Terms of Service
Oldfire OÜ — SupportKontor Version 1.0 · 27 July 2026 · Private beta
This English text is a convenience translation. The German version is the agreed and legally binding one; in case of discrepancy, the German text governs.
§ 1 Scope and parties
(1) These terms govern the provision of the software “SupportKontor” by Oldfire OÜ, J. Pärna tn 1-22, 10128 Tallinn, Estonia, registration number 14744856 (“Provider”) to its customers (“Customer”).
(2) The offering is directed exclusively at businesses within the meaning of § 14 BGB, legal entities under public law and public-law special funds. No contract is concluded with consumers, and accordingly there is no right of withdrawal.
(3) Differing, conflicting or supplementary terms of the Customer do not become part of the contract unless the Provider agrees to them expressly in text form. This applies even where the Provider performs without reservation while aware of such terms.
(4) The exchange of performance governed by this contract is the main agreement (“Hauptvertrag”) referred to in the data processing agreement concluded between the parties (§ 9).
§ 2 Subject matter of the service
(1) SupportKontor is an AI-assisted tool for answering customer service emails about orders. The Customer forwards incoming customer enquiries from their own mailbox to the service. The service reads the enquiry, matches it to an order in the Customer’s shop system and — depending on the autonomy level chosen by the Customer (§ 3) — drafts, proposes or sends a reply and carries out order actions.
(2) The service handles enquiries about shipping status, cancellation, address change, returns, invoice requests and payment status, as well as questions about the policies the Customer has published themselves. Enquiries outside these categories are not answered but placed before the Customer for personal handling.
(3) The service modifies the Customer’s shop system solely by cancelling an order, changing a delivery address and creating a return.
(4) The service does not include, in particular:
a) initiating refunds, credit notes or any other payment transaction; where the service identifies that an enquiry requires a refund, it places it before the Customer;
b) processing payment data; where the service detects card, account or credential data in a message, it stops processing and places the message before the Customer;
c) legal advice or legally binding declarations towards the Customer’s own customers;
d) telephone, chat or any channel other than email;
e) any assurance of a particular automation, resolution or accuracy rate.
(5) The service is provided as software as a service over the internet. For the term of the contract the Customer receives a simple, non-transferable right of use within the agreed scope. Delivery of source code is not owed.
§ 3 An assistant, not an employee — autonomy and supervision
(1) SupportKontor is a tool that the Customer configures and supervises. The service does not act at its own discretion but solely within the limits the Customer sets for each category of enquiry. Towards their own customers, the Customer remains the party who declares and acts.
(2) For each category of enquiry the Customer selects one of three autonomy levels:
- Level 0 — observe. The service decides and drafts, but sends nothing and changes nothing. The Customer answers the enquiry themselves as before and compares.
- Level 1 — approve. The service prepares the action and places it before the Customer for approval. It is carried out only once the Customer consents.
- Level 2 — autonomous. The service carries out the action and replies without prior human review.
(3) Every new installation starts at Level 0 for all categories of enquiry. Level 1 or Level 2 is never set by the Provider, never by an update and never as a default, but exclusively by a deliberate act of the Customer.
(4) For the first 48 hours after setup, all categories of enquiry are held at Level 0 regardless of configuration (watching period).
(5) A proposal placed before the Customer at Level 1 on which the Customer does not decide within the approval window they have configured (default: 48 hours) lapses and is placed before the Customer for personal handling. It is not carried out in the alternative.
(6) The service logs every decision together with the category of enquiry, the autonomy level, the reasoning, the model used and a confidence value. The log is available to the Customer.
(7) The Customer’s duty of supervision. The Customer confirms that they use SupportKontor as an assistive tool which requires regular supervision by responsible people. The Customer designates an internal person in charge, reviews the autonomy levels granted as circumstances require, and evaluates the log under paragraph 6 at appropriate intervals. The Customer is aware that at Level 2 actions in their shop system and replies to their customers are carried out without prior human review, and that choosing that level is their own decision.
(8) Artificial intelligence systems do not operate free of error. The service may misclassify an enquiry or answer it incorrectly. The Provider gives no assurance of freedom from error or of any accuracy rate. The graduated autonomy under paragraph 2, the watching period under paragraph 4 and the log under paragraph 6 are the means by which the Customer manages that risk.
(9) The service marks automatically generated replies as such towards the Customer’s own customers. This marking is enabled by default. The Customer may switch it off; in doing so they act as a deployer within the meaning of Art. 3(4) of Regulation (EU) 2024/1689 (AI Act) and bear the associated obligations on their own responsibility.
§ 4 Prerequisites and the Customer’s cooperation
(1) Operation requires the Customer to run a Shopware 6 shop system with a reachable Admin API, to set up the necessary access for the Provider, to maintain a mailbox with a working forwarding rule to the service and to set the required DNS records.
(2) The Customer records their service policies — in particular return windows — correctly and keeps them up to date. The service decides on the basis of those entries.
(3) The Customer keeps their access credentials confidential and reports their loss without undue delay.
(4) Disruptions originating in the Customer’s sphere — in particular an unreachable shop system, changed or revoked credentials, a deleted or faulty forwarding rule, incorrect DNS records or a full mailbox — do not constitute a defect in the Provider’s performance. The Provider will point out disruptions of this kind that are apparent to it.
(5) The Customer is responsible for the lawfulness of processing towards their own customers, in particular for their information duties under Art. 13, 14 GDPR.
§ 5 Acceptable use
(1) The Customer does not use the service for unlawful purposes, for advertising or bulk mailings, or in any manner apt to circumvent the autonomy levels under § 3.
