Terms of Use
For the "Secure Password Share" web application
Please read these General Terms and Conditions of Use (hereinafter “Terms”) carefully before using the “Secure Password Share” web application (hereinafter “Application”). These Terms govern your use of the Application and set forth the conditions under which you may access the services. By using the Application, you agree to these Terms.
1. Scope and Subject Matter of the Agreement
These Terms apply to all users of the “Secure Password Share” Application, regardless of whether such use is part of the free offering (SPS Lite) or a paid offering (SPS Enterprise).
Secure Password Share is a web application for the secure transmission of sensitive information, particularly via time-limited links.
2. Definitions
“User” means any natural or legal person who uses the application.
“Consumer” means any natural person who enters into a legal transaction for purposes that are predominantly neither commercial nor related to their independent professional activity.
“Business User” means any natural or legal person who, when entering into a contract, acts in the course of their commercial or self-employed professional activity.
“SPS Lite” refers to the free version of the application.
“SPS Enterprise” refers to the paid versions of the application (S/M/L) offered through the Microsoft Azure Marketplace.
3. Conclusion of the Contract
The contract for the use of SPS Lite is concluded upon registration with one of the offered identity providers and acceptance of these terms and conditions.
The contract for SPS Enterprise is concluded by purchasing a corresponding plan through the Microsoft Azure Marketplace.
doubleSlash reserves the right to reject registrations without providing a reason.
4. Right of Withdrawal for Consumers
Consumers generally have a statutory right of withdrawal.
The right of withdrawal expires for digital services once performance of the contract has begun, provided the user has expressly consented and confirmed that they forfeit their right of withdrawal.
5. Service Description
The application enables the secure transmission of information via time-limited and single-use links.
SPS Lite offers basic functions without guaranteed availability.
SPS Enterprise offers advanced features in accordance with the current service description in the Microsoft Azure Marketplace.
The specific scope of services may change for technical or organizational reasons.
6. User Account and Login Credentials
To use SPS Lite, you must register or sign in via one of the supported identity providers. For SPS Enterprise, the access and authentication mechanisms specified in the Microsoft Azure Marketplace or in the respective instance apply.
You are obligated to treat your login credentials as confidential and to protect them from unauthorized access.
You are responsible for all activities carried out through your user account.
Secure Password Share reserves the right to suspend user accounts in the event of misuse or violations of these terms.
7. Pricing and Payment Terms
Use of SPS Lite is free of charge.
For SPS Enterprise, the prices listed in the Microsoft Azure Marketplace apply.
Billing is handled by Microsoft. The Microsoft Marketplace Terms and Conditions apply in addition.
8. Contract Term and Termination
Use of SPS Lite is open-ended and may be terminated at any time. Users can delete their account directly within the application via the menu item “Menu > Manage Account > Delete Account.” This option is only available for the instance provided by doubleSlash with social login.
For customer installations of SPS Enterprise via the Microsoft Azure Marketplace, the terms and conditions for termination of the respective plan booked in the Microsoft Azure Marketplace apply. Termination of use is carried out via the Microsoft Azure Marketplace, specifically by canceling or terminating the plan subscribed to there and uninstalling the provided instance. The “Delete Account” button is not available in these customer installations. Instructions for uninstallation and termination are provided in the Microsoft Azure Marketplace.
9. Rights of Use and Obligations of Use
Secure Password Share grants you a simple, non-transferable right to use the application.
Use is permitted exclusively within the scope of the intended functionality.
In particular, it is prohibited to circumvent security mechanisms, misuse the application, or distribute illegal content.
You are responsible for all content transmitted via the application.
10. Availability and Maintenance
Secure Password Share strives to ensure high availability of the application.
No specific level of availability is guaranteed for the free version.
Maintenance work may result in temporary restrictions.
11. Warranty
Statutory warranty rights apply to paid services.
For free use, the warranty is limited to the extent permitted by law.
12. Liability
Secure Password Share bears unlimited liability in cases of willful misconduct, gross negligence, and for damage to life, limb, or health.
In cases of simple negligence, Secure Password Share is liable only for breaches of material contractual obligations and limited to foreseeable damages.
Any further liability is excluded.
13. Data Protection
The processing of personal data is carried out in accordance with the Privacy Policy.
Insofar as data processing on behalf of a client is involved, the provisions of the Data Processing Agreement shall apply in addition, provided that such an agreement has been concluded between the parties or incorporated into the contract.
14. Intellectual Property
All rights to the application remain with doubleSlash.
It is prohibited to copy, modify, decompile, or otherwise analyze the application, unless permitted by law.
