Terms of use for DocCheck Password Protection


The following terms of use apply to all information providers within DocCheck unless stipulated otherwise.

  § 1 Object and Purpose of the Agreement  
The object and purpose of the Agreement is to integrate DocCheck into the website of the Information Provider. The respective websites arise from the entries of the Information Provider in the Webmaster Lounge.

  § 2 Obligations  
(1) DocCheck shall provide the Information Provider with an HTML code containing a CGI script. The CGI script checks the existence of a user name/password combination in the database of a Web server operated by Donetscape navicCheck ("password server").

(2) In the event that the user name/password combination located and sent by the CGI script exists, the password server sends an Internet address to the browser running the CGI script. This Internet address refers to a defined HTML message on the Information Provider's server (non-public URL). If the user name/password combination is not located, an error message appears.

(3) The CGI script is capable of checking personal user name/password combinations and/or optional site-specific user name/password combinations.

(4) Personal user name/password combinations are issued to the user by DocCheck personally. Personal user name/password combinations are also valid on the websites of all other information providers participating in the DocCheck system if the other information providers have authorized the professional Group or group of persons to which the user belongs by way of their site policy (see paragraph 3.1.).

(5) Users are verified by DocCheck prior to any activation of a user name/password combination. The affiliation of users to a defined professional group or group of persons is reviewed by comparing the registration data with a written verification submitted (by facsimile) by the person registering. The verification document will comprise a copy of the medical licence, the physician's ID or a comparable document.

(6) Site-specific user name/password combinations (so-called company passwords) are defined in the DocCheck Webmaster Lounge by either the Information Provider itself or an authorized party.
It is the sole responsibility of the Information Provider to issue the site-specific user name/password combinations. DocCheck will not perform any verification of user name/password combinations. The company password is valid only for the websites of the Information Provider.

(7) The Information Provider acknowledges that it is aware that its non-public URL can be accessed by other unauthorized means (e.g. by guessing or by passing on of corresponding addresses) even after the integration of the DocCheck HTML code on its sites unless the Information Provider has installed additional directory protection on its Web server.

  § 3 Authorized Group of Persons  
(1) It is the responsibility of the Information Provider to specify the group of users that has authorized access to the defined, non-public URL (site policy). The Information Provider makes a detailed selection of authorized professional groups in the DocCheck Webmaster Lounge.

(2) Regarding the content of the non-public URL Doc Check will not be liable for ensuring that the specifications comply with existing legal standards, e.g. with the standards of the German federal law on advertising of drugs (Heilmittelwerbegesetz) or with comparable legislation in other countries.

(3) The Information Provider shall indemnify DocCheck against any claims for damages resulting from an incorrect selection or selection not in compliance with the valid legal standards.

(4) The Information Provider shall itself deal with all possible objections made by users against its site policy.

  § 4 Warranty  
(1) DocCheck shall check as diligently as possible that users belong to the designated professional groups or groups of persons ("physicians", "pharmacists" etc.).

(2) DocCheck cannot rule out the possibility that unauthorized third parties may, e.g. through deception, falsification of documents or spying, acquire a user name/password combination which allows them to access the non-public URL of the website of the Information Provider. DocCheck cannot guarantee that DocCheck users will not pass on links or bookmarks which allow unauthorized third parties to access the non-public URL of the Information Provider?s website.

(3) In case of site-specific user name/password combinations, the Information Provider shall itself be responsible for the conscientious distribution of the user name/password combinations. DocCheck will not be held liable for ensuring that the group of persons gaining access to the non-public URL with site-specific user name/password combinations is in compliance with existing legal standards. The Information Provider shall be fully liable.

(4) DocCheck shall be liable for damages/losses caused by it or its agents through gross negligence or willful intent. If essential contractual obligations are violated, liability shall, in cases of simple negligence involving financial damages/losses, be limited to foreseeable, direct damages/losses and shall be limited to an amount of Euro 5,000.00. Liability shall otherwise be excluded.

  § 5 Availability  
(1) DocCheck shall ensure that interruptions remain minimal and shall provide the authorized group of users with continuous access to the protected sites of the Information Provider's website. The Information Provider acknowledges that is aware that its non-public URL is inaccessible to users of the DocCheck password as long as the password server is not in operation.

(2) DocCheck shall guarantee an average per annum system operability of 97%.

(3) DocCheck reserves the right, with due notice, to restrict the availability of its service, e.g. to carry out maintenance work on the system.

(4) In cases of failure of software or hardware components of the password server or in case of data line failures DocCheck undertakes to provide replacement services within an adequate period of time and to restore operational status without undue delay.

