Institution Alert← Back to site

Terms of Use

Business-to-business terms for the Institution Alert crisis communication software (“CMP” or the “Service”).

Effective 22 July 2026 · Version 1.3

Communication support, not a crisis-management service

CMP supports communication procedures created and controlled by the Customer. It is not a crisis-management plan, emergency service, safety consultancy or substitute for trained personnel, tested procedures and backup channels.

1. Parties and contractual documents

These Terms apply between the provider identified in the Legal Notice (“Provider”) and the institution, business, authority or other organisation ordering or being granted the Service (“Customer”). CMP is offered for professional and institutional use, not consumer use.

The applicable order form, individual service agreement, service-level agreement (“SLA”), data-processing agreement (“DPA”) and these Terms form the agreement. Individually negotiated terms and the order form prevail over these Terms in the event of conflict.

2. Service scope

CMP provides software functions for institution-controlled alert preparation, delivery through supported communication technologies, acknowledgement tracking, device enrollment, access administration and operational documentation. Available functions depend on the ordered plan.

Unless expressly agreed in writing, the Provider does not:

  • create, review, certify or approve crisis-management, emergency-response, evacuation, business-continuity or regulatory plans;
  • monitor the Customer’s operations or determine whether an emergency exists;
  • make operational, medical, legal, safety or crisis-management decisions or provide professional advice;
  • verify the truth, completeness, legality or suitability of Customer messages;
  • contact police, fire, medical, regulatory or other emergency services; or
  • guarantee that every message will reach every device within a particular time.

3. Plans, capacity, pilots and onboarding

Public prices are stated exclusive of applicable VAT. The Customer's binding plan, fees, billing interval, included device capacity, add-ons, term and renewal conditions are recorded in the applicable order form. Annual fees are payable in advance unless the order form states otherwise.

Device capacity means the number of active enrolled devices permitted under the ordered plan. Additional capacity may be ordered in the increments and up to the plan maximum stated in the order form. Increases may be charged proportionately for the remainder of the current term. Reductions normally take effect at renewal. Reaching capacity may prevent new enrollment but does not automatically remove already enrolled devices.

A free pilot does not require a payment method and does not automatically become a paid subscription. Unless otherwise approved in writing, only one 30-day free pilot is available per legal institution. The Provider may verify eligibility using the Customer's legal name, business domain, verified work-email domain, country, VAT or registration identifier where supplied, and previous pilot records. The Provider may reject duplicate or abusive requests or approve a documented exception. Pilot operational access ends automatically after 30 consecutive days unless the Customer is moved to a paid plan.

Essential and Professional plans use self-service documentation and video guidance unless paid onboarding is ordered. A paid online onboarding session covers only the duration and subjects stated in the order form. Guided initial onboarding for Enterprise Customers is included only to the extent stated in the applicable quotation or order form.

Payments may be processed by Stripe. Essential and Professional subscriptions renew automatically for the selected monthly or annual billing interval until cancelled in accordance with the order form. Enterprise fees may be collected by annual invoice. The Customer must provide accurate billing, address and tax-identification information and keep its payment method current. Failed or overdue payment may restrict new enrollment or operational access after applicable notice and cure periods. Stripe's own payment and portal terms may also apply to the Customer's use of those payment services.

4. Customer responsibilities

The Customer retains sole operational control and responsibility for its crisis management and use of CMP. In particular, the Customer must:

  • maintain appropriate crisis-management, emergency-response, evacuation and business-continuity plans;
  • define decision authority, escalation paths, recipients and regulatory or emergency-service reporting procedures;
  • appoint, train and supervise authorised administrators and promptly revoke unnecessary access;
  • ensure alert content and instructions are accurate, lawful, authorised and suitable for the intended recipients;
  • test CMP and its own procedures at appropriate intervals without sending misleading live alerts;
  • maintain suitable independent backup channels and never rely on CMP as the sole means of emergency communication;
  • ensure supported devices have connectivity, notification permission and appropriate configuration; and
  • comply with employment, data-protection, telecommunications, safety, accessibility, record-retention and sector-specific requirements applicable to its use.

5. Emergency use and delivery dependencies

CMP is not an emergency service.In immediate danger, users must contact the applicable emergency services and follow official and institutional instructions.

