This Subscription Agreement (the “Agreement”) governs Customer’s purchase and use of HiveMQ Services. Please read this Agreement carefully as it is a binding agreement between HiveMQ (defined below) (“Provider”) and the person or entity purchasing the Services (“Customer”). Capitalized terms are defined below.
Provider offers the Services in two forms: (a) Cloud Services are Provider-hosted and delivered on a Software-as-a-Service (SaaS) basis, accessed by Customer through the HiveMQ Platform (currently at app.hivemq.com or successor, the “Platform”); and (b) Software is Provider software made available for download directly to the Customer or through the Platform and installed and operated by Customer in its own infrastructure.
Cloud Services and Software are collectively the “Services”. The specific Services Customer receives are identified on an ordering document either through online order or checkout, or by executing an ordering document that references this Agreement (each, an “Order”).
If Customer uses a Free Service, registers for a free trial or program, or accesses a Beta Service, Section 3 of this Agreement governs that use.
BY (1) CLICKING A BOX INDICATING ACCEPTANCE, (2) CONFIRMING AN ORDER THROUGH ONLINE PURCHASE, OR (3) EXECUTING AN ORDER THAT REFERENCES THIS AGREEMENT, CUSTOMER AGREES TO THE TERMS OF THIS AGREEMENT. IF THE INDIVIDUAL ACCEPTING THIS AGREEMENT IS ACCEPTING ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, SUCH INDIVIDUAL REPRESENTS THAT THEY HAVE THE AUTHORITY TO BIND THAT ENTITY AND ITS AFFILIATES, IN WHICH CASE “CUSTOMER” REFERS TO SUCH ENTITY AND ITS AFFILIATES.
Use of HiveMQ’s Sites is governed by the Terms of Service, not by this Agreement.
1. The Services
1.1 Cloud Services
(a) Provision and license. Provider will provide Customer with access to the Cloud Service in accordance with the Order and grants Customer the right to access and use the Cloud Service for its internal business purposes in accordance with the terms of this Agreement and the Order.
(b) Use by Customer. Customer will only access the Cloud Service through its documented access points and will only use the Cloud Service in accordance with the Documentation, this Agreement, and subject to the limits established in the Orders (such as limits on instances, capacity, connections, messages, nodes, or duration).
(c) Uptime and issue management. Provider will make the Cloud Services available in accordance with the Service Level Agreement and available at hivemq.com/legal (the “SLA”), which is incorporated by reference. The service credits in the SLA are Customer’s exclusive remedy for failure to meet the availability commitment. The SLA may not apply where the Cloud Service is a Free Service, is provided under a free trial or program, or is a Beta Service (each as described in Section 3) unless stated otherwise in an Order.
1.2 Software
(a) Provision and license. Provider will make the Software available for Customer to download either directly or through the Platform, and grants Customer the right to download, install, access, and use the Software for its internal business purposes, in accordance with the terms of this Agreement and the Order.
(b) Use by Customer. Customer will only access and use the Software in accordance with the Documentation, this Agreement, and subject to the limits established in the Orders (such as limits on instances, capacity, connections, messages, nodes, or duration).
(c) Monitoring of contractual use. To verify compliance with this Agreement and any usage limits and metrics set forth in an applicable Order (“Contractual Use”), Provider may, no more than once every six (6) months, request in writing information reasonably necessary to verify Contractual Use, which Customer will provide within fifteen (15) days. Monitoring and verification are limited to usage data needed to confirm Contractual Use; message payloads are not inspected, personal data is not collected, and Customer will have equivalent access to such usage data for its own license management. Provider will use commercially reasonable efforts to minimize business disruption.
2. Elements of the Services
2.1 Documentation. The Services documentation is available online at docs.hivemq.com, together with any additional documentation Provider makes available to Customer (collectively, the “Documentation”).
2.2 Support Services. Provider will provide the support services in accordance with the support and maintenance services agreed to between the parties in an Order (“Support and Maintenance”), and available at hivemq.com/legal.
2.3 Separately Licensed Software. Additional software programs and technology (including open-source software) may be available to Customer to use in conjunction with the Services (“Separately Licensed Software”). Separately Licensed Software is governed by separate terms, which the Services may contain or require for operation, and will be identified or made available to Customer as part of or along with the Services. If the Separately Licensed Software contains open-source terms, such terms will be licensed under an open-source license model (such as Apache 2.0, BSD-3, MIT) (“Open-Source License Model”).
2.4 Future functionality. Provider may make future improvements to the Services, which may include creating new features that are outside of the scope of Customer’s Order or sunsetting features that are within the scope of Customer’s Order. Customer will receive, at no additional charge, all future features and functionality that are sold to new customers as an element of the SKU purchased by Customer. If Provider sunsets material features within the scope of Customer’s Order, it will provide any successor features at no additional charge or, if no such successor features are available, then Customer may terminate the Order and receive a pro-rata refund of its prepaid fees. Customer Orders are not contingent on the delivery of future features. Upgrades to the Software subject to this clause will be available for downloading by the Customer in the Provider Support Portal.
2.5 Acceptable Use Policy. Use of the Services is subject to the Acceptable Use Policy (the “AUP”), which is incorporated by reference.
2.6 AI Features. The Services may comprise or include artificial intelligence (“AI”) features or functionality. Provider is committed to the responsible development of AI in the Services and will maintain appropriate technical safeguards. Customer’s use of any AI features or Agents within any Service is additionally governed by the AI Section of the AUP.
