The Phish Menu® by jaeger + haeckerhase GmbH – for the use of the platform thephishmenu.de. These terms are addressed exclusively to businesses (B2B).
Version: September 2026. This English text is a convenience translation; the German version (Allgemeine Geschäftsbedingungen) is the legally binding one.
1. Scope, parties and definitions
jaeger + haeckerhase GmbH (hereinafter "jaeger + haeckerhase") provides customers with the web application The Phish Menu® and the security-awareness content accessible through it via the website thephishmenu.de.
These General Terms and Conditions ("Terms") apply to all contracts between jaeger + haeckerhase and the customer concerning the use of The Phish Menu® and the security-awareness content.
Deviating, conflicting or supplementary terms of the customer do not become part of the contract unless jaeger + haeckerhase expressly agrees to them in text form.
These Terms are addressed exclusively to businesses, legal entities under public law and special funds under public law within the meaning of Section 310(1) of the German Civil Code (BGB). Contracts with consumers are not intended.
Definitions for these Terms are set out in the annex. In case of doubt, the service and tariff information displayed during the order process takes precedence over these Terms to the extent it contains specific details on tariff, number of users, prices or term.
2. Conclusion of contract and scope of services
The subject matter is the use of the training platform including the content it contains (e.g. video series, interactive deep dives, awareness games, knowledge checks, certificates) and the underlying software as a service (SaaS) for internal training purposes.
The contract is concluded when the customer creates a customer account on thephishmenu.de, selects a tariff or number of users, completes the paid order and jaeger + haeckerhase confirms the order electronically or activates access to The Phish Menu®. No separate quotation is issued.
During the contract term the customer receives access to The Phish Menu® as a pure web application and to the security-awareness content included in the booked tariff. The product description shown during the order process, the booked number of users, the booked tariff and any usage restrictions stated there are decisive.
The Phish Menu® is provided as SaaS over the internet at the handover point of the data centre used by jaeger + haeckerhase. Installation, technical implementation or integration into the customer's own systems is not part of the contract and is not required for use.
jaeger + haeckerhase may further develop functions, content, user interfaces and technical specifications, provided this does not materially impair the contractual usability of the booked services.
Not owed are, in particular, individual consulting services, customer-specific implementations, bespoke programming, the creation of customer-specific content, training outside the platform and guaranteed learning or security outcomes, unless expressly stated as part of the booked tariff.
3. Obligations of the customer
The customer ensures that its technical and organisational prerequisites for using a web-based application are met, in particular a current web browser, a stable internet connection and the necessary internal approvals.
The customer is responsible for ensuring that all information provided by it or its users is correct, current and complete.
The customer designates one person as administrator who is authorised to manage the customer account and can take or coordinate decisions in connection with The Phish Menu®.
Faults, security incidents or the suspicion of unauthorised use must be reported to jaeger + haeckerhase without delay in text form.
The customer is responsible for compliance with all employment-law, co-determination, data-protection and other statutory requirements applicable to it.
4. Customer account, users and rules of use
Use of The Phish Menu® requires the creation of a customer account. Registration requires at least the administrator's business email address, first and last name, company details, VAT ID and a password.
The platform may only be used for the contractually intended purposes (delivery of the security-awareness training). Access is permitted exclusively to users authorised by the customer within the booked number of users. User accounts are personal, non-transferable and may not be shared by several persons.
Access credentials must be kept secret. Administrators must set up two-factor authentication. The customer informs jaeger + haeckerhase without delay if there is reason to suspect that access credentials have become known to unauthorised third parties.
Where there is a reasonable suspicion of unauthorised use, use that endangers security or use in breach of the contract, jaeger + haeckerhase may temporarily, for a longer period or permanently block access, reset access credentials or take other appropriate protective measures.
The customer cannot upload its own content to the platform and cannot modify the security-awareness content provided, unless jaeger + haeckerhase expressly provides individual configuration options.
The following in particular are prohibited:
- passing on access credentials or sharing one account between several persons;
- any unlawful, discriminatory, insulting or infringing use;
- any action that impairs the security, availability or integrity of the platform (e.g. unauthorised intrusion, automated scraping without permission, circumvention of protective mechanisms, introduction of malicious code).
