Acceptable Use Policy
Website, customer portal and digital services
- VERSION
- 1.0
- EFFECTIVE DATE
- 4 August 2026
- PROVIDER
- AP Digital Solutions GbR
- CONTACT
- info@apdigitalsolutions.eu
Please Read the Terms of this Policy Carefully Before Using the Site
Prepared for publication on AP Digital Solutions' website and customer portal. This Policy supplements the AP Digital Solutions Terms and Conditions.
What is in this Policy?
This Acceptable Use Policy (the “Policy”) sets out the standards that apply when you access or use our Site or Services, upload or submit content, communicate with other users where that functionality is available, link to our Site, use an account or customer portal, or interact with our Site or Services in any other way.
The Policy protects AP Digital Solutions GbR (“AP Digital”, “we”, “us” or “our”), our customers, Users, systems and third parties against unlawful, insecure, abusive or disruptive use. It supplements our Terms and Conditions (the “Terms”), Privacy Notice, applicable Order and data processing terms.
By using the Site, you must comply with this Policy. If you access the Site or Services for an organisation, you must ensure that your use is authorised and that the organisation and its Users comply with this Policy. If you cannot comply, you must not use the affected Site functionality or Service.
Use the Site and Services only for authorised, lawful and legitimate business purposes. Protect your credentials, respect system security and capacity, and submit only content and data that you are entitled to provide and that are necessary for the agreed purpose.
This Policy does not authorise security testing, scanning, scraping, reverse engineering or access to any account, data, tenant, system or functionality beyond the access expressly granted to you.
Scope, status and relationship with other documents
1.1The provider of the Site and Services is AP Digital Solutions GbR, Schulte Strasse 25, 57076 Siegen, Germany. Email: info@apdigitalsolutions.eu.
1.2This Policy applies to every person who accesses or uses apdigitalsolutions.eu, any language version, account, customer portal, upload facility, communication function, API or other digital service operated by AP Digital (together, the Site).
1.3This Policy forms part of the Terms and, where applicable, the agreement between AP Digital and the Customer. Capitalised terms not defined in this Policy have the meanings given in the Terms or the relevant Order.
1.4If there is a conflict, a specifically negotiated written agreement or Order prevails, followed by any applicable data processing agreement, the Terms and then this Policy. This Policy does not expand the scope of the Services or authorise any activity not permitted by the Order or Terms.
1.5Paid Services are offered exclusively on a business-to-business basis. A User accessing restricted functionality confirms that the User acts for an organisation, has authority to use the relevant account and is not using the Services as a consumer.
1.6The Customer must make this Policy available to its Users and take reasonable steps to ensure their compliance. The Customer remains responsible for its Users to the extent provided in the Terms and applicable law.
1.7To the extent that AP Digital provides an intermediary service within Regulation (EU) 2022/2065 (the Digital Services Act), this Policy also describes the contractual restrictions and the principal measures that AP Digital may use in relation to information supplied by Users. Mandatory rights and obligations under applicable law remain unaffected.
1.8This Policy takes effect on 4 August 2026.
Definitions and interpretation
2.1In this Policy:
“Applicable Law” means all laws, regulations, binding regulatory requirements, court and authority orders and legally binding codes applicable to the User, Customer, Site, Services or relevant activity.
“Customer” means the business, organisation, public-law entity or special public fund that enters into an Order or otherwise authorises a User to access restricted parts of the Site.
“Customer Data” means all data, documents, content, instructions and materials submitted, uploaded, transmitted or otherwise made available by or for a Customer in connection with the Services.
“Illegal Content” means information that, by itself or by reference to an activity, product or service, is not in compliance with European Union law or the law of a Member State that applies to the relevant matter.
“Order” means an order form, proposal, engagement letter, statement of work or other accepted document identifying the Services supplied to a Customer.
“Restricted Area” means any account-protected or otherwise non-public part of the Site, including a customer portal, workspace, upload area or administrative function.
“Security Event” means an actual or reasonably suspected loss, compromise, misuse or unauthorised access affecting an account, credential, device, system, network, Customer Data or the Site.
“Services” means the services described in an Order, including authorised use of the Site, customer portal and associated support.
“User” means any individual who accesses or uses the Site, including a person acting for a Customer.
“User Content” means any text, data, file, document, image, message, instruction, link, code or other information uploaded, submitted, transmitted, posted, shared or communicated by or for a User through the Site or Services. User Content includes Customer Data.
