Terms of Use of octoja GmbH
for Resellers and Managed Service Providers (MSP)
octoja GmbH — As of: July 2026
This is a courtesy translation. The legally binding version is the German original.
Notice: These Terms of Use are addressed exclusively to businesses within the meaning of § 14 BGB (B2B). Use by consumers within the meaning of § 13 BGB is neither intended nor permitted. The usage license is acquired through an authorized octoja distributor.
§ 1 Scope of Application
- These Terms of Use (hereinafter "ToU") of octoja GmbH (hereinafter "octoja") govern the conditions under which resellers and managed service providers (hereinafter collectively "User") may use the octoja RMM platform (hereinafter "Platform").
- The User has licensed the Platform through a distributor authorized by octoja. The contractual partner of the User with respect to remuneration, billing, and commercial terms is exclusively the respective distributor. octoja acts as a third party within the meaning of these ToU and operates vis-à-vis the User solely as the Platform operator.
- Deviating terms and conditions of the User shall have no validity against these ToU unless octoja expressly agrees to them in writing.
- By using the Platform for the first time (login, account activation), the User bindingly acknowledges these ToU.
§ 2 Subject Matter of Services
- octoja provides the User with the Platform as Software-as-a-Service (SaaS) via the Internet.
- The Platform enables the User in particular to:
- remotely monitor, control, and manage IT endpoints and systems of their customers (hereinafter "End Customers"),
- automate recurring IT tasks,
- perform patch and update management for managed endpoints,
- create reports, evaluations, and documentation,
- manage user roles and access permissions.
- octoja is entitled to adjust, expand, or replace individual functions of the Platform in line with technological progress. The User will be informed of material changes in a timely manner. There is no entitlement to the retention of a specific scope of functions.
- octoja is not responsible for:
- the internet connection of the User or their End Customers,
- the proper configuration of systems managed by the User,
- content, data, or actions initiated by the User via the Platform.
§ 3 Usage Rights
- octoja grants the User, for the duration of the contractual relationship, a simple, non-transferable, and non-sublicensable right to use the Platform exclusively for providing IT managed services to their End Customers.
- Usage is limited to the User and their authorized employees (hereinafter "User Accounts"). Sharing access credentials or User Accounts with third parties outside the User's organization is not permitted.
- The User is not entitled to offer the Platform or parts thereof to third parties as a standalone product under their own brand name (white-label) unless this has been separately agreed in writing with octoja.
- All rights to the Platform, including source code, design, functionalities, trademarks, and other intellectual property rights, remain exclusively with octoja or its licensors. The User does not acquire any ownership rights.
§ 4 Obligations and Duties of the User
- The User undertakes to use the Platform exclusively in accordance with these ToU, applicable laws, and the rights of third parties.
- The User is specifically prohibited from:
- using the Platform for unlawful purposes or instructing third parties to do so,
- introducing or distributing malicious code, viruses, trojans, or other harmful programs,
- overloading, attacking, or manipulating the Platform infrastructure,
- circumventing, disabling, or undermining security mechanisms of the Platform,
- decompiling, disassembling, or reverse-engineering the source code or architecture of the Platform,
- accessing systems, networks, or data of third parties without authorization – even if such systems are generally reachable via the Platform,
- using the Platform for penetration tests, vulnerability scans, or similar security analyses against infrastructures for which the User does not have explicit authorization.
- Responsibility towards End Customers: The User is solely responsible for all actions that they or their employees carry out on End Customer systems via the Platform. The User ensures that they have sufficient legal basis for each access to End Customer systems (in particular, a written managed service agreement with their End Customers that expressly permits remote access and remote management).
- Credential Security: The User is obligated to securely store access credentials, API keys, and other authentication means and to protect them from unauthorized access. octoja must be notified immediately in the event of suspected compromise.
- Data Backup: The User is solely responsible for regular and sufficient data backup of their own systems as well as their End Customers' systems. octoja assumes no responsibility for data losses attributable to missing or insufficient data backups.
