Version dated 10 September 2026. These terms apply once they have been validly incorporated into the relevant contract. Publication alone does not amend existing contracts.
1. Provider and scope
1.1 Sendequelle is provided by Norbert Sehm, trading as Sendequelle, Von-Möller-Str. 23a, 33649 Bielefeld, Germany, email: emailn@emailn.de, telephone: +49 521 5462877, VAT identification number: DE262023108, referred to below as the “Provider”.
1.2 These terms govern contracts for use of the web-based Sendequelle platform, including the analysis, monitoring, team, API and export functions agreed in each case. The platform service offered under a customer contract is intended exclusively for businesses acting in their commercial or independent professional capacity within the meaning of section 14 of the German Civil Code, legal entities under public law and special funds under public law. Customers enter into the contract for that activity or for the organisation they represent.
1.3 Merely visiting publicly accessible information pages or using public tools does not turn a private individual into a business customer. These business terms do not restrict the statutory rights of such visitors. The privacy notice applies independently of any customer contract.
1.4 The individual service agreement or accepted offer, expressly agreed supplementary service conditions and these terms govern the contract. Individual agreements take precedence. Where personal data are processed on behalf of the Customer, the data processing agreement takes precedence in the event of conflicting provisions concerning data protection.
1.5 The Customer’s differing terms apply only if the Provider has agreed to them. Performing the contract does not, by itself, constitute such agreement.
2. Formation of the contract, customer account and authority
2.1 Public prices and product descriptions invite enquiries or orders. A paid contract is formed only when the Customer expressly orders a specific scope of service at an agreed price and the Provider accepts that order, for example by an order confirmation in text form. A non-binding enquiry, registration or technical assignment to a plan does not, by itself, create a payment obligation.
2.2 Registration details must be accurate and current. A person acting for an organisation must have authority to do so. The Customer must provide an accessible address for contractual and security notices and promptly update any changes.
2.3 A free account is provided through the relevant activation confirmation or account activation. Unless expressly agreed otherwise, a trial lasts 14 days. It does not automatically become a paid subscription. Access rights actually available after the trial are communicated in the account; continued technical access does not create a payment obligation.
2.4 The Customer receives the applicable version of these terms and the agreed commercial conditions in a form that can be saved. This version can be saved using the browser’s print function. The contractual language is German unless expressly agreed otherwise. An English translation is provided for comprehension; the language version validly agreed by the parties remains authoritative.
3. Services and limits of technical findings
3.1 Sendequelle supports the technical assessment of email infrastructure. Depending on the agreed and enabled scope, services include DNS and mail server checks, DMARC and TLS-RPT analysis, sending-source and reputation information, incident handling, notifications, and technical analysis of individual emails and delivery problems. Functions expressly described as planned or not yet operational do not form part of the service owed unless separately promised.
3.2 The Provider owes the agreed technical functionality and professional processing of the available input data. Unless expressly agreed in an individual case, the Provider does not owe a particular delivery outcome, an improvement in reputation, removal from a blocklist, prevention of every attack, or legal or official recognition of a report.
3.3 Results are technical findings with the stated date, scope and evidential basis. Measurements performed by Sendequelle, information in third-party messages or reports, subsequent checks and simulations must be distinguished. Missing evidence is neither a passed nor a failed check. Scores are guidance based on a particular model and are not certification.
3.4 Sendequelle does not participate in the Customer’s ordinary production email flow, provide an SMTP relay for the Customer or access customer mailboxes. The platform does not automatically modify third-party DNS zones. The Customer decides on changes to its infrastructure and remains responsible for implementing them professionally. The Provider remains responsible for performing its own contractual service.
3.5 Information and availability of external DNS services, registries, reputation sources or mail servers may change or be incomplete. The Provider remains responsible under applicable law for selecting and using its own service providers and persons engaged in performance; using a service provider does not in itself exclude liability.
4. Email forensics and comparisons within an account
4.1 Authenticated, authorised organisation members may submit header text and supported individual email files within the enabled scope. If a complete email source is pasted into the header field, the message body is separated for header analysis. Analysis requiring unchanged original bytes, including the body, requires the supported original file. Bytes reconstructed from an MSG file are not an SMTP original with identical bytes.
4.2 Displayed sender, Return-Path, sending hub, domain registry and abuse contact information is derived from the sources identified in the report. A From field does not prove a person’s identity. A network operator, registrar or abuse contact is not, merely for that reason, the author, legally responsible person or originator of a message. Registrant information that is not publicly available is not invented or guessed.
