Last updated
25.06.2026
de-CH version
SaaS terms and conditions for edoobox
Contractual terms for edoobox, a SaaS service from Etzensperger Informatik AG. Last updated: June 25, 2026.

Last updated
25.06.2026
de-CH version
SaaS terms and conditions for edoobox
provider
Etzensperger Informatik AG
Kirchweg 24
CH-3366 Bettenhausen
Switzerland
Contract framework
Order form or offer
General terms and conditions as a basis
SLA if agreed
Digital DPA where applicable
Direct links
Status: 25.06.2026
Language version notice: This German version is the legally binding and authoritative version. Any English translations are provided for information only; in the event of inconsistencies, the German version prevails.
Provider / Contracting party: Etzensperger Informatik AG, Kirchweg 24, CH‑3366 Bettenhausen, Switzerland UID: CHE‑107.413.131 Contact: support@edoobox.com (or as specified in the contact details published at the time)
1.1 These General Terms and Conditions regulate the use of the software-as-a-service platform “edoobox” (“Service”) by customers (“Customer”) and their users (“Users”).
1.2 These General Terms and Conditions apply to all services related to edoobox, including web app, mobile access, APIs, integrations, support and documentation, unless expressly agreed otherwise in writing.
1.3 Differing or supplementary conditions of the customer only apply if the provider expressly agrees to them in writing.
1.4 Order of precedence in the event of contradictions: (1) order form/offer, (2) any special terms (e.g. SLA), (3) digitally accepted or signed data processing agreement (DPA), where applicable, (4) these Terms and Conditions.
2.1 Order form: The order, quotation, online booking or other agreement that specifies, among other things, the plan, term, scope of services and prices.
2.2 Customer data: All data/content that the customer and/or users enter, upload, create or process in the service, such as course data, participant data, communication content, documents, and payment/booking data insofar as supplied by the customer.
2.3 Provider data: Data processed by the provider as controller, such as account data, billing, support tickets, and security and operational logs.
2.4 Third-party services: Services from third parties used or integrated through edoobox, such as payment providers, email providers, SMS, analytics, hosting, maps and single sign-on.
2.5 Documentation: Technical/product-related descriptions, instructions and specifications provided by the provider.
3.1 The contract is concluded by (i) signing an order form, (ii) online ordering with acceptance of these General Terms and Conditions or (iii) activation/performance by the provider.
3.2 The customer confirms that the person placing the order is authorized to represent him.
3.3 The customer is obliged to keep all information current and correct and to communicate any changes immediately.
4.1 The provider provides the customer with the service to the agreed extent during the term of the contract. The specific scope of functions results from the order form and/or the current plan.
4.2 The Service is standard software (SaaS). A specific suitability, a specific economic success or the achievement of specific goals are not owed unless this is expressly agreed in writing.
4.3 The provider can further develop the service, adapt or change functions, as long as this does not significantly affect the contractually agreed core functionality or an equivalent solution is provided.
4.4 The customer receives a non-exclusive, non-transferable right, limited to the duration of the contract, to use the service in accordance with the contract (license to use). Further licensing, rental or making available to third parties outside the contractually intended user group is prohibited.
5.1 Availability/SLA: A binding service level, such as an availability guarantee, response times or service credits, exists only if expressly agreed in the order form or an SLA. If no SLA is agreed, the provider does not owe any specific minimum availability but endeavors to operate the service in line with the state of the art.
5.2 Maintenance: The provider is entitled to perform scheduled maintenance. Where reasonable, scheduled maintenance is announced in advance. Emergency maintenance may take place without prior notice.
5.3 Support: The scope and channels of support, such as email, telephone or tickets, are determined by the order form or the support model published at the time.
6.1 The customer is responsible for managing user accounts, roles and permissions within the service.
6.2 Access data must be treated confidentially. The customer ensures that users keep passwords safe and use appropriate security measures (e.g. MFA, where available).
6.3 If misuse or compromise is suspected, the customer informs the provider immediately and takes immediate measures (e.g. changing the password, blocking affected access).