3. Free Services, Free Trials, and Beta Services
3.1 Free Services. Provider may make certain Services available to Customer at no charge on a permanent basis or up to certain usage limits described in the Documentation or Order (“Free Services”). Use of Free Services is subject to the terms and conditions of this Agreement. In the event of a conflict between this Section 3.1 and any other portion of this Agreement, this Section 3.1 shall control. Usage over any published limits requires Customer’s purchase of additional resources or paid Services. Provider may, in its sole discretion and for any or no reason, terminate Customer’s access to the Free Services (or any part thereof) at any time, with or without notice, and Provider will not be liable to Customer or any third party for such termination. Customer is solely responsible for exporting Customer Data from the Free Services prior to termination of Customer’s access for any reason.
NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, THE FREE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT ANY WARRANTY, AND PROVIDER SHALL HAVE NO INDEMNIFICATION OBLIGATIONS OR LIABILITY OF ANY TYPE WITH RESPECT TO THE FREE SERVICES UNLESS SUCH EXCLUSION IS NOT ENFORCEABLE UNDER APPLICABLE LAW, IN WHICH CASE PROVIDER’S LIABILITY WITH RESPECT TO THE FREE SERVICES SHALL NOT EXCEED USD $1,000.00. NOTWITHSTANDING ANYTHING TO THE CONTRARY IN SECTION 14 (LIMITATION OF LIABILITY), CUSTOMER SHALL BE FULLY LIABLE UNDER THIS AGREEMENT TO PROVIDER FOR ANY DAMAGES ARISING OUT OF CUSTOMER’S USE OF THE FREE SERVICES, ANY BREACH BY CUSTOMER OF THIS AGREEMENT IN CONNECTION WITH THE FREE SERVICES, AND ANY OF CUSTOMER’S INDEMNIFICATION OBLIGATIONS HEREUNDER.
3.2 Free Trials or Programs. If Customer registers for a free trial or program for the Services, Provider will provide those Services to Customer on a trial basis free of charge until the earlier of (a) the end of the free trial or program period; (b) the start date of any paid subscription to such Services; or (c) termination of the free trial or program by either party, in either’s sole discretion.
3.3 Beta Services. Provider may occasionally provide Customer access to new service offerings still in development (“Beta Services”). Provider will clearly designate all Beta Services as “alpha,” “beta,” “early access,” or something similar within the Services or Documentation. Customer may choose to use these Beta Services at its sole discretion. Customer will treat the Beta Services and any related documentation as Provider’s Confidential Information until Provider makes such information publicly available. Customer acknowledges that Provider is under no obligation to support the Beta Services, and Beta Services may not be as secure or reliable as Provider’s other Services. In Provider’s sole discretion, Provider may change the functionality of the Beta Services and/or discontinue, suspend, or remove Customer’s access to such Beta Services (including any Customer Data stored or processed within the Beta Services) and has no obligation to make such Beta Services generally available. NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, PROVIDER WILL HAVE NO LIABILITY ARISING OUT OF OR IN CONNECTION WITH BETA SERVICES.
4. Warranties and Disclaimer
4.1 Mutual. Each party represents that it has validly entered into this Agreement and has the legal power to do so.
4.2 Services warranty. For the full term of Customer’s Order, the Services will perform as described in the Documentation (the “General Performance Standard”). If the Services fail to meet the General Performance Standard, Customer may seek a remedy by providing a reasonably detailed notice of the failure, after which Provider will have thirty (30) days to correct the failure. If Provider cannot do so, then Customer may terminate any or all Orders for the Services immediately upon notice and receive a prorated refund for its prepaid but unused fees, measured from the date of the failure notice.
4.3 Professional services. All professional services will be provided according to industry standards and in a good and workmanlike manner.
4.4 Disclaimers. This Agreement is not a contract for the sale of goods, as those terms are defined under the Uniform Commercial Code, and that their intent is for the Uniform Commercial Code to not apply to this Agreement and the course of action it contemplates. The United Nations Convention on Contracts for the International Sale of Goods (CISG) is excluded. EXCEPT AS STATED HEREIN, PROVIDER DISCLAIMS ALL OTHER WARRANTIES AND ALL IMPLIED WARRANTIES, INCLUDING THE IMPLIED WARRANTY OF MERCHANTABILITY AND THE IMPLIED WARRANTY OF FITNESS FOR A PARTICULAR PURPOSE, AND THE SERVICES ARE OTHERWISE PROVIDED “AS IS”.
5. Provider Responsibilities
5.1 Protection Against Unwanted Code and Licenses. The Services, when used in accordance with this Agreement, will not expose Customer to (i) malicious software code, such as code designed to secretly penetrate Customer’s IT infrastructure or to create vulnerabilities within that infrastructure that can be exploited for such purpose, or (ii) licensing terms that would require Customer’s technology to be disclosed or distributed to the public (such as “copyleft” open-source licensing terms).
5.2 Security. Provider shall implement and maintain administrative, physical, and technical safeguards designed to comply with industry-standard security practices, including access controls, encryption, network security, vulnerability management, and incident response measures appropriate to the nature of the data and the Services provided. Provider shall review and update its security controls periodically to address evolving threats and maintain compliance with cybersecurity requirements.
