Version: 1.0
Effective from: 30/07/2026, 21:52
Terms and Conditions (AGB)
§1 Scope and B2B status
- These terms apply to all contracts between SHELL-AFFECT as contractor and the customer as client for the conception, creation, extension and technical implementation of individual websites, web applications, cybersecurity assessments and related digital services.
- The services are directed exclusively at entrepreneurs within the meaning of Sec. 14 BGB. Consumers within the meaning of Sec. 13 BGB are excluded from contract formation.
- By submitting a project request and B2B confirmation, the customer confirms that they act in the exercise of commercial or independent professional activity. Incorrect information may lead to rejection or termination for cause.
- Deviating customer terms apply only if SHELL-AFFECT expressly agrees to them in text form.
§2 Contract formation
- The website, price examples and live calculations are not binding offers. They invite the customer to submit a project request.
- The customer submits a binding project request by sending the questionnaire and confirming the terms, B2B status and billing data.
- A contract is formed only when SHELL-AFFECT accepts the request in text form, releases a first Stripe invoice or payment link, or starts performance after express acceptance.
- Project start requires full receipt of the first installment. Until then, there is no duty to start work.
- SHELL-AFFECT may reject requests, especially where project information, billing data, B2B status, legality or economic feasibility is unclear.
§3 Scope of services
- SHELL-AFFECT provides freelance IT, software development and cybersecurity services with a focus on security-oriented conception, architecture, implementation and review of individual websites, web applications and digital attack surfaces.
- The specific scope follows from the accepted project configuration, any additional agreements and these terms. Development projects are generally aimed at an agreed work result. Consulting, support, training, research, security assessment or operations services may be agreed as services or ancillary services.
- Cybersecurity services such as CASP, authorized penetration tests, IT security audits or executive exposure reviews are performed only within the accepted scope, authorization, rules of engagement, target list, time window and communication path.
- Depending on the agreement, services may include conception, information architecture, design system creation, UI implementation, web development, API or payment integrations, dashboard functions, basic technical optimization and appropriate security-oriented safeguards.
- Legal texts, imprint, privacy notices, terms, cookie notices or comparable content are not legal advice. Technical integration support — including optional AI suggestions in the questionnaire — does not replace legal review. The customer remains responsible for legality, accuracy, timeliness and approval.
5a. The optional questionnaire AI assistant in the customer dashboard is a platform tool, not a separate contract for work or consulting engagement. Outputs may be incorrect. AI suggestions accepted by the customer count as the customer’s own inputs and cooperation under §5. Outage, quota exhaustion or disabling of the assistant does not constitute a defect of the project deliverable and creates no damages claim, subject to §10.
- Security-oriented development within the agreed project scope does not replace a separately commissioned penetration test, IT security audit, certification, or any assurance or guarantee that the delivered website or web application can be operated permanently, without interruption, free of attacks or free of vulnerabilities. Formal security assessments, hardening beyond the agreed scope, ongoing security maintenance and re-tests after go-live are owed only if separately commissioned and paid for.
- SHELL-AFFECT does not provide ongoing hosting, server or operations services unless separately agreed. Hosting contracts, costs, backups, updates, availability and operation remain with the customer.
- Services outside the agreed scope, especially new features, pages, migrations, redesigns, maintenance or major conceptual changes, are offered and billed separately.
- Performance is primarily provided by SHELL-AFFECT. SHELL-AFFECT may engage suitable vicarious agents and subcontractors, provided confidentiality and, where required, data-protection requirements (including any processing on behalf) are observed. Responsibility toward the customer remains with SHELL-AFFECT.
§4 Prices, Stripe invoices and payment terms
- Project prices displayed in the system are in euros including statutory VAT unless expressly shown as net amounts. The finalized invoice is decisive.
- The total price results from project configuration, quality level, additional features, express or extension options and agreed discounts or credits.
- Payment is made in two installments: 50 percent as down payment after acceptance and before project start; 50 percent after completion, acceptance or deemed acceptance, before final handover or go-live.
- Payments are processed through Stripe. The payment methods shown in the Stripe hosted invoice, payment link or checkout are decisive.
- For online payments, the Stripe-finalized invoice number, hosted invoice and invoice PDF provided by Stripe are the decisive invoice level. Dashboard views are project context and technical copies.
- Invoices and payment links are provided by email and/or in the customer dashboard.
- In case of late payment, statutory rules apply. SHELL-AFFECT may suspend work until payment is received.
