metisora — General Terms and Conditions for the metisora Service
Version 2.0 — effective 29 September 2026
This is a convenience translation and is not binding. The German version of these Terms is the sole authoritative text and is available at
https://app.metisora.com/legal/terms. In the event of any discrepancy, the German wording governs (§ 21.5).
These General Terms and Conditions ("Terms") govern the provision of the metisora software-as-a-service offering by
metisora — Julian Miksch
Schlott 24, 86558 Hohenwart, Germany
Sole proprietorship (Einzelunternehmen), not entered in the commercial register
E-mail: info@metisora.com
("metisora", "we", "us") to its business customers ("Customer", "you").
1. Scope, business customers only
1.1 These Terms apply to every contract for the use of the metisora service (the "Service") between metisora and the Customer, including all associated onboarding, configuration and support services.
1.2 The Service is offered exclusively to entrepreneurs within the meaning of § 14 BGB, legal persons under public law and special funds under public law. It is not offered to consumers (§ 13 BGB). By accepting these Terms the Customer confirms that it is concluding the contract in the exercise of its commercial or independent professional activity.
1.3 Terms and conditions of the Customer do not apply, even if metisora does not separately object to them and performs the Service without reservation. Deviating or supplementary terms of the Customer become part of the contract only if metisora has agreed to them expressly and in text form.
1.4 The following documents form part of the contract and, in the event of conflict, take precedence in this order: (1) an individually agreed order confirmation or order form, if any; (2) the Data Processing Agreement (Annex A); (3) these Terms.
2. Conclusion of the contract, authority to accept
2.1 How the contract is concluded. metisora provisions the Customer's organisation and designates a person as the Customer's initial administrator ("Administrator"). When that person first signs in, the Service presents these Terms and the Data Processing Agreement and requires their acceptance before the Service can be used. Acceptance concludes the contract on the plan and at the fee communicated to the Customer prior to acceptance (§ 9).
The Privacy Policy and the Imprint are presented alongside them for information and are not accepted. The Privacy Policy is notice under Art. 13 and 14 GDPR and the Imprint is a statutory disclosure under § 5 DDG; neither is an agreement, and requiring "acceptance" of a privacy notice would wrongly suggest that the processing it describes rests on consent. It does not — § 12.2 and the Privacy Policy itself state the legal bases.
2.2 Authority. The person accepting warrants that they are authorised to conclude this contract on behalf of the Customer. metisora may rely on that warranty. If the Customer requires a signed order form instead, it must notify metisora in text form before the Administrator accepts; metisora will then provide one and the contract is concluded on signature.
2.3 Record of acceptance. metisora records the identity of the accepting person, the time of acceptance, and the version and content fingerprint (SHA-256) of each document accepted, and makes that record available to the Customer on request. The fingerprint is shown with each document, so a copy the Customer has kept can be matched against the record of what was accepted. The accepted versions are retrievable, downloadable and printable at all times at https://app.metisora.com/legal/terms and https://app.metisora.com/legal/dpa.
2.4 Free trial or evaluation access, where granted, is provided for the agreed evaluation period only, may be withdrawn at any time, is provided without any warranty beyond § 16.5, and converts into a paid subscription only on the Customer's express acceptance.
3. Subject matter of the Service
3.1 metisora is a Sales Process Intelligence service for Salesforce Sales Cloud. It connects to the Customer's Salesforce organisation, extracts historical opportunity and opportunity stage-history data, analyses how deals actually moved through the Customer's sales process, computes the metisora SPI Score and related metrics, visualises them, and generates written findings using a large language model.
3.2 The functional scope in force is the scope described in the product documentation and in the Service itself at the time of acceptance. metisora develops the Service continuously. metisora may add, change and improve functions; § 20 applies to changes that materially reduce the agreed functional scope.
3.3 What the Service is not. The Service is a decision-support tool. It does not replace the Customer's own commercial, managerial or personnel judgement, and it is not a system of record. The Customer's Salesforce organisation remains the source of truth for all data taken from it.