Delivery depends on systems outside the Provider’s direct control, including internet and mobile connectivity, electricity, device condition and settings, browser and operating-system behavior, push-notification providers and third-party infrastructure. Delayed, duplicated or failed delivery can occur. Any availability or response commitment applies only if expressly stated in an SLA.

6. Accounts and security

Administrative accounts are personal and may not be shared. The Customer must use accurate account information, protect credentials, restrict administrative access to authorised personnel and promptly notify the Provider of suspected compromise. Invitation, activation and NFC links must be handled according to their intended purpose and may not be published or transferred without authorisation.

7. NFC software and customer-supplied media

Where the NFC add-on is ordered, CMP provides software for creating and managing supported provisioning links, visitor access and location tags. The Provider does not supply physical cards, labels, printers or NFC-writing equipment unless expressly agreed in writing.

The Customer is responsible for selecting compatible media and equipment and for purchasing, writing, testing, labelling, distributing, securing, recovering, replacing and disposing of its NFC cards and tags. Published compatibility information is guidance and does not guarantee that every card, label, writer, phone or operating-system version will function correctly. NFC media must be tested before operational use.

8. Acceptable use

The Service may not be used to send unlawful, deceptive, discriminatory, harassing or knowingly false messages; impersonate another person or authority; interfere with the Service; bypass security controls; or create avoidable danger. The Provider may restrict or suspend access where reasonably necessary to protect users, the Service or third parties, investigate misuse or comply with law.

9. Customer content and indemnification

The Customer remains responsible for content, recipient selection and instructions submitted through CMP. The Customer grants the Provider the rights required to process and transmit that content solely to operate the Service.

To the extent permitted by law, the Customer will indemnify the Provider against third-party claims, reasonable costs and damages arising from the Customer’s culpable unlawful content, unauthorised instructions or material breach of these Terms, except to the extent caused by the Provider.

10. Availability, maintenance and changes

The Provider maintains and develops the Service with reasonable care. Planned maintenance, urgent security work and circumstances outside reasonable control may affect availability. Specific uptime, support, recovery or response commitments exist only where stated in the applicable SLA. The Provider may update the Service to improve security, reliability, compliance or functionality, provided the essential agreed service is not unreasonably reduced.

11. Documentation and reports

CMP records and exports document activity processed through the Service. They are not a certification that a Customer’s crisis-management plan, response, message delivery, legal reporting or other obligations were complete or effective. The Customer must review records for accuracy and retain any additional evidence required by its own policies or law.

12. Data protection

Each party must comply with applicable data-protection law. Where the Provider processes personal data on the Customer’s behalf, the parties will enter into the applicable DPA. The Customer is responsible for establishing the legal basis, transparency information, retention requirements and internal permissions required for its use. General information is available in the Privacy Notice.

13. Warranty and liability

The Provider is liable without limitation where required by law, including for intent and gross negligence; culpable injury to life, body or health; expressly assumed guarantees; and mandatory product-liability claims.

For simple negligence, the Provider is liable only for breach of an essential contractual obligation whose performance is necessary for proper performance of the agreement and on which the Customer may regularly rely. In that case liability is limited to the damage foreseeable and typical when the agreement was concluded, subject to mandatory law and any individually agreed provision.

Subject to those rules, the Provider is not responsible for the Customer’s crisis plans, operational decisions, message content, recipient selection, failure to use required emergency or regulatory channels, unauthorised use, unsupported devices, or failures of connectivity and third-party systems outside the Provider’s reasonable control. Nothing in these Terms excludes liability that cannot legally be excluded.

14. Term, suspension and termination

The contract term, fees and ordinary termination rights are stated in the order form. Either party’s right to terminate for good cause remains unaffected. Upon termination, Customer access ends subject to agreed export and retention arrangements and legal obligations.

15. Final provisions

German law applies, excluding conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods, to the extent legally permitted. If the Customer is a merchant, legal entity under public law or special fund under public law, the Provider’s registered office is the agreed venue, subject to mandatory venue rules.

Changes to these Terms apply to existing contracts only in accordance with the contract and applicable law. If a provision is invalid, the remaining provisions remain unaffected; the applicable statutory rule takes its place.