5.3 Privacy. Provider’s processing of personal data in connection with the Services is governed by the Privacy Policy and, where Provider acts as processor on Customer’s behalf, by the Data Processing Agreement available on hivemq.com/legal/ (the “DPA”), which is incorporated by reference.
5.4 Return of Customer Data. Within thirty (30) days after termination of this Agreement, Customer may export Customer Data; after that period, Provider will delete Customer Data in the ordinary course, subject to legal retention obligations and the DPA where it applies.
6. Customer Responsibilities
6.1 Authorized Users. All persons authorized by Customer to access and use the Services by or on behalf of Customer (“Authorized Users”) are the responsibility of Customer. Customer is responsible for Authorized Users’ compliance with this Agreement.
6.2 Customer responsibilities. Customer will use the Services in accordance with this Agreement and the Documentation, will be responsible for the accuracy, quality, and legality of Customer Data and its means of acquiring it, and will use commercially reasonable efforts to prevent unauthorized access to the Services through its accounts and notify Provider promptly of any such access. Any use in breach of this Agreement that in Provider’s judgment threatens the security, integrity, or availability of the Services may result in immediate suspension, with Provider using commercially reasonable efforts to give notice and an opportunity to remedy before suspension.
6.3 Restrictions. The Services may only be accessed and used in accordance with this Agreement and the Documentation. Additionally, the Services may not be accessed for purposes of monitoring their availability, performance, or functionality, or for any other benchmarking or competitive purposes. Customer will not (i) interfere with or disrupt the integrity or performance of any Service or third-party data contained therein, or (ii) attempt to gain unauthorized access to any Service or its related systems or networks, including through penetration testing, vulnerability scanning, red-teaming, or similar security testing, except with Provider’s prior written consent and in accordance with any conditions Provider specifies. Except to the extent applicable law permits (including, for HiveMQ GmbH contracting parties, § 69e UrhG), Customer will not disassemble, reverse engineer, or decompile a Service, or access it to build a competing product, copy features or graphics, or determine patent scope.
6.4 Usage Limits. Services are subject to usage limits specified in Orders and the Documentation. If Customer exceeds a contractual usage limit, Provider may work with Customer to seek to reduce Customer’s usage so that it conforms to that limit. If, notwithstanding Provider’s efforts, Customer is unable or unwilling to abide by a contractual usage limit, Customer will execute an Order for additional quantities of the applicable Services promptly upon Provider’s request, and/or pay any invoice for excess usage in accordance with Section 9.3 (Authorization for Recurring Payments).
7. Compliance
7.1 Compliance with laws. Each party shall comply with all applicable federal, state, and foreign laws, codes, rules, and regulations in performing its obligations under this Agreement.
7.2 Export compliance and sanctions. Each party will comply with all applicable export control, sanctions, and trade laws in connection with, in the case of Provider, its provision of the Services, and in the case of Customer, its access to and use of the Services. Customer represents that neither Customer, its Affiliates, nor any personnel accessing the Services is subject to comprehensive sanctions or listed on any government restricted-parties list. Provider may screen Customer and suspend or terminate access if it determines in good faith that Customer’s use puts Provider at risk under these laws.
8. Term and Termination
8.1 Term. This Agreement commences on the date Customer first accepts it and continues until all subscriptions or Orders hereunder have expired or have been terminated.
8.2 Order term and renewal. The term of each subscription and its renewal is specified in the Order or on Customer’s account on the Platform portal.
8.3 Termination for cause. A party may terminate this Agreement (and the affected Order) upon thirty (30) days’ written notice of a material breach if the breach remains uncured at the end of that period.
8.4 Effect of termination. In addition to any refunds stated elsewhere in this Agreement, on termination for Provider’s uncured breach, Customer will receive a pro-rata refund of prepaid unused Fees for the period after termination. On termination for Customer’s uncured breach or non-payment, no refund is due and all amounts owed on an Order or invoiced Fees remain payable.
8.5 Suspension of Services. Provider may temporarily suspend the Services to an Authorized User or Authorized Users in response to misuse, for non-payment that remains uncured for fifteen (15) days after written notice, or as necessary to preserve the integrity or availability of the Services.
8.6 Survival of terms. Rights and obligations established under this Agreement that must survive termination in order to have their customarily intended effect (such as rights and obligations related to confidentiality, indemnification, limitation of liability and damages, and data and intellectual property) will so survive.
9. Fees and Payment
9.1 Fees. Customer will pay all fees specified in an Order or in the applicable online purchasing portal (the “Fees”). Except as otherwise specified in this Agreement or an Order: (i) payment obligations are non-cancelable and Fees paid are non-refundable; and (ii) quantities purchased cannot be decreased during the relevant subscription term.
9.2 Data Transfer Fees. Customer’s use of certain Cloud Services may incur data transfer, network egress, or similar bandwidth-related charges (“Data Transfer Fees”) based on the rates of the underlying cloud infrastructure provider used for Customer’s deployment (e.g., AWS, Azure, or similar). Such Fees may not be expressly listed in an Order. Data Transfer Fees are measured based on the total volume of data transmitted from the Cloud Service and are charged per gigabyte (GB) at cost to Customer in arrears.