2.2The words “including”, “includes” and “in particular” are illustrative and do not limit the preceding words. An obligation not to do something includes an obligation not to attempt, assist, encourage, permit or enable it.
2.3References to laws or EU acts include amendments, replacements and applicable national implementing measures. Headings are for convenience only.
General acceptable use requirements
3.1A User may use the Site and Services only for the lawful, authorised and intended business purposes for which access was granted.
3.2Each User must comply with Applicable Law, the Terms, this Policy, the relevant Order, applicable data processing terms and reasonable operational or security instructions communicated by AP Digital.
3.3A User must not use the Site or Services in a way that:
- is unlawful, fraudulent, deceptive, abusive or contrary to the rights of another person;
- creates a material risk to the confidentiality, integrity, availability or resilience of the Site, Services, Customer Data or a third-party system;
- interferes with another User, Customer or third party, or with the normal operation of the Site or Services;
- causes AP Digital, a Customer or another person to breach Applicable Law, a court or authority order, professional secrecy, confidentiality, data protection, export-control or sanctions obligations;
- uses materially more storage, bandwidth, processing capacity or support resources than is reasonable for the agreed purpose, or is designed to avoid usage limits; or
- misrepresents the User’s identity, authority, affiliation, intentions or the origin of any communication or User Content.
3.4A User must not assist or permit another person to do anything prohibited by this Policy, including by providing credentials, access tokens, instructions, infrastructure or User Content.
3.5A User who is uncertain whether an intended use is permitted must stop the activity and contact AP Digital before proceeding.
Accounts and access security
4.1Accounts are individual and may be used only by the person to whom they are issued. A User must provide accurate registration information and must not create an account using a false identity, unauthorised email address or misleading affiliation.
4.2Users must:
- use a strong, unique password and keep all passwords, recovery codes, API keys, access tokens and authentication devices confidential;
- use multi-factor authentication where offered or required;
- not share, transfer, sell, lend or otherwise make an account or credential available to another person;
- secure devices and browsers used to access the Site, apply reasonable security updates and protect active sessions from unauthorised use;
- sign out or lock the relevant device when access is no longer actively supervised; and
- follow least-privilege principles and use only the permissions necessary for the User’s role.
4.3The Customer must promptly remove or request removal of access when a User changes role, leaves the organisation or no longer requires access. Shared or generic accounts may be used only where AP Digital has expressly approved them and appropriate accountability controls are in place.
4.4A User must not access another person’s account, another Customer’s workspace or any data, system, function or tenant for which the User has not been expressly authorised, even if a technical configuration appears to permit access.
4.5Loss, suspected compromise, unauthorised use or disclosure of credentials, or any other Security Event, must be reported to info@apdigitalsolutions.eu without undue delay. The User and Customer must cooperate with reasonable containment, investigation, credential-reset and remediation steps.
4.6AP Digital may require a password or credential reset, terminate active sessions, restrict permissions or temporarily disable access where reasonably necessary to protect the Site, Services, Customer Data or third parties.
Prohibited technical and security activity
5.1Without AP Digital’s prior written authorisation, a User must not:
- gain or attempt to gain unauthorised access to an account, tenant, database, file, server, network, source code, model, prompt, algorithm, administrative function or security control;
- probe, scan, enumerate, test or assess the vulnerability, configuration, performance or capacity of the Site or any connected system, including through penetration testing, load testing or security research;
- circumvent or attempt to circumvent authentication, authorisation, encryption, rate limits, usage limits, storage limits, access controls, security warnings, content controls or audit logging;
- introduce, upload, transmit or activate malware, ransomware, spyware, a virus, worm, Trojan horse, logic bomb, malicious macro, exploit, backdoor, corrupted file or other harmful code;
- perform or facilitate a denial-of-service attack, distributed denial-of-service attack, traffic flood, resource-exhaustion attack or other activity intended or likely to materially degrade availability or performance;
- intercept, monitor, capture, alter, redirect or exfiltrate data or communications without authority, including through packet capture, session hijacking or man-in-the-middle techniques;
- scrape, crawl, spider, harvest, index, mirror, copy or systematically extract Site content, metadata, account information or data except through a documented interface expressly approved for that purpose;
- reverse engineer, decompile, disassemble, decode or otherwise attempt to discover source code, object code, models, prompts, algorithms, workflows, trade secrets or non-public technical information, except to the limited extent that a prohibition is not permitted by mandatory law;
- remove, falsify or conceal attribution, copyright notices, security labels, headers, identifiers, logs or the origin of a request or communication;
- use the Site to send spam, phishing messages, malicious links, unsolicited bulk communications or fraudulent requests;
- use Site resources for cryptocurrency mining, unrelated high-volume computation, a general-purpose backup repository, file distribution or any activity outside the agreed Services;
- publish or disclose non-public security findings, vulnerability information, benchmark results or performance tests concerning the Site without AP Digital’s prior written consent; or
- use the Site or AP Digital infrastructure to attack, compromise, test or interfere with any third-party system.