- Referral or account credits are not payable in cash, do not bear interest and can be offset only against future SHELL-AFFECT services; an invoice cannot be reduced below EUR 0. A claim to referral credit arises only after the referred customer used the referral link/code, bound or submitted a project, and fully paid the regular project installments (in particular the first installment and the final installment). Mere registrations, open requests, drafts, unpaid, cancelled or terminated projects create no payout or credit claim.
- Delivery times begin only after contract formation, full receipt of the down payment and full provision of required customer cooperation.
- Set-off and retention: The customer may only set off against undisputed or finally adjudicated claims. Rights of retention exist only insofar as they arise from the same contractual relationship.
§5 Customer cooperation
- The customer provides all required information, content, brand materials, access credentials, approvals, technical data, references and decisions on time, completely and in suitable form.
- The customer confirms that they hold the necessary rights to provided content and indemnifies SHELL-AFFECT against resulting third-party claims.
- For cybersecurity services, the customer confirms authorization for all named targets and indemnifies SHELL-AFFECT against claims arising from missing or incorrect authorization.
- Communication primarily takes place through the customer dashboard and by email.
- If required cooperation is not provided within a reasonable deadline, SHELL-AFFECT may shift deadlines, suspend services, charge additional effort or terminate under statutory rules.
- SHELL-AFFECT develops locally and generally has no access to the customer’s production infrastructure, tools or personal data stores. The customer provides mock, demo or anonymized data for development. Third-party personal data may only be provided if expressly agreed; in that case the parties conclude a data processing agreement under Art. 28 GDPR before processing begins.
§6 Revisions and additional services
- The offer includes the stated number of revision rounds. A revision round covers collected customer change requests that deviate from the approved or submitted project plan (questionnaire, accepted configuration, approved designs and the written scope).
- In particular, a revision includes content, design or functional changes that go beyond implementing the approved plan or that alter the plan after approval (e.g. changed copy/layouts, reordering, further tweaks to already agreed elements).
- Development defects and deviations of the delivered implementation from the approved plan are not revisions and do not consume a revision round; they are remedied free of charge under warranty when the work does not match the agreed plan and the customer is not requesting a changed plan.
- New features, pages, fundamental direction changes, later requirement changes, integrations, migrations, legal checks, ongoing maintenance or other work outside the agreed scope are not revisions and are not free within a revision round.
- Additional revision credits apply as shown in the dashboard. Other change requests are billed separately under a separate offer or the current price list.
§7 Acceptance and warranty
- SHELL-AFFECT provides the completed work or an acceptability-ready phase through dashboard, preview, test system, repository or another suitable channel.
- The customer reviews the service without undue delay. SHELL-AFFECT may request acceptance and set a reasonable deadline of at least 14 days.
- Acceptance is deemed given if the customer expressly accepts, uses the work productively, pays the final installment without reservation, or lets the deadline pass without refusing acceptance by naming at least one specific defect.
- Defects must be reported in text form with understandable description and reproduction steps. SHELL-AFFECT receives an opportunity to remedy within a reasonable period.
- For B2B contracts, the warranty period for defects in work is limited to 12 months from acceptance to the extent permitted by law. Mandatory statutory rights remain unaffected.
- No warranty applies to disruptions caused by later changes by the customer or third parties, unsuitable hosting, third-party outages, cyberattacks or other circumstances outside SHELL-AFFECT’s control.
- Security-related defects at acceptance. Where the individual deliverable (website or web application) is owed as a contract for work, defects under this §7 include in particular security-related deviations of the delivered own work from the agreed scope that
a) already existed at acceptance (or deemed acceptance under §7(3)) and were recognizable to the customer upon contractual review or reasonably demonstrable, or b) are reported within the warranty period under paragraph 5 in text form with an understandable description, reproduction steps and, where possible, a severity assessment (e.g. under common vulnerability scoring practices), and that c) fall within SHELL-AFFECT’s sphere (agreed code, configuration and integration scope of the own work), and not solely within the customer’s sphere, third-party systems chosen by the customer, hosting, DNS, email, identity providers, browsers, operating systems, framework/dependency updates after acceptance, later third-party changes, or general zero-day risks outside SHELL-AFFECT’s control.
- No security state as a guarantee. SHELL-AFFECT does not give a guarantee or strict assurance that the delivered website or web application is free of critical, severe or other vulnerabilities at delivery, acceptance or go-live. Freedom from vulnerabilities is not an assured characteristic in the sense of a guarantee. The agreed description of services, the acceptance rules of this §7 and liability under §10 remain decisive.
