ROSTECH GmbH
Legal
Terms of service, privacy statement and legal notice for ROSTECH GmbH and for Resonate, our managed configuration-assurance service.
01 · Terms
Terms of Service
Last updated: 31 July 2026
Provider
Resonate is a managed configuration-assurance service operated by ROSTECH GmbH, Hallerstrasse 133, 6020 Innsbruck, Austria. Company registration FN 658967w, VAT ID ATU82398727.
Contractual basis
Access to Resonate is provided under a service agreement with ROSTECH GmbH and is governed by our Allgemeine Geschäftsbedingungen (AGB). Where these Terms and the AGB conflict, the order confirmation and the AGB prevail, in the order set out in AGB §15.10. The German AGB is the binding version; this page is an English-language summary for reference.
Allgemeine GeschäftsbedingungenLicence grant
ROSTECH GmbH grants the customer a non-exclusive, non-transferable, revocable licence to access and use Resonate solely for auditing IT security findings and tracking measures to mitigate them, subject to these Terms.
Restrictions
Users of Resonate may not:
- copy, modify, or create derivative works of the application;
- reverse engineer, decompile, or disassemble any part of the application;
- export, reproduce, or redistribute content made available through the application — including security findings, mitigation guidance, remediation scripts and audit data — outside the application or to any unauthorised third party without prior written consent;
- use the application for any unlawful or unauthorised purpose;
- interfere with the functionality of the application in unintended ways.
Customer responsibilities
The customer is responsible for maintaining the confidentiality of login credentials, for ensuring that their use of the application complies with applicable law, and for testing any executable, command or script suggested by the application in a non-production environment before running it in production (AGB §1.8).
Nature of the service
Findings, analyses and reports produced by Resonate are point-in-time assessments; the underlying environment can change at any time and with it the assessment (AGB §9.3).
ROSTECH owes best efforts, not a specific result (AGB §1.6). Complete IT security cannot be guaranteed by any technical means (AGB §9.2). ROSTECH issues recommendations; decision-making authority and responsibility remain with the customer.
Warranty, liability, intellectual property
As set out in AGB §§9, 10 and 11. In particular: the application is provided without warranty that it will be uninterrupted or error-free; liability for slight negligence is excluded except for personal injury; and liability is capped at the order value.
Governing law
Austrian law applies, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Place of jurisdiction is the court competent for the registered seat of ROSTECH GmbH (AGB §15).
Sign-in with Microsoft Entra ID. The Resonate application registration requests only openid, profile, email and User.Read. It requests no permission to read your directory. Directory and configuration data is collected separately, by a collector you deploy and control in your own environment.
02 · Privacy
Privacy Statement
Last updated: 31 July 2026
1. Two distinct roles
For the personal data of users of the Resonate application — name, business email address, user principal name, directory object ID, sign-in and audit events — ROSTECH GmbH acts as controller.
For the configuration and directory data of the customer environment that Resonate collects and analyses, ROSTECH GmbH acts as processor on behalf of the customer, under a data processing agreement pursuant to Art 28 GDPR (AGB §12.1).
2. Data processed as controller
| Data | Purpose | Legal basis |
|---|---|---|
| Contact data name, address, email |
Required to use the application; collected when a user account is created. | Art 6(1)(b), (c) |
| Billing data name, address, VAT ID, payment method |
Processed to meet accounting and tax obligations. | Art 6(1)(c) |
| Technical data IP address, browser, operating system, request time |
Required to serve the application correctly and to detect, prevent and investigate attacks against it. | Art 6(1)(f) |
| Email address | Used to send notifications, for example when a security-relevant condition is detected. | Art 6(1)(b) |
Signing in via Microsoft Entra ID discloses your name, email address or user principal name and your directory object ID to Resonate. No directory-read permission is requested.
3. Data processed as processor
To perform configuration assessment, Resonate processes data collected from the customer environment. Depending on the assessment scope this may include:
- account, group, computer and service-principal objects and their attributes;
- group memberships and privileged-role assignments;
- access control lists and delegations;
- Group Policy objects and their settings;
- certificate templates and public-key-infrastructure configuration;
- vulnerability-scan results.
Passwords are not collected in cleartext. This data is processed solely on the customer's documented instructions and exclusively to produce the assessment results, attack-path analyses and reports the customer has commissioned. It is not used for any other purpose, is not aggregated across customers, and is not used to train any model.
4. Hosting and location
All customer data is stored and processed exclusively on infrastructure operated by ROSTECH GmbH in Austria. No customer data is transferred to a third country outside the European Union.
5. Sub-processors
ROSTECH GmbH engages no sub-processor that stores or has access to customer assessment data. All such data remains on ROSTECH-operated infrastructure in Austria.
Microsoft Entra ID is used for user authentication, and Microsoft Azure Application Proxy for secure publishing of the application. These services process connection and authentication metadata in the course of establishing a session; they do not store assessment or directory data collected by Resonate.
6. Retention
Customer assessment data is retained for 360 days and deleted thereafter. This covers check results, collected configuration data, vulnerability-scan results, attack-path analyses and generated reports.
Account and billing data is retained for as long as required by statutory retention periods, in particular seven years under §132(1) BAO and §§190, 212 UGB, and for as long as necessary to assert or defend legal claims.
7. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. Requests concerning data described in section 3 should be addressed to the customer as controller; ROSTECH will assist pursuant to Art 28(3)(e) GDPR.
You may lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
8. Data security
Personal data is protected by appropriate organisational and technical measures against unauthorised, unlawful or accidental access, loss, processing, use and manipulation.
9. Underlying German documents
The binding German-language privacy declarations are available below. In case of conflict the German versions prevail.
Datenschutzerklärung — ROSTECH GmbHrostech.at itself sets no cookies and runs no analytics or tracking. This is a read-only website; no personal data is collected when you visit it.
03 · Imprint
Imprint & Legal Notice
Media owner and publisher
ROSTECH GmbH
Hallerstrasse 133, 6020 Innsbruck, Austria
Company registration: FN 658967w
VAT ID: ATU82398727
Business purpose: IT security consulting and services
Copyright & liability
Copyright: all content on this website is protected by copyright. Reproduction or use without express written permission is not permitted.
Liability: the information provided here is for general informational purposes only. No liability is assumed for accuracy or completeness, nor for content accessible via external links.
Online dispute resolution
The European Commission provides a platform for online dispute resolution at ec.europa.eu/consumers/odr (Art 14(1) ODR Regulation).
04 · Contact
Contact
ROSTECH GmbH
Hallerstrasse 133, 6020 Innsbruck, Austria
Business hours: Mon–Thu 09:00–19:00, Fri 09:00–13:00
Written enquiries should be sent to support@rostech.at (AGB §13.7).