In the event of culpable breaches of these Terms, jaeger + haeckerhase may block the access concerned, request the customer to remedy the breach and, in the case of serious or continued breaches, terminate the contract for cause. Further claims for damages by jaeger + haeckerhase remain reserved.
5. Rights of use and rights to content
The subject matter of the licence agreement is the use of the training platform including the content it contains (e.g. video series, interactive deep dives, awareness games, knowledge checks, certificates) and the underlying software as a service (SaaS) for training purposes.
For the contract term, jaeger + haeckerhase grants the customer a simple, non-exclusive, non-transferable, non-sublicensable and time-limited right to use The Phish Menu® and the security-awareness content for its own business purposes with the agreed number of users.
Any further use is not permitted. In particular, the customer may not
- reproduce, distribute, make publicly available, rent, lend or provide the platform, its account or the content to third parties (other than its own employees);
- edit, decompile, reverse engineer the content or the software, or create derivative works;
- remove or alter protection, licence or copyright notices;
- exceed the booked number of seats or use access outside the licensed organisation.
All rights to The Phish Menu®, the platform, the trade mark, the security-awareness content, key visuals, designs, texts, graphics, video, graphic and audio content, databases, software, concepts and other protectable components remain with jaeger + haeckerhase or the respective rights holders.
The customer may use and export the completion and certificate data generated during the training for internal evidence purposes (e.g. audits).
jaeger + haeckerhase may use the customer's feedback free of charge, permanently and worldwide for the analysis, maintenance, further development and marketing of its services, provided no personal data or confidential information is thereby disclosed impermissibly.
The licence ends with the end of the subscription. The right of use expires at the end of the contract; further use of the content is not permitted.
In the "Artificial Intelligence" module the user may voluntarily make a short voice recording (approx. 10 to 20 seconds). The recording is transmitted via the server of jaeger + haeckerhase to the service provider ElevenLabs Inc. (New York, USA), which generates a temporary voice model from it and plays back a predefined sample text in that voice. Recording and voice model are deleted immediately after the exercise and are not stored permanently by either jaeger + haeckerhase or ElevenLabs. The exercise requires the user's explicit consent and can be skipped without any disadvantage. The transfer to the USA is safeguarded by the EU-US Data Privacy Framework and, in addition, by the EU Standard Contractual Clauses. Details of the data processing are described in the privacy policy, section 9.
6. Contract term, subscription model and termination
The Phish Menu® is provided on a subscription basis. The minimum term is twelve (12) months unless a longer term is stated in the order process. The contract term begins with the activation of the customer account or on the start date stated in the order process.
After expiry of the minimum term, the contract is automatically extended by a further twelve (12) months in each case unless it is terminated with three (3) months' notice to the end of the respective contract term. Notice may be given in text form, in particular by email to tpm@jaeger-haeckerhase.de, or via a termination function provided by jaeger + haeckerhase.
The right of both parties to terminate for cause remains unaffected. Cause exists in particular in the event of significant payment default, material breaches of the rules of use or significant infringements of law.
If the customer terminates for cause for which jaeger + haeckerhase is responsible, jaeger + haeckerhase refunds prepaid fees pro rata for the period after the end of the contract. If jaeger + haeckerhase terminates for cause for which the customer is responsible, the fees owed until the end of the agreed contract term remain due to the extent permitted by law.
After the end of the contract, users' access to the training content is blocked. For a further 30 days the customer can export the progress overview (CSV) and its users' certificates via the administration area. After this period, jaeger + haeckerhase deletes the customer's accounts and training data within 30 days; data contained in backups is overwritten no later than 14 days thereafter. Statutory retention obligations (in particular invoicing data, 8 years) remain unaffected.
7. Fees, payment terms and payment default
The fees are determined by the tariff selected in the order process, the booked number of users and the prices stated there. For EU customers with a valid VAT ID, invoicing is net without VAT (reverse charge).
The customer may pay by PayPal or credit card, where offered. Payment is made once in advance for the term (12 months).
If the customer is in default of payment, jaeger + haeckerhase may charge default interest and reminder costs in accordance with statutory provisions and, after a reminder, block access temporarily or permanently.