3.4 Connection to Salesforce. The Service accesses the Customer's Salesforce organisation via OAuth 2.0, using an access authorisation granted by a user of the Customer. The Customer is responsible for granting, maintaining and — where it wishes to end the access — revoking that authorisation, and for the permissions assigned to the connecting user, which determine what the Service can read. Salesforce is the Customer's own contractual relationship; metisora is not a party to it and owes nothing in respect of Salesforce's availability, API limits or terms of use.
3.5 No Salesforce writes. The Service reads from Salesforce. It does not create, modify or delete records in the Customer's Salesforce organisation.
4. Plans, limits and users
4.1 The Service is offered in plans that differ in the number of sales representatives covered, the number of Scopes (independently configurable analysis configurations) and the functions included. The plan booked, its limits and its fee follow from the order confirmation or from the plan selected on acceptance.
4.2 Named users. Access is granted to individual named users of the Customer. Accounts may not be shared between persons. The Customer is responsible for all activity under its users' accounts.
4.3 Authentication. Users authenticate exclusively via Salesforce single sign-on. metisora stores no passwords. The security of the Customer's Salesforce authentication — including multi-factor authentication and the de-provisioning of departing employees — is the Customer's responsibility. A user who loses access to the Customer's Salesforce organisation loses access to the Service; existing sessions end at the latest on expiry of their session lifetime (currently 14 days) or immediately on sign-out.
4.4 Exceeding plan limits. If the Customer's actual usage exceeds the booked plan (for example, more sales representatives than the plan covers), metisora will notify the Customer and the parties will agree the appropriate plan. metisora may charge the difference from the beginning of the month in which the limit was first exceeded.
5. Onboarding, configuration and support
5.1 Onboarding. Unless agreed otherwise, onboarding is included: metisora supports the Customer in connecting Salesforce, mapping fields, defining the sales process stages, configuring the sales hierarchy and setting up the first Scope. Onboarding is a service (Dienstleistung); metisora owes diligent performance, not a particular analytical result.
5.2 Support is provided in English and German by e-mail to info@metisora.com during metisora's business hours (Monday to Friday, 09:00–17:00 CET/CEST, excluding public holidays at metisora's seat). metisora aims to respond within one business day. No response or resolution time is guaranteed unless separately agreed in text form.
5.3 Customer cooperation. The Customer will name a competent contact person, provide the information and access metisora reasonably requires, and respond to metisora's queries without undue delay. Where metisora's performance depends on the Customer's cooperation and that cooperation is not provided, the corresponding deadlines are extended accordingly.
6. Availability
6.1 metisora provides the Service with an availability of 99.0 % per calendar month, measured at the transfer point between metisora's hosting infrastructure and the public internet.
6.2 The following do not count as unavailability: (a) scheduled maintenance announced at least 24 hours in advance, up to 4 hours per calendar month, wherever possible outside 09:00–18:00 CET/CEST on business days; (b) urgent security maintenance; (c) unavailability caused by force majeure (§ 19), by the Customer, by the Customer's Salesforce organisation or by third-party services outside metisora's control; (d) unavailability of the Anthropic API, which affects only the AI functions (§ 8.5).
6.3 If availability falls below 95 % in a calendar month, the Customer may request a credit of 10 % of the monthly fee for that month. The request must be made within one month of the end of the affected month. Statutory rights under § 16 and § 17 remain unaffected.
7. Customer obligations and responsibility for data
7.1 The Customer is responsible for the data it makes accessible to the Service ("Customer Data"), including the lawfulness of its collection and of its transfer to metisora for analysis.
7.2 The Customer warrants that it is entitled to have the Customer Data processed by metisora and by metisora's sub-processors as described in the Data Processing Agreement, and that such processing does not infringe third-party rights, works agreements or statutory provisions.
7.3 The Customer will not (a) use the Service in breach of applicable law; (b) attempt to circumvent the Service's access controls or tenant separation, or to access data of another customer; (c) perform load, penetration or vulnerability testing against the Service without metisora's prior consent in text form; (d) make the Service available to third parties other than its own affiliates' personnel agreed in the order confirmation; (e) reverse engineer the Service except to the extent § 69e UrhG permits.