7.1 The customer is responsible for (i) the accuracy of the content of the customer data, (ii) the legal permissibility of processing and use (including necessary information/consent), and (iii) compliance with any industry-specific regulations.
7.2 The customer ensures that only authorized users use the service and that usage is carried out in accordance with the documentation.
7.3 The customer is responsible for the local IT environment (internet connection, browser, devices, internal security). The provider is not liable for disruptions that lie outside of its area of responsibility.
8.1 It is prohibited to use the Service for: a) unlawful content or actions; b) Violation of third party rights (in particular copyright, trademark and personal rights); c) Processing particularly sensitive data without an appropriate legal basis and protective measures; d) Malware, phishing, spam, unauthorized mass communications; e) Scans, penetration tests or load tests without the prior written consent of the provider; f) Circumvention of security mechanisms, rate limits or access restrictions; g) Reverse engineering, decompiling, or analysis of the source code, unless mandatory law permits this.
8.2 If misuse, security risks or serious breaches of contract are suspected, the provider is entitled to temporarily restrict or block access (suspension) in order to prevent damage and to inform the customer about this, to the extent legally and technically reasonable.
9.1 The customer remains the owner of the rights to his customer data. The customer grants the provider the right to store, process and transmit customer data for the duration of the contract to the extent this is necessary for contract fulfillment, support, troubleshooting, security, or as instructed by the customer.
9.2 The customer warrants that he has all necessary rights and authorizations to the customer data.
9.3 The provider is not obliged to check the content of customer data unless this is necessary to resolve technical problems, for security or due to mandatory legal obligations.
10.1 The customer can use or integrate third-party services. Third-party services are not controlled by the provider; their conditions apply additionally. The provider is not liable for third-party service availability or malfunctions.
10.2 APIs may only be used in accordance with documentation and agreed limits. The provider can throttle or block API access in the event of a security risk, misuse or excessive load.
10.3 Changes to third-party services or their interfaces may affect the functionality of integrations; The provider assumes no liability for this, unless expressly agreed.
11.1 Roles (Swiss DPA/GDPR): a) Where the customer processes personal data in edoobox, such as participant and booking data, the customer is generally the controller and the provider the processor. b) For provider data, such as account, billing, support and security logs, the provider is generally the controller.
11.2 Processing on behalf of the customer / AVV/DPA: Where edoobox processes personal data on behalf of the customer, the data processing agreement (AVV/DPA) is provided digitally in the edoobox account and, where required, accepted or signed digitally. The accepted AVV/DPA governs, in particular, the subject matter, duration, nature and purpose of processing, categories of data subjects and data, technical and organizational measures, subprocessors, international transfers, assistance obligations, deletion/return and evidence/audits. In the event of conflicts, the data protection and processing provisions of the accepted AVV/DPA take precedence over these Terms and Conditions.
11.3 Subcontractors/Subprocessors: The provider may engage subprocessors. The provider lists subprocessors, either directly or through a published list, and informs the customer of material changes, such as replacements or additions, so that the customer can object within a reasonable period. If an objection is justified, the parties seek a reasonable alternative; otherwise, either the provider or the customer may terminate the affected part on extraordinary grounds.
11.4 International data transfers: The customer acknowledges that the service can be used globally and that cross-border data processing may occur as part of its operation, including hosting, support and third-party services. The provider ensures that international transfers are structured lawfully under applicable data protection law, for example through adequacy, protective clauses or appropriate safeguards.
11.5 Data security: The provider implements appropriate technical and organizational measures according to the risk, such as access controls, encryption, logging, backup/restore and monitoring. Details may be described in security documentation or an SLA.
11.6 Logs and monitoring: The provider may record technical logs to ensure operation, security, abuse detection, error analysis and performance optimization. Logs may also serve as evidence of contractual and security events.