- Testing Obligation Before Rollout: The User is obligated to test to a reasonable extent all scripts, automations, patch rollouts, and configuration changes initiated or configured by the User on test or reference devices prior to deployment in production environments, and to verify compatibility and error-free operation. The User bears sole responsibility for damages caused by untested deployment of such measures on production systems. octoja is not liable for damages resulting from the User's failure to adequately fulfil this testing obligation. This applies in particular to system failures, data losses, or operational disruptions at the User's End Customers. This does not apply to damages caused by defects of the Platform itself; § 6 applies in that respect.
- Reporting Obligation: The User undertakes to immediately inform octoja of security incidents, misuse, unauthorized access, or malfunctions of the Platform upon becoming aware of them.
- Accurate Information: The User undertakes to provide truthful and complete information during registration and ongoing operations and to keep such information up to date.
§ 5 Availability and Maintenance
- octoja strives for high availability of the Platform. A guaranteed minimum availability is only assured within the framework of a separately agreed Service Level Agreement (SLA). Without a separate SLA, there is no entitlement to a specific availability.
- octoja is entitled to temporarily restrict or interrupt the Platform for maintenance work, updates, and security-relevant measures. Planned maintenance windows will be announced to the User, where possible, at least 48 hours in advance.
- No liability exists for outages or impairments resulting from the following circumstances:
- disruptions to telecommunications or internet infrastructure,
- failures of third-party services (e.g., cloud infrastructure, DNS, external APIs),
- force majeure, natural disasters, pandemics, or governmental orders,
- cyberattacks, DDoS attacks, or comparable external influences,
- errors or incompatibilities on the part of the User's or their End Customers' systems.
§ 6 Liability of octoja
- Unlimited Liability: octoja is liable without limitation for damages arising from injury to life, body, or health, as well as for damages based on intent or gross negligence by octoja, its legal representatives, or vicarious agents. This also applies to damages based on an expressly assumed guarantee and to claims under the Product Liability Act.
- Limited Liability for Simple Negligence: In the case of a slightly negligent breach of a material contractual obligation (cardinal obligation), octoja's liability is limited to the typically foreseeable damage, but in no event exceeding the payments made by the User to their distributor for the octoja license in the 12 months preceding the event giving rise to the damage.
- Exclusion of Liability Otherwise: Any further liability of octoja for simple negligence is excluded. In particular, octoja is not liable for:
- indirect damages, consequential damages, lost profits, or data losses,
- damages resulting from defective, improper, or contractually non-compliant use of the Platform by the User,
- damages attributable to inadequate data backup by the User or their End Customers,
- damages caused by failures of third-party services or internet infrastructure,
- damages arising from actions performed by the User on End Customer systems via the Platform,
- damages resulting from loss of access credentials that the User failed to adequately secure,
- damages arising because the User did not have the required authorization to manage the affected End Customer systems.
- No Liability for End Customer Damages: octoja is not liable towards the User's End Customers. The contractual relationship between the User and their End Customers is solely within the User's responsibility. Claims by the User's End Customers against octoja are excluded to the extent permitted by law.
- The above limitations of liability also apply in favour of octoja's employees, representatives, and officers.
§ 7 Indemnification by the User
- The User shall indemnify octoja upon first request against all claims, damages, losses, costs, and expenses (including reasonable attorney's fees) arising from third parties – in particular the User's End Customers – against octoja due to:
- contractually non-compliant or unlawful use of the Platform by the User or their employees,
- actions by the User on End Customer systems without sufficient legal basis,
- a breach of these ToU by the User,
- a violation of data protection regulations by the User in connection with the use of the Platform,
- false or misleading statements by the User to End Customers regarding the capabilities of the Platform.
- octoja shall promptly inform the User of any third-party claims and, to the extent legally possible, give the User the opportunity to participate in the defence.
§ 8 Third-Party Services and Integrations
- The Platform may contain or enable integrations with services and products of third-party providers, including for example ThreatDown (Malwarebytes), Lywand, Acronis, and other security and backup solutions (hereinafter "Third-Party Services"). The current list of integrated Third-Party Services is available at https://octoja.de/en/features/integrations.