4.3 Comparisons are restricted to explicitly selected messages and approved reference versions within the same authorised organisation. Approving a reference profile does not increase the evidential value of its input data. Membership in several organisations does not permit confidential data to be combined across those organisations.
4.4 Public registry lookups are performed only as part of the separately selected function. Domain names or public IP addresses necessary for that function are sent to the relevant registry services. The privacy notice and, where applicable, the data processing agreement explain the details, recipients and possible international transfers.
4.5 Originals, analysis values and exports serve technical diagnosis. Sendequelle is not a long-term archive and, without a specific agreement, is not a forensic expert service for court proceedings. The Customer must independently preserve originals that may be needed as evidence. Legally permitted uses of a report are not prohibited; no particular evidential weight is promised.
5. Bounces and delivery diagnosis
5.1 Delivery diagnosis analyses deliberately submitted, supported bounce messages and limited Postfix log extracts. This may require processing the machine-readable DSN section in the message body. Private correspondence is not subject to general semantic content assessment.
5.2 A submitted log entry or bounce message is initially a third-party statement. Acceptance by the next server, a reported delivery status, placement in an inbox and reading a message are different events. Without corresponding evidence, Sendequelle does not infer a broader delivery or read confirmation.
5.3 Passive analysis does not send test messages, sign in to a mailbox or automatically contact the reported recipient or an abuse contact. Indications of possible causes and next steps do not replace checking the relevant server configuration and complete original logs.
6. Monitoring, test reception and notifications
6.1 Continuous active monitoring requires the designated domain verification and the Customer’s necessary authority. Checks for third parties may be configured only under an actual authorisation and within the designated organisation and tenant structure.
6.2 Active standard checks are limited to the described protocols and ports. They do not sign in to customer mailboxes or send messages to third-party recipients. Additional service endpoints require explicit activation within the authorised scope.
6.3 SMTP test reception, optional return reports and recurring test profiles are available only where the particular function has been expressly agreed, operationally enabled and activated in the account. The Customer sends test messages from its own system to the assigned test address. Proven receipt by Sendequelle does not confirm delivery to other providers.
6.4 Return reports are sent only after separate activation and only to previously confirmed destinations. An address stated in a message header as the sender or return address does not thereby become an approved return-report destination.
6.5 Check intervals describe scheduled execution, not uninterrupted observation in real time. Missing measurements and technical failures are treated according to the identifiable status. Performing agreed scheduled checks and handling faults appropriately remain contractual obligations.
6.6 The Customer keeps notification destinations current and observes plan limits. Transmission of a notification to a technical channel does not prove that it was actually retrieved. For particularly time-critical or security-critical processes, the Customer should maintain suitable additional checks; this does not waive the Provider’s obligations.
7. Cooperation, permitted use and account security
7.1 The Customer may submit data or have data processed only where it has sufficient authority and, where required, a legal basis under data protection law. In particular, the Customer must consider the rights of employees, communication partners and its own customers, as well as confidentiality and professional obligations. Merely possessing a header does not permit every further use.
7.2 Input should be limited to what the diagnostic purpose requires. Unnecessary credentials, private keys, particularly sensitive information and unrelated message sections must be removed before submission where this does not defeat the analysis purpose. Special categories of personal data or data about criminal convictions may be submitted only where expressly covered by the agreed processing scope and legally permitted.
7.3 Prohibited uses include unauthorised monitoring, circumventing tenant boundaries or usage limits, exploiting vulnerabilities, deliberately overloading the service and unlawful publication. Technical investigations of the platform itself require a separate agreement insofar as they exceed intended use. Mandatory statutory permissions remain unaffected.
7.4 The Customer protects passwords, passkeys, recovery codes and API tokens and grants roles according to need. The Customer must promptly notify the Provider of any compromise it discovers. Responsibility for authorised persons is governed by law; no strict liability for every unauthorised third-party account access is agreed.
7.5 For fault reports, the Customer documents the necessary technical circumstances and provides reasonable assistance in identifying the cause. Credentials and complete customer messages must not be sent to support without being requested.
8. Rights of use, customer data and public results
8.1 For the contractual term, the Customer receives a non-exclusive right to use the agreed platform through its designated access methods within the purchased scope. Serving the Customer’s own clients is permitted within an agreed MSP or comparable service scope. Further provision of the platform to third parties requires agreement.