15. Relationship to the Microsoft Azure Marketplace
For paid offerings via the Microsoft Azure Marketplace, the Microsoft Commercial Marketplace Terms apply in addition.
Microsoft handles payment processing.
doubleSlash remains the provider and service provider of the application.
In the event of any conflicts, the Microsoft terms regarding payment processing shall take precedence.
16. Changes to the Terms
Secure Password Share reserves the right to amend these terms for operational reasons.
Changes will be announced at least four weeks before they take effect.
You have the right to object to the changes. If no objection is raised, the changes are deemed accepted.
17. Force Majeure
Secure Password Share is exempt from its obligation to perform to the extent that such performance becomes impossible due to events beyond its control.
18. Final Provisions
Should any individual provision of these Terms and Conditions be invalid, the validity of the remaining provisions shall remain unaffected.
Amendments and additions to these Terms and Conditions must be made in writing.
Rights and obligations under this contract may only be transferred with the consent of doubleSlash.
19. Governing Law and Place of Jurisdiction
The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
For consumers, mandatory consumer protection regulations of their country of residence remain unaffected.
For business customers, the place of jurisdiction is the registered office of doubleSlash Net-Business GmbH.
20. Contact and Support
If you have any problems or feedback regarding SPS, the support team is available through the following channels:
- Emailan info@secure-password-share.de
- via the feedback function in the application’s user menu
Support requests are typically answered within 24 hours on business days.
Data Processing Agreement (DPA)
1. Purpose and Duration of Processing
(1) This agreement governs the processing of personal data by doubleSlash Net-Business GmbH (“Processor”) on behalf of the customer (“Controller”).
(2) The processing takes place in connection with the use of the “Secure Password Share” (SPS) web application.
(3) The duration of the processing corresponds to the term of the underlying user agreement.
2. Nature and Purpose of the Processing
The processing serves to provide the application, in particular for:
- Creating and providing password links
- secure transmission of data
- Managing user accounts
- Ensuring the operation and security of the application
3. Type of Data and Categories of Data Subjects
(1) Categories of data processed:
- Access data (e.g., login information)
- Content data (e.g., transmitted passwords or files)
- Usage data (e.g., access, log data)
(2) Data subjects:
- Users of the application
- Recipients of password links
4. The Controller’s Right to Issue Instructions
(1) The processor shall process personal data exclusively in accordance with the documented instructions of the controller.
(2) Instructions shall be provided in writing (e.g., via email).
(3) If the processor considers an instruction to be unlawful, it shall immediately bring this to the attention of the controller.
5. Confidentiality
(1) The processor shall require all persons involved in data processing to maintain confidentiality.
(2) This obligation shall continue even after the termination of their employment.
6. Technical and Organizational Measures (TOMs)
The processor shall implement appropriate measures in accordance with Art. 32 of the GDPR, in particular:
- Access control: role-based permissions
- Access control: authentication (e.g., Microsoft login)
- Data transfer controls: encrypted data transmission (HTTPS/TLS)
- Storage control: Protection against unauthorized access
- Input Control: Logging of Access Events
- Availability control: Backup and recovery mechanisms
- Segregation Control: Logical Segregation of Data
These measures are regularly reviewed and updated.
7. Use of Subprocessors
(1) The processor may engage subprocessors (e.g., hosting providers).
(2) The controller has granted general authorization.
(3) The processor shall notify the controller of any changes regarding subprocessors.
(4) The data controller may object for good cause.
8. Obligations to Provide Assistance
The processor shall assist the controller in:
- the exercise of data subjects’ rights (Art. 15–22 GDPR)
- compliance with data breach notification obligations
- data protection impact assessments (Art. 35 GDPR), where necessary
9. Reporting of Data Breaches
(1) The processor shall promptly notify the controller of any personal data breaches.
(2) The notification shall include, to the extent possible:
- Nature of the breach
- Affected data
- Recommended measures
10. Rights of Inspection
(1) The data controller is entitled to verify compliance with this agreement.
(2) Inspections shall be conducted to a reasonable extent, taking trade secrets into account.
(3) The data processor shall provide the information necessary for this purpose.
11. Deletion and Return of Data
(1) Upon termination of the Agreement, personal data shall be deleted or returned, at the discretion of the Data Controller.
(2) Statutory retention obligations remain unaffected.
(3) Deletion shall be confirmed upon request.
12. Liability
Liability is governed by the statutory provisions of the GDPR and the underlying Terms and Conditions.
13. Final Provisions
(1) Amendments to this agreement must be made in writing.
(2) Should individual provisions be invalid, the remainder of the agreement shall remain valid.
(3) The General Terms and Conditions of Secure Password Share apply in addition.