If the customer exceeds the booked number of users or usage limits, jaeger + haeckerhase is entitled to adjust the tariff to the appropriate one or to invoice the difference according to the applicable price list.
jaeger + haeckerhase is entitled to adjust prices for renewal periods with effect for the future. The adjustment is communicated no later than six (6) weeks before the start of the renewal period. If the customer objects, either party may terminate the contract at the end of the current contract term.
8. Availability, maintenance and warranty
jaeger + haeckerhase warrants an availability of the platform of 98.5 % as a monthly average, measured at the handover point of the data centre. The following do not count as downtime: announced maintenance work (announced at least 24 hours in advance, no more than 4 hours per month in total, where possible outside 8 a.m. to 6 p.m. on working days), disruptions due to force majeure, disruptions of the internet or of the data-centre operator outside the control of jaeger + haeckerhase, and disruptions caused by the customer or its users. If availability falls short in two consecutive months, the customer may terminate the contract for cause.
Temporary restrictions may result in particular from maintenance, updates, security measures, disruptions of telecommunications networks, third-party services, force majeure or other circumstances outside our control.
The customer must report defects or faults without delay in text form, describing the circumstances, effects and error messages as precisely as possible.
In the event of a defect, jaeger + haeckerhase will, at its own discretion and within a reasonable period, rectify the defect, provide a workaround or provide the service again. If the rectification finally fails, the customer may reduce the fee in accordance with statutory provisions or terminate for cause.
Warranty claims do not exist to the extent that the restriction is due to use not in accordance with the contract, the customer's own systems, missing technical prerequisites or other causes outside the area of responsibility of jaeger + haeckerhase.
Strict liability for defects existing at the time of conclusion of the contract pursuant to Section 536a(1), first alternative, BGB is excluded to the extent permitted by law.
9. Liability
jaeger + haeckerhase is liable without limitation for damage resulting from injury to life, body or health, for damage caused intentionally or by gross negligence, in the event of fraudulent concealment of a defect, in the event of the assumption of a guarantee and to the extent mandatory statutory provisions have been breached.
In the event of a slightly negligent breach of material contractual obligations, jaeger + haeckerhase is liable only for the typical, foreseeable damage.
Liability under clause 9.2 is limited in amount to the fees paid by the customer in the twelve months preceding the occurrence of the damage.
jaeger + haeckerhase is not liable for damage to the extent it results from the customer failing to fulfil statutory, organisational or technical obligations or not using The Phish Menu® in accordance with the contract.
Liability under the German Product Liability Act and other mandatory statutory liability provisions remains unaffected.
10. Confidentiality
The parties undertake to keep the other party's confidential information secret and to use it exclusively for the performance of the contract.
Confidential information is all information not publicly known that is marked as confidential or whose confidentiality is evident from the circumstances.
The confidentiality obligation does not apply to information that was already known without a confidentiality obligation, was lawfully obtained from third parties, is or becomes publicly known, was developed independently or must be disclosed by law.
The parties protect confidential information with appropriate technical and organisational measures.
The obligations continue for five (5) years beyond the end of the contract. Statutory confidentiality obligations remain unaffected.
11. Data protection and anonymised usage data
The parties process personal data in accordance with the applicable data-protection provisions, in particular the EU GDPR and the German Federal Data Protection Act (BDSG).
To the extent that jaeger + haeckerhase processes personal data on behalf of the customer, the parties conclude a data processing agreement pursuant to Art. 28 GDPR.
- As processor (on behalf of the customer): all data of the customer's employees: accounts (name, email, function role), credentials (password hash, 2FA), training and progress data, completions and certificates, the voice recording in the AI demo.
- As controller in its own right: contract and master data of the customer and its administrator contacts (company, name, email, order), invoicing and payment data (payment processing via Mollie), support and contact correspondence (mailboxes info@, support@, datenschutz@), web-server security logs (IP addresses, 14 days), error monitoring (Sentry, without personal data), visitor statistics of the public website (umami, without cookies), reminder and trial-period emails to administrators.
jaeger + haeckerhase may anonymise or aggregate technical, statistical and usage-related data and use it for statistics, benchmarking, security, product development and improvement.
Further information is provided in the privacy policy on thephishmenu.de and in the data processing agreement.