5.2Nothing in this Policy grants authorisation to conduct security testing. A person who encounters a potential vulnerability accidentally or during ordinary authorised use must stop any further testing or access, avoid viewing or altering data beyond what is necessary to identify the issue, and report it under section 11.
5.3Where AP Digital approves an integration, API, migration, test or security activity in writing, the User must comply with the approved scope, timing, rate limits, safeguards and instructions and must stop immediately if the activity exceeds that scope or creates an unexpected risk.
Standards for User Content
6.1User Content must:
- comply with Applicable Law in each relevant jurisdiction;
- be relevant, necessary and proportionate to the authorised purpose for which it is submitted;
- be accurate and complete to the extent reasonably required for the Services, and clearly distinguish verified facts, assumptions, estimates, allegations and opinions;
- be submitted by a person who has the rights, permissions and authority required to provide it and permit its processing for the intended purpose;
- use the approved format and secure transmission channel and comply with any classification, file-size, encryption or labelling requirements communicated by AP Digital; and
- be free from malicious code, hidden executable content and features intended to circumvent security or content controls.
6.2User Content must not:
- constitute or facilitate Illegal Content, fraud, deception, impersonation or a criminal offence;
- infringe copyright, database rights, trade marks, patents, trade secrets, confidentiality, privacy, data protection, personality rights or any other rights of a third party;
- be defamatory, knowingly false or materially misleading;
- be threatening, abusive, harassing, stalking, hateful or discriminatory on grounds protected by Applicable Law;
- promote or facilitate terrorism, violent extremism, unlawful violence, exploitation, trafficking, child sexual abuse, unlawful weapons activity or other serious harm;
- contain obscene or sexually explicit material unrelated to the legitimate Services;
- contain unsolicited advertising, promotional material, chain messages, bulk solicitations or other spam;
- include stolen credentials, private keys, access tokens, unlawfully obtained personal data, unauthorised surveillance material or information obtained through a breach of confidence;
- breach a court order, legal privilege, professional secrecy, an employment restriction, a contractual restriction or a legally binding non-disclosure obligation; or
- contain material that is export-controlled, sanctioned, classified or subject to heightened legal restrictions unless AP Digital has expressly agreed in writing to receive and process it.
6.3Section 6.2 does not prevent the lawful and necessary submission of relevant business records, allegations, investigation material, vulnerability information or other sensitive evidence for an authorised engagement, provided that the User has authority and a lawful basis to submit it, clearly identifies its context and status, limits access appropriately and follows the agreed secure process.
6.4Where the Site permits publication or sharing beyond the Customer’s authorised workspace, a User must not post Confidential Information, personal data or security-sensitive information unless the disclosure is lawful, necessary and expressly authorised.
6.5Rights in User Content and the limited licence required for AP Digital to process it are governed by the Terms and the applicable Order. AP Digital does not endorse User Content merely because it is stored, transmitted or processed through the Site.
Personal, confidential and regulated data
7.1A User may submit personal data only where the Customer has determined and documented a lawful basis, has provided required information to affected individuals, has authority to disclose the data to AP Digital and has complied with applicable employment, worker-representation, confidentiality and data protection requirements. Consent must not be treated as the default basis where it is not freely given or otherwise valid.
7.2Users must apply data minimisation. Names and direct identifiers should be removed or replaced with pseudonymous identifiers where they are not necessary. A User must not submit personal data merely because it may be convenient or available.
7.3Special-category data, criminal-conviction data, biometric data, genetic data and information subject to professional secrecy or equivalent heightened protection may be submitted only where:
- the data are demonstrably necessary for the agreed Services;
- the Customer has identified the applicable legal condition and completed any required assessment or consultation;
- the applicable Order or written instruction expressly covers the relevant category; and
- the data are transmitted and accessed using safeguards appropriate to their sensitivity.
