General Terms and Conditions of Use for the Strong Authentication Authenticator Enrollment Portal (AEP).

Version 1.0 (of May 6, 2021)

0. Preamble

These terms and conditions of use shall apply to external as well as internal users.

1. Scope

BMW AG ("BMW") offers the Authenticators Enrollment Portal (AEP) externally at https://securelogin.bmw.com or internally at https://strong.bmwgroup.net.

The following terms and conditions shall regulate the use of the AEP. It is possible that existing contracts (including terms and conditions of use, confidentiality agreements, conditions of purchase) could apply to any services of BMW and its affiliated companies to which the AEP may refer. In the event of a conflict between those existing contracts and these General Terms and Conditions of Use the former shall prevail.

2. Services

The BMW Authenticators Enrollment Portal (AEP) is a self-service interface (part of the Advance Authentication (AA) application) to help users link or unlink authenticators (Smartphone, Yubikey, PIN, etc.…) to their primary account. Each authenticator is used by AA to help verify that a user is who they say they are.

The AEP has web pages, which are accessible by the public, as well as access-restricted web pages for which registration is required. After logging in, authorized users have access to a general as well as a function-specific selection of information and services.

Disruptions to the services of the AEP may occur as a result of force majeure, including strikes, lockouts and public agency orders, and also as a result of technical and other work that may need to be carried out on the systems of BMW, the suppliers of traffic data or network operators in order to operate properly or improve the EAP (e.g. maintenance, repair, software updates to systems, expansions). Disruptions to the services of the AEP may also result from temporary capacity shortages due to peaks in demand for the services of the AEP or from malfunctions in third-party telecommunications systems. BMW's responsibility to solve such disruptions shall be limited to commercially reasonable efforts.

3. Costs

BMW, itself, shall request no remuneration for the development of the AEP and making it available for use. The cost of any services provided by means of the AEP shall be subject to separate agreement. Any user costs associated with the AEP such as access to the Internet, authorized users and administration overheads as well as the purchase of necessary hardware and software is not refundable by BMW.

4. Organizational Requirements

Access to the AEP's non-public web pages is restricted to the employees of BMW and its affiliated companies and those companies designated by BMW and/or its any of its affiliated companies as partners.

Users shall log in at the beginning of every session. BMW reserves the right to refuse registration or login fully or partially or to cancel any existing rights of access.

5. Technical Requirements

The current technical requirements for access are (at a minimum) username and initial login credentials. Each user account is unique in name, methods of access and policy restrictions, therefore, these requirements may, if necessary, be adapted by BMW to individual situations.

6. Duration and Extent of User Rights

The right to use the AEP is restricted to employees (incl. former) of BMW and its affiliated companies and to the employees of those companies designated by BMW and/or its any of its affiliated companies as BMW partners.

The use the AEP by the above-mentioned group of individuals shall only be in connection with the enrollment and management of personal authentication factors for BMW systems. Any other use is prohibited.

BMW is entitled to determine the duration and extent of any rights of access as well as the general scope of services provided to the user through the AEP. Both BMW and the user are entitled to terminate a user's use of the AEP at any time.

7. User's Duty of Care

The right of access is not transferable. The user shall assure that their method of authenticating does not come into the possession of any unauthorized third party. In the event that a user becomes aware that an unauthorized third party has come into possession of one of these methods or if the user has reason to believe that improper use is being made of his access details, the user shall immediately notify the Strong Authentication team via the IT service desk.

The user shall inform their management and/or their BMW partner contact (as applicable) whenever the reasons for utilizing and managing strong authentication at BMW cease to exist such as in connection with the termination of employment by a partner company or an early termination of the contractual relationship between BMW or its affiliate company and the partner company.

BMW reserves the right to deny access and to seek other forms of legal redress in the event of any infringement of these terms and conditions in relation to the improper use of user-related access details.

The user is further prohibited to engage in any activities, which could result in the destruction or manipulation by that user or any third party of databases or IT systems of BMW or its affiliated companies or its designated partner companies.

8. Confidentiality, Information Protection, and Protection of Personal Data

Notwithstanding any existing legal or contractual obligations regarding confidentiality, the following undertakings shall be continuing and therefore remain valid after the termination of user rights:

The user undertakes to treat all knowledge relating to business secrets, which come into his possession, as confidential.

The user shall assure that any protected data, which comes into his possession through the use of AEP, is not transmitted to any unauthorized persons.

9. Liability

The Authenticators Enrollment Portal (AEP) is maintained with the necessary diligence. Nevertheless, while the information provided is believed to be accurate, it may include errors or inaccuracies.

In the event of minor negligence, BMW shall only be liable for the violation of essential contractual duties (cardinal duties), such as those duties the contract is deemed to impose upon BMW according to its spirit and purpose and the very performance of which is deemed to be necessary for a due and careful fulfilment of the contract and which may with good reason permanently be relied on by the customer. This liability is limited to the typical losses foreseeable at the time of concluding the contract.

The personal liability of the legal representatives, vicarious agents, and employees of BMW for any damage caused by their minor negligence shall similarly be limited by the extent described in the previous section.

The liability of BMW shall remain unaffected in the event of any malicious concealment of a fault, on account of a guarantee or procurement risk being accepted and in accordance with product liability legislation. Limitations of liability shall not apply to willful intent, gross negligence or loss of life, physical injuries, or damage to health.

10. Third Party Services

Any link or function contained in the AEP which provides access to third party programs or content are provided for convenience only. BMW does not express any opinion on or endorsement of the content of any such third party programs and expressly disclaims any liability for the quality, content, nature, or reliability of any such third party resources and the information, products and services found thereon.

11. Trademarks

Unless otherwise stated, all trademarks used in the AEP are protected by BMW or its affiliated companies. This is applicable to any trademarks, type designations, logos, and emblems. No license is granted to you to use any trademark of BMW.

12. License

All intellectual property contained in the AEP such as patents, trademarks and copyrights are protected. User rights are granted only to the extent and for the duration that they are required in connection with any legal use of the AEP. In addition, no license is granted for the use of intellectual property of BMW or its affiliated companies or third parties.

13. Copyright

Text, pictures, graphics, sound, animations, and videos as well as their layout in the AEP are protected by copyright and/or other intellectual property rights. User rights are granted only to the extent and duration that they are required for the legal use of the AEP. In addition, the contents of the website may not be copied, distributed, altered, or otherwise made available to third parties, if not permitted by applicable law It is possible that photographs or other images on the website may have been copyrighted by third parties

14. Concluding Provisions

Although the AEP and its content may be accessible worldwide, any product or service offered herein is void where prohibited by law. Accessing the AEP from territories where its contents are illegal or unlawful is prohibited.

BMW reserves the right to change these Terms and Conditions at any time. BMW shall notify the user of such changes, which shall become effective if the user does not object to the changes within six weeks upon receipt of the change notice. If the amended terms and conditions are rejected by the user, BMW shall be entitled to terminate user privileges and cancel existing rights of access.

If any provision of these General Terms and Conditions of Use is or becomes ineffective, then all other terms and conditions of use shall remain unaffected. BMW and their partner companies shall, in all reasonable good faith, replace the ineffective provision with a permissible provision, the commercial consequences of which are as close as possible to those of the ineffective provision, to the extent that this does not result in a material amendment of the content.

These terms and conditions as well as the legal relationship between the parties are subject to German law. Any disputes arising in connection with these General Terms and Conditions of Use shall be subject to the exclusive jurisdiction of the courts of Munich.

Any questions regarding these General Terms and Conditions of Use shall be directed to (yubikey(at)bmwgroup.com).