9.3 Authorization for Recurring Payments. Where Customer pays by credit card, Customer will provide payment card information (a “Payment Method”). By providing a Payment Method, Customer authorizes Provider to charge the Payment Method on a monthly, annual, or pay-as-you-go basis, or as otherwise specified in the Order or online checkout, for Fees associated with the applicable subscription. Customer’s Payment Method must be valid and kept current. By providing a Payment Method, Customer represents that Customer is authorized to use it. Provider will begin billing the Payment Method for the Services on the date Customer is given access, regardless of whether Customer has fully configured or started using the Services as of that date. Where Customer pays by invoice, invoicing terms are set out in the Order and, unless the Order provides otherwise, invoiced Fees are due net thirty (30) days from the invoice date.
9.4 Third-Party Payments Processor. Provider uses Stripe, Inc. and its affiliates (the “Third-Party Payments Processor”) for online payment services (for example, card acceptance, merchant settlement, and related services). If Customer makes a purchase through the Platform, Customer will provide payment details and any additional information required to complete the transaction directly to the Third-Party Payments Processor. Customer agrees to be bound by Stripe’s Privacy Policy and its Terms of Service, and authorizes Provider and Stripe to share the information and payment instructions Customer provides to the minimum extent required to complete the transaction. Online payment transactions may be subject to validation checks by the Third-Party Payments Processor and Customer’s card issuer, and Provider is not responsible if a card issuer declines to authorize payment for any reason. The Third-Party Payments Processor uses fraud-prevention protocols and industry-standard verification systems to reduce fraud, and Customer authorizes it to verify and authenticate Customer’s payment information. Customer’s card issuer may charge an online handling fee or processing fee; Provider is not responsible for that. In some jurisdictions, the Third-Party Payments Processor may use third parties under strict confidentiality and data-protection requirements for the purposes of payment processing services.
9.5 Taxes. Fees are exclusive of any taxes, levies, duties, or governmental assessments, including withholding taxes (collectively, “Taxes”). Customer is responsible for paying all Taxes associated with its purchases, other than Taxes assessable against Provider based on its income, property, and employees.
9.6 Promotional Offers. Provider may offer special promotional offers or plans from time to time in Provider’s sole discretion (each an “Offer”). Offer eligibility will be determined by Provider in Provider’s sole discretion, and Provider reserves the right to revoke or end an Offer at any time. Customer agrees that Provider may use information such as device identifier, Payment Method, and the name and email address associated with Customer’s account to determine Offer eligibility. Eligibility requirements and other limitations and conditions will be disclosed when Customer signs up for the Offer or in other communications from Provider. Free trials and programs are governed by Section 3.1 and not by this Section.
10. Confidentiality
10.1 Confidential Information. “Confidential Information” means information disclosed by one party (the “Disclosing Party”) to the other (the “Receiving Party”) that is designated as confidential or that reasonably should be understood to be confidential given the nature and circumstances of disclosure. Customer’s Confidential Information includes Customer Data. Provider’s Confidential Information includes non-public information about the Services, pricing, Beta Services, and product roadmap. Confidential Information of each party includes business plans, technology and technical information, product plans and designs, and business processes disclosed by such party. Confidential Information excludes information that (i) is or becomes public without breach, (ii) was rightfully known to the Receiving Party before disclosure, (iii) is rightfully received from a third party without breach, or (iv) was independently developed by the Receiving Party.
10.2 Protection. The Receiving Party will use at least the same care as for its own Confidential Information of like kind (but not less than reasonable care) to protect the Disclosing Party’s Confidential Information and to limit access to those personnel, third-party service providers, and Affiliates who have a need to know and are bound by comparable confidentiality obligations.
10.3 Compelled disclosure. The Receiving Party may disclose Confidential Information to the extent compelled by law, provided it gives the Disclosing Party prior notice (where legally permitted) and reasonable assistance if the Disclosing Party wishes to contest.
10.4 Survival; NDA supersession. This Section 10 survives termination indefinitely for trade secrets and for three (3) years for other Confidential Information. This Section supersedes any prior non-disclosure agreement between the parties as of the Last Updated date.
11. Data Ownership and Use
11.1 Customer Data. All electronic data and information submitted by or on behalf of Customer to a Cloud Service, including Outputs (collectively, “Customer Data”) is and will remain the property of Customer. Customer grants Provider the right to use Customer Data to provide the Services under this Agreement.
11.2 Outputs. Data generated by a Cloud Service, including by any AI or agent feature within a Cloud Service, based on Customer Data (“Outputs”) is and will remain the property of Customer.
11.3 Aggregated and Anonymized Data. Notwithstanding Section 11.1, Provider may collect data from Outputs or Customer Data that has been modified so as to be attributable neither to the Customer nor to any personally identified individual (“Aggregated and Anonymized Data”). Aggregated and Anonymized Data is and will remain the property of Provider.
11.4 Usage and System Data. Provider may collect and process technical and operational data relating to the access to, use of, operation, performance, security, and entitlement to the Services, including system logs, telemetry, metrics, diagnostic data, license and entitlement information, configuration metadata, and similar data (“Usage and System Data”). Provider may use such data for its lawful business purposes, such as to improve the Services, provided that Usage and System Data does not identify Customer Data or personal data.
12. Intellectual Property
12.1 The Services. The Services (including, for example, their algorithms, calculations, organization, look and feel, and the underlying software code) are and will remain the sole property of Provider, and Provider is and will remain the sole owner of all intellectual property embodied or practiced by the Services.
12.2 Feedback. Suggestions for improvements to any element of the Services that are provided by Customer will be provided without restriction and will not operate to grant Customer an ownership interest in any intellectual property embodied or practiced by the Services or entitle Customer to royalties.