11.7 Retention, export and deletion: a) During the contract term, the customer may export customer data using the functions provided. b) After the contract ends, the provider makes customer data available for retrieval during a post-contract period, if agreed; otherwise, a reasonable period, typically 30 days. Customer data is then deleted or anonymized unless statutory retention obligations or technical backup cycles prevent this. c) Backup data may be overwritten with a delay for technical reasons; it is not used in production during the lifetime of the backup.
11.8 Notification of data security incidents: The provider informs the customer of relevant security incidents insofar as they affect customer data and the provider becomes aware of them. Where the GDPR applies, the following applies as a minimum: the processor informs the controller without undue delay after becoming aware.
11.9 Audit/evidence rights: On request, the provider supplies reasonable evidence of data security and data protection measures, such as policies, technical descriptions and audit summaries. Customer-specific audits, security questionnaires, additional evidence, DPA assistance and extraordinary inspections take place only by prior agreement, during business hours, under confidentiality and for separate remuneration, unless they are legally mandatory or triggered by a relevant security incident caused by the provider. On-site audits are possible only in exceptional cases and must not jeopardize security or operations.
12.1 Confidential information means all non-public information that is designated as confidential or should be considered confidential under the circumstances.
12.2 Both parties undertake to maintain confidentiality. The obligation does not apply to information that (i) is public without infringement, (ii) was lawfully obtained from third parties, or (iii) must be disclosed due to a compelling legal obligation (with notice to the counterparty, where permitted).
13.1 Prices: Fees are determined by the order form/price list. Unspecified services, such as additional storage, additional modules or professional services, are charged according to effort or a separate agreement.
13.2 Invoicing: Periodically as specified in the order form, such as monthly or annually. Payment deadline: as stated on the invoice or order form.
13.3 Late payment: If payment is overdue, the provider may (i) charge reminder fees/default interest within the limits permitted by law, (ii) suspend services, and/or (iii) terminate the contract for good cause.
13.4 Taxes: Prices exclude VAT unless otherwise stated. The customer bears applicable taxes, duties or withholding taxes where legally permissible.
13.5 Price changes: Price adjustments for renewal periods are permitted if the provider informs the customer in good time before the new period begins and the customer can terminate by the start of that period in the event of material changes.
14.1 Trial period: A trial period may be offered. Its duration and scope are as specified in the offer/order form. Unless otherwise agreed, the trial ends automatically without any payment obligation; paid use requires an explicit order.
14.2 Plan changes: Upgrades/downgrades are possible under the plan rules. Billing and effective dates follow the order form/pricing logic.
14.3 Refunds: Unless mandatory law provides otherwise, or a different arrangement is expressly stated in the order form, an SLA or a written individual agreement, fees already paid are non-refundable. Any service credits or other credits exist only if expressly agreed or required by mandatory law.
14.4 Consumer withdrawal where services begin immediately: If a customer acting as a consumer has a right of withdrawal under mandatory consumer law, that right remains unaffected. However, if the customer expressly requests that edoobox begin the paid service before a statutory withdrawal period expires and confirms that they understand the consequences for their right of withdrawal, edoobox begins providing the service immediately. Where the contract is fully performed during the withdrawal period, the right of withdrawal may expire under the mandatory law applicable; if withdrawal occurs before full performance, edoobox may request compensation for value or proportionate remuneration for services already provided, where legally permitted.
15.1 All rights to the service, software, documentation, trademarks, designs and know-how remain with the provider or its licensors.
15.2 The customer only receives the usage rights expressly granted in these General Terms and Conditions.
15.3 The provider may use customer feedback (ideas, suggestions) free of charge, for an unlimited period of time and without restriction to improve the service, provided that no customer secrets are affected.
16.1 The provider delivers the service with the level of care customary in the industry.
16.2 The Service is provided on an “as available” basis. The provider does not guarantee that the service will be available uninterrupted or error-free at all times, in particular not in the event of third-party services, internet disruptions or force majeure.
16.3 The customer is obliged to report faults or defects immediately and to provide appropriate assistance in limiting/resolving them.
