Skip to content
CertMapCertMap

General Terms and Conditions (General Part)

As of: 2026-09-12Version 2.3

This document as PDF

Sec. 1 Scope and Structure

(1) These General Terms and Conditions (hereinafter "GTC") apply to the use of the CertMap platform and all services offered through it by Threat-Informed Cybersecurity Solutions GmbH (hereinafter the "Provider") by users and customers.

(2) The GTC consist of this general part and special terms for individual services. The module "CertMap for Organizations" is governed by the Special Terms for Organizations. In case of conflict, special terms take precedence over the general part; an individual offer in text form takes precedence over both. The processing of personal data on behalf of a customer is governed primarily by the data processing agreement.

(3) A consumer within the meaning of these GTC is any natural person who enters into a legal transaction for purposes that are predominantly outside their trade, business or profession (Sec. 13 BGB). An entrepreneur within the meaning of these GTC is a natural or legal person or a partnership with legal capacity who, when entering into a legal transaction, acts in the exercise of their trade, business or profession (Sec. 14 BGB).

(4) Deviating, conflicting or supplementary general terms and conditions of the customer become part of the contract only if and to the extent that the Provider has expressly agreed to their application in text form. This consent requirement also applies if the Provider performs services without reservation while aware of the customer's terms.

Sec. 2 Contractual Partner, Contact Details

(1) The contractual partner of users and customers is:

Threat-Informed Cybersecurity Solutions GmbH
Ober-Saulheimer Str. 15
55291 Saulheim
Germany

Commercial register: Amtsgericht Mainz, HRB 53346
VAT ID: DE 450829291
Represented by the managing director Daniel Thomas Heessel

Email: kontakt@certmap.de

(2) Further provider information is available in the imprint.

Sec. 3 Platform Services

(1) CertMap provides free tools for comparing and classifying IT certifications without registration, in particular the certification catalog, the comparison, the portfolio and editorial knowledge articles. These contents inform and classify. They are not legal, tax, career or investment advice and do not replace individual advice.

(2) Information on certifications (in particular prices, validity periods, prerequisites, continuing education requirements) is taken from public sources of the respective certification providers and is maintained to the best of our knowledge. Every certification links to the provider page; for a growing share of the individual data points we additionally keep the verbatim quote of the source with the date it was retrieved. Certification programs change continuously. The Provider does not guarantee the accuracy, completeness or currency of this information; only the conditions of the respective certification provider are binding.

(3) With a free account (Sec. 4), users can save comparisons and portfolios, record their own certifications along with data such as certificate number, issue and expiry date and continuing education activities, keep their expiry in view and link their account to an organization (Sec. 5). There is no storage for uploaded evidence files; certificate PDFs are read but not retained (privacy policy, Section 5).

(4) The module "CertMap for Organizations" is aimed at companies and institutions and is provided under the Special Terms for Organizations.

(5) Editorial recommendations by the Provider are not for sale. Paid placements by training providers are labelled as advertisements; they have no influence on editorial ratings, classifications or the order outside the labelled area.

(6) The Provider may develop, change, restrict or discontinue free services. If this affects data stored in an account, the Provider informs account holders in text form with reasonable notice; until then the stored data can be downloaded via the data export in the account.

Sec. 4 Account

(1) An account is created with an email address. Login is by one-time code sent by email; there is no password. One account per person is intended; the details provided must be accurate.

(2) The contract for the free use of the account is concluded upon completion of registration. The Provider refers to these GTC and the privacy policy before registration.

(3) One-time codes and access to the email mailbox must be kept secret. Any suspected misuse of the account must be reported to the Provider without delay.

(4) Users can delete their account at any time in the settings or in text form. Upon deletion, the stored data is removed in accordance with the privacy policy.

(5) The Provider may suspend or terminate an account for cause if it is used abusively, unlawfully or contrary to Sec. 6. The Provider may also terminate a free account with four weeks' notice in text form; stored data can be downloaded until the termination takes effect.