7.4 Salesforce data minimisation. The Customer decides which Salesforce objects the Service extracts and over what period, and which fields through the field-level security of the Salesforce user who authorises the connection: for opportunities, opportunity line items and accounts, the Service extracts every field that user can read. The Customer will not configure the Service or that user's access so as to extract fields containing special categories of personal data (Art. 9 GDPR), data relating to criminal convictions (Art. 10 GDPR), or personal data it does not require for the analysis. If it does so nonetheless, it does so on its own responsibility and will indemnify metisora against claims arising from it on first demand, save where metisora is responsible for the breach.
8. Permitted purpose, employee data and artificial intelligence
This section exists because the Service analyses data in which individual sales representatives are identifiable. It is deliberately specific.
8.1 Intended purpose. The Service is intended and supplied for the analysis and improvement of a sales process at an organisational level — where deals stall, which stage transitions leak, how forecast quality develops. Individual sales representatives appear in the analysis because opportunities are owned by them, and results can be viewed for a level or member of the sales hierarchy.
8.2 Prohibited purpose. The Customer may not use the Service, or its output, as a basis for decisions about individual employees — in particular decisions on recruitment, promotion, remuneration, disciplinary measures, task allocation or termination — and may not use it for the systematic monitoring of individual employee behaviour or performance. The Customer will impose the same restriction on its own users.
8.3 Consequence under the EU Artificial Intelligence Act. Regulation (EU) 2024/1689 classifies AI systems intended to be used for the evaluation or monitoring of workers' performance and behaviour as high-risk (Annex III no. 4). metisora does not supply the Service for that purpose, and § 8.2 is a condition of use rather than a recommendation. A Customer that uses the Service for that purpose, or presents it to its workforce as serving that purpose, may itself become a provider of a high-risk AI system under Art. 25(1) of that Regulation and assume the corresponding obligations. The Customer will indemnify metisora on first demand against claims and penalties arising from a use in breach of § 8.2.
8.4 Works constitution and employee data protection. Where the Customer has a works council, the introduction and use of the Service may be subject to co-determination under § 87(1) no. 6 BetrVG, because the Service is objectively capable of being used to monitor performance, irrespective of metisora's intention. The Customer is responsible for obtaining any required co-determination, for the works agreement, and for informing the affected employees under Art. 13 or 14 GDPR. metisora will provide, on request and free of charge, the technical information the Customer needs for that purpose (Annex 1 and Annex 2 of the Data Processing Agreement, and a works-council information sheet where available).
8.5 AI-generated output. Parts of the Service generate text, findings and recommendations using a large language model operated by Anthropic (§ 12). The Customer acknowledges that:
a. such output is generated statistically and may be incomplete, imprecise or wrong, even where it reads as confident and is accompanied by figures; b. every output is labelled in the interface as AI-generated; c. the output must be reviewed by a competent person before it is relied upon, and must not be the sole basis for a commercially significant decision; d. metisora computes the figures shown alongside the narrative itself and constrains the model to the data provided, but gives no warranty that the narrative is factually correct (§ 16.4); e. metisora does not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
8.6 AI literacy. The Customer will ensure that its users have a sufficient level of AI literacy in accordance with Art. 4 of Regulation (EU) 2024/1689. metisora supports this with the product documentation and, on request, a briefing.
8.7 No training on Customer Data. metisora does not use Customer Data to train, fine-tune or improve any machine-learning model, whether its own or a third party's, and has contracted with its AI sub-processor on the same basis. Aggregated, irreversibly anonymised statistics may be used as set out in § 15.4.
9. Fees, invoicing and payment
9.1 The fee follows from the plan booked, as communicated before acceptance or as stated in the order confirmation.
Value added tax. All fees are net amounts and exclusive of value added tax, which is added at the applicable statutory rate and shown separately on the invoice. Where the Customer is established in another EU Member State and provides a valid VAT identification number, the reverse-charge procedure applies and metisora invoices without German VAT; the Customer is then responsible for accounting for the tax in its own Member State.
9.2 Billing period. Monthly plans are invoiced monthly in advance; annual plans are invoiced annually in advance. The first billing period begins on the day the Service is made available to the Customer.
9.3 Payment is due within 14 days of the invoice date without deduction, by bank transfer. Invoices are issued electronically; the Customer consents to electronic invoicing.