12.3 Reservation of rights. Each party reserves all intellectual property rights not expressly granted in this Agreement.
13. Indemnification
13.1 Definition of Indemnification. To “Indemnify” is defined to mean (i) to defend against all third-party claims (construed broadly, so as to include, for example, complaints and causes of action both when filed and when threatened) and regulatory actions (construed broadly, so as to include investigations and disciplinary actions by any government entity with the power to investigate or impose a penalty of any kind); and (ii) to pay all amounts (construed broadly, so as to include, for example, settlements, judgments, fines, and attorneys’ fees awarded under all available theories of liability and damages) owed to such third-party claimants or regulators.
13.2 Procedure. A party seeking to be Indemnified will provide timely notice to the Indemnifying party, although untimely notice will relieve the Indemnifying party of its obligations only to the extent that the delay has prejudiced its ability to defend the claim. The Indemnifying party will have the right to control the defense, including the right to reach a settlement with the claimant; however, the Indemnified party will have a right to participate through its own counsel at its own expense, and the Indemnifying party will not enter into a settlement that requires the Indemnified party to pay any amount or admit to any liability without the written consent of that Indemnified party.
13.3 Customer’s Indemnifiable Claims. Provider will Indemnify Customer for a claim that the Services infringe a patent or copyright, provided that the infringement arises through Customer’s licensed use of the Services, either alone or (when Provider would be liable for indirect or contributory infringement) in combination with other technology or processes.
13.4 Provider’s Indemnifiable Claims. Customer will Indemnify Provider for a claim that Customer Data, when used by Provider to provide Customer with the Services, infringes a patent, copyright, or other intellectual property right.
13.5 Remedies for IP infringement. In the event any portion of the Services is enjoined, or in Provider’s reasonable opinion is likely to be enjoined due to a proceeding alleging that the Services infringe, misappropriate, or otherwise violate any third-party intellectual property rights, Provider shall, at its own expense and as Customer’s sole and exclusive remedy: (a) procure for Customer the right to continue using the Services; (b) replace or modify the Services so that they become non-infringing while providing substantially equivalent functionality; or (c) if neither (a) nor (b) is commercially reasonable, terminate the affected Services and refund to Customer any prepaid fees for the unused portion of the terminated Services.
14. Limitation of Liability
14.1 Cap. EXCEPT AS SET OUT IN SECTION 14.3, EACH PARTY’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT (WHETHER IN CONTRACT, TORT, OR OTHERWISE) SHALL NOT EXCEED THE TOTAL AMOUNT PAID OR PAYABLE BY CUSTOMER TO PROVIDER UNDER THE ORDER(S) GIVING RISE TO THE LIABILITY IN THE CONTRACT (SUBSCRIPTION) YEAR IN WHICH THE EVENTS OCCURRED. THE CAP IS MEASURED ON A PER-CONTRACT-YEAR BASIS.
14.2 Excluded damages. NEITHER PARTY IS LIABLE FOR ANY LOST PROFITS, REVENUES, GOODWILL, OR INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, COVER, BUSINESS INTERRUPTION, OR PUNITIVE DAMAGES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
14.3 Carve-outs. The limits in Sections 14.1 and 14.2 do not apply to: (a) each party’s indemnification obligations under Section 13; (b) Customer’s payment obligations; (c) breaches of Section 6.3 (Restrictions) or Section 7.2 (Export Compliance and Sanctions); (d) willful or reckless misconduct or fraud; (e) for HiveMQ GmbH contracting parties, the Non-Excludable Liabilities and Kardinalpflicht regime in Annex A; and (f) any other liability that cannot be limited or excluded under applicable law.
15. HiveMQ Contracting Entity, Governing Law, and Venue
The HiveMQ entity entering into this Agreement, the applicable governing law, and the applicable forum depend on where Customer is domiciled:
| If Customer is domiciled in: | The HiveMQ entity is: | Notices to: | Governing law: | Forum with exclusive jurisdiction: |
|---|---|---|---|---|
| The European Economic Area, the United Kingdom, or Switzerland | HiveMQ GmbH (Berlin, Germany) | Friedrichstr. 68, 10117 Berlin, Germany, c/o Mindspace; attn: Legal; copy to legal@hivemq.com | Federal Republic of Germany (excluding CISG and conflict-of-laws rules) | Courts of Munich, Germany. Proceedings in English unless the parties otherwise agree. |
| Any country not listed above | HiveMQ Inc. (Delaware, USA) | 600 N Broad St, Suite 5, Middletown DE 19709, USA; attn: Legal; copy to legal@hivemq.com | State of Delaware (excluding conflict-of-laws rules and CISG) | Binding arbitration in Delaware, before a panel of three arbitrators administered by JAMS under its commercial arbitration rules. Either party may seek preliminary injunctive relief from a court of competent jurisdiction and may file in court to enforce an arbitration judgment. |
“HiveMQ” (or “Provider”) means the applicable entity above based on Customer’s domicile. For negotiated deals, HiveMQ and Customer may agree in the Order to contract with the non-default entity; the applicable governing law and forum will match the entity specified in the Order.
