Back to Login

meddevo eIFU Platform - Terms of Use

Last updated: 20.08.2025

Initial Information

Terms of Use ("Terms") of dytab GmbH SaaS Solutions ("dytab" or "Provider").

dytab reserves the right to update and modify these Terms at any time. When updates are made, dytab will notify its customers and update the date at the top of this page. By using the eIFU Platform after publication of a new version, the Customer agrees to accept the new Terms.

"Hosted Services" means dytab SaaS with its solutions and features, including the meddevo eTD and the eIFU Platform.

"Platform" means the platform managed by Provider and used by Provider to provide the Hosted Services, including the application and database software, the system and server software used to provide the Hosted Services, and the computer hardware on which such software is installed.

Services

The Provider shall provide the Customer with access credentials enabling access and use of the Hosted Services.

Provider grants to Customer a worldwide, non-exclusive license to use the Hosted Services through the User Interface and the API for Customer's business purposes during the Term in accordance with the Documentation.

The license is subject to the following limitations:

  • The User Interface may only be used through a supported web browser or mobile application.
  • The User Interface may only be used by Customer's officers, employees, or affiliates.
  • Access is limited to named users in the Platform's user management.
  • The number of users is limited to the Cloud User Management allocation (fair use applies).
  • The API may only be used by applications approved in writing by Provider and controlled by Customer.

Customer shall not sublicense, allow unauthorized access, alter the Platform, perform load or penetration tests, or misuse the Platform in any unlawful or harmful manner.

For the eIFU Platform specifically, Customer acknowledges that:

  • The Customer is responsible for the accuracy, regulatory compliance, and legal sufficiency of uploaded eIFUs and documents.
  • The Platform supports product data, document handling and multilingual access, but final compliance responsibility remains with the Customer.

Scheduled Maintenance

Provider may suspend Hosted Services for scheduled maintenance, with at least 5 Business Days' notice.

Maintenance will be performed outside Business Hours (07:00–20:00 CET) and shall not exceed 8 hours per month.

Support Service

Provider shall provide technical support via E-Mail or the integrated help desk during the Usage Period depending on the subscription plan. Support includes assistance with system use and troubleshooting, but does not include regulatory consulting.

Customer Data

Customer grants Provider a non-exclusive license to process Customer Data only as required to perform Hosted Services. Provider shall perform incremental back ups of the Cloud System at least every 24 hours, with retention for 30 days.

Customer remains responsible for regulatory content of documents, including correctness, labeling, availability of paper IFUs when required, and timely updates.

Imprint / Legal Notice

The Platform provides the Customer with the technical option to include a clearly labeled link ("Imprint" or "Legal Notice") on any public-facing pages generated through the Platform. This link must lead directly to the Customer's imprint (legal notice) hosted on the Customer's own primary website.

The Customer is solely responsible for ensuring that such imprint (legal notice) complies with all applicable legal requirements, including but not limited to accessibility, completeness, accuracy, and availability under the laws of the jurisdictions in which the Customer offers its products or services.

The Provider assumes no responsibility or liability for the content, correctness, or legal sufficiency of the Customer's imprint (legal notice), or for any failure by the Customer to provide or maintain a valid link to such imprint.

No Assignment of Intellectual Property Rights

Except as otherwise agreed, no IP rights are transferred between Provider and Customer under these Terms.

Payment

Invoices will be issued in advance for each service period. Payments are due within the term specified in the invoice.

Confidentiality

Provider will keep Customer's confidential information secure and confidential, using at least reasonable care, and shall not disclose it to unauthorized third parties. Exceptions apply where disclosure is legally required.

Data Protection

Each party shall comply with applicable data protection laws, including GDPR. A Data Processing Agreement (DPA) under Art. 28 GDPR forms part of these Terms.

Warranties

Provider warrants that:

  • It has the right and authority to provide Hosted Services.
  • The Hosted Services meet applicable specifications and are free from known malware.
  • Security measures are in line with good industry practice.
  • The Platform supports compliance with eIFU regulations, but regulatory responsibility lies with the Customer.

Customer warrants that:

  • It has rights to use and distribute the content provided.

Acknowledgements and Warranty Limitations

Customer acknowledges that:

  • Complex software may contain defects or vulnerabilities.
  • Provider does not guarantee uninterrupted service availability.
  • Provider does not provide legal advice.