8.2 Rights in submitted data remain with the respective rights holder. The Provider receives only the permissions needed to process, store, transmit, secure and output the data as agreed. This provision does not replace a legal basis under data protection law. It grants no general right to use private messages for advertising, sale or training general-purpose AI models.
8.3 The Customer may use and retain lawfully obtained reports and exports for its own business purposes and for agreed services to its clients. Third-party rights and accurate source, time and evidence information must be respected. An abridged report must not be misleadingly presented as certification or conclusive proof of identity.
8.4 Private account reports do not become public merely because they have been created. Public status pages and publication of active monitoring values require the designated separate approval. Publicly initiated domain checks may, in accordance with the notice shown before starting, produce public result pages and temporary domain overviews. Those results contain no privately uploaded emails.
8.5 Restrictions on use do not exclude statutory rights to interoperability, data access or switching providers.
9. Prices, quotas and billing
9.1 Prices agreed when the contract is formed apply. Where indicated, public business prices are in euros, net per organisation per month, plus applicable VAT. Changes to the new-customer catalogue do not automatically amend existing contracts.
9.2 Payment amount, billing start, billing method and any different term are stated in the order confirmation. Unless another payment period is agreed, correctly issued invoices are payable within 14 days of receipt. Statutory rules on late payment apply.
9.3 Analyses use the agreed total pool for the organisation. Email forensics and delivery diagnosis share this analysis pool. Enabled test receipts count towards that pool and may additionally be subject to an indicated sublimit. Reading existing reports again, comparing existing reports and exporting them do not consume another analysis unit.
9.4 Monthly analysis quotas follow UTC calendar months and renew on the first day at 00:00 UTC, independently of the individual billing date. Unused units do not carry over. System errors and invalid input do not consume an analysis unit; usable analytical results, including negative findings or identified partial reports, count as an analysis.
9.5 Once a limit is reached, new analyses or resources may be refused. There are no overage charges or automatic plan changes without an express order. Existing reports remain accessible within their applicable access and retention periods. Additional technical safeguards against misuse are permitted where necessary and proportionate.
9.6 The Customer may set off claims that are undisputed, established by a final judgment or arise from the same contractual relationship. Statutory rights to retain performance for claims arising from the same contractual relationship remain unaffected.
10. Operation, maintenance, support and changes
10.1 The Provider operates and maintains the platform with appropriate professional care. A specific availability percentage, fixed response time or particular service level agreement is owed only if expressly agreed. This does not remove the obligation to make the agreed service generally available and appropriately remedy faults attributable to the Provider.
10.2 Regular email support is available Monday to Friday; a continuously staffed, round-the-clock incident desk is not included without a separate agreement. The contact address is emailn@emailn.de or another expressly communicated support channel.
10.3 Planned maintenance expected to have a substantial impact will, where possible, be announced in advance and scheduled during periods of lower usage. Urgent security measures may be necessary at short notice. The extent and duration of interruptions must be limited to what is reasonably required.
10.4 The Provider may make technically necessary or reasonable improvements provided these do not impair the agreed purpose or essential service features. Permanent substantial reductions in purchased services or changes to agreed prices require a separate contractual basis or consent. Continued use alone is not consent to amended terms.
10.5 Statutory remedies for defects, including rights to proper contractual performance and applicable rights to reduce payment, terminate or claim damages, remain unaffected. Section 14 governs damages.
11. Suspension and misuse
11.1 The Provider may temporarily suspend access or individual functions if there are specific indications of unlawful use, a substantial contractual breach or a threat to the platform or third parties, and the measure is necessary to address that risk. Suspension for late payment is permitted only subject to the applicable legal requirements and after reasonable notice with an opportunity to remedy the situation.
11.2 Where practicable, the Customer will first be informed and given a reasonable opportunity to remedy the situation. Immediate action may be taken in the event of imminent danger; information will follow where legally permitted. Suspension must be limited to the affected functions and necessary duration and lifted once the reason no longer applies.
11.3 The Customer may explain the circumstances through the stated contact channel and request a review. Valid statutory or contractual rights to obtain data are not categorically excluded by suspension. Confidentiality, identity verification and specific security concerns must still be considered.
12. Term and termination
12.1 Standard paid contracts run for one month and renew for another month unless terminated by the end of the current billing period. The first period begins as stated in the order confirmation. Expressly agreed individual terms remain applicable, subject to mandatory statutory rights.