- Remedies for justified security defects. For a security-related defect validly reported under paragraph 7, primary performance is remedy (repair) within a reasonable period. Further claims, in particular damages for security incidents, data loss, business interruption, third-party loss or lost profits, are governed solely by §10 and mandatory statutory law to the extent not validly excluded. Immaterial security findings, pure best-practice notes and findings outside the agreed scope do not justify refusal of acceptance and do not create a claim to free redevelopment or ongoing security maintenance.
§8 Acceptance satisfaction rule
- The final installment becomes due only after completion, acceptance or deemed acceptance. Material, justified defects must be handled before final handover.
- This rule is not a general money-back guarantee.
- Statutory defect rights and §9 remain unaffected.
§9 Termination, cancellation and settlement under Sec. 648 BGB
- The customer may terminate a contract for work at any time until completion. Sec. 648 BGB applies.
- For services not owed as a specific work result, performed services, reserved capacity and non-cancellable third-party costs are settled according to the agreement and statutory rules.
- Orientation refund values (subject to proof of different statutory remuneration or savings): before project start, 85 percent refund of the first installment; after start but before design approval or below 50 percent progress, usually 50 percent; after design approval, from 50 percent progress or substantial completion, usually no refund of the first installment.
- An unpaid final installment becomes due only to the extent owed based on project status, acceptance, performed work or statutory settlement.
- Account and referral credits are not payable in cash.
- SHELL-AFFECT may terminate for cause, especially late payment, missing cooperation, incorrect B2B confirmation, unlawful project content or persistent disruption.
- Work results are handed over only after all due remuneration up to that point has been paid.
§10 Liability and security limits
- Unlimited liability for intent, gross negligence, injury to life, body or health, fraudulent concealment, assumed guarantee and mandatory statutory liability.
- For slightly negligent breach of essential contractual obligations, liability is limited to typical and foreseeable damage, and in any event not exceeding the total net remuneration agreed for the affected contract. Otherwise slight negligence is excluded to the extent permitted by law.
- No liability for content, tools or third-party services supplied or chosen by the customer.
- No guarantee of freedom from vulnerabilities. Without a separate written security engagement (e.g. penetration test, IT security audit, CASP, executive exposure review, ongoing maintenance), SHELL-AFFECT does not owe a complete security assessment, certification, or any guarantee or assurance of vulnerability-free, uninterrupted or attack-free operation—neither at delivery or acceptance nor thereafter. Security-oriented implementation included in a development project is not an assurance of a particular security level under external standards (e.g. OWASP ASVS, ISO 27001) unless expressly agreed.
- Scope allocation and customer co-responsibility. SHELL-AFFECT is not liable for security incidents and related damage to the extent they materially result from the customer or third parties engaged by the customer
a) making changes after acceptance to code, infrastructure, access credentials, secrets, CMS/plugins or integrations, b) failing to apply updates, patches, backups, access controls or hosting hardening, c) selecting or operating insecure third-party, payment, email or identity services, or d) breaching cooperation or notification duties (including prompt reporting of concrete security suspicions). The burden of proof for such circumstances in B2B relationships follows statutory law; this clause does not create a contractual reverse burden of proof against the customer where that would be unlawful.
- Damages and cap. Where SHELL-AFFECT is liable in principle for security defects or incidents under paragraphs 1 and 2, the limitation in paragraph 2 remains unaffected. In particular, liability for slight negligence is limited to typical and foreseeable damage and in any event not exceeding the total net remuneration agreed for the affected contract, to the extent permitted by law. Unlimited liability under paragraph 1 and mandatory statutory rights remain unaffected.
- No specific economic result is owed (including rankings, traffic, conversion rates, revenue or market outcomes).
- AI tools: Where the optional questionnaire assistant is used, SHELL-AFFECT is not liable for the accuracy, completeness or currency of AI outputs, except for intent or gross negligence or unlimited liability under paragraph 1. The customer reviews all accepted suggestions themselves.
§11 Rights of use, source code and third-party components
- After full payment, the customer receives a simple, geographically and temporally unrestricted right to use the individually created work results for the agreed business purpose.
- Exclusive rights only if expressly agreed in text form. Until full payment, rights remain with SHELL-AFFECT.
- Pre-existing know-how, generic modules, internal tools and non-customer-specific building blocks remain with SHELL-AFFECT.
- Open-source and third-party components are subject to their respective licenses.
- Source code and project documentation are provided in reasonable scope after full payment. Internal tools, secrets and third-party rights are excluded.
- SHELL-AFFECT may name a publicly released project as a reference unless confidential information would be disclosed or the customer objects in text form.