(6) If a consumer has a right of withdrawal for the contract on the free account, the cancellation policy in Annex A applies. Withdrawal can also be declared by deleting the account within the withdrawal period.

Sec. 5 Linking with an Organization

(1) An account can be linked, by invitation, to an organization that uses CertMap for Organizations. Linking is voluntary. The account holder decides for each certification whether and what becomes visible to the organization and can end any release and the link as a whole at any time, including while the organization only has read-only access.

(2) The account remains the property of the account holder. The deletion of an organization does not affect the account or the certifications recorded in it.

(3) For data an organization records itself about its employees, the organization is the controller under data protection law; the Provider processes it on the organization's behalf. For the account, the Provider remains the controller (privacy policy).

Sec. 6 Rights of Use and Obligations

(1) The certification catalog, the editorial content, graphics and software of CertMap are protected by copyright. Use is permitted for personal information and for own purposes. Not permitted are the systematic reproduction or extraction of content, automated bulk queries, the circumvention of technical protection measures and the use of the content for competing databases. Short quotations with source reference remain permitted.

(2) Content that users record in their account (in particular certification data and continuing education activities) remains their property. They grant the Provider the right to process this content in order to provide the services. They ensure that they are entitled to record it and do not enter unlawful content or third-party data without authorization.

(3) The Provider may use corrections and feedback on content to improve the platform without remuneration.

Sec. 7 Availability

(1) No specific availability is guaranteed for free services. The Provider strives for high availability and announces planned maintenance where possible.

(2) Availability and support for paid services are governed by the respective special terms.

Sec. 8 Liability

(1) The contents of CertMap are information and orientation aids based on the information available at the time. The Provider provides no guarantee for the occurrence of specific career, certification or remuneration outcomes that users derive from the contents.

(2) The Provider is liable without limitation for intent and gross negligence as well as for damage arising from injury to life, body or health resulting from a breach of duty by the Provider, a legal representative or a vicarious agent.

(3) In the event of simple negligence, the Provider is only liable for damage arising from the breach of essential contractual obligations (so-called cardinal obligations). Essential contractual obligations are those obligations whose fulfilment is a prerequisite for the proper performance of the contract in the first place and on whose compliance the contractual partner regularly relies. In such case, the Provider's liability is limited to the foreseeable damage typical for the contract.

(4) Otherwise, the Provider's liability for simple negligence is excluded. For services provided free of charge, the Provider is liable only under paragraph 2, to the extent permitted by law.

(5) Liability of the Provider under the German Product Liability Act and from guarantees assumed remains unaffected by the foregoing limitations.

(6) The Provider is not liable for failures, delays or defects caused by third-party providers used for the performance of the services (in particular hosting and email delivery) or by the user's internet connection and systems, provided the Provider has selected and supervised these third-party providers with the care required.

(7) For clarification: within the limitation of liability under paragraph 3, consequential damages, damages from data loss on the customer's side, damages from compromised or insecure customer IT systems and damages from third-party cyberattacks on customer systems are generally not foreseeable for the contract type and are therefore excluded from liability. This does not apply in cases of intent or gross negligence by the Provider, nor for damage arising from injury to life, body or health.

(8) Monetary caps on liability towards entrepreneurs for paid services are governed by the respective special terms. No monetary cap applies towards consumers.

Sec. 9 Data Protection

(1) Information on the processing of personal data when using CertMap is contained in the privacy policy.

(2) Data that organizations process about their employees in the module "CertMap for Organizations" is governed by the data processing agreement.

Sec. 10 Consumer Dispute Resolution

(1) The Provider is neither obliged nor willing to participate in a dispute resolution procedure before a consumer arbitration board within the meaning of the German Consumer Dispute Resolution Act (VSBG) (Sec. 36(1) No. 1 VSBG).

