Skip to content

ROSTECH GmbH

Legal

Terms of service, privacy statement and legal notice for ROSTECH GmbH and for Resonate, our managed configuration-assurance service.

01 · Terms

Terms of Service

Last updated: 31 July 2026

Provider

Resonate is a managed configuration-assurance service operated by ROSTECH GmbH, Hallerstrasse 133, 6020 Innsbruck, Austria. Company registration FN 658967w, VAT ID ATU82398727.

Contractual basis

Access to Resonate is provided under a service agreement with ROSTECH GmbH and is governed by our Allgemeine Geschäftsbedingungen (AGB). Where these Terms and the AGB conflict, the order confirmation and the AGB prevail, in the order set out in AGB §15.10. The German AGB is the binding version; this page is an English-language summary for reference.

Allgemeine Geschäftsbedingungen

Licence grant

ROSTECH GmbH grants the customer a non-exclusive, non-transferable, revocable licence to access and use Resonate solely for auditing IT security findings and tracking measures to mitigate them, subject to these Terms.

Restrictions

Users of Resonate may not:

  • copy, modify, or create derivative works of the application;
  • reverse engineer, decompile, or disassemble any part of the application;
  • export, reproduce, or redistribute content made available through the application — including security findings, mitigation guidance, remediation scripts and audit data — outside the application or to any unauthorised third party without prior written consent;
  • use the application for any unlawful or unauthorised purpose;
  • interfere with the functionality of the application in unintended ways.

Customer responsibilities

The customer is responsible for maintaining the confidentiality of login credentials, for ensuring that their use of the application complies with applicable law, and for testing any executable, command or script suggested by the application in a non-production environment before running it in production (AGB §1.8).

Nature of the service

Findings, analyses and reports produced by Resonate are point-in-time assessments; the underlying environment can change at any time and with it the assessment (AGB §9.3).

ROSTECH owes best efforts, not a specific result (AGB §1.6). Complete IT security cannot be guaranteed by any technical means (AGB §9.2). ROSTECH issues recommendations; decision-making authority and responsibility remain with the customer.

Warranty, liability, intellectual property

As set out in AGB §§9, 10 and 11. In particular: the application is provided without warranty that it will be uninterrupted or error-free; liability for slight negligence is excluded except for personal injury; and liability is capped at the order value.

Governing law

Austrian law applies, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Place of jurisdiction is the court competent for the registered seat of ROSTECH GmbH (AGB §15).

Sign-in with Microsoft Entra ID. The Resonate application registration requests only openid, profile, email and User.Read. It requests no permission to read your directory. Directory and configuration data is collected separately, by a collector you deploy and control in your own environment.

02 · Privacy

Privacy Statement

Last updated: 31 July 2026

1. Two distinct roles

For the personal data of users of the Resonate application — name, business email address, user principal name, directory object ID, sign-in and audit events — ROSTECH GmbH acts as controller.

For the configuration and directory data of the customer environment that Resonate collects and analyses, ROSTECH GmbH acts as processor on behalf of the customer, under a data processing agreement pursuant to Art 28 GDPR (AGB §12.1).

2. Data processed as controller

DataPurposeLegal basis
Contact data
name, address, email
Required to use the application; collected when a user account is created. Art 6(1)(b), (c)
Billing data
name, address, VAT ID, payment method
Processed to meet accounting and tax obligations. Art 6(1)(c)
Technical data
IP address, browser, operating system, request time
Required to serve the application correctly and to detect, prevent and investigate attacks against it. Art 6(1)(f)
Email address Used to send notifications, for example when a security-relevant condition is detected. Art 6(1)(b)

Signing in via Microsoft Entra ID discloses your name, email address or user principal name and your directory object ID to Resonate. No directory-read permission is requested.

3. Data processed as processor

To perform configuration assessment, Resonate processes data collected from the customer environment. Depending on the assessment scope this may include:

  • account, group, computer and service-principal objects and their attributes;
  • group memberships and privileged-role assignments;
  • access control lists and delegations;
  • Group Policy objects and their settings;
  • certificate templates and public-key-infrastructure configuration;
  • vulnerability-scan results.

Passwords are not collected in cleartext. This data is processed solely on the customer's documented instructions and exclusively to produce the assessment results, attack-path analyses and reports the customer has commissioned. It is not used for any other purpose, is not aggregated across customers, and is not used to train any model.

4. Hosting and location

All customer data is stored and processed exclusively on infrastructure operated by ROSTECH GmbH in Austria. No customer data is transferred to a third country outside the European Union.

5. Sub-processors

ROSTECH GmbH engages no sub-processor that stores or has access to customer assessment data. All such data remains on ROSTECH-operated infrastructure in Austria.

Microsoft Entra ID is used for user authentication, and Microsoft Azure Application Proxy for secure publishing of the application. These services process connection and authentication metadata in the course of establishing a session; they do not store assessment or directory data collected by Resonate.

6. Retention

Customer assessment data is retained for 360 days and deleted thereafter. This covers check results, collected configuration data, vulnerability-scan results, attack-path analyses and generated reports.

Account and billing data is retained for as long as required by statutory retention periods, in particular seven years under §132(1) BAO and §§190, 212 UGB, and for as long as necessary to assert or defend legal claims.

7. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. Requests concerning data described in section 3 should be addressed to the customer as controller; ROSTECH will assist pursuant to Art 28(3)(e) GDPR.

You may lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

8. Data security

Personal data is protected by appropriate organisational and technical measures against unauthorised, unlawful or accidental access, loss, processing, use and manipulation.

9. Underlying German documents

The binding German-language privacy declarations are available below. In case of conflict the German versions prevail.

Datenschutzerklärung — ROSTECH GmbH

rostech.at itself sets no cookies and runs no analytics or tracking. This is a read-only website; no personal data is collected when you visit it.

03 · Imprint

Imprint & Legal Notice

Media owner and publisher

ROSTECH GmbH

Hallerstrasse 133, 6020 Innsbruck, Austria

Company registration: FN 658967w

VAT ID: ATU82398727

Business purpose: IT security consulting and services

Copyright & liability

Copyright: all content on this website is protected by copyright. Reproduction or use without express written permission is not permitted.

Liability: the information provided here is for general informational purposes only. No liability is assumed for accuracy or completeness, nor for content accessible via external links.

Online dispute resolution

The European Commission provides a platform for online dispute resolution at ec.europa.eu/consumers/odr (Art 14(1) ODR Regulation).

04 · Contact

Contact

ROSTECH GmbH

Hallerstrasse 133, 6020 Innsbruck, Austria

support@rostech.at

Business hours: Mon–Thu 09:00–19:00, Fri 09:00–13:00

Written enquiries should be sent to support@rostech.at (AGB §13.7).