7.4For pay-transparency Services, Users should not submit private contact details, home addresses, national identification numbers, bank-account details, medical information, disability information, trade-union membership, ethnicity, religion, sexual orientation, disciplinary records or reasons for absence unless the relevant item is expressly agreed and demonstrably necessary.
7.5For Cyber Resilience Act or product-security Services, Users must not submit live passwords, private keys, authentication secrets, active malware, weaponised exploit code, unrestricted production credentials or third-party vulnerability information without authority. Where such material is strictly necessary, the User must obtain AP Digital’s prior written agreement and use the designated secure channel and handling instructions.
7.6Classified information, national-security information, export-controlled technical data, payment-card data, patient or clinical data, highly sensitive financial data and other information requiring controls beyond AP Digital’s agreed service environment must not be submitted unless AP Digital has expressly accepted the relevant data category and security requirements in writing.
7.7The Site and Services must not be used to conduct unlawful employee monitoring, discriminatory profiling, retaliation, covert surveillance or decisions based solely on automated processing that produce legal or similarly significant effects for an individual.
7.8Sensitive User Content must be transmitted through the portal or other secure channel designated by AP Digital, not through an unapproved personal account, public link, consumer file-sharing service or public generative-AI tool.
7.9Processing of personal data is further governed by AP Digital’s Privacy Notice, the data processing terms in the Terms and any separately agreed data processing agreement.
Communications and interaction with other users
8.1This section applies where the Site permits a User to send messages, share material, invite another User, comment, collaborate or otherwise communicate with another person.
8.2Communications must be lawful, professional, relevant to the authorised business purpose and addressed only to persons whom the User is entitled to contact through the Site.
8.3A User must not:
- harass, threaten, intimidate, discriminate against or abuse another person;
- impersonate another person or falsely claim authority, endorsement, affiliation or professional status;
- send unsolicited marketing, repeated unwanted messages, chain communications, phishing requests or malicious links;
- request or disclose passwords, authentication codes, private keys, unnecessary personal data or Confidential Information through a communication function;
- circumvent a block, access restriction, consent preference or reasonable request to stop communications; or
- use communications to coordinate an unlawful act, security breach, misuse of data or breach of this Policy.
8.4Users must exercise appropriate caution when acting on information supplied by another User and must independently verify authority, instructions and payment or data-transfer requests where the circumstances require it.
Linking to the Site
9.1A User may link to a publicly accessible page of the Site in a fair and lawful manner that does not damage AP Digital’s reputation or take unfair advantage of it.
9.2A link must not:
- suggest an association, approval, partnership, certification or endorsement by AP Digital where none exists;
- use AP Digital’s name, logo or trade marks in a way that is misleading or not otherwise permitted;
- frame, embed, mirror or reproduce the Site, or hotlink Site assets, without prior written consent;
- bypass authentication, payment, access controls, security warnings or restrictions on a Restricted Area;
- originate from a page or service containing Illegal Content or content that materially breaches the standards in section 6; or
- enable another person to access Customer Data, Confidential Information or a non-public Deliverable without authorisation.
9.3A User must have authority over the website, application or communication from which the link is made. AP Digital may withdraw linking permission where a link is misleading, unlawful, insecure or otherwise materially inconsistent with this Policy.
Automated access, APIs and artificial intelligence
10.1Automated access is prohibited unless it uses an API, integration or function expressly made available or approved by AP Digital for that purpose.
10.2Users of an approved API or integration must protect credentials, follow the documentation, respect rate and volume limits, validate outputs, maintain appropriate logs and stop use if the integration behaves unexpectedly or creates a security or data-protection risk.
10.3Without AP Digital’s prior written consent, a User must not use the Site, Services, Site content, Deliverables or outputs to:
- train, fine-tune, test, benchmark or improve a competing model, platform, product or service;
- build a dataset, knowledge base, template library or replicated service for commercial redistribution;
- perform automated extraction, model inversion, prompt extraction, prompt injection, data exfiltration or attempts to override safeguards; or
- misrepresent machine-generated or assisted output as independently verified legal advice, regulatory approval, certification or a final human decision.