  § 6 Data Protection  
(1) User data obtained by DocCheck is subject to data protection. DocCheck will only pass on available data such as addresses and e-mail addresses to third parties with the user's prior, express consent (e.g. in the context of DocCheck Personal).

(2) The user's consent to passing on his/her data to the Information Provider applies only to the usage of data for CRM or market research purposes. The consent shall not include receipt of advertising or information material to e-mail addresses and fax numbers.

(3) DocCheck shall exclusively provide anonymized statistics about the use of websites connected to DocCheck. Personal user profiles with information on the user's personal access habits shall not be provided.
  § 7 Obligations Information Provider  
(1) In the public area of its websites the Information Provider undertakes to offer access via DocCheck obviously so that DocCheck users are able to directly recognize the possibility of access via DocCheck.

(2) Access via DocCheck shall be provided with a DocCheck logo of at least 95 x 69 pixels in size and with a link to password application (http://www.doccheck.de/). Sample logos are available at http://www.doccheck.de/webmaster/code/index.htm.

(3) The CGI script made available by DocCheck through the HTML code shall not be modified by the Information Provider. The reading out and storing of user name/password combinations by the Information Provider shall constitute a breach of data protection legislation and is not permissible.

(4) The Information Provider shall be obliged to inform DocCheck immediately in the event that suspicion of misuse of a user name/password combination arises.

(5) If the Information Provider places a cookie after verification by DocCheck e.g. in order to facilitate access for the user within an interlinked system of several Internet websites, the cookie shall be valid only for one user session (temporary cookie). Other cookies (e.g. lifetime cookies) are not permissible.

(6) The Information Provider undertakes not to use any other system apart from DocCheck for verification of access authorization. This does not apply to the Information Provider's own systems.

(7) The Information Provider undertakes to carefully install the DocCheck HTML code on its server system in accordance with the technical guidelines of DocCheck.

(8) In the event that the Information Provider uses services that transfer personal data or DocCheck user IDs with the user's consent from DocCheck to the Information Provider (e.g. DocCheck Personal) it undertakes to handle the data according to the regulations of the German laws of data protection and the European directive on data protection (95/46/EG). Furthermore, it undertakes to not pass on the data to a third party without the user?s consent.

(9) The responsibility for proper handling of data will rest upon the Information Provider once DocCheck transfers the data. The Information Provider indemnifies DocCheck from all claims against DocCheck in the event that the Information Provider or an authorized party does not adhere to its obligations and responsibilities contained in this Agreement or those contained in the relevant legislation.

(10) The Information Provider undertakes to request the user's consent to receive e-mails according to the legal requirements before it contacts the user by e-mail.

(11) The user reserves the right to revoke his/her consent relating to the use of his/her data towards the Information Provider and/or DocCheck. In this case the Information Provider is bound to desist the further data usage and must delete it without delay.
  § 8 Duration of Agreement, Termination  
(1) The term of the Agreement shall be 1 year. The term of the Agreement shall automatically be renewed for a further year unless notice of termination is given 3 months prior to the expiration of the Agreement. The relevant date of notification shall be the date on which DocCheck received written notification. Immediate termination for good cause shall remain unaffected.

(2) The following non-exclusive reasons shall be deemed good cause for termination of the Agreement by DocCheck:
- the Information Provider breaches its obligations as defined in sections 7.1 - 7.11;
- the Information Provider breaches statutory prohibitions, particularly if it violates regulations under criminal law, copyright law, competition law, law relating to the use of names or data protection law;
- there is a fundamental change in the legal or technical standards of the Internet, as a result of which DocCheck cannot reasonably be expected to continue to provide its services in whole or in part.

  § 9 Choice of Law, Place of Performance  
(1) The Agreement is subject to the laws of the Federal Republic of Germany.

(2) The Agreement's place of performance is the registered office of DocCheck.

(3) Any disputes relating to this Agreement shall fall within the jurisdiction of the courts of Cologne.

(4) General terms and conditions of the Information Provider do not apply.

(5) This Agreement shall constitute the entire agreement. Additional oral agreements are not made. Modifications or additions to this Agreement must be in written form to take effect and expressly incorporated into this Agreement. This applies also for the modification of the written form.

(6) In the event that a provision of this Agreement is rendered ineffective or inoperable, the remainder of the Agreement shall remain unaffected. In the case of one contractual provision being ineffective the parties undertake to find a regulation that both of them can consent to. Its commercial success has to come up to the ineffective provision as far as possible.