9.4 Default. On default, metisora is entitled to default interest at 9 percentage points above the base rate (§ 288(2) BGB) and to the lump sum under § 288(5) BGB. If the Customer is more than 30 days in default with a not insignificant amount, metisora may, after a warning in text form with a grace period of at least 10 days, suspend access to the Service until payment is made. Suspension does not reduce the fee and does not affect metisora's right to terminate for cause.
9.5 Fee adjustment. metisora may adjust the fees with effect from the start of a renewal period, with at least three months' notice in text form before the end of the current period. If the increase exceeds 10 % compared with the previous period, the Customer may terminate the contract with effect from the date the increase takes effect, by notice in text form received within one month of receipt of the notification. metisora will point out this right in the notification.
9.6 Set-off and retention. The Customer may set off only against claims that are undisputed or have been finally determined by a court, and may exercise a right of retention only in respect of claims arising from the same contractual relationship.
10. Term and termination
10.1 Term. The contract runs for the term booked — one month or twelve months — and renews automatically for successive periods of the same length unless terminated.
10.2 Ordinary termination. A monthly contract may be terminated by either party with 14 days' notice to the end of the month. An annual contract may be terminated by either party with one month's notice to the end of the term. Notice must be given in text form (e-mail is sufficient) or through the function provided in the Service.
10.3 Termination for cause by either party for good cause remains unaffected. Good cause exists for metisora in particular where the Customer (a) is in default of a not insignificant payment after a warning and grace period under § 9.4; (b) breaches § 7.3 or § 8.2 and does not remedy the breach after a warning; or (c) suffers the opening of insolvency proceedings over its assets or the rejection of such proceedings for lack of assets.
10.4 Effect of termination. On the effective date of termination, access to the Service ends. § 11 governs the Customer's data.
10.5 No refund of fees already paid for the current period, unless metisora is responsible for the termination.
11. Data on termination — export and deletion
Read this section together with § 3.3: metisora holds a copy of data whose original remains in the Customer's own Salesforce organisation.
11.1 Before the end of the contract, the Customer is responsible for securing any data it wishes to keep. Data extracted from Salesforce remains in the Customer's Salesforce organisation and is not affected by the end of this contract. Data created inside the Service — in particular Scope configurations, stage mappings, sales hierarchies, targets, weekly SPI snapshots and generated findings — exists only in the Service. metisora will, on request made before the deletion under § 11.3 and free of charge once, provide a machine-readable export of that data.
11.2 Deletion on request by the Customer. The Customer's administrator can close the organisation's account in the Service at any time. Closure triggers immediate and irreversible deletion; there is no waiting period, no automatic export and no undo. The Service states this before the action is confirmed. The Customer is responsible for requesting the export under § 11.1 first.
11.3 Deletion on termination. Unless the Customer requests earlier deletion, metisora deletes the Customer Data within 30 days of the end of the contract.
11.4 What deletion covers, and what survives it, is set out in Annex 1 § 8 of the Data Processing Agreement. In summary: all extracted Salesforce records and the change history kept from them, all Scope configurations and snapshots, all AI calls with their stored prompts and responses, the business profile, the Salesforce connection (whose refresh token metisora revokes at Salesforce) and all user accounts are deleted at once; copies remain in infrastructure backups for up to approximately four weeks and are then overwritten in the ordinary course; and metisora retains a minimal record that the deletion took place and who instructed it, as evidence under Art. 5(2) GDPR.
11.5 Return is not possible after deletion. A Customer who returns later is set up as a new organisation with no data.
12. Data protection
12.1 In respect of Customer Data, the Customer is the controller and metisora is the processor within the meaning of Art. 4 nos. 7 and 8 GDPR. The Data Processing Agreement at https://app.metisora.com/legal/dpa forms an integral part of this contract and is accepted together with these Terms (Art. 28(9) GDPR: electronic form).
12.2 In respect of the personal data metisora processes for its own purposes — the account data of the Customer's users, contract and billing data, and communications — metisora is the controller. The Privacy Policy at https://app.metisora.com/legal/privacy describes that processing.
12.3 metisora engages sub-processors, including providers established outside the European Economic Area. The current list, the purposes and the transfer safeguards are in Annex 3 of the Data Processing Agreement. The Customer grants general written authorisation for their engagement subject to the notification and objection procedure in § 6 of that Agreement.