Class Action Waiver. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ALL DISPUTES, CLAIMS, OR CAUSES OF ACTION ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICES MUST BE BROUGHT IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, REPRESENTATIVE, PRIVATE ATTORNEY GENERAL, OR CONSOLIDATED PROCEEDING. THE ARBITRATOR (OR COURT, WHERE APPLICABLE) MAY AWARD RELIEF ONLY IN FAVOR OF THE INDIVIDUAL PARTY SEEKING RELIEF AND ONLY TO THE EXTENT NECESSARY TO RESOLVE THAT INDIVIDUAL CLAIM, AND MAY NOT CONSOLIDATE CLAIMS OF MORE THAN ONE PERSON OR PRESIDE OVER ANY FORM OF CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING. NOTWITHSTANDING THE FOREGOING, THIS WAIVER DOES NOT PRECLUDE A PARTY FROM BRINGING AN INDIVIDUAL CLAIM FOR PUBLIC INJUNCTIVE RELIEF WHERE SUCH WAIVER IS PROHIBITED BY APPLICABLE LAW (INCLUDING, WITHOUT LIMITATION, UNDER CALIFORNIA LAW). IF A COURT OR ARBITRATOR DETERMINES THAT THIS WAIVER IS UNENFORCEABLE AS TO A PARTICULAR CLAIM OR JURISDICTION, THEN SUCH CLAIM SHALL PROCEED ONLY ON AN INDIVIDUAL BASIS TO THE EXTENT PERMITTED BY LAW, AND THE REMAINDER OF THIS WAIVER SHALL REMAIN IN FULL FORCE AND EFFECT.
For HiveMQ GmbH contracting parties, the additional warranty and liability provisions in Annex A apply. Where Customer is a natural person purchasing for themselves (not on behalf of a legal entity), the provisions in Annex B apply and, where applicable, carry mandatory consumer-law protections.
16. General Provisions
16.1 Additional terms. If Customer is a natural person purchasing for themselves (not on behalf of an entity), Annex B applies. Where Annex B conflicts with this Agreement on a matter within its scope, Annex B prevails.
16.2 Entire agreement and order of precedence. This Agreement is the entire agreement between Provider and Customer regarding the Services and supersedes all prior and contemporaneous agreements, proposals, or representations concerning its subject matter. Any term in Customer’s purchase order or vendor onboarding document (other than an Order executed in accordance with this Agreement) is void. Order of precedence: (1) the applicable Order, (2) Annex A (where the contracting entity is HiveMQ GmbH), (3) Annex B (where Customer is a natural person under Annex B), (4) this Agreement, (5) the DPA, (6) the SLA, (7) the Support Policy, (8) the AUP, and (9) the Documentation.
16.3 Force majeure. A party’s failure to perform will be excused for up to thirty (30) days when directly caused by an intervening event of a magnitude or unpredictability (such as a natural disaster) that renders performance impractical despite that party’s continuity and recovery investments. The affected party shall promptly notify the other of the occurrence of a force majeure event and use all efforts to mitigate the effects of such event. If the duration of the force majeure event exceeds thirty (30) days, either party may terminate this Agreement upon written notice to the other party, and Provider will provide Customer with a pro-rata refund of its prepaid fees upon receipt of such notice. For HiveMQ GmbH contracting parties, “höhere Gewalt” within the meaning of German law is included.
16.4 Assignment. Neither party may assign this Agreement without the other’s prior written consent (not to be unreasonably withheld), except that either party may assign in its entirety without consent to an Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets. If a party is acquired by a direct competitor of the other party, the other party may terminate on notice and Provider will refund prepaid unused Fees.
16.5 Provider Affiliates. Customer consents to provision of the Services by a Provider Affiliate other than the contracting entity, where operationally needed. Provider remains responsible regardless of which Affiliate operationally provides the Services. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity (“control” meaning ownership or control of more than 50% of voting interests).
16.6 Subcontractors. Provider may engage subcontractors to perform its obligations and remains responsible for their performance. Provider’s sub-processors of Customer personal data are managed under the DPA.
16.7 Notices. Notices will be sent to the address or email of Customer set forth in the Order or the applicable account; notices to Provider will be sent to the email address listed for the applicable Provider entity in Section 15 above. Notices are in writing and effective on (a) personal delivery, (b) the second business day after mailing by recognized courier, or (c) the day of sending by email. Legal Notices (termination, indemnifiable claims) must be clearly identified as such and are effective on delivery.
16.8 Anti-corruption. Neither party has offered or received any improper bribe, kickback, or thing of value in connection with this Agreement (reasonable business gifts and entertainment excepted).
16.9 Relationship of the parties. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship between the parties.
16.10 Waiver. No failure or delay by either party in exercising any right under this Agreement will constitute a waiver of that right.
16.11 Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
16.12 Third-party beneficiaries. There are no third-party beneficiaries under this Agreement.
16.13 Updates to this Agreement. Provider may update this Agreement from time to time. Material changes are notified as described in Provider’s prior versions and take effect at the start of Customer’s next renewal term unless Customer accepts earlier or the change is required by law.
16.14 EU Data Act Terms.
The following EU Data Act Terms (“Data Act Terms”) apply where Customer is domiciled in the European Union or European Economic Area, or where Regulation (EU) 2023/2854 (the “Data Act”) otherwise applies to Customer’s use of the Services. In relation to Cloud Services, Provider is a “data processing service” within the meaning of Article 2(8) of the Data Act.