(2) A reference to the European Commission's ODR platform is omitted, as the underlying Regulation (EU) No 524/2013 (ODR Regulation) was repealed by Regulation (EU) 2024/3228 of 19 December 2024 with effect from 20 July 2025. The information obligation under Sec. 36 VSBG remains unaffected and is covered by paragraph 1.

Sec. 11 Applicable Law and Jurisdiction

(1) All legal relations between the Provider and the customer are governed exclusively by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).

(2) For consumers, this choice of law applies only to the extent that the protection granted to the consumer is not withdrawn by mandatory provisions of the law of the country in which the consumer has their habitual residence (Art. 6(2) Rome I Regulation).

(3) For actions brought by the consumer against the Provider as well as for actions brought by the Provider against the consumer, the statutory places of jurisdiction apply. In particular, the consumer may sue the Provider at the Provider's seat (Saulheim, Rhineland-Palatinate) or at the consumer's own place of residence.

(4) If the customer is an entrepreneur, a legal entity under public law or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from or in connection with the contractual relationship is the Provider's seat in 55291 Saulheim, Rhineland-Palatinate. The Provider is also entitled to sue the customer at the customer's general place of jurisdiction.

Sec. 12 Amendments to these GTC

(1) Amendments to these GTC do not become effective for existing customers for contracts already concluded without their express consent. A unilateral amendment of the GTC by the Provider with a fiction of consent is excluded. For future contracts, the version published at the time of conclusion of the contract applies.

(2) For free accounts, the Provider announces planned amendments in text form at least six weeks before they take effect. Account holders may consent or delete their account. Without consent, the Provider may terminate the free account under Sec. 4(5) as of the date the amendment takes effect.

(3) Amendments for paid services are governed by the respective special terms.

Sec. 13 Final Provisions

(1) Should individual provisions of these GTC be or become wholly or partially invalid, void or unenforceable, the validity of the remaining provisions remains unaffected. The respective statutory provision replaces the invalid, void or unenforceable provision.

(2) Declarations in connection with the contractual relationship (in particular withdrawal, termination, complaints) may be made in text form by email to kontakt@certmap.de. To the extent that the law prescribes the written form, this requirement remains unaffected.

(3) Version of these GTC: 12 September 2026, Version 2.3.

The annexes are part of this document. Expand to read; each annex is also available as a PDF download.

Annex A: Cancellation Policy

Right of withdrawal

You have the right to withdraw from the contract on your CertMap account within 14 days without giving any reason.

The withdrawal period is 14 days from the day of conclusion of the contract, that is, from the day you completed registration.

To exercise the right of withdrawal, you must inform us

Threat-Informed Cybersecurity Solutions GmbH
Ober-Saulheimer Str. 15
55291 Saulheim
Germany
Email: kontakt@certmap.de

of your decision to withdraw from this contract by an unequivocal statement (e.g. a letter sent by post or an email). You may use the attached model withdrawal form, but it is not obligatory. You may also declare the withdrawal by deleting your account in the settings within the withdrawal period.

To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.

Effects of withdrawal

If you withdraw from this contract, the use of the account ends. Since no fee was paid for the account, there is nothing to refund. The data stored in the account is deleted in accordance with the privacy policy; until deletion you can download it via the data export in the account.

Download as PDF
Annex B: Model Withdrawal Form

(If you wish to withdraw from the contract, please complete and return this form.)

To:

Threat-Informed Cybersecurity Solutions GmbH
Ober-Saulheimer Str. 15
55291 Saulheim
Germany
Email: kontakt@certmap.de

I/We () hereby withdraw from the contract concluded by me/us () on the use of my/our (*) CertMap account.

Registered on (*): ____________________

Email address of the account: ____________________

Name of consumer(s): ____________________

Address of consumer(s): ____________________

Signature of consumer(s) (only if this form is notified on paper): ____________________

Date: ____________________

(*) Delete as appropriate.

Download as PDF