13. Confidentiality
13.1 Each party will keep confidential all information of the other party that is marked as confidential or whose confidentiality is apparent from the circumstances ("Confidential Information"), use it only for the purposes of this contract, and disclose it only to those of its personnel and advisers who need it and who are bound to equivalent confidentiality.
13.2 The obligation does not apply to information that is or becomes publicly known without breach, was already lawfully known to the recipient, was independently developed, or must be disclosed by law or by order of a court or authority — in which case the recipient will, where permitted, inform the other party in advance.
13.3 The obligation survives the end of the contract by three years. For Customer Data it survives without time limit, alongside the Data Processing Agreement.
13.4 Reference. metisora may name the Customer and use its logo as a reference only with the Customer's prior consent in text form, which may be withdrawn for the future at any time.
14. Subcontractors and personnel
14.1 metisora may use subcontractors to provide the Service. metisora remains responsible for their performance as for its own. The engagement of sub-processors within the meaning of Art. 28(2) and (4) GDPR is governed exclusively by § 6 of the Data Processing Agreement.
14.2 metisora will ensure that every person it allows to process Customer Data is bound to confidentiality and is instructed in the applicable data protection requirements (Art. 28(3)(b), Art. 32(4) GDPR).
14.3 Access by metisora personnel. metisora personnel access Customer Data only where necessary to provide, support, secure or troubleshoot the Service, and only on a need-to-know basis. Annex 2 of the Data Processing Agreement describes the technical limits on that access.
15. Rights in the Service and in data
15.1 The Service remains metisora's. metisora and its licensors hold all rights in the Service, in its software, its design, its documentation and the SPI Score methodology. The Customer receives, for the term of the contract, a non-exclusive, non-transferable, non-sublicensable right to use the Service for its own internal business purposes within the booked plan. No further rights are granted.
15.2 Customer Data remains the Customer's. metisora receives only the right to process Customer Data as necessary to provide the Service and as instructed under the Data Processing Agreement.
15.3 Feedback. If the Customer provides suggestions for improving the Service, metisora may use them without restriction and without compensation. The Customer is not obliged to provide feedback.
15.4 Aggregated statistics. metisora may compile statistics about the use and performance of the Service across customers, and use them to operate, secure, benchmark and improve the Service. Such statistics are irreversibly anonymised, contain no personal data and no Customer Data, and do not permit the Customer or any of its personnel, accounts or deals to be identified or singled out.
16. Warranty
16.1 The provision of the Service against periodic payment is governed by the law of lease (§§ 535 ff. BGB). The strict liability for defects existing at the time of conclusion of the contract under § 536a(1) alt. 1 BGB is excluded.
16.2 The Customer will notify metisora of defects without undue delay in text form, with a description sufficient to reproduce them.
16.3 A defect is a deviation of the Service from the functional scope described in § 3.2 that is more than insignificant. Not a defect: an impairment caused by the Customer's own environment, by the Customer's Salesforce organisation or its configuration, by the Customer's use contrary to this contract, or by a third-party service outside metisora's control.
16.4 AI output is expressly not warranted to be correct. metisora warrants that the AI functions operate, not that a generated narrative, finding or recommendation is accurate, complete or fit for a particular decision (§ 8.5). The metrics and figures computed by metisora itself are not covered by this exclusion.
16.5 For free trial or evaluation access, metisora is liable only in accordance with § 17.1 and § 17.2; there is no warranty.
17. Liability
17.1 metisora is liable without limitation for damage arising from injury to life, body or health; for damage caused intentionally or by gross negligence; under the Product Liability Act; in the case of fraudulent concealment of a defect; and to the extent metisora has given a guarantee.
17.2 In the case of slight negligence, metisora is liable only for the breach of a material contractual obligation — an obligation whose fulfilment makes the proper performance of the contract possible in the first place and on whose fulfilment the Customer may regularly rely. In that case liability is limited to the damage typical for this type of contract and foreseeable at the time of conclusion.