12. Changes to the services and to these Terms
jaeger + haeckerhase may amend these Terms and the service conditions with effect for the future where there is an objective reason, in particular a change in the legal situation, and the customer is not unreasonably disadvantaged.
Changes are communicated no later than four (4) weeks before they take effect in text form, in the customer account or by email. If the customer does not object in text form within this period, the changes are deemed accepted. The customer is informed of the consequences of remaining silent.
If the customer objects in time, the contract continues on the previous terms. jaeger + haeckerhase may terminate the contract if continuation on the previous terms is unreasonable.
It is expressly excluded that material primary obligations may be changed at will via the mechanism under clause 12.2.
13. References and marketing
jaeger + haeckerhase may name the customer as a reference customer and use its name, logo or trade mark for marketing purposes only with the customer's prior consent.
This does not affect the internal use of the customer's name and contract data for contract performance, invoicing, customer support and internal documentation.
14. Export control and permitted use
The customer ensures that the use of The Phish Menu® does not breach applicable export-control, sanctions or embargo regulations.
The customer may not make The Phish Menu® available to persons or organisations that are prohibited from using it under such regulations. jaeger + haeckerhase may block or refuse access to the extent necessary for compliance.
15. Final provisions
- The place of performance for all obligations is the registered office of jaeger + haeckerhase.
- The contract is governed exclusively by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods.
- The exclusive place of jurisdiction is Düsseldorf, Germany. Mandatory statutory places of jurisdiction remain unaffected.
- Amendments and additions to the contract must be made in text form.
- Should any provision be or become invalid or unenforceable, the validity of the remaining provisions remains unaffected.
- Support is provided by email to support@thephishmenu.de on working days (Monday to Friday, 9 a.m. to 5 p.m., excluding public holidays in North Rhine-Westphalia). Requests are usually answered within one working day. Support covers questions about using the platform and the remedying of platform faults; it does not cover the set-up or operation of the customer's IT systems. Faults and maintenance are published on the status page.
16. Annex: definitions
| Term | Definition |
|---|---|
| Administrator | the person designated by the customer to manage the customer account or recorded as such in the customer account. |
| Terms | these General Terms and Conditions. |
| Customer | the company, public body, institution or other organisation that books The Phish Menu® for its own business purposes. |
| Customer account | the customer's account for managing the subscription, the users, the invoicing data and the platform. |
| User | a natural person authorised by the customer who receives access to The Phish Menu® within the booked number of users. |
| Platform | the web application The Phish Menu® provided at thephishmenu.de and associated subdomains, including administration, learning, reporting and other functions to the extent included in the booked tariff. |
| Security-awareness content | the content, modules, learning materials, simulations, guidance, evaluations and other content provided by jaeger + haeckerhase via The Phish Menu® to raise awareness of information security and related topics. |
| The Phish Menu® | the SaaS product provided by jaeger + haeckerhase for the use of security-awareness content. |
| Contract | the contract concluded between jaeger + haeckerhase and the customer on the use of The Phish Menu®, consisting of the online order process, the tariff and service details, these Terms and, where applicable, the data processing agreement. |
| Contract year | each period of twelve (12) consecutive months from the start of the contract term or of a renewal period. |
| Confidential information | all information of a party not publicly known that becomes accessible to the other party in connection with the contract and is to be regarded as confidential. |
17. Provider identification and contact
The provider within the meaning of these Terms and the contact for contractual communication is:
| Company | jaeger + haeckerhase GmbH Kommunikation für Mensch und Marke |
| Managing directors | Markus Jäger, Denis Häcker and Michael Hasselbusch |
| Address | Pinienstraße 2 40233 Düsseldorf, Germany |
| Contact | Tel.: +49 211 828075-0 info@jaeger-haeckerhase.de www.jaeger-haeckerhase.de |
| Commercial register | Düsseldorf Local Court, HRB 66211 |
| VAT ID | DE278970438 |
| Competent regulatory authority | Landesanstalt für Medien Nordrhein-Westfalen Mauerstraße 51 40476 Düsseldorf |
| Termination | Notice of termination may be given in text form, in particular by email to tpm@jaeger-haeckerhase.de. |