16.14.1 Right to switch. Consistent with Chapter VI of the Data Act, Customer has the right to switch to another data processing service, to on-premises infrastructure, or to use multiple providers in parallel, without undue commercial, technical, contractual, or organizational obstacles. On Customer’s written request, Provider will provide the assistance reasonably necessary to enable Customer to complete the switching process, including access to and export of Customer Data and, to the extent applicable, exportable digital assets in the formats supported by the Cloud Service. The switching period will be as agreed with Customer and, absent agreement, up to thirty (30) days.
16.14.2 Switching charges. In accordance with Article 29 of the Data Act, Provider’s switching charges (if any) will be gradually withdrawn on the timeline set by the Data Act, and from 12 January 2027 no switching charges will apply. Prior to that date, switching charges (if any) will not exceed the costs directly related to the switching process.
16.14.3 Transparency. Provider will make available to Customer, in a clear and comprehensive manner, information about the switching process and the technical measures Provider takes to facilitate switching, including standard contractual clauses concerning switching and any applicable charges, as required by Articles 25 and 26 of the Data Act.
16.14.4 Functional equivalence and interoperability. Where feasible for the type of Cloud Service, Provider will use reasonable efforts to facilitate functional equivalence following a switch. Provider will use open interfaces and, where available, adopted European standards and interoperability specifications, in accordance with Article 30 of the Data Act.
16.14.5 Unlawful third-country access. In accordance with Article 32 of the Data Act, Provider will take all reasonable technical, legal, and organizational measures, including contractual arrangements, to prevent international transfer of, or governmental access to, non-personal Customer Data held in the European Union or European Economic Area that would conflict with Union law or the national law of the relevant Member State. Provider will notify Customer, to the extent legally permitted, of any such request.
16.14.6 Data access and use. Where the Cloud Service processes data from connected products or related services within the meaning of Chapter II of the Data Act, Customer’s rights of access, use, and sharing of such data are as set forth in the Data Act. Provider will not use non-personal data generated by Customer’s use of a connected product or related service to derive insights about the economic situation, assets, or production methods of Customer, or to enable any other undertaking to do so, except as expressly authorized by Customer.
16.14.7 Effective date; phased applicability. The obligations in this Section 16.14 apply in accordance with the entry-into-force and applicability calendar of the Data Act under Article 50, including the phased withdrawal of switching charges under Article 29(1) with full withdrawal by 12 January 2027. Nothing in this Section 16.14 requires either party to comply with a Data Act obligation that is not yet in force.
Annex A — HiveMQ GmbH Contracting Parties
If Customer is contracting with HiveMQ GmbH per Section 15, the following provisions apply and prevail over conflicting provisions of this Agreement.
A.1 Warranty modifications. Provider’s strict liability under BGB § 536a(1) for defects existing at the time of contracting is excluded. Customer’s right of self-remedy under BGB § 536a(2) is excluded. Customer shall report defects (deviations from the Documentation) to Provider in writing without undue delay; Provider shall rectify within a reasonable time; if rectification fails, Customer may terminate the affected Order under Section 8 with a pro-rata refund of prepaid unused Fees. Section 6.3 is read together with Customer’s mandatory rights under § 69e UrhG (decompilation for interoperability, subject to statutory conditions).
A.2 Non-Excludable Liabilities. Notwithstanding Section 14 of the Agreement, each party is liable without limitation for: (a) intent (Vorsatz); (b) gross negligence (grobe Fahrlässigkeit) where exclusion would be invalid under BGB § 309 No. 7(b); (c) breach of a guarantee (Beschaffenheitsgarantie); (d) malicious concealment of a defect; (e) injury to life, body, or health; (f) liability under the German Product Liability Law (Produkthaftungsgesetz); (g) fraud; (h) Provider’s indemnification obligations under Section 13; and (i) Customer’s payment obligations. These are the “Non-Excludable Liabilities.”
A.3 Kardinalpflicht. For slight negligence in breach of a cardinal duty (an obligation the fulfillment of which is essential to the proper performance of this Agreement and on which the counterparty regularly relies), liability is limited to the foreseeable damage typical for the contract. Otherwise, liability for slight negligence is excluded.
A.4 Cap and scope. Except for Non-Excludable Liabilities, the cap and exclusions in Section 14 apply, including to employees, agents, and bodies of the parties. These limitations apply to all claims for damages regardless of legal basis (including tort).
A.5 Free Services, free trials, and Beta Services. For Free Services, Services provided under a free trial or program, and Beta Services, Provider’s liability is further limited to intent, gross negligence, and the Non-Excludable Liabilities. Provider does not warrant Free Services, Services provided under a free trial or program, or any Beta Service.
Annex B — Individual Purchasers
If Customer is a natural person purchasing for themselves (not on behalf of a company or other legal entity), the following provisions apply and prevail over conflicting provisions of this Agreement within their scope. This Annex is a thin layer of modifications, not a parallel contract. The license, warranty, limitation of liability, and use rules elsewhere in this Agreement apply equally to natural-person and entity buyers. This Annex carries only what changes when the buyer is a natural person.
B.1 Contracting party. The natural person named on the Order or in the checkout flow is Customer under this Agreement. There is no entity, corporate veil, or separate legal person between Customer and HiveMQ. Customer is personally responsible for the account, payment of Fees, use of the Services, and compliance with this Agreement and the AUP.
B.2 Modified mechanics. The following provisions of this Agreement are modified when this Annex applies:
(a) Affiliates. Section 16.5 (Provider Affiliates) continues to apply to HiveMQ. Customer, as a natural person, has no “Affiliates” for purposes of this Agreement, and Customer may not extend the Services to any other person or entity as an Affiliate, family member, business, or otherwise.