12.2 Notice of termination may be given in text form, for example by email to emailn@emailn.de. Where an account cancellation function is offered, it may also be used. The Provider processes notices sent by email. The Provider’s confirmation documents termination and is not a condition for the effectiveness of a notice that has been received.
12.3 The Customer may terminate a free account contract at any time. The Provider may ordinarily terminate it on 30 days’ notice. Both parties’ rights to terminate for good cause remain unaffected for all contract types. Any required prior warning or opportunity to remedy is governed by law.
12.4 Terminating a paid plan, changing plans and deleting an entire organisation are different actions. The consequences for data are explained before organisation deletion. Deleting one person’s user access does not, by itself, authorise that person to remove other organisation members’ lawful data or contracts.
12.5 Prepayments for periods after effective termination are refunded unless a valid different agreement or statutory entitlement to that payment applies. Mandatory switching rights under section 13 remain unaffected.
13. Data export, switching providers and deletion
13.1 Sendequelle processes technical data with limited retention. Retention periods stated in the relevant module or contract apply separately to original files, reports and other data. Data lawfully deleted after its retention period cannot be restored by a later export request. During the contract, the Customer may export necessary, available data within the designated scope.
13.2 To the extent that Sendequelle is a data processing service subject to the switching rules in Chapter VI of Regulation (EU) 2023/2854, the Provider supports switching to another provider or to the Customer’s own infrastructure, as well as termination without switching as provided by law. The following provisions do not restrict statutory rights.
13.3 The Customer may initiate a switch in text form by contacting emailn@emailn.de. No contractual advance notice period is required for switching. The transitional period is generally no more than 30 calendar days after initiation; a later start requested expressly by the Customer will be coordinated. The Provider verifies authority, coordinates scope and a suitable secure transfer method, provides reasonable assistance, maintains contractually owed continuity of service and explains known risks. The Customer, Provider and authorised third parties cooperate in good faith to complete the switch securely and on time.
13.4 If the period cannot be met for technical reasons, the Provider explains those reasons within 14 working days of receiving the switching request and specifies the necessary alternative period, which must not exceed seven months. The Customer retains its statutory right to extend the transitional period once.
13.5 Exportable data include customer inputs still lawfully stored, available original files, analysis and measurement data, customer-related metadata, configurations and digital assets to the extent covered by the statutory export scope. Personal data of other customers, security-critical internal secrets and protected internal software components do not become exportable merely because of the contract. Such exceptions must not prevent or delay switching.
13.6 The data export and infrastructure register describes the currently available export categories, formats, procedures and limitations, the jurisdiction governing the infrastructure and the handling of international governmental access requests. This information is available before contract formation and forms part of these switching provisions. The Provider separately supplies any additional data required by law as part of the requested switch in a structured, commonly used and machine-readable format. This broader switching process is handled with the Customer through emailn@emailn.de; it does not promise a complete automated migration export as an account function. Existing individual exports do not limit any broader statutory right to export. Identical technical operation at the destination provider is not promised for the SaaS application; statutory assistance and interoperability duties remain unaffected.
13.7 After the agreed transitional period ends, the exportable data covered by the switch are available for retrieval for at least 30 calendar days. The Provider arranges secure export availability for the individual switch and coordinates this with short diagnostic retention periods so that an initiated statutory switch is not defeated by automatic deletion. This separate provision must be distinguished from an ordinary account download link with a short validity period. Section 13.1 applies to data properly deleted before the switch.
13.8 No separate switching or data transfer fees are charged. Charges for services actually provided under the contract until effective termination remain payable; a permitted switch alone does not incur an additional contractual penalty. Before initiation, the Provider explains the billing consequences. Upon successful completion of the switch, the contract for the affected service ends and does not renew for a further month under section 12.1. The Provider confirms successful completion and the termination date.
13.9 After the retrieval period expires and the switch has been successfully completed, the affected customer data are deleted under the agreed deletion process unless statutory retention is required. Alternatively, the Customer may expressly request termination of the affected data processing service without switching and deletion of its exportable data and digital assets. A notice to emailn@emailn.de is sufficient; this differs from ordinary cancellation of a plan. For this route, the notice period is seven calendar days from receipt. The contract for the affected service ends when that period expires and does not renew for another month. An earlier date requested by the Customer may be agreed. Deletion follows after the period in accordance with the lawful instruction; any legally required residual retention and the specifically documented backup cycle remain limited to their respective purposes. Before confirming the deletion instruction, the Customer is informed that data retrieval will no longer be possible. The data processing agreement specifies return and deletion and may not curtail statutory rights. In the individual return and deletion process, the Provider communicates which backup copies are affected, the limited reason why they are temporarily required and when they will be removed. No general right to retain them indefinitely is granted.
