chosen, the contract runs for a monthly or a yearly term and renews for the same duration unless terminated by the end of the current period. Termination is by text form or directly through account management in the application. The right to terminate for cause remains unaffected. Free accounts may be ended by either side at any time without notice.

§ 12 Termination, data export and deletion

Until termination, customers can export their data themselves through the application at any time. After termination the provider deletes the organisation's content data; statutory retention duties and the retention of the audit trail remain unaffected. Export remains possible for 30 days after termination; content data is then deleted within a further 30 days. The audit trail is kept as an HMAC signature chain and is retained as proof of immutability where statutory retention duties require it; it records operations and field names, not the content itself.

§ 13 Final provisions

The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). The place of jurisdiction is, where permitted, Braunschweig. Should individual provisions be invalid, the validity of the remainder is unaffected.