(b) Authorized Users. Section 6.1 (Authorized Users) is limited: Customer is the sole Authorized User of the account. Team-seat management, delegated admins, and sub-accounts do not apply. Customer may not permit any other person to access or use the Services through Customer’s account.
(c) Assignment. Section 16.4 (Assignment) is limited: Customer may not assign this Agreement other than to Customer themselves (for example, on a name change or personal-account restructuring). Assignment to a company Customer forms or controls requires HiveMQ’s prior written consent.
(d) Monitoring of contractual use. Section 1.2(c) (Monitoring of contractual use) applies only where Customer uses Software, and monitoring is limited to information reasonably available to a natural-person user.
(e) Notices. Notices to Customer under Section 16.7 (Notices) go to the email address Customer provided at signup and, where required by consumer law, to any postal address Customer also provided.
B.3 Auto-renewal and cancellation. Where local consumer-protection law requires it, HiveMQ will provide the notices and cancellation mechanics prescribed by that law. Without limiting this, for natural-person buyers in jurisdictions with mandatory subscription-renewal disclosure or cooling-off periods (see Section B.4), HiveMQ will: (a) give clear pre-renewal notice a reasonable time before an auto-renewal or long-term commitment renews; (b) provide a straightforward mechanism to cancel the subscription in the Platform; and (c) honor any cooling-off or withdrawal right that applies under the applicable consumer-protection law.
B.4 Mandatory Consumer Protections. The following provisions auto-apply only when all three of the following are true:
(a) Customer is purchasing for purposes that are wholly or mainly outside Customer’s trade, business, craft, or profession (a mixed-purpose purchase qualifies where the trade or business purpose is not the predominant purpose, consistent with Recital 17 of Directive 2011/83/EU, BGB § 13, and section 2(3) of the UK Consumer Rights Act 2015); and
(b) Customer is located in the European Union, United Kingdom, or California; and
(c) the purchase qualifies as a consumer contract under the law of that jurisdiction.
Where all three are met, this Section B.4 carves out the mandatory consumer-law protections listed below, and these carve-outs prevail over any conflicting provision of this Agreement, Annex A, or the balance of this Annex.
B.4.1 EU consumers. Customer has (a) the right of withdrawal under Directive 2011/83/EU (Consumer Rights Directive), Articles 9–16, together with the pre-contract information and plain-language requirements at Articles 5–6; (b) protection against unfair terms under Directive 93/13/EEC; and (c) statutory remedies under Directive (EU) 2019/770 (Digital Content / Digital Services Directive) where the Services qualify as digital content or a digital service — including where the Services are supplied in exchange for personal data rather than money. Nothing in this Agreement or this Annex excludes or limits these rights.
B.4.2 German consumers specifically. BGB §§ 305–310 (AGB-Kontrolle) apply with heightened scrutiny to standard-form terms used with consumers. Provisions of this Agreement’s limitation-of-liability, warranty-disclaimer, and venue clauses that would not survive AGB review as applied to consumers are read down to the extent required by German law. The mandatory-liability regime in Annex A (Non-Excludable Liabilities and Kardinalpflicht) continues to apply.
B.4.3 UK consumers. The statutory implied terms of the Consumer Rights Act 2015 — satisfactory quality, fit for purpose, conformity with description — apply to Customer’s use of the Services and cannot be excluded. The Act’s controls on unfair terms also apply.
B.4.4 California consumers. The California Consumer Legal Remedies Act (Civil Code § 1750 et seq.) applies to the extent applicable to digital goods or services. California applies its own, narrower “personal, family, or household purposes” test under CLRA § 1761(d), so a Customer who qualifies as a consumer under EU or UK law (Section B.4(a)) may not separately qualify as a consumer under California law. Where CLRA does apply, specific limitations on liability-cap and warranty-disclaimer enforceability under California consumer-protection law take precedence over the corresponding provisions in this Agreement. CCPA / CPRA privacy protections are handled in the Privacy Policy and continue to apply.
B.4.5 EU Data Act. For natural-person consumers domiciled in the European Union or European Economic Area, the switching, portability, and unlawful-third-country-access protections in Section 16.14 (EU Data Act Terms) continue to apply. Consumer protections under the Data Act — including any right to switch without undue obstacles — are not waived by this Annex.
B.5 Self-identification. At checkout, Customer indicates (a) whether Customer is buying as an individual (for themselves) or on behalf of a company, and (b) Customer’s country of residence. This Annex attaches when Customer identifies as an individual. Section B.4 additionally applies when the three triggers in that Section are met. If Customer’s self-identification is inaccurate, this Annex still applies where its triggers are objectively met — but Customer’s representation gives HiveMQ a defensible position on what was disclosed at acceptance.
B.6 Consumer forum rights. Governing law and venue follow Section 15 based on Customer’s domicile. Nothing in this Annex overrides mandatory consumer-law protections under Section B.4, including consumer rights of access to the courts of Customer’s country of residence where guaranteed by local law (for example, Brussels I bis Regulation (EU) 1215/2012, Articles 17–19, for EU consumers).
B.7 Consumer contact. For natural-person consumer inquiries — including cooling-off, withdrawal, and consumer-rights requests — write to contact@hivemq.com. Data-protection inquiries: privacy@hivemq.com.