14. Liability
14.1 The Provider has unlimited liability for intent and gross negligence, culpable injury to life, body or health, fraudulent concealment of a defect and within the scope of an expressly assumed guarantee. Mandatory statutory liability, including under product liability law and towards data subjects under data protection law, remains unaffected.
14.2 In the event of ordinary negligence, the Provider is liable for breach of an essential contractual duty: a duty whose fulfilment enables proper performance of the contract and on whose fulfilment the Customer may ordinarily rely. In that case, liability is limited to the loss typical of the contract and foreseeable when it was formed.
14.3 Liability for ordinary negligence in breach of duties other than essential contractual duties is excluded. The exceptions in section 14.1 always apply. These provisions on damages do not exclude statutory rights to contractual performance, reduction of payment or termination.
14.4 In the event of data loss, backup measures reasonably expected of the Customer and necessary for the agreed purpose, and possible restoration costs, are considered under statutory contributory fault rules. A backup, retention or data provision obligation assumed by the Provider is not thereby transferred to the Customer.
14.5 No blanket exclusion of all indirect losses, lost profits or data protection damages is agreed. Where such losses are recoverable, recovery is governed by law and the preceding permissible liability limits.
14.6 These liability limits also benefit the Provider’s legal representatives, employees and persons engaged in performance. Their own intentional or grossly negligent conduct and the other cases listed in section 14.1 remain subject to the liability stated there.
15. Third-party claims
15.1 If a third party brings a claim against the Provider because of unlawful data submission or use, the Customer indemnifies the Provider against valid claims to the extent the Customer culpably caused the underlying breach. Any contributory fault of the Provider must be considered. This provision does not impose a blanket obligation to assume administrative fines and does not cover legal violations for which the Provider itself is responsible.
15.2 Necessary and reasonable costs of an appropriate legal defence are included. The Provider promptly informs the Customer, allows reasonable participation and does not make admissions or settlements binding on the Customer without its consent unless compelled by an unavoidable legal requirement. Consent must not be withheld without an objective reason.
16. Confidentiality and data protection
16.1 Both parties keep the other party’s non-public technical, business and personal information confidential. Access is limited to persons and properly engaged service providers who need it for the agreed task and are appropriately bound to confidentiality.
16.2 This does not cover information that becomes public without breach of contract, is lawfully obtained from third parties or is independently developed. Legally required disclosure remains permitted; where lawful, the other party is informed beforehand and disclosure is limited to what is necessary. Confidentiality continues after the contract ends for as long as a legitimate confidentiality interest exists.
16.3 The Provider processes personal data as a controller for account administration, its own contractual administration and its own security operations. For personal customer data processed exclusively for diagnostic and monitoring purposes determined by the Customer, the Provider acts under a separate data processing agreement. If the Customer is itself a processor, its authority to appoint a subprocessor and the corresponding contractual chain must be established.
16.4 Before such processing on behalf of the Customer begins, an agreement is concluded covering the processing, actual subprocessors and technical and organisational measures. The privacy notice explains processing; it replaces neither that agreement nor a required legal basis. Accepting these terms does not grant blanket consent to advertising or transfers to third countries.
17. Final provisions
17.1 German law applies, excluding the United Nations Convention on Contracts for the International Sale of Goods. Applicable mandatory rules, particularly data protection law and the law governing data processing services, remain unaffected.
17.2 The exclusive place of jurisdiction is the Provider’s place of business where the Customer is a merchant within the meaning of German commercial law, a legal entity under public law or a special fund under public law, unless a mandatory exclusive statutory jurisdiction applies. Other customers are subject to statutory jurisdiction unless another valid jurisdiction agreement exists.
17.3 Changes and additions should be recorded in text form for documentation. Individual agreements take precedence even where made in another form. New terms do not bind existing customers merely through publication or silence.
17.4 If a provision is invalid, statutory provisions apply in its place; the remainder of the contract continues in accordance with section 306 of the German Civil Code. An invalid clause is not automatically reduced to the maximum content that would still be permissible.