17.3 Cap. Liability under § 17.2 is limited in the aggregate, per contract year, to the fees paid by the Customer in the twelve months preceding the event giving rise to the claim, and in any case to not less than the annual fee for the plan booked at the time of the event. Where the Customer pays monthly, the annual fee is twelve times the monthly fee.
17.4 Loss of data. Liability for loss of data is limited to the effort typically required to restore it from backups that the Customer maintains in accordance with proper data processing. § 3.3 applies: the Customer's Salesforce organisation is the source of truth for the data extracted from it.
17.5 Any further liability is excluded. The limitations in §§ 17.2 to 17.4 apply equally in favour of metisora's legal representatives, employees, agents and vicarious agents.
17.6 Limitation period. Claims of the Customer for damages become time-barred twelve months after the statutory start of the limitation period, except in the cases of § 17.1, where the statutory periods apply.
17.7 Data protection claims. Liability under Art. 82 GDPR towards data subjects is governed by that provision and is not limited by this § 17. As between the parties, Art. 82(5) GDPR applies: each party bears the share of any compensation corresponding to its share of responsibility for the damage. § 11 of the Data Processing Agreement supplements this.
18. Indemnity for third-party claims
18.1 The Customer will indemnify metisora on first demand against all claims third parties — including employees, works councils, data subjects and authorities — assert against metisora arising from the Customer's breach of § 7.2, § 7.4, § 8.2 or § 8.4, including reasonable costs of legal defence, unless the Customer is not responsible for the breach.
18.2 metisora will notify the Customer of any such claim without undue delay, give the Customer the opportunity to defend it, and will not acknowledge or settle it without the Customer's consent, which may not be unreasonably withheld.
19. Force majeure
Neither party is in breach to the extent that performance is prevented by an event outside its reasonable control — in particular natural disasters, war, terrorism, labour disputes not affecting the party's own workforce, epidemics and pandemics and official measures taken in response to them, failures of the public power or telecommunications network, and large-scale failures of upstream providers. The affected party will notify the other without undue delay. If the event lasts longer than two months, either party may terminate the contract for cause.
20. Changes to these Terms
20.1 metisora may amend these Terms where the amendment is necessary to reflect a change in the law or in the case law, to close a gap that has become apparent, or to account for a change in the Service that does not materially reduce the agreed functional scope or increase the fee, and where the amendment does not disturb the balance of the contract to the Customer's disadvantage.
20.2 metisora will notify the Customer of the amendment in text form at least six weeks before it takes effect, and will point out the objection right and the consequence of silence. If the Customer does not object in text form before the amendment takes effect, the amendment is deemed accepted. If the Customer objects, the contract continues on the previous terms; metisora may in that case terminate the contract to the end of the then current period.
20.3 Amendments to the fee are governed exclusively by § 9.5. Amendments that materially reduce the agreed functional scope require the Customer's express consent.
21. Final provisions
21.1 Text form. Amendments and supplements to the contract require text form. This also applies to any waiver of the text-form requirement. Individual agreements made in a particular case take precedence (§ 305b BGB).
21.2 Assignment. The Customer may transfer the contract to a third party only with metisora's prior consent in text form, which may not be unreasonably withheld. metisora may transfer the contract to an affiliate or to an acquirer of the business to which the contract relates; the Customer may terminate the contract within one month of notification if it does not wish the transfer to apply to it.
21.3 Governing law. The contract is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods and excluding the conflict-of-laws rules. Mandatory provisions of the law of the state in which the Customer has its seat remain unaffected.
21.4 Place of jurisdiction. The place of jurisdiction for all disputes arising from or in connection with this contract is Ingolstadt, Germany, to the extent an agreement on jurisdiction is permissible between the parties under § 38 ZPO. Otherwise the statutory places of jurisdiction apply. metisora is also entitled to sue at the Customer's general place of jurisdiction.
21.5 Language. The contractual language is German. The German version of these Terms is the sole authoritative text. This English version is provided for convenience and is not binding; in the event of any discrepancy, the German wording governs.
21.6 Severability. Should a provision of these Terms be or become invalid or unenforceable, the validity of the remaining provisions is unaffected. The parties will replace the invalid provision with a valid one that comes closest to its economic purpose.
metisora — General Terms and Conditions, version 2.0, 29 September 2026.