§12 Data protection and processing on behalf
- SHELL-AFFECT processes personal data for pre-contractual communication, contract performance, communication, invoicing, payment processing, documentation and — where used — operation of the optional questionnaire assistant under GDPR and German data protection law. Details: Privacy Policy.
- For account, login, billing and communication data of the customer, SHELL-AFFECT is generally the controller.
- Processing on behalf under Art. 28 GDPR only arises if SHELL-AFFECT processes third-party personal data on the customer’s documented instructions (e.g. import of real customer data, user database migration). In that case a DPA is concluded before processing begins. Pure local development without access to the customer’s personal data stores does not constitute processing on behalf.
- For the questionnaire assistant SHELL-AFFECT uses technical providers (in particular Cloudflare Workers AI). Account identifiers are not sent to AI inference; content is privacy-minimised first. Neither SHELL-AFFECT nor — based on Cloudflare’s Workers AI documentation known to us — Cloudflare uses chat/fill content to train AI models without separate explicit consent.
§13 Confidentiality
- Both parties treat confidential information of the other party as confidential and use it only for contract performance.
- Exceptions: public information without breach, prior lawful knowledge, lawful third-party disclosure, or legal/administrative/court duties.
- Confidentiality continues for five years after contract end; trade secrets remain protected as long as legally protected. Statutory retention and disclosure to professionally bound advisers remain permitted.
§14 Platform account, acceptable use and suspension
- Use of the customer dashboard is also subject to the separate Terms of Use.
- No cyberattacks, probes, injection attacks or similar abuse via the platform.
- No unlawful content uploads. SHELL-AFFECT may remove or block such content and restrict the account. Reports: support@shell-affect.com.
- Accounts may be locked automatically or manually for misuse, security threats or material breach.
- Unlock after cyberattack or abuse attempts is at SHELL-AFFECT’s equitable discretion, taking into account the specific circumstances (in particular severity, recurrence, the customer’s cooperation, and actual or imminent harm). There is no claim to unlock within a particular time.
- No claim to refund for policy locks to the extent permitted by law.
- Termination for cause remains available in parallel.
- Reverse engineering: Reverse engineering, decompiling, disassembling or otherwise probing SHELL-AFFECT platform software, interfaces or security mechanisms is prohibited except where mandatory law (in particular Sec. 69d, 69e UrhG) provides otherwise.
§15 Platform availability and force majeure
- The customer dashboard is a tool for contract performance. No specific availability (SLA) is owed unless separately agreed.
- Maintenance, updates and temporary restrictions are permitted. Material interruptions are announced where reasonable.
- No liability for force majeure or circumstances beyond reasonable control (network/power outages, Cloudflare or infrastructure failures, third-party attacks, official measures, etc.).
- Temporary unavailability alone does not create a damages claim to the extent permitted by law and subject to §10.
§16 Customer content on the platform
- The customer retains rights to uploaded or submitted content.
- SHELL-AFFECT receives a non-exclusive right to store and process such content for contract performance and to make it available internally to persons assigned to the engagement.
- After project end, termination or account deletion, statutory retention rules and the Terms of Use on export and deletion apply.
§17 Good-faith dispute resolution
- Before court proceedings about a platform or project dispute, the parties first attempt good-faith bilateral resolution via dashboard and/or email within a reasonable period.
- This does not exclude interim relief, limitation periods, non-waivable rights or termination for cause.
§18 Consumer dispute resolution
- Services are directed exclusively at entrepreneurs.
- SHELL-AFFECT is neither willing nor obliged to participate in consumer arbitration board proceedings.
- The former EU ODR platform has been discontinued; no link is provided.
§19 Changes to these terms
- SHELL-AFFECT may update these terms for the future where legally, technically or organizationally necessary and not unreasonably detrimental to the customer.
- Material changes are announced by email and/or dashboard with reasonable advance notice and documented with a change summary.
- If the customer does not object within the period stated in the notice and continues use, the changed terms apply to the extent permitted by law. Non-waivable rights remain unaffected.
- The version published on shell-affect.com is decisive.
§20 Final provisions
- German law applies, excluding the CISG.
- If the customer is a merchant, legal entity under public law or special fund under public law, venue is the business seat of SHELL-AFFECT. Mandatory venues remain unaffected.
- Changes and additions require text form unless stricter form is required. Individual agreements take precedence.
- The German version is authoritative. The English version is a convenience translation unless otherwise agreed in text form.
- If individual provisions are invalid, the remaining provisions remain effective; statutory rules replace the invalid provision.
Version 1.0 · Last updated: July 2026
Last updated: 30/07/2026 · v1.0