(2) The Customer does not reverse engineer, decompile or disassemble the service except where mandatory law permits, and does not make the service available to third parties for their use.
(3) In the event of a serious or repeated breach the Provider may temporarily suspend access after prior notice. Where there is imminent danger, notice may be given afterwards.
§ 6 Conclusion, term and termination
(1) The contract is concluded by ordering through the Provider’s checkout with express confirmation of these terms, or by a pilot agreement signed by both parties.
(2) The contract runs for one month and renews for one further month at a time unless terminated with 30 days’ notice to the end of a month. Termination requires text form.
(3) The right of either party to terminate for cause remains unaffected.
(4) After the contract ends, the data processed on the Customer’s behalf is deleted in accordance with the data processing agreement. Within 30 days of the end of the contract the Customer may request release of their data in a common machine-readable format.
§ 7 Fees and payment
(1) The fee stated in the ordering process applies. It is payable monthly in advance. The fee does not depend on usage; there is no charge per enquiry handled.
(2) Payments are processed by Paddle.com Market Ltd, which acts as seller in its own name (merchant of record), issues the invoice and accounts for VAT. Paddle’s terms apply in addition to the payment relationship. The provision of the service itself is governed exclusively by these terms.
(3) Price changes are notified to the Customer in text form with 30 days’ notice and take effect from the next renewal. If the Customer objects before they take effect, the contract ends when the change takes effect.
§ 8 Availability
(1) The service is in a closed trial phase (private beta). No particular availability is promised for this phase, and there is no service level agreement. The Provider states this expressly rather than leaving it open.
(2) The Provider performs according to the state of the art with the diligence of a prudent business and remedies disruptions known to it within a reasonable period. Paragraph 1 does not affect the Provider’s obligation to make the service available in a contractually compliant condition at all.
(3) The Provider announces maintenance in text form where foreseeable. Where a disruption lasts more than 24 hours, the Provider informs the Customer without being asked.
(4) The service relies on third-party inputs, in particular for language models, email delivery and hosting. The Provider cannot rule out failures of those inputs.
§ 9 Data protection
(1) The Customer is the controller and the Provider the processor within the meaning of Art. 28 GDPR. The data processing agreement concluded between the parties forms part of this contract; in case of conflict it prevails over these terms in matters of data protection law.
(2) The sub-processors engaged, the technical and organisational measures and the deletion periods are set out in the annexes to the data processing agreement.
(3) Message content is deleted after 90 days.
(4) Claims of data subjects under Art. 82 GDPR are governed by statute and are neither created nor limited by this contract.
§ 10 Liability
(1) The Provider is liable without limitation for intent and gross negligence, for injury to life, body or health, for fraudulent concealment of a defect, to the extent of any guarantee assumed, and under the German Product Liability Act.
(2) Where a material contractual obligation is breached with slight negligence — an obligation whose fulfilment makes proper performance of the contract possible in the first place and on whose observance the Customer may regularly rely — the Provider’s liability is limited in amount to the foreseeable damage typical for this type of contract at the time of conclusion.
(3) Liability for slight negligence is otherwise excluded.
(4) Liability under paragraph 2 is limited, per event and in aggregate, to the fees the Customer paid in the twelve months preceding the event giving rise to the damage.
(5) For loss of data the Provider is liable within the framework of paragraphs 2 to 4 only up to the expense that would have been required to restore the data had the Customer backed it up properly and regularly.
(6) Where damage results from a category of enquiry having been set to Level 2, § 254 BGB remains unaffected; the autonomy level chosen by the Customer, the exercise of their duty of supervision under § 3 paragraph 7 and the accuracy of their entries under § 4 paragraph 2 are to be taken into account in the assessment. No exemption from liability of the Provider follows from this.
(7) The above limitations also apply to the personal liability of the Provider’s legal representatives and agents.
(8) Claims of the Customer under this contract become time-barred twelve months after they become known; the cases in paragraph 1 are time-barred under the statutory provisions.
(9) Paragraph 4 does not affect § 9 paragraph 4.
§ 11 Changes to these terms
(1) The Provider may change these terms where the change is prompted by further development of the service, by a change in the law or in the case law of the highest courts, and does not unreasonably disadvantage the Customer.
(2) The change is notified to the Customer in text form at least 30 days before it takes effect. If the Customer does not object before it takes effect, the change is deemed accepted; the Provider will point this out separately in the notification. In the event of an objection, the contract ends when the change takes effect, without any need for termination.
§ 12 Final provisions
(1) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
(2) Jurisdiction is governed by the statutory provisions.
(3) Amendments and additions to this contract require text form. There are no oral side agreements.
(4) The Customer may transfer rights under this contract only with the Provider’s prior consent. The Customer may set off only against undisputed claims or claims established by final judgment.
(5) Should a provision of this contract be or become invalid, the validity of the remaining provisions is unaffected. The statutory provisions take the place of the invalid provision.
Annex — Confirmation at signup
The following text is shown to the Customer at conclusion of the contract, immediately next to the confirmation of these terms, and must be confirmed separately:
I understand that SupportKontor is an AI-assisted tool, not an employee. It does not work free of error and requires regular supervision by responsible people in my company. For each category of enquiry I decide myself whether the service only observes, places actions before me for approval, or acts on its own — and I am aware that when it acts on its own, order actions and replies to my customers are carried out without prior human review.
The Art. 28 GDPR data processing agreement forms part of these terms and is concluded in the pilot conversation. Also here: Data protection · Imprint