- octoja assumes no responsibility or liability for the availability, functionality, security, accuracy, or completeness of Third-Party Services. Disruptions, errors, data losses, or other damages originating from a Third-Party Service do not fall within octoja's area of responsibility.
- The use of Third-Party Services is subject to the respective terms of use, privacy policies, and license agreements of the corresponding providers. The User is obligated to review and comply with these independently. octoja is not a party to these agreements.
- octoja is entitled to adjust, restrict, or discontinue integrations with Third-Party Services at any time, in particular if a third-party provider changes or discontinues its API, product, or availability. No claims for damages against octoja arise from this.
- Insofar as the User executes actions via the Platform using Third-Party Services on End Customer systems (e.g., virus scans, backups, vulnerability assessments), the User bears sole responsibility for the correct configuration, proper use, and effects of these actions. octoja acts exclusively as a technical integration layer and is neither the principal nor the controller for the measures carried out by the Third-Party Service.
§ 9 Term, Suspension and Termination of Use
- The term of the usage authorization is determined by the contract with the respective distributor. These ToU apply for the entire duration of the usage authorization.
- octoja is entitled to suspend or permanently terminate the User's access to the Platform with immediate effect if:
- the User breaches material obligations under these ToU and fails to remedy the breach within 7 days of being requested to do so,
- the User uses or threatens to use the Platform for unlawful purposes,
- insolvency proceedings are opened or applied for against the User's assets,
- the distributor through which the User is licensed fails to meet its payment obligations to octoja (in this case, octoja is not liable for any resulting damages to the User). In such a case, octoja will inform the User at least 14 days before the suspension in order to allow for a change of distributor or a direct resolution.
- Upon termination of the usage authorization, the User no longer has any right of access to the Platform. octoja is entitled to delete all data associated with the User after a retention period of 30 days, unless statutory retention obligations apply. The User is solely responsible for backing up their data before termination of use.
§ 10 Data Protection and Data Processing
- Insofar as octoja processes personal data on behalf of the User in the course of providing the Platform, the Data Processing Agreement (DPA) of octoja GmbH, including its Annex 1 (Technical and Organizational Measures), available at https://octoja.de/en/avv, applies in addition. The DPA becomes part of the usage relationship upon activation of the account.
- The User remains, under data protection law, the controller – or, in relation to its End Customers, a processor – for the personal data processed via the Platform and ensures that a sufficient legal basis exists for each processing activity, including any required data processing agreements with its End Customers.
- Information on the processing of personal data by octoja as controller (e.g., account administration, support) is set out in the privacy policy at https://octoja.de/en/datenschutz.
§ 11 Amendments to the Terms of Use
- octoja reserves the right to amend these ToU with effect for the future. Amendments will be communicated to the User at least 30 days before they take effect by email or via the Platform.
- If the User does not object to the amended ToU in writing or by email within 14 days of receipt of the notification, the amended ToU shall be deemed accepted. The significance of silence will be expressly pointed out in the amendment notification.
- In the event of a timely objection, the User may terminate their usage authorization through their distributor. There is no obligation to continue use.
§ 12 Final Provisions
- Applicable Law: The law of the Federal Republic of Germany shall apply, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
- Jurisdiction: The exclusive place of jurisdiction for all disputes arising from or in connection with these ToU is the registered office of octoja, provided that the User is a merchant, a legal entity under public law, or a special fund under public law.
- Severability Clause: Should individual provisions of these ToU be or become invalid or unenforceable, this shall not affect the validity of the remaining provisions. The invalid provision shall be replaced by a valid provision that most closely approximates its economic purpose.
- Prohibition of Assignment: The User is not entitled to transfer rights under these ToU to third parties without the prior written consent of octoja.
- No Waiver: The failure of octoja to exercise a right does not constitute a waiver of that right.
octoja GmbH – As of July 2026