Limitations and Exclusions of Liability / Force Majeure

Provider's liability is excluded for indirect damages, loss of profits, or force majeure events, except for cases of gross negligence, willful misconduct, or liability that cannot be excluded under German law.

General

If any provision is held unenforceable, the remainder shall remain in force. German law applies. Jurisdiction is the domicile of the Provider.

Service Particulars – eIFU Platform

  • The eIFU Platform enables manufacturers to provide electronic instructions for use in compliance with EU MDR/IVDR and (EU) 2021/2226.
  • Provider ensures system validation according to ISO/TR 80002-2:2017.
  • Records are archived for at least 20 years to meet regulatory retention requirements.
  • Cloud Security standards: ISO/IEC 27001:2013, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 9001:2015.

Acceptable Use Policy

Introduction

This Acceptable Use Policy (the "Policy") sets out the rules that apply to you:

  • the use of the website at app.meddevo-cloud.com, any successor website and the services available on this website or any successor website (the "Services"); and
  • the transmission, storage and processing of content by you or anyone on your behalf using the Services ("Content").

References in this policy to "you" are to any customer of the Services and any individual user of the Services (and "your" should be construed accordingly); and references in this policy to "us" are to meddevo (and "we" and "our" should be construed accordingly).

General Rules of Use

You must not use the Services in any way that causes or is likely to cause damage to the Services or impair the availability or accessibility of the Services.

You may not use the Services:

  • in any way that is unlawful, illegal, fraudulent, deceptive or harmful; or
  • in connection with any unlawful, illegal, fraudulent, deceptive or harmful purpose or activity.

You must ensure that all Content complies with this Policy.

Illegal Content

Content must not be illegal or unlawful, violate the rights of any person or give rise to any legal action against any person (in each case in any jurisdiction and under any applicable law).

The Content, and our use of the Content in any manner licensed or otherwise authorized by you, must not:

  • be defamatory or maliciously false
  • be obscene or indecent;
  • infringe any copyright, moral right, database right, trade mark right, right of publicity, right of passing off or any other intellectual property right;
  • be in breach of any right of confidence, right of privacy or right under data protection legislation
  • constitute negligent advice or contain negligent statements;
  • constitute an incitement to commit a criminal offence, instructions for the commission of a criminal offence or the promotion of such an offence.

Data Mining

You shall not engage in any systematic or automated data scraping, data mining, data extraction or data harvesting or any other systematic or automated data gathering activity through or in connection with the Services.

Hyperlinks

You must not link to any material on or through the Services that, if made available through the Services, would violate the provisions of this Policy.

Harmful Software

The Content must not contain or consist of, and you must not promote, distribute or run through the Services, any viruses, worms, spyware, adware or other harmful or malicious software, programs, routines, applications or technologies.

The Content shall not contain or consist of, and you shall not promote, distribute or execute through the Services, any software, program, routine, application or technology that will or is likely to have a material adverse effect on the performance of a computer or introduce a material security risk to a computer.

Data Processing Agreement (DPA)

Data processing on behalf of the Controller "DPA" is concluded between the Client (Controller) and the Provider (Processor).

Categories of Personal Data

  • User Data (Name, email address, IP addresses)
  • Authentication data (e.g. login, ID, IP address, etc.)
  • Contractual information (e.g. terms and conditions, product interests, customer history, etc.)

Data Subjects

  • Employees of the Controller and other Client companies that will use the Software
  • Supplier and Contact persons / Employees of suppliers
  • other Contractors (in case of "critical contractors")

Sub-contractors

Vercel Inc.

340 S Lemon Ave #4133, Walnut, CA 91789, United States

Server/Data residency: EU: Frankfurt, Germany; Dublin, Ireland; Stockholm, Sweden

Supabase Inc.

970 Toa Payoh North #07-04, Singapore 318992

Server/Data residency: EU: Frankfurt, Germany

PostHog Inc.

2261 Market Street #4008, San Francisco, CA 94114, United States

Server/Data residency: EU

Sleekplan GmbH

Leopoldstraße 31, 80802 Munich (München), Germany

Server: EU

Technical and Organisational Measures (TOM)

  • Cloud Security: ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 9001
  • Application Security: Regular Penetration Tests by 3rd party, Information Security Policy
  • Security Features: 2FA, Password Policy, Security Audits, End-to-End Tests

Data Protection Officers: Michael M. Kania, Matthias Risto

Processing shall exclusively take place in Germany, in a Member State of the EU or in the EEA, subject to adequate data protection safeguards under GDPR Articles 44 et seq.