Legal
DEEN
← Back to the home page

Schedule 1a to the platform provider agreement

Schedule 1a – Special Use Restrictions for vin.vehicle with Provider 1

Special agreement to the tapinomahub Platform Provider Agreement

Version: 01.09.2026

CONTENTS011. Scope and priority022. Mandatory redirect; no embedding or circumvention033. Prohibition on capturing browser data044. Changes and evidence055. Supplemental recourse

This Schedule supplements the obligations already governed by the Main Agreement solely by the following special restrictions for Provider 1. General use, security, storage, deletion, liability, indemnity and suspension provisions are not repeated.

01 / 1. SCOPE AND PRIORITY

1. Scope and priority

1.1 This Schedule forms part of the Order Form entered into between gobecom and the Customer, including the Platform Addendum and the GTC (together, the “Main Agreement”).

1.2 It applies exclusively to vehicle matching under the billing key (endpoint_key) vin.vehicle where the delivery mode numerically designated in the tapinomahub documentation as “Provider 1 · Guided browser lookup” is used. “Provider 1” is solely this numerical product designation; it makes no statement regarding any identity or technical implementation in the background.

1.3 Only within this narrow scope do the restrictions below prevail over conflicting general integration or onward-delivery rights under the Main Agreement. In all other respects, the Main Agreement remains unchanged.

02 / 2. MANDATORY REDIRECT; NO EMBEDDING OR CIRCUMVENTION

2. Mandatory redirect; no embedding or circumvention

2.1 The Customer may provide the Provider-1 vehicle lookup solely through the documented redirect-session flow. The redirect session must be created from the Customer's backend through POST /vin/redirect-sessions; the API key must remain in the backend. The returned redirectUrl may be opened only in the respective User's browser as a stand-alone top-level browser page or view (top-level browsing context).

2.2 Any direct API or server-to-server retrieval of the Provider-1 result, in particular through GET /vin/{vin}/vehicle, and any technically or functionally equivalent circumvention of the redirect-session flow are prohibited.

2.3 In particular, the redirect interface must not be embedded, copied, relayed, modified or concealed within the Customer Platform or another system by means of an iframe, frame, WebView, embedded browser window, reverse proxy, URL masking, mirroring, white-label presentation or comparable technology.

2.4 The Customer must not read, reproduce or circumvent the redirect flow through screen scraping, DOM or network extraction, browser automation, undocumented return or callback mechanisms or other technical measures. It must ensure this technically and organisationally for its Users and engaged service providers.

03 / 3. PROHIBITION ON CAPTURING BROWSER DATA

3. Prohibition on capturing browser data

3.1 Vehicle data, equipment data and manufacturer notations originating from and displayed in the guided browser lookup must not be read, captured or exported manually or automatically, transmitted to the Customer Platform or other systems, disclosed to third parties or stored permanently.

3.2 If such browser data is captured or stored contrary to this Schedule, the Customer must immediately stop further processing and disclosure, notify gobecom in text form, delete all copies in full and, upon justified request, provide evidence of deletion and remediation.

04 / 4. CHANGES AND EVIDENCE

4. Changes and evidence

4.1 If gobecom notifies the Customer in text form of an amended or additional integration, use, storage or onward-delivery restriction relating to Provider 1, the Customer must fully implement the specifically identified requirement technically and organisationally within ten Business Days after receipt. A shorter period applies only where mandatorily required by an immediately enforceable statutory or regulatory requirement or an acute security risk.

4.2 Where there are specific indications or reasonable grounds to suspect a breach, the Customer must, upon a justified request, provide gobecom with the necessary and proportionate evidence concerning integration, configuration, access protection and deletion. The review will be limited to the affected Provider-1 flow and conducted with due protection of the Customer's trade secrets; prohibited browser data need not be stored or newly generated for evidence purposes.

05 / 5. SUPPLEMENTAL RECOURSE

5. Supplemental recourse

5.1 If a culpable breach of this Schedule by the Customer, a User or a service provider engaged by the Customer demonstrably results in gobecom being charged by an entitled third party, in respect of the same matter, with a legally valid and enforceable contractual penalty or comparable contractual sanction, the Customer shall indemnify gobecom against that charge or reimburse an amount already paid by gobecom.

5.2 Recourse is limited to the documented portion causally attributable to the same culpable breach. Recourse will be reduced to the extent gobecom culpably contributed to the charge; double recovery is excluded. Notice and conduct of the defence are governed by the Main Agreement.

UNTERSCHRIFTEN · SIGNATURES

ImpressumDatenschutzAI/LLM documentation
© 2026 gobecom GmbH