17.1 The provider has unlimited liability in the event of intent and gross negligence as well as mandatory statutory liability.
17.2 In the event of slight negligence, the Provider is liable, to the extent permitted by law, only for direct damages arising from the breach of material contractual obligations and only on a limited basis.
17.3 Liability cap: Unless expressly agreed otherwise in the order form, an SLA or an individual agreement, and to the extent permitted by law, the provider's total liability arising out of or in connection with the contract, regardless of its legal basis, is limited to the fees paid by the customer for the service in the last 12 months before the event causing the damage. If the contract term is shorter, the amount paid up to that point applies.
17.4 The provider is not liable - to the extent permitted by law - for indirect damages, consequential damages, lost profits, loss of data (if avoidable through backups/export) or claims from third parties, unless Section 17.1 applies.
17.5 The customer is obliged to carry out appropriate data backups/exports.
18.1 The customer releases the provider (including bodies, employees, auxiliary persons) from all third-party claims that arise from the use of the service by the customer/user, in particular due to: a) illegality of the customer data or lack of legal basis/information; b) Violation of IP or personal rights; c) Violations of data protection, communications or competition law due to customer content/communication; d) Misuse, security incidents, unauthorized access or API misuse by the customer.
18.2 The provider informs the customer about such claims, to the extent legally permissible, and enables the customer to participate appropriately in the defense.
19.1 Term: As specified in the order form, for example monthly or annually. Automatically renews for the agreed period unless terminated in the ordinary manner.
19.2 Ordinary termination: Unless otherwise agreed, the customer may terminate no later than 30 days before the end of the relevant contract period. A shorter termination arrangement may apply to monthly plans if specified in the order form.
19.3 Extraordinary termination for good cause: Either party may terminate without notice for good cause, such as a serious breach of contract, continued non-payment despite a reminder, or serious security/compliance breaches. Where reasonable, an appropriate additional period must be granted to remedy the issue.
19.4 Suspension: The provider may suspend the service in the event of (i) late payment, (ii) a security/abuse risk, (iii) a breach of clause 8, or (iv) sanctions/export controls (clause 21).
19.5 Effects of termination: The right of use ends when the contract ends. Data export/deletion follows clause 11.7. Obligations that by their nature survive, such as confidentiality, liability provisions, intellectual property and outstanding payments, remain in force.
20.1 Neither party is liable for non-performance due to events beyond its reasonable control (e.g. natural events, war, terrorism, strikes, major network/cloud disruptions), provided that notice is given immediately and appropriate measures are taken to mitigate damages.
21.1 The customer warrants that he will not use the service in violation of any applicable export control or sanctions regulations.
21.2 The provider may refuse, restrict or terminate services if this is necessary to comply with sanctions/embargoes or official orders.
22.1 The provider can change these terms and conditions, in particular in the event of (i) legal changes, (ii) security requirements, (iii) product developments, (iv) adjustments to business processes.
22.2 Material changes are communicated to the customer in an appropriate form, such as email or an in-app notification, at least 30 days before they take effect. If the customer does not object within this period and continues using the service, the changes are deemed accepted. If the customer objects in time, the provider may terminate the contract at the end of the current period.
23.1 Legally relevant notifications are made in writing (including email) to the most recently announced contact addresses.
24.1 The customer may only assign/transfer rights and obligations under the contract with the provider’s prior written consent.
24.2 The provider may transfer the contract as part of a restructuring, an asset deal or a transfer of the service to a group company if this does not significantly affect the rights of the customer; the customer is informed.
25.1 If a provision is wholly or partially invalid, the rest of the contract remains valid. The parties replace the invalid provision with an effective provision that comes closest to the economic purpose.
26.1 Substantive Swiss law applies, excluding the conflict of laws and the UN Convention on Contracts for the International Sale of Goods (CISG), to the extent permissible.
26.2 For customers acting as businesses, the exclusive place of jurisdiction is the registered office of the Provider. Mandatory statutory places of jurisdiction and mandatory consumer law remain reserved.