10.4Where AP Digital provides AI-assisted functionality, the User must apply competent human review, verify material inputs and outputs and remain responsible for decisions and submissions. The functionality must not be used as the sole basis for an employment, remuneration, disciplinary, legal, credit, insurance or other decision producing legal or similarly significant effects for an individual.
10.5A User must not upload AP Digital Confidential Information, Customer Data or personal data obtained through the Services into a public or unapproved third-party AI system. Approved AI or automation use remains subject to the Terms, the Order, data processing terms and Applicable Law.
Reporting illegal content, misuse and security issues
11.1Suspected Illegal Content or a material breach of this Policy may be reported to info@apdigitalsolutions.eu with the subject line “Acceptable Use Report”.
11.2A report concerning Illegal Content should include, so far as reasonably available:
- a sufficiently precise explanation of why the information or activity is alleged to be illegal or prohibited;
- the exact electronic location, account, workspace, file, message, URL or other information enabling AP Digital to identify the relevant material;
- the reporting person’s name and email address, except where Applicable Law permits or requires a report without those details;
- any relevant legal provision, right, authority or supporting evidence; and
- a statement confirming that the report is made in good faith and that the information supplied is accurate and complete to the reporting person’s knowledge.
11.3AP Digital may request additional information where a report is too vague to assess. AP Digital is not required to act on manifestly unfounded, abusive, duplicative or malicious reports, subject to any mandatory legal duty.
11.4A suspected vulnerability or security issue must be reported to info@apdigitalsolutions.eu with the subject line “Security Vulnerability”. The reporter should provide a clear description, affected page or function, time observed, reproducible steps that do not involve further exploitation, potential impact and safe contact details.
11.5A vulnerability reporter must stop testing, not access or retain data beyond what was encountered incidentally, not alter or delete data, not disrupt the Site, not demand payment or threaten disclosure, and not publish the issue before AP Digital has had a reasonable opportunity to investigate and address it. This reporting route does not grant prior or retrospective authorisation for prohibited testing.
11.6Loss or compromise of an account or credential, unintended access to another Customer’s information, suspected malware or any Security Event must be reported without undue delay. Immediate reporting is required where continued access or disclosure could increase harm.
11.7Knowingly false, misleading, malicious or retaliatory reports are prohibited. This does not prevent a person from making a good-faith report that later proves to be mistaken.
Monitoring, moderation and enforcement
12.1AP Digital does not undertake to monitor all User Content or communications and, except where Applicable Law requires otherwise, is not subject to a general obligation to do so.
12.2AP Digital may use proportionate automated and manual measures to operate and protect the Site, investigate reports and enforce this Policy. These measures may include authentication and access logs, malware scanning, file-type and file-size controls, rate limits, anomaly and abuse detection, security alerts, duplicate detection, quarantine and manual review by authorised personnel.
12.3Automated measures may block, limit or quarantine a request, file, session or account where an immediate technical response is reasonably necessary. A decision to terminate a Customer’s Services or impose another material continuing restriction will ordinarily involve human review, unless immediate action is necessary to address an urgent security, legal or operational risk.
12.4Where AP Digital reasonably believes that this Policy, the Terms, an Order or Applicable Law has been breached, AP Digital may take one or more proportionate measures, including:
- issue a warning, request information, require correction or specify remedial steps;
- reject, remove, disable, redact, restrict, block or quarantine affected User Content, links, communications or functionality;
- apply technical limits, suspend an upload, terminate a session, reset credentials or restrict permissions;
- temporarily suspend a User, account, workspace or affected part of the Services;
- terminate access or an affected Order in accordance with the Terms;
- preserve relevant evidence and notify the Customer’s authorised administrator;
- notify an affected third party, service provider, rights holder, insurer, professional adviser or competent authority where permitted or required by law; and
- exercise any other contractual or statutory right reasonably available in the circumstances.
12.5In selecting a measure, AP Digital may consider the nature, severity, duration, frequency and impact of the conduct; whether it was intentional or repeated; the User’s explanation and remediation; the risk to persons, data or systems; legal obligations; and whether a narrower measure can adequately address the issue.
12.6AP Digital may act immediately and without prior notice where delay could create or increase a material security risk, unlawful disclosure, harm to another person, breach of law, compromise of an investigation or disruption to the Site or Services.
12.7Where the Digital Services Act applies to a particular restriction, AP Digital will apply and enforce that restriction diligently, objectively and proportionately, with due regard to the rights and legitimate interests of affected persons, including privacy, data protection, non-discrimination and freedom of expression and information.
12.8Removal or restriction does not require AP Digital to retain User Content beyond the period required by the Terms, a data processing agreement, Applicable Law or a legitimate evidence-preservation need.
Notice, reasons and request for review
13.1Where reasonably possible and legally permitted, AP Digital will notify the affected User or Customer before or without undue delay after taking a material enforcement measure. The notice will identify the affected account, content or functionality and provide a reasonably sufficient explanation of the principal ground and measure.
13.2AP Digital may withhold or limit notice or reasons where disclosure is prohibited by law or an authority, would expose confidential or security-sensitive information, would facilitate evasion or further abuse, would prejudice an investigation, would create a material risk to another person or system, or where AP Digital cannot reasonably identify or contact the affected person.
13.3Where the issue is remediable and does not require urgent action, AP Digital will ordinarily provide a reasonable opportunity to remedy it before terminating access. Immediate suspension, restriction or removal remains permitted under section 12.6.
13.4An affected User or Customer may request a review by emailing info@apdigitalsolutions.eu within 30 calendar days after notice of the measure. The request should identify the measure, explain why it is said to be incorrect or disproportionate and provide relevant supporting information.
13.5The review will be carried out by an appropriately authorised person and will not be decided solely by an automated system. AP Digital may maintain the measure while the review is pending where reasonably necessary to manage risk or comply with law.
13.6AP Digital will communicate the outcome within a reasonable period having regard to the complexity, urgency and information available. A review under this Policy does not limit any mandatory complaint, court or regulatory right.
Preservation, disclosure and cooperation
14.1AP Digital may preserve relevant User Content, logs, account information and technical records where reasonably necessary to investigate a suspected breach, contain a Security Event, comply with a legal obligation or order, establish or defend legal claims, or protect persons, data or systems.
14.2Preservation and any disclosure will be limited to what is reasonably necessary and will be handled in accordance with Applicable Law, the Privacy Notice, the Terms and applicable data processing terms.
14.3AP Digital may cooperate with competent courts, regulators, law-enforcement bodies, data protection authorities, digital-services authorities and other legally authorised bodies. Nothing in this Policy requires AP Digital to challenge or notify a User about a lawful order where doing so is prohibited or inappropriate.
14.4Users and Customers must provide reasonable assistance in investigating and remedying misuse attributable to their accounts, devices, personnel or User Content, including preserving relevant evidence, identifying authorised Users and implementing reasonable containment measures.
14.5AP Digital will not disclose a vulnerability reporter’s identity or a reporting person’s contact details beyond those who reasonably need the information, except where disclosure is required by law, necessary to investigate or address the matter, or authorised by that person.
Changes to this Policy
15.1AP Digital may update this Policy to reflect changes in law, regulatory expectations, security threats, technology, Site functionality or the Services.
15.2The current version and effective date will be published on the Site. Material changes will be notified through the Site, a Restricted Area or email where reasonably appropriate.
15.3For an existing paid Services agreement, changes apply in accordance with the change provisions of the Terms and may not be used to alter a specifically negotiated Order retrospectively, except to the extent necessary to comply with mandatory law or address an urgent security risk.
15.4For public Site use and new access granted after the effective date, the revised Policy applies from the stated effective date to the extent permitted by law. A User who cannot comply must stop the affected use.
Contact, governing law and jurisdiction
16.1Questions, reports and requests concerning this Policy should be sent to:
16.2The governing law and jurisdiction provisions in the Terms apply to this Policy. Where no separate contractual provision applies, this Policy and non-contractual obligations connected with it are governed by the laws of the Federal Republic of Germany, excluding conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods.
16.3Where the User or Customer is a merchant (Kaufmann), a legal person under public law or a special fund under public law, the courts having jurisdiction for AP Digital’s registered office in Siegen have exclusive jurisdiction to the extent permitted by law. Mandatory statutory jurisdictions remain unaffected.
16.4If a provision of this Policy is invalid or unenforceable, the remaining provisions continue to apply. The invalid or unenforceable provision will be replaced by the applicable statutory rule; section 306 of the German Civil Code remains unaffected where applicable.
16.5Failure or delay in enforcing this Policy does not waive the relevant right. No person other than AP Digital, the relevant Customer and their permitted successors has a contractual right to enforce this Policy, without prejudice to mandatory rights under Applicable Law.